@@ -28,47 +28,47 @@ import (
|
||||
)
|
||||
|
||||
type (
|
||||
Control struct {
|
||||
ID gid.GID `db:"id"`
|
||||
FrameworkID gid.GID `db:"framework_id"`
|
||||
Category string `db:"category"`
|
||||
Name string `db:"name"`
|
||||
Description string `db:"description"`
|
||||
Importance ControlImportance `db:"importance"`
|
||||
State ControlState `db:"state"`
|
||||
ContentRef string `db:"content_ref"`
|
||||
CreatedAt time.Time `db:"created_at"`
|
||||
UpdatedAt time.Time `db:"updated_at"`
|
||||
Version int `db:"version"`
|
||||
Standards []string `db:"standards"`
|
||||
Mitigation struct {
|
||||
ID gid.GID `db:"id"`
|
||||
FrameworkID gid.GID `db:"framework_id"`
|
||||
Category string `db:"category"`
|
||||
Name string `db:"name"`
|
||||
Description string `db:"description"`
|
||||
Importance MitigationImportance `db:"importance"`
|
||||
State MitigationState `db:"state"`
|
||||
ContentRef string `db:"content_ref"`
|
||||
CreatedAt time.Time `db:"created_at"`
|
||||
UpdatedAt time.Time `db:"updated_at"`
|
||||
Version int `db:"version"`
|
||||
Standards []string `db:"standards"`
|
||||
}
|
||||
|
||||
Controls []*Control
|
||||
Mitigations []*Mitigation
|
||||
|
||||
UpdateControlParams struct {
|
||||
UpdateMitigationParams struct {
|
||||
ExpectedVersion int
|
||||
Name *string
|
||||
Description *string
|
||||
Category *string
|
||||
State *ControlState
|
||||
Importance *ControlImportance
|
||||
State *MitigationState
|
||||
Importance *MitigationImportance
|
||||
}
|
||||
)
|
||||
|
||||
func (c Control) CursorKey(orderBy ControlOrderField) page.CursorKey {
|
||||
func (c Mitigation) CursorKey(orderBy MitigationOrderField) page.CursorKey {
|
||||
switch orderBy {
|
||||
case ControlOrderFieldCreatedAt:
|
||||
case MitigationOrderFieldCreatedAt:
|
||||
return page.NewCursorKey(c.ID, c.CreatedAt)
|
||||
}
|
||||
|
||||
panic(fmt.Sprintf("unsupported order by: %s", orderBy))
|
||||
}
|
||||
|
||||
func (c *Control) LoadByID(
|
||||
func (c *Mitigation) LoadByID(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
controlID gid.GID,
|
||||
mitigationID gid.GID,
|
||||
) error {
|
||||
q := `
|
||||
SELECT
|
||||
@@ -85,41 +85,41 @@ SELECT
|
||||
standards,
|
||||
version
|
||||
FROM
|
||||
controls
|
||||
mitigations
|
||||
WHERE
|
||||
%s
|
||||
AND id = @control_id
|
||||
AND id = @mitigation_id
|
||||
LIMIT 1;
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{"control_id": controlID}
|
||||
args := pgx.StrictNamedArgs{"mitigation_id": mitigationID}
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query controls: %w", err)
|
||||
return fmt.Errorf("cannot query mitigations: %w", err)
|
||||
}
|
||||
|
||||
control, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[Control])
|
||||
mitigation, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[Mitigation])
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot collect controls: %w", err)
|
||||
return fmt.Errorf("cannot collect mitigations: %w", err)
|
||||
}
|
||||
|
||||
*c = control
|
||||
*c = mitigation
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (c Control) Insert(
|
||||
func (c Mitigation) Insert(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
) error {
|
||||
q := `
|
||||
INSERT INTO
|
||||
controls (
|
||||
mitigations (
|
||||
tenant_id,
|
||||
id,
|
||||
framework_id,
|
||||
@@ -136,7 +136,7 @@ INSERT INTO
|
||||
)
|
||||
VALUES (
|
||||
@tenant_id,
|
||||
@control_id,
|
||||
@mitigation_id,
|
||||
@framework_id,
|
||||
@category,
|
||||
@name,
|
||||
@@ -152,30 +152,30 @@ VALUES (
|
||||
`
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"tenant_id": scope.GetTenantID(),
|
||||
"control_id": c.ID,
|
||||
"framework_id": c.FrameworkID,
|
||||
"category": c.Category,
|
||||
"name": c.Name,
|
||||
"version": 0,
|
||||
"description": c.Description,
|
||||
"content_ref": c.ContentRef,
|
||||
