Add data request pages to compliance portal
Let trust-portal data subjects submit and track GDPR/CCPA rights requests. The new Data Requests page lists the viewer's own requests and a dialog submits new ones, scoped server-side to the verified viewer email so former or inactive users can still exercise their rights. Submission requires magic-link sign-in (reusing the existing gate) but not the NDA gate. Extend the shared rights_request enums with RECTIFICATION, OBJECTION and COMPLAINT types plus a REJECTED state, and keep the console GraphQL, @probo/helpers and the MCP specification in sync. Expose a trust GraphQL surface (myRightsRequests query, createRightsRequest mutation) backed by a trust service and contact-scoped coredata loaders. Add the missing v2 UI kit primitives the dialog needs on top of Base UI: a SegmentedControl radio-cards group, a form Textarea, and a Field wrapper. Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
@@ -240,6 +240,98 @@ WHERE
|
||||
return nil
|
||||
}
|
||||
|
||||
func (rrs *RightsRequests) CountByOrganizationIDAndContact(
|
||||
ctx context.Context,
|
||||
conn pg.Querier,
|
||||
scope Scoper,
|
||||
organizationID gid.GID,
|
||||
contact string,
|
||||
) (int, error) {
|
||||
q := `
|
||||
SELECT
|
||||
COUNT(id)
|
||||
FROM
|
||||
rights_requests
|
||||
WHERE
|
||||
%s
|
||||
AND organization_id = @organization_id
|
||||
AND contact = @contact
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"organization_id": organizationID,
|
||||
"contact": contact,
|
||||
}
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
|
||||
row := conn.QueryRow(ctx, q, args)
|
||||
|
||||
var count int
|
||||
|
||||
err := row.Scan(&count)
|
||||
if err != nil {
|
||||
return 0, fmt.Errorf("cannot count rights requests: %w", err)
|
||||
}
|
||||
|
||||
return count, nil
|
||||
}
|
||||
|
||||
func (rrs *RightsRequests) LoadByOrganizationIDAndContact(
|
||||
ctx context.Context,
|
||||
conn pg.Querier,
|
||||
scope Scoper,
|
||||
organizationID gid.GID,
|
||||
contact string,
|
||||
cursor *page.Cursor[RightsRequestOrderField],
|
||||
) error {
|
||||
q := `
|
||||
SELECT
|
||||
id,
|
||||
organization_id,
|
||||
request_type,
|
||||
request_state,
|
||||
data_subject,
|
||||
contact,
|
||||
details,
|
||||
deadline,
|
||||
action_taken,
|
||||
created_at,
|
||||
updated_at
|
||||
FROM
|
||||
rights_requests
|
||||
WHERE
|
||||
%s
|
||||
AND organization_id = @organization_id
|
||||
AND contact = @contact
|
||||
AND %s
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment(), cursor.SQLFragment())
|
||||
|
||||
args := pgx.StrictNamedArgs{
|
||||
"organization_id": organizationID,
|
||||
"contact": contact,
|
||||
}
|
||||
maps.Copy(args, scope.SQLArguments())
|
||||
maps.Copy(args, cursor.SQLArguments())
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query rights requests: %w", err)
|
||||
}
|
||||
|
||||
requests, err := pgx.CollectRows(rows, pgx.RowToAddrOfStructByName[RightsRequest])
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot collect rights requests: %w", err)
|
||||
}
|
||||
|
||||
*rrs = requests
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func (rr *RightsRequest) Insert(
|
||||
ctx context.Context,
|
||||
conn pg.Tx,
|
||||
|
||||
Reference in New Issue
Block a user