Skip to content

Fix: Route authentication logs to Eclipse Error Log (AST-136023)#244

Merged
cx-aniket-shinde merged 3 commits into
integration/eclipse-bug-fixesfrom
bug/AST-136023
Apr 20, 2026
Merged

Fix: Route authentication logs to Eclipse Error Log (AST-136023)#244
cx-aniket-shinde merged 3 commits into
integration/eclipse-bug-fixesfrom
bug/AST-136023

Conversation

@cx-aniket-shinde

Copy link
Copy Markdown
Collaborator

Replace SLF4J log calls in Authenticator.doAuthentication() with CxLogger so auth success/failure messages appear in .metadata/.log and the Eclipse Error Log UI instead of being silently dropped.

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Describe the purpose of this PR along with any background information and the impacts of the proposed change.

References

Include supporting link to GitHub Issue/PR number

Testing

Describe how this change was tested. Be specific about anything not tested and reasons why. If this solution has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

Please include any manual steps for testing end-to-end or functionality not covered by unit/integration tests.

Checklist

  • I have added documentation for new/changed functionality in this PR (if applicable).
  • All active GitHub checks for tests, formatting, and security are passing
  • The correct base branch is being used

Replace SLF4J log calls in Authenticator.doAuthentication() with
CxLogger so auth success/failure messages appear in .metadata/.log
and the Eclipse Error Log UI instead of being silently dropped.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added the bug Something isn't working label Apr 14, 2026
@github-actions

github-actions Bot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Logo
Checkmarx One – Scan Summary & Details99d7e279-76b9-4582-9608-d70e0184697c


New Issues (1) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-24400 Maven-org.assertj:assertj-core-3.27.2
detailsRecommended version: 3.27.7
Description: AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 prior to 3.27.7 and 4.0.0-M1, an ...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package

Replace SLF4J mockLogger verification with MockedStatic<CxLogger>
to match the updated Authenticator.doAuthentication() which now
routes log output through CxLogger instead of the SLF4J instance.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@cx-aniket-shinde cx-aniket-shinde changed the base branch from main to integration/eclipse-bug-fixes April 14, 2026 13:10
…message

Replace string concatenation (AUTH_STATUS + cxValidateOutput) with
String.format(PluginConstants.INFO_AUTHENTICATION_STATUS, cxValidateOutput)
to be consistent with the error logging pattern. Updated the unit test
assertion to verify the formatted string accordingly.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Comment thread checkmarx-ast-eclipse-plugin/src/com/checkmarx/eclipse/runner/Authenticator.java Outdated
@cx-aniket-shinde cx-aniket-shinde merged commit 644dae9 into integration/eclipse-bug-fixes Apr 20, 2026
4 checks passed
cx-nisan-benabu added a commit that referenced this pull request Jun 25, 2026
* docs AST-146800: Add Cloud.md standardization file

Adds the Cloud.md documentation file covering all essential sections:
Project Overview, Architecture, Repository Structure, Technology Stack,
Development Setup, Coding Standards, Project Rules, Testing Strategy,
Known Issues — plus recommended sections: External Integrations,
Deployment, Security & Access, Logging, and Debugging Steps.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* AST-101305: Disable Branch and Scan dropdown when no project is selected

- Add FocusListener to project combo viewer
- When user clears project and clicks outside, branch combo is disabled
- Resets currentProjectId to empty when project field is cleared
- Preserves existing behavior for all other scenarios

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Fix: Route authentication logs to Eclipse Error Log (AST-136023) (#244)

* Fix AST-136023: Route authentication logs to Eclipse Error Log

Replace SLF4J log calls in Authenticator.doAuthentication() with
CxLogger so auth success/failure messages appear in .metadata/.log
and the Eclipse Error Log UI instead of being silently dropped.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix AST-136023: Update unit tests to verify CxLogger static calls

Replace SLF4J mockLogger verification with MockedStatic<CxLogger>
to match the updated Authenticator.doAuthentication() which now
routes log output through CxLogger instead of the SLF4J instance.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Refactor AST-136023: Use String.format for authentication status log message

Replace string concatenation (AUTH_STATUS + cxValidateOutput) with
String.format(PluginConstants.INFO_AUTHENTICATION_STATUS, cxValidateOutput)
to be consistent with the error logging pattern. Updated the unit test
assertion to verify the formatted string accordingly.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix: Clear detail panels on severity filter change (AST-136035) (#245)

* Fix AST-136035: Clear detail panels on severity filter change; fix scan ID combo overflow

- Hide resultViewComposite and attackVectorCompositePanel when filter changes
  so the description and attack vector windows no longer show stale content
- Replace fixed widthHint=520 on scan ID combo with SWT.FILL/grabExcess layout
  so the combo is always visible without needing to maximize the window

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix AST-136035: Clear right panels only when displayed item's severity is filtered out

Previously, toggling any severity filter always hid the description and
attack vector panels. Now the panels are only cleared when the currently
displayed item belongs to a severity that was just disabled. If the item's
severity is still active, the panels stay visible.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix AST-136035: Preserve tree expansion state when severity filter changes

- Capture expanded elements before clearing the model so the snapshot
  is accurate when restoring after refresh
- Pass expand=true for FILTER_CHANGED (keep GET_RESULTS at false) so
  previously expanded group nodes are restored after filtering instead
  of collapsing the entire tree

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix: Truncate long custom state names in filter menu (AST-137779) (#246)

* Fix AST-137779: Truncate long custom state names in filter menu and triage combo

Custom states with very long names caused the state filter dropdown menu
to expand across the entire screen. Fix truncates display text to 50 chars
(with trailing "...") in both the state filter MenuItem and the triage
state ComboViewer LabelProvider. The full state name is still used
internally for filtering and triage submission.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix AST-137779: Guard against null getResults() in cxProjectMatchesWorkspaceProject

Results.getResults() can return null when no results have been loaded yet
(e.g. fresh IDE session before any scan is imported). The prior check only
guarded against a null Results object, causing an NPE on the first click
of the Start Scan button and preventing scans from running.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Toolyip custom state

* Parity and project combobox

* CISO-920: remove broken Teams notify job (secret CXONE_SCAN_WEBHOOK_URL not set) (#250)

The notify job references secrets.CXONE_SCAN_WEBHOOK_URL which does not
exist in this repo or at org level, causing the step to fail silently.

Ref: https://checkmarx.atlassian.net/browse/CISO-920
Ref: https://checkmarx.atlassian.net/browse/CISO-815

* [StepSecurity] Apply security best practices (#251)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>

* [StepSecurity] Apply security best practices (#252)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>

* remove dependabot (#254)

* rerun

* Bumped java wrapper version

* bump java wrapper version to 2.4.24

---------

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Noam Brendel <139764378+cx-noam-brendel@users.noreply.github.com>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Co-authored-by: Alon Rosenhek <80337069+cx-alon-rosenhek@users.noreply.github.com>
Co-authored-by: Nisan Ben Abu <nisan.ben-abu@checkmarx.com>
Co-authored-by: atishj99 <atish.jadhav@checkmarx.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants