#!/bin/bash
# Copyright Security Onion Solutions LLC and/or licensed to Security Onion Solutions LLC under one
# or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
# https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0.

. /usr/sbin/so-elastic-fleet-common

# Get all the fleet policies
if ! json_output=$(fleet_api "agent_policies" -H 'kbn-xsrf: true'); then
    echo "Error: Failed to retrieve Fleet agent policies." >&2
    exit 1
fi

if ! jq -e '.items' <<<"$json_output" >/dev/null 2>&1; then
    echo "Error: Invalid Fleet agent policies response." >&2
    exit 1
fi

# Extract the IDs that start with "FleetServer_"
POLICY=$(jq -r '.items[] | select(.id | startswith("FleetServer_")) | .id' <<<"$json_output")

# Iterate over each ID in the POLICY variable
for POLICYNAME in $POLICY; do
    printf "\nUpdating Policy: $POLICYNAME\n"

    if ! POLICY_JSON=$(elastic_fleet_require_agent_policy "$POLICYNAME"); then
        exit 1
    fi

    INTEGRATION_ID=$(jq -r '.item.package_policies[]? | select(.package.name == "fleet_server") | .id' <<<"$POLICY_JSON")
    if [ -z "$INTEGRATION_ID" ]; then
        echo "Error: fleet_server integration was not found in agent policy '$POLICYNAME'." >&2
        exit 1
    fi

    # Modify the default integration policy to update the policy_id and an with the correct naming
    UPDATED_INTEGRATION_POLICY=$(jq --arg policy_id "$POLICYNAME" --arg name "fleet_server-$POLICYNAME" '
    .policy_id = $policy_id |
    .name = $name' /opt/so/conf/elastic-fleet/integrations/fleet-server/fleet-server.json)

    # Now update the integration policy using the modified JSON
    if ! elastic_fleet_integration_update "$INTEGRATION_ID" "$UPDATED_INTEGRATION_POLICY"; then
        # exit 1 on failure to update fleet integration policies, let salt handle retries
        echo "Failed to update $POLICYNAME.."
        exit 1
    fi
done