Add trust center configuration

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
Sacha Al Himdani
2025-07-24 21:11:46 +02:00
parent e85a7b4955
commit 32c47a1988
49 changed files with 4755 additions and 126 deletions

View File

@@ -28,15 +28,16 @@ import (
type (
Audit struct {
ID gid.GID `db:"id"`
OrganizationID gid.GID `db:"organization_id"`
FrameworkID gid.GID `db:"framework_id"`
ReportID *gid.GID `db:"report_id"`
ValidFrom *time.Time `db:"valid_from"`
ValidUntil *time.Time `db:"valid_until"`
State AuditState `db:"state"`
CreatedAt time.Time `db:"created_at"`
UpdatedAt time.Time `db:"updated_at"`
ID gid.GID `db:"id"`
OrganizationID gid.GID `db:"organization_id"`
FrameworkID gid.GID `db:"framework_id"`
ReportID *gid.GID `db:"report_id"`
ValidFrom *time.Time `db:"valid_from"`
ValidUntil *time.Time `db:"valid_until"`
State AuditState `db:"state"`
ShowOnTrustCenter bool `db:"show_on_trust_center"`
CreatedAt time.Time `db:"created_at"`
UpdatedAt time.Time `db:"updated_at"`
}
Audits []*Audit
@@ -72,6 +73,7 @@ SELECT
valid_from,
valid_until,
state,
show_on_trust_center,
created_at,
updated_at
FROM
@@ -150,6 +152,7 @@ SELECT
valid_from,
valid_until,
state,
show_on_trust_center,
created_at,
updated_at
FROM
@@ -196,6 +199,7 @@ INSERT INTO audits (
valid_from,
valid_until,
state,
show_on_trust_center,
created_at,
updated_at
) VALUES (
@@ -207,22 +211,24 @@ INSERT INTO audits (
@valid_from,
@valid_until,
@state,
@show_on_trust_center,
@created_at,
@updated_at
)
`
args := pgx.StrictNamedArgs{
"id": a.ID,
"tenant_id": scope.GetTenantID(),
"organization_id": a.OrganizationID,
"framework_id": a.FrameworkID,
"report_id": a.ReportID,
"valid_from": a.ValidFrom,
"valid_until": a.ValidUntil,
"state": a.State,
"created_at": a.CreatedAt,
"updated_at": a.UpdatedAt,
"id": a.ID,
"tenant_id": scope.GetTenantID(),
"organization_id": a.OrganizationID,
"framework_id": a.FrameworkID,
"report_id": a.ReportID,
"valid_from": a.ValidFrom,
"valid_until": a.ValidUntil,
"state": a.State,
"show_on_trust_center": a.ShowOnTrustCenter,
"created_at": a.CreatedAt,
"updated_at": a.UpdatedAt,
}
_, err := conn.Exec(ctx, q, args)
@@ -245,6 +251,7 @@ SET
valid_from = @valid_from,
valid_until = @valid_until,
state = @state,
show_on_trust_center = @show_on_trust_center,
updated_at = @updated_at
WHERE
%s
@@ -254,12 +261,13 @@ WHERE
q = fmt.Sprintf(q, scope.SQLFragment())
args := pgx.StrictNamedArgs{
"id": a.ID,
"report_id": a.ReportID,
"valid_from": a.ValidFrom,
"valid_until": a.ValidUntil,
"state": a.State,
"updated_at": a.UpdatedAt,
"id": a.ID,
"report_id": a.ReportID,
"valid_from": a.ValidFrom,
"valid_until": a.ValidUntil,
"state": a.State,
"show_on_trust_center": a.ShowOnTrustCenter,
"updated_at": a.UpdatedAt,
}
maps.Copy(args, scope.SQLArguments())