"created_at": c.CreatedAt,
|
||||
"updated_at": c.UpdatedAt,
|
||||
"state": c.State,
|
||||
"importance": c.Importance,
|
||||
"standards": c.Standards,
|
||||
"tenant_id": scope.GetTenantID(),
|
||||
"mitigation_id": c.ID,
|
||||
"framework_id": c.FrameworkID,
|
||||
"category": c.Category,
|
||||
"name": c.Name,
|
||||
"version": 0,
|
||||
"description": c.Description,
|
||||
"content_ref": c.ContentRef,
|
||||
"created_at": c.CreatedAt,
|
||||
"updated_at": c.UpdatedAt,
|
||||
"state": c.State,
|
||||
"importance": c.Importance,
|
||||
"standards": c.Standards,
|
||||
}
|
||||
_, err := conn.Exec(ctx, q, args)
|
||||
return err
|
||||
}
|
||||
|
||||
func (c *Controls) LoadByFrameworkID(
|
||||
func (c *Mitigations) LoadByFrameworkID(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
frameworkID gid.GID,
|
||||
cursor *page.Cursor[ControlOrderField],
|
||||
cursor *page.Cursor[MitigationOrderField],
|
||||
) error {
|
||||
q := `
|
||||
SELECT
|
||||
@@ -192,7 +192,7 @@ SELECT
|
||||
standards,
|
||||
version
|
||||
FROM
|
||||
controls
|
||||
mitigations
|
||||
WHERE
|
||||
%s
|
||||
AND framework_id = @framework_id
|
||||
@@ -206,27 +206,27 @@ WHERE
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query controls: %w", err)
|
||||
return fmt.Errorf("cannot query mitigations: %w", err)
|
||||
}
|
||||
|
||||
controls, err := pgx.CollectRows(rows, pgx.RowToAddrOfStructByName[Control])
|
||||
mitigations, err := pgx.CollectRows(rows, pgx.RowToAddrOfStructByName[Mitigation])
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot collect controls: %w", err)
|
||||
return fmt.Errorf("cannot collect mitigations: %w", err)
|
||||
}
|
||||
|
||||
*c = controls
|
||||
*c = mitigations
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (c *Control) Update(
|
||||
func (c *Mitigation) Update(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
params UpdateControlParams,
|
||||
params UpdateMitigationParams,
|
||||
) error {
|
||||
q := `
|
||||
UPDATE controls SET
|
||||
UPDATE mitigations SET
|
||||
name = COALESCE(@name, name),
|
||||
description = COALESCE(@description, description),
|
||||
category = COALESCE(@category, category),
|
||||
@@ -235,7 +235,7 @@ UPDATE controls SET
|
||||
updated_at = @updated_at,
|
||||
version = version + 1
|
||||
WHERE %s
|
||||
AND id = @control_id
|
||||
AND id = @mitigation_id
|
||||
AND version = @expected_version
|
||||
RETURNING
|
||||
id,
|
||||
@@ -254,7 +254,7 @@ RETURNING
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.NamedArgs{
|
||||
"control_id": c.ID,
|
||||
"mitigation_id": c.ID,
|
||||
"expected_version": params.ExpectedVersion,
|
||||
"name": params.Name,
|
||||
"description": params.Description,
|
||||
@@ -268,15 +268,15 @@ RETURNING
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query controls: %w", err)
|
||||
return fmt.Errorf("cannot query mitigations: %w", err)
|
||||
}
|
||||
|
||||
control, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[Control])
|
||||
mitigation, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[Mitigation])
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot collect controls: %w", err)
|
||||
return fmt.Errorf("cannot collect mitigations: %w", err)
|
||||
}
|
||||
|
||||
*c = control
|
||||
*c = mitigation
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -20,48 +20,48 @@ import (
|
||||
"fmt"
|
||||
)
|
||||
|
||||
type ControlImportance uint8
|
||||
type MitigationImportance uint8
|
||||
|
||||
const (
|
||||
ControlImportanceMandatory ControlImportance = iota
|
||||
ControlImportancePreferred
|
||||
ControlImportanceAdvanced
|
||||
MitigationImportanceMandatory MitigationImportance = iota
|
||||
MitigationImportancePreferred
|
||||
MitigationImportanceAdvanced
|
||||
)
|
||||
|
||||
func (i ControlImportance) String() string {
|
||||
func (i MitigationImportance) String() string {
|
||||
return []string{"MANDATORY", "PREFERRED", "ADVANCED"}[i]
|
||||
}
|
||||
|
||||
func (i *ControlImportance) Scan(value interface{}) error {
|
||||
func (i *MitigationImportance) Scan(value interface{}) error {
|
||||
switch v := value.(type) {
|
||||
case uint8:
|
||||
*i = ControlImportance(v)
|
||||
*i = MitigationImportance(v)
|
||||
case string:
|
||||
switch v {
|
||||
case "MANDATORY":
|
||||
*i = ControlImportanceMandatory
|
||||
*i = MitigationImportanceMandatory
|
||||
case "PREFERRED":
|
||||
*i = ControlImportancePreferred
|
||||
*i = MitigationImportancePreferred
|
||||
case "ADVANCED":
|
||||
*i = ControlImportanceAdvanced
|
||||
*i = MitigationImportanceAdvanced
|
||||
default:
|
||||
return fmt.Errorf("invalid ControlImportance value: %q", v)
|
||||
return fmt.Errorf("invalid MitigationImportance value: %q", v)
|
||||
}
|
||||
default:
|
||||
return fmt.Errorf("unsupported type for ControlImportance: %T", value)
|
||||
return fmt.Errorf("unsupported type for MitigationImportance: %T", value)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (i ControlImportance) Value() (driver.Value, error) {
|
||||
func (i MitigationImportance) Value() (driver.Value, error) {
|
||||
return i.String(), nil
|
||||
}
|
||||
|
||||
func (i ControlImportance) MarshalJSON() ([]byte, error) {
|
||||
func (i MitigationImportance) MarshalJSON() ([]byte, error) {
|
||||
return json.Marshal(i.String())
|
||||
}
|
||||
|
||||
func (i *ControlImportance) UnmarshalJSON(data []byte) error {
|
||||
func (i *MitigationImportance) UnmarshalJSON(data []byte) error {
|
||||
var s string
|
||||
if err := json.Unmarshal(data, &s); err != nil {
|
||||
return err
|
||||
@@ -69,18 +69,18 @@ func (i *ControlImportance) UnmarshalJSON(data []byte) error {
|
||||
|
||||
switch s {
|
||||
case "MANDATORY":
|
||||
*i = ControlImportanceMandatory
|
||||
*i = MitigationImportanceMandatory
|
||||
case "PREFERRED":
|
||||
*i = ControlImportancePreferred
|
||||
*i = MitigationImportancePreferred
|
||||
case "ADVANCED":
|
||||
*i = ControlImportanceAdvanced
|
||||
*i = MitigationImportanceAdvanced
|
||||
default:
|
||||
return fmt.Errorf("invalid ControlImportance value: %q", s)
|
||||
return fmt.Errorf("invalid MitigationImportance value: %q", s)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (i *ControlImportance) UnmarshalText(text []byte) error {
|
||||
func (i *MitigationImportance) UnmarshalText(text []byte) error {
|
||||
var s string
|
||||
if err := json.Unmarshal(text, &s); err != nil {
|
||||
return err
|
||||
@@ -88,13 +88,13 @@ func (i *ControlImportance) UnmarshalText(text []byte) error {
|
||||
|
||||
switch s {
|
||||
case "MANDATORY":
|
||||
*i = ControlImportanceMandatory
|
||||
*i = MitigationImportanceMandatory
|
||||
case "PREFERRED":
|
||||
*i = ControlImportancePreferred
|
||||
*i = MitigationImportancePreferred
|
||||
case "ADVANCED":
|
||||
*i = ControlImportanceAdvanced
|
||||
*i = MitigationImportanceAdvanced
|
||||
default:
|
||||
return fmt.Errorf("invalid ControlImportance value: %q", s)
|
||||
return fmt.Errorf("invalid MitigationImportance value: %q", s)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -15,26 +15,26 @@
|
||||
package coredata
|
||||
|
||||
type (
|
||||
ControlOrderField string
|
||||
MitigationOrderField string
|
||||
)
|
||||
|
||||
const (
|
||||
ControlOrderFieldCreatedAt ControlOrderField = "CREATED_AT"
|
||||
MitigationOrderFieldCreatedAt MitigationOrderField = "CREATED_AT"
|
||||
)
|
||||
|
||||
func (p ControlOrderField) Column() string {
|
||||
func (p MitigationOrderField) Column() string {
|
||||
return string(p)
|
||||
}
|
||||
|
||||
func (p ControlOrderField) String() string {
|
||||
func (p MitigationOrderField) String() string {
|
||||
return string(p)
|
||||
}
|
||||
|
||||
func (p ControlOrderField) MarshalText() ([]byte, error) {
|
||||
func (p MitigationOrderField) MarshalText() ([]byte, error) {
|
||||
return []byte(p.String()), nil
|
||||
}
|
||||
|
||||
func (p *ControlOrderField) UnmarshalText(text []byte) error {
|
||||
*p = ControlOrderField(text)
|
||||
func (p *MitigationOrderField) UnmarshalText(text []byte) error {
|
||||
*p = MitigationOrderField(text)
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -20,65 +20,65 @@ import (
|
||||
)
|
||||
|
||||
type (
|
||||
ControlState uint8
|
||||
MitigationState uint8
|
||||
)
|
||||
|
||||
const (
|
||||
ControlStateNotStarted ControlState = iota
|
||||
ControlStateInProgress
|
||||
ControlStateNotApplicable
|
||||
ControlStateImplemented
|
||||
MitigationStateNotStarted MitigationState = iota
|
||||
MitigationStateInProgress
|
||||
MitigationStateNotApplicable
|
||||
MitigationStateImplemented
|
||||
)
|
||||
|
||||
func (cs ControlState) MarshalText() ([]byte, error) {
|
||||
func (cs MitigationState) MarshalText() ([]byte, error) {
|
||||
return []byte(cs.String()), nil
|
||||
}
|
||||
|
||||
func (cs *ControlState) UnmarshalText(data []byte) error {
|
||||
func (cs *MitigationState) UnmarshalText(data []byte) error {
|
||||
val := string(data)
|
||||
|
||||
switch val {
|
||||
case ControlStateNotStarted.String():
|
||||
*cs = ControlStateNotStarted
|
||||
case ControlStateInProgress.String():
|
||||
*cs = ControlStateInProgress
|
||||
case ControlStateNotApplicable.String():
|
||||
*cs = ControlStateNotApplicable
|
||||
case ControlStateImplemented.String():
|
||||
*cs = ControlStateImplemented
|
||||
case MitigationStateNotStarted.String():
|
||||
*cs = MitigationStateNotStarted
|
||||
case MitigationStateInProgress.String():
|
||||
*cs = MitigationStateInProgress
|
||||
case MitigationStateNotApplicable.String():
|
||||
*cs = MitigationStateNotApplicable
|
||||
case MitigationStateImplemented.String():
|
||||
*cs = MitigationStateImplemented
|
||||
default:
|
||||
return fmt.Errorf("invalid ControlState value: %q", val)
|
||||
return fmt.Errorf("invalid MitigationState value: %q", val)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (cs ControlState) String() string {
|
||||
func (cs MitigationState) String() string {
|
||||
var val string
|
||||
|
||||
switch cs {
|
||||
case ControlStateNotStarted:
|
||||
case MitigationStateNotStarted:
|
||||
val = "NOT_STARTED"
|
||||
case ControlStateInProgress:
|
||||
case MitigationStateInProgress:
|
||||
val = "IN_PROGRESS"
|
||||
case ControlStateNotApplicable:
|
||||
case MitigationStateNotApplicable:
|
||||
val = "NOT_APPLICABLE"
|
||||
case ControlStateImplemented:
|
||||
case MitigationStateImplemented:
|
||||
val = "IMPLEMENTED"
|
||||
}
|
||||
|
||||
return val
|
||||
}
|
||||
|
||||
func (cs *ControlState) Scan(value any) error {
|
||||
func (cs *MitigationState) Scan(value any) error {
|
||||
val, ok := value.(string)
|
||||
if !ok {
|
||||
return fmt.Errorf("invalid scan source for ControlState, expected string got %T", value)
|
||||
return fmt.Errorf("invalid scan source for MitigationState, expected string got %T", value)
|
||||
}
|
||||
|
||||
return cs.UnmarshalText([]byte(val))
|
||||
}
|
||||
|
||||
func (cs ControlState) Value() (driver.Value, error) {
|
||||
func (cs MitigationState) Value() (driver.Value, error) {
|
||||
return cs.String(), nil
|
||||
}
|
||||
|
||||
@@ -17,7 +17,7 @@ package coredata
|
||||
const (
|
||||
OrganizationEntityType uint16 = iota
|
||||
FrameworkEntityType
|
||||
ControlEntityType
|
||||
MitigationEntityType
|
||||
TaskEntityType
|
||||
EvidenceEntityType
|
||||
ControlStateTransitionEntityType
|
||||
|
||||
97
pkg/coredata/migrations/20250327T093314Z.sql
Normal file
97
pkg/coredata/migrations/20250327T093314Z.sql
Normal file
@@ -0,0 +1,97 @@
|
||||
-- Rename control_state ENUM to mitigation_state
|
||||
-- We need to create a new type and update all references since
|
||||
