/*
* Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.
*/
import { SDKCore } from "../core.js";
import { encodeFormQuery, encodeJSON } from "../lib/encodings.js";
import { matchStatusCode } from "../lib/http.js";
import * as M from "../lib/matchers.js";
import { compactMap } from "../lib/primitives.js";
import { safeParse } from "../lib/schemas.js";
import { RequestOptions } from "../lib/sdks.js";
import { extractSecurity, resolveGlobalSecurity } from "../lib/security.js";
import { pathToFunc } from "../lib/url.js";
import {
ConnectionError,
InvalidRequestError,
RequestAbortedError,
RequestTimeoutError,
UnexpectedClientError,
} from "../models/errors/httpclienterrors.js";
import * as errors from "../models/errors/index.js";
import { ResponseValidationError } from "../models/errors/responsevalidationerror.js";
import { SDKBaseError } from "../models/errors/sdkbaseerror.js";
import { SDKValidationError } from "../models/errors/sdkvalidationerror.js";
import * as operations from "../models/operations/index.js";
import { APICall, APIPromise } from "../types/async.js";
import { Result } from "../types/fp.js";
/**
* CensEye: Retrieve value counts to discover pivots
*
* @remarks
* Get counts of web assets for specific field-value pairs and combinations of field-value pairs. This is similar to the [CensEye functionality](https://docs.censys.com/docs/platform-threat-hunting-use-censeye-to-build-detections#/) available in the Platform web UI, but it allows you to define specific fields of interest rather than the [default fields](https://docs.censys.com/docs/platform-threat-hunting-use-censeye-to-build-detections#default-pivot-fields) leveraged by the tool in the UI.
Each array can only target fields within the same nested object and may contain at most 5 field-value pairs. For example, you can combine `host.services.port=80` and `host.services.protocol=SSH` in the same array, but you cannot combine `host.services.port=80` and `host.location.country="United States"` in the same array. You can input multiple arrays of objects in each API call.
To use this endpoint, your organization must have access to the Adversary Investigation module. This endpoint costs 1 credit per count condition (array of objects) included in the API call.
*/
export function threatHuntingValueCounts(
client: SDKCore,
request: operations.V3ThreathuntingValueCountsRequest,
options?: RequestOptions,
): APIPromise<
Result<
operations.V3ThreathuntingValueCountsResponse,
| errors.AuthenticationError
| errors.ErrorModel
| SDKBaseError
| ResponseValidationError
| ConnectionError
| RequestAbortedError
| RequestTimeoutError
| InvalidRequestError
| UnexpectedClientError
| SDKValidationError
>
> {
return new APIPromise($do(
client,
request,
options,
));
}
async function $do(
client: SDKCore,
request: operations.V3ThreathuntingValueCountsRequest,
options?: RequestOptions,
): Promise<
[
Result<
operations.V3ThreathuntingValueCountsResponse,
| errors.AuthenticationError
| errors.ErrorModel
| SDKBaseError
| ResponseValidationError
| ConnectionError
| RequestAbortedError
| RequestTimeoutError
| InvalidRequestError
| UnexpectedClientError
| SDKValidationError
>,
APICall,
]
> {
const parsed = safeParse(
request,
(value) =>
operations.V3ThreathuntingValueCountsRequest$outboundSchema.parse(value),
"Input validation failed",
);
if (!parsed.ok) {
return [parsed, { status: "invalid" }];
}
const payload = parsed.value;
const body = encodeJSON("body", payload.SearchValueCountsInputBody, {
explode: true,
});
const path = pathToFunc("/v3/threat-hunting/value-counts")();
const query = encodeFormQuery({
"organization_id": payload.organization_id
?? client._options.organizationId,
}, { explode: false });
const headers = new Headers(compactMap({
"Content-Type": "application/json",
Accept: "application/json",
}));
const secConfig = await extractSecurity(client._options.personalAccessToken);
const securityInput = secConfig == null
? {}
: { personalAccessToken: secConfig };
const requestSecurity = resolveGlobalSecurity(securityInput);
const context = {
options: client._options,
baseURL: options?.serverURL ?? client._baseURL ?? "",
operationID: "v3-threathunting-value-counts",
oAuth2Scopes: null,
resolvedSecurity: requestSecurity,
securitySource: client._options.personalAccessToken,
retryConfig: options?.retries
|| client._options.retryConfig
|| { strategy: "none" },
retryCodes: options?.retryCodes || ["429", "500", "502", "503", "504"],
};
const requestRes = client._createRequest(context, {
security: requestSecurity,
method: "POST",
baseURL: options?.serverURL,
path: path,
headers: headers,
query: query,
body: body,
userAgent: client._options.userAgent,
timeoutMs: options?.timeoutMs || client._options.timeoutMs || -1,
}, options);
if (!requestRes.ok) {
return [requestRes, { status: "invalid" }];
}
const req = requestRes.value;
const doResult = await client._do(req, {
context,
isErrorStatusCode: (statusCode: number) =>
matchStatusCode({ status: statusCode } as Response, ["4XX", "5XX"]),
retryConfig: context.retryConfig,
retryCodes: context.retryCodes,
});
if (!doResult.ok) {
return [doResult, { status: "request-error", request: req }];
}
const response = doResult.value;
const responseFields = {
HttpMeta: { Response: response, Request: req },
};
const [result] = await M.match<
operations.V3ThreathuntingValueCountsResponse,
| errors.AuthenticationError
| errors.ErrorModel
| SDKBaseError
| ResponseValidationError
| ConnectionError
| RequestAbortedError
| RequestTimeoutError
| InvalidRequestError
| UnexpectedClientError
| SDKValidationError
>(
M.json(200, operations.V3ThreathuntingValueCountsResponse$inboundSchema, {
hdrs: true,
key: "Result",
}),
M.jsonErr(401, errors.AuthenticationError$inboundSchema),
M.jsonErr([400, 403, 422], errors.ErrorModel$inboundSchema, {
ctype: "application/problem+json",
}),
M.jsonErr(500, errors.ErrorModel$inboundSchema, {
ctype: "application/problem+json",
}),
M.fail("4XX"),
M.fail("5XX"),
)(response, req, { extraFields: responseFields });
if (!result.ok) {
return [result, { status: "complete", request: req, response }];
}
return [result, { status: "complete", request: req, response }];
}