Sitelet https://github.com/Shuffle/python-apps/issues/401
Skip to content

Missing org_id Parameter in Velociraptor App #401

Description

@Afaf-dev

By testing the app with the latest versions of Velociraptor, I found that the org_id parameter is missing and the queries doesn't work to other organisations because by default the API connection will be to the root org of Velociraptor.

This parameter should be added here
https://github.com/Shuffle/python-apps/blob/master/velociraptor/1.0.0/src/app.py#L43C11-L48C16

As referenced in the official Velociraptor repository, the org_id parameter is expected:
https://github.com/Velocidex/pyvelociraptor/blob/master/pyvelociraptor%2Fclient_example.py#L71

Additionally, org_id should be available as a parameter in the Shuffle UI to specify when running a given query.

Would it be possible to add this enhancement? maybe on an other version of the app..

Thanks!

Activity

  1. frikky commented on Feb 10, 2025

    @frikky
    Member

    By testing the app with the latest versions of Velociraptor, I found that the org_id parameter is missing and the queries doesn't work to other organisations because by default the API connection will be to the root org of Velociraptor.

    This parameter should be added here https://github.com/Shuffle/python-apps/blob/master/velociraptor/1.0.0/src/app.py#L43C11-L48C16

    As referenced in the official Velociraptor repository, the org_id parameter is expected: https://github.com/Velocidex/pyvelociraptor/blob/master/pyvelociraptor%2Fclient_example.py#L71

    Additionally, org_id should be available as a parameter in the Shuffle UI to specify when running a given query.

    Would it be possible to add this enhancement? maybe on an other version of the app..

    Thanks!

    Hey!

    Would you be able to send a PR for it? We don't have a test environment, so it could be tricky. You would need two things:

    1. Update the app.yaml file so that it shows up in the Shuffle UI
    2. Add the "org_id" parameter to the relevant functions in the src/app.py file

    Otherwise I'd be happy to jump on a call and fix it with you in realtime :)

  2. chiefghost47 commented on Oct 9, 2026

    @chiefghost47
    Contributor

    Hi @frikky, we hit this on a multi-org Velociraptor setup and opened #457 with the change you
    described here: an optional org_id in api.yaml on all 14 actions, passed through src/app.py to
    VQLCollectorArgs.

    We had the test environment for it, so it was tested against Velociraptor 0.77.3:

    • with an API user holding roles in one org only, calls with that org's org_id work;
    • calls to other orgs, or to root, are refused;
    • an empty org_id builds a byte-identical request to today's, so existing workflows are unaffected.

    Details are in the PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions