Skip to content

fix!: require hostname or computerId for audit file history (WYREAI-386) - #32

Merged
asachs01 merged 1 commit into
mainfrom
cursor/threatlocker-file-history-params-adcf
Sep 23, 2026
Merged

asachs01 merged 1 commit into
mainfrom
cursor/threatlocker-file-history-params-adcf

Conversation

@asachs01

@asachs01 asachs01 commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

EpiOn threatlocker_audit_file_history fails with HTTP 417 because auditLog.getFileHistory only sent fullPath. Linked from WYREAI-386 (ThreatLocker file-history 417, not the Automate pin).

GET /portalapi/ActionLog/ActionLogGetAllForFileHistoryV2 ("Get All File History by hostname and fullpath") takes query params fullPath, hostname, computerId (UUID), and optional sourceTableId, pageNumber, pageSize. The published OpenAPI spec marks every parameter optional. The live Portal API returns HTTP 417 Missing Parameters. Unable to load details. unless fullPath plus either hostname or computerId is present.

This SDK method previously called that endpoint with { fullPath } only, which is the 417.

Change

  • getFileHistory now takes { fullPath, hostname?, computerId?, sourceTableId?, pageNumber?, pageSize? }.
  • It throws client-side, and does not send the request, when fullPath is blank or both hostname and computerId are missing (including the old string call getFileHistory(fullPath)).
  • When both identifiers are set, both are sent. Optional paging / sourceTableId are forwarded when provided.
  • A bare JSON array response is unwrapped. The previous { logs } shape is still accepted.

BREAKING: callers must pass an object. @wyre-ai/node-threatlocker@^1.0.7 will not pick up the major this commit requests.

Tests

npm run lint and npm test (33 tests) passed locally. Contract tests cover hostname, computerId, both identifiers, optional query params, { logs } and bare-array bodies, and client-side rejection with zero requests.

Follow-up (not in this repo)

WYRE-AI/threatlocker-mcp still requires only fullPath and calls client.auditLog.getFileHistory(fullPath) (src/domains/audit_log.ts, asserted in src/__tests__/audit_log.test.ts). It depends on @wyre-ai/node-threatlocker@^1.0.7. After this SDK release:

  1. Bump the MCP dependency to the new major.
  2. Require hostname or computerId on threatlocker_audit_file_history and pass { fullPath, hostname } or { fullPath, computerId }.
  3. Repin the threatlocker image in the Conduit fleet.

Do not merge this PR from the agent.

Open in Web Open in Cursor 

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

ActionLogGetAllForFileHistoryV2 returns HTTP 417 Missing Parameters
unless fullPath is sent with hostname or computerId. getFileHistory
previously forwarded only fullPath (WYREAI-386).

BREAKING CHANGE: auditLog.getFileHistory now takes
{ fullPath, hostname?, computerId? } instead of a fullPath string.
Missing fullPath, or missing both hostname and computerId, throws
before the request is sent.

Co-authored-by: Aaron Sachs <asachs01@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: a2cde6d7-90f3-4706-90e7-0566e1a72931

📥 Commits

Reviewing files that changed from the base of the PR and between 75db3b1 and d57f69e.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • README.md
  • src/resources/audit-log.ts
  • src/types/index.ts
  • tests/mocks/handlers.ts
  • tests/unit/real-api-contracts.test.ts
 _______________________________________________________________
< Ghost in the Shell (Script): Stand Alone Complex Code Review. >
 ---------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@asachs01
asachs01 marked this pull request as ready for review September 23, 2026 23:53
@asachs01
asachs01 merged commit d5db1d6 into main Sep 23, 2026
5 checks passed
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 2.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants