Skip to content

Backlog/v11 federation - #2781

Merged
Kbayero merged 36 commits into
v11from
backlog/v11_federation
Sep 29, 2026
Merged

Kbayero merged 36 commits into
v11from
backlog/v11_federation

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit
AlexSanchez-bit requested a review from a team September 29, 2026 18:19
@github-actions

Copy link
Copy Markdown

❌ Go dependencies check failed

There are outdated Go dependencies, or modules that could not be inspected.
Run bash .github/scripts/go-deps.sh --update --discover locally and
commit the updated go.mod / go.sum files.

Script output
🔍 Discovered 25 Go projects

📦 Dependencies with updates available:

  📁 ./utmstack-collector:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2: v1.47.0 → v1.47.1
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.88.1
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/events:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/inputs:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/modules-config:
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.88.1
     - github.com/aws/aws-sdk-go-v2/service/sts: v1.51.0 → v1.51.1
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/config:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.2
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./as400:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./as400/updater:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

�[0;31m❌ Please update dependencies before merging.�[0m

@github-actions

Copy link
Copy Markdown

🛑 AI review — Engineer review required

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. @Kbayero @osmontero please review.

🛑 architecture (silas-1.7-pro) — blocking — must fix before merge

Summary: Federation feature leaks into core auth/routing/HTTP stack, changes password policy, adds global instance header, and creates shared-module coupling; needs compatibility review.

  • high frontend/src/app/app-routing.module.ts:181 — Adds public route /auth/login to PasswordResetFinishComponent, changing auth route contract and likely hiding login. Remove or point to LoginComponent; if intentional, document compatibility.
  • high frontend/src/app/blocks/interceptor/federation-instance.interceptor.ts:31 — Global HTTP interceptor injects X-UTM-Instance into all non-auth API requests based on client state, a new wire contract. Scope to federation endpoints or make backend versioned/tolerant and define rollout.
  • high frontend/src/app/shared/components/layout/header/shared/notification/utm-notification-user-setting/password/password.component.html:29 — Password minimum length changes from 4 to 8 in a shared auth component. Align backend validation/policy and migration; frontend-only change can create inconsistent auth behavior.
  • medium frontend/src/app/core/auth/account.service.ts:176 — Core AccountService now depends on federation services and performs instance loading/onboarding redirects. Move federation onboarding to a guard or feature bootstrap to keep auth layer decoupled.
  • medium frontend/src/app/core/auth/user-route-access-service.ts:37 — Core route guard now encodes federation no-instance redirect. Use a dedicated federation guard for affected routes or a policy service instead of core guard knowing feature state.
  • medium frontend/src/app/shared/utm-shared.module.ts:277 — Shared module imports/exports feature FederationModule and declares FederationEmailConfigPageComponent from the feature. Declare feature pages inside FederationModule and let shared module depend on stable abstractions only.
  • medium frontend/src/app/federation/federation.module.ts:46 — FederationModule exports only sidebar/user-menu/overview grid, while app-routing references Welcome, TeamMembers, and EmailConfig pages. Export/declare the routed feature pages in the feature module instead of relying on shared-module declarations.
  • medium frontend/src/app/app.module.ts:145 — APP_INITIALIZER blocks application bootstrap on /api/v1/mode. Detect federation lazily after auth or use a non-blocking state service to avoid coupling startup to a network endpoint.
  • medium frontend/src/app/federation/services/federation-instance-state.service.ts:35 — Active instance id is persisted in localStorage without per-user scoping or logout clear. This can carry state across accounts; clear on sign-out and scope by user/session.
  • medium frontend/src/app/federation/components/instance-form-modal/instance-form-modal.component.html:25 — UI collects instance API keys and allows TLS skip verification. Treat as secret-handling path: avoid storing in client state, confirm server-side validation, and document security risk of tlsSkipVerify.
  • low frontend/src/app/federation/pages/email-config/federation-email-config-params.const.ts:51 — Hardcoded development default URL and example SMTP host are embedded as config values. Use empty defaults or server-provided configuration to avoid shipping non-production values.
  • low frontend/src/environments/environment.ts:3 — New environment file sets production:false and localhost SERVER_API_URL. Verify this is generated per environment and not a committed default that can leak into release builds.

