Skip to content

Backlog/v12 dashboard filters - #2804

Merged
AlexSanchez-bit merged 3 commits into
release/v12.0.0from
backlog/v12_dashboard_filters
Sep 30, 2026
Merged

AlexSanchez-bit merged 3 commits into
release/v12.0.0from
backlog/v12_dashboard_filters

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit AlexSanchez-bit linked an issue Sep 30, 2026 that may be closed by this pull request
2 of 3 tasks
@github-actions

Copy link
Copy Markdown

🛑 AI review — Sensitive area, extra care recommended

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. Review carefully before merging.

🛑 architecture (silas-1.7-pro) — high/critical — please review

Summary: Tier 3: new dashboard_filter table/endpoints lack tenant scoping, legacy filter backfill, and use visualization audit; requires senior review.

  • high backend/database/migrations.go:68 — Adds DashboardFilter GORM model, creating a new persisted table via auto-migration. Provide an explicit production-safe migration with rollback/roll-forward and backfill plan.
  • high backend/modules/dashboards/usecase/dashboard_filter.go:22 — Create ignores the authenticated user/tenant and never sets TenantID, while List/Update/Delete do not enforce tenant ownership. Resolve tenant from context and scope all repository queries by tenant_id.
  • high backend/modules/dashboards/repository/dashboard_filters.pg.go:37 — List, FindByID, and Delete query dashboard_filter without tenant_id, allowing cross-tenant reads/deletes if dashboard IDs are not globally unique. Add tenant scoping to repository interfaces and queries.
  • high frontend/src/features/dashboard/pages/DashboardPage.tsx:135 — UI now reads chips only from the new dashboard_filter table and ignores existing dashboard.filters JSON. Add a data migration/backfill or fallback so deployed dashboards do not lose filters.
  • medium backend/modules/dashboards/handler/dashboard_filter.go:135 — Delete records visualization.delete and VISUALIZATION_DELETE_* audit events instead of the new dashboard_filter delete events. Use DASHBOARD_FILTER_DELETE_ATTEMPT/SUCCESS and correct resource type.
  • medium frontend/src/features/dashboard/pages/DashboardPage.tsx:336 — handleSaveFilters performs sequential create/update/delete calls with no server-side transaction, so partial failures can leave inconsistent filter state. Add a bulk sync endpoint or compensating logic.
  • low backend/modules/dashboards/handler/dashboard_filter.go:37 — Handlers bind domain.DashboardFilter directly as the HTTP request body, coupling the API contract to the persistence model. Use dedicated DTOs for create/update input.

🛑 bugs (silas-1.7-pro) — high/critical — please review

Summary: Delete handler logs visualization audit events (copy-paste bug); Create usecase never sets TenantID so all inserts fail on the NOT NULL constraint.

  • high backend/modules/dashboards/handler/dashboard_filter.go:130 — Delete handler records audit events for the wrong resource. It uses Action "visualization.delete", ResourceType "visualization", and VISUALIZATION_DELETE_ATTEMPT/SUCCESS instead of the dashboard-filter equivalents (DASHBOARD_FILTER_DELETE_ATTEMPT/SUCCESS, Action "dashboard_filter.delete", ResourceType "dashboard_filter"). This is a copy-paste residue from the visualization handler and will corrupt the audit trail. Reproduce: DELETE /dashboards/filters/:id and inspect the audit log — the event will be tagged as a visualization deletion.
  • high backend/modules/dashboards/usecase/dashboard_filter.go:30 — Create never sets v.TenantID. The field is tagged json:"-" so it is always uuid.Nil after JSON binding, and the column has a NOT NULL constraint. Every POST /dashboards/filters will fail with a database error. The usecase must derive the tenant from the authenticated user (e.g. via the context or the user parameter) and assign it before calling repo.Save. Reproduce: call the Create endpoint with a valid body — the insert will be rejected by the database.
  • low frontend/src/shared/i18n/locales/fr.json:555 — Missing accents in French user-facing strings: "Echec" should be "Échec" and "creation" should be "création" in filterCreateFailed. Affects the toast shown when filter creation fails.
  • low frontend/src/shared/i18n/locales/fr.json:556 — Missing accents in French user-facing string: "Echec" should be "Échec" and "mise a jour" should be "mise à jour" in filterUpdateFailed. Affects the toast shown when filter update fails.
  • low frontend/src/shared/i18n/locales/fr.json:557 — Missing accent in French user-facing string: "Echec" should be "Échec" in filterDeleteFailed. Affects the toast shown when filter deletion fails.

🛑 security (silas-1.7-pro) — high/critical — please review

Summary: Dashboard filter endpoints lack tenant scoping and set no tenant on create, enabling cross-tenant read/update/delete; audit delete event is wrong.

  • high backend/modules/dashboards/usecase/dashboard_filter.go:33 — Create saves the filter without setting TenantID from the authenticated request context and ignores the user parameter. Filters can be inserted with a zero tenant and for arbitrary dashboard IDs. Set TenantID from context and verify the target dashboard belongs to that tenant before saving.
  • high backend/modules/dashboards/repository/dashboard_filters.pg.go:38 — List does not filter by tenant_id. Any authenticated user with dashboards.read can enumerate dashboard filters across tenants when dashboardId is omitted or guessed. Add a tenant_id predicate sourced from the request context.
  • high backend/modules/dashboards/repository/dashboard_filters.pg.go:27 — FindByID retrieves a filter by ID only, with no tenant check. This is used by Update and Delete, allowing cross-tenant read/update/delete of dashboard filters. Include tenant_id in the query and reject records that do not match the caller's tenant.
  • low backend/modules/dashboards/handler/dashboard_filter.go:135 — Delete records the audit event as visualization.delete with visualization event types instead of a dashboard_filter delete action. This corrupts the audit trail. Use dashboard_filter.delete and DASHBOARD_FILTER_DELETE_ATTEMPT/SUCCESS.
  • low backend/modules/dashboards/usecase/dashboard_filter.go:22 — Create and Update do not validate Type against the allowed values multiple and searchable. Invalid types can be persisted and may break frontend filter behavior. Validate the enum before saving.

🔴 go-deps — pending updates

🔍 Discovered 30 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.1 → v1.89.0
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/alerts:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/playground:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.2
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/feeds:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/soar:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./backend:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./tools/rulecheck:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./log-input:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./collectors/utmstack:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/forwarder:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/as400:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

❌ Please update dependencies before merging.

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor Author

database handler captures the tenant via context and injects it to the query, so all filter operations are tenant scoped

@AlexSanchez-bit
AlexSanchez-bit merged commit bf87020 into release/v12.0.0 Sep 30, 2026
1 check passed
@AlexSanchez-bit
AlexSanchez-bit deleted the backlog/v12_dashboard_filters branch September 30, 2026 23:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dashboard filter dropped

1 participant