Update e2e tests for compliance portal
Rename trust center coverage to compliance portal so console, MCP, and trust suites assert against the new API surface. Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
@@ -33,17 +33,17 @@ import (
|
||||
"go.probo.inc/probo/e2e/internal/testutil"
|
||||
)
|
||||
|
||||
func TestTrustCenter_LogoFileDownloadURL(t *testing.T) {
|
||||
func TestCompliancePortal_LogoFileDownloadURL(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
owner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
organizationID := owner.GetOrganizationID().String()
|
||||
|
||||
const trustCenterQuery = `
|
||||
const compliancePortalQuery = `
|
||||
query($organizationId: ID!) {
|
||||
node(id: $organizationId) {
|
||||
... on Organization {
|
||||
trustCenter {
|
||||
compliancePortal {
|
||||
id
|
||||
}
|
||||
}
|
||||
@@ -51,26 +51,26 @@ func TestTrustCenter_LogoFileDownloadURL(t *testing.T) {
|
||||
}
|
||||
`
|
||||
|
||||
var trustCenterLookup struct {
|
||||
var compliancePortalLookup struct {
|
||||
Node struct {
|
||||
TrustCenter struct {
|
||||
CompliancePortal struct {
|
||||
ID string `json:"id"`
|
||||
} `json:"trustCenter"`
|
||||
} `json:"compliancePortal"`
|
||||
} `json:"node"`
|
||||
}
|
||||
|
||||
err := owner.Execute(trustCenterQuery, map[string]any{
|
||||
err := owner.Execute(compliancePortalQuery, map[string]any{
|
||||
"organizationId": organizationID,
|
||||
}, &trustCenterLookup)
|
||||
}, &compliancePortalLookup)
|
||||
require.NoError(t, err)
|
||||
require.NotEmpty(t, trustCenterLookup.Node.TrustCenter.ID)
|
||||
require.NotEmpty(t, compliancePortalLookup.Node.CompliancePortal.ID)
|
||||
|
||||
trustCenterID := trustCenterLookup.Node.TrustCenter.ID
|
||||
compliancePortalID := compliancePortalLookup.Node.CompliancePortal.ID
|
||||
|
||||
const activateMutation = `
|
||||
mutation($input: UpdateTrustCenterInput!) {
|
||||
updateTrustCenter(input: $input) {
|
||||
trustCenter {
|
||||
mutation($input: UpdateCompliancePortalInput!) {
|
||||
updateCompliancePortal(input: $input) {
|
||||
compliancePortal {
|
||||
id
|
||||
active
|
||||
publicUrl
|
||||
@@ -80,19 +80,19 @@ func TestTrustCenter_LogoFileDownloadURL(t *testing.T) {
|
||||
`
|
||||
|
||||
var activateResult struct {
|
||||
UpdateTrustCenter struct {
|
||||
TrustCenter struct {
|
||||
UpdateCompliancePortal struct {
|
||||
CompliancePortal struct {
|
||||
ID string `json:"id"`
|
||||
Active bool `json:"active"`
|
||||
PublicURL string `json:"publicUrl"`
|
||||
} `json:"trustCenter"`
|
||||
} `json:"updateTrustCenter"`
|
||||
} `json:"compliancePortal"`
|
||||
} `json:"updateCompliancePortal"`
|
||||
}
|
||||
|
||||
err = owner.Execute(activateMutation, map[string]any{
|
||||
"input": map[string]any{
|
||||
"trustCenterId": trustCenterID,
|
||||
"active": true,
|
||||
"compliancePortalId": compliancePortalID,
|
||||
"active": true,
|
||||
},
|
||||
}, &activateResult)
|
||||
require.NoError(t, err)
|
||||
@@ -100,18 +100,18 @@ func TestTrustCenter_LogoFileDownloadURL(t *testing.T) {
|
||||
// Publishing the page provisions a managed {slug}.probopage.localhost
|
||||
// domain; the effective public URL resolves to it while no customer
|
||||
// custom domain is primary.
