Flatten compliance portal package layout

Remove the root complianceportal package and the resolver
facade that existed only to break an IAM import cycle. Admin
policies, domain URL helpers, and actions live under
management; visitor OAuth metadata, brand URLs, and public
read paths live under visitor. Drop the duplicate trust API
magic-link mutations now that Connect handles portal auth, and
stop IAM from owning compliance page email branding.

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-07-17 16:19:39 +02:00
parent 4cec74c1a1
commit 7e0d187dcf
57 changed files with 737 additions and 1061 deletions

View File

@@ -1,51 +0,0 @@
// Copyright (c) 2025-2026 Probo Inc <hello@probo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package complianceportal
import (
"context"
"go.gearno.de/kit/pg"
"go.probo.inc/probo/pkg/complianceportal/resolver"
"go.probo.inc/probo/pkg/coredata"
)
// EffectiveDomainForTrustCenter returns the domain a compliance page is served
// under: the custom domain when it has an active certificate, otherwise the
// default subdomain when its certificate is active. It returns nil when no
// serving domain is available yet.
//
// It is the single certificate-status-aware domain resolver shared by the
// management and visitor sub-packages.
func EffectiveDomainForTrustCenter(
ctx context.Context,
conn pg.Querier,
scope coredata.Scoper,
trustCenter *coredata.TrustCenter,
) (*coredata.CustomDomain, error) {
return resolver.EffectiveDomainForTrustCenter(ctx, conn, scope, trustCenter)
}
// PublicURLForTrustCenter returns the canonical public URL of a compliance
// page on its dedicated domain.
func PublicURLForTrustCenter(
ctx context.Context,
conn pg.Querier,
scope coredata.Scoper,
trustCenter *coredata.TrustCenter,
baseDomain string,
) (string, error) {
return resolver.PublicURLForTrustCenter(ctx, conn, scope, trustCenter, baseDomain)
}

View File

@@ -83,7 +83,7 @@ func (utcar *UpdateAccessRequest) Validate() error {
func (s *Service) ListAccesses(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
cursor *page.Cursor[coredata.TrustCenterAccessOrderField],
) (*page.Page[*coredata.TrustCenterAccess, coredata.TrustCenterAccessOrderField], error) {
var accesses coredata.TrustCenterAccesses
@@ -91,7 +91,7 @@ func (s *Service) ListAccesses(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
return accesses.LoadByTrustCenterID(ctx, conn, scope, trustCenterID, cursor)
return accesses.LoadByTrustCenterID(ctx, conn, scope, compliancePageID, cursor)
},
)
if err != nil {
@@ -244,7 +244,7 @@ func (s *Service) UpdateAccess(
access = &coredata.TrustCenterAccess{}
if err := access.LoadByID(ctx, tx, scope, req.ID); err != nil {
return fmt.Errorf("cannot load trust center access: %w", err)
return fmt.Errorf("cannot load compliance page access: %w", err)
}
var tcdas coredata.TrustCenterDocumentAccesses
@@ -310,11 +310,11 @@ func (s *Service) UpdateAccess(
trustCenterFiles := &coredata.TrustCenterFiles{}
if err := trustCenterFiles.LoadByIDs(ctx, tx, scope, trustCenterFileIDs); err != nil {
return fmt.Errorf("cannot load trust center files: %w", err)
return fmt.Errorf("cannot load compliance page files: %w", err)
}
if err := tcdas.MergeTrustCenterFileAccesses(ctx, tx, scope, access.OrganizationID, access.ID, fileData); err != nil {
return fmt.Errorf("cannot merge trust center file accesses: %w", err)
return fmt.Errorf("cannot merge compliance page file accesses: %w", err)
}
}
@@ -358,11 +358,11 @@ func (s *Service) DeleteAccess(
access := &coredata.TrustCenterAccess{}
if err := access.LoadByID(ctx, tx, scope, trustCenterAccessID); err != nil {
return fmt.Errorf("cannot load trust center access: %w", err)
return fmt.Errorf("cannot load compliance page access: %w", err)
}
if err := access.Delete(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot delete trust center access: %w", err)
return fmt.Errorf("cannot delete compliance page access: %w", err)
}
return nil
@@ -387,7 +387,7 @@ func (s *Service) sendAccessEmail(
access.UpdatedAt = now
if err := access.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update trust center access with expiration: %w", err)
return fmt.Errorf("cannot update compliance page access with expiration: %w", err)
}
profile := &coredata.MembershipProfile{}
@@ -410,7 +410,7 @@ func (s *Service) sendAccessEmail(
subject, textBody, htmlBody, err := emailPresenter.RenderTrustCenterAccess(ctx, organization.Name)
if err != nil {
return fmt.Errorf("cannot render trust center access email: %w", err)
return fmt.Errorf("cannot render compliance page access email: %w", err)
}
accessEmail := coredata.NewEmail(

View File

@@ -12,7 +12,7 @@
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package complianceportal
package management
const (
// Custom domain actions.

View File

@@ -78,7 +78,7 @@ func (r *DeleteCustomLinkRequest) Validate() error {
func (s *Service) ListCustomLinks(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
cursor *page.Cursor[coredata.ComplianceCustomLinkOrderField],
) (*page.Page[*coredata.ComplianceCustomLink, coredata.ComplianceCustomLinkOrderField], error) {
var items coredata.ComplianceCustomLinks
@@ -86,7 +86,7 @@ func (s *Service) ListCustomLinks(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
if err := items.LoadByTrustCenterID(ctx, conn, scope, trustCenterID, cursor); err != nil {
if err := items.LoadByTrustCenterID(ctx, conn, scope, compliancePageID, cursor); err != nil {
return fmt.Errorf("cannot load custom links: %w", err)
}
@@ -117,14 +117,14 @@ func (s *Service) CreateCustomLink(
err := s.pg.WithTx(
ctx,
func(ctx context.Context, tx pg.Tx) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
item = &coredata.ComplianceCustomLink{
ID: id,
OrganizationID: trustCenter.OrganizationID,
OrganizationID: compliancePage.OrganizationID,
TrustCenterID: req.TrustCenterID,
Name: req.Name,
URL: req.URL,

View File

@@ -12,7 +12,7 @@
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package resolver
package management
import (
"context"
@@ -23,29 +23,25 @@ import (
"go.probo.inc/probo/pkg/gid"
)
// EffectiveDomainForTrustCenter returns the domain a compliance page is served
// under: the custom domain when it has an active certificate, otherwise the
// default subdomain when its certificate is active. It returns nil when no
// serving domain is available yet.
func EffectiveDomainForTrustCenter(
func (s *Service) EffectiveDomainForCompliancePage(
ctx context.Context,
conn pg.Querier,
scope coredata.Scoper,
trustCenter *coredata.TrustCenter,
compliancePage *coredata.TrustCenter,
) (*coredata.CustomDomain, error) {
byID, active, err := loadDomains(ctx, conn, scope, trustCenter)
byID, active, err := loadDomains(ctx, conn, scope, compliancePage)
if err != nil {
return nil, err
}
if trustCenter.CustomDomainID != nil {
if d := byID[*trustCenter.CustomDomainID]; d != nil && active[d.ID] {
if compliancePage.CustomDomainID != nil {
if d := byID[*compliancePage.CustomDomainID]; d != nil && active[d.ID] {
return d, nil
}
}
if trustCenter.DefaultDomainID != nil {
if d := byID[*trustCenter.DefaultDomainID]; d != nil && active[d.ID] {
if compliancePage.DefaultDomainID != nil {
if d := byID[*compliancePage.DefaultDomainID]; d != nil && active[d.ID] {
return d, nil
}
}
@@ -53,20 +49,13 @@ func EffectiveDomainForTrustCenter(
return nil, nil
}
// PublicURLForTrustCenter returns the canonical public URL of a compliance
// page. Compliance pages are always served on a dedicated domain: the custom
// domain when its certificate is active, otherwise the default probopage
// subdomain (even while its certificate provisions), and finally the default
// subdomain hostname derived from the page slug when no domain row is loaded
// yet.
func PublicURLForTrustCenter(
func (s *Service) PublicURLForCompliancePage(
ctx context.Context,
conn pg.Querier,
scope coredata.Scoper,
trustCenter *coredata.TrustCenter,
baseDomain string,
compliancePage *coredata.TrustCenter,
) (string, error) {
byID, active, err := loadDomains(ctx, conn, scope, trustCenter)
byID, active, err := loadDomains(ctx, conn, scope, compliancePage)
if err != nil {
return "", err
}
@@ -74,14 +63,14 @@ func PublicURLForTrustCenter(
var host string
switch {
case trustCenter.CustomDomainID != nil && byID[*trustCenter.CustomDomainID] != nil && active[*trustCenter.CustomDomainID]:
host = byID[*trustCenter.CustomDomainID].Domain
case trustCenter.DefaultDomainID != nil && byID[*trustCenter.DefaultDomainID] != nil:
host = byID[*trustCenter.DefaultDomainID].Domain
case compliancePage.CustomDomainID != nil && byID[*compliancePage.CustomDomainID] != nil && active[*compliancePage.CustomDomainID]:
host = byID[*compliancePage.CustomDomainID].Domain
case compliancePage.DefaultDomainID != nil && byID[*compliancePage.DefaultDomainID] != nil:
host = byID[*compliancePage.DefaultDomainID].Domain
}
if host == "" {
host = trustCenter.Slug + "." + baseDomain
host = compliancePage.Slug + "." + s.baseDomain
}
return "https://" + host, nil
@@ -91,15 +80,15 @@ func loadDomains(
ctx context.Context,
conn pg.Querier,
scope coredata.Scoper,
trustCenter *coredata.TrustCenter,
compliancePage *coredata.TrustCenter,
) (map[gid.GID]*coredata.CustomDomain, map[gid.GID]bool, error) {
var ids []gid.GID
if trustCenter.CustomDomainID != nil {
ids = append(ids, *trustCenter.CustomDomainID)
if compliancePage.CustomDomainID != nil {
ids = append(ids, *compliancePage.CustomDomainID)
}
if trustCenter.DefaultDomainID != nil {
ids = append(ids, *trustCenter.DefaultDomainID)
if compliancePage.DefaultDomainID != nil {
ids = append(ids, *compliancePage.DefaultDomainID)
}
byID := make(map[gid.GID]*coredata.CustomDomain)

View File

@@ -21,27 +21,13 @@ import (
"time"
"go.gearno.de/kit/pg"
"go.probo.inc/probo/pkg/complianceportal"
"go.probo.inc/probo/pkg/coredata"
"go.probo.inc/probo/pkg/gid"
"go.probo.inc/probo/pkg/validator"
)
// The compliance portal service owns the relationship between a compliance
// page (trust center) and its domains. A page has two slots stored on the
// trust center row: a default {slug}.probopage.com domain provided by Probo and
// an optional custom domain. It provisions each domain's TLS certificate
// through the generic certmanager service within the trust center's transaction
// so slot changes stay atomic with the page.
// ErrCustomDomainSlotTaken is returned when a compliance page already has a
// custom domain and another one is added.
var ErrCustomDomainSlotTaken = errors.New("compliance page already has a custom domain")
// AddCustomDomain provisions the compliance page's custom domain. It fails
// when the page already has one. The default probopage subdomain, provisioned
// at page creation, keeps serving as a fallback while the new certificate
// provisions.
func (s *Service) AddCustomDomain(
ctx context.Context,
scope coredata.Scoper,
@@ -60,12 +46,12 @@ func (s *Service) AddCustomDomain(
err := s.pg.WithTx(
ctx,
func(ctx context.Context, tx pg.Tx) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, tx, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, tx, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if trustCenter.CustomDomainID != nil {
if compliancePage.CustomDomainID != nil {
return ErrCustomDomainSlotTaken
}
@@ -76,7 +62,7 @@ func (s *Service) AddCustomDomain(
customDomain = coredata.NewCustomDomain(
scope.GetTenantID(),
trustCenter.OrganizationID,
compliancePage.OrganizationID,
domain,
false,
)
@@ -86,11 +72,11 @@ func (s *Service) AddCustomDomain(
return fmt.Errorf("cannot insert custom domain: %w", err)
}
trustCenter.CustomDomainID = &customDomain.ID
trustCenter.UpdatedAt = time.Now()
compliancePage.CustomDomainID = &customDomain.ID
compliancePage.UpdatedAt = time.Now()
if err := trustCenter.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update trust center: %w", err)
if err := compliancePage.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update compliance page: %w", err)
}
return nil
@@ -103,9 +89,6 @@ func (s *Service) AddCustomDomain(
return customDomain, nil
}
// RemoveCustomDomain clears the compliance page's custom domain and deletes
// the underlying domain together with its certificate. The default domain
// cannot be removed.
func (s *Service) RemoveCustomDomain(
ctx context.Context,
scope coredata.Scoper,
@@ -120,24 +103,24 @@ func (s *Service) RemoveCustomDomain(
}
if domain.Managed {
return complianceportal.ErrCustomDomainManaged
return ErrCustomDomainManaged
}
trustCenter := &coredata.TrustCenter{}
err := trustCenter.LoadByDomainID(ctx, tx, customDomainID)
compliancePage := &coredata.TrustCenter{}
err := compliancePage.LoadByDomainID(ctx, tx, customDomainID)
switch {
case err == nil:
if trustCenter.CustomDomainID != nil && *trustCenter.CustomDomainID == customDomainID {
trustCenter.CustomDomainID = nil
trustCenter.UpdatedAt = time.Now()
if compliancePage.CustomDomainID != nil && *compliancePage.CustomDomainID == customDomainID {
compliancePage.CustomDomainID = nil
compliancePage.UpdatedAt = time.Now()
if err := trustCenter.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update trust center: %w", err)
if err := compliancePage.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update compliance page: %w", err)
}
}
case errors.Is(err, coredata.ErrResourceNotFound):
default:
return fmt.Errorf("cannot load trust center by domain id: %w", err)
return fmt.Errorf("cannot load compliance page by domain id: %w", err)
}
if err := domain.Delete(ctx, tx, scope); err != nil {
@@ -155,78 +138,37 @@ func (s *Service) RemoveCustomDomain(
)
}
// GetCertificate returns the certificate backing a custom domain, or nil when
// the domain has no certificate yet.
func (s *Service) GetCertificate(
ctx context.Context,
scope coredata.Scoper,
domain *coredata.CustomDomain,
) (*coredata.Certificate, error) {
if domain == nil || domain.CertificateID == nil {
return nil, nil
}
return s.certManager.Get(ctx, scope, *domain.CertificateID)
}
// GetDefaultDomain returns the compliance page's default probopage subdomain,
// or nil when it has not been provisioned yet.
func (s *Service) GetDefaultDomain(
ctx context.Context,
scope coredata.Scoper,
compliancePageID gid.GID,
) (*coredata.CustomDomain, error) {
return s.domainSlot(ctx, scope, compliancePageID, func(tc *coredata.TrustCenter) *gid.GID {
return tc.DefaultDomainID
},
)
}
// GetCustomDomain returns the compliance page's custom domain, or nil when
// none is configured.
func (s *Service) GetCustomDomain(
ctx context.Context,
scope coredata.Scoper,
compliancePageID gid.GID,
) (*coredata.CustomDomain, error) {
return s.domainSlot(ctx, scope, compliancePageID, func(tc *coredata.TrustCenter) *gid.GID {
return tc.CustomDomainID
},
)
}
func (s *Service) domainSlot(
ctx context.Context,
scope coredata.Scoper,
compliancePageID gid.GID,
slot func(*coredata.TrustCenter) *gid.GID,
) (*coredata.CustomDomain, error) {
var domain *coredata.CustomDomain
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
domainID := slot(trustCenter)
if domainID == nil {
if compliancePage.DefaultDomainID == nil {
return nil
}
loaded := &coredata.CustomDomain{}
if err := loaded.LoadByID(ctx, conn, scope, *domainID); err != nil {
domain = &coredata.CustomDomain{}
if err := domain.LoadByID(ctx, conn, scope, *compliancePage.DefaultDomainID); err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
domain = nil
return nil
}
return fmt.Errorf("cannot load custom domain: %w", err)
}
domain = loaded
return nil
},
)
@@ -237,31 +179,34 @@ func (s *Service) domainSlot(
return domain, nil
}
// EffectiveDomain returns the domain a compliance page is served under: the
// custom domain when it has an active certificate, otherwise the default
// subdomain when its certificate is active. It returns nil when no serving
// domain is available yet.
func (s *Service) EffectiveDomain(
func (s *Service) GetCustomDomain(
ctx context.Context,
scope coredata.Scoper,
compliancePageID gid.GID,
) (*coredata.CustomDomain, error) {
var effective *coredata.CustomDomain
var domain *coredata.CustomDomain
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
d, err := complianceportal.EffectiveDomainForTrustCenter(ctx, conn, scope, trustCenter)
if err != nil {
return err
if compliancePage.CustomDomainID == nil {
return nil
}
effective = d
domain = &coredata.CustomDomain{}
if err := domain.LoadByID(ctx, conn, scope, *compliancePage.CustomDomainID); err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
domain = nil
return nil
}
return fmt.Errorf("cannot load custom domain: %w", err)
}
return nil
},
@@ -270,26 +215,7 @@ func (s *Service) EffectiveDomain(
return nil, err
}
return effective, nil
}
// EffectiveCanonicalHost returns the host a compliance page should be served
// under, or an empty string when no serving host is available yet.
func (s *Service) EffectiveCanonicalHost(
ctx context.Context,
scope coredata.Scoper,
compliancePageID gid.GID,
) (string, error) {
domain, err := s.EffectiveDomain(ctx, scope, compliancePageID)
if err != nil {
return "", err
}
if domain == nil {
return "", nil
}
return domain.Domain, nil
return domain, nil
}
// PublicURL returns the canonical public URL of a compliance page on its
@@ -304,18 +230,17 @@ func (s *Service) PublicURL(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
url, err := complianceportal.PublicURLForTrustCenter(ctx, conn, scope, trustCenter, s.baseDomain)
var err error
publicURL, err = s.PublicURLForCompliancePage(ctx, conn, scope, compliancePage)
if err != nil {
return err
return fmt.Errorf("cannot resolve public url: %w", err)
}
publicURL = url
return nil
},
)

View File

@@ -12,7 +12,7 @@
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package complianceportal
package management
import "errors"

View File

@@ -92,7 +92,7 @@ func (s *Service) ListFilesForOrganizationID(
ctx,
func(ctx context.Context, conn pg.Querier) error {
if err := files.LoadByOrganizationID(ctx, conn, scope, organizationID, cursor, filter); err != nil {
return fmt.Errorf("cannot load trust center files: %w", err)
return fmt.Errorf("cannot load compliance page files: %w", err)
}
return nil
@@ -119,7 +119,7 @@ func (s *Service) CountFilesForOrganizationID(
count, err = (&coredata.TrustCenterFiles{}).CountByOrganizationID(ctx, conn, scope, organizationID)
if err != nil {
return fmt.Errorf("cannot count trust center files: %w", err)
return fmt.Errorf("cannot count compliance page files: %w", err)
}
return nil
@@ -144,7 +144,7 @@ func (s *Service) GetFile(
func(ctx context.Context, conn pg.Querier) error {
file = &coredata.TrustCenterFile{}
if err := file.LoadByID(ctx, conn, scope, id); err != nil {
return fmt.Errorf("cannot load trust center file: %w", err)
return fmt.Errorf("cannot load compliance page file: %w", err)
}
return nil
@@ -210,7 +210,7 @@ func (s *Service) CreateFile(
}
if err := file.Insert(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot insert trust center file: %w", err)
return fmt.Errorf("cannot insert compliance page file: %w", err)
}
return nil
@@ -243,7 +243,7 @@ func (s *Service) UpdateFile(
file = &coredata.TrustCenterFile{}
if err := file.LoadByID(ctx, tx, scope, req.ID); err != nil {
return fmt.Errorf("cannot load trust center file: %w", err)
return fmt.Errorf("cannot load compliance page file: %w", err)
}
if req.Name != nil {
@@ -261,7 +261,7 @@ func (s *Service) UpdateFile(
file.UpdatedAt = now
if err := file.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update trust center file: %w", err)
return fmt.Errorf("cannot update compliance page file: %w", err)
}
return nil
@@ -285,11 +285,11 @@ func (s *Service) DeleteFile(
file := &coredata.TrustCenterFile{}
if err := file.LoadByID(ctx, tx, scope, trustCenterFileID); err != nil {
return fmt.Errorf("cannot load trust center file: %w", err)
return fmt.Errorf("cannot load compliance page file: %w", err)
}
if err := file.Delete(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot delete trust center file: %w", err)
return fmt.Errorf("cannot delete compliance page file: %w", err)
}
return nil
@@ -311,7 +311,7 @@ func (s *Service) GenerateFileURL(
func(ctx context.Context, conn pg.Querier) error {
file := &coredata.TrustCenterFile{}
if err := file.LoadByID(ctx, conn, scope, trustCenterFileID); err != nil {
return fmt.Errorf("cannot load trust center file: %w", err)
return fmt.Errorf("cannot load compliance page file: %w", err)
}
storedFile = &coredata.File{}
@@ -405,9 +405,9 @@ func (s *Service) uploadFile(
ContentType: new(contentType),
CacheControl: new("private, max-age=3600"),
Metadata: map[string]string{
"type": "trust-center-file",
"trust-center-file-id": trustCenterFileID.String(),
"organization-id": organizationID.String(),
"type": "compliance-page-file",
"compliance-page-file-id": trustCenterFileID.String(),
"organization-id": organizationID.String(),
},
},
)

View File

@@ -76,7 +76,7 @@ func (r *DeleteFrameworkRequest) Validate() error {
func (s *Service) ListFrameworksWithHidden(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
cursor *page.Cursor[coredata.ComplianceFrameworkOrderField],
) (*page.Page[*coredata.ComplianceFramework, coredata.ComplianceFrameworkOrderField], error) {
var cfs coredata.ComplianceFrameworks
@@ -84,7 +84,7 @@ func (s *Service) ListFrameworksWithHidden(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
if err := cfs.LoadWithHiddenByTrustCenterID(ctx, conn, scope, trustCenterID, cursor); err != nil {
if err := cfs.LoadWithHiddenByTrustCenterID(ctx, conn, scope, compliancePageID, cursor); err != nil {
return fmt.Errorf("cannot load frameworks with hidden: %w", err)
}
@@ -116,9 +116,9 @@ func (s *Service) CreateFramework(
err := s.pg.WithTx(
ctx,
func(ctx context.Context, tx pg.Tx) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
framework := &coredata.Framework{}
@@ -128,7 +128,7 @@ func (s *Service) CreateFramework(
cf = &coredata.ComplianceFramework{
ID: cfID,
OrganizationID: trustCenter.OrganizationID,
OrganizationID: compliancePage.OrganizationID,
TrustCenterID: req.TrustCenterID,
FrameworkID: req.FrameworkID,
CreatedAt: now,

View File

@@ -12,7 +12,7 @@
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package complianceportal
package management
import (
"go.probo.inc/probo/pkg/coredata"

View File

@@ -12,7 +12,7 @@
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package complianceportal
package management
import (
"go.probo.inc/probo/pkg/iam"

View File

@@ -33,7 +33,6 @@ import (
"go.gearno.de/crypto/uuid"
"go.gearno.de/kit/pg"
"go.probo.inc/probo/packages/emails"
"go.probo.inc/probo/pkg/complianceportal"
"go.probo.inc/probo/pkg/coredata"
"go.probo.inc/probo/pkg/filevalidation"
"go.probo.inc/probo/pkg/gid"
@@ -134,26 +133,26 @@ func (req *UpdateBrandRequest) Validate() error {
func (s *Service) Get(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) (*coredata.TrustCenter, error) {
var trustCenter *coredata.TrustCenter
var compliancePage *coredata.TrustCenter
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter = &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage = &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
return nil
},
)
if err != nil {
return nil, fmt.Errorf("cannot load trust center: %w", err)
return nil, fmt.Errorf("cannot load compliance page: %w", err)
}
return trustCenter, nil
return compliancePage, nil
}
func (s *Service) GetByOrganizationID(
@@ -161,14 +160,14 @@ func (s *Service) GetByOrganizationID(
scope coredata.Scoper,
organizationID gid.GID,
) (*coredata.TrustCenter, error) {
var trustCenter *coredata.TrustCenter
var compliancePage *coredata.TrustCenter
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter = &coredata.TrustCenter{}
if err := trustCenter.LoadByOrganizationID(ctx, conn, scope, organizationID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage = &coredata.TrustCenter{}
if err := compliancePage.LoadByOrganizationID(ctx, conn, scope, organizationID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
return nil
@@ -178,7 +177,7 @@ func (s *Service) GetByOrganizationID(
return nil, err
}
return trustCenter, nil
return compliancePage, nil
}
func (s *Service) Update(
@@ -191,40 +190,40 @@ func (s *Service) Update(
}
var (
trustCenter *coredata.TrustCenter
file *coredata.File
compliancePage *coredata.TrustCenter
file *coredata.File
)
err := s.pg.WithTx(
ctx,
func(ctx context.Context, conn pg.Tx) error {
trustCenter = &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, req.ID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage = &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, req.ID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if req.Active != nil {
trustCenter.Active = *req.Active
compliancePage.Active = *req.Active
}
if req.Slug != nil {
trustCenter.Slug = *req.Slug
compliancePage.Slug = *req.Slug
}
if req.SearchEngineIndexing != nil {
trustCenter.SearchEngineIndexing = *req.SearchEngineIndexing
compliancePage.SearchEngineIndexing = *req.SearchEngineIndexing
}
if req.Title != nil {
trustCenter.Title = *req.Title
compliancePage.Title = *req.Title
}
if req.Description != nil {
trustCenter.Description = *req.Description
compliancePage.Description = *req.Description
}
if req.WebsiteURL != nil {
trustCenter.WebsiteURL = *req.WebsiteURL
compliancePage.WebsiteURL = *req.WebsiteURL
}
if req.Email != nil {
@@ -234,22 +233,22 @@ func (s *Service) Update(
}
}
trustCenter.Email = *req.Email
compliancePage.Email = *req.Email
}
if req.HeadquarterAddress != nil {
trustCenter.HeadquarterAddress = *req.HeadquarterAddress
compliancePage.HeadquarterAddress = *req.HeadquarterAddress
}
trustCenter.UpdatedAt = time.Now()
compliancePage.UpdatedAt = time.Now()
if err := trustCenter.Update(ctx, conn, scope); err != nil {
return fmt.Errorf("cannot update trust center: %w", err)
if err := compliancePage.Update(ctx, conn, scope); err != nil {
return fmt.Errorf("cannot update compliance page: %w", err)
}
if trustCenter.NonDisclosureAgreementFileID != nil {
if compliancePage.NonDisclosureAgreementFileID != nil {
file = &coredata.File{}
if err := file.LoadByID(ctx, conn, scope, *trustCenter.NonDisclosureAgreementFileID); err != nil {
if err := file.LoadByID(ctx, conn, scope, *compliancePage.NonDisclosureAgreementFileID); err != nil {
return fmt.Errorf("cannot load file: %w", err)
}
}
@@ -261,7 +260,7 @@ func (s *Service) Update(
return nil, nil, err
}
return trustCenter, file, nil
return compliancePage, file, nil
}
func (s *Service) UploadNDA(
@@ -274,20 +273,20 @@ func (s *Service) UploadNDA(
}
var (
trustCenter *coredata.TrustCenter
file *coredata.File
compliancePage *coredata.TrustCenter
file *coredata.File
)
err := s.pg.WithTx(
ctx,
func(ctx context.Context, conn pg.Tx) error {
trustCenter = &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage = &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if trustCenter.OrganizationID == gid.Nil {
return fmt.Errorf("trust center %s has no organization", req.TrustCenterID)
if compliancePage.OrganizationID == gid.Nil {
return fmt.Errorf("compliance page %s has no organization", req.TrustCenterID)
}
objectKey, err := uuid.NewV7()
@@ -305,7 +304,7 @@ func (s *Service) UploadNDA(
file = &coredata.File{
ID: fileID,
OrganizationID: trustCenter.OrganizationID,
OrganizationID: compliancePage.OrganizationID,
BucketName: s.bucket,
MimeType: mimeType,
FileName: req.FileName,
@@ -320,9 +319,9 @@ func (s *Service) UploadNDA(
file,
req.File,
map[string]string{
"type": "trust-center-nda",
"trust-center-id": req.TrustCenterID.String(),
"organization-id": trustCenter.OrganizationID.String(),
"type": "compliance-page-nda",
"compliance-page-id": req.TrustCenterID.String(),
"organization-id": compliancePage.OrganizationID.String(),
},
)
if err != nil {
@@ -335,11 +334,11 @@ func (s *Service) UploadNDA(
return fmt.Errorf("cannot insert file: %w", err)
}
trustCenter.NonDisclosureAgreementFileID = &fileID
trustCenter.UpdatedAt = now
compliancePage.NonDisclosureAgreementFileID = &fileID
compliancePage.UpdatedAt = now
if err := trustCenter.Update(ctx, conn, scope); err != nil {
return fmt.Errorf("cannot update trust center: %w", err)
if err := compliancePage.Update(ctx, conn, scope); err != nil {
return fmt.Errorf("cannot update compliance page: %w", err)
}
return nil
@@ -349,29 +348,29 @@ func (s *Service) UploadNDA(
return nil, nil, err
}
return trustCenter, file, nil
return compliancePage, file, nil
}
func (s *Service) DeleteNDA(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) (*coredata.TrustCenter, *coredata.File, error) {
var trustCenter *coredata.TrustCenter
var compliancePage *coredata.TrustCenter
err := s.pg.WithTx(
ctx,
func(ctx context.Context, conn pg.Tx) error {
trustCenter = &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage = &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
trustCenter.NonDisclosureAgreementFileID = nil
trustCenter.UpdatedAt = time.Now()
compliancePage.NonDisclosureAgreementFileID = nil
compliancePage.UpdatedAt = time.Now()
if err := trustCenter.Update(ctx, conn, scope); err != nil {
return fmt.Errorf("cannot update trust center: %w", err)
if err := compliancePage.Update(ctx, conn, scope); err != nil {
return fmt.Errorf("cannot update compliance page: %w", err)
}
return nil
@@ -381,7 +380,7 @@ func (s *Service) DeleteNDA(
return nil, nil, err
}
return trustCenter, nil, nil
return compliancePage, nil, nil
}
func (s *Service) UpdateBrand(
@@ -394,55 +393,55 @@ func (s *Service) UpdateBrand(
}
var (
trustCenter *coredata.TrustCenter
ndaFile *coredata.File
compliancePage *coredata.TrustCenter
ndaFile *coredata.File
)
err := s.pg.WithTx(
ctx,
func(ctx context.Context, conn pg.Tx) error {
trustCenter = &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage = &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
now := time.Now()
if req.LogoFile != nil {
if *req.LogoFile == nil {
trustCenter.LogoFileID = nil
compliancePage.LogoFileID = nil
} else {
file, err := s.uploadBrandFile(ctx, scope, conn, *req.LogoFile, "trust-center-logo", trustCenter)
file, err := s.uploadBrandFile(ctx, scope, conn, *req.LogoFile, "compliance-page-logo", compliancePage)
if err != nil {
return fmt.Errorf("cannot upload logo file: %w", err)
}
trustCenter.LogoFileID = &file.ID
compliancePage.LogoFileID = &file.ID
}
}
if req.DarkLogoFile != nil {
if *req.DarkLogoFile == nil {
trustCenter.DarkLogoFileID = nil
compliancePage.DarkLogoFileID = nil
} else {
file, err := s.uploadBrandFile(ctx, scope, conn, *req.DarkLogoFile, "trust-center-dark-logo", trustCenter)
file, err := s.uploadBrandFile(ctx, scope, conn, *req.DarkLogoFile, "compliance-page-dark-logo", compliancePage)
if err != nil {
return fmt.Errorf("cannot upload dark logo file: %w", err)
}
trustCenter.DarkLogoFileID = &file.ID
compliancePage.DarkLogoFileID = &file.ID
}
}
trustCenter.UpdatedAt = now
compliancePage.UpdatedAt = now
if err := trustCenter.Update(ctx, conn, scope); err != nil {
return fmt.Errorf("cannot update trust center: %w", err)
if err := compliancePage.Update(ctx, conn, scope); err != nil {
return fmt.Errorf("cannot update compliance page: %w", err)
}
if trustCenter.NonDisclosureAgreementFileID != nil {
if compliancePage.NonDisclosureAgreementFileID != nil {
ndaFile = &coredata.File{}
if err := ndaFile.LoadByID(ctx, conn, scope, *trustCenter.NonDisclosureAgreementFileID); err != nil {
if err := ndaFile.LoadByID(ctx, conn, scope, *compliancePage.NonDisclosureAgreementFileID); err != nil {
return fmt.Errorf("cannot load nda file: %w", err)
}
}
@@ -454,7 +453,7 @@ func (s *Service) UpdateBrand(
return nil, nil, err
}
return trustCenter, ndaFile, nil
return compliancePage, ndaFile, nil
}
func (s *Service) uploadBrandFile(
@@ -463,7 +462,7 @@ func (s *Service) uploadBrandFile(
conn pg.Tx,
fileUpload *FileUpload,
fileType string,
trustCenter *coredata.TrustCenter,
compliancePage *coredata.TrustCenter,
) (*coredata.File, error) {
objectKey, err := uuid.NewV7()
if err != nil {
@@ -482,9 +481,9 @@ func (s *Service) uploadBrandFile(
ContentType: &mimeType,
CacheControl: new("max-age=3600, public"),
Metadata: map[string]string{
"type": fileType,
"trust-center-id": trustCenter.ID.String(),
"organization-id": trustCenter.OrganizationID.String(),
"type": fileType,
"compliance-page-id": compliancePage.ID.String(),
"organization-id": compliancePage.OrganizationID.String(),
},
})
if err != nil {
@@ -504,7 +503,7 @@ func (s *Service) uploadBrandFile(
file := &coredata.File{
ID: fileID,
OrganizationID: trustCenter.OrganizationID,
OrganizationID: compliancePage.OrganizationID,
BucketName: s.bucket,
MimeType: mimeType,
FileName: fileUpload.Filename,
@@ -525,26 +524,26 @@ func (s *Service) uploadBrandFile(
func (s *Service) GenerateNDAFileURL(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
expiresIn time.Duration,
) (*string, error) {
var file *coredata.File
trustCenter := &coredata.TrustCenter{}
compliancePage := &coredata.TrustCenter{}
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
if err := trustCenter.LoadByID(ctx, conn, scope, trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if trustCenter.NonDisclosureAgreementFileID == nil {
if compliancePage.NonDisclosureAgreementFileID == nil {
return nil
}
file = &coredata.File{}
if err := file.LoadByID(ctx, conn, scope, *trustCenter.NonDisclosureAgreementFileID); err != nil {
if err := file.LoadByID(ctx, conn, scope, *compliancePage.NonDisclosureAgreementFileID); err != nil {
return fmt.Errorf("cannot load file: %w", err)
}
@@ -555,7 +554,7 @@ func (s *Service) GenerateNDAFileURL(
return nil, err
}
if trustCenter.NonDisclosureAgreementFileID == nil {
if compliancePage.NonDisclosureAgreementFileID == nil {
return nil, nil
}
@@ -691,13 +690,7 @@ func (s *Service) EmailPresenterConfig(
return fmt.Errorf("cannot load organization: %w", err)
}
publicURL, err := complianceportal.PublicURLForTrustCenter(
ctx,
conn,
scope,
compliancePage,
s.baseDomain,
)
publicURL, err := s.PublicURLForCompliancePage(ctx, conn, scope, compliancePage)
if err != nil {
return fmt.Errorf("cannot resolve compliance page URL: %w", err)
}
@@ -736,24 +729,24 @@ func (s *Service) EmailPresenterConfig(
func (s *Service) GetMailingList(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) (*coredata.MailingList, error) {
var mailingList *coredata.MailingList
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if trustCenter.MailingListID == nil {
if compliancePage.MailingListID == nil {
return nil
}
mailingList = &coredata.MailingList{}
if err := mailingList.LoadByID(ctx, conn, scope, *trustCenter.MailingListID); err != nil {
if err := mailingList.LoadByID(ctx, conn, scope, *compliancePage.MailingListID); err != nil {
return fmt.Errorf("cannot load mailing list: %w", err)
}

View File

@@ -82,7 +82,7 @@ func (utcrr *UpdateReferenceRequest) Validate() error {
func (s *Service) ListReferences(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
cursor *page.Cursor[coredata.TrustCenterReferenceOrderField],
) (*page.Page[*coredata.TrustCenterReference, coredata.TrustCenterReferenceOrderField], error) {
var references coredata.TrustCenterReferences
@@ -90,9 +90,9 @@ func (s *Service) ListReferences(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
err := references.LoadByTrustCenterID(ctx, conn, scope, trustCenterID, cursor)
err := references.LoadByTrustCenterID(ctx, conn, scope, compliancePageID, cursor)
if err != nil {
return fmt.Errorf("cannot load trust center references: %w", err)
return fmt.Errorf("cannot load compliance page references: %w", err)
}
return nil
@@ -108,7 +108,7 @@ func (s *Service) ListReferences(
func (s *Service) CountReferences(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) (int, error) {
var count int
@@ -117,9 +117,9 @@ func (s *Service) CountReferences(
func(ctx context.Context, conn pg.Querier) (err error) {
references := coredata.TrustCenterReferences{}
count, err = references.CountByTrustCenterID(ctx, conn, scope, trustCenterID)
count, err = references.CountByTrustCenterID(ctx, conn, scope, compliancePageID)
if err != nil {
return fmt.Errorf("cannot count trust center references: %w", err)
return fmt.Errorf("cannot count compliance page references: %w", err)
}
return nil
@@ -144,7 +144,7 @@ func (s *Service) GetReference(
func(ctx context.Context, conn pg.Querier) error {
err := reference.LoadByID(ctx, conn, scope, referenceID)
if err != nil {
return fmt.Errorf("cannot load trust center reference: %w", err)
return fmt.Errorf("cannot load compliance page reference: %w", err)
}
return nil
@@ -177,9 +177,9 @@ func (s *Service) CreateReference(
err := s.pg.WithTx(
ctx,
func(ctx context.Context, tx pg.Tx) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
fileID, s3Key, err := s.uploadReferenceLogoFile(ctx, scope, tx, req.LogoFile, referenceID, req.TrustCenterID, now)
@@ -191,7 +191,7 @@ func (s *Service) CreateReference(
reference = &coredata.TrustCenterReference{
ID: referenceID,
OrganizationID: trustCenter.OrganizationID,
OrganizationID: compliancePage.OrganizationID,
TrustCenterID: req.TrustCenterID,
Name: req.Name,
Description: req.Description,
@@ -202,7 +202,7 @@ func (s *Service) CreateReference(
}
if err := reference.Insert(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot insert trust center reference: %w", err)
return fmt.Errorf("cannot insert compliance page reference: %w", err)
}
return nil
@@ -239,7 +239,7 @@ func (s *Service) UpdateReference(
reference = &coredata.TrustCenterReference{}
if err := reference.LoadByID(ctx, tx, scope, req.ID); err != nil {
return fmt.Errorf("cannot load trust center reference: %w", err)
return fmt.Errorf("cannot load compliance page reference: %w", err)
}
if req.LogoFile != nil {
@@ -278,7 +278,7 @@ func (s *Service) UpdateReference(
}
if err := reference.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update trust center reference: %w", err)
return fmt.Errorf("cannot update compliance page reference: %w", err)
}
return nil
@@ -303,11 +303,11 @@ func (s *Service) DeleteReference(
reference := &coredata.TrustCenterReference{}
if err := reference.LoadByID(ctx, tx, scope, trustCenterReferenceID); err != nil {
return fmt.Errorf("cannot load trust center reference: %w", err)
return fmt.Errorf("cannot load compliance page reference: %w", err)
}
if err := reference.Delete(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot delete trust center reference: %w", err)
return fmt.Errorf("cannot delete compliance page reference: %w", err)
}
return nil
@@ -331,7 +331,7 @@ func (s *Service) GenerateReferenceLogoURL(
},
)
if err != nil {
return "", fmt.Errorf("cannot load trust center reference: %w", err)
return "", fmt.Errorf("cannot load compliance page reference: %w", err)
}
file, err := s.fileManager.GetPublicFile(ctx, reference.LogoFileID)
@@ -348,7 +348,7 @@ func (s *Service) uploadReferenceLogoFile(
tx pg.Tx,
file File,
referenceID gid.GID,
trustCenterID gid.GID,
compliancePageID gid.GID,
now time.Time,
) (gid.GID, string, error) {
fileID := gid.New(scope.GetTenantID(), coredata.FileEntityType)
@@ -358,9 +358,9 @@ func (s *Service) uploadReferenceLogoFile(
return gid.GID{}, "", fmt.Errorf("cannot generate object key: %w", err)
}
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, tx, scope, trustCenterID); err != nil {
return gid.GID{}, "", fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, tx, scope, compliancePageID); err != nil {
return gid.GID{}, "", fmt.Errorf("cannot load compliance page: %w", err)
}
var (
@@ -418,9 +418,9 @@ func (s *Service) uploadReferenceLogoFile(
ContentType: new(contentType),
CacheControl: new("max-age=3600, public"),
Metadata: map[string]string{
"type": "trust-center-reference-logo",
"trust-center-reference-id": referenceID.String(),
"organization-id": trustCenter.OrganizationID.String(),
"type": "compliance-page-reference-logo",
"compliance-page-reference-id": referenceID.String(),
"organization-id": compliancePage.OrganizationID.String(),
},
},
)
@@ -430,7 +430,7 @@ func (s *Service) uploadReferenceLogoFile(
fileRecord := &coredata.File{
ID: fileID,
OrganizationID: trustCenter.OrganizationID,
OrganizationID: compliancePage.OrganizationID,
BucketName: s.bucket,
MimeType: contentType,
FileName: filename,

View File

@@ -13,7 +13,7 @@
// PERFORMANCE OF THIS SOFTWARE.
// Package management holds the scoped, admin-facing compliance portal services
// (trust center CRUD, domains, frameworks, external URLs, references, files and
// (compliance page CRUD, domains, frameworks, external URLs, references, files and
// accesses). It is the write side of the compliance portal feature.
package management
@@ -37,7 +37,7 @@ const (
type (
// Service is the admin-facing compliance portal service. It exposes the
// scoped CRUD operations for the trust center and its related resources as
// scoped CRUD operations for the compliance page and its related resources as
// methods on a single type.
Service struct {
pg *pg.Client

View File

@@ -12,7 +12,7 @@
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package complianceportal
package visitor
import (
"fmt"

View File

@@ -12,7 +12,7 @@
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package complianceportal
package visitor
import (
"fmt"

View File

@@ -12,7 +12,7 @@
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package complianceportal
package visitor
import (
"testing"
@@ -66,7 +66,7 @@ func TestBuildClientMetadataDocument(t *testing.T) {
websiteURL := "https://www.acme.com"
portal := &coredata.TrustCenter{
Title: "Acme Trust Center",
Title: "Acme Compliance Page",
WebsiteURL: &websiteURL,
}
@@ -76,7 +76,7 @@ func TestBuildClientMetadataDocument(t *testing.T) {
)
require.NoError(t, err)
assert.Equal(t, "https://acme.example.com/.well-known/oauth-client-metadata", doc.ClientID)
assert.Equal(t, "Acme Trust Center", doc.ClientName)
assert.Equal(t, "Acme Compliance Page", doc.ClientName)
assert.Equal(t, []string{"https://acme.example.com/callback"}, doc.RedirectURIs)
assert.Equal(t, "https://acme.example.com", doc.ClientURI)
assert.Equal(t, VisitorOAuthScope, doc.Scope)
@@ -88,7 +88,7 @@ func TestBuildClientMetadataDocument_LogoURIUsesBrandLogoEndpoint(t *testing.T)
logoFileID := gid.MustParseGID("WR-qMrB5AAEAGQAAAZ9mIO8B8vDFQ-i3")
portal := &coredata.TrustCenter{
Title: "Acme Trust Center",
Title: "Acme Compliance Page",
LogoFileID: &logoFileID,
}

View File

@@ -58,7 +58,7 @@ func (s *Service) GetComplianceFramework(
func (s *Service) ListComplianceFrameworksByPortalID(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
cursor *page.Cursor[coredata.ComplianceFrameworkOrderField],
) (*page.Page[*coredata.ComplianceFramework, coredata.ComplianceFrameworkOrderField], error) {
var complianceFrameworks coredata.ComplianceFrameworks
@@ -66,7 +66,7 @@ func (s *Service) ListComplianceFrameworksByPortalID(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
err := complianceFrameworks.LoadByTrustCenterID(ctx, conn, scope, trustCenterID, cursor)
err := complianceFrameworks.LoadByTrustCenterID(ctx, conn, scope, compliancePageID, cursor)
if err != nil {
return fmt.Errorf("cannot load compliance frameworks: %w", err)
}

View File

@@ -122,40 +122,40 @@ type (
func (s *Service) RenderCompliancePageMarkdown(
ctx context.Context,
w io.Writer,
trustCenterID gid.GID,
compliancePageID gid.GID,
scope coredata.Scoper,
) error {
org, err := s.GetPortalOrganization(ctx, trustCenterID)
org, err := s.GetPortalOrganization(ctx, compliancePageID)
if err != nil {
return fmt.Errorf("cannot load organization for compliance page: %w", err)
}
trustCenter, err := s.GetPortalByID(ctx, trustCenterID)
compliancePage, err := s.GetPortalByID(ctx, compliancePageID)
if err != nil {
return fmt.Errorf("cannot load trust center for compliance page: %w", err)
return fmt.Errorf("cannot load compliance page: %w", err)
}
data := &compliancePageData{
OrgName: org.Name,
}
if trustCenter.Description != nil && *trustCenter.Description != "" {
data.Description = *trustCenter.Description
if compliancePage.Description != nil && *compliancePage.Description != "" {
data.Description = *compliancePage.Description
}
if trustCenter.WebsiteURL != nil && *trustCenter.WebsiteURL != "" {
data.Details = append(data.Details, compliancePageDetail{Label: "Website", Value: *trustCenter.WebsiteURL})
if compliancePage.WebsiteURL != nil && *compliancePage.WebsiteURL != "" {
data.Details = append(data.Details, compliancePageDetail{Label: "Website", Value: *compliancePage.WebsiteURL})
}
if trustCenter.Email != nil && *trustCenter.Email != "" {
data.Details = append(data.Details, compliancePageDetail{Label: "Email", Value: *trustCenter.Email})
if compliancePage.Email != nil && *compliancePage.Email != "" {
data.Details = append(data.Details, compliancePageDetail{Label: "Email", Value: *compliancePage.Email})
}
if trustCenter.HeadquarterAddress != nil && *trustCenter.HeadquarterAddress != "" {
data.Details = append(data.Details, compliancePageDetail{Label: "Headquarters", Value: *trustCenter.HeadquarterAddress})
if compliancePage.HeadquarterAddress != nil && *compliancePage.HeadquarterAddress != "" {
data.Details = append(data.Details, compliancePageDetail{Label: "Headquarters", Value: *compliancePage.HeadquarterAddress})
}
data.Frameworks, err = s.fetchComplianceFrameworks(ctx, scope, trustCenterID)
data.Frameworks, err = s.fetchComplianceFrameworks(ctx, scope, compliancePageID)
if err != nil {
return fmt.Errorf("cannot fetch compliance frameworks: %w", err)
}
@@ -175,12 +175,12 @@ func (s *Service) RenderCompliancePageMarkdown(
return fmt.Errorf("cannot fetch thirdParties: %w", err)
}
data.References, err = s.fetchReferences(ctx, scope, trustCenterID)
data.References, err = s.fetchReferences(ctx, scope, compliancePageID)
if err != nil {
return fmt.Errorf("cannot fetch references: %w", err)
}
data.CustomLinks, err = s.fetchCustomLinks(ctx, scope, trustCenterID)
data.CustomLinks, err = s.fetchCustomLinks(ctx, scope, compliancePageID)
if err != nil {
return fmt.Errorf("cannot fetch external links: %w", err)
}
@@ -207,11 +207,11 @@ type (
func (s *Service) RenderSitemap(
ctx context.Context,
w io.Writer,
trustCenterID gid.GID,
compliancePageID gid.GID,
scope coredata.Scoper,
baseURL string,
) error {
org, err := s.GetPortalOrganization(ctx, trustCenterID)
org, err := s.GetPortalOrganization(ctx, compliancePageID)
if err != nil {
return fmt.Errorf("cannot load organization for sitemap: %w", err)
}
@@ -322,7 +322,7 @@ func (s *Service) fetchDocumentIDs(
coredata.NewTrustCenterFileFilter(),
)
if err != nil {
return nil, fmt.Errorf("cannot list trust center files: %w", err)
return nil, fmt.Errorf("cannot list compliance page files: %w", err)
}
for _, file := range result.Data {
@@ -401,7 +401,7 @@ func (s *Service) fetchDocumentIDs(
func (s *Service) fetchComplianceFrameworks(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) ([]compliancePageFramework, error) {
var frameworks []compliancePageFramework
@@ -417,7 +417,7 @@ func (s *Service) fetchComplianceFrameworks(
},
)
result, err := s.ListComplianceFrameworksByPortalID(ctx, scope, trustCenterID, cursor)
result, err := s.ListComplianceFrameworksByPortalID(ctx, scope, compliancePageID, cursor)
if err != nil {
return nil, fmt.Errorf("cannot list compliance frameworks: %w", err)
}
@@ -621,7 +621,7 @@ func (s *Service) fetchThirdParties(
func (s *Service) fetchReferences(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) ([]compliancePageReference, error) {
var refs []compliancePageReference
@@ -637,7 +637,7 @@ func (s *Service) fetchReferences(
},
)
result, err := s.ListPortalReferencesForPortalID(ctx, scope, trustCenterID, cursor)
result, err := s.ListPortalReferencesForPortalID(ctx, scope, compliancePageID, cursor)
if err != nil {
return nil, fmt.Errorf("cannot list references: %w", err)
}
@@ -669,7 +669,7 @@ func (s *Service) fetchReferences(
func (s *Service) fetchCustomLinks(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) ([]compliancePageCustomLink, error) {
var links []compliancePageCustomLink
@@ -685,7 +685,7 @@ func (s *Service) fetchCustomLinks(
},
)
result, err := s.ListCustomLinksForPortalID(ctx, scope, trustCenterID, cursor)
result, err := s.ListCustomLinksForPortalID(ctx, scope, compliancePageID, cursor)
if err != nil {
return nil, fmt.Errorf("cannot list custom links: %w", err)
}

View File

@@ -33,7 +33,7 @@ import (
func (s *Service) ListCustomLinksForPortalID(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
cursor *page.Cursor[coredata.ComplianceCustomLinkOrderField],
) (*page.Page[*coredata.ComplianceCustomLink, coredata.ComplianceCustomLinkOrderField], error) {
var links coredata.ComplianceCustomLinks
@@ -41,7 +41,7 @@ func (s *Service) ListCustomLinksForPortalID(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
err := links.LoadByTrustCenterID(ctx, conn, scope, trustCenterID, cursor)
err := links.LoadByTrustCenterID(ctx, conn, scope, compliancePageID, cursor)
if err != nil {
return fmt.Errorf("cannot load custom links: %w", err)
}

View File

@@ -159,7 +159,7 @@ func (s *Service) exportDocumentPDFData(
}
if document.TrustCenterVisibility == coredata.TrustCenterVisibilityNone {
return fmt.Errorf("document not visible on trust center")
return fmt.Errorf("document not visible on compliance page")
}
if err := version.LoadLatestPublishedVersion(ctx, conn, scope, documentID); err != nil {

View File

@@ -23,17 +23,17 @@ package visitor
import "errors"
var (
ErrOAuthStateNotFound = errors.New("oauth state not found")
ErrOAuthStateExpired = errors.New("oauth state expired")
ErrPageNotFound = errors.New("page not found")
ErrMembershipNotFound = errors.New("membership not found")
ErrUserNotFound = errors.New("user not found")
ErrUserInactive = errors.New("user inactive")
ErrDocumentAccessNotFound = errors.New("document access not found")
ErrNDAFileNotFound = errors.New("NDA file not found")
ErrDocumentNotFound = errors.New("document not found")
ErrDocumentNotVisible = errors.New("document not visible")
ErrReportNotFound = errors.New("report not found")
ErrTrustCenterFileNotFound = errors.New("trust center file not found")
ErrTrustCenterFileNotVisible = errors.New("trust center file not visible")
ErrOAuthStateNotFound = errors.New("oauth state not found")
ErrOAuthStateExpired = errors.New("oauth state expired")
ErrPageNotFound = errors.New("page not found")
ErrMembershipNotFound = errors.New("membership not found")
ErrUserNotFound = errors.New("user not found")
ErrUserInactive = errors.New("user inactive")
ErrDocumentAccessNotFound = errors.New("document access not found")
ErrNDAFileNotFound = errors.New("NDA file not found")
ErrDocumentNotFound = errors.New("document not found")
ErrDocumentNotVisible = errors.New("document not visible")
ErrReportNotFound = errors.New("report not found")
ErrPortalFileNotFound = errors.New("portal file not found")
ErrPortalFileNotVisible = errors.New("portal file not visible")
)

View File

@@ -60,9 +60,9 @@ func (s *Service) RequestPortalAccess(
err := s.pg.WithTx(
ctx,
func(ctx context.Context, tx pg.Tx) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, tx, scope, req.TrustCenterID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
access = &coredata.TrustCenterAccess{}
@@ -70,7 +70,7 @@ func (s *Service) RequestPortalAccess(
return fmt.Errorf("cannot load compliance page membership: %w", err)
}
organizationID := trustCenter.OrganizationID
organizationID := compliancePage.OrganizationID
documentIDs := req.DocumentIDs
if req.DocumentIDs == nil {
@@ -145,7 +145,7 @@ func (s *Service) RequestPortalAccess(
func(ctx context.Context, cursor *page.Cursor[coredata.TrustCenterFileOrderField]) ([]*coredata.TrustCenterFile, error) {
var batch coredata.TrustCenterFiles
if err := batch.LoadByOrganizationID(ctx, tx, scope, organizationID, cursor, filter); err != nil {
return nil, fmt.Errorf("cannot list trust center files: %w", err)
return nil, fmt.Errorf("cannot list compliance page files: %w", err)
}
return batch, nil
@@ -196,7 +196,7 @@ func (s *Service) RequestPortalAccess(
coredata.TrustCenterDocumentAccessStatusRequested,
now,
); err != nil {
return fmt.Errorf("cannot bulk insert trust center document accesses: %w", err)
return fmt.Errorf("cannot bulk insert compliance page document accesses: %w", err)
}
if err := accesses.BulkInsertReportFileAccesses(
@@ -209,7 +209,7 @@ func (s *Service) RequestPortalAccess(
coredata.TrustCenterDocumentAccessStatusRequested,
now,
); err != nil {
return fmt.Errorf("cannot bulk insert trust center report accesses: %w", err)
return fmt.Errorf("cannot bulk insert compliance page report accesses: %w", err)
}
if err := accesses.BulkInsertTrustCenterFileAccesses(
@@ -222,7 +222,7 @@ func (s *Service) RequestPortalAccess(
coredata.TrustCenterDocumentAccessStatusRequested,
now,
); err != nil {
return fmt.Errorf("cannot bulk insert trust center file accesses: %w", err)
return fmt.Errorf("cannot bulk insert compliance page file accesses: %w", err)
}
return nil
@@ -242,7 +242,7 @@ func (s *Service) RequestPortalAccess(
func (s *Service) GetPortalAccess(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
identityID gid.GID,
) (coredata.TrustCenterAccess, error) {
var access coredata.TrustCenterAccess
@@ -250,7 +250,7 @@ func (s *Service) GetPortalAccess(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
return access.LoadByTrustCenterIDAndIdentityID(ctx, conn, scope, trustCenterID, identityID)
return access.LoadByTrustCenterIDAndIdentityID(ctx, conn, scope, compliancePageID, identityID)
},
)
@@ -260,7 +260,7 @@ func (s *Service) GetPortalAccess(
func (s *Service) GetPortalDocumentAccess(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
identityID gid.GID,
documentID gid.GID,
) (*coredata.TrustCenterDocumentAccess, error) {
@@ -271,13 +271,13 @@ func (s *Service) GetPortalDocumentAccess(
func(ctx context.Context, conn pg.Querier) error {
access := &coredata.TrustCenterAccess{}
err := access.LoadByTrustCenterIDAndIdentityID(ctx, conn, scope, trustCenterID, identityID)
err := access.LoadByTrustCenterIDAndIdentityID(ctx, conn, scope, compliancePageID, identityID)
if err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
return ErrMembershipNotFound
}
return fmt.Errorf("cannot load trust center access: %w", err)
return fmt.Errorf("cannot load compliance page access: %w", err)
}
profile := &coredata.MembershipProfile{}
@@ -315,7 +315,7 @@ func (s *Service) GetPortalDocumentAccess(
func (s *Service) GetPortalReportFileAccess(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
identityID gid.GID,
reportFileID gid.GID,
) (*coredata.TrustCenterDocumentAccess, error) {
@@ -326,13 +326,13 @@ func (s *Service) GetPortalReportFileAccess(
func(ctx context.Context, conn pg.Querier) error {
access := &coredata.TrustCenterAccess{}
err := access.LoadByTrustCenterIDAndIdentityID(ctx, conn, scope, trustCenterID, identityID)
err := access.LoadByTrustCenterIDAndIdentityID(ctx, conn, scope, compliancePageID, identityID)
if err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
return ErrMembershipNotFound
}
return fmt.Errorf("cannot load trust center access: %w", err)
return fmt.Errorf("cannot load compliance page access: %w", err)
}
profile := &coredata.MembershipProfile{}
@@ -370,7 +370,7 @@ func (s *Service) GetPortalReportFileAccess(
func (s *Service) GetPortalFileAccess(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
identityID gid.GID,
trustCenterFileID gid.GID,
) (*coredata.TrustCenterDocumentAccess, error) {
@@ -381,13 +381,13 @@ func (s *Service) GetPortalFileAccess(
func(ctx context.Context, conn pg.Querier) error {
access := &coredata.TrustCenterAccess{}
err := access.LoadByTrustCenterIDAndIdentityID(ctx, conn, scope, trustCenterID, identityID)
err := access.LoadByTrustCenterIDAndIdentityID(ctx, conn, scope, compliancePageID, identityID)
if err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
return ErrMembershipNotFound
}
return fmt.Errorf("cannot load trust center access: %w", err)
return fmt.Errorf("cannot load compliance page access: %w", err)
}
profile := &coredata.MembershipProfile{}
@@ -409,7 +409,7 @@ func (s *Service) GetPortalFileAccess(
return ErrDocumentAccessNotFound
}
return fmt.Errorf("cannot load trust center file access: %w", err)
return fmt.Errorf("cannot load compliance page file access: %w", err)
}
return nil
@@ -434,9 +434,9 @@ func (s *Service) GrantPortalAccessByIDs(
return s.pg.WithTx(
ctx,
func(ctx context.Context, tx pg.Tx) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByOrganizationID(ctx, tx, scope, organizationID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByOrganizationID(ctx, tx, scope, organizationID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
identity := &coredata.Identity{}
@@ -445,8 +445,8 @@ func (s *Service) GrantPortalAccessByIDs(
}
access := &coredata.TrustCenterAccess{}
if err := access.LoadByTrustCenterIDAndIdentityID(ctx, tx, scope, trustCenter.ID, identity.ID); err != nil {
return fmt.Errorf("cannot load trust center access: %w", err)
if err := access.LoadByTrustCenterIDAndIdentityID(ctx, tx, scope, compliancePage.ID, identity.ID); err != nil {
return fmt.Errorf("cannot load compliance page access: %w", err)
}
profile := &coredata.MembershipProfile{}
@@ -477,7 +477,7 @@ func (s *Service) GrantPortalAccessByIDs(
if len(fileIDs) > 0 {
if err := coredata.GrantByTrustCenterFileIDs(ctx, tx, scope, access.ID, fileIDs, now); err != nil {
return fmt.Errorf("cannot grant trust center file accesses: %w", err)
return fmt.Errorf("cannot grant compliance page file accesses: %w", err)
}
}
@@ -515,7 +515,7 @@ func (s *Service) sendPortalAccessEmail(
access.UpdatedAt = now
if err := access.Update(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot update trust center access with expiration: %w", err)
return fmt.Errorf("cannot update compliance page access with expiration: %w", err)
}
emailPresenterCfg, err := s.GetPortalEmailPresenterConfig(ctx, scope, access.TrustCenterID)
@@ -527,7 +527,7 @@ func (s *Service) sendPortalAccessEmail(
subject, textBody, htmlBody, err := emailPresenter.RenderTrustCenterAccess(ctx, organization.Name)
if err != nil {
return fmt.Errorf("cannot render trust center access email: %w", err)
return fmt.Errorf("cannot render compliance page access email: %w", err)
}
accessEmail := coredata.NewEmail(
@@ -560,9 +560,9 @@ func (s *Service) RejectOrRevokePortalAccessByIDs(
return s.pg.WithTx(
ctx,
func(ctx context.Context, tx pg.Tx) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByOrganizationID(ctx, tx, scope, organizationID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByOrganizationID(ctx, tx, scope, organizationID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
identity := &coredata.Identity{}
@@ -571,8 +571,8 @@ func (s *Service) RejectOrRevokePortalAccessByIDs(
}
access := &coredata.TrustCenterAccess{}
if err := access.LoadByTrustCenterIDAndIdentityID(ctx, tx, scope, trustCenter.ID, identity.ID); err != nil {
return fmt.Errorf("cannot load trust center access: %w", err)
if err := access.LoadByTrustCenterIDAndIdentityID(ctx, tx, scope, compliancePage.ID, identity.ID); err != nil {
return fmt.Errorf("cannot load compliance page access: %w", err)
}
profile := &coredata.MembershipProfile{}
@@ -603,7 +603,7 @@ func (s *Service) RejectOrRevokePortalAccessByIDs(
shouldSendEmail = true
if err := coredata.RejectOrRevokeByTrustCenterFileIDs(ctx, tx, scope, access.ID, fileIDs, now); err != nil {
return fmt.Errorf("cannot reject/revoke trust center file accesses: %w", err)
return fmt.Errorf("cannot reject/revoke compliance page file accesses: %w", err)
}
}
@@ -681,7 +681,7 @@ func (s *Service) sendPortalDocumentAccessRejectedEmail(
organization.Name,
)
if err != nil {
return fmt.Errorf("cannot render trust center documents access rejected email: %w", err)
return fmt.Errorf("cannot render compliance page documents access rejected email: %w", err)
}
accessEmail := coredata.NewEmail(

View File

@@ -47,7 +47,7 @@ func (s *Service) GetPortalFile(
func(ctx context.Context, conn pg.Querier) error {
err := trustCenterFile.LoadByID(ctx, conn, scope, trustCenterFileID)
if err != nil {
return fmt.Errorf("cannot load trust center file: %w", err)
return fmt.Errorf("cannot load compliance page file: %w", err)
}
return nil
@@ -58,11 +58,11 @@ func (s *Service) GetPortalFile(
}
if trustCenterFile.OrganizationID != organizationID {
return nil, ErrTrustCenterFileNotFound
return nil, ErrPortalFileNotFound
}
if trustCenterFile.TrustCenterVisibility == coredata.TrustCenterVisibilityNone {
return nil, ErrTrustCenterFileNotVisible
return nil, ErrPortalFileNotVisible
}
return trustCenterFile, nil
@@ -82,7 +82,7 @@ func (s *Service) ListPortalFilesForOrganizationID(
func(ctx context.Context, conn pg.Querier) error {
err := trustCenterFiles.LoadByOrganizationID(ctx, conn, scope, organizationID, cursor, filter)
if err != nil {
return fmt.Errorf("cannot load trust center files: %w", err)
return fmt.Errorf("cannot load compliance page files: %w", err)
}
return nil
@@ -103,7 +103,7 @@ func (s *Service) ExportPortalFile(
) ([]byte, string, error) {
fileData, mimeType, err := s.exportPortalFileData(ctx, scope, trustCenterFileID)
if err != nil {
return nil, "", fmt.Errorf("cannot export trust center file: %w", err)
return nil, "", fmt.Errorf("cannot export compliance page file: %w", err)
}
if mimeType == "application/pdf" {
@@ -141,7 +141,7 @@ func (s *Service) exportPortalFileData(
func(ctx context.Context, conn pg.Querier) error {
trustCenterFile = &coredata.TrustCenterFile{}
if err := trustCenterFile.LoadByID(ctx, conn, scope, trustCenterFileID); err != nil {
return fmt.Errorf("cannot load trust center file: %w", err)
return fmt.Errorf("cannot load compliance page file: %w", err)
}
file = &coredata.File{}

View File

@@ -33,7 +33,7 @@ import (
func (s *Service) ListPortalReferencesForPortalID(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
cursor *page.Cursor[coredata.TrustCenterReferenceOrderField],
) (*page.Page[*coredata.TrustCenterReference, coredata.TrustCenterReferenceOrderField], error) {
var references coredata.TrustCenterReferences
@@ -43,9 +43,9 @@ func (s *Service) ListPortalReferencesForPortalID(
ctx,
func(ctx context.Context, conn pg.Querier) error {
err := references.LoadByTrustCenterID(ctx, conn, scope, trustCenterID, cursor)
err := references.LoadByTrustCenterID(ctx, conn, scope, compliancePageID, cursor)
if err != nil {
return fmt.Errorf("cannot load trust center references: %w", err)
return fmt.Errorf("cannot load compliance page references: %w", err)
}
return nil
@@ -72,7 +72,7 @@ func (s *Service) GeneratePortalReferenceLogoURL(
},
)
if err != nil {
return "", fmt.Errorf("cannot load trust center reference: %w", err)
return "", fmt.Errorf("cannot load compliance page reference: %w", err)
}
file, err := s.fileManager.GetPublicFile(ctx, reference.LogoFileID)
@@ -95,7 +95,7 @@ func (s *Service) GetPortalReference(
func(ctx context.Context, conn pg.Querier) error {
err := reference.LoadByID(ctx, conn, scope, referenceID)
if err != nil {
return fmt.Errorf("cannot load trust center reference: %w", err)
return fmt.Errorf("cannot load compliance page reference: %w", err)
}
return nil

View File

@@ -28,7 +28,6 @@ import (
"go.gearno.de/kit/pg"
"go.probo.inc/probo/packages/emails"
"go.probo.inc/probo/pkg/complianceportal"
"go.probo.inc/probo/pkg/coredata"
"go.probo.inc/probo/pkg/gid"
)
@@ -36,26 +35,26 @@ import (
func (s *Service) GetPortal(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) (*coredata.TrustCenter, error) {
var trustCenter *coredata.TrustCenter
var compliancePage *coredata.TrustCenter
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter = &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage = &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
return nil
},
)
if err != nil {
return nil, fmt.Errorf("cannot load trust center: %w", err)
return nil, fmt.Errorf("cannot load compliance page: %w", err)
}
return trustCenter, nil
return compliancePage, nil
}
func (s *Service) GetPortalByOrganizationID(
@@ -63,14 +62,14 @@ func (s *Service) GetPortalByOrganizationID(
scope coredata.Scoper,
organizationID gid.GID,
) (*coredata.TrustCenter, error) {
trustCenter := &coredata.TrustCenter{}
compliancePage := &coredata.TrustCenter{}
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
err := trustCenter.LoadByOrganizationID(ctx, conn, scope, organizationID)
err := compliancePage.LoadByOrganizationID(ctx, conn, scope, organizationID)
if err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
return fmt.Errorf("cannot load compliance page: %w", err)
}
return nil
@@ -80,30 +79,30 @@ func (s *Service) GetPortalByOrganizationID(
return nil, err
}
return trustCenter, nil
return compliancePage, nil
}
func (s *Service) GetPortalNDAFile(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) (*coredata.File, error) {
var file *coredata.File
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if trustCenter.NonDisclosureAgreementFileID == nil {
if compliancePage.NonDisclosureAgreementFileID == nil {
return nil
}
file = &coredata.File{}
if err := file.LoadByID(ctx, conn, scope, *trustCenter.NonDisclosureAgreementFileID); err != nil {
if err := file.LoadByID(ctx, conn, scope, *compliancePage.NonDisclosureAgreementFileID); err != nil {
return fmt.Errorf("cannot load file: %w", err)
}
@@ -120,7 +119,7 @@ func (s *Service) GetPortalNDAFile(
func (s *Service) GeneratePortalNDAFileURL(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
expiresIn time.Duration,
) (string, error) {
var file *coredata.File
@@ -128,17 +127,17 @@ func (s *Service) GeneratePortalNDAFileURL(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if trustCenter.NonDisclosureAgreementFileID == nil {
if compliancePage.NonDisclosureAgreementFileID == nil {
return fmt.Errorf("no NDA file found")
}
file = &coredata.File{}
if err := file.LoadByID(ctx, conn, scope, *trustCenter.NonDisclosureAgreementFileID); err != nil {
if err := file.LoadByID(ctx, conn, scope, *compliancePage.NonDisclosureAgreementFileID); err != nil {
return fmt.Errorf("cannot load file: %w", err)
}
@@ -281,12 +280,11 @@ func (s *Service) GetPortalEmailPresenterConfig(
return fmt.Errorf("cannot load organization: %w", err)
}
publicURL, err := complianceportal.PublicURLForTrustCenter(
publicURL, err := s.management.PublicURLForCompliancePage(
ctx,
conn,
scope,
compliancePage,
s.baseDomain,
)
if err != nil {
return fmt.Errorf("cannot resolve compliance page URL: %w", err)
@@ -327,24 +325,24 @@ func (s *Service) GetPortalEmailPresenterConfig(
func (s *Service) GetPortalMailingList(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
) (*coredata.MailingList, error) {
var mailingList *coredata.MailingList
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if trustCenter.MailingListID == nil {
if compliancePage.MailingListID == nil {
return nil
}
mailingList = &coredata.MailingList{}
if err := mailingList.LoadByID(ctx, conn, scope, *trustCenter.MailingListID); err != nil {
if err := mailingList.LoadByID(ctx, conn, scope, *compliancePage.MailingListID); err != nil {
return fmt.Errorf("cannot load mailing list: %w", err)
}

