Ludovic Vielle
eccef41767
Adopt File type for trust logos and MCP
...
Trust GraphQL and MCP still exposed presigned URL strings for
trust-center logos while console and connect already serve stable
File.downloadUrl paths. Phase 1 migrates the seven public logo
fields on trust GraphQL and the trust-center file references on MCP
to the shared File type; trust GraphQL NDA stays on fileUrl for a
follow-up.
Trust resolvers load public files through filemanager and map them
with types.NewFile. The trust app Relay queries and components now
read logo.downloadUrl. MCP specification, resolvers, and helpers
are updated in sync, including NDA on MCP where callers already
have file access.
filemanager is split into focused files and its URL surface is
narrowed to GenerateFileURL(file) for stable app URLs and
GeneratePresignedURL for S3 redirects. GetPublicFile remains the
DB entry point when only a file ID is known.
Add trust and MCP e2e coverage for public logo download URLs.
Signed-off-by: Ludovic Vielle <ludovic@probo.com >
2026-06-11 16:03:45 +02:00
Sacha Al Himdani
9ac71f948f
Update contact email to hello@probo.com
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-06-09 16:45:23 +02:00
Bryan Frimin
3e4a9be7c0
Remove tenant service pattern
...
Signed-off-by: Bryan Frimin <bryan@probo.com >
2026-05-20 16:51:15 -07:00
Émile Ré
9156d6a16a
Add wsl linter and fix
...
Signed-off-by: Émile Ré <emile@probo.com >
2026-05-20 09:27:28 +04:00
Sacha Al Himdani
6baa111fed
Fix chi middleware panic in trust API mux
...
The session-transfer route was registered before the session and member
provisioning middlewares, causing chi to panic with "all middlewares must
be defined before routes on a mux". Scope the middlewares to the graphql
route using r.Group so session-transfer remains unauthenticated.
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-31 16:35:47 +02:00
Bryan Frimin
8095ac6233
Validate session transfer redirect with saferedirect
...
The session transfer handler was blindly redirecting to the continue URL
from the signed token. Use saferedirect with a trust center domain check
to prevent open redirects, and only trigger session transfer for known
trust center custom domains instead of any non-base-URL host.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-31 14:49:21 +02:00
Bryan Frimin
84a35c90e9
Add session transfer for SSO cookies on custom domains
...
After OIDC login, if the redirect targets a trust center custom
domain, the callback now redirects through a session-transfer
endpoint on that domain. The endpoint verifies an HMAC-signed,
time-limited token and sets the session cookie on the custom
domain before redirecting to the final URL.
The continue URL is bound into the signed token payload to
prevent open-redirect attacks via parameter tampering.
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-31 14:49:20 +02:00
Sacha Al Himdani
8c02c53315
Update copyright headers across all Go files
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-25 17:38:32 +01:00
Bryan Frimin
ef76a8d2e1
Remove deadcode
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-03-13 17:18:02 +01:00
Émile Ré
6ad808c966
Move and rename EnsureAccess method in trust.Service
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-03-13 16:58:10 +04:00
Émile Ré
ea8253ea78
Add membership provisioning middleware to compliance page
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-03-13 16:58:10 +04:00
Sacha Al Himdani
85ec106cd6
Send mailing list emails
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-11 15:34:37 +01:00
Sacha Al Himdani
aa01c40184
Remove with tenant from mailman
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-11 15:34:36 +01:00
Sacha Al Himdani
4d2cb793b6
Add compliance page mailing list base
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2026-03-11 15:34:36 +01:00
Émile Ré
323cd602a1
Update business logic
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-03-05 10:36:08 +04:00
Émile Ré
c4b06ddc7d
Add compliange page base URL in context and use it to validate redirect URLs
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-03-03 22:07:01 +04:00
Émile Ré
823fc64c37
Implement nda check as a directive
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-03-03 22:07:01 +04:00
Émile Ré
9da8cc2e3d
Add nda signature middleware
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-03-03 22:07:01 +04:00
Émile Ré
316e81f938
Implement continue on verify magic link
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-03-03 22:07:00 +04:00
Bryan Frimin
c191d25e9a
Add electronic signature
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-02-23 09:38:27 +01:00
Émile Ré
7cc1144192
Put backn membership middleware
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-17 12:35:47 -08:00
Émile Ré
a6826826b0
Remove unused code
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-17 12:34:25 -08:00
Émile Ré
44d85a2b12
Trust center access management - get rid of access token
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-17 12:34:24 -08:00
Émile Ré
8b3bda56e6
Add magic link login for trust center
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-17 12:34:24 -08:00
Bryan Frimin
8ff4693bfc
Use session instead of mustBeAuthenticated
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-01-17 12:34:24 -08:00
Émile Ré
e220c259b3
Use trust center from context
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-17 12:34:23 -08:00
Émile Ré
7322201dab
Plug trust center part 1
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-17 12:34:23 -08:00
Émile Ré
1257347df9
Extract authn & authz utils
...
Signed-off-by: Émile Ré <emile@getprobo.com >
2026-01-17 12:34:03 -08:00
Bryan Frimin
74fc3b8cd1
Rewrite identity and access management
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2026-01-17 10:07:34 -08:00
Émile Ré
d702c4b7c6
Use gqlgen via tool and update generated code
...
Signed-off-by: Émile Ré <nemile.re@gmail.com >
2025-12-16 12:45:25 +01:00
manish-singh-bisht
8eeab0a6d0
feat:pull the slack message service out to slack pkg
...
Signed-off-by: manish-singh-bisht <mthefool218@gmail.com >
2025-12-11 18:42:26 +01:00
Sacha Al Himdani
fee5a9232e
Make secure cookie configurable
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-11-04 17:09:51 +01:00
Sacha Al Himdani
5212d0c18f
Add api keys
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-11-04 13:37:31 +01:00
Bryan Frimin
59aa332ab5
Move to vanity import url
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2025-10-31 17:01:52 +01:00
Bryan Frimin
6f2bd9c92f
Fix failed to to cannot
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2025-10-30 16:38:08 +01:00
Sacha Al Himdani
0073846d3b
Add interactif slack message
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-10-23 15:10:55 +02:00
Bryan Frimin
0f96b8518f
Refactoring of authentification
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2025-10-14 16:32:22 +02:00
Bryan Frimin
e109cb602e
Add graphql log
...
Signed-off-by: Bryan Frimin <bryan@getprobo.com >
2025-10-11 23:14:45 +02:00
Sacha Al Himdani
b06bd113f3
Add nda to trust center
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-09-15 16:53:51 +02:00
Sacha Al Himdani
5db9b9f787
Add trust center access requests
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-22 11:04:48 +02:00
Sacha Al Himdani
e0ad0fc4f2
Use configuration for report url duration
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:44 +02:00
Sacha Al Himdani
58ea075f0f
Check if token still exist for trust center access
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:44 +02:00
Sacha Al Himdani
330ba0c18a
Refacto session cookie handling
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:44 +02:00
Sacha Al Himdani
05123185e3
Refacto graphql recovery
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:44 +02:00
Sacha Al Himdani
4ff71312f9
Split Config
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:43 +02:00
Sacha Al Himdani
92e2e9a48a
Clean trust api
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:43 +02:00
Sacha Al Himdani
2355a69f6d
Clean access priority
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:43 +02:00
Sacha Al Himdani
5fb0b9cffc
Clean trust center access
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:43 +02:00
Sacha Al Himdani
032fd14135
Change trust authentification endpoints
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:43 +02:00
Sacha Al Himdani
994ec7b67f
Change Authentification
...
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com >
2025-08-06 16:34:43 +02:00