tshark protocol restriction lifted, frontedn details for packet
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 11s

This commit is contained in:
2026-03-08 16:54:28 +01:00
parent c41e68c0f3
commit 5ea4dd388e
3 changed files with 481 additions and 286 deletions

View File

@@ -271,11 +271,12 @@ class DatabasePool:
self,
*,
iface: str,
eth_type_raw: Optional[int],
src_ip: str,
dst_ip: str,
src_port: int,
dst_port: int,
protocol: int,
protocol: Optional[int],
length: int,
observed_at_ms: int,
enrichment: Dict[str, Any],
@@ -297,35 +298,39 @@ class DatabasePool:
UPDATE packets
SET
updated_at = NOW(),
app_protocol = COALESCE(packets.app_protocol, $10),
app_master_protocol = COALESCE(packets.app_master_protocol, $11),
app_category = COALESCE(packets.app_category, $12),
app_confidence = COALESCE(packets.app_confidence, $13),
app_hostname = COALESCE(packets.app_hostname, $14),
app_is_encrypted = COALESCE(packets.app_is_encrypted, $15),
app_protocol = COALESCE(packets.app_protocol, $11),
app_master_protocol = COALESCE(packets.app_master_protocol, $12),
app_category = COALESCE(packets.app_category, $13),
app_confidence = COALESCE(packets.app_confidence, $14),
app_hostname = COALESCE(packets.app_hostname, $15),
app_is_encrypted = COALESCE(packets.app_is_encrypted, $16),
dpi_metadata = CASE
WHEN $16::jsonb IS NULL THEN packets.dpi_metadata
WHEN packets.dpi_metadata IS NULL THEN $16::jsonb
ELSE packets.dpi_metadata || $16::jsonb
WHEN $17::jsonb IS NULL THEN packets.dpi_metadata
WHEN packets.dpi_metadata IS NULL THEN $17::jsonb
ELSE packets.dpi_metadata || $17::jsonb
END,
capture_sources = (
SELECT ARRAY(
SELECT DISTINCT source
FROM unnest(
COALESCE(packets.capture_sources, ARRAY[]::text[]) ||
COALESCE($17::text[], ARRAY[]::text[])
COALESCE($18::text[], ARRAY[]::text[])
) AS source
)
)
WHERE
ip_proto_raw = $1
AND (capture_iface = $2 OR ingress_if = $2 OR egress_if = $2)
AND src_ip = $3::inet
AND dst_ip = $4::inet
AND src_port = $5
AND dst_port = $6
AND length = $7
AND timestamp BETWEEN $8 AND $9
(
($1::int IS NOT NULL AND ip_proto_raw = $1)
OR
($1::int IS NULL AND $2::int IS NOT NULL AND eth_type_raw = $2)
)
AND (capture_iface = $3 OR ingress_if = $3 OR egress_if = $3)
AND src_ip = $4::inet
AND dst_ip = $5::inet
AND COALESCE(src_port, 0) = $6
AND COALESCE(dst_port, 0) = $7
AND length = $8
AND timestamp BETWEEN $9 AND $10
AND (
packets.app_protocol IS NULL
OR packets.app_master_protocol IS NULL
@@ -333,12 +338,13 @@ class DatabasePool:
OR packets.app_confidence IS NULL
OR packets.app_hostname IS NULL
OR packets.app_is_encrypted IS NULL
OR ($16::jsonb IS NOT NULL)
OR (COALESCE(array_length($17::text[], 1), 0) > 0)
OR ($17::jsonb IS NOT NULL)
OR (COALESCE(array_length($18::text[], 1), 0) > 0)
)
RETURNING *
""",
protocol,
eth_type_raw,
iface,
src_ip,
dst_ip,