Update live query selector logic (OR -> AND) (#9559)
See requirements in #8682. Two assumptions on the implementation (@zayhanlon please take a look): - Hosts explicitly selected to run always run the live query (no matter the values on the selectors). - When selecting `All hosts`, selecting any other platform or label is kind of a no-op. We should look into graying out all the selectors if the user selects `All hosts`. - [X] Changes file added for user-visible changes in `changes/` or `orbit/changes/`. See [Changes files](https://fleetdm.com/docs/contributing/committing-changes#changes-files) for more information. - [X] Documented any API changes (docs/Using-Fleet/REST-API.md or docs/Contributing/API-for-contributors.md) - ~[ ] Documented any permissions changes~ - [X] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements) - ~[ ] Added support on fleet's osquery simulator `cmd/osquery-perf` for new osquery data ingestion features.~ - [X] Added/updated tests - [X] Manual QA for all new/changed functionality - ~For Orbit and Fleet Desktop changes:~ - ~[ ] Manual QA must be performed in the three main OSs, macOS, Windows and Linux.~ - ~[ ] Auto-update manual QA, from released version of component to new version (see [tools/tuf/test](../tools/tuf/test/README.md)).~
This commit is contained in:
@@ -592,9 +592,9 @@ None.
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| ---- | ------- | ---- | --------------------------------------- |
|
||||
| id | integer | path | **Required.** The host's ID in Fleet. |
|
||||
| Name | Type | In | Description |
|
||||
| ---- | ------- | ---- | ------------------------------------- |
|
||||
| id | integer | path | **Required.** The host's ID in Fleet. |
|
||||
|
||||
#### Example
|
||||
|
||||
@@ -631,10 +631,10 @@ Note that the `public_key` and `private_key` are base64 encoded and should be de
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| ---- | ------- | ---- | --------------------------------------- |
|
||||
| email_address | string | body | **Required.** The email that will be associated with the Apple APNs certificate. |
|
||||
| organization | string | body | **Required.** The name of the organization associated with the Apple APNs certificate. |
|
||||
| Name | Type | In | Description |
|
||||
| ------------- | ------ | ---- | -------------------------------------------------------------------------------------- |
|
||||
| email_address | string | body | **Required.** The email that will be associated with the Apple APNs certificate. |
|
||||
| organization | string | body | **Required.** The name of the organization associated with the Apple APNs certificate. |
|
||||
|
||||
#### Example
|
||||
|
||||
@@ -1147,7 +1147,7 @@ If the `name` is not already associated with an existing team, this API route cr
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| ------------- | ------ | ---- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| ------------- | ------ | ----- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| name | string | body | **Required.** The team's name. |
|
||||
| agent_options | object | body | The agent options spec that is applied to the hosts assigned to the specified to team. These agent options completely override the global agent options specified in the [`GET /api/v1/fleet/config API route`](#get-configuration) |
|
||||
| features | object | body | The features that are applied to the hosts assigned to the specified to team. These features completely override the global features specified in the [`GET /api/v1/fleet/config API route`](#get-configuration) |
|
||||
@@ -1403,9 +1403,9 @@ This replaces the active global enroll secrets with the secrets specified.
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| ------ | ------ | ---- | -------------------------------------------------------------- |
|
||||
| secrets | list | body | **Required.** The plain text string used as the enroll secret. Note that there is a limit of 50 secrets allowed. |
|
||||
| Name | Type | In | Description |
|
||||
| ------- | ---- | ---- | ---------------------------------------------------------------------------------------------------------------- |
|
||||
| secrets | list | body | **Required.** The plain text string used as the enroll secret. Note that there is a limit of 50 secrets allowed. |
|
||||
|
||||
#### Example
|
||||
|
||||
@@ -1490,15 +1490,15 @@ for which the user has an observer role.
