Skip to content

Commit b7e5948

Browse files
fix[backend](execution): masked secret variables on execution history (#2767)
* fix[backend](execution): masked secret variables on execution history * fix[backend](command): added start manual execution mask * fix[backend](command): added soar flow execution variable masking
1 parent 93559cc commit b7e5948

1 file changed

Lines changed: 16 additions & 2 deletions

File tree

‎backend/modules/soar/usecase/execution.go‎

Lines changed: 16 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,13 @@ func (u *executionUsecase) HandleMatch(ctx context.Context, req dto.MatchRequest
9393
_ = catcher.Error("soar: command interpolation failed", ierr, map[string]any{"rule": req.RulePath, "root": rootID})
9494
continue
9595
}
96+
97+
masked_command,cerr := u.vars.MaskSecrets(ctx,command)
98+
if cerr != nil {
99+
_ = catcher.Error("soar: command variable masking failed", cerr,map[string]any{"rule": req.RulePath, "root": rootID})
100+
}
101+
102+
96103
exec := &domain.SoarExecution{
97104
TenantID: tenantUUID,
98105
Origin: domain.ExecutionOriginFlow,
@@ -105,7 +112,7 @@ func (u *executionUsecase) HandleMatch(ctx context.Context, req dto.MatchRequest
105112
Executor: node.Executor,
106113
Params: params,
107114
Context: json.RawMessage(bag),
108-
Command: command,
115+
Command: masked_command,
109116
Shell: node.Shell,
110117
Agent: agent,
111118
Status: domain.ExecutionStatusPending,
@@ -164,6 +171,7 @@ func (u *executionUsecase) List(ctx context.Context, f dto.ExecutionFilters) (*d
164171
items := make([]dto.ExecutionResponse, len(executions))
165172
for i, e := range executions {
166173
CommandSummary(ctx, u.vars, &e)
174+
167175
items[i] = dto.ExecutionResponse{
168176
ID: e.ID,
169177
Origin: e.Origin,
@@ -190,11 +198,17 @@ func (u *executionUsecase) List(ctx context.Context, f dto.ExecutionFilters) (*d
190198
}
191199

192200
func (u *executionUsecase) StartManual(ctx context.Context, agent, command, triggeredBy string) (uuid.UUID, error) {
201+
202+
masked_command,cerr := u.vars.MaskSecrets(ctx,command)
203+
if cerr != nil {
204+
_ = catcher.Error("soar: command variable masking failed", cerr,map[string]any{})
205+
}
206+
193207
e, err := u.repo.Create(ctx, &domain.SoarExecution{
194208
Origin: domain.ExecutionOriginManual,
195209
TriggeredBy: triggeredBy,
196210
Agent: agent,
197-
Command: command,
211+
Command: masked_command,
198212
Executor: "shell",
199213
Kind: domain.NodeKindExecutor,
200214
NodeID: "manual",

0 commit comments

Comments
 (0)