Skip to content

fix[backend](execution): masked secret variables on execution history - #2767

Merged
AlexSanchez-bit merged 4 commits into
release/v12.0.0from
backlog/v12_masked_secret_vars
Sep 28, 2026
Merged

AlexSanchez-bit merged 4 commits into
release/v12.0.0from
backlog/v12_masked_secret_vars

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit AlexSanchez-bit linked an issue Sep 28, 2026 that may be closed by this pull request
2 of 3 tasks
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🛑 AI review — Sensitive area, extra care recommended

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. Review carefully before merging.

🛑 architecture (silas-1.7-pro) — high/critical — please review

Summary: SOAR usecase masks secrets before persisting Command; secret-handling change and ignored masking errors can store empty or non-executable commands.

  • high backend/modules/soar/usecase/execution.go:97 — MaskSecrets failure is logged but execution continues with masked_command, which may be empty. Abort or fall back to a safe non-executable state only if masking is display-only; do not persist an empty command.
  • high backend/modules/soar/usecase/execution.go:115 — SoarExecution.Command is now masked before persistence. If this field is used by the executor/agent, secrets are replaced and execution breaks. Keep the executable command separate and expose masked command only in DTO/API responses.
  • medium backend/modules/soar/usecase/execution.go:200 — StartManual applies the same masking before creating the execution, changing manual command behavior and silently dropping the command on masking errors. Validate masking and separate stored executable command from display masking.

🛑 bugs (silas-1.7-pro) — high/critical — please review

Summary: MaskSecrets errors are logged but ignored; executions proceed with masked_command, which may be empty or unmasked.

  • high backend/modules/soar/usecase/execution.go:97 — In HandleMatch, if u.vars.MaskSecrets returns an error, the code logs it but continues and creates a SoarExecution using masked_command. Reproduce by causing MaskSecrets to fail; the execution is created with a zero/partial/unmasked command instead of skipping or returning an error.
  • high backend/modules/soar/usecase/execution.go:200 — In StartManual, if u.vars.MaskSecrets returns an error, the code logs it but continues and creates a SoarExecution using masked_command. Reproduce by causing MaskSecrets to fail; the manual execution is created with a zero/partial/unmasked command instead of returning the error.

🛑 security (silas-1.7-pro) — high/critical — please review

Summary: MaskSecrets errors are ignored and execution continues, potentially persisting unmasked commands; fail closed on masking failure.

  • medium backend/modules/soar/usecase/execution.go:97 — If u.vars.MaskSecrets fails, the code logs the error but still stores masked_command. If MaskSecrets returns the original or partially masked command on error, secrets may be persisted. Abort or return an error when masking fails.
  • medium backend/modules/soar/usecase/execution.go:200 — StartManual has the same fail-open masking behavior. Do not create the execution if MaskSecrets returns an error.

🔴 go-deps — pending updates

🔍 Discovered 30 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/aws:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/alerts:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/events:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/playground:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/azure:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/feeds:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/soar:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./backend:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./tools/rulecheck:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./log-input:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./collectors/utmstack:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/forwarder:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/as400:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

❌ Please update dependencies before merging.

@AlexSanchez-bit
AlexSanchez-bit merged commit b7e5948 into release/v12.0.0 Sep 28, 2026
1 check passed
@AlexSanchez-bit
AlexSanchez-bit deleted the backlog/v12_masked_secret_vars branch September 28, 2026 17:09
Kbayero added a commit that referenced this pull request Sep 29, 2026
* Backlog/v12 mcp soar nodes discovery (#2754)

* fix[backend](mcp): add soar.node_types tool for flow node kind and executor discovery

* chore[](): updated go deps

* Backlog/v12 soar asisted edition (#2761)

* fix[frontend](soar-flows): removed redundant llm action node

* fix[backend](mcp/soar): updated flow properties schema in mcp catalog

* fix[frontend](soc-ai): drop dashboard chat scope when cleared outside dashboard view

* feat[frontend](soar/assitant): Edit with AI in flow editor

* feat[frontend](soar): click soar-edit panel header to open the active flow

* feat[frontend](soar): create flow with AI

* fix[backend](mcp/soar): fixed notifications type schema

* fix[backend](tagrule): added tagrule tenant scoping (#2765)

* fix[backend](execution): masked secret variables on execution history (#2767)

* fix[backend](execution): masked secret variables on execution history

* fix[backend](command): added start manual execution mask

* fix[backend](command): added soar flow execution variable masking

* fix[backend](visualizations): fixed tenat removal on visualization update (#2770)

* fix[frontend](soar): added variable interpolation in soar flows (#2771)

---------

Co-authored-by: Alex Sánchez <alex.sanchez@utmstack.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

showing secrets on soar flows

1 participant