Commit Graph

4811 Commits

Author SHA1 Message Date
Bryan Frimin
be56399069 Add setAlias and removeAlias operations to n8n trust center node
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:50 +02:00
Bryan Frimin
e2219c9d1a Normalize required fields in agent JSON schemas for OpenAI
OpenAI rejects schemas where optional properties are absent from the
required array. Promote all properties to required and mark formerly
optional ones nullable so the model knows it may pass null.

Also upgrade tool error log level from Warn to Error.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:50 +02:00
Bryan Frimin
982509416e Add trust-center alias CLI subcommand
Provides set and remove subcommands for managing trust center aliases
from the command line.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:50 +02:00
Bryan Frimin
a11fdc9520 Add setTrustCenterAlias and removeTrustCenterAlias MCP tools
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:49 +02:00
Bryan Frimin
02153ca0dc Add alias fields and alias-based node resolution in trust API
Node lookup now accepts an alias slug in addition to a GID, resolving
it against the organization's alias table before dispatching. Adds
alias fields to Document, AuditReport, and TrustCenterFile.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:49 +02:00
Bryan Frimin
c50aa28364 Expose alias field and set/remove mutations in console API
Adds an alias field to Document, Audit, and TrustCenterFile types.
Introduces setTrustCenterAlias and removeTrustCenterAlias mutations
with proper authorization and error handling.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:49 +02:00
Bryan Frimin
325465ab41 Add trust center alias service and integrate into sitemap
The sitemap now covers files and audit reports alongside documents
and resolves aliases so human-readable paths appear when configured.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:48 +02:00
Bryan Frimin
dbf022f772 Add TrustCenterAlias application service
Exposes Create, Remove, GetByResourceID, and LoadByResourceIDs.
Registers ActionTrustCenterAliasSet and ActionTrustCenterAliasRemove
under the trust center write OAuth2 scope.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:48 +02:00
Bryan Frimin
95a5227fcb Add TrustCenterAlias coredata layer
Supports upsert, load by alias, load by resource ID, bulk load by
resource IDs, and delete operations.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:48 +02:00
Bryan Frimin
ac5ee73997 Add trust_center_aliases table migration
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-22 11:38:48 +02:00
Ludovic Vielle
c93932f026 Introduce oauth2scope registry with freeze lifecycle
Replace pkg/iam/scopeset with pkg/iam/oauth2scope.Registry, a shared
OAuth2 scope→action registry used by the authorizer, OAuth2 service,
and Connect API. Registration stays open until probod calls Freeze();
read paths (RegisteredScopes, Allows, ValidateScopes) panic before
that.

Drop the leaky APIScopes surface and AllowedAPIScopes on manual
access-token creation in favor of registry.ValidateScopes. Metadata,
protected-resource metadata, and CIMD scope lists are built from
RegisteredScopes() via helpers in pkg/iam/oauth2/scopes.go. Expose
oauth2ScopesSupported as an OAuth2Scope GraphQL scalar.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-22 11:22:19 +02:00
Bryan Frimin
0d33750735 Style
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-19 18:53:39 +02:00
Bryan Frimin
c24e7f7ae8 Release probod/v0.216.1 2026-06-19 18:50:55 +02:00
Bryan Frimin
9fd95a0bf9 Fix missing cmid scope
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-19 18:49:33 +02:00
Bryan Frimin
8add4713c8 Release helm/v0.8.0
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-19 17:28:41 +02:00
Bryan Frimin
5d37d9899c Release probod/v0.216.0
Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-19 17:27:19 +02:00
Bryan Frimin
d7e23fd890 Harden CIMD client resolution and caching
Tighten redirect URI validation for metadata documents, honor
Cache-Control no-store when caching fetched documents, and resolve
clients on the same transaction as authorization. Load
external_client_id from the database and parse unbounded max-stale
directives in cachecontrol.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-19 17:13:39 +02:00
Bryan Frimin
5b0d3e5052 Add OAuth2 Client ID Metadata Document support
MCP connectors such as ChatGPT and Claude register via HTTPS
client_id URLs instead of pre-provisioned GIDs. Fetch and cache
their metadata documents, upsert clients on first use, and
advertise CIMD in OIDC discovery when allowed URLs are configured.

