Commit Graph

3738 Commits

Author SHA1 Message Date
Bryan Frimin
d92632933b Fix bootstrap YAML round-trip tests
Replace gopkg.in/yaml.v3 with sigs.k8s.io/yaml in write_test.go to match
the marshaling library used by WriteConfig. The sigs.k8s.io/yaml library
uses JSON struct tags, enabling proper round-trip serialization of configs
with custom unmarshaling logic like ConnectorConfig.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-18 15:35:01 +01:00
Bryan Frimin
7895dd32b0 Fix logging format string bugs and add missing contributor guides
Replace three instances of leftover %T format verbs in logger.ErrorCtx() calls with proper structured logging fields. Add alphabetically-sorted reference documentation for six new contrib/claude/ guides and reorder the existing list.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-18 15:09:31 +01:00
Bryan Frimin
2f6574ee49 Update package-lock.json
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-18 15:06:38 +01:00
Bryan Frimin
312e30d9e4 Add sandbox-specific probod config generation
Add a make target for probod-bootstrap and integrate it into the sandbox provisioning workflow. During VM provisioning, generate /etc/probod/config.yml with the Lima VM IP as the cookie domain, secure=false for HTTP access, and correct CORS origins. Also generate .env files for console and trust apps pointing to the VM IP. Update sandbox documentation to explain the auto-generated configuration.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-18 15:06:37 +01:00
Sacha Al Himdani
6c9b338ad5 Deprecate useMutationWithToasts and promisifyMutation
Update relay agent rules to mark both helpers as deprecated.
Replace examples with the preferred pattern: useMutation with
onCompleted/onError callbacks and useToast.

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-03-17 17:51:55 +01:00
Sacha Al Himdani
73d5dbb5db Replace panic calls with proper error handling in resolvers
All panic(fmt.Errorf(...)) calls in the console and trust center
GraphQL resolvers are replaced with structured error logging via
r.logger.ErrorCtx and gqlutils.Internal(ctx) returns.

Mutation resolvers for Create, Update, Upload, Import, and Assess
operations now check for validator.ValidationErrors before returning
an internal error, surfacing field-level INVALID errors to clients
via gqlutils.InvalidValidationErrors.

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-03-17 16:15:51 +01:00
Sacha Al Himdani
16b966b8fb Fix multiline function call style violations
Expand mixed inline/multiline function calls so each argument
is on its own line, matching the one-argument-per-line rule.

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-03-17 15:59:26 +01:00
Sacha Al Himdani
532347fcda Add commit signing and authorship rules
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-03-17 15:39:50 +01:00
Bryan Frimin
52b4951507 Hide audit report buttons when no file attached
When an audit has no report attached, neither the View nor Request access button should be displayed. Updated the conditional rendering to wrap the entire button section with the audit.report check instead of only checking it in the nested ternary.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:20:04 +01:00
Bryan Frimin
91a06d1fb5 Use logger + gqlutils.Internal pattern instead of panic for NDA errors
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:19:23 +01:00
Bryan Frimin
6770fb7e1f Fix NDA file display on page reload
The Organization.TrustCenter and Node resolvers were not loading the NDA file from the database, causing ndaFileName to be null on page reload even though the file was uploaded. Now the resolvers fetch the file when NonDisclosureAgreementFileID is set.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:19:21 +01:00
Bryan Frimin
c8df8b0c87 Update TS types for nullable audit framework
The console GraphQL schema made Audit.framework nullable which
requires updating the TrustCenterDocumentAccess type and its
helper to handle the optional framework field.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:33 +01:00
Bryan Frimin
a82e353a47 Update shared helpers for findings
Add new finding statuses (RISK_ACCEPTED, MITIGATED, FALSE_POSITIVE)
to the registry status helper. Update snapshot type references to
use FINDINGS instead of NONCONFORMITIES and CONTINUAL_IMPROVEMENTS.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:33 +01:00
Bryan Frimin
fde65eb10b Add finding e2e tests
Add comprehensive end-to-end tests for the finding GraphQL API
covering CRUD operations, audit linking/unlinking, filtering by
kind/status/priority, pagination, and ordering.

Remove the old nonconformity and continual improvement e2e tests.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:33 +01:00
Bryan Frimin
0e0539f1f3 Replace console frontend with unified findings pages
Add FindingsPage, FindingDetailsPage, and CreateFindingDialog
supporting all finding kinds (nonconformity, observation, exception)
with filtering, sorting, and audit linking.

Remove the separate nonconformity and continual improvement pages,
routes, and graph hooks. Update sidebar navigation, routes, and
components for nullable audit framework field.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:33 +01:00
Bryan Frimin
ad0cf38e76 Add finding CLI commands
Add prb finding subcommands: create, list, view, update, and delete.
Register the finding command group in the root command and update
the factory to expose FindingService.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:32 +01:00
Bryan Frimin
69ab9c60cd Add finding MCP API
Replace nonconformity and continual improvement MCP tools with
unified finding tools: list_findings, get_finding, create_finding,
update_finding, delete_finding, link_finding_to_audit, and
unlink_finding_from_audit.

Update specification and resolvers to use the new finding types.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:32 +01:00
Bryan Frimin
0ab88a9bbc Add finding console GraphQL API
Replace nonconformity and continual improvement GraphQL types with a
unified Finding type supporting kind, status, priority, and audit
associations. Update schema, resolver, and type mappings.

Add mutations for createFinding, updateFinding, deleteFinding,
linkFindingToAudit, and unlinkFindingFromAudit.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:32 +01:00
Bryan Frimin
123e5c36b7 Add finding service layer
Introduce FindingService with create, update, delete, get, and list
operations including audit association management. Update the probo
service orchestration, actions, and policies to use findings.

Remove the old NonconformityService and ContinualImprovementService.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:31 +01:00
Bryan Frimin
bf276cd3db Add finding coredata types and queries
Introduce the Finding, FindingAudit, FindingKind, FindingStatus,
FindingPriority, FindingFilter, and FindingOrderField types in the
coredata layer. Add CRUD operations, list with filtering/pagination,
and audit association queries.

Remove the now-replaced nonconformity and continual_improvement
coredata types. Update entity type registry and snapshot types
to reference the new findings type.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:31 +01:00
Bryan Frimin
736436e997 Add database migration to merge findings
Merge nonconformities and continual_improvements tables into a
unified findings table with kind (NONCONFORMITY, OBSERVATION,
EXCEPTION), status, and priority enums. Create findings_audits
junction table for the many-to-many audit relationship.

The migration generates new FND-XXX reference IDs per organization,
migrates both live and snapshot records preserving source_id links,
and carries over audit associations to the junction table.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 15:05:30 +01:00
Bryan Frimin
72d2f85ed2 Hide meetings menu from auditors
Auditors should not see the meetings menu in the navigation bar since they lack the necessary permissions to access meetings.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 14:32:18 +01:00
Sacha Al Himdani
5e3cb79550 Release v0.144.0
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-03-17 14:14:53 +01:00
Sacha Al Himdani
cf1dadc0b5 Add implemented state and justification to controls
Introduce `implemented` enum (IMPLEMENTED/NOT_IMPLEMENTED) and
`not_implemented_justification` (nullable text) fields on the Control
entity across all API surfaces (GraphQL, MCP, CLI), database, frontend,
and SOA export.

The database stores implementation state as a PostgreSQL enum
`control_implementation_state`. Controls default to IMPLEMENTED during
migration. The SOA list and PDF export show implementation status
alongside applicability, with "-" for non-applicable controls.
Justification columns are renamed for clarity: "Justification for
non-applicability" and "Justification for non-implementation".

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-03-17 11:01:04 +01:00
Bryan Frimin
d8670d2412 Add Lima sandbox environment for parallel feature testing
Implement a complete sandbox system for testing multiple features in parallel
using git worktrees and Lima VMs. Each worktree gets its own isolated VM with
Docker, full service stack, and unique IP via vzNAT networking.

- contrib/lima/provision.sh: Idempotent provisioning script (Docker, Go 1.26.1, Node.js 24, npm 11.8.0, Go tools, mkcert)
- contrib/lima/probo.yaml: Lima VM template with vz vmType, Rosetta, vzNAT, virtiofs mount
- contrib/lima/sandbox.sh: Lifecycle CLI (create, start, stop, restart, delete, ssh, exec, status, list)
- contrib/lima/README.md: Human documentation with prerequisites, quickstart, troubleshooting
- contrib/claude/sandbox.md: Agent reference doc for sandbox usage patterns
- GNUmakefile: Convenience targets for sandbox.sh commands
- AGENTS.md: Updated reference documentation index

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 08:52:33 +01:00
Bryan Frimin
cb659411ba Add release guide documentation
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 08:52:32 +01:00
Bryan Frimin
3a38930628 Add seed script to populate dev environment with realistic compliance data
Validate GraphQL mutation responses in create_vendor, create_measure, and
create_framework helpers to ensure mutations actually returned data instead
of silently discarding the response.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 08:50:48 +01:00
Bryan Frimin
8819b69d2d Support http:// hosts in CLI client for local development
The CLI client was hardcoding https:// scheme, which prevents local dev with http://localhost. Add support for bare hostnames (auto-prepend https) while preserving http:// and https:// prefixes when explicitly provided.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 08:50:48 +01:00
Bryan Frimin
46635e7f04 Add Lima sandbox environment for parallel feature testing
Implement a complete sandbox system for testing multiple features in parallel
using git worktrees and Lima VMs. Each worktree gets its own isolated VM with
Docker, full service stack, and unique IP via vzNAT networking.