-- PostgreSQL doesn't support renaming enum types directly
|
||||
CREATE TYPE mitigation_state AS ENUM (
|
||||
'NOT_STARTED',
|
||||
'IN_PROGRESS',
|
||||
'NOT_APPLICABLE',
|
||||
'IMPLEMENTED'
|
||||
);
|
||||
|
||||
-- Create new mitigation_importance type
|
||||
CREATE TYPE mitigation_importance AS ENUM (
|
||||
'MANDATORY',
|
||||
'PREFERRED',
|
||||
'ADVANCED'
|
||||
);
|
||||
|
||||
-- Rename controls table to mitigations, adding the new columns with the new types
|
||||
CREATE TABLE mitigations (
|
||||
id TEXT PRIMARY KEY,
|
||||
tenant_id TEXT NOT NULL,
|
||||
framework_id TEXT NOT NULL,
|
||||
name TEXT NOT NULL,
|
||||
description TEXT NOT NULL,
|
||||
content_ref TEXT NOT NULL,
|
||||
category TEXT NOT NULL,
|
||||
state mitigation_state NOT NULL,
|
||||
importance mitigation_importance NOT NULL,
|
||||
version INTEGER NOT NULL,
|
||||
standards TEXT[] NOT NULL,
|
||||
created_at TIMESTAMP WITH TIME ZONE NOT NULL,
|
||||
updated_at TIMESTAMP WITH TIME ZONE NOT NULL
|
||||
);
|
||||
|
||||
-- Copy data from controls to mitigations table
|
||||
INSERT INTO mitigations (
|
||||
id,
|
||||
tenant_id,
|
||||
framework_id,
|
||||
name,
|
||||
description,
|
||||
content_ref,
|
||||
category,
|
||||
state,
|
||||
importance,
|
||||
version,
|
||||
standards,
|
||||
created_at,
|
||||
updated_at
|
||||
)
|
||||
SELECT
|
||||
id,
|
||||
tenant_id,
|
||||
framework_id,
|
||||
name,
|
||||
description,
|
||||
content_ref,
|
||||
category,
|
||||
(state::TEXT)::mitigation_state,
|
||||
(importance::TEXT)::mitigation_importance,
|
||||
version,
|
||||
standards,
|
||||
created_at,
|
||||
updated_at
|
||||
FROM controls;
|
||||
|
||||
-- Update tasks to reference mitigations instead of controls
|
||||
ALTER TABLE tasks RENAME COLUMN control_id TO mitigation_id;
|
||||
|
||||
-- Update foreign key constraint
|
||||
ALTER TABLE tasks DROP CONSTRAINT fk_tasks_control_id;
|
||||
ALTER TABLE tasks ADD CONSTRAINT fk_tasks_mitigation_id
|
||||
FOREIGN KEY (mitigation_id) REFERENCES mitigations(id) ON DELETE CASCADE;
|
||||
|
||||
-- If we have any control_state_transitions table, rename it
|
||||
-- Since the original migration file 20250310T161900Z.sql dropped it, this might not be necessary,
|
||||
-- but including for completeness
|
||||
DO $$
|
||||
BEGIN
|
||||
IF EXISTS (
|
||||
SELECT FROM information_schema.tables
|
||||
WHERE table_name = 'control_state_transitions'
|
||||
) THEN
|
||||
ALTER TABLE control_state_transitions RENAME TO mitigation_state_transitions;
|
||||
ALTER TABLE mitigation_state_transitions RENAME COLUMN control_id TO mitigation_id;
|
||||
ALTER TABLE mitigation_state_transitions
|
||||
DROP CONSTRAINT IF EXISTS control_state_transitions_control_id_fkey;
|
||||
ALTER TABLE mitigation_state_transitions
|
||||
ADD CONSTRAINT mitigation_state_transitions_mitigation_id_fkey
|
||||
FOREIGN KEY (mitigation_id) REFERENCES mitigations(id);
|
||||
END IF;
|
||||
END $$;
|
||||
|
||||
-- Drop old controls table and enum types after migration is complete
|
||||
DROP TABLE controls;
|
||||
DROP TYPE control_state;
|
||||
DROP TYPE control_importance;
|
||||
@@ -30,16 +30,15 @@ import (
|
||||
type (
|
||||
Task struct {
|
||||
ID gid.GID `db:"id"`
|
||||
ControlID gid.GID `db:"control_id"`
|
||||
MitigationID gid.GID `db:"mitigation_id"`
|
||||
Name string `db:"name"`
|
||||
Description string `db:"description"`
|
||||
State TaskState `db:"state"`
|
||||
ContentRef string `db:"content_ref"`
|
||||
TimeEstimate *time.Duration `db:"time_estimate"`
|
||||
AssignedToID *gid.GID `db:"assigned_to"`
|
||||
CreatedAt time.Time `db:"created_at"`
|
||||
UpdatedAt time.Time `db:"updated_at"`
|
||||
Version int `db:"version"`
|
||||
AssignedTo *gid.GID `db:"assigned_to"`
|
||||
TimeEstimate *time.Duration `db:"time_estimate"`
|
||||
}
|
||||
|
||||
Tasks []*Task
|
||||
@@ -53,16 +52,16 @@ type (
|
