On-demand DAST configuration improvements
## Problem to solve After completing some recent [research initiatives](https://gitlab.com/gitlab-org/gitlab/-/issues/348203#related-research-recommendations) we've learned that there are a few notable pain points throughout the DAST configuration UI. In preparation for DAST to reach Complete maturity by the end of FY23-Q1, we'd like to address some of those problematic areas. **Note: This epic is for the On-demand configuration UI only.** <br> CI/CD configuration updates can be found: &7632<br> ## Plan details #### User experience goals 1. Improve learnability by adding better explanations of the concepts and available options 1. Rework the configuration workflow to minimize context switching 1. Restructure the DAST configuration areas (CI/CD, On-demand, Manage DAST scans) to improve the relationship between CI/CD & On-demand configuration. #### Intended users 1. [Sasha (Software Developer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sasha-software-developer) 1. [Sam (Security Analyst)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sam-security-analyst) #### JTBD 1. When I am configuring a CI/CD security scan, I want to specify which assets need to be scanned and under which circumstances, So that I can ensure my assets are secure prior to or at their release. 1. When I am configuring a security scan, I want to specify which types of vulnerabilities the scan should detect, So that we don't waste time sorting through irrelevant findings. 1. When I am either enabling or configuring a security scan, I want to run a demo scan, So that I can validate my configuration before it is implemented #### Related Research & Recommendations - [DAST CMS - Viable](https://gitlab.com/gitlab-org/gitlab-design/-/issues/1560) - [Recommendation - Iterate on the configuration UI to add better explanations of the concepts and available options](https://gitlab.com/gitlab-org/gitlab-design/-/issues/1814) - [Recommendation - Refine the DAST documentation to make the basic configuration requirements easier to find and follow](https://gitlab.com/gitlab-org/gitlab-design/-/issues/1815) - [UX Audit: DAST CI/CD configuration UI](https://gitlab.com/gitlab-org/gitlab/-/issues/342739#findings-unique-to-dast-cicd-on-demand) - [UX Audit: DAST on-demand configuration UI](https://gitlab.com/gitlab-org/gitlab/-/issues/342740) - [UX Scorecard: Dynamic analysis configuration](https://gitlab.com/gitlab-org/gitlab-design/-/issues/1702) ## Proposal * [🎨 Design issue and mocks](https://gitlab.com/gitlab-org/gitlab/-/issues/351476) * [:joystick: Design prototype](https://www.figma.com/proto/o6NoqgLnxv0KnK2y9Qum51/DAST-Configuration-UI?page-id=1273%3A76836&node-id=1273%3A82538&viewport=431%2C48%2C1&scaling=min-zoom&starting-point-node-id=1273%3A82538) * [:art: Figma design file](https://www.figma.com/file/o6NoqgLnxv0KnK2y9Qum51/DAST-Configuration-UI?node-id=1273%3A82538) **Summary of changes** - Update the design of the new scan form to align with https://gitlab.com/gitlab-org/gitlab/-/issues/348203 - Set us up for the future by removing the DAST-first approach to configuration - Add UI copy throughout helping to explain the available options and promote learnability for new users. <!-- Use this section to explain the feature and how it will work. It can be helpful to add technical details, design proposals, and links to related epics or issues. --> <!-- triage-serverless v3 PLEASE DO NOT REMOVE THIS SECTION --> *This page may contain information related to upcoming products, features and functionality. It is important to note that the information presented is for informational purposes only, so please do not rely on the information for purchasing or planning purposes. Just like with all projects, the items mentioned on the page are subject to change or delay, and the development, release, and timing of any products, features, or functionality remain at the sole discretion of GitLab Inc.* <!-- triage-serverless v3 PLEASE DO NOT REMOVE THIS SECTION -->
epic