Add proboctl statement of applicability commands
Add CRUD commands for statements of applicability and their applicability statements (add, list, remove, update). Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
130
pkg/cmd/soa/create/create.go
Normal file
130
pkg/cmd/soa/create/create.go
Normal file
@@ -0,0 +1,130 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package create
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const createMutation = `
|
||||||
|
mutation($input: CreateStateOfApplicabilityInput!) {
|
||||||
|
createStateOfApplicability(input: $input) {
|
||||||
|
stateOfApplicabilityEdge {
|
||||||
|
node {
|
||||||
|
id
|
||||||
|
name
|
||||||
|
createdAt
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
type createResponse struct {
|
||||||
|
CreateStateOfApplicability struct {
|
||||||
|
StateOfApplicabilityEdge struct {
|
||||||
|
Node struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
Name string `json:"name"`
|
||||||
|
CreatedAt string `json:"createdAt"`
|
||||||
|
} `json:"node"`
|
||||||
|
} `json:"stateOfApplicabilityEdge"`
|
||||||
|
} `json:"createStateOfApplicability"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewCmdCreate(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var (
|
||||||
|
flagOrg string
|
||||||
|
flagName string
|
||||||
|
flagOwner string
|
||||||
|
)
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "create",
|
||||||
|
Short: "Create a new statement of applicability",
|
||||||
|
Example: ` # Create a statement of applicability
|
||||||
|
proboctl soa create --name "ISO 27001 SoA" --owner PROFILE_ID`,
|
||||||
|
Args: cobra.NoArgs,
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
if flagOrg == "" {
|
||||||
|
flagOrg = hc.Organization
|
||||||
|
}
|
||||||
|
|
||||||
|
if flagOrg == "" {
|
||||||
|
return fmt.Errorf("organization is required; pass --org or set a default with 'proboctl auth login'")
|
||||||
|
}
|
||||||
|
|
||||||
|
input := map[string]any{
|
||||||
|
"organizationId": flagOrg,
|
||||||
|
"name": flagName,
|
||||||
|
"ownerId": flagOwner,
|
||||||
|
}
|
||||||
|
|
||||||
|
data, err := client.Do(
|
||||||
|
createMutation,
|
||||||
|
map[string]any{"input": input},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
var resp createResponse
|
||||||
|
if err := json.Unmarshal(data, &resp); err != nil {
|
||||||
|
return fmt.Errorf("cannot parse response: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
s := resp.CreateStateOfApplicability.StateOfApplicabilityEdge.Node
|
||||||
|
_, _ = fmt.Fprintf(
|
||||||
|
f.IOStreams.Out,
|
||||||
|
"Created statement of applicability %s (%s)\n",
|
||||||
|
s.ID,
|
||||||
|
s.Name,
|
||||||
|
)
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.Flags().StringVar(&flagOrg, "org", "", "Organization ID")
|
||||||
|
cmd.Flags().StringVar(&flagName, "name", "", "Name (required)")
|
||||||
|
cmd.Flags().StringVar(&flagOwner, "owner", "", "Owner profile ID (required)")
|
||||||
|
|
||||||
|
_ = cmd.MarkFlagRequired("name")
|
||||||
|
_ = cmd.MarkFlagRequired("owner")
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
102
pkg/cmd/soa/delete/delete.go
Normal file
102
pkg/cmd/soa/delete/delete.go
Normal file
@@ -0,0 +1,102 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package delete
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/charmbracelet/huh"
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const deleteMutation = `
|
||||||
|
mutation($input: DeleteStateOfApplicabilityInput!) {
|
||||||
|
deleteStateOfApplicability(input: $input) {
|
||||||
|
deletedStateOfApplicabilityId
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
func NewCmdDelete(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var flagYes bool
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "delete <id>",
|
||||||
|
Short: "Delete a statement of applicability",
|
||||||
|
Args: cobra.ExactArgs(1),
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
if !flagYes {
|
||||||
|
if !f.IOStreams.IsInteractive() {
|
||||||
|
return fmt.Errorf("cannot delete statement of applicability: confirmation required, use --yes to confirm")
|
||||||
|
}
|
||||||
|
|
||||||
|
var confirmed bool
|
||||||
|
err := huh.NewConfirm().
|
||||||
|
Title(fmt.Sprintf("Delete statement of applicability %s?", args[0])).
|
||||||
|
Value(&confirmed).