|
||||
require.NotEmpty(t, activateResult.UpdateTrustCenter.TrustCenter.PublicURL)
|
||||
require.NotEmpty(t, activateResult.UpdateCompliancePortal.CompliancePortal.PublicURL)
|
||||
|
||||
publicURL, err := url.Parse(activateResult.UpdateTrustCenter.TrustCenter.PublicURL)
|
||||
publicURL, err := url.Parse(activateResult.UpdateCompliancePortal.CompliancePortal.PublicURL)
|
||||
require.NoError(t, err)
|
||||
|
||||
trustHost := publicURL.Host
|
||||
require.NotEmpty(t, trustHost)
|
||||
|
||||
const uploadMutation = `
|
||||
mutation UpdateTrustCenterBrand($input: UpdateTrustCenterBrandInput!) {
|
||||
updateTrustCenterBrand(input: $input) {
|
||||
trustCenter {
|
||||
mutation UpdateCompliancePortalBrand($input: UpdateCompliancePortalBrandInput!) {
|
||||
updateCompliancePortalBrand(input: $input) {
|
||||
compliancePortal {
|
||||
id
|
||||
logo {
|
||||
id
|
||||
@@ -136,22 +136,22 @@ func TestTrustCenter_LogoFileDownloadURL(t *testing.T) {
|
||||
}
|
||||
|
||||
var uploadResult struct {
|
||||
UpdateTrustCenterBrand struct {
|
||||
TrustCenter struct {
|
||||
UpdateCompliancePortalBrand struct {
|
||||
CompliancePortal struct {
|
||||
ID string `json:"id"`
|
||||
Logo *struct {
|
||||
ID string `json:"id"`
|
||||
FileName string `json:"fileName"`
|
||||
DownloadURL string `json:"downloadUrl"`
|
||||
} `json:"logo"`
|
||||
} `json:"trustCenter"`
|
||||
} `json:"updateTrustCenterBrand"`
|
||||
} `json:"compliancePortal"`
|
||||
} `json:"updateCompliancePortalBrand"`
|
||||
}
|
||||
|
||||
err = owner.ExecuteWithFile(uploadMutation, map[string]any{
|
||||
"input": map[string]any{
|
||||
"trustCenterId": trustCenterID,
|
||||
"logoFile": nil,
|
||||
"compliancePortalId": compliancePortalID,
|
||||
"logoFile": nil,
|
||||
},
|
||||
}, "input.logoFile", testutil.UploadFile{
|
||||
Filename: "trust-center-logo.png",
|
||||
@@ -159,11 +159,11 @@ func TestTrustCenter_LogoFileDownloadURL(t *testing.T) {
|
||||
Content: pngContent,
|
||||
}, &uploadResult)
|
||||
require.NoError(t, err)
|
||||
require.NotNil(t, uploadResult.UpdateTrustCenterBrand.TrustCenter.Logo)
|
||||
require.NotNil(t, uploadResult.UpdateCompliancePortalBrand.CompliancePortal.Logo)
|
||||
|
||||
const trustGraphQLQuery = `
|
||||
query {
|
||||
currentTrustCenter {
|
||||
currentCompliancePortal {
|
||||
logo {
|
||||
id
|
||||
fileName
|
||||
@@ -174,31 +174,31 @@ func TestTrustCenter_LogoFileDownloadURL(t *testing.T) {
|
||||
`
|
||||
|
||||
var trustResult struct {
|
||||
CurrentTrustCenter struct {
|
||||
CurrentCompliancePortal struct {
|
||||
Logo *struct {
|
||||
ID string `json:"id"`
|
||||
FileName string `json:"fileName"`
|
||||
DownloadURL string `json:"downloadUrl"`
|
||||
} `json:"logo"`
|
||||
} `json:"currentTrustCenter"`
|
||||
} `json:"currentCompliancePortal"`
|
||||
}
|
||||
|
||||
// The dedicated HTTPS listener only serves the page once the managed
|
||||
// domain's certificate has been provisioned (async, ~1s poll in e2e), so
|
||||
// retry until the TLS handshake and query succeed.
|
||||
require.Eventually(t, func() bool {
|
||||
trustResult.CurrentTrustCenter.Logo = nil
|
||||
trustResult.CurrentCompliancePortal.Logo = nil
|
||||
if err := owner.ExecuteTrust(trustHost, trustGraphQLQuery, nil, &trustResult); err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
return trustResult.CurrentTrustCenter.Logo != nil
|
||||
}, 30*time.Second, 500*time.Millisecond, "trust center did not become servable on the dedicated listener")
|
||||
return trustResult.CurrentCompliancePortal.Logo != nil
|
||||
}, 30*time.Second, 500*time.Millisecond, "compliance portal did not become servable on the dedicated listener")
|
||||
|
||||
require.NotNil(t, trustResult.CurrentTrustCenter.Logo)
|
||||
assert.Equal(t, uploadResult.UpdateTrustCenterBrand.TrustCenter.Logo.ID, trustResult.CurrentTrustCenter.Logo.ID)
|
||||
require.NotNil(t, trustResult.CurrentCompliancePortal.Logo)
|
||||
assert.Equal(t, uploadResult.UpdateCompliancePortalBrand.CompliancePortal.Logo.ID, trustResult.CurrentCompliancePortal.Logo.ID)
|
||||
|
||||
downloadURL := trustResult.CurrentTrustCenter.Logo.DownloadURL
|
||||
downloadURL := trustResult.CurrentCompliancePortal.Logo.DownloadURL
|
||||
assert.True(
|
||||
t,
|
||||
strings.Contains(downloadURL, "/api/files/v1/public/"),
|
||||
@@ -49,21 +49,21 @@ const minimalPDFBase64 = "JVBERi0xLjcKJeLjz9MKMSAwIG9iago8PC9QYWdlcyAyIDAgUi9UeX
|
||||
"ES//AhpppZNeBhllklmyLLLKJrsclh/4AgAA//9tzQSTZW5kc3RyZWFtCmVuZG9iagoKc3RhcnR4" +
|
||||
"cmVmCjUxMgolJUVPRg=="
|
||||
|
||||
// TestTrustCenter_AcceptElectronicSignature_RejectsForeignSignature is a
|
||||
// TestCompliancePortal_AcceptElectronicSignature_RejectsForeignSignature is a
|
||||
// regression test for GHSA-22xj-f767-ppw6: any self-provisioned trust
|
||||
// center visitor could accept another visitor's NDA signature, or inject
|
||||
// audit-trail events into it, simply by knowing its GID.
|
||||
func TestTrustCenter_AcceptElectronicSignature_RejectsForeignSignature(t *testing.T) {
|
||||
func TestCompliancePortal_AcceptElectronicSignature_RejectsForeignSignature(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
owner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
trustCenterID := lookupTrustCenterID(t, owner)
|
||||
compliancePortalID := lookupCompliancePortalID(t, owner)
|
||||
|
||||
uploadTrustCenterNDA(t, owner, trustCenterID)
|
||||
trustHost := lookupTrustHost(t, owner, trustCenterID)
|
||||
uploadCompliancePortalNDA(t, owner, compliancePortalID)
|
||||
trustHost := lookupTrustHost(t, owner, compliancePortalID)
|
||||
|
||||
victim := testutil.SelfProvisionTrustCenterVisitor(t, trustHost)
|
||||
attacker := testutil.SelfProvisionTrustCenterVisitor(t, trustHost)
|
||||
victim := testutil.SelfProvisionCompliancePortalVisitor(t, trustHost)
|
||||
attacker := testutil.SelfProvisionCompliancePortalVisitor(t, trustHost)
|
||||
|
||||
victimSignatureID, victimSignatureStatus := viewerSignature(t, victim, trustHost)
|
||||
require.NotEmpty(t, victimSignatureID)
|
||||
@@ -119,13 +119,13 @@ func TestTrustCenter_AcceptElectronicSignature_RejectsForeignSignature(t *testin
|
||||
assert.Equal(t, "ACCEPTED", acceptResult.AcceptElectronicSignature.Signature.Status)
|
||||
}
|
||||
|
||||
func uploadTrustCenterNDA(t *testing.T, owner *testutil.Client, trustCenterID string) {
|
||||
func uploadCompliancePortalNDA(t *testing.T, owner *testutil.Client, compliancePortalID string) {
|
||||
t.Helper()
|
||||
|
||||
const query = `
|
||||
mutation($input: UploadTrustCenterNDAInput!) {
|
||||
uploadTrustCenterNDA(input: $input) {
|
||||
trustCenter { id }
|
||||
mutation($input: UploadCompliancePortalNDAInput!) {
|
||||
uploadCompliancePortalNDA(input: $input) {
|
||||
compliancePortal { id }
|
||||
}
|
||||
}
|
||||
`
|
||||
@@ -135,9 +135,9 @@ func uploadTrustCenterNDA(t *testing.T, owner *testutil.Client, trustCenterID st
|
||||
|
||||
err = owner.ExecuteWithFile(query, map[string]any{
|
||||
"input": map[string]any{
|
||||
"trustCenterId": trustCenterID,
|
||||
"fileName": "nda.pdf",
|
||||
"file": nil,
|
||||
"compliancePortalId": compliancePortalID,
|
||||
"fileName": "nda.pdf",
|
||||
"file": nil,
|
||||
},
|
||||
}, "input.file", testutil.UploadFile{
|
||||
Filename: "nda.pdf",
|
||||
@@ -152,7 +152,7 @@ func viewerSignature(t *testing.T, visitor *testutil.Client, trustHost string) (
|
||||
|
||||
const query = `
|
||||
query {
|
||||
currentTrustCenter {
|
||||
currentCompliancePortal {
|
||||
nonDisclosureAgreement {
|
||||
viewerSignature { id status }
|
||||
}
|
||||
@@ -161,20 +161,20 @@ func viewerSignature(t *testing.T, visitor *testutil.Client, trustHost string) (
|
||||
`
|
||||
|
||||
var result struct {
|
||||
CurrentTrustCenter struct {
|
||||
CurrentCompliancePortal struct {
|
||||
NonDisclosureAgreement struct {
|
||||
ViewerSignature struct {
|
||||
ID string `json:"id"`
|
||||
Status string `json:"status"`
|
||||
} `json:"viewerSignature"`
|
||||
} `json:"nonDisclosureAgreement"`
|
||||
} `json:"currentTrustCenter"`
|
||||
} `json:"currentCompliancePortal"`
|
||||
}
|
||||
|
||||
err := visitor.ExecuteTrust(trustHost, query, nil, &result)
|
||||
require.NoError(t, err)
|
||||
|
||||
sig := result.CurrentTrustCenter.NonDisclosureAgreement.ViewerSignature
|
||||
sig := result.CurrentCompliancePortal.NonDisclosureAgreement.ViewerSignature
|
||||
|
||||
return sig.ID, sig.Status
|
||||
}
|
||||
@@ -26,13 +26,13 @@ import (
|
||||
"go.probo.inc/probo/e2e/internal/testutil"
|
||||
)
|
||||
|
||||
func TestTrustCenter_CIMDMetadataDocument(t *testing.T) {
|
||||
func TestCompliancePortal_CIMDMetadataDocument(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
owner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
trustCenterID := lookupTrustCenterID(t, owner)
|
||||
trustHost := lookupTrustHost(t, owner, trustCenterID)
|
||||
testutil.WaitForTrustCenterHTTPS(t, trustHost)
|
||||
compliancePortalID := lookupCompliancePortalID(t, owner)
|
||||
trustHost := lookupTrustHost(t, owner, compliancePortalID)
|
||||
testutil.WaitForCompliancePortalHTTPS(t, trustHost)
|
||||
|
||||
client := testutil.TrustHTTPClient(trustHost)
|
||||
resp, err := client.Get("https://" + trustHost + "/.well-known/oauth-client-metadata")
|
||||
@@ -71,35 +71,35 @@ func TestTrustCenter_CIMDMetadataDocument(t *testing.T) {
|
||||
assert.NotEmpty(t, doc.ClientName)
|
||||
}
|
||||
|
||||
func TestTrustCenter_VisitorConnectViaCIMD(t *testing.T) {
|
||||
func TestCompliancePortal_VisitorConnectViaCIMD(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
owner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
trustCenterID := lookupTrustCenterID(t, owner)
|
||||
trustHost := lookupTrustHost(t, owner, trustCenterID)
|
||||
compliancePortalID := lookupCompliancePortalID(t, owner)
|
||||
trustHost := lookupTrustHost(t, owner, compliancePortalID)
|
||||
|
||||
visitor := testutil.SelfProvisionTrustCenterVisitor(t, trustHost)
|
||||
visitor := testutil.SelfProvisionCompliancePortalVisitor(t, trustHost)
|
||||
|
||||
const query = `
|
||||
query {
|
||||
currentTrustCenter {
|
||||
currentCompliancePortal {
|
||||
title
|
||||
}
|
||||
}
|
||||
`
|
||||
|
||||
var result struct {
|
||||
CurrentTrustCenter struct {
|
||||
CurrentCompliancePortal struct {
|
||||
Title string `json:"title"`
|
||||
} `json:"currentTrustCenter"`
|
||||
} `json:"currentCompliancePortal"`
|
||||
}
|
||||
|
||||
err := visitor.ExecuteTrust(trustHost, query, nil, &result)
|
||||
require.NoError(t, err, "visitor session must authenticate trust GraphQL after CIMD connect")
|
||||
assert.NotEmpty(t, result.CurrentTrustCenter.Title)
|
||||
assert.NotEmpty(t, result.CurrentCompliancePortal.Title)
|
||||
}
|
||||
|
||||
func TestTrustCenter_UnknownCIMDClientRejected(t *testing.T) {
|
||||
func TestCompliancePortal_UnknownCIMDClientRejected(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
owner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
@@ -46,30 +46,30 @@ const nodeQuery = `
|
||||
}
|
||||
`
|
||||
|
||||
// TestTrustCenter_ExportReportPDF_TenantIsolation verifies that a public
|
||||
// TestCompliancePortal_ExportReportPDF_TenantIsolation verifies that a public
|
||||
// audit-report PDF can only be exported through its own organization's trust
|
||||
// center. A visitor on another organization's trust center must not be able to
|
||||
// center. A visitor on another organization's compliance portal must not be able to
|
||||
// download it by supplying the foreign report GID (cross-tenant IDOR).
|
||||
func TestTrustCenter_ExportReportPDF_TenantIsolation(t *testing.T) {
|
||||
func TestCompliancePortal_ExportReportPDF_TenantIsolation(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
victimOwner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
attackerOwner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
|
||||
victimTrustCenterID, victimReportID := setupPublicAuditReport(t, victimOwner)
|
||||
attackerTrustCenterID, _ := setupPublicAuditReport(t, attackerOwner)
|
||||
victimCompliancePortalID, victimReportID := setupPublicAuditReport(t, victimOwner)
|
||||
attackerCompliancePortalID, _ := setupPublicAuditReport(t, attackerOwner)
|
||||
|
||||
t.Run("owning trust center can export its report", func(t *testing.T) {
|
||||
t.Run("owning compliance portal can export its report", func(t *testing.T) {
|
||||
var result struct {
|
||||
ExportReportPDF struct {
|
||||
Data string `json:"data"`
|
||||
} `json:"exportReportPDF"`
|
||||
}
|
||||
|
||||
err := victimOwner.ExecuteTrust(victimTrustCenterID, exportReportPDFMutation, map[string]any{
|
||||
err := victimOwner.ExecuteTrust(victimCompliancePortalID, exportReportPDFMutation, map[string]any{
|
||||
"input": map[string]any{"reportId": victimReportID},
|
||||
}, &result)
|
||||
require.NoError(t, err, "the owning trust center must serve its own public report")
|
||||
require.NoError(t, err, "the owning compliance portal must serve its own public report")
|
||||
assert.True(
|
||||
t,
|
||||
strings.HasPrefix(result.ExportReportPDF.Data, "data:application/pdf;base64,"),
|
||||
@@ -78,11 +78,11 @@ func TestTrustCenter_ExportReportPDF_TenantIsolation(t *testing.T) {
|
||||
)
|
||||
})
|
||||
|
||||
t.Run("foreign trust center cannot export another org's report", func(t *testing.T) {
|
||||
err := attackerOwner.ExecuteTrust(attackerTrustCenterID, exportReportPDFMutation, map[string]any{
|
||||
t.Run("foreign compliance portal cannot export another org's report", func(t *testing.T) {
|
||||
err := attackerOwner.ExecuteTrust(attackerCompliancePortalID, exportReportPDFMutation, map[string]any{
|
||||
"input": map[string]any{"reportId": victimReportID},
|
||||
}, nil)
|
||||
require.Error(t, err, "a foreign trust center must not export another org's report")
|
||||
require.Error(t, err, "a foreign compliance portal must not export another org's report")
|
||||
assert.Contains(
|
||||
t,
|
||||
err.Error(),
|
||||
@@ -92,37 +92,37 @@ func TestTrustCenter_ExportReportPDF_TenantIsolation(t *testing.T) {
|
||||
})
|
||||
}
|
||||
|
||||
// TestTrustCenter_Node_TenantIsolation exercises the generic node(id:) resolver:
|
||||
// a visitor on one organization's trust center must not resolve a node that
|
||||
// TestCompliancePortal_Node_TenantIsolation exercises the generic node(id:) resolver:
|
||||
// a visitor on one organization's compliance portal must not resolve a node that
|
||||
// belongs to another organization, even with a valid foreign GID.