🛑 bugs (silas-1.7-pro) — blocking — must fix before merge

Summary: Federation PR introduces malformed API base URL, wrong auth/login route, missing admin guard, pagination off-by-one, and several unhandled errors/mobile UI gaps.

  • high frontend/src/environments/environment.ts:3 — SERVER_API_URL lacks a trailing slash, but federation services concatenate 'api/v1/...' (e.g. 'http://localhost:8080api/v1/instances'), producing malformed URLs and API failures.
  • high frontend/src/app/app-routing.module.ts:181 — New route 'auth/login' is mapped to PasswordResetFinishComponent instead of a login component; navigating to /auth/login shows the password reset finish page.
  • high frontend/src/app/app-routing.module.ts:171 — Federation child route 'email-config' only sets data authorities for ADMIN_ROLE; the parent UserRouteAccessService does not enforce child data, so non-admin users can reach the page. Add a child canActivate guard.
  • high frontend/src/app/federation/pages/team-members/team-members.page.component.ts:224 — Pagination is zero-based but has_prev is computed as page > 1; on the second page (page=1) Previous is disabled, so users cannot navigate back to page 0. Use page > 0.
  • medium frontend/src/app/federation/components/instance-form-modal/instance-form-modal.component.ts:45 — isEditMode returns true when instance is undefined (instance !== null). If the modal is opened with undefined, it is treated as edit mode but submit falls through to create. Use !!this.instance or an explicit null/undefined check.
  • medium frontend/src/app/federation/components/federation-overview-grid/federation-overview-grid.component.ts:124 — openEdit assigns ref.componentInstance.instance = target without checking for undefined; if the instance is missing from state, the edit modal opens with no instance and can create a new instance instead of failing.
  • medium frontend/src/app/core/auth/account.service.ts:171 — ensureFederationInstancesLoaded swallows list() errors in catch, leaving instances empty without feedback; authentication still succeeds and the UI may silently stay in the empty federation welcome flow.
  • medium frontend/src/app/federation/pages/welcome/welcome.component.ts:35 — After creating an instance, list().subscribe has no error handler; if refresh fails the modal closes but the user is not navigated and no error is shown.
  • medium frontend/src/app/shared/components/layout/header/mobile-header/mobile-header.component.html:23 — In federation mode the mobile header hides the normal user settings but never renders app-federation-user-menu, so mobile users lose profile/password/sign-out access.
  • medium frontend/src/app/shared/components/layout/header/mobile-header/mobile-header.component.html:27 — Mobile header still shows the admin burger menu in federation mode; desktop header explicitly hides it, causing inconsistent navigation.
  • medium frontend/src/app/federation/pages/team-members/team-members.page.component.ts:178 — activate() sends email: user.email || '', which can submit a blank email for users without an email address, either failing the update or clearing the email field.
  • medium frontend/src/app/federation/pages/email-config/federation-email-config-params.const.ts:51 — Default confParamValue leaks an internal-looking dev URL, https://v11dev2.utmstack.com, into user-facing email configuration.
  • low frontend/src/app/federation/pages/email-config/federation-email-config-params.const.ts:35 — User-facing label 'Utmstack' should be 'UTMStack'.
  • low frontend/src/app/federation/pages/email-config/federation-email-config-params.const.ts:49 — User-facing label 'Utmstack' should be 'UTMStack'.
  • low frontend/src/app/federation/pages/email-config/federation-email-config-params.const.ts:50 — User-facing description 'Utmstack' should be 'UTMStack'.
  • low frontend/src/app/shared/components/utm/config/app-config-sections/app-config-sections.component.html:40 — Tooltip 'you must check before saving' is lowercase and misleading because saveDisabled is also true when saving, config invalid, or no changes exist.
  • low frontend/src/app/federation/components/federation-sidebar-instances/federation-sidebar-instances.component.html:3 — ngbDropdown placement value 'bottom-left bottom-right' is not a valid single placement; this can cause the instance selector menu to fall back to default placement.
  • low frontend/src/app/blocks/interceptor/federation-instance.interceptor.ts:47 — isAuthEndpoint uses url.includes(prefix), so any non-auth endpoint whose path contains 'auth/' or other prefixes will skip the X-UTM-Instance header; use startsWith or full path matching.
  • low frontend/src/app/federation/pages/email-config/federation-email-config.page.component.ts:26 — paramsService.query has no error handler; if the section query fails, the page renders blank/default values with no user feedback.

🛑 security (silas-1.7-pro) — blocking — must fix before merge

Summary: Federation changes expose user/instance admin functions to non-admins, allow TLS verification bypass, and leak an internal dev URL.

  • high frontend/src/app/app-routing.module.ts:162 — The new /federation routes are guarded only by USER_ROLE at the parent level, while /federation/team-members allows inviting users, disabling 2FA, and deactivating accounts. Add ADMIN_ROLE to sensitive child routes and enforce the same authorization on the backend.
  • medium frontend/src/app/app-routing.module.ts:169 — /federation/instances and /federation/welcome expose instance create, edit, and delete controls to non-admin users, allowing arbitrary instance baseUrl values and disclosure of existing instance endpoints. Restrict instance management to ADMIN_ROLE and validate instance endpoints server-side.
  • medium frontend/src/app/federation/components/instance-form-modal/instance-form-modal.component.html:34 — The UI allows enabling tlsSkipVerify for federation instances, which disables TLS certificate validation and enables man-in-the-middle attacks. Remove this option unless explicitly required, warn strongly, and ensure the server validates and logs the setting.
  • medium frontend/src/app/federation/pages/email-config/federation-email-config-params.const.ts:51 — The default mail baseUrl value contains an internal/dev URL (https://v11dev2.utmstack.com) that is rendered in the admin email configuration page. Replace it with a neutral placeholder or remove the default to avoid internal infrastructure disclosure.
  • low frontend/src/environments/environment.ts:8 — A development environment file is committed with production: false and DEBUG_INFO_ENABLED: true. Verify this file is never used in production builds and disable debug info to avoid information disclosure.
  • low frontend/src/app/app-routing.module.ts:182 — The route /auth/login is mapped to PasswordResetFinishComponent, which is likely a typo or misplaced auth-flow route. Confirm intent; if this is the login route, use LoginComponent, and if it is a reset route, ensure token handling remains explicit and authorized.
  • low frontend/src/app/federation/pages/team-members/team-members.page.component.ts:236 — Raw backend error.message values are displayed to users. Return generic client-side error text and keep detailed errors in server logs to avoid leaking internal implementation details.
  • low frontend/src/app/federation/services/federation-overview.service.ts:21 — The severity overview request uses top=100000, which may force large result sets and cause performance degradation. Use a bounded page size or server-side aggregate limits.
  • low frontend/src/app/blocks/interceptor/federation-instance.interceptor.ts:49 — Auth endpoint detection uses substring matching, so URLs containing auth/ in unexpected places can bypass instance header injection. Parse request URLs and match API paths explicitly.
  • low frontend/src/app/federation/pages/email-config/federation-email-config.page.component.ts:42 — The SMTP password field can become optional when empty if other fields are populated, which may allow saving incomplete mail credentials. Have the backend distinguish unset from previously set secrets and keep the field required unless a valid credential is confirmed.

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — Go dependencies check failed (see above).

@Kbayero
Kbayero merged commit fc39da9 into v11 Sep 29, 2026
5 of 7 checks passed
@Kbayero
Kbayero deleted the backlog/v11_federation branch September 29, 2026 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants