Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 13 additions & 2 deletions cli/src/commands/flows.js
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,11 @@ function parseTime(timeStr) {
return date.getTime() / 1000;
}

const buildFlowQuery = (gid, query) => {
const boxQuery = `box.id:${gid}`;
return query ? `${boxQuery} ${query}` : boxQuery;
};

const Flows = {
report: async (options) => {
const gid = await resolveBoxGid(options.box, options);
Expand Down Expand Up @@ -104,7 +109,7 @@ const Flows = {
const gid = await resolveBoxGid(options.box, options);
const client = getClient(options);

let apiParams = { gid };
let apiParams = {};
let queryParts = [];

// Build query from convenience flags
Expand Down Expand Up @@ -163,6 +168,11 @@ const Flows = {
});
}

// GET /v2/flows is MSP-wide. Enforce the selected box using the
// documented flow search qualifier after all caller-provided filters
// have been applied, so raw params cannot remove the box boundary.
apiParams.query = buildFlowQuery(gid, apiParams.query);

try {
// Auto-pagination when limit > 500 or --all flag
const shouldPaginate = options.all || (targetLimit && targetLimit > 500);
Expand Down Expand Up @@ -277,4 +287,5 @@ function computeStats(flows) {
return stats;
}

module.exports = Flows;
module.exports = Flows;
module.exports.buildFlowQuery = buildFlowQuery;
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
"fw": "./src/index.js"
},
"scripts": {
"test": "echo \"Error: no test specified\" && exit 1"
"test": "node --test"
},
"dependencies": {
"axios": "^1.6.0",
Expand Down
22 changes: 22 additions & 0 deletions test/flows.test.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
const test = require('node:test');
const assert = require('node:assert/strict');

const { buildFlowQuery } = require('../cli/src/commands/flows');

test('scopes flow queries to the selected box', () => {
assert.equal(buildFlowQuery('box-a'), 'box.id:box-a');
});

test('preserves additional flow filters while enforcing box scope', () => {
assert.equal(
buildFlowQuery('box-a', 'direction:outbound ts:>123'),
'box.id:box-a direction:outbound ts:>123'
);
});

test('does not allow a caller query to replace the selected box', () => {
assert.equal(
buildFlowQuery('box-a', 'box.id:box-b'),
'box.id:box-a box.id:box-b'
);
});