#918 Adding buttons for node operations
Pull request opened by
javuto
Summary
• Added single-node actions to the node detail page:
• Run an osquery query against the current node
• Start a file carve for the current node
• Apply an existing tag or create/apply a custom tag
• Updated the single-node query modal to support both saved-query selection and ad-hoc SQL input.
• Made single-node queries expire after 24 hours.
• Improved node detail header actions for smaller windows:
• Actions now wrap into multiple rows instead of overlapping hostname/UUID
• Added icons for copy node key, refresh, archive, query, carve, tag, and console actions
• Fixed distributed query delivery for non-expiring queries by treating zero-time expiration as “never expires.”
• Made API query creation atomic so node-target rows and expected counts are committed together, preventing queries from being marked completed before nodes can pick them up.
Validation
•
go test ./pkg/queries
•
go test ./cmd/api/handlers
•
npm test -- NodeDetailPage.test.tsx
•
npm run check
•
git diff --check
jmpsec/osctrl