Render longer vetting notes as markdown

Keep more of the orchestrator assessment text,
skipping profile fields already on the third party,
and render the notes as markdown in the console.

Signed-off-by: Sacha Al Himdani <sacha@probo.com>
This commit is contained in:
Sacha Al Himdani
2026-07-21 15:01:48 +02:00
parent 3805afc806
commit 5c5f60d5e1
3 changed files with 344 additions and 6 deletions

View File

@@ -28,6 +28,185 @@ import (
"go.probo.inc/probo/pkg/coredata"
)
func TestBuildRiskAssessmentNotesFromResult_FiltersDocument(t *testing.T) {
t.Parallel()
document := `# Third party Assessment: Acme
## Executive Summary
Approve with conditions.
## Third party Classification
- Name: Acme
- Description: SaaS analytics
## Overall Risk Score
Score 70/100.
## Compliance & Certifications
- SOC 2 Type II
## Privacy & Data Processing
Retention is 30 days.
### Data Classification & Handling
PII is encrypted at rest.
### Sub-Processors
| Name | Country | Purpose |
|------|---------|---------|
| AWS | United States | Hosting |
## Security Posture
TLS looks good.
## Market Presence
Strong brand.
`
notes := buildRiskAssessmentNotesFromResult(
Result{
Document: document,
Info: ThirdPartyInfo{
OverallRiskScore: 70,
Recommendation: "APPROVE_WITH_CONDITIONS",
},
},
)
assert.Contains(t, notes, "Executive Summary")
assert.Contains(t, notes, "Approve with conditions.")
assert.Contains(t, notes, "Overall Risk Score")
assert.Contains(t, notes, "Score 70/100.")
assert.Contains(t, notes, "Privacy & Data Processing")
assert.Contains(t, notes, "Retention is 30 days.")
assert.Contains(t, notes, "Data Classification & Handling")
assert.Contains(t, notes, "PII is encrypted at rest.")
assert.Contains(t, notes, "Security Posture")
assert.Contains(t, notes, "Market Presence")
assert.NotContains(t, notes, "Third party Classification")
assert.NotContains(t, notes, "Name: Acme")
assert.NotContains(t, notes, "Compliance & Certifications")
assert.NotContains(t, notes, "SOC 2 Type II")
assert.NotContains(t, notes, "Sub-Processors")
assert.NotContains(t, notes, "AWS")
assert.NotContains(t, notes, "Automated vetting")
}
func TestBuildRiskAssessmentNotesFromResult_FallsBackWhenDocumentEmpty(t *testing.T) {
t.Parallel()
info := ThirdPartyInfo{
OverallRiskRating: "Medium",
OverallRiskScore: 62,
Recommendation: "APPROVE_WITH_CONDITIONS",
}
notes := buildRiskAssessmentNotesFromResult(Result{Info: info})
assert.Equal(t, buildRiskAssessmentNotes(info), notes)
assert.Contains(t, notes, "Automated vetting")
}
func TestShouldDropVettingNotesSection(t *testing.T) {
t.Parallel()
assert.True(t, shouldDropVettingNotesSection("Third party Classification"))
assert.True(t, shouldDropVettingNotesSection("Third-Party Classification"))
assert.True(t, shouldDropVettingNotesSection("Vendor Classification"))
assert.True(t, shouldDropVettingNotesSection("Vendor-Classification"))
assert.True(t, shouldDropVettingNotesSection("Compliance & Certifications"))
assert.True(t, shouldDropVettingNotesSection("Sub-Processors"))
assert.True(t, shouldDropVettingNotesSection("Subprocessors"))
assert.False(t, shouldDropVettingNotesSection("Executive Summary"))
assert.False(t, shouldDropVettingNotesSection("Security Posture"))
assert.False(t, shouldDropVettingNotesSection("Three-Pillar Risk Assessment"))
assert.False(t, shouldDropVettingNotesSection("Data Classification & Handling"))
assert.False(t, shouldDropVettingNotesSection("AI risk classifications"))
}
func TestFilterVettingDocumentNotes_IgnoresHeadingsInFences(t *testing.T) {
t.Parallel()
document := `# Assessment
## Security Posture
Looks good.
` + "```" + `
## Third party Classification
This is an example heading inside a fence.
` + "```" + `
## Market Presence
Strong.
`
notes := filterVettingDocumentNotes(document)
assert.Contains(t, notes, "Security Posture")
assert.Contains(t, notes, "Looks good.")
assert.Contains(t, notes, "Third party Classification")
assert.Contains(t, notes, "This is an example heading inside a fence.")
assert.Contains(t, notes, "Market Presence")
assert.Contains(t, notes, "Strong.")
}
func TestFilterVettingDocumentNotes_IndentedAndTabHeadings(t *testing.T) {
t.Parallel()
document := `# Assessment
## Third party Classification
- Name: Acme
##` + "\t" + `Security Posture
TLS looks good.
## Market Presence
Strong.
`
notes := filterVettingDocumentNotes(document)
assert.NotContains(t, notes, "Third party Classification")
assert.NotContains(t, notes, "Name: Acme")
assert.Contains(t, notes, "Security Posture")
assert.Contains(t, notes, "TLS looks good.")
assert.Contains(t, notes, "Market Presence")
}
func TestParseMarkdownHeading(t *testing.T) {
t.Parallel()
level, title, ok := parseMarkdownHeading("## Executive Summary")
assert.True(t, ok)
assert.Equal(t, 2, level)
assert.Equal(t, "Executive Summary", title)
level, title, ok = parseMarkdownHeading(" ## Indented")
assert.True(t, ok)
assert.Equal(t, 2, level)
assert.Equal(t, "Indented", title)
level, title, ok = parseMarkdownHeading("##\tTabbed")
assert.True(t, ok)
assert.Equal(t, 2, level)
assert.Equal(t, "Tabbed", title)
level, title, ok = parseMarkdownHeading("## Trailing ##")
assert.True(t, ok)
assert.Equal(t, 2, level)
assert.Equal(t, "Trailing", title)
_, _, ok = parseMarkdownHeading(" ## Too indented")
assert.False(t, ok)
_, _, ok = parseMarkdownHeading("##NoSpace")
assert.False(t, ok)
}
func TestBuildRiskAssessmentNotes(t *testing.T) {
t.Parallel()