Skip to content

Backlog/v11 compilance report export - #2863

Open
AlexSanchez-bit wants to merge 2 commits into
v11from
backlog/v11_compilance_report_export
Open

AlexSanchez-bit wants to merge 2 commits into
v11from
backlog/v11_compilance_report_export

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit
AlexSanchez-bit requested a review from a team October 9, 2026 01:43
@AlexSanchez-bit AlexSanchez-bit linked an issue Oct 9, 2026 that may be closed by this pull request
2 of 3 tasks
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

❌ Go dependencies check failed

There are outdated Go dependencies, or modules that could not be inspected.
Run bash .github/scripts/go-deps.sh --update --discover locally and
commit the updated go.mod / go.sum files.

Script output
🔍 Discovered 25 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - google.golang.org/api: v0.299.0 → v0.301.0

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2: v1.47.0 → v1.47.2
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.8
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.8
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.2

  📁 ./plugins/alerts:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./plugins/events:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./plugins/modules-config:
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.8
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.8
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.2
     - github.com/aws/aws-sdk-go-v2/service/sts: v1.51.0 → v1.51.3
     - github.com/crowdstrike/gofalcon: v0.22.0 → v0.23.0
     - google.golang.org/api: v0.299.0 → v0.301.0

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.3
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2

  📁 ./plugins/crowdstrike:
     - github.com/crowdstrike/gofalcon: v0.22.0 → v0.23.0

  📁 ./plugins/geolocation:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./agent:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8

�[0;31m❌ Please update dependencies before merging.�[0m

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🛑 AI review — Blocking issues

One or more high/critical issues can break things and must be fixed before merging. Details below.

⚠️ architecture (silas-1.7-pro) — non-blocking warnings

Summary: Tier 2: frontend PDF export changes introduce parent-child ViewChild coupling, lifecycle changes, and shared print service side effects.

  • medium frontend/src/app/compliance/compliance-report-viewer/compliance-report-viewer.component.ts:154 — Parent reaches into child via ViewChild and calls exportToPdf(), creating tight component coupling. Prefer a child event, input, or shared service for PDF export.
  • medium frontend/src/app/compliance/compliance-report-viewer/compliance-report-viewer.component.html:81 — Replacing *ngIf with [hidden] changes component lifecycle by always initializing app-compliance-result-view. Keep conditional rendering or use a lazy route if the view should not exist in other modes.
  • low frontend/src/app/compliance/compliance-report-viewer/compliance-report-viewer.component.ts:186 — Removing encodeURIComponent from the print-view URL can break routing when section contains reserved characters. Centralize URL construction and encode parameters explicitly.
  • low frontend/src/app/shared/services/util/export-pdf.service.ts:28 — Shared PDF handler now injects a hidden iframe and invokes print() for all consumers, adding DOM side effects to a generic service. Keep print behavior explicit or isolate it in a dedicated report/export component.

🛑 bugs (silas-1.7-pro) — blocking — must fix before merge

Summary: PDF export changes introduce state/count bugs in the print view, iframe/blob cleanup issues, and hidden component side effects.

  • high frontend/src/app/compliance/compliance-reports-view/components/compliance-print-view/compliance-print-view.component.ts:57 — visualizationCount is calculated as the total length of each report's visualization value, but the template renders one visualization component per report with [visualizationRender]='[report.visualization]'. If report.visualization is a string/object or the component emits once per report, loadedCount will never reach visualizationCount, leaving preparingPrint true. Reproduce by loading a report whose visualization is a non-empty JSON string or object.
  • high frontend/src/app/compliance/compliance-reports-view/components/compliance-print-view/compliance-print-view.component.ts:81 — loadedCount is never reset when the reports observable emits again. After a first successful load, a subsequent refresh or filter change can start with a stale loadedCount, causing preparingPrint to clear too early once a new visualization emits. Reproduce by loading the print view, letting charts load, then re-triggering the reports fetch and exporting before all charts have loaded again.
  • high frontend/src/app/compliance/compliance-reports-view/components/compliance-print-view/compliance-print-view.component.ts:82 — preparingPrint is only cleared when loadedCount reaches visualizationCount, with no error or timeout path. If one visualization fails to emit visualizationLoaded, the print preparation state remains true indefinitely. Reproduce by making one visualization request fail in a multi-visualization report.
  • medium frontend/src/app/compliance/compliance-report-viewer/compliance-report-viewer.component.html:81 — Changing the result view from *ngIf to [hidden] causes ComplianceResultViewComponent to be instantiated for actions other than 'reports'. If that component performs route/API work in ngOnInit, hidden instances can trigger unnecessary network calls or side effects. Reproduce by opening the viewer in the compliance action and observing the result-view component initialization or requests.
  • medium frontend/src/app/compliance/compliance-report-viewer/compliance-report-viewer.component.ts:156 — For action=='reports', exportToPdf calls this.compilanceRep.exportToPdf() without setting this.pdfExport or otherwise coordinating completion, so the top Save to PDF button does not show Generating and can be clicked repeatedly. It also dereferences compilanceRep without a null check in case the child view is unavailable. Reproduce by clicking the top Save to PDF button multiple times in reports mode.
  • medium frontend/src/app/shared/services/util/export-pdf.service.ts:27 — The blob URL created by window.URL.createObjectURL is never revoked after printing. Repeated PDF exports will accumulate unreleased object URLs. Add window.URL.revokeObjectURL(url) after the iframe has been removed.
  • low frontend/src/app/shared/services/util/export-pdf.service.ts:51 — The iframe is removed after a fixed 1000 ms after invoking print. On slow systems or if print processing takes longer, this may remove the iframe too early; if iframe.onload never fires, the iframe is also never cleaned up. Prefer afterprint, a user action callback, or a fallback cleanup with blob URL revocation.

⚠️ security (silas-1.7-pro) — non-blocking warnings

Summary: Low-risk unencoded section in PDF export URL may allow query-parameter injection; encode section with encodeURIComponent.

  • low frontend/src/app/compliance/compliance-report-viewer/compliance-report-viewer.component.ts:186 — The section value is concatenated into the export URL without encoding, which can allow query-parameter or URL-shape injection if section is client-controllable. Encode it individually, e.g. '/compliance/print-view?section=' + encodeURIComponent(section).

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — Go dependencies check failed (see above).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ad missing pdf report compilance exportation

1 participant