Files
fleet/server/fleet/api_labels.go
T
227e94de5b 🤖 Chore: remove deprecated appendListOptionsWithCursorToSQL (#44385)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #44723

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Strengthened validation of sorting/order parameters across many list
and cursor-based endpoints — unsupported sort keys now return explicit
errors and prevent unsafe queries.
* Labels listing: label-list pagination query name changed; ordering by
host_count is rejected when host counts are disabled (validated at
request parsing).

* **Tests**
* Added/expanded tests covering allowed order keys, rejection of unknown
keys, and pagination behavior for multiple listing APIs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Lucas Manuel Rodriguez <lucas@fleetdm.com>
2026-05-05 10:26:47 -04:00

188 lines
5.6 KiB
Go

package fleet
////////////////////////////////////////////////////////////////////////////////
// Create Label
////////////////////////////////////////////////////////////////////////////////
type CreateLabelRequest struct {
LabelPayload
}
type CreateLabelResponse struct {
Label LabelResponse `json:"label"`
Err error `json:"error,omitempty"`
}
func (r CreateLabelResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// Modify Label
////////////////////////////////////////////////////////////////////////////////
type ModifyLabelRequest struct {
ID uint `json:"-" url:"id"`
ModifyLabelPayload
}
type ModifyLabelResponse struct {
Label LabelWithTeamNameResponse `json:"label"`
Err error `json:"error,omitempty"`
}
func (r ModifyLabelResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// Get Label
////////////////////////////////////////////////////////////////////////////////
type GetLabelRequest struct {
ID uint `url:"id"`
}
type LabelWithTeamNameResponse struct {
LabelWithTeamName
DisplayText string `json:"display_text"`
Count int `json:"count"`
HostIDs []uint `json:"host_ids,omitempty"`
}
type LabelResponse struct {
Label
DisplayText string `json:"display_text"`
Count int `json:"count"`
HostIDs []uint `json:"host_ids,omitempty"`
}
type GetLabelResponse struct {
Label LabelWithTeamNameResponse `json:"label"`
Err error `json:"error,omitempty"`
}
func (r GetLabelResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// List Labels
////////////////////////////////////////////////////////////////////////////////
type ListLabelsRequest struct {
ListOptions ListOptions `url:"label_list_options"`
TeamID *string `query:"team_id,optional" renameto:"fleet_id"` // string because it's an int or "global"
IncludeHostCounts *bool `query:"include_host_counts,optional"`
}
type ListLabelsResponse struct {
Labels []LabelResponse `json:"labels"`
Err error `json:"error,omitempty"`
}
func (r ListLabelsResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// Labels Summary
////////////////////////////////////////////////////////////////////////////////
type GetLabelsSummaryRequest struct {
TeamID *string `query:"team_id,optional" renameto:"fleet_id"` // string because it's an int or "global"
}
type GetLabelsSummaryResponse struct {
Labels []*LabelSummary `json:"labels"`
Err error `json:"error,omitempty"`
}
func (r GetLabelsSummaryResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// List Hosts in Label
////////////////////////////////////////////////////////////////////////////////
type ListHostsInLabelRequest struct {
ID uint `url:"id"`
ListOptions HostListOptions `url:"host_options"`
}
////////////////////////////////////////////////////////////////////////////////
// Delete Label
////////////////////////////////////////////////////////////////////////////////
type DeleteLabelRequest struct {
Name string `url:"name"`
}
type DeleteLabelResponse struct {
Err error `json:"error,omitempty"`
}
func (r DeleteLabelResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// Delete Label By ID
////////////////////////////////////////////////////////////////////////////////
type DeleteLabelByIDRequest struct {
ID uint `url:"id"`
}
type DeleteLabelByIDResponse struct {
Err error `json:"error,omitempty"`
}
func (r DeleteLabelByIDResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// Apply Label Specs
////////////////////////////////////////////////////////////////////////////////
type ApplyLabelSpecsRequest struct {
Specs []*LabelSpec `json:"specs"`
TeamID *uint `json:"-" query:"team_id,optional" renameto:"fleet_id"`
NamesToMove []string `json:"names_to_move,omitempty"`
}
type ApplyLabelSpecsResponse struct {
Err error `json:"error,omitempty"`
}
func (r ApplyLabelSpecsResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// Get Label Specs
////////////////////////////////////////////////////////////////////////////////
type GetLabelSpecsRequest struct {
TeamID *uint `query:"team_id,optional" renameto:"fleet_id"`
}
type GetLabelSpecsResponse struct {
Specs []*LabelSpec `json:"specs"`
Err error `json:"error,omitempty"`
}
func (r GetLabelSpecsResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// Get Label Spec
////////////////////////////////////////////////////////////////////////////////
type GetLabelSpecResponse struct {
Spec *LabelSpec `json:"specs,omitempty"`
Err error `json:"error,omitempty"`
}
func (r GetLabelSpecResponse) Error() error { return r.Err }
////////////////////////////////////////////////////////////////////////////////
// Remove Labels From Host
////////////////////////////////////////////////////////////////////////////////
type RemoveLabelsFromHostRequest struct {
ID uint `url:"id"`
Labels []string `json:"labels"`
}
type RemoveLabelsFromHostResponse struct {
Err error `json:"error,omitempty"`
}
func (r RemoveLabelsFromHostResponse) Error() error { return r.Err }