Skip to content

fix[backend](pipelines): added tenant scope on pipeline updates - #2805

Merged
AlexSanchez-bit merged 1 commit into
release/v12.0.0from
backlog/v12_pipeline_update
Oct 1, 2026
Merged

AlexSanchez-bit merged 1 commit into
release/v12.0.0from
backlog/v12_pipeline_update

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit AlexSanchez-bit linked an issue Oct 1, 2026 that may be closed by this pull request
2 of 3 tasks
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🛑 AI review — Sensitive area, extra care recommended

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. Review carefully before merging.

⚠️ architecture (silas-1.7-pro) — minor findings

Summary: Adds tenant-scoped pipeline updates but places tenant path/content logic in the repository and changes an internal interface; move logic to the usecase and verify data compatibility.

  • medium backend/modules/eventprocessing/repository/pipeline_store.go:199 — The repository now injects tenant IDs into content and rewrites relPath, which is business logic in the wrong layer. The usecase should compute the tenant-scoped content and relPath before calling the store.
  • medium backend/modules/eventprocessing/connectors/repository.go:75 — Changing PipelineRepository.Update is an internal contract change. Ensure all implementations and callers are updated, and consider passing a domain object or context-derived value to avoid future interface churn.
  • medium backend/modules/eventprocessing/repository/pipeline_store.go:210 — Tenant path construction may duplicate existing Create logic and changes the persisted key used for updates. Extract a shared helper and confirm existing tenant pipelines remain compatible or provide a migration/roll-forward plan.

🛑 bugs (silas-1.7-pro) — high/critical — please review

Summary: High: tenant Update path rewrite is non-idempotent and can target the wrong key; medium: base path rewrite drops directories.

  • high backend/modules/eventprocessing/repository/pipeline_store.go:210 — Update appends tenantId to the base name without checking whether the suffix is already present. If req.RelPath is the stored tenant-scoped path (e.g. t1/foo-t1.yaml), it becomes t1/foo-t1-t1.yaml, so the update targets a different map key and may create a new pipeline instead of updating the existing one.
  • medium backend/modules/eventprocessing/repository/pipeline_store.go:207 — filepath.Base(relPath) drops any parent directory from relPath before constructing the tenant key. If existing pipelines are stored under subdirectories, Update will look for or create a flat tenant path that does not match the original relPath.

🛑 security (silas-1.7-pro) — high/critical — please review

Summary: Tenant-scoped pipeline update introduces path construction from tenantId and allows empty tenant bypass; needs validation.

  • medium backend/modules/eventprocessing/repository/pipeline_store.go:208 — relPath is built with filepath.Join(tenantId, ...) without validating tenantId; if tenantId contains path separators or traversal, updates can write outside the intended tenant directory. Validate tenantId against a strict safe pattern or sanitize/reject unsafe values.
  • low backend/modules/eventprocessing/repository/pipeline_store.go:200 — When tenantId is empty, Update skips tenant injection and relPath rewriting, allowing unscoped updates to arbitrary relPath if context lacks tenant. Require non-empty tenantId for Update or enforce tenant in usecase.

🔴 go-deps — pending updates

🔍 Discovered 30 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.1 → v1.89.0
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/alerts:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/playground:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.2
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/feeds:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/soar:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./backend:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./tools/rulecheck:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./log-input:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./collectors/utmstack:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/forwarder:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/as400:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

❌ Please update dependencies before merging.

@AlexSanchez-bit
AlexSanchez-bit merged commit 961fb8c into release/v12.0.0 Oct 1, 2026
1 check passed
@AlexSanchez-bit
AlexSanchez-bit deleted the backlog/v12_pipeline_update branch October 1, 2026 02:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pipeline edition makes it available between tenants

1 participant