||||
}
|
||||
)
|
||||
|
||||
func (t Task) CursorKey(orderBy TaskOrderField) page.CursorKey {
|
||||
func (c Task) CursorKey(orderBy TaskOrderField) page.CursorKey {
|
||||
switch orderBy {
|
||||
case TaskOrderFieldCreatedAt:
|
||||
return page.NewCursorKey(t.ID, t.CreatedAt)
|
||||
return page.NewCursorKey(c.ID, c.CreatedAt)
|
||||
}
|
||||
|
||||
panic(fmt.Sprintf("unsupported order by: %s", orderBy))
|
||||
}
|
||||
|
||||
func (t *Task) LoadByID(
|
||||
func (c *Task) LoadByID(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
@@ -71,13 +70,12 @@ func (t *Task) LoadByID(
|
||||
q := `
|
||||
SELECT
|
||||
id,
|
||||
control_id,
|
||||
mitigation_id,
|
||||
name,
|
||||
description,
|
||||
time_estimate,
|
||||
state,
|
||||
assigned_to,
|
||||
content_ref,
|
||||
time_estimate,
|
||||
assigned_to,
|
||||
created_at,
|
||||
updated_at,
|
||||
version
|
||||
@@ -96,104 +94,100 @@ LIMIT 1;
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query task: %w", err)
|
||||
return fmt.Errorf("cannot query tasks: %w", err)
|
||||
}
|
||||
|
||||
task, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[Task])
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot collect task: %w", err)
|
||||
return fmt.Errorf("cannot collect tasks: %w", err)
|
||||
}
|
||||
|
||||
*t = task
|
||||
*c = task
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (t Task) Insert(
|
||||
func (c Task) Insert(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
) error {
|
||||
q := `
|
||||
INSERT INTO tasks (
|
||||
tenant_id,
|
||||
id,
|
||||
name,
|
||||
control_id,
|
||||
description,
|
||||
content_ref,
|
||||
created_at,
|
||||
updated_at,
|
||||
version,
|
||||
state,
|
||||
time_estimate,
|
||||
assigned_to
|
||||
)
|
||||
INSERT INTO
|
||||
tasks (
|
||||
tenant_id,
|
||||
id,
|
||||
mitigation_id,
|
||||
name,
|
||||
description,
|
||||
state,
|
||||
time_estimate,
|
||||
assigned_to,
|
||||
created_at,
|
||||
updated_at,
|
||||
version
|
||||
)
|
||||
VALUES (
|
||||
@tenant_id,
|
||||
@task_id,
|
||||
@mitigation_id,
|
||||
@name,
|
||||
@control_id,
|
||||
@description,
|
||||
@content_ref,
|
||||
@state,
|
||||
@time_estimate,
|
||||
@assigned_to,
|
||||
@created_at,
|
||||
@updated_at,
|
||||
@version,
|
||||
@state,
|
||||
@time_estimate,
|
||||
@assigned_to
|
||||
@version
|
||||
);
|
||||
`
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"tenant_id": scope.GetTenantID(),
|
||||
"task_id": t.ID,
|
||||
"control_id": t.ControlID,
|
||||
"name": t.Name,
|
||||
"description": t.Description,
|
||||
"content_ref": t.ContentRef,
|
||||
"created_at": t.CreatedAt,
|
||||
"updated_at": t.UpdatedAt,
|
||||
"version": t.Version,
|
||||
"state": t.State,
|
||||
"time_estimate": t.TimeEstimate,
|
||||
"assigned_to": t.AssignedTo,
|
||||
"task_id": c.ID,
|
||||
"mitigation_id": c.MitigationID,
|
||||
"name": c.Name,
|
||||
"description": c.Description,
|
||||
"state": c.State,
|
||||
"time_estimate": c.TimeEstimate,
|
||||
"assigned_to": c.AssignedToID,
|
||||
"created_at": c.CreatedAt,
|
||||
"updated_at": c.UpdatedAt,
|
||||
"version": 0,
|
||||
}
|
||||
_, err := conn.Exec(ctx, q, args)
|
||||
return err
|
||||
}
|
||||
|
||||
func (t *Tasks) LoadByControlID(
|
||||
func (c *Tasks) LoadByMitigationID(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
controlID gid.GID,
|
||||
mitigationID gid.GID,
|
||||
cursor *page.Cursor[TaskOrderField],
|
||||
) error {
|
||||
q := `
|
||||
SELECT
|
||||
id,
|
||||
control_id,
|
||||
mitigation_id,
|
||||
name,
|
||||
description,
|
||||
state,
|
||||
time_estimate,
|
||||
content_ref,
|
||||
time_estimate,
|
||||
assigned_to,
|
||||
created_at,
|
||||
updated_at,
|
||||
version,
|
||||
assigned_to
|
||||
version
|
||||
FROM
|
||||
tasks
|
||||
WHERE
|
||||
%s
|
||||
AND control_id = @control_id
|
||||
AND mitigation_id = @mitigation_id
|
||||
AND %s
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment(), cursor.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{"control_id": controlID}
|
||||
args := pgx.StrictNamedArgs{"mitigation_id": mitigationID}
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
maps.Copy(args, cursor.SQLArguments())
|
||||
|
||||
@@ -207,40 +201,44 @@ WHERE
|
||||
return fmt.Errorf("cannot collect tasks: %w", err)
|
||||
}
|
||||
|
||||
*t = tasks
|
||||
*c = tasks
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (t *Task) Update(
|
||||
func (c *Task) Update(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
params UpdateTaskParams,
|
||||
) error {
|
||||
q := `
|
||||
UPDATE tasks
|
||||
SET
|
||||
UPDATE tasks SET
|
||||
name = COALESCE(@name, name),
|
||||
description = COALESCE(@description, description),
|
||||
state = COALESCE(@state, state),
|
||||
time_estimate = COALESCE(@time_estimate, time_estimate),
|
||||
time_estimate = COALESCE(@time_estimate, time_estimate),
|
||||
updated_at = @updated_at,
|
||||
version = version + 1
|
||||
WHERE
|
||||
%s
|
||||
WHERE %s
|
||||
AND id = @task_id
|
||||
AND version = @expected_version
|
||||
RETURNING
|
||||
state,
|
||||
time_estimate,
|
||||
updated_at,
|
||||
version;
|
||||
RETURNING
|
||||
id,
|
||||
mitigation_id,
|
||||
name,
|
||||
description,
|
||||
state,
|
||||
time_estimate,
|
||||
assigned_to,
|
||||
created_at,
|
||||
updated_at,
|
||||
version
|
||||
`
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"task_id": t.ID,
|
||||
args := pgx.NamedArgs{
|
||||
"task_id": c.ID,
|
||||
"expected_version": params.ExpectedVersion,
|
||||
"name": params.Name,
|
||||
"description": params.Description,
|
||||
@@ -248,75 +246,235 @@ RETURNING
|
||||
"time_estimate": params.TimeEstimate,
|
||||
"updated_at": time.Now(),
|
||||
}
|
||||
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
err := conn.QueryRow(ctx, q, args).Scan(&t.State, &t.TimeEstimate, &t.UpdatedAt, &t.Version)
|
||||
return err
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query tasks: %w", err)
|
||||
}
|
||||
|
||||
task, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[Task])
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot collect tasks: %w", err)
|
||||
}
|
||||
|
||||
*c = task
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (t *Task) AssignTo(
|
||||
func (c *Task) AssignTo(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
assignedTo gid.GID,
|
||||
assignTo gid.GID,
|
||||
) error {
|
||||
q := `
|
||||
UPDATE tasks
|
||||
SET
|
||||
assigned_to = @assigned_to
|
||||
WHERE
|
||||
%s
|
||||
UPDATE tasks SET
|
||||
assigned_to = @assigned_to,
|
||||
updated_at = @updated_at,
|
||||
version = version + 1
|
||||
WHERE %s
|
||||
AND id = @task_id
|
||||
RETURNING
|
||||
id,
|
||||
mitigation_id,
|
||||
name,
|
||||
description,
|
||||
state,
|
||||
time_estimate,
|
||||
assigned_to,
|
||||
created_at,
|
||||
updated_at,
|
||||
version
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"task_id": t.ID,
|
||||
"assigned_to": assignedTo,
|
||||
args := pgx.NamedArgs{
|
||||
"task_id": c.ID,
|
||||
"assigned_to": assignTo,
|
||||
"updated_at": time.Now(),
|
||||
}
|
||||
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
_, err := conn.Exec(ctx, q, args)
|
||||
return err
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query tasks: %w", err)
|
||||
}
|
||||
|
||||
task, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[Task])
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot collect tasks: %w", err)
|
||||
}
|
||||
|
||||
*c = task
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (t *Task) Unassign(
|
||||
func (c *Task) Unassign(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
) error {
|
||||
q := `
|
||||
UPDATE tasks
|
||||
SET
|
||||
assigned_to = NULL
|
||||
WHERE
|
||||
%s
|
||||
UPDATE tasks SET
|
||||
assigned_to = NULL,
