jenkinsci / jenkinsci/script-security-plugin
[JENKINS-45976] In-process Script Approval provides no interface/indication of approved Pipeline scripts
- Dominant language
- Java
- Stars
- 76
- Forks
- 181
- Avg merge
- 14h 55m
- Merged PRs (30d)
- 3
Description
Currently the "In-process Script Approval" view provides no information about approved scripts or that there have even been any scripts whatsoever approved.
In the attached screenshots, there is one configured script from a non-administrative user (approving-unsandboxed-script.png which contains a good bit of useful information. Once the script is "Approve"d however, the administrator loses insight into all information pertaining to what scripts have previously been approved.
I also noticed that the text highlighted in after-approving-unsandboxed-script.png is the exact same in a fresh instance (no script approvals) vs. an instance with approvals. Providing even a slight modification to say "You can also remove all $X previous script approvals [Clear Approvals]" would be an improvement.
---
Originally reported by
rtyler, imported from: In-process Script Approval provides no interface/indication of approved Pipeline scripts
Raw content of original issue
Currently the "In-process Script Approval" view provides no information about approved scripts or that there have even been any scripts whatsoever approved.
In the attached screenshots, there is one configured script from a non-administrative user (approving-unsandboxed-script.png which contains a good bit of useful information. Once the script is "Approve"d however, the administrator loses insight into all information pertaining to what scripts have previously been approved.
I also noticed that the text highlighted in after-approving-unsandboxed-script.png is the exact same in a fresh instance (no script approvals) vs. an instance with approvals. Providing even a slight modification to say "You can also remove all $X previous script approvals [Clear Approvals]" would be an improvement.
2 attachments
- [after-approving-unsandboxed-script.png](https://issues.jenkins.io/secure/attachment/39139/after-approving-unsandboxed-script.png)
> 
- [approving-unsandboxed-script.png](https://issues.jenkins.io/secure/attachment/39138/approving-unsandboxed-script.png)
> 
Contributor guide
Research direction
Start at the In-process Script Approval view described in the issue and compare its empty and post-approval states using the two referenced screenshots. Trace where approved scripts are represented, then verify that administrators can see an indication of existing approvals and a way to clear them.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- groovy, java
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100