OWASP / threat-dragon

An open source threat modeling tool from OWASP
https://owasp.org/www-project-threat-dragon/
Apache License 2.0
902 stars 244 forks source link

Github models within a repo are inaccessible #538

Closed jgadsden closed 1 year ago

jgadsden commented 2 years ago

Describe the bug @Ziconius has identified a problem where some threat models are not shown in the web application, and so can not be accessed.

Expected behaviour When browsing a repo for threat models, all models in the directory tree should be visible and accessible

Environment

To Reproduce

Any additional context, screenshots, etc This is happening because the repo did not have any subdirectories, the threat models were in the top directory only. See this repo, and only the models under directory ThreatDragonModels are accessible / visible

jgadsden commented 1 year ago

Not sure if this is fixed by #632 or not

jgadsden commented 1 year ago

This is a false positive, the models must be under directory ThreatDragonModels and then they also must be under a subdirectory with a matching name. Just the way Threat Dragon does it

jgadsden commented 1 year ago

reopen this as a documentation issue documented here

directory