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
|-------------------|---------|------|--------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| query | string | body | The query used to identify hosts to target. Searchable items include a host's hostname or IPv4 address. |
|
||||
| query_id | integer | body | The saved query (if any) that will be run. The `observer_can_run` property on the query and the user's roles affect which targets are included. |
|
||||
| excluded_host_ids | array | body | The list of host ids to omit from the search results. |
|
||||
| Name | Type | In | Description |
|
||||
| ----------------- | ------- | ---- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| query | string | body | The query used to identify hosts to target. Searchable items include a host's hostname or IPv4 address. |
|
||||
| query_id | integer | body | The saved query (if any) that will be run. The `observer_can_run` property on the query and the user's roles affect which targets are included. |
|
||||
| excluded_host_ids | array | body | The list of host ids to omit from the search results. |
|
||||
|
||||
#### Example
|
||||
|
||||
`POST /api/v1/fleet/targets/search`
|
||||
`POST /api/v1/fleet/hosts/search`
|
||||
|
||||
##### Request body
|
||||
|
||||
@@ -1571,10 +1571,10 @@ Counts the number of online and offline hosts included in a given set of selecte
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
|----------|---------|------|-----------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| query_id | integer | body | The saved query (if any) that will be run. The `observer_can_run` property on the query and the user's roles determine which targets are included. |
|
||||
| selected | object | body | The object includes lists of selected host IDs, label IDs, and team IDs. |
|
||||
| Name | Type | In | Description |
|
||||
| -------- | ------- | ---- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| query_id | integer | body | The saved query (if any) that will be run. The `observer_can_run` property on the query and the user's roles determine which targets are included. |
|
||||
| selected | object | body | The object includes lists of selected host IDs (`selected.hosts`), label IDs (`selected.labels`), and team IDs (`selected.teams`). When provided, builtin label IDs, custom label IDs and team IDs become `AND` filters. Within each selector, selecting two or more teams, two or more builtin labels, or two or more custom labels, behave as `OR` filters. There's one special case for the builtin label "All hosts", if such label is selected, then all other label and team selectors are ignored (and all hosts will be selected). If a host ID is explicitly included in `selected.hosts`, then it is assured that the query will be selected to run on it (no matter the contents of `selected.labels` and `selected.teams`). See examples below. |
|
||||
|
||||
#### Example
|
||||
|
||||
@@ -1613,11 +1613,11 @@ After you initiate the query, [get results via WebSocket](#retrieve-live-query-r
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| -------- | ------- | ---- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| query | string | body | The SQL if using a custom query. |
|
||||
| query_id | integer | body | The saved query (if any) that will be run. Required if running query as an observer. The `observer_can_run` property on the query effects which targets are included. |
|
||||
| selected | object | body | **Required.** The desired targets for the query specified by ID. This object can contain `hosts`, `labels`, and/or `teams` properties. See examples below. |
|
||||
| Name | Type | In | Description |
|
||||
| -------- | ------- | ---- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| query | string | body | The SQL if using a custom query. |
|
||||
| query_id | integer | body | The saved query (if any) that will be run. Required if running query as an observer. The `observer_can_run` property on the query effects which targets are included. |
|
||||
| selected | object | body | **Required.** The object includes lists of selected host IDs (`selected.hosts`), label IDs (`selected.labels`), and team IDs (`selected.teams`). When provided, builtin label IDs, custom label IDs and team IDs become `AND` filters. Within each selector, selecting two or more teams, two or more builtin labels, or two or more custom labels, behave as `OR` filters. There's one special case for the builtin label "All hosts", if such label is selected, then all other label and team selectors are ignored (and all hosts will be selected). If a host ID is explicitly included in `selected.hosts`, then it is assured that the query will be selected to run on it (no matter the contents of `selected.labels` and `selected.teams`). See examples below. |
|
||||
|
||||
One of `query` and `query_id` must be specified.
|
||||
|
||||
@@ -1709,11 +1709,11 @@ After the query has been initiated, [get results via WebSocket](#retrieve-live-q
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| -------- | ------- | ---- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||
| query | string | body | The SQL of the query. |
|
||||
| query_id | integer | body | The saved query (if any) that will be run. The `observer_can_run` property on the query effects which targets are included. |
|
||||
| selected | object | body | **Required.** The desired targets for the query specified by name. This object can contain `hosts`, `labels`, and/or `teams` properties. See examples below. |
|
||||
| Name | Type | In | Description |
|
||||
| -------- | ------- | ---- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| query | string | body | The SQL of the query. |
|
||||
| query_id | integer | body | The saved query (if any) that will be run. The `observer_can_run` property on the query effects which targets are included. |
|
||||
| selected | object | body | **Required.** The object includes lists of selected hostnames (`selected.hosts`), label names (`labels`). When provided, builtin label names and custom label names become `AND` filters. Within each selector, selecting two or more builtin labels, or two or more custom labels, behave as `OR` filters. There's one special case for the builtin label `"All hosts"`, if such label is selected, then all other label and team selectors are ignored (and all hosts will be selected). If a host's hostname is explicitly included in `selected.hosts`, then it is assured that the query will be selected to run on it (no matter the contents of `selected.labels`). See examples below. |
|
||||
|
||||
One of `query` and `query_id` must be specified.
|
||||
|
||||
@@ -2091,9 +2091,9 @@ currently pending.
