jenkinsci / jenkinsci/lacework-security-scanner-plugin

Does the lacework plugin (Reports) Supports encoded URL from jenkins

Open
#5 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
3
Forks
2
PR merge metrics
No merged PRs in 30d

Description

Hi,

So we're trialing lacework reports via jenkins plugin and we've configured all the needed things etc. but we're currently having issues viewing the reports through Jenkins, and it's giving a `404` error in the IFrame, digging further the resource URL in jenkins (when secured) is encoded.

see https://www.jenkins.io/doc/book/security/user-content/#authenticity

Cheers

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the 404 when viewing a Lacework report through the Jenkins plugin with secured user content enabled. Inspect how the plugin constructs the report resource URL for the iframe; done means encoded Jenkins URLs load the report successfully instead of returning 404.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.