|
||||||
|
Run()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if !confirmed {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
_, err = client.Do(
|
||||||
|
deleteMutation,
|
||||||
|
map[string]any{
|
||||||
|
"input": map[string]any{
|
||||||
|
"stateOfApplicabilityId": args[0],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
_, _ = fmt.Fprintf(
|
||||||
|
f.IOStreams.Out,
|
||||||
|
"Deleted statement of applicability %s\n",
|
||||||
|
args[0],
|
||||||
|
)
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.Flags().BoolVarP(&flagYes, "yes", "y", false, "Skip confirmation prompt")
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
189
pkg/cmd/soa/list/list.go
Normal file
189
pkg/cmd/soa/list/list.go
Normal file
@@ -0,0 +1,189 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package list
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const listQuery = `
|
||||||
|
query($id: ID!, $first: Int, $after: CursorKey, $orderBy: StateOfApplicabilityOrder) {
|
||||||
|
node(id: $id) {
|
||||||
|
__typename
|
||||||
|
... on Organization {
|
||||||
|
statesOfApplicability(first: $first, after: $after, orderBy: $orderBy) {
|
||||||
|
totalCount
|
||||||
|
edges {
|
||||||
|
node {
|
||||||
|
id
|
||||||
|
name
|
||||||
|
createdAt
|
||||||
|
updatedAt
|
||||||
|
}
|
||||||
|
}
|
||||||
|
pageInfo {
|
||||||
|
hasNextPage
|
||||||
|
endCursor
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
type stateOfApplicability struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
Name string `json:"name"`
|
||||||
|
CreatedAt string `json:"createdAt"`
|
||||||
|
UpdatedAt string `json:"updatedAt"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewCmdList(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var (
|
||||||
|
flagOrg string
|
||||||
|
flagLimit int
|
||||||
|
flagOrderBy string
|
||||||
|
flagOrderDir string
|
||||||
|
flagOutput *string
|
||||||
|
)
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "list",
|
||||||
|
Short: "List statements of applicability",
|
||||||
|
Aliases: []string{"ls"},
|
||||||
|
Args: cobra.NoArgs,
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
if err := cmdutil.ValidateOutputFlag(flagOutput); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
if flagOrg == "" {
|
||||||
|
flagOrg = hc.Organization
|
||||||
|
}
|
||||||
|
|
||||||
|
if flagOrg == "" {
|
||||||
|
return fmt.Errorf("organization is required; pass --org or set a default with 'proboctl auth login'")
|
||||||
|
}
|
||||||
|
|
||||||
|
variables := map[string]any{
|
||||||
|
"id": flagOrg,
|
||||||
|
}
|
||||||
|
|
||||||
|
if flagOrderBy != "" {
|
||||||
|
if err := cmdutil.ValidateEnum("order-by", flagOrderBy, []string{"NAME", "CREATED_AT"}); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
variables["orderBy"] = map[string]any{
|
||||||
|
"field": flagOrderBy,
|
||||||
|
"direction": flagOrderDir,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
soas, totalCount, err := api.Paginate(
|
||||||
|
client,
|
||||||
|
listQuery,
|
||||||
|
variables,
|
||||||
|
flagLimit,
|
||||||
|
func(data json.RawMessage) (*api.Connection[stateOfApplicability], error) {
|
||||||
|
var resp struct {
|
||||||
|
Node *struct {
|
||||||
|
Typename string `json:"__typename"`
|
||||||
|
StatesOfApplicability api.Connection[stateOfApplicability] `json:"statesOfApplicability"`
|
||||||
|
} `json:"node"`
|
||||||
|
}
|
||||||
|
if err := json.Unmarshal(data, &resp); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if resp.Node == nil {
|
||||||
|
return nil, fmt.Errorf("organization %s not found", flagOrg)
|
||||||
|
}
|
||||||
|
if resp.Node.Typename != "Organization" {
|
||||||
|
return nil, fmt.Errorf("expected Organization node, got %s", resp.Node.Typename)
|
||||||
|
}
|
||||||
|
return &resp.Node.StatesOfApplicability, nil
|
||||||
|
},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
if *flagOutput == cmdutil.OutputJSON {
|
||||||
|
if soas == nil {
|
||||||
|
soas = []stateOfApplicability{}
|
||||||
|
}
|
||||||
|
return cmdutil.PrintJSON(f.IOStreams.Out, soas)
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(soas) == 0 {
|
||||||
|
_, _ = fmt.Fprintln(f.IOStreams.Out, "No statements of applicability found.")