|
||||
func TestTrustCenter_Node_TenantIsolation(t *testing.T) {
|
||||
func TestCompliancePortal_Node_TenantIsolation(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
victimOwner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
attackerOwner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
|
||||
victimTrustCenterID, _ := setupPublicAuditReport(t, victimOwner)
|
||||
attackerTrustCenterID, _ := setupPublicAuditReport(t, attackerOwner)
|
||||
victimCompliancePortalID, _ := setupPublicAuditReport(t, victimOwner)
|
||||
attackerCompliancePortalID, _ := setupPublicAuditReport(t, attackerOwner)
|
||||
|
||||
t.Run("owning trust center resolves its own node", func(t *testing.T) {
|
||||
t.Run("owning compliance portal resolves its own node", func(t *testing.T) {
|
||||
var result struct {
|
||||
Node struct {
|
||||
Typename string `json:"__typename"`
|
||||
} `json:"node"`
|
||||
}
|
||||
|
||||
err := victimOwner.ExecuteTrust(victimTrustCenterID, nodeQuery, map[string]any{
|
||||
"id": victimTrustCenterID,
|
||||
err := victimOwner.ExecuteTrust(victimCompliancePortalID, nodeQuery, map[string]any{
|
||||
"id": victimCompliancePortalID,
|
||||
}, &result)
|
||||
require.NoError(t, err, "the owning trust center must resolve its own node")
|
||||
require.NoError(t, err, "the owning compliance portal must resolve its own node")
|
||||
assert.NotEmpty(t, result.Node.Typename, "expected the node to resolve to a concrete type")
|
||||
})
|
||||
|
||||
t.Run("foreign trust center cannot resolve another org's node", func(t *testing.T) {
|
||||
err := attackerOwner.ExecuteTrust(attackerTrustCenterID, nodeQuery, map[string]any{
|
||||
"id": victimTrustCenterID,
|
||||
t.Run("foreign compliance portal cannot resolve another org's node", func(t *testing.T) {
|
||||
err := attackerOwner.ExecuteTrust(attackerCompliancePortalID, nodeQuery, map[string]any{
|
||||
"id": victimCompliancePortalID,
|
||||
}, nil)
|
||||
require.Error(t, err, "a foreign trust center must not resolve another org's node")
|
||||
require.Error(t, err, "a foreign compliance portal must not resolve another org's node")
|
||||
assert.Contains(
|
||||
t,
|
||||
err.Error(),
|
||||
@@ -133,9 +133,9 @@ func TestTrustCenter_Node_TenantIsolation(t *testing.T) {
|
||||
}
|
||||
|
||||
// setupPublicAuditReport creates an audit with an uploaded report file, marks it
|
||||
// as publicly visible on the trust center, activates the trust center, and
|
||||
// returns the trust center ID and the report file ID.
|
||||
func setupPublicAuditReport(t *testing.T, owner *testutil.Client) (trustCenterID string, reportID string) {
|
||||
// as publicly visible on the compliance portal, activates the compliance portal, and
|
||||
// returns the compliance portal ID and the report file ID.
|
||||
func setupPublicAuditReport(t *testing.T, owner *testutil.Client) (compliancePortalID string, reportID string) {
|
||||
t.Helper()
|
||||
|
||||
frameworkID := factory.NewFramework(owner).WithName(factory.SafeName("Framework")).Create()
|
||||
@@ -188,14 +188,14 @@ func setupPublicAuditReport(t *testing.T, owner *testutil.Client) (trustCenterID
|
||||
|
||||
err = owner.Execute(setVisibilityMutation, map[string]any{
|
||||
"input": map[string]any{
|
||||
"id": auditID,
|
||||
"trustCenterVisibility": "PUBLIC",
|
||||
"id": auditID,
|
||||
"compliancePortalVisibility": "PUBLIC",
|
||||
},
|
||||
}, nil)
|
||||
require.NoError(t, err)
|
||||
|
||||
trustCenterID = lookupTrustCenterID(t, owner)
|
||||
activateTrustCenter(t, owner, trustCenterID)
|
||||
compliancePortalID = lookupCompliancePortalID(t, owner)
|
||||
activateCompliancePortal(t, owner, compliancePortalID)
|
||||
|
||||
return trustCenterID, reportID
|
||||
return compliancePortalID, reportID
|
||||
}
|
||||
@@ -29,7 +29,7 @@ import (
|
||||
"go.probo.inc/probo/e2e/internal/testutil"
|
||||
)
|
||||
|
||||
func TestTrustCenter_SlugHasEntropySuffix(t *testing.T) {
|
||||
func TestCompliancePortal_SlugHasEntropySuffix(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
owner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
@@ -39,7 +39,7 @@ func TestTrustCenter_SlugHasEntropySuffix(t *testing.T) {
|
||||
query($organizationId: ID!) {
|
||||
node(id: $organizationId) {
|
||||
... on Organization {
|
||||
trustCenter {
|
||||
compliancePortal {
|
||||
slug
|
||||
}
|
||||
}
|
||||
@@ -49,9 +49,9 @@ func TestTrustCenter_SlugHasEntropySuffix(t *testing.T) {
|
||||
|
||||
var result struct {
|
||||
Node struct {
|
||||
TrustCenter struct {
|
||||
CompliancePortal struct {
|
||||
Slug string `json:"slug"`
|
||||
} `json:"trustCenter"`
|
||||
} `json:"compliancePortal"`
|
||||
} `json:"node"`
|
||||
}
|
||||
|
||||
@@ -59,8 +59,8 @@ func TestTrustCenter_SlugHasEntropySuffix(t *testing.T) {
|
||||
"organizationId": organizationID,
|
||||
}, &result)
|
||||
require.NoError(t, err)
|
||||
require.NotEmpty(t, result.Node.TrustCenter.Slug)
|
||||
require.NotEmpty(t, result.Node.CompliancePortal.Slug)
|
||||
|
||||
slugWithEntropy := regexp.MustCompile(`^[a-z0-9-]+-[0-9a-f]{8}$`)
|
||||
assert.Regexp(t, slugWithEntropy, result.Node.TrustCenter.Slug)
|
||||
assert.Regexp(t, slugWithEntropy, result.Node.CompliancePortal.Slug)
|
||||
}
|
||||
@@ -28,15 +28,15 @@ import (
|
||||
"go.probo.inc/probo/e2e/internal/testutil"
|
||||
)
|
||||
|
||||
// lookupTrustCenterID resolves the trust center ID of the owner's organization.
|
||||
func lookupTrustCenterID(t *testing.T, owner *testutil.Client) string {
|
||||
// lookupCompliancePortalID resolves the compliance portal ID of the owner's organization.
|
||||
func lookupCompliancePortalID(t *testing.T, owner *testutil.Client) string {
|
||||
t.Helper()
|
||||
|
||||
const query = `
|
||||
query($organizationId: ID!) {
|
||||
node(id: $organizationId) {
|
||||
... on Organization {
|
||||
trustCenter { id }
|
||||
compliancePortal { id }
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -44,9 +44,9 @@ func lookupTrustCenterID(t *testing.T, owner *testutil.Client) string {
|
||||
|
||||
var result struct {
|
||||
Node struct {
|
||||
TrustCenter struct {
|
||||
CompliancePortal struct {
|
||||
ID string `json:"id"`
|
||||
} `json:"trustCenter"`
|
||||
} `json:"compliancePortal"`
|
||||
} `json:"node"`
|
||||
}
|
||||
|
||||
@@ -54,21 +54,21 @@ func lookupTrustCenterID(t *testing.T, owner *testutil.Client) string {
|
||||
"organizationId": owner.GetOrganizationID().String(),
|
||||
}, &result)
|
||||
require.NoError(t, err)
|
||||
require.NotEmpty(t, result.Node.TrustCenter.ID)
|
||||
require.NotEmpty(t, result.Node.CompliancePortal.ID)
|
||||
|
||||
return result.Node.TrustCenter.ID
|
||||
return result.Node.CompliancePortal.ID
|
||||
}
|
||||
|
||||
func lookupTrustHost(t *testing.T, owner *testutil.Client, trustCenterID string) string {
|
||||
func lookupTrustHost(t *testing.T, owner *testutil.Client, compliancePortalID string) string {
|
||||
t.Helper()
|
||||
|
||||
activateTrustCenter(t, owner, trustCenterID)
|
||||
activateCompliancePortal(t, owner, compliancePortalID)
|
||||
|
||||
const query = `
|
||||
query($organizationId: ID!) {
|
||||
node(id: $organizationId) {
|
||||
... on Organization {
|
||||
trustCenter { publicUrl }
|
||||
compliancePortal { publicUrl }
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -76,9 +76,9 @@ func lookupTrustHost(t *testing.T, owner *testutil.Client, trustCenterID string)
|
||||
|
||||
var result struct {
|
||||
Node struct {
|
||||
TrustCenter struct {
|
||||
CompliancePortal struct {
|
||||
PublicURL string `json:"publicUrl"`
|
||||
} `json:"trustCenter"`
|
||||
} `json:"compliancePortal"`
|
||||
} `json:"node"`
|
||||
}
|
||||
|
||||
@@ -86,32 +86,32 @@ func lookupTrustHost(t *testing.T, owner *testutil.Client, trustCenterID string)
|
||||
"organizationId": owner.GetOrganizationID().String(),
|
||||
}, &result)
|
||||
require.NoError(t, err)
|
||||
require.NotEmpty(t, result.Node.TrustCenter.PublicURL)
|
||||
require.NotEmpty(t, result.Node.CompliancePortal.PublicURL)
|
||||
|
||||
publicURL, err := url.Parse(result.Node.TrustCenter.PublicURL)
|
||||
publicURL, err := url.Parse(result.Node.CompliancePortal.PublicURL)
|
||||
require.NoError(t, err)
|
||||
require.NotEmpty(t, publicURL.Host)
|
||||
|
||||
return publicURL.Host
|
||||
}
|
||||
|
||||
// activateTrustCenter flips the trust center to active so its public surface
|
||||
// activateCompliancePortal flips the compliance portal to active so its public surface
|
||||
// (NDA, subprocessors, reports, branding) becomes reachable by visitors.
|
||||
func activateTrustCenter(t *testing.T, owner *testutil.Client, trustCenterID string) {
|
||||
func activateCompliancePortal(t *testing.T, owner *testutil.Client, compliancePortalID string) {
|
||||
t.Helper()
|
||||
|
||||
const query = `
|
||||
mutation($input: UpdateTrustCenterInput!) {
|
||||
updateTrustCenter(input: $input) {
|
||||
trustCenter { id active }
|
||||
mutation($input: UpdateCompliancePortalInput!) {
|
||||
updateCompliancePortal(input: $input) {
|
||||
compliancePortal { id active }
|
||||
}
|
||||
}
|
||||
`
|
||||
|
||||
err := owner.Execute(query, map[string]any{
|
||||
"input": map[string]any{
|
||||
"trustCenterId": trustCenterID,
|
||||
"active": true,
|
||||
"compliancePortalId": compliancePortalID,
|
||||
"active": true,
|
||||
},
|
||||
}, nil)
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -29,12 +29,12 @@ import (
|
||||
"go.probo.inc/probo/e2e/internal/testutil"
|
||||
)
|
||||
|
||||
func TestTrustCenter_SubprocessorsFilter(t *testing.T) {
|
||||
func TestCompliancePortal_SubprocessorsFilter(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
owner := testutil.NewClient(t, testutil.RoleOwner)
|
||||
trustCenterID := lookupTrustCenterID(t, owner)
|
||||
activateTrustCenter(t, owner, trustCenterID)
|
||||
compliancePortalID := lookupCompliancePortalID(t, owner)
|
||||
activateCompliancePortal(t, owner, compliancePortalID)
|
||||
|
||||
awsName := factory.SafeName("AWS")
|
||||
awsID := factory.NewThirdParty(owner).WithName(awsName).WithCategory("CLOUD_PROVIDER").Create()
|
||||
@@ -51,69 +51,69 @@ func TestTrustCenter_SubprocessorsFilter(t *testing.T) {
|
||||
t.Run("no filter returns every published subprocessor", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
result := querySubprocessors(t, owner, trustCenterID, nil)
|
||||
assert.Equal(t, 3, result.CurrentTrustCenter.Subprocessors.TotalCount)
|
||||
assert.Len(t, result.CurrentTrustCenter.Subprocessors.Edges, 3)
|
||||
result := querySubprocessors(t, owner, compliancePortalID, nil)
|
||||
assert.Equal(t, 3, result.CurrentCompliancePortal.Subprocessors.TotalCount)
|
||||
assert.Len(t, result.CurrentCompliancePortal.Subprocessors.Edges, 3)
|
||||
})
|
||||
|
||||
t.Run("category filter narrows to one category", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
result := querySubprocessors(t, owner, trustCenterID, map[string]any{
|
||||
result := querySubprocessors(t, owner, compliancePortalID, map[string]any{
|
||||
"category": "CLOUD_PROVIDER",
|
||||
})
|
||||
require.Equal(t, 1, result.CurrentTrustCenter.Subprocessors.TotalCount)
|
||||
require.Len(t, result.CurrentTrustCenter.Subprocessors.Edges, 1)
|
||||
assert.Equal(t, awsName, result.CurrentTrustCenter.Subprocessors.Edges[0].Node.Name)
|
||||
require.Equal(t, 1, result.CurrentCompliancePortal.Subprocessors.TotalCount)
|
||||
require.Len(t, result.CurrentCompliancePortal.Subprocessors.Edges, 1)
|
||||
assert.Equal(t, awsName, result.CurrentCompliancePortal.Subprocessors.Edges[0].Node.Name)
|
||||
})
|
||||
|
||||
t.Run("country filter matches array membership", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
result := querySubprocessors(t, owner, trustCenterID, map[string]any{
|
||||
result := querySubprocessors(t, owner, compliancePortalID, map[string]any{
|
||||
"country": "IE",
|
||||
})
|
||||
require.Equal(t, 1, result.CurrentTrustCenter.Subprocessors.TotalCount)
|
||||
require.Len(t, result.CurrentTrustCenter.Subprocessors.Edges, 1)
|
||||
assert.Equal(t, stripeName, result.CurrentTrustCenter.Subprocessors.Edges[0].Node.Name)
|
||||
require.Equal(t, 1, result.CurrentCompliancePortal.Subprocessors.TotalCount)
|
||||
require.Len(t, result.CurrentCompliancePortal.Subprocessors.Edges, 1)
|
||||
assert.Equal(t, stripeName, result.CurrentCompliancePortal.Subprocessors.Edges[0].Node.Name)
|
||||
})
|
||||
|
||||
t.Run("query filter matches name substring", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
result := querySubprocessors(t, owner, trustCenterID, map[string]any{
|
||||
result := querySubprocessors(t, owner, compliancePortalID, map[string]any{
