Skip to content

Fix field path bugs in Okta.Support.Reset and Slack app rules - #2092

Merged
arielkr256 merged 1 commit into
developfrom
fix/open-issues-2087-2088-2089-2090
Jun 11, 2026
Merged

arielkr256 merged 1 commit into
developfrom
fix/open-issues-2087-2088-2089-2090

Conversation

@arielkr256

Copy link
Copy Markdown
Contributor

Summary

Test plan

  • pat test --filter RuleID=Okta.Support.Reset — all tests pass
  • pat test --filter RuleID=Slack.AuditLogs.AppAdded — all tests pass
  • pat test --filter RuleID=Slack.AuditLogs.AppAccessExpanded — all tests pass
  • Pre-commit hooks (fmt + lint) passed

Closes #2087, #2088, #2089, #2090

🤖 Generated with Claude Code

- Okta.Support.Reset: fix userAgent path (top-level → client.userAgent.rawUserAgent)
- Okta.Support.Reset: fix title() to show impacted user from target[] not actor
- Slack.AuditLogs.AppAdded: fix alert_context scopes path (entity.scopes → entity.app.scopes)
- Slack.AuditLogs.AppAdded + AppAccessExpanded: fix severity() fallback (new_scope → new_scopes)

Closes #2087, #2088, #2089, #2090

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@arielkr256
arielkr256 requested a review from a team as a code owner June 11, 2026 16:52
@cursor

cursor Bot commented Jun 11, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes detection logic and severity escalation paths; mis-tuned rules could alter alert volume or miss admin-scope events until validated in tests.

Overview
Corrects wrong deep_get paths in Okta support-reset and Slack app audit rules so matching, alert text, context, and severity behave as intended.

For Okta support reset, the rule now reads user agent from client.userAgent.rawUserAgent instead of a non-existent top-level userAgent, and titles name the impacted user from target[] (User) rather than the actor (system@okta.com).

For Slack app added / access expanded, alert_context pulls scopes from entity.app.scopes, and the admin severity fallback uses details.new_scopes (plural) so High escalation can fire when admin appears only in details.

Reviewed by Cursor Bugbot for commit 6cf11a8. Bugbot is set up for automated code reviews on this repo. Configure here.

@arielkr256 arielkr256 added bug Something isn't working tuning detection tuning labels Jun 11, 2026
@arielkr256
arielkr256 added this pull request to the merge queue Jun 11, 2026
Merged via the queue into develop with commit 4e0b139 Jun 11, 2026
18 checks passed
@arielkr256
arielkr256 deleted the fix/open-issues-2087-2088-2089-2090 branch June 11, 2026 17:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working tuning detection tuning

2 participants