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------------------|
|
||||
| name | string | query | The name of the cron schedule to trigger. |
|
||||
| Name | Type | In | Description |
|
||||
| ---- | ------ | ----- | ----------------------------------------- |
|
||||
| name | string | query | The name of the cron schedule to trigger. |
|
||||
|
||||
#### Example
|
||||
|
||||
@@ -2126,9 +2126,9 @@ Returns the host information about the device that makes the request.
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
##### Example
|
||||
|
||||
@@ -2288,9 +2288,9 @@ Same as [Refetch host route](https://fleetdm.com/docs/using-fleet/rest-api#refet
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
#### Get device's Google Chrome profiles
|
||||
|
||||
@@ -2300,9 +2300,9 @@ Same as [Get host's Google Chrome profiles](https://fleetdm.com/docs/using-fleet
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
#### Get device's mobile device management (MDM) and Munki information
|
||||
|
||||
@@ -2312,9 +2312,9 @@ Same as [Get host's mobile device management and Munki information](https://flee
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
|
||||
#### Get Fleet Desktop information
|
||||
@@ -2326,9 +2326,9 @@ Gets all information required by Fleet Desktop to notify the user if there are a
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
##### Example
|
||||
|
||||
@@ -2356,9 +2356,9 @@ Lists the policies applied to the current device.
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
##### Example
|
||||
|
||||
@@ -2410,9 +2410,9 @@ This supports the dynamic discovery of API features supported by the server for
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
##### Example
|
||||
|
||||
@@ -2436,9 +2436,9 @@ Returns the URL to open when clicking the "Transparency" menu item in Fleet Desk
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
##### Example
|
||||
|
||||
@@ -2458,9 +2458,9 @@ Downloads the Mobile Device Management (MDM) enrollment profile to install on th
|
||||
|
||||
##### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| --------------- | ------ | ----- | ---------------------------------------|
|
||||
| token | string | path | The device's authentication token. |
|
||||
| Name | Type | In | Description |
|
||||
| ----- | ------ | ---- | ---------------------------------- |
|
||||
| token | string | path | The device's authentication token. |
|
||||
|
||||
##### Example
|
||||
|
||||
@@ -2495,12 +2495,12 @@ Downloads a pre-built fleet-osquery installer with the given parameters.
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| ------------- | ------- | ---------------------- | ------------------------------------------------------------------ |
|
||||
| kind | string | path | The installer kind: pkg, msi, deb or rpm. |
|
||||
| enroll_secret | string | x-www-form-urlencoded | The global enroll secret. |
|
||||
| token | string | x-www-form-urlencoded | The authentication token. |
|
||||
| desktop | boolean | x-www-form-urlencoded | Set to `true` to ask for an installer that includes Fleet Desktop. |
|
||||
| Name | Type | In | Description |
|
||||
| ------------- | ------- | --------------------- | ------------------------------------------------------------------ |
|
||||
| kind | string | path | The installer kind: pkg, msi, deb or rpm. |
|
||||
| enroll_secret | string | x-www-form-urlencoded | The global enroll secret. |
|
||||
| token | string | x-www-form-urlencoded | The authentication token. |
|
||||
| desktop | boolean | x-www-form-urlencoded | Set to `true` to ask for an installer that includes Fleet Desktop. |
|
||||
|
||||
##### Default response
|
||||
|
||||
@@ -2555,11 +2555,11 @@ Sets up a new Fleet instance with the given parameters.
|
||||
|
||||
#### Parameters
|
||||
|
||||
| Name | Type | In | Description |
|
||||
| ------------- | ------- | ---------------------- | ------------------------------------------------------------------ |
|
||||
| admin | object | body | **Required.** Contains the following admin user details: `admin`, `email`, `name`, `password`, and `password_confirmation`. |
|
||||
| org_info | object | body | **Required.** Contains the following organizational details: `org_name`. |
|
||||
| server_url | string | body | **Required.** The URL of the Fleet instance. |
|
||||
| Name | Type | In | Description |
|
||||
| ---------- | ------ | ---- | --------------------------------------------------------------------------------------------------------------------------- |
|
||||
| admin | object | body | **Required.** Contains the following admin user details: `admin`, `email`, `name`, `password`, and `password_confirmation`. |
|
||||
| org_info | object | body | **Required.** Contains the following organizational details: `org_name`. |
|
||||
| server_url | string | body | **Required.** The URL of the Fleet instance. |
|
||||
|
||||
|
||||
##### Request body
|
||||
|
||||
Reference in New Issue
Block a user