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
rows := make([][]string, 0, len(soas))
|
||||||
|
for _, s := range soas {
|
||||||
|
rows = append(rows, []string{
|
||||||
|
s.ID,
|
||||||
|
s.Name,
|
||||||
|
cmdutil.FormatTime(s.CreatedAt),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
t := cmdutil.NewTable("ID", "NAME", "CREATED").Rows(rows...)
|
||||||
|
|
||||||
|
_, _ = fmt.Fprintln(f.IOStreams.Out, t)
|
||||||
|
|
||||||
|
if totalCount > len(soas) {
|
||||||
|
_, _ = fmt.Fprintf(
|
||||||
|
f.IOStreams.ErrOut,
|
||||||
|
"\nShowing %d of %d statements of applicability\n",
|
||||||
|
len(soas),
|
||||||
|
totalCount,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.Flags().StringVar(&flagOrg, "org", "", "Organization ID")
|
||||||
|
cmd.Flags().IntVarP(&flagLimit, "limit", "L", 30, "Maximum number of items to list")
|
||||||
|
cmd.Flags().StringVar(&flagOrderBy, "order-by", "", "Order by field (NAME, CREATED_AT)")
|
||||||
|
flagOutput = cmdutil.AddOutputFlag(cmd)
|
||||||
|
cmd.Flags().StringVar(&flagOrderDir, "order-direction", "DESC", "Sort direction (ASC, DESC)")
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
42
pkg/cmd/soa/soa.go
Normal file
42
pkg/cmd/soa/soa.go
Normal file
@@ -0,0 +1,42 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package soa
|
||||||
|
|
||||||
|
import (
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/create"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/delete"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/list"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/statement"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/update"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/view"
|
||||||
|
)
|
||||||
|
|
||||||
|
func NewCmdSoa(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "soa <command>",
|
||||||
|
Short: "Manage statements of applicability",
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.AddCommand(list.NewCmdList(f))
|
||||||
|
cmd.AddCommand(create.NewCmdCreate(f))
|
||||||
|
cmd.AddCommand(view.NewCmdView(f))
|
||||||
|
cmd.AddCommand(update.NewCmdUpdate(f))
|
||||||
|
cmd.AddCommand(delete.NewCmdDelete(f))
|
||||||
|
cmd.AddCommand(statement.NewCmdStatement(f))
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
183
pkg/cmd/soa/statement/add/add.go
Normal file
183
pkg/cmd/soa/statement/add/add.go
Normal file
@@ -0,0 +1,183 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package add
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/charmbracelet/huh"
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const createMutation = `
|
||||||
|
mutation($input: CreateApplicabilityStatementInput!) {
|
||||||
|
createApplicabilityStatement(input: $input) {
|
||||||
|
applicabilityStatementEdge {
|
||||||
|
node {
|
||||||
|
id
|
||||||
|
applicability
|
||||||
|
justification
|
||||||
|
control {
|
||||||
|
id
|
||||||
|
sectionTitle
|
||||||
|
name
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
type createResponse struct {
|
||||||
|
CreateApplicabilityStatement struct {
|
||||||
|
ApplicabilityStatementEdge struct {
|
||||||
|
Node struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
Applicability bool `json:"applicability"`
|
||||||
|
Justification string `json:"justification"`
|
||||||
|
Control struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
SectionTitle string `json:"sectionTitle"`
|
||||||
|
Name string `json:"name"`
|
||||||
|
} `json:"control"`
|
||||||
|
} `json:"node"`
|
||||||
|
} `json:"applicabilityStatementEdge"`
|
||||||
|
} `json:"createApplicabilityStatement"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewCmdAdd(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var (
|
||||||
|
flagSoA string
|
||||||
|
flagControl string
|
||||||
|
flagApplicable bool
|
||||||
|
flagNotApplicable bool
|
||||||
|
flagJustification string
|
||||||
|
)
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "add",
|
||||||
|
Short: "Add an applicability statement to a SoA",
|
||||||
|
Example: ` # Add a control as applicable
|
||||||
|
proboctl soa statement add --soa SOA_ID --control CTRL_ID --applicable
|
||||||
|
|
||||||
|
# Add a control as not applicable with justification
|
||||||
|
proboctl soa statement add --soa SOA_ID --control CTRL_ID --not-applicable --justification "Not in scope"`,
|
||||||
|
Args: cobra.NoArgs,
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
if flagApplicable && flagNotApplicable {
|
||||||
|
return fmt.Errorf("cannot set both --applicable and --not-applicable")
|
||||||
|
}
|
||||||
|
if !flagApplicable && !flagNotApplicable {
|
||||||
|
if !f.IOStreams.IsInteractive() {
|
||||||
|
return fmt.Errorf("either --applicable or --not-applicable is required")
|
||||||
|
}
|
||||||
|
|
||||||
|
var choice string
|
||||||
|
err := huh.NewSelect[string]().
|
||||||
|
Title("Is this control applicable?").
|
||||||
|
Options(
|
||||||
|
huh.NewOption("Applicable", "applicable"),
|
||||||
|
huh.NewOption("Not applicable", "not-applicable"),
|
||||||
|
).
|
||||||
|
Value(&choice).
|
||||||
|
Run()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
flagApplicable = choice == "applicable"
|
||||||
|
}
|
||||||
|
|
||||||
|
if !flagApplicable && flagJustification == "" && f.IOStreams.IsInteractive() {
|
||||||
|
err := huh.NewText().
|
||||||
|
Title("Justification for not applicable").
|
||||||
|
Value(&flagJustification).
|
||||||
|
Run()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
input := map[string]any{
|
||||||
|
"stateOfApplicabilityId": flagSoA,
|
||||||
|
"controlId": flagControl,
|
||||||
|
"applicability": flagApplicable,
|
||||||
|
}
|
||||||
|
|
||||||
|
if flagJustification != "" {
|
||||||
|
input["justification"] = flagJustification
|
||||||
|
}
|
||||||
|
|
||||||
|
data, err := client.Do(
|
||||||
|
createMutation,
|
||||||
|
map[string]any{"input": input},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
var resp createResponse
|
||||||
|
if err := json.Unmarshal(data, &resp); err != nil {
|
||||||
|
return fmt.Errorf("cannot parse response: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
s := resp.CreateApplicabilityStatement.ApplicabilityStatementEdge.Node
|
||||||
|
applicable := "not applicable"
|
||||||
|
if s.Applicability {
|
||||||
|
applicable = "applicable"
|
||||||
|
}
|
||||||
|
_, _ = fmt.Fprintf(
|
||||||
|
f.IOStreams.Out,
|
||||||
|
"Added statement %s: control %s (%s) marked as %s\n",
|
||||||
|
s.ID,
|
||||||
|
s.Control.SectionTitle,
|
||||||
|
s.Control.Name,
|
||||||
|
applicable,
|
||||||
|
)
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.Flags().StringVar(&flagSoA, "soa", "", "Statement of applicability ID (required)")
|
||||||
|
cmd.Flags().StringVar(&flagControl, "control", "", "Control ID (required)")
|
||||||
|
cmd.Flags().BoolVar(&flagApplicable, "applicable", false, "Mark control as applicable")
|
||||||
|
cmd.Flags().BoolVar(&flagNotApplicable, "not-applicable", false, "Mark control as not applicable")
|
||||||
|
cmd.Flags().StringVar(&flagJustification, "justification", "", "Justification for the applicability decision")
|
||||||
|
|
||||||
|
_ = cmd.MarkFlagRequired("soa")
|
||||||
|
_ = cmd.MarkFlagRequired("control")
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
190
pkg/cmd/soa/statement/list/list.go
Normal file
190
pkg/cmd/soa/statement/list/list.go
Normal file
@@ -0,0 +1,190 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package list
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const listQuery = `
|
||||||
|
query($id: ID!, $first: Int, $after: CursorKey, $orderBy: ApplicabilityStatementOrder) {
|
||||||
|
node(id: $id) {
|
||||||
|
__typename
|
||||||
|
... on StateOfApplicability {
|
||||||
|
applicabilityStatements(first: $first, after: $after, orderBy: $orderBy) {
|
||||||
|
totalCount
|
||||||
|
edges {
|
||||||
|
node {
|
||||||
|
id
|
||||||
|
applicability
|
||||||
|
justification
|
||||||
|
control {
|
||||||
|
id
|
||||||
|
sectionTitle
|
||||||
|
name
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
pageInfo {
|
||||||
|
hasNextPage
|
||||||
|
endCursor
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
type applicabilityStatement struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
Applicability bool `json:"applicability"`
|
||||||
|
Justification string `json:"justification"`
|
||||||
|
Control struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
SectionTitle string `json:"sectionTitle"`
|
||||||
|
Name string `json:"name"`
|
||||||
|
} `json:"control"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewCmdList(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var (
|
||||||
|
flagLimit int
|
||||||
|
flagOrderBy string
|
||||||
|
flagOrderDir string
|
||||||
|
flagOutput *string
|
||||||
|
)
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "list <soa-id>",
|
||||||
|
Short: "List applicability statements in a SoA",
|
||||||
|
Aliases: []string{"ls"},
|
||||||
|
Args: cobra.ExactArgs(1),
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
if err := cmdutil.ValidateOutputFlag(flagOutput); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
variables := map[string]any{
|
||||||
|
"id": args[0],
|
||||||
|
}
|
||||||
|
|
||||||
|
if flagOrderBy != "" {
|
||||||
|
if err := cmdutil.ValidateEnum("order-by", flagOrderBy, []string{"CREATED_AT", "CONTROL_SECTION_TITLE"}); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
variables["orderBy"] = map[string]any{
|
||||||
|
"field": flagOrderBy,
|
||||||
|
"direction": flagOrderDir,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
statements, totalCount, err := api.Paginate(
|
||||||
|
client,
|
||||||
|
listQuery,
|
||||||
|
variables,
|
||||||
|
flagLimit,
|
||||||
|
func(data json.RawMessage) (*api.Connection[applicabilityStatement], error) {
|
||||||
|
var resp struct {
|
||||||
|
Node *struct {
|
||||||
|
Typename string `json:"__typename"`
|
||||||
|
ApplicabilityStatements api.Connection[applicabilityStatement] `json:"applicabilityStatements"`
|
||||||
|
} `json:"node"`
|
||||||
|
}
|
||||||
|
if err := json.Unmarshal(data, &resp); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if resp.Node == nil {
|
||||||
|
return nil, fmt.Errorf("statement of applicability %s not found", args[0])
|
||||||
|
}
|
||||||
|
if resp.Node.Typename != "StateOfApplicability" {
|
||||||
|
return nil, fmt.Errorf("expected StateOfApplicability node, got %s", resp.Node.Typename)
|
||||||
|
}
|
||||||
|
return &resp.Node.ApplicabilityStatements, nil
|
||||||
|
},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
if *flagOutput == cmdutil.OutputJSON {
|
||||||
|
return cmdutil.PrintJSON(f.IOStreams.Out, statements)
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(statements) == 0 {
|
||||||
|
_, _ = fmt.Fprintln(f.IOStreams.Out, "No applicability statements found.")
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
rows := make([][]string, 0, len(statements))
|
||||||
|
for _, s := range statements {
|
||||||
|
applicable := "No"
|
||||||
|
if s.Applicability {
|
||||||
|
applicable = "Yes"
|
||||||
|
}
|
||||||
|
rows = append(rows, []string{
|
||||||
|
s.ID,
|
||||||
|
s.Control.SectionTitle,
|
||||||
|
s.Control.Name,
|
||||||
|
applicable,
|
||||||
|
s.Justification,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
t := cmdutil.NewTable("ID", "SECTION", "CONTROL", "APPLICABLE", "JUSTIFICATION").Rows(rows...)
|
||||||
|
|
||||||
|
_, _ = fmt.Fprintln(f.IOStreams.Out, t)
|
||||||
|
|
||||||
|
if totalCount > len(statements) {
|
||||||
|
_, _ = fmt.Fprintf(
|
||||||
|
f.IOStreams.ErrOut,
|
||||||
|
"\nShowing %d of %d statements\n",
|
||||||
|
len(statements),
|
||||||
|
totalCount,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.Flags().IntVarP(&flagLimit, "limit", "L", 30, "Maximum number of statements to list")
|
||||||
|
cmd.Flags().StringVar(&flagOrderBy, "order-by", "", "Order by field (CREATED_AT, CONTROL_SECTION_TITLE)")
|
||||||
|
flagOutput = cmdutil.AddOutputFlag(cmd)
|
||||||
|
cmd.Flags().StringVar(&flagOrderDir, "order-direction", "DESC", "Sort direction (ASC, DESC)")
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
102
pkg/cmd/soa/statement/remove/remove.go
Normal file
102
pkg/cmd/soa/statement/remove/remove.go
Normal file
@@ -0,0 +1,102 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package remove
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/charmbracelet/huh"
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const deleteMutation = `
|
||||||
|
mutation($input: DeleteApplicabilityStatementInput!) {
|
||||||
|
deleteApplicabilityStatement(input: $input) {
|
||||||
|
deletedApplicabilityStatementId
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
func NewCmdRemove(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var flagYes bool
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "remove <id>",
|
||||||
|
Short: "Remove an applicability statement from a SoA",
|
||||||
|
Args: cobra.ExactArgs(1),
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
if !flagYes {
|
||||||
|
if !f.IOStreams.IsInteractive() {
|
||||||
|
return fmt.Errorf("cannot remove statement: confirmation required, use --yes to confirm")
|
||||||
|
}
|
||||||
|
|
||||||
|
var confirmed bool
|
||||||
|
err := huh.NewConfirm().
