Skip to content

2460528 Cosmetic bug: Inconsistent Error Response Formatting Across Aviator SSC Operations - #1130

Open
anishkumarnagaraj-design wants to merge 1 commit into
fortify:dev/v3.xfrom
anishkumarnagaraj-design:bug/exception_handling_cosmetic
Open

anishkumarnagaraj-design wants to merge 1 commit into
fortify:dev/v3.xfrom
anishkumarnagaraj-design:bug/exception_handling_cosmetic

Conversation

@anishkumarnagaraj-design

@anishkumarnagaraj-design anishkumarnagaraj-design commented Oct 9, 2026 •

Copy link
Copy Markdown

2460528 Cosmetic bug: Inconsistent Error Response Formatting Across Aviator SSC Operations

Description Some expected failures in Aviator SSC commands printed a raw Java stack trace, while the equivalent SAST and audit failures returned a structured  FAILED  result. This PR makes the DAST audit and correlation commands return a structured failure for these cases. The change also removes technical wording like "webinspect.xml not found in DAST FPR" from user-facing output.

Problem 1. Concurrent operations: Starting  correlate-sast-dast  while an audit was already running for the same Aviator application printed a full stack trace. The reverse order (an audit while a correlation was running) already returned a structured failure.
2. Invalid FPR type: Running  audit-dast  against a SAST FPR printed a stack trace with  webinspect.xml not found in DAST FPR . SAST audit with a DAST FPR already returned a clear validation error.

Changes
•  FprHandle : Added  validateDast() . It throws  AviatorSimpleException  with a clear message when  webinspect.xml  is missing, either "provided file is a SAST scan result" or "does not appear to be a valid DAST scan result".
•  DastAuditFPR ,  WebInspectParser ,  StreamingWebInspectParser : Call  validateDast()  instead of throwing generic RuntimeException  or  AviatorTechnicalException.
•  AviatorSSCDastAuditCommand : Catches  FcliSimpleException  and returns a structured  FAILED  output with the message. It logs the exception at ERROR level and the stack trace at DEBUG level.
•  AviatorSSCCorrelateSastDastCommand :
• Catches  FcliSimpleException  and returns a structured  FAILED  output ( buildFailedOutput ).
• Unwraps  ExecutionException  from the correlation stream ( toCorrelationException ), so the server-provided message such as "audit already running" is shown instead of a wrapper message.

Tests • Added unit tests for  FprHandle.validateDast() ,  DastAuditFPR , both WebInspect parsers, and the failure output of both commands.

@anishkumarnagaraj-design

Copy link
Copy Markdown
Author

Tested locally,
audit dast scan on sast fpr
correlation console message in parallel to audit

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant