Add finding and obligation publish to document system

Replace the old snapshot-based approach with the new publish document
system for findings and obligations. Includes GraphQL mutations, MCP
tools, CLI commands, e2e tests, frontend publish dialogs, and
snapshot-to-document migration tools.

Remove snapshot mode entirely from findings and obligations: drop
snapshotId from GraphQL schemas, filters, resolvers, MCP spec, frontend
routes, pages, and helpers. The snapshot_id column remains in the
database but is now filtered out with snapshot_id IS NULL.

Remove auditor's ability to publish SoA.

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
Sacha Al Himdani
2026-04-23 10:53:57 +02:00
parent e473884b31
commit bdb16d4abe
57 changed files with 4241 additions and 609 deletions

View File

@@ -112,6 +112,29 @@ func (r *mutationResolver) DeleteObligation(ctx context.Context, input types.Del
}, nil
}
// PublishObligationList is the resolver for the publishObligationList field.
func (r *mutationResolver) PublishObligationList(ctx context.Context, input types.PublishObligationListInput) (*types.PublishObligationListPayload, error) {
if err := r.authorize(ctx, input.OrganizationID, probo.ActionObligationPublish); err != nil {
return nil, err
}
prb := r.ProboService(ctx, input.OrganizationID.TenantID())
document, documentVersion, err := prb.GeneratedDocuments.PublishObligationList(ctx, input.OrganizationID, input.ApproverIds)
if err != nil {
if errors.Is(err, coredata.ErrResourceAlreadyExists) {
return nil, gqlutils.Conflict(ctx, err)
}
r.logger.ErrorCtx(ctx, "cannot publish obligation list", log.Error(err))
return nil, gqlutils.Internal(ctx)
}
return &types.PublishObligationListPayload{
DocumentEdge: types.NewDocumentEdge(document, coredata.DocumentOrderFieldCreatedAt),
DocumentVersionEdge: types.NewDocumentVersionEdge(documentVersion, coredata.DocumentVersionOrderFieldCreatedAt),
}, nil
}
// Organization is the resolver for the organization field.
func (r *obligationResolver) Organization(ctx context.Context, obj *types.Obligation) (*types.Organization, error) {
if err := r.authorize(ctx, obj.ID, probo.ActionOrganizationGet); err != nil {
@@ -169,24 +192,14 @@ func (r *obligationConnectionResolver) TotalCount(ctx context.Context, obj *type
switch obj.Resolver.(type) {
case *organizationResolver:
obligationFilter := coredata.NewObligationFilter(nil)
if obj.Filter != nil {
obligationFilter = coredata.NewObligationFilter(&obj.Filter.SnapshotID)
}
count, err := prb.Obligations.CountForOrganizationID(ctx, obj.ParentID, obligationFilter)
count, err := prb.Obligations.CountForOrganizationID(ctx, obj.ParentID)
if err != nil {
r.logger.ErrorCtx(ctx, "cannot count obligations", log.Error(err))
return 0, gqlutils.Internal(ctx)
}
return count, nil
case *riskResolver:
obligationFilter := coredata.NewObligationFilter(nil)
if obj.Filter != nil {
obligationFilter = coredata.NewObligationFilter(&obj.Filter.SnapshotID)
}
count, err := prb.Obligations.CountForRiskID(ctx, obj.ParentID, obligationFilter)
count, err := prb.Obligations.CountForRiskID(ctx, obj.ParentID)
if err != nil {
r.logger.ErrorCtx(ctx, "cannot count risk obligations", log.Error(err))
return 0, gqlutils.Internal(ctx)