View File

@@ -30,7 +30,7 @@ import (
"go.gearno.de/kit/log"
"go.gearno.de/kit/pg"
"go.probo.inc/probo/packages/emails"
"go.probo.inc/probo/pkg/complianceportal"
"go.probo.inc/probo/pkg/complianceportal/management"
"go.probo.inc/probo/pkg/coredata"
"go.probo.inc/probo/pkg/esign"
"go.probo.inc/probo/pkg/filemanager"
@@ -45,7 +45,7 @@ const NDAConsentText = "By clicking \"Review and sign\", I consent to sign this
type (
// Service is the visitor-facing compliance portal service. It exposes the
// public read operations for the trust center and its related resources as
// public read operations for the compliance page and its related resources as
// methods on a single type.
Service struct {
pg *pg.Client
@@ -61,6 +61,7 @@ type (
logger *log.Logger
slack *slack.Service
resourceAlias *resourcealias.Service
management *management.Service
}
)
@@ -78,6 +79,7 @@ func NewService(
logger *log.Logger,
slack *slack.Service,
resourceAliasSvc *resourcealias.Service,
managementSvc *management.Service,
) *Service {
svc := &Service{
pg: pgClient,
@@ -93,6 +95,7 @@ func NewService(
logger: logger,
slack: slack,
resourceAlias: resourceAliasSvc,
management: managementSvc,
}
return svc
@@ -102,18 +105,18 @@ func (s *Service) GetPortalByID(
ctx context.Context,
id gid.GID,
) (*coredata.TrustCenter, error) {
trustCenter := &coredata.TrustCenter{}
compliancePage := &coredata.TrustCenter{}
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
err := trustCenter.LoadByID(ctx, conn, coredata.NewNoScope(), id)
err := compliancePage.LoadByID(ctx, conn, coredata.NewNoScope(), id)
if err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
return ErrPageNotFound
}
return fmt.Errorf("cannot load trust center: %w", err)
return fmt.Errorf("cannot load compliance page: %w", err)
}
return nil
@@ -123,25 +126,25 @@ func (s *Service) GetPortalByID(
return nil, err
}
return trustCenter, nil
return compliancePage, nil
}
func (s *Service) GetPortalBySlug(
ctx context.Context,
slug string,
) (*coredata.TrustCenter, error) {
trustCenter := &coredata.TrustCenter{}
compliancePage := &coredata.TrustCenter{}
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
err := trustCenter.LoadBySlug(ctx, conn, slug)
err := compliancePage.LoadBySlug(ctx, conn, slug)
if err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
return ErrPageNotFound
}
return fmt.Errorf("cannot load trust center: %w", err)
return fmt.Errorf("cannot load compliance page: %w", err)
}
return nil
@@ -151,25 +154,25 @@ func (s *Service) GetPortalBySlug(
return nil, err
}
return trustCenter, nil
return compliancePage, nil
}
// GetEffectiveCanonicalHost returns the host a compliance page should be
// served under. It prefers the primary domain when its certificate is active,
// and otherwise falls back to the managed probopage subdomain. An empty string
// is returned when no serving host can be determined.
func (s *Service) GetPortalEffectiveCanonicalHost(ctx context.Context, trustCenterID gid.GID) (string, error) {
func (s *Service) GetPortalEffectiveCanonicalHost(ctx context.Context, compliancePageID gid.GID) (string, error) {
var host string
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, coredata.NewNoScope(), trustCenterID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, coredata.NewNoScope(), compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
domain, err := complianceportal.EffectiveDomainForTrustCenter(ctx, conn, coredata.NewNoScope(), trustCenter)
domain, err := s.management.EffectiveDomainForCompliancePage(ctx, conn, coredata.NewNoScope(), compliancePage)
if err != nil {
return err
}
@@ -189,7 +192,7 @@ func (s *Service) GetPortalEffectiveCanonicalHost(ctx context.Context, trustCent
}
func (s *Service) GetPortalByDomainName(ctx context.Context, domain string) (*coredata.TrustCenter, error) {
trustCenter := &coredata.TrustCenter{}
compliancePage := &coredata.TrustCenter{}
err := s.pg.WithConn(
ctx,
@@ -203,13 +206,13 @@ func (s *Service) GetPortalByDomainName(ctx context.Context, domain string) (*co
return fmt.Errorf("cannot load custom domain: %w", err)
}
trustCenter = &coredata.TrustCenter{}
if err := trustCenter.LoadByDomainID(ctx, conn, customDomain.ID); err != nil {
compliancePage = &coredata.TrustCenter{}
if err := compliancePage.LoadByDomainID(ctx, conn, customDomain.ID); err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
return ErrPageNotFound
}
return fmt.Errorf("cannot load trust center: %w", err)
return fmt.Errorf("cannot load compliance page: %w", err)
}
return nil
@@ -219,37 +222,37 @@ func (s *Service) GetPortalByDomainName(ctx context.Context, domain string) (*co
return nil, err
}
return trustCenter, err
return compliancePage, err
}
// GetPortalEmailPresenterConfigByOrganizationID resolves the emails.PresenterConfig for
// the trust center that belongs to the given organization. This is used by the
// the compliance page that belongs to the given organization. This is used by the
// esign certificate worker which needs per-org branding at render time.
func (s *Service) GetPortalEmailPresenterConfigByOrganizationID(ctx context.Context, orgID gid.GID) (emails.PresenterConfig, error) {
var trustCenter coredata.TrustCenter
var compliancePage coredata.TrustCenter
scope := coredata.NewScopeFromObjectID(orgID)
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
return trustCenter.LoadByOrganizationID(ctx, conn, scope, orgID)
return compliancePage.LoadByOrganizationID(ctx, conn, scope, orgID)
},
)
if err != nil {
return emails.PresenterConfig{}, fmt.Errorf("cannot load trust center for org %s: %w", orgID, err)
return emails.PresenterConfig{}, fmt.Errorf("cannot load compliance page for org %s: %w", orgID, err)
}
return s.GetPortalEmailPresenterConfig(ctx, scope, trustCenter.ID)
return s.GetPortalEmailPresenterConfig(ctx, scope, compliancePage.ID)
}
func (s *Service) GetPortalOrganization(
ctx context.Context,
trustCenterID gid.GID,
compliancePageID gid.GID,
) (*coredata.Organization, error) {
trustCenter, err := s.GetPortalByID(ctx, trustCenterID)
compliancePage, err := s.GetPortalByID(ctx, compliancePageID)
if err != nil {
return nil, fmt.Errorf("cannot load trust center: %w", err)
return nil, fmt.Errorf("cannot load compliance page: %w", err)
}
org := &coredata.Organization{}
@@ -257,7 +260,7 @@ func (s *Service) GetPortalOrganization(
err = s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
return org.LoadByID(ctx, conn, coredata.NewNoScope(), trustCenter.OrganizationID)
return org.LoadByID(ctx, conn, coredata.NewNoScope(), compliancePage.OrganizationID)
},
)
if err != nil {
@@ -305,17 +308,17 @@ func (s *Service) GetPortalNDAFileByID(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) error {
trustCenter := &coredata.TrustCenter{}
if err := trustCenter.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, conn, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load compliance page: %w", err)
}
if trustCenter.NonDisclosureAgreementFileID == nil {
if compliancePage.NonDisclosureAgreementFileID == nil {
return ErrNDAFileNotFound
}
file = &coredata.File{}
if err := file.LoadByID(ctx, conn, scope, *trustCenter.NonDisclosureAgreementFileID); err != nil {
if err := file.LoadByID(ctx, conn, scope, *compliancePage.NonDisclosureAgreementFileID); err != nil {
if errors.Is(err, coredata.ErrResourceNotFound) {
return ErrNDAFileNotFound
}
@@ -349,7 +352,7 @@ func (s *Service) ProvisionPortalMember(
func(ctx context.Context, tx pg.Tx) error {
compliancePage := &coredata.TrustCenter{}
if err := compliancePage.LoadByID(ctx, tx, scope, compliancePageID); err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
return fmt.Errorf("cannot load compliance page: %w", err)
}
identity := &coredata.Identity{}
@@ -360,7 +363,7 @@ func (s *Service) ProvisionPortalMember(
access = &coredata.TrustCenterAccess{}
if err := access.LoadByTrustCenterIDAndIdentityID(ctx, tx, scope, compliancePageID, identityID); err != nil {
if !errors.Is(err, coredata.ErrResourceNotFound) {
return fmt.Errorf("cannot load trust center access: %w", err)
return fmt.Errorf("cannot load compliance page access: %w", err)
}
access = &coredata.TrustCenterAccess{
@@ -399,7 +402,7 @@ func (s *Service) ProvisionPortalMember(
}
if err := access.Insert(ctx, tx, scope); err != nil {
return fmt.Errorf("cannot insert trust center access: %w", err)
return fmt.Errorf("cannot insert compliance page access: %w", err)
}
}

View File

@@ -87,7 +87,7 @@ func (s *Service) ListThirdPartiesForOrganizationID(
return page.NewPage(thirdParties, cursor), nil
}
func (s *Service) ListDistinctTrustCenterCategoriesForOrganizationID(
func (s *Service) ListDistinctPortalCategoriesForOrganizationID(
ctx context.Context,
scope coredata.Scoper,
organizationID gid.GID,
@@ -116,7 +116,7 @@ func (s *Service) ListDistinctTrustCenterCategoriesForOrganizationID(
return categories, nil
}
func (s *Service) ListDistinctTrustCenterCountriesForOrganizationID(
func (s *Service) ListDistinctPortalCountriesForOrganizationID(
ctx context.Context,
scope coredata.Scoper,
organizationID gid.GID,
@@ -148,7 +148,7 @@ func (s *Service) ListDistinctTrustCenterCountriesForOrganizationID(
func (s *Service) CountThirdPartiesForPortalID(
ctx context.Context,
scope coredata.Scoper,
trustCenterID gid.GID,
compliancePageID gid.GID,
filter *coredata.ThirdPartyFilter,
) (int, error) {
if filter == nil {
@@ -161,14 +161,14 @@ func (s *Service) CountThirdPartiesForPortalID(
err := s.pg.WithConn(
ctx,
func(ctx context.Context, conn pg.Querier) (err error) {
trustCenter, err := s.GetPortal(ctx, scope, trustCenterID)
compliancePage, err := s.GetPortal(ctx, scope, compliancePageID)
if err != nil {
return fmt.Errorf("cannot load trust center: %w", err)
return fmt.Errorf("cannot load compliance page: %w", err)
}
thirdParties := &coredata.ThirdParties{}
count, err = thirdParties.CountByOrganizationID(ctx, conn, scope, trustCenter.OrganizationID, filter)
count, err = thirdParties.CountByOrganizationID(ctx, conn, scope, compliancePage.OrganizationID, filter)
if err != nil {
return fmt.Errorf("cannot count thirdParties: %w", err)
}