mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-07-24 04:51:51 +00:00
032499c29a
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: César Arroba <19954079+cesararroba@users.noreply.github.com> Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com> Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com> Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com> Co-authored-by: HugoPBrito <hugopbrit@gmail.com> Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com> Co-authored-by: Pepe Fagoaga <pepe@prowler.com> Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Co-authored-by: Chandrapal Badshah <Chan9390@users.noreply.github.com> Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com> Co-authored-by: Adrián Peña <adrianjpr@gmail.com> Co-authored-by: Pedro Martín <pedromarting3@gmail.com> Co-authored-by: KonstGolfi <73020281+KonstGolfi@users.noreply.github.com> Co-authored-by: lydiavilchez <114735608+lydiavilchez@users.noreply.github.com> Co-authored-by: Prowler Bot <bot@prowler.com> Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com> Co-authored-by: StylusFrost <43682773+StylusFrost@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com> Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com> Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com> Co-authored-by: bota4go <108249054+bota4go@users.noreply.github.com> Co-authored-by: Daniel Barranquero <74871504+danibarranqueroo@users.noreply.github.com> Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com> Co-authored-by: mchennai <50082780+mchennai@users.noreply.github.com> Co-authored-by: Ryan Nolette <sonofagl1tch@users.noreply.github.com> Co-authored-by: Ulissis Correa <123517149+ulissisc@users.noreply.github.com> Co-authored-by: Sergio Garcia <hello@mistercloudsec.com> Co-authored-by: Lee Trout <ltrout@watchpointlabs.com> Co-authored-by: Sergio Garcia <sergargar1@gmail.com> Co-authored-by: Alan-TheGentleman <alan@thegentleman.dev>
98 lines
2.5 KiB
TypeScript
98 lines
2.5 KiB
TypeScript
"use server";
|
|
|
|
import { z } from "zod";
|
|
|
|
import { apiBaseUrl, getAuthHeaders } from "@/lib";
|
|
import { handleApiResponse } from "@/lib/server-actions-helper";
|
|
import {
|
|
AttackPathQueriesResponse,
|
|
AttackPathQuery,
|
|
AttackPathQueryResult,
|
|
ExecuteQueryRequest,
|
|
} from "@/types/attack-paths";
|
|
|
|
import { adaptAttackPathQueriesResponse } from "./queries.adapter";
|
|
|
|
// Validation schema for UUID - RFC 9562/4122 compliant
|
|
const UUIDSchema = z.uuid();
|
|
|
|
/**
|
|
* Fetch available queries for a specific attack path scan
|
|
*/
|
|
export const getAvailableQueries = async (
|
|
scanId: string,
|
|
): Promise<{ data: AttackPathQuery[] } | undefined> => {
|
|
// Validate scanId is a valid UUID format to prevent request forgery
|
|
const validatedScanId = UUIDSchema.safeParse(scanId);
|
|
if (!validatedScanId.success) {
|
|
console.error("Invalid scan ID format");
|
|
return undefined;
|
|
}
|
|
|
|
const headers = await getAuthHeaders({ contentType: false });
|
|
|
|
try {
|
|
const response = await fetch(
|
|
`${apiBaseUrl}/attack-paths-scans/${validatedScanId.data}/queries`,
|
|
{
|
|
headers,
|
|
method: "GET",
|
|
},
|
|
);
|
|
|
|
const apiResponse = (await handleApiResponse(
|
|
response,
|
|
)) as AttackPathQueriesResponse;
|
|
const adaptedData = adaptAttackPathQueriesResponse(apiResponse);
|
|
|
|
return { data: adaptedData.data };
|
|
} catch (error) {
|
|
console.error("Error fetching available queries for scan:", error);
|
|
return undefined;
|
|
}
|
|
};
|
|
|
|
/**
|
|
* Execute a query on an attack path scan
|
|
*/
|
|
export const executeQuery = async (
|
|
scanId: string,
|
|
queryId: string,
|
|
parameters?: Record<string, string | number | boolean>,
|
|
): Promise<AttackPathQueryResult | undefined> => {
|
|
// Validate scanId is a valid UUID format to prevent request forgery
|
|
const validatedScanId = UUIDSchema.safeParse(scanId);
|
|
if (!validatedScanId.success) {
|
|
console.error("Invalid scan ID format");
|
|
return undefined;
|
|
}
|
|
|
|
const headers = await getAuthHeaders({ contentType: true });
|
|
|
|
const requestBody: ExecuteQueryRequest = {
|
|
data: {
|
|
type: "attack-paths-query-run-requests",
|
|
attributes: {
|
|
id: queryId,
|
|
...(parameters && { parameters }),
|
|
},
|
|
},
|
|
};
|
|
|
|
try {
|
|
const response = await fetch(
|
|
`${apiBaseUrl}/attack-paths-scans/${validatedScanId.data}/queries/run`,
|
|
{
|
|
headers,
|
|
method: "POST",
|
|
body: JSON.stringify(requestBody),
|
|
},
|
|
);
|
|
|
|
return handleApiResponse(response);
|
|
} catch (error) {
|
|
console.error("Error executing query on scan:", error);
|
|
return undefined;
|
|
}
|
|
};
|