View File

@@ -34,6 +34,7 @@ type (
Title string `db:"title"`
DocumentType DocumentType `db:"document_type"`
CurrentPublishedVersion *int `db:"current_published_version"`
ShowOnTrustCenter bool `db:"show_on_trust_center"`
CreatedAt time.Time `db:"created_at"`
UpdatedAt time.Time `db:"updated_at"`
}
@@ -68,6 +69,7 @@ SELECT
title,
document_type,
current_published_version,
show_on_trust_center,
created_at,
updated_at
FROM
@@ -147,6 +149,7 @@ SELECT
title,
document_type,
current_published_version,
show_on_trust_center,
created_at,
updated_at
FROM
@@ -195,6 +198,7 @@ INSERT INTO
title,
document_type,
current_published_version,
show_on_trust_center,
created_at,
updated_at
)
@@ -206,6 +210,7 @@ VALUES (
@title,
@document_type,
@current_published_version,
@show_on_trust_center,
@created_at,
@updated_at
);
@@ -219,6 +224,7 @@ VALUES (
"title": p.Title,
"document_type": p.DocumentType,
"current_published_version": p.CurrentPublishedVersion,
"show_on_trust_center": p.ShowOnTrustCenter,
"created_at": p.CreatedAt,
"updated_at": p.UpdatedAt,
}
@@ -257,6 +263,7 @@ SET
current_published_version = @current_published_version,
owner_id = @owner_id,
document_type = @document_type,
show_on_trust_center = @show_on_trust_center,
updated_at = @updated_at
WHERE %s
AND id = @document_id
@@ -270,6 +277,7 @@ WHERE %s
"current_published_version": p.CurrentPublishedVersion,
"owner_id": p.OwnerID,
"document_type": p.DocumentType,
"show_on_trust_center": p.ShowOnTrustCenter,
}
maps.Copy(args, scope.SQLArguments())
@@ -342,6 +350,7 @@ WITH plcs AS (
p.title,
p.document_type,
p.current_published_version,
p.show_on_trust_center,
p.created_at,
p.updated_at
FROM
@@ -358,6 +367,7 @@ SELECT
title,
document_type,
current_published_version,
show_on_trust_center,
created_at,
updated_at
FROM
@@ -448,6 +458,7 @@ WITH plcs AS (
p.title,
p.document_type,
p.current_published_version,
p.show_on_trust_center,
p.created_at,
p.updated_at
FROM
@@ -464,6 +475,7 @@ SELECT
title,
document_type,
current_published_version,
show_on_trust_center,
created_at,
updated_at
FROM

View File

@@ -37,4 +37,5 @@ const (
DatumEntityType
AuditEntityType
ReportEntityType
TrustCenterEntityType
)

View File

@@ -0,0 +1,51 @@
CREATE EXTENSION IF NOT EXISTS unaccent;
CREATE TABLE trust_centers (
id TEXT PRIMARY KEY,
organization_id TEXT NOT NULL REFERENCES organizations(id) ON DELETE CASCADE,
tenant_id TEXT NOT NULL,
active BOOLEAN NOT NULL,
slug TEXT NOT NULL CHECK (slug ~ '^[a-z0-9_-]+$'),
created_at TIMESTAMP WITH TIME ZONE NOT NULL,
updated_at TIMESTAMP WITH TIME ZONE NOT NULL,
UNIQUE(slug)
);
INSERT INTO trust_centers (
id,
organization_id,
tenant_id,
active,
slug,
created_at,
updated_at
)
SELECT
generate_gid(decode_base64_unpadded(o.tenant_id), 22),
o.id,
o.tenant_id,
false,
LOWER(
REGEXP_REPLACE(
REGEXP_REPLACE(
unaccent(o.name),
'[^a-zA-Z0-9\s]', '', 'g'
),
'\s+', '-', 'g'
)
),
NOW(),
NOW()
FROM organizations o;
ALTER TABLE documents ADD COLUMN show_on_trust_center BOOLEAN NOT NULL DEFAULT false;
ALTER TABLE audits ADD COLUMN show_on_trust_center BOOLEAN NOT NULL DEFAULT false;
ALTER TABLE vendors ADD COLUMN show_on_trust_center BOOLEAN NOT NULL DEFAULT false;
ALTER TABLE documents ALTER COLUMN show_on_trust_center DROP DEFAULT;
ALTER TABLE audits ALTER COLUMN show_on_trust_center DROP DEFAULT;
ALTER TABLE vendors ALTER COLUMN show_on_trust_center DROP DEFAULT;