Signed-off-by: Bryan Frimin <bryan@probo.com>
2026-06-19 17:13:37 +02:00
Émile Ré
9e6f1b9e8f Release @probo/n8n-nodes-probo/v0.196.0 2026-06-19 17:12:45 +02:00
Émile Ré
d4b0040e95 Release probod/v0.215.1 2026-06-19 17:12:27 +02:00
Émile Ré
4d28dab2f4 Centralize ESLint into a single root config
Replace the duplicated per-workspace eslint.config.mjs files in
apps/console, apps/trust, packages/ui, and packages/eslint-config with
one root eslint.config.mjs that reuses the shared @probo/eslint-config
rule sets and scopes them per directory. Linting now runs from the repo
root, so pin the type-checked project service root and broaden the
import-x resolver to every workspace tsconfig (the #/* aliases live in
each app's tsconfig.app.json).

Drop the now-redundant per-package lint scripts and lint-only devDeps,
and add a root lint script that runs eslint over the four dirs with
multithreading restored via --concurrency auto, then lints n8n-node
through a direct workspace call. packages/n8n-node keeps its own
external preset.

Collapse the redundant lint-js -> npm-lint Makefile chain into a single
lint-js target and update the make docs accordingly.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 16:47:43 +02:00
Émile Ré
652be7a984 Stop sibling re-enqueue from flooding mapping logs
The tracker-mapping worker re-arms same-banner siblings after a pattern
resolves a vendor. Its predicate only excluded promoted siblings
(third_party_id IS NULL), but since org-party auto-creation was dropped a
pattern can resolve a common third party yet never gain an org
third_party_id. Those siblings, and terminal first-party ones, stayed
eligible forever, so every cascade step re-enqueued and reprocessed them,
amplifying Process runs to O(N^2) per banner. The deadlock fix in the
last release removed the rollbacks that had accidentally throttled the
cascade, so the latent amplification surfaced as an INFO-log flood.

Tighten the re-enqueue to skip siblings already linked to a catalog row
that carries a common third party or marked FIRST_PARTY, dropping
per-banner reprocessing back to O(N). Also demote the two per-run handler
logs ("mapped tracker pattern", "re-enqueued unmapped sibling tracker
patterns") to Debug so routine processing no longer logs at INFO.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 16:31:58 +02:00
Émile Ré
01bdccaf2a Release @probo/cookie-banner/v0.10.0
Signed-off-by: Émile Ré <emile@getprobo.com>
2026-06-19 15:25:48 +02:00
Émile Ré
ff5e0d8706 Release proboctl/v0.7.0
Signed-off-by: Émile Ré <emile@getprobo.com>
2026-06-19 15:24:38 +02:00
Émile Ré
42ddefc261 Release probod/v0.215.0
Signed-off-by: Émile Ré <emile@getprobo.com>
2026-06-19 15:19:31 +02:00
Émile Ré
4433e0a9d0 Restore GraphQL schema merge for Relay query text
relay-compiler requires a single schema file: a directory is rejected
and schemaExtensions marks fields as client-only, so it emitted
text: null and the console posted query: null, getting a 400 on every
operation.

Restore the merge step (contrib/merge-graphql-schema.sh, the
RELAY_SCHEMAS make rules, and the gitignore entry) and point each
relay.config.json project back at the merged schema.graphql. The IDE
graphql-config removal and npm-script cleanup are unrelated and stay.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 14:57:28 +02:00
Émile Ré
4348c409a1 Fix lint findings on upgraded console pages
Wrap the usePreloadedQuery calls whose explicit type arguments pushed
them past the 120-character limit, and merge the two duplicate
@probo/helpers imports in FrameworkControlPage into one. These were
flagged by reviewdog on the dependency-upgrade PR.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 14:31:30 +02:00
Émile Ré
abb641111a Fix rela type issue
Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 14:27:25 +02:00
Émile Ré
7e943c8105 Drop merged GraphQL schema for split files
Relay no longer needs a single merged schema.graphql: each project in
relay.config.json now reads the split graphql/*.graphql files directly
via `schema` (base.graphql) plus `schemaExtensions`. gqlgen already
consumed the split files, so the merge step only fed Relay and the
optional IDE GraphQL extension.

Remove the merge machinery (contrib/merge-graphql-schema.sh, the
RELAY_SCHEMAS make rules, and the gitignore entry) and drop the
graphql-config files (apps/trust/graphql.config.yml and the root
package.json graphql field); the Relay extension provides schema-aware
language features from relay.config.json on its own.

relay-compiler keeps generated artifacts in sync (stale ones are
removed automatically), so the relay npm script just runs the local
relay-compiler and the make target delegates to it.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 13:51:17 +02:00
Émile Ré
89427845c4 Fix type-aware lint errors on OAuth tokens page
The linter's project service ignores the generated Relay artifacts,
so the untyped usePreloadedQuery call left viewer as an error type and
triggered no-unsafe-argument/member-access errors. Pass the explicit
query generic like the sibling audit-log page does.

Drop the redundant GraphQLError cast on the revoke error handler since
formatError already accepts the callback's error type.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 13:51:17 +02:00
Émile Ré
f98b73f073 Upgrade frontend toolchain to latest majors
Bump React 19.2, Relay 21, React Router 8, Vite 8 with
@vitejs/plugin-react 6, ESLint 10, GraphQL 17, TypeScript 6,
@types/node 24, and Tailwind 4.3 across the workspaces.

vite-plugin-react 6 (Vite 8) no longer runs Babel, so the Relay
tagged-template transform now runs through @rolldown/plugin-babel
in the console and trust Vite configs.

Relay 21 ships first-party types and enables the ambiguous-alias
check by default; disable that flag to preserve existing queries
and add explicit usePreloadedQuery type arguments where the new
types no longer infer the operation. TypeScript 6 deprecations and
stricter inference are addressed in tsconfigs and call sites.

Keep n8n-node on ESLint 9 and eslint-plugin-react on 7.37.5, the
newest releases compatible with their toolchains.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 13:51:17 +02:00
Émile Ré
f1fc2dc0e0 Show persistent for local-storage trackers
Local storage, IndexedDB, and cache storage have no expiry yet
persist until explicitly cleared, so a missing max-age should read
as "persistent", not "session" (the latter only fits cookies and
session storage, which end with the session or tab).

Thread the tracker type through humanizeSeconds (helpers) and
humanizeDuration (cookie-banner, with a localized persistent label)
and pass it at every console and banner call site. The consent
record query now selects trackerType so its duration column can
make the same distinction. This mirrors the Go HumanizedDuration
helper that already renders these types as persistent.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 10:46:44 +02:00
Émile Ré
a4cc82441a Fix deadlock in concurrent tracker mapping
The tracker-mapping worker runs many Process calls in parallel. In
Phase 4 a single transaction locked the worker's own claimed pattern
row via UpdateMapping and then locked sibling rows on the same banner
via the re-enqueue. Two workers mapping sibling patterns on one banner
each held their own row and waited on the other's, forming a lock cycle
that Postgres aborted with deadlock detected (40P01).

Split the sibling re-enqueue into its own short transaction that runs
after the mapping commits, so the claimed-row lock is released before
any sibling row is locked. Also take the sibling UPDATE row locks in a
deterministic id order through an ORDER BY id ... FOR UPDATE subquery,
so overlapping re-enqueues can no longer invert lock order between
themselves. The re-enqueue only flags siblings, so deferring it past
the commit is safe and lets reprocessed siblings observe committed data.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 10:46:44 +02:00
Émile Ré
4435a93eca Rank HTTP cookie source above pre-existing
The tracker-pattern source ranking collapsed HTTP into the PRE_EXISTING
tier, so a cookie first enumerated as pre-existing and later re-observed
only via a Set-Cookie response header stayed pre-existing. That left it
on the agent-skipped tier (isPreExistingSource), even though an HTTP
server-set cookie is real page evidence, not the extension-state
catch-all the skip was built to suppress.

Give HTTP its own rank between SCRIPT and EXTENSION
(SCRIPT > HTTP > EXTENSION > PRE_EXISTING) in both sourceRank and the
bestSource merge rollup, so an HTTP re-detection now promotes the
pattern and re-arms mapping, unblocking the identification agent.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 10:46:44 +02:00
Émile Ré
f56d3daa2c Make tracker pattern category editable on detail page
The category property on the tracker pattern detail page was
read-only text. Wire in the existing MoveToCategorySelect and the
moveTrackerPatternToCategory mutation so a pattern can be recategorized
directly from its detail view, matching the table-row behaviour.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 10:46:44 +02:00
Émile Ré
a2d3852fea Give unlink full parity with first-party cleanup
Unlinking previously cleared only the catalog vendor link, leaving the
stale description that still named the removed vendor and leaving the
linked org tracker patterns pointing at it. Because the verdict becomes
UNDETERMINED the pipeline is meant to re-probe the row, so the stale
state was misleading until that happened.

Clear the description on both the catalog row and its uncategorised org
tracker patterns, and remap those org patterns so they drop the stale
vendor and re-resolve. A re-resolved vendor re-arms catalog enrichment
via the blank-and-unlinked upsert path, re-deriving the description.
This mirrors the cleanup mark-first-party already performs, minus the
terminal verdict.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 10:46:44 +02:00
Émile Ré
265c56d00b Improve tracker source and first-party cleanup
Surface every CookieSource value in the console: the trackers page
filter was missing the HTTP option and the source badge helper had no
EXTENSION case, so HTTP-sourced rows could not be filtered and
extension-sourced rows rendered the raw enum string.

On the backend, the mark-first-party verdict now blanks the stale
description on both the catalog row and its uncategorised org tracker
patterns. A terminal non-third-party row keeps no vendor link, so a
description naming the (now-cleared) vendor would be misleading; the
mapping worker only copies descriptions into empty rows and never
clears them, so clearing is done explicitly here.

Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 10:46:43 +02:00
Émile Ré
3b777e985c Fix n8n and cookie-banner release workflow npm version
Signed-off-by: Émile Ré <emile@probo.com>
2026-06-19 10:39:52 +02:00
Ludovic Vielle
eb9cfc103a Release @probo/n8n-nodes-probo/v0.195.0
Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-19 10:27:52 +02:00
Ludovic Vielle
e79747a5f3 Release probod/v0.214.0
Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-19 10:27:27 +02:00
Ludovic Vielle
9e22f75442 Release prb/v0.196.0
Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-19 10:26:58 +02:00
Ludovic Vielle
6e6a093300 Add v1:iam:read scope to auditor mode
Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-19 10:05:20 +02:00
Ludovic Vielle
0256babc9d Accept OAuth access tokens on MCP API
Manual OAuth bearer tokens worked on Console and Connect but
were rejected by MCP, which only ran the personal API key
middleware. Align MCP with the shared bearer chain used
elsewhere: API key, OAuth access token, then identity
presence. Drop the local RequireAPIKeyHandler.

Add e2e coverage for MCP calls authenticated with a manual
OAuth token, including scope enforcement.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-19 09:34:19 +02:00
Sacha Al Himdani
fdf5188707 Skip notifications for inactive users
Signed-off-by: Sacha Al Himdani <sacha@probo.com>
2026-06-19 08:59:54 +02:00
Ludovic Vielle
fd2e0903ee Register API scopes on prb CLI OAuth client
Device logins only requested OIDC scopes while the authorizer now
gates API calls on v1:* scopes. Register the full scope set on the
well-known prb client, request it at login via CLIClientScopes, and
cover the device flow in e2e.

Collapse API scopes under an accordion on the consent screen and
document scope sync for future namespace additions.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-18 20:11:55 +02:00
Ludovic Vielle
26c5002932 Add identity-scoped OAuth token management
Let users create, list, and revoke manual bearer tokens from
/me/oauth-tokens, scoped to their identity rather than an
organization. Manual tokens store a null client_id and are
authorized with a self-manage IAM policy.

Wire Connect GraphQL on Identity (list, create, revoke), add
console UI with scoped create flow and credentials dialog, and
cover the flow in e2e tests. Fix list pagination ordering and
keep the Relay connection in sync after create.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-18 20:08:49 +02:00
Ludovic Vielle
e20f1de58a Backfill OAuth2 access token API scopes
OAuth grant tokens issued before API scope enforcement only stored
OIDC scopes. Set every existing iam_oauth2_access_tokens row to the
full supported scope set so bearer tokens keep working under the
OAuth2 scope gate.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-18 19:07:28 +02:00
Ludovic Vielle
3ebb221a9b Add OAuth2 API scope registration and enforcement
Register v1 API scopes in coredata, advertise them in OIDC discovery
and protected-resource metadata, show them on the consent screen, and
enforce scope-to-action mapping in the IAM Authorizer before policy
evaluation.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
2026-06-18 19:07:25 +02:00
Émile Ré
25151fa089 Release proboctl/v0.6.0 2026-06-18 17:49:39 +02:00
Émile Ré
8906140ab3 Release probod/v0.213.0 2026-06-18 17:49:32 +02:00