|
||||||
|
Title(fmt.Sprintf("Remove applicability statement %s?", args[0])).
|
||||||
|
Value(&confirmed).
|
||||||
|
Run()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if !confirmed {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
_, err = client.Do(
|
||||||
|
deleteMutation,
|
||||||
|
map[string]any{
|
||||||
|
"input": map[string]any{
|
||||||
|
"applicabilityStatementId": args[0],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
_, _ = fmt.Fprintf(
|
||||||
|
f.IOStreams.Out,
|
||||||
|
"Removed applicability statement %s\n",
|
||||||
|
args[0],
|
||||||
|
)
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.Flags().BoolVarP(&flagYes, "yes", "y", false, "Skip confirmation prompt")
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
38
pkg/cmd/soa/statement/statement.go
Normal file
38
pkg/cmd/soa/statement/statement.go
Normal file
@@ -0,0 +1,38 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package statement
|
||||||
|
|
||||||
|
import (
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/statement/add"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/statement/list"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/statement/remove"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/soa/statement/update"
|
||||||
|
)
|
||||||
|
|
||||||
|
func NewCmdStatement(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "statement <command>",
|
||||||
|
Short: "Manage applicability statements in a SoA",
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.AddCommand(list.NewCmdList(f))
|
||||||
|
cmd.AddCommand(add.NewCmdAdd(f))
|
||||||
|
cmd.AddCommand(update.NewCmdUpdate(f))
|
||||||
|
cmd.AddCommand(remove.NewCmdRemove(f))
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
142
pkg/cmd/soa/statement/update/update.go
Normal file
142
pkg/cmd/soa/statement/update/update.go
Normal file
@@ -0,0 +1,142 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package update
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const updateMutation = `
|
||||||
|
mutation($input: UpdateApplicabilityStatementInput!) {
|
||||||
|
updateApplicabilityStatement(input: $input) {
|
||||||
|
applicabilityStatement {
|
||||||
|
id
|
||||||
|
applicability
|
||||||
|
justification
|
||||||
|
control {
|
||||||
|
id
|
||||||
|
sectionTitle
|
||||||
|
name
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
type updateResponse struct {
|
||||||
|
UpdateApplicabilityStatement struct {
|
||||||
|
ApplicabilityStatement struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
Applicability bool `json:"applicability"`
|
||||||
|
Justification string `json:"justification"`
|
||||||
|
Control struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
SectionTitle string `json:"sectionTitle"`
|
||||||
|
Name string `json:"name"`
|
||||||
|
} `json:"control"`
|
||||||
|
} `json:"applicabilityStatement"`
|
||||||
|
} `json:"updateApplicabilityStatement"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewCmdUpdate(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var (
|
||||||
|
flagApplicable bool
|
||||||
|
flagNotApplicable bool
|
||||||
|
flagJustification string
|
||||||
|
)
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "update <id>",
|
||||||
|
Short: "Update an applicability statement",
|
||||||
|
Args: cobra.ExactArgs(1),
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
if flagApplicable && flagNotApplicable {
|
||||||
|
return fmt.Errorf("cannot set both --applicable and --not-applicable")
|
||||||
|
}
|
||||||
|
if !flagApplicable && !flagNotApplicable && !cmd.Flags().Changed("justification") {
|
||||||
|
return fmt.Errorf("at least one of --applicable, --not-applicable, or --justification is required")
|
||||||
|
}
|
||||||
|
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
input := map[string]any{
|
||||||
|
"applicabilityStatementId": args[0],
|
||||||
|
}
|
||||||
|
|
||||||
|
if cmd.Flags().Changed("applicable") || cmd.Flags().Changed("not-applicable") {
|
||||||
|
input["applicability"] = flagApplicable
|
||||||
|
}
|
||||||
|
|
||||||
|
if cmd.Flags().Changed("justification") {
|
||||||
|
input["justification"] = flagJustification
|
||||||
|
}
|
||||||
|
|
||||||
|
data, err := client.Do(
|
||||||
|
updateMutation,
|
||||||
|
map[string]any{"input": input},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
var resp updateResponse
|
||||||
|
if err := json.Unmarshal(data, &resp); err != nil {
|
||||||
|
return fmt.Errorf("cannot parse response: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
s := resp.UpdateApplicabilityStatement.ApplicabilityStatement
|
||||||
|
applicable := "not applicable"
|
||||||
|
if s.Applicability {
|
||||||
|
applicable = "applicable"
|
||||||
|
}
|
||||||
|
_, _ = fmt.Fprintf(
|
||||||
|
f.IOStreams.Out,
|
||||||
|
"Updated statement %s: control %s (%s) marked as %s\n",
|
||||||
|
s.ID,
|
||||||
|
s.Control.SectionTitle,
|
||||||
|
s.Control.Name,
|
||||||
|
applicable,
|
||||||
|
)
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.Flags().BoolVar(&flagApplicable, "applicable", false, "Mark control as applicable")
|
||||||
|
cmd.Flags().BoolVar(&flagNotApplicable, "not-applicable", false, "Mark control as not applicable")
|
||||||
|
cmd.Flags().StringVar(&flagJustification, "justification", "", "Justification for the applicability decision")
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
122
pkg/cmd/soa/update/update.go
Normal file
122
pkg/cmd/soa/update/update.go
Normal file
@@ -0,0 +1,122 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package update
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const updateMutation = `
|
||||||
|
mutation($input: UpdateStateOfApplicabilityInput!) {
|
||||||
|
updateStateOfApplicability(input: $input) {
|
||||||
|
stateOfApplicability {
|
||||||
|
id
|
||||||
|
name
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
type updateResponse struct {
|
||||||
|
UpdateStateOfApplicability struct {
|
||||||
|
StateOfApplicability struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
Name string `json:"name"`
|
||||||
|
} `json:"stateOfApplicability"`
|
||||||
|
} `json:"updateStateOfApplicability"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewCmdUpdate(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var (
|
||||||
|
flagName string
|
||||||
|
flagOwner string
|
||||||
|
)
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "update <id>",
|
||||||
|
Short: "Update a statement of applicability",
|
||||||
|
Args: cobra.ExactArgs(1),
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
input := map[string]any{
|
||||||
|
"id": args[0],
|
||||||
|
}
|
||||||
|
|
||||||
|
if cmd.Flags().Changed("name") {
|
||||||
|
input["name"] = flagName
|
||||||
|
}
|
||||||
|
if cmd.Flags().Changed("owner") {
|
||||||
|
if flagOwner == "" {
|
||||||
|
input["ownerId"] = nil
|
||||||
|
} else {
|
||||||
|
input["ownerId"] = flagOwner
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(input) == 1 {
|
||||||
|
return fmt.Errorf("at least one field must be specified for update")
|
||||||
|
}
|
||||||
|
|
||||||
|
data, err := client.Do(
|
||||||
|
updateMutation,
|
||||||
|
map[string]any{"input": input},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
var resp updateResponse
|
||||||
|
if err := json.Unmarshal(data, &resp); err != nil {
|
||||||
|
return fmt.Errorf("cannot parse response: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
s := resp.UpdateStateOfApplicability.StateOfApplicability
|
||||||
|
_, _ = fmt.Fprintf(
|
||||||
|
f.IOStreams.Out,
|
||||||
|
"Updated statement of applicability %s (%s)\n",
|
||||||
|
s.ID,
|
||||||
|
s.Name,
|
||||||
|
)
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd.Flags().StringVar(&flagName, "name", "", "Name")
|
||||||
|
cmd.Flags().StringVar(&flagOwner, "owner", "", "Owner profile ID")
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
140
pkg/cmd/soa/view/view.go
Normal file
140
pkg/cmd/soa/view/view.go
Normal file
@@ -0,0 +1,140 @@
|
|||||||
|
// Copyright (c) 2026 Probo Inc <hello@getprobo.com>.
|
||||||
|
//
|
||||||
|
// Permission to use, copy, modify, and/or distribute this software for any
|
||||||
|
// purpose with or without fee is hereby granted, provided that the above
|
||||||
|
// copyright notice and this permission notice appear in all copies.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||||
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||||
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||||
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||||
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||||
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||||
|
// PERFORMANCE OF THIS SOFTWARE.
|
||||||
|
|
||||||
|
package view
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"github.com/charmbracelet/lipgloss"
|
||||||
|
"github.com/spf13/cobra"
|
||||||
|
"go.probo.inc/probo/pkg/cli/api"
|
||||||
|
"go.probo.inc/probo/pkg/cmd/cmdutil"
|
||||||
|
)
|
||||||
|
|
||||||
|
const viewQuery = `
|
||||||
|
query($id: ID!) {
|
||||||
|
node(id: $id) {
|
||||||
|
__typename
|
||||||
|
... on StateOfApplicability {
|
||||||
|
id
|
||||||
|
name
|
||||||
|
owner {
|
||||||
|
... on PeopleProfile {
|
||||||
|
id
|
||||||
|
fullName
|
||||||
|
}
|
||||||
|
}
|
||||||
|
createdAt
|
||||||
|
updatedAt
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
type viewResponse struct {
|
||||||
|
Node *struct {
|
||||||
|
Typename string `json:"__typename"`
|
||||||
|
ID string `json:"id"`
|
||||||
|
Name string `json:"name"`
|
||||||
|
Owner struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
FullName string `json:"fullName"`
|
||||||
|
} `json:"owner"`
|
||||||
|
CreatedAt string `json:"createdAt"`
|
||||||
|
UpdatedAt string `json:"updatedAt"`
|
||||||
|
} `json:"node"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewCmdView(f *cmdutil.Factory) *cobra.Command {
|
||||||
|
var flagOutput *string
|
||||||
|
|
||||||
|
cmd := &cobra.Command{
|
||||||
|
Use: "view <id>",
|
||||||
|
Short: "View a statement of applicability",
|
||||||
|
Args: cobra.ExactArgs(1),
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
if err := cmdutil.ValidateOutputFlag(flagOutput); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
cfg, err := f.Config()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
host, hc, err := cfg.DefaultHost()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
client := api.NewClient(
|
||||||
|
host,
|
||||||
|
hc.Token,
|
||||||
|
"/api/console/v1/graphql",
|
||||||
|
cfg.HTTPTimeoutDuration(),
|
||||||
|
)
|
||||||
|
|
||||||
|
data, err := client.Do(
|
||||||
|
viewQuery,
|
||||||
|
map[string]any{"id": args[0]},
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
var resp viewResponse
|
||||||
|
if err := json.Unmarshal(data, &resp); err != nil {
|
||||||
|
return fmt.Errorf("cannot parse response: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if resp.Node == nil {
|
||||||
|
return fmt.Errorf("statement of applicability %s not found", args[0])
|
||||||
|
}
|
||||||
|
|
||||||
|
if resp.Node.Typename != "StateOfApplicability" {
|
||||||
|
return fmt.Errorf("expected StateOfApplicability node, got %s", resp.Node.Typename)
|
||||||
|
}
|
||||||
|
|
||||||
|
if *flagOutput == cmdutil.OutputJSON {
|
||||||
|
return cmdutil.PrintJSON(f.IOStreams.Out, resp.Node)
|
||||||
|
}
|
||||||
|
|
||||||
|
s := resp.Node
|
||||||
|
out := f.IOStreams.Out
|
||||||
|
|
||||||
|
bold := lipgloss.NewStyle().Bold(true)
|
||||||
|
label := lipgloss.NewStyle().Foreground(lipgloss.Color("242")).Width(22)
|
||||||
|
|
||||||
|
_, _ = fmt.Fprintf(out, "%s\n\n", bold.Render(s.Name))
|
||||||
|
|
||||||
|
_, _ = fmt.Fprintf(out, "%s%s\n", label.Render("ID:"), s.ID)
|
||||||
|
|
||||||
|
if s.Owner.FullName != "" {
|
||||||
|
_, _ = fmt.Fprintf(out, "%s%s (%s)\n", label.Render("Owner:"), s.Owner.FullName, s.Owner.ID)
|
||||||
|
}
|
||||||
|
|
||||||
|
_, _ = fmt.Fprintln(out)
|
||||||
|
_, _ = fmt.Fprintf(out, "%s%s\n", label.Render("Created:"), cmdutil.FormatTime(s.CreatedAt))
|
||||||
|
_, _ = fmt.Fprintf(out, "%s%s\n", label.Render("Updated:"), cmdutil.FormatTime(s.UpdatedAt))
|
||||||
|
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
flagOutput = cmdutil.AddOutputFlag(cmd)
|
||||||
|
|
||||||
|
return cmd
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user