View File

@@ -0,0 +1,213 @@
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package coredata
import (
"context"
"fmt"
"maps"
"time"
"github.com/getprobo/probo/pkg/gid"
"github.com/getprobo/probo/pkg/page"
"github.com/jackc/pgx/v5"
"go.gearno.de/kit/pg"
)
type (
TrustCenter struct {
ID gid.GID `db:"id"`
OrganizationID gid.GID `db:"organization_id"`
TenantID gid.TenantID `db:"tenant_id"`
Active bool `db:"active"`
Slug string `db:"slug"`
CreatedAt time.Time `db:"created_at"`
UpdatedAt time.Time `db:"updated_at"`
}
TrustCenters []*TrustCenter
)
func (tc *TrustCenter) CursorKey(orderBy TrustCenterOrderField) page.CursorKey {
switch orderBy {
case TrustCenterOrderFieldCreatedAt:
return page.NewCursorKey(tc.ID, tc.CreatedAt)
}
panic(fmt.Sprintf("unsupported order by: %s", orderBy))
}
func (tc *TrustCenter) LoadByID(
ctx context.Context,
conn pg.Conn,
scope Scoper,
trustCenterID gid.GID,
) error {
q := `
SELECT
id,
organization_id,
tenant_id,
active,
slug,
created_at,
updated_at
FROM
trust_centers
WHERE
%s
AND id = @trust_center_id
LIMIT 1;
`
q = fmt.Sprintf(q, scope.SQLFragment())
args := pgx.StrictNamedArgs{"trust_center_id": trustCenterID}
maps.Copy(args, scope.SQLArguments())
rows, err := conn.Query(ctx, q, args)
if err != nil {
return fmt.Errorf("cannot query trust center: %w", err)
}
trustCenter, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[TrustCenter])
if err != nil {
return fmt.Errorf("cannot collect trust center: %w", err)
}
*tc = trustCenter
return nil
}
func (tc *TrustCenter) LoadByOrganizationID(
ctx context.Context,
conn pg.Conn,
scope Scoper,
organizationID gid.GID,
) error {
q := `
SELECT
id,
organization_id,
tenant_id,
active,
slug,
created_at,
updated_at
FROM
trust_centers
WHERE
%s
AND organization_id = @organization_id
LIMIT 1;
`
q = fmt.Sprintf(q, scope.SQLFragment())
args := pgx.StrictNamedArgs{"organization_id": organizationID}
maps.Copy(args, scope.SQLArguments())
rows, err := conn.Query(ctx, q, args)
if err != nil {
return fmt.Errorf("cannot query trust center: %w", err)
}
trustCenter, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[TrustCenter])
if err != nil {
return fmt.Errorf("cannot collect trust center: %w", err)
}
*tc = trustCenter
return nil
}
func (tc *TrustCenter) Insert(
ctx context.Context,
conn pg.Conn,
scope Scoper,
) error {
q := `
INSERT INTO trust_centers (
id,
organization_id,
tenant_id,
active,
slug,
created_at,
updated_at
) VALUES (
@id,
@organization_id,
@tenant_id,
@active,
@slug,
@created_at,
@updated_at
)
`
args := pgx.StrictNamedArgs{
"id": tc.ID,
"organization_id": tc.OrganizationID,
"tenant_id": tc.TenantID,
"active": tc.Active,
"slug": tc.Slug,
"created_at": tc.CreatedAt,
"updated_at": tc.UpdatedAt,
}
_, err := conn.Exec(ctx, q, args)
if err != nil {
return fmt.Errorf("cannot insert trust center: %w", err)
}
return nil
}
func (tc *TrustCenter) Update(
ctx context.Context,
conn pg.Conn,
scope Scoper,
) error {
q := `
UPDATE trust_centers
SET
active = @active,
slug = @slug,
updated_at = @updated_at
WHERE
%s
AND id = @id
`
q = fmt.Sprintf(q, scope.SQLFragment())
args := pgx.StrictNamedArgs{
"id": tc.ID,
"active": tc.Active,
"slug": tc.Slug,
"updated_at": tc.UpdatedAt,
}
maps.Copy(args, scope.SQLArguments())
_, err := conn.Exec(ctx, q, args)
if err != nil {
return fmt.Errorf("cannot update trust center: %w", err)
}
return nil
}

View File

@@ -0,0 +1,38 @@
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package coredata
type TrustCenterOrderField string
const (
TrustCenterOrderFieldCreatedAt TrustCenterOrderField = "CREATED_AT"
)
func (p TrustCenterOrderField) Column() string {
return string(p)
}
func (p TrustCenterOrderField) String() string {
return string(p)
}
func (p TrustCenterOrderField) MarshalText() ([]byte, error) {
return []byte(p.String()), nil
}
func (p *TrustCenterOrderField) UnmarshalText(text []byte) error {
*p = TrustCenterOrderField(text)
return nil
}

View File

@@ -49,6 +49,7 @@ type (
TermsOfServiceURL *string `db:"terms_of_service_url"`
SecurityPageURL *string `db:"security_page_url"`
TrustPageURL *string `db:"trust_page_url"`
ShowOnTrustCenter bool `db:"show_on_trust_center"`
CreatedAt time.Time `db:"created_at"`
UpdatedAt time.Time `db:"updated_at"`
}
@@ -98,6 +99,7 @@ SELECT
terms_of_service_url,
security_page_url,
trust_page_url,
show_on_trust_center,
created_at,
updated_at
FROM
@@ -158,6 +160,7 @@ INSERT INTO
terms_of_service_url,
security_page_url,
trust_page_url,
show_on_trust_center,
created_at,
updated_at
)
@@ -183,6 +186,7 @@ VALUES (
@terms_of_service_url,
@security_page_url,
@trust_page_url,
@show_on_trust_center,
@created_at,
@updated_at
)
@@ -210,6 +214,7 @@ VALUES (
"terms_of_service_url": v.TermsOfServiceURL,
"security_page_url": v.SecurityPageURL,
"trust_page_url": v.TrustPageURL,
"show_on_trust_center": v.ShowOnTrustCenter,
"created_at": v.CreatedAt,
"updated_at": v.UpdatedAt,
}
@@ -297,6 +302,7 @@ SELECT
terms_of_service_url,
security_page_url,
trust_page_url,
show_on_trust_center,
created_at,
updated_at
FROM
@@ -353,6 +359,7 @@ SET
trust_page_url = @trust_page_url,
business_owner_id = @business_owner_id,
security_owner_id = @security_owner_id,
show_on_trust_center = @show_on_trust_center,
updated_at = @updated_at
WHERE %s
AND id = @vendor_id
@@ -380,6 +387,7 @@ WHERE %s
"trust_page_url": v.TrustPageURL,
"business_owner_id": v.BusinessOwnerID,
"security_owner_id": v.SecurityOwnerID,
"show_on_trust_center": v.ShowOnTrustCenter,
}
maps.Copy(args, scope.SQLArguments())

View File

@@ -39,10 +39,11 @@ type (
}
UpdateAuditRequest struct {
ID gid.GID
ValidFrom *time.Time
ValidUntil *time.Time
State *coredata.AuditState
ID gid.GID
ValidFrom *time.Time
ValidUntil *time.Time
State *coredata.AuditState
ShowOnTrustCenter *bool
}
UpdateAuditStateRequest struct {
@@ -87,14 +88,15 @@ func (s *AuditService) Create(
now := time.Now()
audit := &coredata.Audit{
ID: gid.New(s.svc.scope.GetTenantID(), coredata.AuditEntityType),
OrganizationID: req.OrganizationID,
FrameworkID: req.FrameworkID,
ValidFrom: req.ValidFrom,
ValidUntil: req.ValidUntil,
State: coredata.AuditStateNotStarted,
CreatedAt: now,
UpdatedAt: now,
ID: gid.New(s.svc.scope.GetTenantID(), coredata.AuditEntityType),
OrganizationID: req.OrganizationID,
FrameworkID: req.FrameworkID,
ValidFrom: req.ValidFrom,
ValidUntil: req.ValidUntil,
State: coredata.AuditStateNotStarted,
ShowOnTrustCenter: false,
CreatedAt: now,
UpdatedAt: now,
}
if req.State != nil {
@@ -151,6 +153,9 @@ func (s *AuditService) Update(
if req.State != nil {
audit.State = *req.State
}
if req.ShowOnTrustCenter != nil {
audit.ShowOnTrustCenter = *req.ShowOnTrustCenter
}
audit.UpdatedAt = time.Now()

View File

@@ -297,11 +297,12 @@ func (s *DocumentService) Create(
people := &coredata.People{}
document := &coredata.Document{
ID: documentID,
Title: req.Title,
DocumentType: req.DocumentType,
CreatedAt: now,
UpdatedAt: now,
ID: documentID,
Title: req.Title,
DocumentType: req.DocumentType,
ShowOnTrustCenter: false,
CreatedAt: now,
UpdatedAt: now,
}
documentVersion := &coredata.DocumentVersion{
@@ -984,6 +985,7 @@ func (s *DocumentService) Update(
newOwnerID *gid.GID,
documentType *coredata.DocumentType,
title *string,
showOnTrustCenter *bool,
) (*coredata.Document, error) {
document := &coredata.Document{}
people := &coredata.People{}
@@ -1011,6 +1013,10 @@ func (s *DocumentService) Update(
document.Title = *title
}
if showOnTrustCenter != nil {
document.ShowOnTrustCenter = *showOnTrustCenter
}
document.UpdatedAt = now
if err := document.Update(ctx, tx, s.svc.scope); err != nil {

View File

@@ -29,6 +29,7 @@ import (
"github.com/getprobo/probo/pkg/coredata"
"github.com/getprobo/probo/pkg/filevalidation"
"github.com/getprobo/probo/pkg/gid"
"github.com/getprobo/probo/pkg/slug"
"go.gearno.de/crypto/uuid"
"go.gearno.de/kit/pg"
)
@@ -65,13 +66,27 @@ func (s OrganizationService) Create(
UpdatedAt: now,
}
err := s.svc.pg.WithConn(
err := s.svc.pg.WithTx(
ctx,
func(tx pg.Conn) error {
if err := organization.Insert(ctx, tx); err != nil {
return fmt.Errorf("cannot insert organization: %w", err)
}
trustCenter := &coredata.TrustCenter{
ID: gid.New(s.svc.scope.GetTenantID(), coredata.TrustCenterEntityType),
OrganizationID: organization.ID,
TenantID: organization.TenantID,
Active: false,
Slug: slug.Make(organization.Name),
CreatedAt: now,
UpdatedAt: now,
}
if err := trustCenter.Insert(ctx, tx, s.svc.scope); err != nil {
return fmt.Errorf("cannot insert trust center: %w", err)
}
return nil
},
)

