Skip to content

fix[backend](incidents): added tenant id on newly added incident aler… - #2811

Merged
AlexSanchez-bit merged 2 commits into
release/v12.0.0from
backlog/v12_alert_incident_relation_update
Oct 1, 2026
Merged

AlexSanchez-bit merged 2 commits into
release/v12.0.0from
backlog/v12_alert_incident_relation_update

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

…ts so newly linked alerts dont get a no tenant state
@AlexSanchez-bit AlexSanchez-bit linked an issue Oct 1, 2026 that may be closed by this pull request
2 of 3 tasks
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🛑 AI review — Sensitive area, extra care recommended

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. Review carefully before merging.

⚠️ architecture (silas-1.7-pro) — minor findings

Summary: Repository injects tenant ID by mutating the alert object; minor layering/side-effect concern, no contract or agent impact.

  • low backend/modules/incidents/repository/incident_alert_pg.go:34 — Avoid mutating the caller's domain object in the repository. Prefer setting TenantID in the persistence query or operating on a copy to keep repository side effects explicit.

🛑 bugs (silas-1.7-pro) — high/critical — please review

Summary: Update overwrites alert.TenantID whenever ctx has a tenant, even if alert already has a different TenantID.

  • high backend/modules/incidents/repository/incident_alert_pg.go:32 — The condition only checks that alert is non-nil and tid is not uuid.Nil, so it unconditionally overwrites alert.TenantID. If the caller passes an alert with an existing TenantID different from the context tenant, the update will save the alert under the wrong tenant. Reproduce by calling Update with ctx tenant B and alert.TenantID set to A; the saved alert will have TenantID B. The check should likely be alert.TenantID == uuid.Nil if the intent is to fill it only when missing.

🛑 security (silas-1.7-pro) — high/critical — please review

Summary: No vulnerabilities introduced; change modifies multi-tenant authorization path and warrants human review.

No findings.

🔴 go-deps — pending updates

🔍 Discovered 30 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - google.golang.org/api: v0.299.0 → v0.300.0

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.1 → v1.89.0

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.2
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2

  📁 ./backend:
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36
     - google.golang.org/api: v0.299.0 → v0.300.0

  📁 ./tools/rulecheck:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./log-input:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./collectors/utmstack:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/forwarder:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/as400:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

❌ Please update dependencies before merging.

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor Author

requests are tenant scoped with only one tenant, so rewriting the tenant id wont cause any damage

@AlexSanchez-bit
AlexSanchez-bit merged commit 140adbd into release/v12.0.0 Oct 1, 2026
1 check passed
@AlexSanchez-bit
AlexSanchez-bit deleted the backlog/v12_alert_incident_relation_update branch October 1, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

v12 alert indices link dissapearing on update

1 participant