Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Data-component channels crashes and log-sources returns an empty body when optional log sources are absent

Aperta Adatta ai principianti
#513 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
85/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
javascript
Ambito
api, backend

Direzione di ricerca

Inizia dagli handler channels e log-sources in app/controllers/data-components-controller.js, poi cerca i test REST esistenti per queste proiezioni. Aggiungi test per i campi assenti, le revisioni successive che li omettono, i campi valorizzati e i componenti inesistenti. Il lavoro è concluso quando entrambe le proiezioni restituiscono JSON [] per i campi assenti, preservando le risposte con campi valorizzati e HTTP 404 per i componenti mancanti.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Verified on REST API 4.24.0, commit 69b37fe769e6abe7675d413451a8361aecc36bea.

Reproduction and impact

Create a valid data component with populated x_mitre_log_sources, then create a newer revision omitting that optional field. The write succeeds with HTTP 201 and ordinary component GET selects the new revision.

GET /api/data-components/COMPONENT_ID/channels
GET /api/data-components/COMPONENT_ID/log-sources
  • Channels returns HTTP 500 with body Server error..
  • Log-sources returns HTTP 200 with zero body bytes and no JSON content type.

Both populated projections work. Correlated REST logs confirm the channels exception twice:

TypeError: Cannot read properties of undefined (reading 'map')

Root cause and expected fix

The channels controller calls .map() on the missing value; the log-sources controller sends it directly.

Return HTTP 200 JSON [] from both projections when the field is absent, preserving populated responses and missing-component HTTP 404.

Omission is valid in REST, Mongoose and the version-matched ADM schema. A present STIX array requires at least one entry, so default the read projection without storing an invalid empty array.

Add REST tests for initially absent fields, later revisions omitting them, populated fields, and nonexistent components. Assert JSON array bodies explicitly.

Lingua principale
JavaScript
Stelle
57
Fork
18
Merge medio
1g 26m
PR unite (30g)
7

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di mitre-attack/attack-workbench-rest-api

Tutte le issue di mitre-attack/attack-workbench-rest-api

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.