View File

@@ -65,6 +65,7 @@ type (
Data *DatumService
Audits *AuditService
Reports *ReportService
TrustCenters *TrustCenterService
}
)
@@ -144,5 +145,6 @@ func (s *Service) WithTenant(tenantID gid.TenantID) *TenantService {
tenantService.Data = &DatumService{svc: tenantService}
tenantService.Audits = &AuditService{svc: tenantService}
tenantService.Reports = &ReportService{svc: tenantService}
tenantService.TrustCenters = &TrustCenterService{svc: tenantService}
return tenantService
}

View File

@@ -0,0 +1,124 @@
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package probo
import (
"context"
"fmt"
"time"
"github.com/getprobo/probo/pkg/coredata"
"github.com/getprobo/probo/pkg/gid"
"go.gearno.de/kit/pg"
)
type (
TrustCenterService struct {
svc *TenantService
}
UpdateTrustCenterRequest struct {
ID gid.GID
Active *bool
Slug *string
}
)
func (s TrustCenterService) Get(
ctx context.Context,
trustCenterID gid.GID,
) (*coredata.TrustCenter, error) {
trustCenter := &coredata.TrustCenter{}
err := s.svc.pg.WithConn(
ctx,
func(conn pg.Conn) error {
err := trustCenter.LoadByID(ctx, conn, s.svc.scope, trustCenterID)
if err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
}
return nil
},
)
if err != nil {
return nil, err
}
return trustCenter, nil
}
func (s TrustCenterService) GetByOrganizationID(
ctx context.Context,
organizationID gid.GID,
) (*coredata.TrustCenter, error) {
trustCenter := &coredata.TrustCenter{}
err := s.svc.pg.WithConn(
ctx,
func(conn pg.Conn) error {
err := trustCenter.LoadByOrganizationID(ctx, conn, s.svc.scope, organizationID)
if err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
}
return nil
},
)
if err != nil {
return nil, err
}
return trustCenter, nil
}
func (s *TrustCenterService) Update(
ctx context.Context,
req *UpdateTrustCenterRequest,
) (*coredata.TrustCenter, error) {
trustCenter := &coredata.TrustCenter{}
err := s.svc.pg.WithTx(
ctx,
func(conn pg.Conn) error {
if err := trustCenter.LoadByID(ctx, conn, s.svc.scope, req.ID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
}
if req.Active != nil {
trustCenter.Active = *req.Active
}
if req.Slug != nil {
trustCenter.Slug = *req.Slug
}
trustCenter.UpdatedAt = time.Now()
if err := trustCenter.Update(ctx, conn, s.svc.scope); err != nil {
return fmt.Errorf("cannot update trust center: %w", err)
}
return nil
},
)
if err != nil {
return nil, err
}
return trustCenter, nil
}

View File

@@ -72,6 +72,7 @@ type (
StatusPageURL *string
BusinessOwnerID *gid.GID
SecurityOwnerID *gid.GID
ShowOnTrustCenter *bool
}
AssessVendorRequest struct {
@@ -259,6 +260,10 @@ func (s VendorService) Update(
vendor.SecurityPageURL = req.SecurityPageURL
}
if req.ShowOnTrustCenter != nil {
vendor.ShowOnTrustCenter = *req.ShowOnTrustCenter
}
if req.TrustPageURL != nil {
vendor.TrustPageURL = req.TrustPageURL
}
@@ -385,6 +390,7 @@ func (s VendorService) Create(
TrustPageURL: req.TrustPageURL,
StatusPageURL: req.StatusPageURL,
TermsOfServiceURL: req.TermsOfServiceURL,
ShowOnTrustCenter: false,
}
err := s.svc.pg.WithTx(

View File

@@ -703,6 +703,14 @@ input RiskFilter {
}
# Core Types
type TrustCenter implements Node {
id: ID!
active: Boolean!
slug: String!
createdAt: Datetime!
updatedAt: Datetime!
}
type Organization implements Node {
id: ID!
name: String!
@@ -816,6 +824,8 @@ type Organization implements Node {
orderBy: AuditOrder
): AuditConnection! @goField(forceResolver: true)
trustCenter: TrustCenter @goField(forceResolver: true)
createdAt: Datetime!
updatedAt: Datetime!
}
@@ -891,6 +901,7 @@ type Vendor implements Node {
headquarterAddress: String
legalName: String
websiteUrl: String
showOnTrustCenter: Boolean!
createdAt: Datetime!
updatedAt: Datetime!
}
@@ -1052,6 +1063,7 @@ type Document implements Node {
description: String!
documentType: DocumentType!
currentPublishedVersion: Int
showOnTrustCenter: Boolean!
owner: People! @goField(forceResolver: true)
organization: Organization! @goField(forceResolver: true)
@@ -1134,6 +1146,7 @@ type Audit implements Node {
report: Report @goField(forceResolver: true)
reportUrl: String @goField(forceResolver: true)
state: AuditState!
showOnTrustCenter: Boolean!
createdAt: Datetime!
updatedAt: Datetime!
}
@@ -1397,6 +1410,10 @@ type Mutation {
input: UpdateOrganizationInput!
): UpdateOrganizationPayload!
updateTrustCenter(
input: UpdateTrustCenterInput!
): UpdateTrustCenterPayload!
# User mutations
confirmEmail(input: ConfirmEmailInput!): ConfirmEmailPayload!
inviteUser(input: InviteUserInput!): InviteUserPayload!
@@ -1563,6 +1580,12 @@ input UpdateOrganizationInput {
logo: Upload
}
input UpdateTrustCenterInput {
trustCenterId: ID!
active: Boolean
slug: String
}
input CreateVendorInput {
organizationId: ID!
name: String!
@@ -1605,6 +1628,7 @@ input UpdateVendorInput {
trustPageUrl: String
businessOwnerId: ID
securityOwnerId: ID
showOnTrustCenter: Boolean
}
input DeleteVendorInput {
@@ -1836,6 +1860,7 @@ input UpdateDocumentInput {
ownerId: ID
createdBy: ID
documentType: DocumentType
showOnTrustCenter: Boolean
}
input ExportDocumentVersionPDFInput {
@@ -1897,6 +1922,7 @@ input UpdateAuditInput {
validFrom: Datetime
validUntil: Datetime
state: AuditState
showOnTrustCenter: Boolean
}
input DeleteAuditInput {
@@ -1921,6 +1947,10 @@ type UpdateOrganizationPayload {
organization: Organization!
}
type UpdateTrustCenterPayload {
trustCenter: TrustCenter!
}
type CreateControlPayload {
controlEdge: ControlEdge!
}

File diff suppressed because it is too large Load Diff

View File

@@ -54,12 +54,13 @@ func NewAuditConnection(
func NewAudit(a *coredata.Audit) *Audit {
return &Audit{
ID: a.ID,
ValidFrom: a.ValidFrom,
ValidUntil: a.ValidUntil,
State: a.State,
CreatedAt: a.CreatedAt,
UpdatedAt: a.UpdatedAt,
ID: a.ID,
ValidFrom: a.ValidFrom,
ValidUntil: a.ValidUntil,
State: a.State,
ShowOnTrustCenter: a.ShowOnTrustCenter,
CreatedAt: a.CreatedAt,
UpdatedAt: a.UpdatedAt,
}
}

View File

@@ -79,6 +79,7 @@ func NewDocument(document *coredata.Document) *Document {
Title: document.Title,
DocumentType: document.DocumentType,
CurrentPublishedVersion: document.CurrentPublishedVersion,
ShowOnTrustCenter: document.ShowOnTrustCenter,
CreatedAt: document.CreatedAt,
UpdatedAt: document.UpdatedAt,
}

View File

@@ -0,0 +1,29 @@
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package types
import (
"github.com/getprobo/probo/pkg/coredata"
)
func NewTrustCenter(tc *coredata.TrustCenter) *TrustCenter {
return &TrustCenter{
ID: tc.ID,
Active: tc.Active,
Slug: tc.Slug,
CreatedAt: tc.CreatedAt,
UpdatedAt: tc.UpdatedAt,
}
}

View File

@@ -57,16 +57,17 @@ type AssignTaskPayload struct {
}
type Audit struct {
ID gid.GID `json:"id"`
Organization *Organization `json:"organization"`
Framework *Framework `json:"framework"`
ValidFrom *time.Time `json:"validFrom,omitempty"`
ValidUntil *time.Time `json:"validUntil,omitempty"`
Report *Report `json:"report,omitempty"`
ReportURL *string `json:"reportUrl,omitempty"`
State coredata.AuditState `json:"state"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
ID gid.GID `json:"id"`
Organization *Organization `json:"organization"`
Framework *Framework `json:"framework"`
ValidFrom *time.Time `json:"validFrom,omitempty"`
ValidUntil *time.Time `json:"validUntil,omitempty"`
Report *Report `json:"report,omitempty"`
ReportURL *string `json:"reportUrl,omitempty"`
State coredata.AuditState `json:"state"`
ShowOnTrustCenter bool `json:"showOnTrustCenter"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
}
func (Audit) IsNode() {}
@@ -582,6 +583,7 @@ type Document struct {
Description string `json:"description"`
DocumentType coredata.DocumentType `json:"documentType"`
CurrentPublishedVersion *int `json:"currentPublishedVersion,omitempty"`
ShowOnTrustCenter bool `json:"showOnTrustCenter"`
Owner *People `json:"owner"`
Organization *Organization `json:"organization"`
Versions *DocumentVersionConnection `json:"versions"`
@@ -800,24 +802,25 @@ type Mutation struct {
}
type Organization struct {
ID gid.GID `json:"id"`
Name string `json:"name"`
LogoURL *string `json:"logoUrl,omitempty"`
Users *UserConnection `json:"users"`
Connectors *ConnectorConnection `json:"connectors"`
Frameworks *FrameworkConnection `json:"frameworks"`
Controls *ControlConnection `json:"controls"`
Vendors *VendorConnection `json:"vendors"`
Peoples *PeopleConnection `json:"peoples"`
Documents *DocumentConnection `json:"documents"`
Measures *MeasureConnection `json:"measures"`
Risks *RiskConnection `json:"risks"`
Tasks *TaskConnection `json:"tasks"`
Assets *AssetConnection `json:"assets"`
Data *DatumConnection `json:"data"`
Audits *AuditConnection `json:"audits"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
ID gid.GID `json:"id"`
Name string `json:"name"`
LogoURL *string `json:"logoUrl,omitempty"`
Users *UserConnection `json:"users"`
Connectors *ConnectorConnection `json:"connectors"`
Frameworks *FrameworkConnection `json:"frameworks"`
Controls *ControlConnection `json:"controls"`
Vendors *VendorConnection `json:"vendors"`
Peoples *PeopleConnection `json:"peoples"`
Documents *DocumentConnection `json:"documents"`
Measures *MeasureConnection `json:"measures"`
Risks *RiskConnection `json:"risks"`
Tasks *TaskConnection `json:"tasks"`
Assets *AssetConnection `json:"assets"`
Data *DatumConnection `json:"data"`
Audits *AuditConnection `json:"audits"`
TrustCenter *TrustCenter `json:"trustCenter,omitempty"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
}
func (Organization) IsNode() {}
@@ -992,6 +995,17 @@ type TaskEdge struct {
Node *Task `json:"node"`
}
type TrustCenter struct {
ID gid.GID `json:"id"`
Active bool `json:"active"`
Slug string `json:"slug"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
}
func (TrustCenter) IsNode() {}
func (this TrustCenter) GetID() gid.GID { return this.ID }
type UnassignTaskInput struct {
TaskID gid.GID `json:"taskId"`
}
@@ -1016,10 +1030,11 @@ type UpdateAssetPayload struct {
}
type UpdateAuditInput struct {
ID gid.GID `json:"id"`
ValidFrom *time.Time `json:"validFrom,omitempty"`
ValidUntil *time.Time `json:"validUntil,omitempty"`
State *coredata.AuditState `json:"state,omitempty"`
ID gid.GID `json:"id"`
ValidFrom *time.Time `json:"validFrom,omitempty"`
ValidUntil *time.Time `json:"validUntil,omitempty"`
State *coredata.AuditState `json:"state,omitempty"`
ShowOnTrustCenter *bool `json:"showOnTrustCenter,omitempty"`
}
type UpdateAuditPayload struct {
@@ -1052,12 +1067,13 @@ type UpdateDatumPayload struct {
}
type UpdateDocumentInput struct {
ID gid.GID `json:"id"`
Title *string `json:"title,omitempty"`
Content *string `json:"content,omitempty"`
OwnerID *gid.GID `json:"ownerId,omitempty"`
CreatedBy *gid.GID `json:"createdBy,omitempty"`
DocumentType *coredata.DocumentType `json:"documentType,omitempty"`
ID gid.GID `json:"id"`
Title *string `json:"title,omitempty"`
Content *string `json:"content,omitempty"`
OwnerID *gid.GID `json:"ownerId,omitempty"`
CreatedBy *gid.GID `json:"createdBy,omitempty"`
DocumentType *coredata.DocumentType `json:"documentType,omitempty"`
ShowOnTrustCenter *bool `json:"showOnTrustCenter,omitempty"`
}
type UpdateDocumentPayload struct {
@@ -1151,6 +1167,16 @@ type UpdateTaskPayload struct {
Task *Task `json:"task"`
}
type UpdateTrustCenterInput struct {
TrustCenterID gid.GID `json:"trustCenterId"`
Active *bool `json:"active,omitempty"`
Slug *string `json:"slug,omitempty"`
}
type UpdateTrustCenterPayload struct {
TrustCenter *TrustCenter `json:"trustCenter"`
}
type UpdateVendorInput struct {
ID gid.GID `json:"id"`
Name *string `json:"name,omitempty"`
@@ -1171,6 +1197,7 @@ type UpdateVendorInput struct {
TrustPageURL *string `json:"trustPageUrl,omitempty"`
BusinessOwnerID *gid.GID `json:"businessOwnerId,omitempty"`
SecurityOwnerID *gid.GID `json:"securityOwnerId,omitempty"`
ShowOnTrustCenter *bool `json:"showOnTrustCenter,omitempty"`
}
type UpdateVendorPayload struct {
@@ -1261,6 +1288,7 @@ type Vendor struct {
HeadquarterAddress *string `json:"headquarterAddress,omitempty"`
LegalName *string `json:"legalName,omitempty"`
WebsiteURL *string `json:"websiteUrl,omitempty"`
ShowOnTrustCenter bool `json:"showOnTrustCenter"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
}

