diff --git a/backend/src/api/nftables_api.py b/backend/src/api/nftables_api.py index 5bf93a0..ae3f0e3 100644 --- a/backend/src/api/nftables_api.py +++ b/backend/src/api/nftables_api.py @@ -317,7 +317,21 @@ def delete_rules_by_ids(ids: List[str], family: str, table: str, chain: str) -> # ---------------------- API endpoints ---------------------- @router.get("/rules") -def get_rules(family: Optional[str] = DEFAULT_FAMILY, table: Optional[str] = DEFAULT_TABLE): +def get_rules(family: Optional[str] = DEFAULT_FAMILY, table: Optional[str] = DEFAULT_TABLE, chain: Optional[str] = DEFAULT_CHAIN): + """ + Ensure the table/chain exist (try to create them if missing), then return + the rules from nftables. If ensure_table_chain fails we return 500 with a clear message. + """ + logger.debug("GET /nft/rules called (family=%s table=%s chain=%s)", family, table, chain) + try: + # Ensure required table/chain exist before listing rules + ensure_table_chain(family, table, chain) + except RuntimeError as e: + logger.error("failed to create/ensure nft table/chain %s.%s/%s: %s", family, table, chain, e) + # return an HTTP 500 so the frontend knows setup failed + raise HTTPException(status_code=500, detail=f"failed to ensure nft table/chain: {e}") + + # now safe to list rules rules = list_rules_from_nft(family, table) return {"count": len(rules), "rules": rules, "version": _current_version}