jenkinsci / jenkinsci/script-security-plugin

[JENKINS-45976] In-process Script Approval provides no interface/indication of approved Pipeline scripts

Open
#754 0 comments 0 reactions 0 assignees View on GitHub
component:script-security-plugin imported-jira-issue priority:minor resolution:unresolved
Dominant language
Java
Stars
76
Forks
181
Avg merge
14h 55m
Merged PRs (30d)
3

Description

Currently the "In-process Script Approval" view provides no information about approved scripts or that there have even been any scripts whatsoever approved.

In the attached screenshots, there is one configured script from a non-administrative user (approving-unsandboxed-script.png which contains a good bit of useful information. Once the script is "Approve"d however, the administrator loses insight into all information pertaining to what scripts have previously been approved.

I also noticed that the text highlighted in after-approving-unsandboxed-script.png is the exact same in a fresh instance (no script approvals) vs. an instance with approvals. Providing even a slight modification to say "You can also remove all $X previous script approvals [Clear Approvals]" would be an improvement.

---
Originally reported by rtyler, imported from: In-process Script Approval provides no interface/indication of approved Pipeline scripts


  • status: Open
  • priority: Minor
  • component(s): script-security-plugin
  • resolution: Unresolved
  • votes: 0
  • watchers: 2
  • imported: 2025-12-09

Raw content of original issue

Currently the "In-process Script Approval" view provides no information about approved scripts or that there have even been any scripts whatsoever approved.

In the attached screenshots, there is one configured script from a non-administrative user (approving-unsandboxed-script.png which contains a good bit of useful information. Once the script is "Approve"d however, the administrator loses insight into all information pertaining to what scripts have previously been approved.

I also noticed that the text highlighted in after-approving-unsandboxed-script.png is the exact same in a fresh instance (no script approvals) vs. an instance with approvals. Providing even a slight modification to say "You can also remove all $X previous script approvals [Clear Approvals]" would be an improvement.

2 attachments

- [after-approving-unsandboxed-script.png](https://issues.jenkins.io/secure/attachment/39139/after-approving-unsandboxed-script.png)
> ![after-approving-unsandboxed-script.png](https://issues.jenkins.io/secure/attachment/39139/after-approving-unsandboxed-script.png)
- [approving-unsandboxed-script.png](https://issues.jenkins.io/secure/attachment/39138/approving-unsandboxed-script.png)
> ![approving-unsandboxed-script.png](https://issues.jenkins.io/secure/attachment/39138/approving-unsandboxed-script.png)

Contributor guide

Open the contributing guide

Research direction

Start at the In-process Script Approval view described in the issue and compare its empty and post-approval states using the two referenced screenshots. Trace where approved scripts are represented, then verify that administrators can see an indication of existing approvals and a way to clear them.

Written by the indexing model from the issue text.

Assessment

Tech stack
groovy, java
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.