From 0dcedf5d76f420643307cb410bf21ff5b8d45e92 Mon Sep 17 00:00:00 2001 From: ypratama Date: Mon, 7 Sep 2026 13:29:20 +0700 Subject: [PATCH] Fix: strictly filter flows by agent UUID to prevent org-level data pollution --- proxy/backoneClient.js | 6 +++++- proxy/backoneClientCore.js | 3 ++- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/proxy/backoneClient.js b/proxy/backoneClient.js index c2aeeb1..0067ac7 100644 --- a/proxy/backoneClient.js +++ b/proxy/backoneClient.js @@ -13,6 +13,10 @@ async function fetchFlows(limit = 500, agentUuid = null, siteUuid = null, interv backoneFetch('/data/stats/top/tls_sni/download', { filter_interval: intervalMinutes, settings_limit: 50 }, agentUuid, siteUuid), ]); if (!raw || !Array.isArray(raw)) return null; + + // Safety check: Filter flows strictly to the requested agent to prevent Org-level pollution + const filteredRaw = agentUuid ? raw.filter(r => r.agent_uuid === agentUuid) : raw; + const sniList = []; if (sniRaw && Array.isArray(sniRaw)) { for (const r of sniRaw) { @@ -22,7 +26,7 @@ async function fetchFlows(limit = 500, agentUuid = null, siteUuid = null, interv } } } - return raw.map(r => { + return filteredRaw.map(r => { const port = r.remote_port ?? null; const portService = port ? (stats.PORT_SERVICE_MAP[port] ?? `Port ${port}`) : null; const appLabel = r.application?.label || portService; diff --git a/proxy/backoneClientCore.js b/proxy/backoneClientCore.js index 8caa999..0c74fe6 100644 --- a/proxy/backoneClientCore.js +++ b/proxy/backoneClientCore.js @@ -37,7 +37,8 @@ function fixDates(obj) { async function backoneFetch(endpoint, params = {}, agentUuid = null, siteUuid = null) { if (agentUuid) { const agentId = agentMap[agentUuid]; - if (agentId) { + // Only use filter_agents if agentId is a number or numeric string + if (agentId && !isNaN(Number(agentId))) { params.filter_agents = `[${agentId}]`; } else { params.settings_agent = agentUuid;