|
||||
"query": slackName,
|
||||
})
|
||||
require.Equal(t, 1, result.CurrentTrustCenter.Subprocessors.TotalCount)
|
||||
require.Len(t, result.CurrentTrustCenter.Subprocessors.Edges, 1)
|
||||
assert.Equal(t, slackName, result.CurrentTrustCenter.Subprocessors.Edges[0].Node.Name)
|
||||
require.Equal(t, 1, result.CurrentCompliancePortal.Subprocessors.TotalCount)
|
||||
require.Len(t, result.CurrentCompliancePortal.Subprocessors.Edges, 1)
|
||||
assert.Equal(t, slackName, result.CurrentCompliancePortal.Subprocessors.Edges[0].Node.Name)
|
||||
})
|
||||
|
||||
t.Run("combined filters intersect", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
result := querySubprocessors(t, owner, trustCenterID, map[string]any{
|
||||
result := querySubprocessors(t, owner, compliancePortalID, map[string]any{
|
||||
"category": "FINANCE",
|
||||
"country": "US",
|
||||
})
|
||||
require.Equal(t, 1, result.CurrentTrustCenter.Subprocessors.TotalCount)
|
||||
require.Len(t, result.CurrentTrustCenter.Subprocessors.Edges, 1)
|
||||
assert.Equal(t, stripeName, result.CurrentTrustCenter.Subprocessors.Edges[0].Node.Name)
|
||||
require.Equal(t, 1, result.CurrentCompliancePortal.Subprocessors.TotalCount)
|
||||
require.Len(t, result.CurrentCompliancePortal.Subprocessors.Edges, 1)
|
||||
assert.Equal(t, stripeName, result.CurrentCompliancePortal.Subprocessors.Edges[0].Node.Name)
|
||||
})
|
||||
|
||||
t.Run("non-matching filter returns empty set", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
result := querySubprocessors(t, owner, trustCenterID, map[string]any{
|
||||
result := querySubprocessors(t, owner, compliancePortalID, map[string]any{
|
||||
"category": "SECURITY",
|
||||
})
|
||||
assert.Equal(t, 0, result.CurrentTrustCenter.Subprocessors.TotalCount)
|
||||
assert.Empty(t, result.CurrentTrustCenter.Subprocessors.Edges)
|
||||
assert.Equal(t, 0, result.CurrentCompliancePortal.Subprocessors.TotalCount)
|
||||
assert.Empty(t, result.CurrentCompliancePortal.Subprocessors.Edges)
|
||||
})
|
||||
}
|
||||
|
||||
type subprocessorsResult struct {
|
||||
CurrentTrustCenter struct {
|
||||
CurrentCompliancePortal struct {
|
||||
Subprocessors struct {
|
||||
TotalCount int `json:"totalCount"`
|
||||
Edges []struct {
|
||||
@@ -125,20 +125,20 @@ type subprocessorsResult struct {
|
||||
} `json:"node"`
|
||||
} `json:"edges"`
|
||||
} `json:"subprocessors"`
|
||||
} `json:"currentTrustCenter"`
|
||||
} `json:"currentCompliancePortal"`
|
||||
}
|
||||
|
||||
func querySubprocessors(
|
||||
t *testing.T,
|
||||
owner *testutil.Client,
|
||||
trustCenterID string,
|
||||
compliancePortalID string,
|
||||
filter map[string]any,
|
||||
) subprocessorsResult {
|
||||
t.Helper()
|
||||
|
||||
const query = `
|
||||
query($filter: SubprocessorFilter) {
|
||||
currentTrustCenter {
|
||||
currentCompliancePortal {
|
||||
subprocessors(first: 50, filter: $filter) {
|
||||
totalCount
|
||||
edges {
|
||||
@@ -156,7 +156,7 @@ func querySubprocessors(
|
||||
|
||||
var result subprocessorsResult
|
||||
|
||||
err := owner.ExecuteTrust(trustCenterID, query, map[string]any{"filter": filter}, &result)
|
||||
err := owner.ExecuteTrust(compliancePortalID, query, map[string]any{"filter": filter}, &result)
|
||||
require.NoError(t, err)
|
||||
|
||||
return result
|
||||
@@ -168,16 +168,16 @@ func publishSubprocessor(t *testing.T, owner *testutil.Client, thirdPartyID stri
|
||||
const mutation = `
|
||||
mutation($input: UpdateThirdPartyInput!) {
|
||||
updateThirdParty(input: $input) {
|
||||
thirdParty { id showOnTrustCenter countries }
|
||||
thirdParty { id showOnCompliancePortal countries }
|
||||
}
|
||||
}
|
||||
`
|
||||
|
||||
err := owner.Execute(mutation, map[string]any{
|
||||
"input": map[string]any{
|
||||
"id": thirdPartyID,
|
||||
"showOnTrustCenter": true,
|
||||
"countries": countries,
|
||||
"id": thirdPartyID,
|
||||
"showOnCompliancePortal": true,
|
||||
"countries": countries,
|
||||
},
|
||||
}, nil)
|
||||
require.NoError(t, err)
|
||||
|
||||
Reference in New Issue
Block a user