- contrib/lima/provision.sh: Idempotent provisioning script (Docker, Go 1.26.1, Node.js 24, npm 11.8.0, Go tools, mkcert)
- contrib/lima/probo.yaml: Lima VM template with vz vmType, Rosetta, vzNAT, virtiofs mount
- contrib/lima/sandbox.sh: Lifecycle CLI (create, start, stop, restart, delete, ssh, exec, status, list)
- contrib/lima/README.md: Human documentation with prerequisites, quickstart, troubleshooting
- contrib/claude/sandbox.md: Agent reference doc for sandbox usage patterns
- GNUmakefile: Convenience targets for sandbox.sh commands
- AGENTS.md: Updated reference documentation index

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-17 08:46:48 +01:00
Bryan Frimin
2a0cdc841c Add FreeBSD and OpenBSD support to release builds
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 23:52:11 +01:00
Bryan Frimin
7ffb2d5e94 Add document viewer with proper 404 handling for trust center
Move document download/view to a dedicated viewer page with PDF preview,
access request flow, and a proper 404 error boundary when documents are
not found. The backend now returns NOT_FOUND instead of INTERNAL for
missing documents and reports.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 19:13:21 +01:00
Sacha Al Himdani
dc8e6d0817 Add validation to mailman service
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-03-16 17:46:32 +01:00
Bryan Frimin
7ed9c6c2e6 Add go fmt and go fix checks to lint
Adds go-fmt and go-fix Makefile targets that fail when gofmt or go fix
suggest changes. Both are wired into the lint target and used in CI.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 17:32:25 +01:00
Bryan Frimin
364c193d33 Style
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 17:19:02 +01:00
Bryan Frimin
842bbfbe97 Style
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 16:54:48 +01:00
Sacha Al Himdani
5864719a3f Release v0.143.0
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-03-16 16:32:44 +01:00
Bryan Frimin
807213d384 Stop tracking generated files
Run make generate in CI lint and test jobs since generated files are
now gitignored. Also include Relay codegen for frontend apps in the
generate target.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 16:19:47 +01:00
Bryan Frimin
3e3138f764 Cache Go modules explicitly with go mod download
Add go mod download step after setup-go in all CI jobs to ensure the
module cache is populated as a discrete step. This makes cache hits visible
in logs and prevents module downloads from being interleaved with build
operations, improving cache effectiveness.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:54:54 +01:00
Bryan Frimin
7e86d2c89f Rename proboctl CLI binary to prb
Shorter CLI name for faster typing. Renames the binary, build targets,
goreleaser config, command examples, and documentation.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:51 +01:00
Bryan Frimin
1f1df63676 Add proboctl CLI AGENTS.md
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:51 +01:00
Bryan Frimin
779f549530 Fix missing __typename checks and standalone var declarations
Add __typename to GraphQL queries and type guards in risk view,
risk list, user view, and user list commands to prevent silent
garbage output when a wrong node type ID is passed. Wrap
standalone var declarations in var () blocks per style guide.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:50 +01:00
Bryan Frimin
0438b8457d Clear active host on logout
When logging out of the active host while other hosts exist,
the stale ActiveHost reference caused DefaultHost() to silently
fall through to the first alphabetical host instead of treating
the user as logged out.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:50 +01:00
Bryan Frimin
a8ac1fa2a1 Add proboctl webhook commands
Add CRUD commands for webhook subscriptions and a command
to list webhook events.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:50 +01:00
Bryan Frimin
f1a028c4f1 Add proboctl statement of applicability commands
Add CRUD commands for statements of applicability and their
applicability statements (add, list, remove, update).

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:50 +01:00
Bryan Frimin
04cb9e08fb Add proboctl framework and control commands
Add create, list, view, update, and delete commands
for managing frameworks and controls.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:49 +01:00
Bryan Frimin
5a230278b2 Add proboctl risk commands
Add create, list, view, update, and delete commands
for managing risks.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:49 +01:00
Bryan Frimin
b313fbb951 Add proboctl org and user commands
Add organization list and user list/view commands.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:49 +01:00
Bryan Frimin
72c15b2a17 Add proboctl browse command
Add a command to open Probo resources in the web browser.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:49 +01:00
Bryan Frimin
94673d4ee2 Add proboctl config commands
Add get, set, and list commands for managing CLI
configuration values.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:48 +01:00
Bryan Frimin
907ba623e8 Add proboctl api command
Add a raw API command for executing GraphQL queries
directly against the Probo API.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2026-03-16 15:41:48 +01:00