Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Missing draft detection-strategy name passes dry-run but returns 500 on save

オープン
#504 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
68/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
javascript
領域
api, backend, database

調査の方向性

Start at the POST /api/detection-strategies entry point and trace how dry-run and save requests apply ADM draft validation before reaching the Mongoose model. Reproduce the missing stix.name cases with both dry-run values and awaiting-review, then add regression coverage. Done means consistent validation and an HTTP 400 response instead of a save-time HTTP 500.

索引モデルが issue の本文から書いたものです。

説明

Description

A draft detection strategy without stix.name passes dry-run validation but returns HTTP 500 when saved.

Affected version: REST API 4.24.0, commit 69b37fe769e6abe7675d413451a8361aecc36bea.

Reproduction
  1. Start with a valid detection-strategy POST payload.
  2. Remove only stix.name, keeping workspace.workflow.state as work-in-progress.
  3. POST to /api/detection-strategies with the following variations:
Request Actual result
?dryRun=true 200
?dryRun=false 500
Same missing-name payload with state awaiting-review 400

REST API logs show:

Detection-Strategy validation failed: stix.name: Path stix.name is required.

Apparent cause

Draft ADM validation uses a partial schema that permits an omitted name. The Mongoose detection-strategy model requires name regardless of workflow state.

Saving fails Mongoose validation, which the repository wraps as DatabaseError and translates to HTTP 500.

Expected behavior

Draft validation, persistence, and dry-run should agree on required fields. Either support nameless drafts consistently or reject them with HTTP 400 before saving.

Suggested fix
  • Align ADM draft validation and Mongoose name requirements.
  • Return HTTP 400 for input validation failures.
  • Add regression coverage for missing-name drafts with both dry-run values and for awaiting-review validation.

Confirmed through controlled live requests and container logs. The API remained responsive; this failure did not crash the process.

主要言語
JavaScript
スター
57
フォーク
18
平均マージ
1日 26分
マージ済み PR(30日)
7

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

mitre-attack/attack-workbench-rest-api のほかの issue

mitre-attack/attack-workbench-rest-api の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。