Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Integration][Snyk] - Validation to Prevent Fetching Non Existent Users #1098

Merged

Conversation

PeyGis
Copy link
Contributor

@PeyGis PeyGis commented Oct 24, 2024

Description

What - Customers had the impression that the integration was bringing data from other organizations that were not specified during the installation process. The particular cause of concern was the Snyk API that enriches the project data with the importer and owner details. It is possible that an importer or the owner of the Snyk project have left the organization. In this instance, when we query the API, we will get 404, which is expected. But the fact that the customer sees an API call to the owners new organization makes it appear that the integration is pulling data from other org.

Why -

How - Added validation to prevent the integration from making attempts to fetch users from other organisation instead of the ones provided to the integration

Type of change

Please leave one option from the following and delete the rest:

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • New Integration (non-breaking change which adds a new integration)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Non-breaking change (fix of existing functionality that will not change current behavior)
  • Documentation (added/updated documentation)

All tests should be run against the port production environment(using a testing org).

Core testing checklist

  • Integration able to create all default resources from scratch
  • Resync finishes successfully
  • Resync able to create entities
  • Resync able to update entities
  • Resync able to detect and delete entities
  • Scheduled resync able to abort existing resync and start a new one
  • Tested with at least 2 integrations from scratch
  • Tested with Kafka and Polling event listeners
  • Tested deletion of entities that don't pass the selector

Integration testing checklist

  • Integration able to create all default resources from scratch
  • Resync able to create entities
  • Resync able to update entities
  • Resync able to detect and delete entities
  • Resync finishes successfully
  • If new resource kind is added or updated in the integration, add example raw data, mapping and expected result to the examples folder in the integration directory.
  • If resource kind is updated, run the integration with the example data and check if the expected result is achieved
  • If new resource kind is added or updated, validate that live-events for that resource are working as expected
  • Docs PR link here

Preflight checklist

  • Handled rate limiting
  • Handled pagination
  • Implemented the code in async
  • Support Multi account

Screenshots

Include screenshots from your environment showing how the resources of the integration will look.

API Documentation

Provide links to the API documentation used for this integration.

@PeyGis PeyGis requested a review from a team as a code owner October 24, 2024 17:29
@github-actions github-actions bot added size/S and removed size/M labels Oct 24, 2024
Copy link
Contributor

@Tankilevitch Tankilevitch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lets add a test for that

integrations/snyk/snyk/client.py Outdated Show resolved Hide resolved
PeyGis and others added 3 commits October 29, 2024 11:36
- Includes tests for handling `None` user references, users from non-configured organizations, and cached user details.
- Adds test coverage for successful user detail retrieval, 404 error handling, non-404 error handling, and empty API responses.
@github-actions github-actions bot added size/L and removed size/S labels Nov 26, 2024
PeyGis and others added 10 commits November 26, 2024 14:12
…g-org' of https://github.com/port-labs/ocean into PORT-10933-bug-snyk-ingesting-vulnerabilities-from-wrong-org
- Updated `mock_ocean_context` fixture to simplify initialization.
- Converted `snyk_client` and `mock_event_context` fixtures to async generators.
…g-org' of https://github.com/port-labs/ocean into PORT-10933-bug-snyk-ingesting-vulnerabilities-from-wrong-org
- Simplified type annotations and variable declarations.
- Update fixture and test method signatures.
- Use `patch.object()` for more precise mocking.
- Simplify async context management.
@PeyGis PeyGis merged commit 84db27c into main Nov 27, 2024
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants