Skip to content

feat(security): Exposed Services (port-drift) scans UI - #78

Merged
ralyodio merged 1 commit into
masterfrom
scans-ui
Jul 5, 2026
Merged

ralyodio merged 1 commit into
masterfrom
scans-ui

Conversation

@ralyodio

@ralyodio ralyodio commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

Makes the §12 scans feature visible in the app — a new per-project Security tab.

What you'll see

  • New Security tab in the project tab nav (after Stats).
  • Exposed Services page: explanation, Run scan button, an open findings list (severity-tagged host:port (service)), and a recent scans history table.
  • Empty states when there's no data yet.

Wiring

  • requestPortScan server action queues a port_scans row (status queued) for the off-Railway prober to pick up — RLS ensures the caller owns the project.
  • New tables port_scans + port_findings with owner-scoped RLS (mirrors project_repos).
  • The page degrades gracefully if the migration isn't applied yet (queries fall back to empty), so the tab renders immediately on deploy — findings light up once the migration is applied and the prober runs.

Still to come (not in this PR)

  • The actual prober app (prober/) that consumes queued scans and writes findings — that's the BullMQ/droplet work from the earlier PRs.
  • Applying the migration in prod (per repo convention, via psql over the pooler).
  • Baseline-confirmation flow + ack/mute finding actions (PRD §12.4).

npm run typecheck passes.

🤖 Generated with Claude Code

Adds a per-project Security tab (§12) in the app UI: open-findings list,
recent-scan history, and a 'Run scan' button that queues a port_scans row for
the prober to pick up. New port_scans/port_findings tables (owner-scoped RLS).
Page degrades to empty states if the migration isn't applied yet, so the tab
renders immediately on deploy.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 5, 2026

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 1608b94 into master Jul 5, 2026
8 checks passed
@ralyodio
ralyodio deleted the scans-ui branch July 5, 2026 17:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant