mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
+23









Josema Camacho
César Arroba
Alan Buscaglia
Claude
Andoni Alonso
Rubén De la Torre Vico
HugoPBrito
Hugo Pereira Brito
Pepe Fagoaga
Copilot Autofix powered by AI
Chandrapal Badshah
Chandrapal Badshah
Adrián Peña
Pedro Martín
KonstGolfi
lydiavilchez
Prowler Bot
prowler-bot
StylusFrost
dependabot[bot]
alejandrobailo
Alejandro Bailo
Víctor Fernández Poyatos
bota4go
Daniel Barranquero
Daniel Barranquero
mchennai
Ryan Nolette
Ulissis Correa
Sergio Garcia
Lee Trout
Sergio Garcia
Alan-TheGentleman
032499c29a
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: César Arroba <19954079+cesararroba@users.noreply.github.com> Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com> Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com> Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com> Co-authored-by: HugoPBrito <hugopbrit@gmail.com> Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com> Co-authored-by: Pepe Fagoaga <pepe@prowler.com> Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Co-authored-by: Chandrapal Badshah <Chan9390@users.noreply.github.com> Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com> Co-authored-by: Adrián Peña <adrianjpr@gmail.com> Co-authored-by: Pedro Martín <pedromarting3@gmail.com> Co-authored-by: KonstGolfi <73020281+KonstGolfi@users.noreply.github.com> Co-authored-by: lydiavilchez <114735608+lydiavilchez@users.noreply.github.com> Co-authored-by: Prowler Bot <bot@prowler.com> Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com> Co-authored-by: StylusFrost <43682773+StylusFrost@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com> Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com> Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com> Co-authored-by: bota4go <108249054+bota4go@users.noreply.github.com> Co-authored-by: Daniel Barranquero <74871504+danibarranqueroo@users.noreply.github.com> Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com> Co-authored-by: mchennai <50082780+mchennai@users.noreply.github.com> Co-authored-by: Ryan Nolette <sonofagl1tch@users.noreply.github.com> Co-authored-by: Ulissis Correa <123517149+ulissisc@users.noreply.github.com> Co-authored-by: Sergio Garcia <hello@mistercloudsec.com> Co-authored-by: Lee Trout <ltrout@watchpointlabs.com> Co-authored-by: Sergio Garcia <sergargar1@gmail.com> Co-authored-by: Alan-TheGentleman <alan@thegentleman.dev>
70 lines
1.8 KiB
TypeScript
70 lines
1.8 KiB
TypeScript
"use server";
|
|
|
|
import { z } from "zod";
|
|
|
|
import { apiBaseUrl, getAuthHeaders } from "@/lib";
|
|
import { handleApiResponse } from "@/lib/server-actions-helper";
|
|
import { AttackPathScan, AttackPathScansResponse } from "@/types/attack-paths";
|
|
|
|
import { adaptAttackPathScansResponse } from "./scans.adapter";
|
|
|
|
// Validation schema for UUID - RFC 9562/4122 compliant
|
|
const UUIDSchema = z.uuid();
|
|
|
|
/**
|
|
* Fetch list of attack path scans (latest scan for each provider)
|
|
*/
|
|
export const getAttackPathScans = async (): Promise<
|
|
{ data: AttackPathScan[] } | undefined
|
|
> => {
|
|
const headers = await getAuthHeaders({ contentType: false });
|
|
|
|
try {
|
|
const response = await fetch(`${apiBaseUrl}/attack-paths-scans`, {
|
|
headers,
|
|
method: "GET",
|
|
});
|
|
|
|
const apiResponse = (await handleApiResponse(
|
|
response,
|
|
)) as AttackPathScansResponse;
|
|
const adaptedData = adaptAttackPathScansResponse(apiResponse);
|
|
|
|
return { data: adaptedData.data };
|
|
} catch (error) {
|
|
console.error("Error fetching attack path scans:", error);
|
|
return undefined;
|
|
}
|
|
};
|
|
|
|
/**
|
|
* Fetch detail of a specific attack path scan
|
|
*/
|
|
export const getAttackPathScanDetail = async (
|
|
scanId: string,
|
|
): Promise<{ data: AttackPathScan } | undefined> => {
|
|
// Validate scanId is a valid UUID format to prevent request forgery
|
|
const validatedScanId = UUIDSchema.safeParse(scanId);
|
|
if (!validatedScanId.success) {
|
|
console.error("Invalid scan ID format");
|
|
return undefined;
|
|
}
|
|
|
|
const headers = await getAuthHeaders({ contentType: false });
|
|
|
|
try {
|
|
const response = await fetch(
|
|
`${apiBaseUrl}/attack-paths-scans/${validatedScanId.data}`,
|
|
{
|
|
headers,
|
|
method: "GET",
|
|
},
|
|
);
|
|
|
|
return handleApiResponse(response);
|
|
} catch (error) {
|
|
console.error("Error fetching attack path scan detail:", error);
|
|
return undefined;
|
|
}
|
|
};
|