View File

@@ -79,6 +79,7 @@ func NewVendor(v *coredata.Vendor) *Vendor {
LegalName: v.LegalName,
WebsiteURL: v.WebsiteURL,
Category: v.Category,
ShowOnTrustCenter: v.ShowOnTrustCenter,
UpdatedAt: v.UpdatedAt,
CreatedAt: v.CreatedAt,
}

View File

@@ -980,6 +980,24 @@ func (r *mutationResolver) UpdateOrganization(ctx context.Context, input types.U
}, nil
}
// UpdateTrustCenter is the resolver for the updateTrustCenter field.
func (r *mutationResolver) UpdateTrustCenter(ctx context.Context, input types.UpdateTrustCenterInput) (*types.UpdateTrustCenterPayload, error) {
prb := r.ProboService(ctx, input.TrustCenterID.TenantID())
trustCenter, err := prb.TrustCenters.Update(ctx, &probo.UpdateTrustCenterRequest{
ID: input.TrustCenterID,
Active: input.Active,
Slug: input.Slug,
})
if err != nil {
return nil, fmt.Errorf("cannot update trust center: %w", err)
}
return &types.UpdateTrustCenterPayload{
TrustCenter: types.NewTrustCenter(trustCenter),
}, nil
}
// ConfirmEmail is the resolver for the confirmEmail field.
func (r *mutationResolver) ConfirmEmail(ctx context.Context, input types.ConfirmEmailInput) (*types.ConfirmEmailPayload, error) {
err := r.usrmgrSvc.ConfirmEmail(ctx, input.Token)
@@ -1158,6 +1176,7 @@ func (r *mutationResolver) UpdateVendor(ctx context.Context, input types.UpdateV
Certifications: input.Certifications,
BusinessOwnerID: input.BusinessOwnerID,
SecurityOwnerID: input.SecurityOwnerID,
ShowOnTrustCenter: input.ShowOnTrustCenter,
})
if err != nil {
return nil, fmt.Errorf("cannot update vendor: %w", err)
@@ -1879,6 +1898,7 @@ func (r *mutationResolver) UpdateDocument(ctx context.Context, input types.Updat
input.OwnerID,
input.DocumentType,
input.Title,
input.ShowOnTrustCenter,
)
if err != nil {
@@ -2300,10 +2320,11 @@ func (r *mutationResolver) UpdateAudit(ctx context.Context, input types.UpdateAu
prb := r.ProboService(ctx, input.ID.TenantID())
req := probo.UpdateAuditRequest{
ID: input.ID,
ValidFrom: input.ValidFrom,
ValidUntil: input.ValidUntil,
State: input.State,
ID: input.ID,
ValidFrom: input.ValidFrom,
ValidUntil: input.ValidUntil,
State: input.State,
ShowOnTrustCenter: input.ShowOnTrustCenter,
}
audit, err := prb.Audits.Update(ctx, &req)
@@ -2718,6 +2739,18 @@ func (r *organizationResolver) Audits(ctx context.Context, obj *types.Organizati
return types.NewAuditConnection(page, r, obj.ID), nil
}
// TrustCenter is the resolver for the trustCenter field.
func (r *organizationResolver) TrustCenter(ctx context.Context, obj *types.Organization) (*types.TrustCenter, error) {
prb := r.ProboService(ctx, obj.ID.TenantID())
trustCenter, err := prb.TrustCenters.GetByOrganizationID(ctx, obj.ID)
if err != nil {
return nil, fmt.Errorf("cannot get trust center: %w", err)
}
return types.NewTrustCenter(trustCenter), nil
}
// TotalCount is the resolver for the totalCount field.
func (r *peopleConnectionResolver) TotalCount(ctx context.Context, obj *types.PeopleConnection) (int, error) {
prb := r.ProboService(ctx, obj.ParentID.TenantID())
@@ -2849,6 +2882,12 @@ func (r *queryResolver) Node(ctx context.Context, id gid.GID) (types.Node, error
panic(fmt.Errorf("cannot get report: %w", err))
}
return types.NewReport(report), nil
case coredata.TrustCenterEntityType:
trustCenter, err := prb.TrustCenters.GetByOrganizationID(ctx, id)
if err != nil {
panic(fmt.Errorf("cannot get trust center: %w", err))
}
return types.NewTrustCenter(trustCenter), nil
default:
}