Fix field path bugs in Okta.Support.Reset and Slack app rules - #2092
Conversation
- Okta.Support.Reset: fix userAgent path (top-level → client.userAgent.rawUserAgent) - Okta.Support.Reset: fix title() to show impacted user from target[] not actor - Slack.AuditLogs.AppAdded: fix alert_context scopes path (entity.scopes → entity.app.scopes) - Slack.AuditLogs.AppAdded + AppAccessExpanded: fix severity() fallback (new_scope → new_scopes) Closes #2087, #2088, #2089, #2090 Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
PR SummaryMedium Risk Overview For Okta support reset, the rule now reads user agent from For Slack app added / access expanded, Reviewed by Cursor Bugbot for commit 6cf11a8. Bugbot is set up for automated code reviews on this repo. Configure here. |
Summary
userAgentcondition #2090Okta.Support.Reset: fixuserAgentpath —event.deep_get("userAgent", "rawUserAgent")→event.deep_get("client", "userAgent", "rawUserAgent")(top-level field doesn't exist; it's nested underclient)Okta.Support.Reset: fixtitle()to show the impacted user fromtarget[]instead ofactor_user(which always resolves tosystem@okta.com)scopesin alert_context #2088Slack.AuditLogs.AppAdded: fixalert_context()scopes path —entity.scopes→entity.app.scopes(was always returningNone)details.new_scopefield doesn't exist #2087Slack.AuditLogs.AppAdded+Slack.AuditLogs.AppAccessExpanded: fix severity fallback —details.new_scope→details.new_scopes(singular field never exists; escalation could never fire)Test plan
pat test --filter RuleID=Okta.Support.Reset— all tests passpat test --filter RuleID=Slack.AuditLogs.AppAdded— all tests passpat test --filter RuleID=Slack.AuditLogs.AppAccessExpanded— all tests passCloses #2087, #2088, #2089, #2090
🤖 Generated with Claude Code