Add configurable compliance portal commitment cards

The compliance portal home page rendered security-commitment cards from
a hardcoded placeholder POJO. Back them with real, per-organization data
that admins configure in the console and the portal loads over the trust
center GraphQL API.

Model two entities under the trust center: a commitment group (title,
description, rank) and a commitment card (icon, eyebrow, title,
description, rank). The card icon is a curated enum mapped to a Phosphor
icon in the portal. New entities adopt the compliance_portal_ prefix as
the start of the broader rename away from trust_center_ naming.

Expose the groups and cards read-only on the public trust API and with
full CRUD on the console API, add a Commitments tab to the compliance
page, and replace the placeholder section with a Relay-driven one.

Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
Émile Ré
2026-07-16 13:36:44 +02:00
parent 936162d5c7
commit 0b146a4054
39 changed files with 4079 additions and 175 deletions

View File

@@ -69,6 +69,20 @@ const (
ActionTrustCenterReferenceUpdate = "core:trust-center-reference:update"
ActionTrustCenterReferenceDelete = "core:trust-center-reference:delete"
// CompliancePortalCommitmentGroup actions
ActionCompliancePortalCommitmentGroupList = "core:compliance-portal-commitment-group:list"
ActionCompliancePortalCommitmentGroupCreate = "core:compliance-portal-commitment-group:create"
ActionCompliancePortalCommitmentGroupUpdate = "core:compliance-portal-commitment-group:update"
ActionCompliancePortalCommitmentGroupUpdateRank = "core:compliance-portal-commitment-group:update-rank"
ActionCompliancePortalCommitmentGroupDelete = "core:compliance-portal-commitment-group:delete"
// CompliancePortalCommitment actions
ActionCompliancePortalCommitmentList = "core:compliance-portal-commitment:list"
ActionCompliancePortalCommitmentCreate = "core:compliance-portal-commitment:create"
ActionCompliancePortalCommitmentUpdate = "core:compliance-portal-commitment:update"
ActionCompliancePortalCommitmentUpdateRank = "core:compliance-portal-commitment:update-rank"
ActionCompliancePortalCommitmentDelete = "core:compliance-portal-commitment:delete"
// ComplianceFramework actions
ActionComplianceFrameworkList = "core:compliance-framework:list"
ActionComplianceFrameworkCreate = "core:compliance-framework:create"

View File

@@ -0,0 +1,257 @@
// Copyright (c) 2026 Probo Inc <hello@probo.com>.
//
// Permission is hereby granted, free of charge, to any person obtaining a copy
// of this software and associated documentation files (the "Software"), to deal
// in the Software without restriction, including without limitation the rights
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
// copies of the Software, and to permit persons to whom the Software is
// furnished to do so, subject to the following conditions:
//
// The above copyright notice and this permission notice shall be included in
// all copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
// SOFTWARE.
package probo
import (
"context"
"fmt"
"time"
"go.gearno.de/kit/pg"
"go.probo.inc/probo/pkg/coredata"
"go.probo.inc/probo/pkg/gid"
"go.probo.inc/probo/pkg/page"
"go.probo.inc/probo/pkg/validator"
)
type (
CompliancePortalCommitmentGroupService struct {
svc *Service
}
CreateCompliancePortalCommitmentGroupRequest struct {
TrustCenterID gid.GID
Title string
Description string
}
UpdateCompliancePortalCommitmentGroupRequest struct {
ID gid.GID
Title *string
Description *string
Rank *int
}
)
func (r *CreateCompliancePortalCommitmentGroupRequest) Validate() error {
v := validator.New()
v.Check(r.TrustCenterID, "trust_center_id", validator.Required(), validator.GID(coredata.TrustCenterEntityType))
v.Check(r.Title, "title", validator.Required(), validator.SafeTextNoNewLine(TitleMaxLength))
v.Check(r.Description, "description", validator.SafeText(ContentMaxLength))
return v.Error()
}
func (r *UpdateCompliancePortalCommitmentGroupRequest) Validate() error {
v := validator.New()
v.Check(r.ID, "id", validator.Required(), validator.GID(coredata.CompliancePortalCommitmentGroupEntityType))
v.Check(r.Title, "title", validator.SafeTextNoNewLine(TitleMaxLength))
v.Check(r.Description, "description", validator.SafeText(ContentMaxLength))
return v.Error()
}
func (s CompliancePortalCommitmentGroupService) ListForTrustCenterID(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
cursor *page.Cursor[coredata.CompliancePortalCommitmentGroupOrderField],
) (*page.Page[*coredata.CompliancePortalCommitmentGroup, coredata.CompliancePortalCommitmentGroupOrderField], error) {
var groups coredata.CompliancePortalCommitmentGroups
err := s.svc.pg.WithConn(ctx, func(ctx context.Context, conn pg.Querier) error {
err := groups.LoadByTrustCenterID(ctx, conn, scope, trustCenterID, cursor)
if err != nil {
return fmt.Errorf("cannot load compliance portal commitment groups: %w", err)
}
return nil
})
if err != nil {
return nil, err
}
return page.NewPage(groups, cursor), nil
}
func (s CompliancePortalCommitmentGroupService) CountForTrustCenterID(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
) (int, error) {
var count int
err := s.svc.pg.WithConn(ctx, func(ctx context.Context, conn pg.Querier) (err error) {
groups := coredata.CompliancePortalCommitmentGroups{}
count, err = groups.CountByTrustCenterID(ctx, conn, scope, trustCenterID)
if err != nil {
return fmt.Errorf("cannot count compliance portal commitment groups: %w", err)
}
return nil
})
if err != nil {
return 0, err
}
return count, nil
}
func (s CompliancePortalCommitmentGroupService) Get(
ctx context.Context,
scope coredata.Scoper,
groupID gid.GID,
) (*coredata.CompliancePortalCommitmentGroup, error) {
var group coredata.CompliancePortalCommitmentGroup
err := s.svc.pg.WithConn(ctx, func(ctx context.Context, conn pg.Querier) error {
err := group.LoadByID(ctx, conn, scope, groupID)
if err != nil {
return fmt.Errorf("cannot load compliance portal commitment group: %w", err)
}
return nil
})
if err != nil {
return nil, err
}
return &group, nil
}
func (s CompliancePortalCommitmentGroupService) Create(
ctx context.Context,
scope coredata.Scoper,
req *CreateCompliancePortalCommitmentGroupRequest,
) (*coredata.CompliancePortalCommitmentGroup, error) {
if err := req.Validate(); err != nil {
return nil, err
}
now := time.Now()
groupID := gid.New(scope.GetTenantID(), coredata.CompliancePortalCommitmentGroupEntityType)
var group *coredata.CompliancePortalCommitmentGroup
err := s.svc.pg.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
}
group = &coredata.CompliancePortalCommitmentGroup{
ID: groupID,
OrganizationID: trustCenter.OrganizationID,
TrustCenterID: req.TrustCenterID,
Title: req.Title,
Description: req.Description,
CreatedAt: now,
UpdatedAt: now,
}
if err := group.Insert(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot insert compliance portal commitment group: %w", err)
}
return nil
})
if err != nil {
return nil, err
}
return group, nil
}
func (s CompliancePortalCommitmentGroupService) Update(
ctx context.Context,
scope coredata.Scoper,
req *UpdateCompliancePortalCommitmentGroupRequest,
) (*coredata.CompliancePortalCommitmentGroup, error) {
if err := req.Validate(); err != nil {
return nil, err
}
now := time.Now()
var group *coredata.CompliancePortalCommitmentGroup
err := s.svc.pg.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
group = &coredata.CompliancePortalCommitmentGroup{}
if err := group.LoadByID(ctx, tx, scope, req.ID); err != nil {
return fmt.Errorf("cannot load compliance portal commitment group: %w", err)
}
if req.Title != nil {
group.Title = *req.Title
}
if req.Description != nil {
group.Description = *req.Description
}
group.UpdatedAt = now
if req.Rank != nil {
group.Rank = *req.Rank
if err := group.UpdateRank(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update rank: %w", err)
}
}
if err := group.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update compliance portal commitment group: %w", err)
}
return nil
})
if err != nil {
return nil, err
}
return group, nil
}
func (s CompliancePortalCommitmentGroupService) Delete(
ctx context.Context,
scope coredata.Scoper,
groupID gid.GID,
) error {
err := s.svc.pg.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
group := &coredata.CompliancePortalCommitmentGroup{}
if err := group.LoadByID(ctx, tx, scope, groupID); err != nil {
return fmt.Errorf("cannot load compliance portal commitment group: %w", err)
}
if err := group.Delete(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot delete compliance portal commitment group: %w", err)
}
return nil
})
return err
}

View File

@@ -0,0 +1,278 @@
// Copyright (c) 2026 Probo Inc <hello@probo.com>.
//
// Permission is hereby granted, free of charge, to any person obtaining a copy
// of this software and associated documentation files (the "Software"), to deal
// in the Software without restriction, including without limitation the rights
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
// copies of the Software, and to permit persons to whom the Software is
// furnished to do so, subject to the following conditions:
//
// The above copyright notice and this permission notice shall be included in
// all copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
// SOFTWARE.
package probo
import (
"context"
"fmt"
"time"
"go.gearno.de/kit/pg"
"go.probo.inc/probo/pkg/coredata"
"go.probo.inc/probo/pkg/gid"
"go.probo.inc/probo/pkg/page"
"go.probo.inc/probo/pkg/validator"
)
type (
CompliancePortalCommitmentService struct {
svc *Service
}
CreateCompliancePortalCommitmentRequest struct {
GroupID gid.GID
Icon coredata.CompliancePortalCommitmentIcon
Eyebrow string
Title string
Description string
}
UpdateCompliancePortalCommitmentRequest struct {
ID gid.GID
Icon *coredata.CompliancePortalCommitmentIcon
Eyebrow *string
Title *string
Description *string
Rank *int
}
)
func (r *CreateCompliancePortalCommitmentRequest) Validate() error {
v := validator.New()
v.Check(r.GroupID, "group_id", validator.Required(), validator.GID(coredata.CompliancePortalCommitmentGroupEntityType))
v.Check(r.Icon, "icon", validator.Required(), validator.OneOfSlice(coredata.CompliancePortalCommitmentIcons()))
v.Check(r.Eyebrow, "eyebrow", validator.SafeTextNoNewLine(TitleMaxLength))
v.Check(r.Title, "title", validator.Required(), validator.SafeTextNoNewLine(TitleMaxLength))
v.Check(r.Description, "description", validator.SafeText(ContentMaxLength))
return v.Error()
}
func (r *UpdateCompliancePortalCommitmentRequest) Validate() error {
v := validator.New()
v.Check(r.ID, "id", validator.Required(), validator.GID(coredata.CompliancePortalCommitmentEntityType))
if r.Icon != nil {
v.Check(*r.Icon, "icon", validator.OneOfSlice(coredata.CompliancePortalCommitmentIcons()))
}
v.Check(r.Eyebrow, "eyebrow", validator.SafeTextNoNewLine(TitleMaxLength))
v.Check(r.Title, "title", validator.SafeTextNoNewLine(TitleMaxLength))
v.Check(r.Description, "description", validator.SafeText(ContentMaxLength))
return v.Error()
}
func (s CompliancePortalCommitmentService) ListForGroupID(
ctx context.Context,
scope coredata.Scoper,
groupID gid.GID,
cursor *page.Cursor[coredata.CompliancePortalCommitmentOrderField],
) (*page.Page[*coredata.CompliancePortalCommitment, coredata.CompliancePortalCommitmentOrderField], error) {
var commitments coredata.CompliancePortalCommitments
err := s.svc.pg.WithConn(ctx, func(ctx context.Context, conn pg.Querier) error {
err := commitments.LoadByGroupID(ctx, conn, scope, groupID, cursor)
if err != nil {
return fmt.Errorf("cannot load compliance portal commitments: %w", err)
}
return nil
})
if err != nil {
return nil, err
}
return page.NewPage(commitments, cursor), nil
}
func (s CompliancePortalCommitmentService) CountForGroupID(
ctx context.Context,
scope coredata.Scoper,
groupID gid.GID,
) (int, error) {
var count int
err := s.svc.pg.WithConn(ctx, func(ctx context.Context, conn pg.Querier) (err error) {
commitments := coredata.CompliancePortalCommitments{}
count, err = commitments.CountByGroupID(ctx, conn, scope, groupID)
if err != nil {
return fmt.Errorf("cannot count compliance portal commitments: %w", err)
}
return nil
})
if err != nil {
return 0, err
}
return count, nil
}
func (s CompliancePortalCommitmentService) Get(
ctx context.Context,
scope coredata.Scoper,
commitmentID gid.GID,
) (*coredata.CompliancePortalCommitment, error) {
var commitment coredata.CompliancePortalCommitment
err := s.svc.pg.WithConn(ctx, func(ctx context.Context, conn pg.Querier) error {
err := commitment.LoadByID(ctx, conn, scope, commitmentID)
if err != nil {
return fmt.Errorf("cannot load compliance portal commitment: %w", err)
}
return nil
})
if err != nil {
return nil, err
}
return &commitment, nil
}
func (s CompliancePortalCommitmentService) Create(
ctx context.Context,
scope coredata.Scoper,
req *CreateCompliancePortalCommitmentRequest,
) (*coredata.CompliancePortalCommitment, error) {
if err := req.Validate(); err != nil {
return nil, err
}
now := time.Now()
commitmentID := gid.New(scope.GetTenantID(), coredata.CompliancePortalCommitmentEntityType)
var commitment *coredata.CompliancePortalCommitment
err := s.svc.pg.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
group := &coredata.CompliancePortalCommitmentGroup{}
if err := group.LoadByID(ctx, tx, scope, req.GroupID); err != nil {
return fmt.Errorf("cannot load compliance portal commitment group: %w", err)
}
commitment = &coredata.CompliancePortalCommitment{
ID: commitmentID,
OrganizationID: group.OrganizationID,
TrustCenterID: group.TrustCenterID,
GroupID: req.GroupID,
Icon: req.Icon,
Eyebrow: req.Eyebrow,
Title: req.Title,
Description: req.Description,
CreatedAt: now,
UpdatedAt: now,
}
if err := commitment.Insert(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot insert compliance portal commitment: %w", err)
}
return nil
})
if err != nil {
return nil, err
}
return commitment, nil
}
func (s CompliancePortalCommitmentService) Update(
ctx context.Context,
scope coredata.Scoper,
req *UpdateCompliancePortalCommitmentRequest,
) (*coredata.CompliancePortalCommitment, error) {
if err := req.Validate(); err != nil {
return nil, err
}
now := time.Now()
var commitment *coredata.CompliancePortalCommitment
err := s.svc.pg.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
commitment = &coredata.CompliancePortalCommitment{}
if err := commitment.LoadByID(ctx, tx, scope, req.ID); err != nil {
return fmt.Errorf("cannot load compliance portal commitment: %w", err)
}
if req.Icon != nil {
commitment.Icon = *req.Icon
}
if req.Eyebrow != nil {
commitment.Eyebrow = *req.Eyebrow
}
if req.Title != nil {
commitment.Title = *req.Title
}
if req.Description != nil {
commitment.Description = *req.Description
}
commitment.UpdatedAt = now
if req.Rank != nil {
commitment.Rank = *req.Rank
if err := commitment.UpdateRank(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update rank: %w", err)
}
}
if err := commitment.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update compliance portal commitment: %w", err)
}
return nil
})
if err != nil {
return nil, err
}
return commitment, nil
}
func (s CompliancePortalCommitmentService) Delete(
ctx context.Context,
scope coredata.Scoper,
commitmentID gid.GID,
) error {
err := s.svc.pg.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
commitment := &coredata.CompliancePortalCommitment{}
if err := commitment.LoadByID(ctx, tx, scope, commitmentID); err != nil {
return fmt.Errorf("cannot load compliance portal commitment: %w", err)
}
if err := commitment.Delete(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot delete compliance portal commitment: %w", err)
}
return nil
})
return err
}

View File

@@ -108,6 +108,7 @@ var ViewerPolicy = policy.NewPolicy(
ActionTrustCenterDocumentAccessList,
ActionTrustCenterFileGet, ActionTrustCenterFileList, ActionTrustCenterFileGetFileUrl,
ActionTrustCenterReferenceList, ActionTrustCenterReferenceGetLogoUrl,
ActionCompliancePortalCommitmentGroupList, ActionCompliancePortalCommitmentList,
ActionComplianceFrameworkList,
).WithSID("trust-center-read-access").When(organizationCondition),

View File

@@ -113,6 +113,8 @@ type (
TrustCenters *TrustCenterService
TrustCenterAccesses *TrustCenterAccessService
TrustCenterReferences *TrustCenterReferenceService
CompliancePortalCommitmentGroups *CompliancePortalCommitmentGroupService
CompliancePortalCommitments *CompliancePortalCommitmentService
TrustCenterFiles *TrustCenterFileService
ComplianceFrameworks *ComplianceFrameworkService
ComplianceExternalURLs *ComplianceExternalURLService
@@ -235,6 +237,8 @@ func NewService(
svc.TrustCenters = &TrustCenterService{svc: svc}
svc.TrustCenterAccesses = &TrustCenterAccessService{svc: svc}
svc.TrustCenterReferences = &TrustCenterReferenceService{svc: svc}
svc.CompliancePortalCommitmentGroups = &CompliancePortalCommitmentGroupService{svc: svc}
svc.CompliancePortalCommitments = &CompliancePortalCommitmentService{svc: svc}
svc.ComplianceFrameworks = &ComplianceFrameworkService{svc: svc}
svc.ComplianceExternalURLs = &ComplianceExternalURLService{svc: svc}
svc.TrustCenterFiles = &TrustCenterFileService{