Rename vendors to third parties
Renames the user-facing 'vendor' concept to 'third party' across the entire codebase. The shared common_third_parties reference table is unchanged. Migration. Renames the vendor_category enum, the vendors and vendor_<entity> tables (contacts, services, compliance_reports, business_associate_agreements, data_privacy_agreements, risk_assessments) and their vendor_id columns, the asset_vendors / data_vendors / processing_activity_vendors junction tables, generated_documents.vendors_document_id, the webhook_event_type 'vendor:<verb>' values, and the snapshots_type 'VENDORS' value. Backend. Renames coredata models and SQL queries, probo services, GraphQL / MCP API surface, console / trust / webhook resolvers and types, the CLI (prb vendor* -> prb third-party*; pkg/cmd/vendormgmt -> pkg/cmd/thirdpartymgmt), the document generator, vetting agent prompts, and the common-third-parties-import command. Frontend, packages, n8n, e2e. Renames apps/console pages, components, hooks, routes, dialogs, and tabs; the shared @probo/vendors package (now @probo/third-parties); the @probo/ui Vendors atoms (now ThirdParties, VendorLogo -> ThirdPartyLogo); the n8n community node actions/vendor folder (now actions/thirdParty); and the e2e Go test suite (console and MCP). Filesystem and URL paths use kebab-case (third-parties), GraphQL fields and TypeScript identifiers use camelCase (thirdParty / thirdParties), Go types use PascalCase (ThirdParty), and human-facing text uses 'third party' with a space. Co-authored-by: Bryan Frimin <bryan@getprobo.com> Signed-off-by: Bryan Frimin <bryan@getprobo.com> Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
@@ -8,18 +8,18 @@ Policy-based authorization in `pkg/iam/` using an evaluation model similar to AW
|
||||
|
||||
**Policy** — a named collection of statements:
|
||||
```go
|
||||
policy.NewPolicy("vendor-crud", "Vendor CRUD",
|
||||
policy.Allow(ActionVendorGet, ActionVendorList).WithSID("read-vendors"),
|
||||
policy.Deny(ActionVendorDelete).WithSID("deny-vendor-delete"),
|
||||
).WithDescription("Standard vendor access")
|
||||
policy.NewPolicy("thirdParty-crud", "ThirdParty CRUD",
|
||||
policy.Allow(ActionThirdPartyGet, ActionThirdPartyList).WithSID("read-thirdParties"),
|
||||
policy.Deny(ActionThirdPartyDelete).WithSID("deny-thirdParty-delete"),
|
||||
).WithDescription("Standard third party access")
|
||||
```
|
||||
|
||||
**Statement** — a single permission rule with effect (allow/deny), actions, optional resources, and optional conditions.
|
||||
|
||||
**Action format** — `SERVICE:RESOURCE:OPERATION` with wildcard support:
|
||||
```
|
||||
core:vendor:create # specific action
|
||||
core:vendor:* # all vendor actions
|
||||
core:thirdParty:create # specific action
|
||||
core:thirdParty:* # all third party actions
|
||||
core:* # all core actions
|
||||
* # everything
|
||||
```
|
||||
@@ -39,8 +39,8 @@ The evaluator processes all statements against a request:
|
||||
```go
|
||||
err := iamService.Authorizer.Authorize(ctx, iam.AuthorizeParams{
|
||||
Principal: identityID, // who
|
||||
Resource: vendorID, // what
|
||||
Action: probo.ActionVendorGet, // which action
|
||||
Resource: thirdPartyID, // what
|
||||
Action: probo.ActionThirdPartyGet, // which action
|
||||
ResourceAttributes: map[string]string{}, // optional extra attributes
|
||||
})
|
||||
```
|
||||
@@ -78,8 +78,8 @@ Conditions constrain when a statement applies. All conditions must be satisfied.
|
||||
// Users can only access resources in their organization
|
||||
organizationCondition := policy.Equals("principal.organization_id", "resource.organization_id")
|
||||
|
||||
policy.Allow(ActionVendorGet).
|
||||
WithSID("view-vendor").
|
||||
policy.Allow(ActionThirdPartyGet).
|
||||
WithSID("view-thirdParty").
|
||||
When(organizationCondition)
|
||||
```
|
||||
|
||||
@@ -97,14 +97,14 @@ Key paths use `principal.ATTR` or `resource.ATTR` (e.g., `principal.organization
|
||||
Resources that support authorization must implement this interface in `pkg/coredata/`:
|
||||
|
||||
```go
|
||||
func (v *Vendor) AuthorizationAttributes(ctx context.Context, conn pg.Conn) (map[string]string, error) {
|
||||
q := `SELECT organization_id FROM vendors WHERE id = $1 LIMIT 1;`
|
||||
func (v *ThirdParty) AuthorizationAttributes(ctx context.Context, conn pg.Conn) (map[string]string, error) {
|
||||
q := `SELECT organization_id FROM thirdParties WHERE id = $1 LIMIT 1;`
|
||||
var organizationID gid.GID
|
||||
if err := conn.QueryRow(ctx, q, v.ID).Scan(&organizationID); err != nil {
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
return nil, ErrResourceNotFound
|
||||
}
|
||||
return nil, fmt.Errorf("cannot query vendor authorization attributes: %w", err)
|
||||
return nil, fmt.Errorf("cannot query third party authorization attributes: %w", err)
|
||||
}
|
||||
return map[string]string{"organization_id": organizationID.String()}, nil
|
||||
}
|
||||
@@ -126,14 +126,14 @@ var (
|
||||
|
||||
**GraphQL resolvers** use `AuthorizeFunc` from `pkg/server/api/authz/`:
|
||||
```go
|
||||
if err := authorize(ctx, vendorID, probo.ActionVendorGet); err != nil {
|
||||
if err := authorize(ctx, thirdPartyID, probo.ActionThirdPartyGet); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
```
|
||||
|
||||
**MCP resolvers** use `MustAuthorize` which panics (caught by middleware):
|
||||
```go
|
||||
r.MustAuthorize(ctx, input.ID, probo.ActionVendorGet)
|
||||
r.MustAuthorize(ctx, input.ID, probo.ActionThirdPartyGet)
|
||||
```
|
||||
|
||||
## File locations
|
||||
@@ -155,11 +155,11 @@ IAM actions live in `pkg/iam/iam_actions.go`, probo actions in `pkg/probo/action
|
||||
|
||||
```go
|
||||
const (
|
||||
ActionVendorGet = "core:vendor:get"
|
||||
ActionVendorList = "core:vendor:list"
|
||||
ActionVendorCreate = "core:vendor:create"
|
||||
ActionVendorUpdate = "core:vendor:update"
|
||||
ActionVendorDelete = "core:vendor:delete"
|
||||
ActionThirdPartyGet = "core:thirdParty:get"
|
||||
ActionThirdPartyList = "core:thirdParty:list"
|
||||
ActionThirdPartyCreate = "core:thirdParty:create"
|
||||
ActionThirdPartyUpdate = "core:thirdParty:update"
|
||||
ActionThirdPartyDelete = "core:thirdParty:delete"
|
||||
)
|
||||
```
|
||||
|
||||
|
||||
Reference in New Issue
Block a user