Skip to content

Disable policy DAST scan profile modification

Alexander Turinske requested to merge 321886-disable-policy-dast-profile into master

What does this MR do?

Disable policy DAST scan profile modification

  • if a policy is linked to a DAST scan/site profile, do not allow a user to modify it on the On-demand scan page

How to test

https://gitlab.com/-/snippets/2088929

Screenshots (strongly suggested)

I am only showing the disabled screenshots because otherwise the pages look the same

Page Screenshot
Site List - Large Screen_Shot_2021-03-12_at_9.24.41_AM
Site List - Small Screen_Shot_2021-03-12_at_9.28.14_AM
Scanner List - Large Screen_Shot_2021-03-08_at_2.09.19_PM
Scanner List - Small Screen_Shot_2021-03-08_at_2.09.25_PM
Site Profile - Disabled Screen_Shot_2021-03-09_at_1.28.18_PM
Site Profile Auth - Disabled Screen_Shot_2021-03-09_at_2.22.11_PM
Scanner Profile - Disabled Screen_Shot_2021-03-08_at_3.12.28_PM

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Related to #321886 (closed)

Edited by Alexander Turinske

Merge request reports