Fix: strictly filter flows by agent UUID to prevent org-level data pollution

This commit is contained in:
ypratama committed 2026-09-07 13:29:20 +07:00
1 parent 068435ffb9
commit 0dcedf5d76
2 files changed
+7 -2

No files matched your search

+5 -1
View File
@@ -13,6 +13,10 @@ async function fetchFlows(limit = 500, agentUuid = null, siteUuid = null, interv
backoneFetch('/data/stats/top/tls_sni/download', { filter_interval: intervalMinutes, settings_limit: 50 }, agentUuid, siteUuid), backoneFetch('/data/stats/top/tls_sni/download', { filter_interval: intervalMinutes, settings_limit: 50 }, agentUuid, siteUuid),
]); ]);
if (!raw || !Array.isArray(raw)) return null; if (!raw || !Array.isArray(raw)) return null;
// Safety check: Filter flows strictly to the requested agent to prevent Org-level pollution
const filteredRaw = agentUuid ? raw.filter(r => r.agent_uuid === agentUuid) : raw;
const sniList = []; const sniList = [];
if (sniRaw && Array.isArray(sniRaw)) { if (sniRaw && Array.isArray(sniRaw)) {
for (const r of sniRaw) { for (const r of sniRaw) {
@@ -22,7 +26,7 @@ async function fetchFlows(limit = 500, agentUuid = null, siteUuid = null, interv
} }
} }
} }
return raw.map(r => { return filteredRaw.map(r => {
const port = r.remote_port ?? null; const port = r.remote_port ?? null;
const portService = port ? (stats.PORT_SERVICE_MAP[port] ?? `Port ${port}`) : null; const portService = port ? (stats.PORT_SERVICE_MAP[port] ?? `Port ${port}`) : null;
const appLabel = r.application?.label || portService; const appLabel = r.application?.label || portService;
+2 -1
View File
@@ -37,7 +37,8 @@ function fixDates(obj) {
async function backoneFetch(endpoint, params = {}, agentUuid = null, siteUuid = null) { async function backoneFetch(endpoint, params = {}, agentUuid = null, siteUuid = null) {
if (agentUuid) { if (agentUuid) {
const agentId = agentMap[agentUuid]; const agentId = agentMap[agentUuid];
if (agentId) { // Only use filter_agents if agentId is a number or numeric string
if (agentId && !isNaN(Number(agentId))) {
params.filter_agents = `[${agentId}]`; params.filter_agents = `[${agentId}]`;
} else { } else {
params.settings_agent = agentUuid; params.settings_agent = agentUuid;