/*
* Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.
*/
import { SDKCore } from "../core.js";
import { encodeFormQuery, encodeSimple } from "../lib/encodings.js";
import { matchStatusCode } from "../lib/http.js";
import * as M from "../lib/matchers.js";
import { compactMap } from "../lib/primitives.js";
import { safeParse } from "../lib/schemas.js";
import { RequestOptions } from "../lib/sdks.js";
import { extractSecurity, resolveGlobalSecurity } from "../lib/security.js";
import { pathToFunc } from "../lib/url.js";
import {
ConnectionError,
InvalidRequestError,
RequestAbortedError,
RequestTimeoutError,
UnexpectedClientError,
} from "../models/errors/httpclienterrors.js";
import * as errors from "../models/errors/index.js";
import { ResponseValidationError } from "../models/errors/responsevalidationerror.js";
import { SDKBaseError } from "../models/errors/sdkbaseerror.js";
import { SDKValidationError } from "../models/errors/sdkvalidationerror.js";
import * as operations from "../models/operations/index.js";
import { APICall, APIPromise } from "../types/async.js";
import { Result } from "../types/fp.js";
/**
* Get host history for a certificate
*
* @remarks
* Retrieve the historical observations of hosts associated with a certificate. This is useful for threat hunting, detection engineering, and timeline generation. Certificate history is also visible to Adversary Investigation users in the Platform UI on the [certificate timeline](https://docs.censys.com/docs/platform-threat-hunting-use-cert-history-to-build-better-detections#/).
You can define a specific time frame of interest. If you do not specify a time frame, this endpoint will search the historical dataset that is available to your account. You may also filter results by port and transport protocol.
This endpoint is available to organizations that have access to the Adversary Investigation module. It costs 5 credits per page of results.
*/
export function threatHuntingGetHostObservationsWithCertificate(
client: SDKCore,
request: operations.V3ThreathuntingGetHostObservationsWithCertificateRequest,
options?: RequestOptions,
): APIPromise<
Result<
operations.V3ThreathuntingGetHostObservationsWithCertificateResponse,
| errors.AuthenticationError
| errors.ErrorModel
| SDKBaseError
| ResponseValidationError
| ConnectionError
| RequestAbortedError
| RequestTimeoutError
| InvalidRequestError
| UnexpectedClientError
| SDKValidationError
>
> {
return new APIPromise($do(
client,
request,
options,
));
}
async function $do(
client: SDKCore,
request: operations.V3ThreathuntingGetHostObservationsWithCertificateRequest,
options?: RequestOptions,
): Promise<
[
Result<
operations.V3ThreathuntingGetHostObservationsWithCertificateResponse,
| errors.AuthenticationError
| errors.ErrorModel
| SDKBaseError
| ResponseValidationError
| ConnectionError
| RequestAbortedError
| RequestTimeoutError
| InvalidRequestError
| UnexpectedClientError
| SDKValidationError
>,
APICall,
]
> {
const parsed = safeParse(
request,
(value) =>
operations
.V3ThreathuntingGetHostObservationsWithCertificateRequest$outboundSchema
.parse(value),
"Input validation failed",
);
if (!parsed.ok) {
return [parsed, { status: "invalid" }];
}
const payload = parsed.value;
const body = null;
const pathParams = {
certificate_id: encodeSimple("certificate_id", payload.certificate_id, {
explode: false,
charEncoding: "percent",
}),
};
const path = pathToFunc(
"/v3/threat-hunting/certificate/{certificate_id}/observations/hosts",
)(pathParams);
const query = encodeFormQuery({
"end_time": payload.end_time,
"organization_id": payload.organization_id
?? client._options.organizationId,
"page_size": payload.page_size,
"page_token": payload.page_token,
"port": payload.port,
"protocol": payload.protocol,
"start_time": payload.start_time,
}, { explode: false });
const headers = new Headers(compactMap({
Accept: "application/json",
}));
const secConfig = await extractSecurity(client._options.personalAccessToken);
const securityInput = secConfig == null
? {}
: { personalAccessToken: secConfig };
const requestSecurity = resolveGlobalSecurity(securityInput);
const context = {
options: client._options,
baseURL: options?.serverURL ?? client._baseURL ?? "",
operationID: "v3-threathunting-get-host-observations-with-certificate",
oAuth2Scopes: null,
resolvedSecurity: requestSecurity,
securitySource: client._options.personalAccessToken,
retryConfig: options?.retries
|| client._options.retryConfig
|| { strategy: "none" },
retryCodes: options?.retryCodes || ["429", "500", "502", "503", "504"],
};
const requestRes = client._createRequest(context, {
security: requestSecurity,
method: "GET",
baseURL: options?.serverURL,
path: path,
headers: headers,
query: query,
body: body,
userAgent: client._options.userAgent,
timeoutMs: options?.timeoutMs || client._options.timeoutMs || -1,
}, options);
if (!requestRes.ok) {
return [requestRes, { status: "invalid" }];
}
const req = requestRes.value;
const doResult = await client._do(req, {
context,
isErrorStatusCode: (statusCode: number) =>
matchStatusCode({ status: statusCode } as Response, ["4XX", "5XX"]),
retryConfig: context.retryConfig,
retryCodes: context.retryCodes,
});
if (!doResult.ok) {
return [doResult, { status: "request-error", request: req }];
}
const response = doResult.value;
const responseFields = {
HttpMeta: { Response: response, Request: req },
};
const [result] = await M.match<
operations.V3ThreathuntingGetHostObservationsWithCertificateResponse,
| errors.AuthenticationError
| errors.ErrorModel
| SDKBaseError
| ResponseValidationError
| ConnectionError
| RequestAbortedError
| RequestTimeoutError
| InvalidRequestError
| UnexpectedClientError
| SDKValidationError
>(
M.json(
200,
operations
.V3ThreathuntingGetHostObservationsWithCertificateResponse$inboundSchema,
{ hdrs: true, key: "Result" },
),
M.jsonErr(401, errors.AuthenticationError$inboundSchema),
M.jsonErr([400, 403, 404], errors.ErrorModel$inboundSchema, {
ctype: "application/problem+json",
}),
M.jsonErr(500, errors.ErrorModel$inboundSchema, {
ctype: "application/problem+json",
}),
M.fail("4XX"),
M.fail("5XX"),
)(response, req, { extraFields: responseFields });
if (!result.ok) {
return [result, { status: "complete", request: req, response }];
}
return [result, { status: "complete", request: req, response }];
}