// Copyright (c) 2026 Probo Inc . // // Permission is hereby granted, free of charge, to any person obtaining a copy // of this software and associated documentation files (the "Software"), to deal // in the Software without restriction, including without limitation the rights // to use, copy, modify, merge, publish, distribute, sublicense, and/or sell // copies of the Software, and to permit persons to whom the Software is // furnished to do so, subject to the following conditions: // // The above copyright notice and this permission notice shall be included in // all copies or substantial portions of the Software. // // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, // OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE // SOFTWARE. package decideall import ( "encoding/json" "fmt" "github.com/spf13/cobra" "go.probo.inc/probo/pkg/cli/api" "go.probo.inc/probo/pkg/cmd/cmdutil" ) const decideAllMutation = ` mutation($input: RecordAccessReviewEntryDecisionsInput!) { recordAccessReviewEntryDecisions(input: $input) { accessReviewEntries { id email decision } } } ` type decideAllResponse struct { RecordAccessReviewEntryDecisions struct { AccessReviewEntries []struct { ID string `json:"id"` Email string `json:"email"` Decision string `json:"decision"` } `json:"accessReviewEntries"` } `json:"recordAccessReviewEntryDecisions"` } func NewCmdDecideAll(f *cmdutil.Factory) *cobra.Command { var ( flagEntryIDs []string flagDecision string flagNote string flagOutput *string ) cmd := &cobra.Command{ Use: "decide-all", Short: "Record decisions on multiple access entries", Args: cobra.NoArgs, Example: ` # Approve multiple entries prb access-review entry decide-all --entry-id --entry-id --decision APPROVED # Revoke multiple entries with a note prb access-review entry decide-all --entry-id --entry-id --decision REVOKE --note "Batch cleanup"`, RunE: func(cmd *cobra.Command, args []string) error { if err := cmdutil.ValidateOutputFlag(flagOutput); err != nil { return err } if err := cmdutil.ValidateEnum( "decision", flagDecision, []string{"APPROVED", "REVOKE", "DEFER", "ESCALATE"}, ); err != nil { return err } cfg, err := f.Config() if err != nil { return err } host, hc, err := cfg.DefaultHost() if err != nil { return err } client := api.NewClient( host, hc.Token, "/api/console/v1/graphql", cfg.HTTPTimeoutDuration(), cmdutil.TokenRefreshOption(cfg, host, hc), ) decisions := make([]map[string]any, len(flagEntryIDs)) for i, id := range flagEntryIDs { d := map[string]any{ "accessReviewEntryId": id, "decision": flagDecision, } if flagNote != "" { d["decisionNote"] = flagNote } decisions[i] = d } data, err := client.Do( decideAllMutation, map[string]any{"input": map[string]any{"decisions": decisions}}, ) if err != nil { return err } var resp decideAllResponse if err := json.Unmarshal(data, &resp); err != nil { return fmt.Errorf("cannot parse response: %w", err) } entries := resp.RecordAccessReviewEntryDecisions.AccessReviewEntries if *flagOutput == cmdutil.OutputJSON { return cmdutil.PrintJSON(f.IOStreams.Out, entries) } for _, e := range entries { _, _ = fmt.Fprintf( f.IOStreams.Out, "Recorded decision %s on entry %s\n", e.Decision, e.ID, ) } return nil }, } cmd.Flags().StringSliceVar( &flagEntryIDs, "entry-id", nil, "Access entry IDs (can be repeated)", ) _ = cmd.MarkFlagRequired("entry-id") cmd.Flags().StringVar( &flagDecision, "decision", "", "Decision to record (APPROVED, REVOKE, DEFER, ESCALATE)", ) _ = cmd.MarkFlagRequired("decision") cmd.Flags().StringVar(&flagNote, "note", "", "Decision note (applied to all entries)") flagOutput = cmdutil.AddOutputFlag(cmd) return cmd }