|
||||
updated_at = @updated_at,
|
||||
version = version + 1
|
||||
WHERE %s
|
||||
AND id = @task_id
|
||||
RETURNING
|
||||
id,
|
||||
mitigation_id,
|
||||
name,
|
||||
description,
|
||||
state,
|
||||
time_estimate,
|
||||
assigned_to,
|
||||
created_at,
|
||||
updated_at,
|
||||
version
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"task_id": t.ID,
|
||||
args := pgx.NamedArgs{
|
||||
"task_id": c.ID,
|
||||
"updated_at": time.Now(),
|
||||
}
|
||||
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
_, err := conn.Exec(ctx, q, args)
|
||||
return err
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query tasks: %w", err)
|
||||
}
|
||||
|
||||
task, err := pgx.CollectExactlyOneRow(rows, pgx.RowToStructByName[Task])
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot collect tasks: %w", err)
|
||||
}
|
||||
|
||||
*c = task
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (t *Task) Delete(
|
||||
func (c *Task) Delete(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
) error {
|
||||
q := `DELETE FROM tasks WHERE %s AND id = @task_id`
|
||||
q := `
|
||||
DELETE FROM tasks
|
||||
WHERE %s
|
||||
AND id = @task_id
|
||||
`
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{"task_id": t.ID}
|
||||
args := pgx.NamedArgs{
|
||||
"task_id": c.ID,
|
||||
}
|
||||
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
_, err := conn.Exec(ctx, q, args)
|
||||
return err
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot delete task: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// Helper functions for task management
|
||||
|
||||
var (
|
||||
ErrAssignTaskFailed = fmt.Errorf("failed to assign task")
|
||||
ErrUnassignTaskFailed = fmt.Errorf("failed to unassign task")
|
||||
ErrUpdateTaskFailed = fmt.Errorf("failed to update task")
|
||||
ErrDeleteTaskFailed = fmt.Errorf("failed to delete task")
|
||||
)
|
||||
|
||||
type TaskUpdate struct {
|
||||
Name *string
|
||||
Description *string
|
||||
State *TaskState
|
||||
TimeEstimate *time.Duration
|
||||
}
|
||||
|
||||
func AssignTask(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
taskID gid.GID,
|
||||
assignedToID gid.GID,
|
||||
) (*Task, error) {
|
||||
task := &Task{ID: taskID}
|
||||
if err := task.LoadByID(ctx, conn, scope, taskID); err != nil {
|
||||
return nil, ErrAssignTaskFailed
|
||||
}
|
||||
|
||||
if err := task.AssignTo(ctx, conn, scope, assignedToID); err != nil {
|
||||
return nil, ErrAssignTaskFailed
|
||||
}
|
||||
|
||||
return task, nil
|
||||
}
|
||||
|
||||
func UnassignTask(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
taskID gid.GID,
|
||||
) (*Task, error) {
|
||||
task := &Task{ID: taskID}
|
||||
if err := task.LoadByID(ctx, conn, scope, taskID); err != nil {
|
||||
return nil, ErrUnassignTaskFailed
|
||||
}
|
||||
|
||||
if err := task.Unassign(ctx, conn, scope); err != nil {
|
||||
return nil, ErrUnassignTaskFailed
|
||||
}
|
||||
|
||||
return task, nil
|
||||
}
|
||||
|
||||
func UpdateTask(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
taskID gid.GID,
|
||||
expectedVersion int,
|
||||
updates *TaskUpdate,
|
||||
) (*Task, error) {
|
||||
task := &Task{ID: taskID}
|
||||
|
||||
if err := task.Update(ctx, conn, scope, UpdateTaskParams{
|
||||
ExpectedVersion: expectedVersion,
|
||||
Name: updates.Name,
|
||||
Description: updates.Description,
|
||||
State: updates.State,
|
||||
TimeEstimate: updates.TimeEstimate,
|
||||
}); err != nil {
|
||||
return nil, ErrUpdateTaskFailed
|
||||
}
|
||||
|
||||
return task, nil
|
||||
}
|
||||
|
||||
func DeleteTask(
|
||||
ctx context.Context,
|
||||
conn pg.Conn,
|
||||
scope Scoper,
|
||||
taskID gid.GID,
|
||||
) error {
|
||||
task := &Task{ID: taskID}
|
||||
|
||||
if err := task.Delete(ctx, conn, scope); err != nil {
|
||||
return ErrDeleteTaskFailed
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user