Skip to content

feat: show cleared high-cost approvals and record budget-skipped scheduled runs - #1247

Merged
crypt0rr merged 1 commit into
mainfrom
feat/high-cost-approval-visibility
Oct 7, 2026
Merged

crypt0rr merged 1 commit into
mainfrom
feat/high-cost-approval-visibility

Conversation

@crypt0rr

@crypt0rr crypt0rr commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Summary

Makes high-cost approval and probe-budget refusals visible (#1223). Before this change an operator's scope edit could silently clear an administrator's approval, and from then on every scheduled run was refused before a scan record existed, with nothing in history, Activity or notifications.

Approval cleared on a scope change

  • Clearing the approval on a scope change stays as designed ([P2] Reapprove high-cost scans when an operator expands approved scope #523). What changes is that people are told:
    • The scope-change confirmation (409 rebaseline_confirmation_required, details.changes) now includes "high-cost approval: cleared; an administrator must approve the new scope again". It adds whether the new scope exceeds the probe budget, with the estimate and limit, or that it fits without the approval.
    • The 200 save response carries high_cost_approval_cleared: true.
    • The editor tells an operator editing an approved job that changing targets, ports or scanner clears the approval.

Budget state on the job

  • GET, create and update responses for a job now include scan_budget:
    • exceeded
    • estimated_probes and limit
    • approval_would_fit: whether an administrator's approval would let the job run.
  • The job page shows a warning when scheduled scans are skipped. An approval can fix that ("…until an administrator approves high-cost scans") unless the job exceeds the hard ceiling ("…until its scope is reduced").
  • The page header notes "High-cost scans approved".

Scheduled budget skips are recorded

  • A scheduled run that its probe budget stops before a scan record exists now records a scan-budget-exceeded event. It goes into the outbox for the job's destinations, is published live, and appears in Activity as Scheduled scan skipped in the warning tone.
  • Deduplication: a BudgetSkipAlertKey (scope hash and budget) in the job's runtime state stops an hourly job from alerting every hour.
    • The key is stored in the job's runtime state JSON, so there is no schema change.
    • Any finalized scan of the job clears it, and a scope or budget change produces a new key.
  • If the destinations cannot be resolved, nothing is recorded, as the silence watchdog does, and the next scheduled run tries again.
  • Manual Scan now keeps its existing visible 422.

Docs: the scanning guide covers budget refusals, the job-page warning and approval clearing; the notifications guide lists the new alert.

Compatibility

  • Additive:
    • scan_budget and high_cost_approval_cleared in job responses;
    • a new entry in the confirmation's changes list;
    • a new scan-budget-exceeded event type and notification.
  • There are no schema changes.

Validation

  • gofmt, go vet ./...
  • go test -race for internal/app, internal/engine, internal/model and internal/web.
  • npm run lint
  • Vitest: 45 files passed. One footprint test timed out once under local load and passes on its own.
  • npm --prefix docs run build

New tests:

  • internal/app/budget_skip_test.go: a scheduled over-budget run records one delivered and published event; a repeat records nothing; after a scan runs, the next skip is reported again.
  • internal/web/high_cost_visibility_test.go:
    • an approved job's budget fits;
    • an operator's scope edit gets the cleared approval, with the budget overrun, in the 409;
    • the confirmed save reports high_cost_approval_cleared and scan_budget with approval_would_fit;
    • a routine edit reports nothing.
  • Console: the job-page warning in both variants and the approved note; the editor hint; the Activity label and tone; the stream invalidation.

Fixes #1223

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Deploying edgewatch with  Cloudflare Pages  Cloudflare Pages

Latest commit: de7749a
Status: ✅  Deploy successful!
Preview URL: https://ad00d34f.edgewatch-cpd.pages.dev
Branch Preview URL: https://feat-high-cost-approval-visi.edgewatch-cpd.pages.dev

View logs

@crypt0rr
crypt0rr force-pushed the feat/high-cost-approval-visibility branch 2 times, most recently from 2d21209 to 21b2677 Compare October 7, 2026 17:01
…duled runs

- An operator's scope edit on an approved job lists the cleared
  high-cost approval in the scope-change confirmation, with whether the
  new scope exceeds the probe budget, and the save response reports
  high_cost_approval_cleared.
- Job responses include scan_budget: whether the estimated work exceeds
  the unit's probe budget and whether a high-cost approval would let it
  run. The job page warns when scheduled scans are skipped for it.
- A scheduled run that its probe budget stops before it starts records a
  scan-budget-exceeded event, delivered to the job's destinations and
  shown in Activity as Scheduled scan skipped. It is reported once per
  scope and budget, and again after a scan of the job has run.

Fixes #1223
@crypt0rr
crypt0rr force-pushed the feat/high-cost-approval-visibility branch from 21b2677 to de7749a Compare October 7, 2026 17:13
@crypt0rr
crypt0rr merged commit bfb88ba into main Oct 7, 2026
15 checks passed
@crypt0rr
crypt0rr deleted the feat/high-cost-approval-visibility branch October 7, 2026 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P2] An operator scope edit silently clears high-cost approval, and scheduled runs then fail without a trace

1 participant