Skip to content

show social provider label in groups#14457

Open
fopina wants to merge 1 commit intoDefectDojo:devfrom
fopina:feat/show-group-social-provider
Open

show social provider label in groups#14457
fopina wants to merge 1 commit intoDefectDojo:devfrom
fopina:feat/show-group-social-provider

Conversation

@fopina
Copy link
Contributor

@fopina fopina commented Mar 6, 2026

Description

When groups are synchronized with a social provider (that supports it), group.social_provider is set.
There is no way to set it manually nor any other scenario that sets it.
There's no visual indiciation in the UI of a group that was created (and is maitained) by a social provider integration and a group that was created manually (exists only in Dojo / local).

This is missed as social groups should not be modified as (most) changes will be overwritten and it's good to be able to spot them besides the name prefix of the configuration.

Test results

  • Logged in with a social provider to populate groups
  • Logged in as admin and created a group (via UI)
  • Check list of groups: verify provider groups have a label with its name and local group has no label
  • Check details of group with and without provider: verify same as previous step

@fopina fopina requested review from Maffooch and mtesauro as code owners March 6, 2026 14:28
@github-actions github-actions bot added the ui label Mar 6, 2026
@dryrunsecurity
Copy link

dryrunsecurity bot commented Mar 6, 2026

DryRun Security

🔴 Risk threshold exceeded.

This pull request modifies sensitive template files (dojo/templates/dojo/groups.html and dojo/templates/dojo/view_group.html); the scanner flags these as sensitive edits and notes that allowed paths/authors can be configured in .dryrunsecurity.yaml. Review these changes carefully to ensure they are intended and comply with your repository's security policies.

🔴 Configured Codepaths Edit in dojo/templates/dojo/groups.html (drs_42fd8861)
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.
🔴 Configured Codepaths Edit in dojo/templates/dojo/view_group.html (drs_aa8e483a)
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.

We've notified @mtesauro.


Comment to provide feedback on these findings.

Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]

Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing

All finding details can be found in the DryRun Security Dashboard.

@valentijnscholten valentijnscholten added this to the 2.57.0 milestone Mar 6, 2026
@fopina
Copy link
Contributor Author

fopina commented Mar 7, 2026

Btw I've added this as a label rather than a new column/form field as I guess it's not very meaningful for most people (as it wasn't asked before), so it doesn't take any visual space if social groups are not used

@Maffooch Maffooch requested review from blakeaowens and dogboat March 9, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants