Skip to content

Backlog/v12 soar asisted edition - #2761

Merged
AlexSanchez-bit merged 7 commits into
release/v12.0.0from
backlog/v12_soar_asisted_edition
Sep 25, 2026
Merged

AlexSanchez-bit merged 7 commits into
release/v12.0.0from
backlog/v12_soar_asisted_edition

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit AlexSanchez-bit linked an issue Sep 25, 2026 that may be closed by this pull request
1 of 2 tasks
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

🛑 AI review — Sensitive area, extra care recommended

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. Review carefully before merging.

🛑 architecture (silas-1.7-pro) — high/critical — please review

Summary: SOAR flow contract tightened and llm_action removed without migration; frontend couples editor to global SOC-AI state.

  • high backend/modules/mcp/catalog.json:639 — params schema changes from a free-form object to a strict oneOf with required fields; existing persisted SOAR flows may fail validation. Keep the old shape accepted or add a versioned schema/migration and roll-forward plan.
  • high frontend/src/features/soar/types/soar.types.ts:169 — Removes the llm_action executor from the frontend catalog; flows already using llm_action may become uneditable or invalid. Preserve support or migrate existing flows.
  • medium backend/modules/mcp/catalog.json:688 — incident params require name but the schema does not define a name property; the contract is inconsistent. Define name or remove it from required.
  • medium frontend/src/features/soar/components/FlowEditor.tsx:71 — Editor now refetches based on global soarEditVersion and silently ignores errors, coupling SOAR to SocAiProvider. Prefer query invalidation or an explicit domain event from the AI service.
  • medium frontend/src/features/soc-ai/SocAiProvider.tsx:156 — clear() now uses location.pathname to reset SOAR/dashboard scopes, adding route-specific side effects to a global provider. Move scope lifecycle to feature components or a dedicated event.
  • low frontend/src/features/soar/pages/FlowsPage.tsx:161 — Flows list refetch is driven by global soarEditVersion; this is a cross-feature coupling. Use queryClient invalidation for SOAR flows after AI create/update.
  • low frontend/src/features/soar/components/SoarCreateDialog.tsx:44 — Dialog directly sets AI target, opens panel, and submits to assistant, coupling manual creation to SOC-AI internals. Consider a SOAR-owned create command that optionally invokes AI.

🛑 bugs (silas-1.7-pro) — high/critical — please review

Summary: dirtyRef set true on initial load permanently blocks AI edits; missing soarCreateTitle i18n key in all locales; incident schema requires undefined 'name' prop.

  • high frontend/src/features/soar/components/FlowEditor.tsx:67 — dirtyRef.current = true is set during the initial flow-load effect and is never reset to false anywhere in the component. The new soarEditVersion effect (line 74) checks 'if (dirtyRef.current) return', so after the first load the guard is always true and AI-driven refetches are silently skipped. The entire AI-edit feature is non-functional: the user clicks 'Edit with AI', the agent updates the flow server-side, soarEditVersion increments, but the editor never picks up the change. Fix: do not set dirtyRef on load, or reset it to false after the initial setForm.
  • medium frontend/src/features/soc-ai/components/SocAiPanel.tsx:28 — SCOPE_TITLE_KEY maps 'soar-create' to 'socAi.chat.soarCreateTitle', but this key is absent from every locale file (en, de, es, fr, it, pt, ru). i18next will render the raw key string 'socAi.chat.soarCreateTitle' as the panel title. Add the missing key to all seven locale files (e.g. en: "SOAR flow creation").
  • medium backend/modules/mcp/catalog.json:703 — The incident-node params schema lists 'name' in required but has no corresponding entry in properties. The field's type is therefore unconstrained (any JSON value passes). Add '"name": { "type": "string" }' to the properties object so the schema actually validates the field.
  • medium frontend/src/features/soar/components/FlowEditor.tsx:80 — .catch(() => {}) silently swallows all errors from soarFlowsService.get(). If the refetch after an AI edit fails (network error, 404, etc.) the user gets no feedback and the editor stays stale with no indication something went wrong. At minimum, log the error or show a toast.
  • low frontend/src/features/soc-ai/SocAiProvider.tsx:169 — In clear(), the 'soar-create' branch calls setActiveScope('panel') but does not call setSoarCreateTarget(null), unlike the 'soar-edit' branch which clears soarEditTarget. A stale create target persists in state and could leak into a subsequent soar-create session's system prompt. Add setSoarCreateTarget(null) for consistency.

✅ security (silas-1.7-pro) — clean

Summary: No new vulnerabilities or customer-facing information disclosure identified in the SOAR AI editor changes.

No findings.

🔴 go-deps — pending updates

🔍 Discovered 30 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/aws:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/alerts:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/events:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/playground:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/azure:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/feeds:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/soar:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./backend:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./tools/rulecheck:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./log-input:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./collectors/utmstack:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/forwarder:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/as400:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

❌ Please update dependencies before merging.

@AlexSanchez-bit
AlexSanchez-bit merged commit 919173f into release/v12.0.0 Sep 25, 2026
1 check passed
@AlexSanchez-bit
AlexSanchez-bit deleted the backlog/v12_soar_asisted_edition branch September 25, 2026 21:33
Kbayero added a commit that referenced this pull request Sep 29, 2026
* Backlog/v12 mcp soar nodes discovery (#2754)

* fix[backend](mcp): add soar.node_types tool for flow node kind and executor discovery

* chore[](): updated go deps

* Backlog/v12 soar asisted edition (#2761)

* fix[frontend](soar-flows): removed redundant llm action node

* fix[backend](mcp/soar): updated flow properties schema in mcp catalog

* fix[frontend](soc-ai): drop dashboard chat scope when cleared outside dashboard view

* feat[frontend](soar/assitant): Edit with AI in flow editor

* feat[frontend](soar): click soar-edit panel header to open the active flow

* feat[frontend](soar): create flow with AI

* fix[backend](mcp/soar): fixed notifications type schema

* fix[backend](tagrule): added tagrule tenant scoping (#2765)

* fix[backend](execution): masked secret variables on execution history (#2767)

* fix[backend](execution): masked secret variables on execution history

* fix[backend](command): added start manual execution mask

* fix[backend](command): added soar flow execution variable masking

* fix[backend](visualizations): fixed tenat removal on visualization update (#2770)

* fix[frontend](soar): added variable interpolation in soar flows (#2771)

---------

Co-authored-by: Alex Sánchez <alex.sanchez@utmstack.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Soar Ai driven creation/edition flow

1 participant