Files
probo/pkg/server/api/console/v1/graphql/risk.graphql
Sacha Al Himdani 553901e4ad Add risk publish to document system
Replace the old snapshot-based system for risks with the publish
document system, mirroring the prior vendor / processing activity / DPIA
/ TIA migration. Includes the GraphQL mutation, MCP tool, CLI command,
n8n operation, frontend publish dialog, e2e tests, and a prosemirror
register template covering name, description, category, treatment,
owner, inherent and residual scoring, and notes.

The risk register lives as a generated DocumentTypeRegister document on
the organization, reused across publishes (the major version bumps on
every republish). Approvers can be passed in to create a draft pending
approval; otherwise the version is published immediately. The frontend
Risks page exposes a Publish button and a Document link button when the
document exists, and pre-fills the previous default approvers.

Risks was the last remaining snapshot type, so this commit also removes
the entire snapshot system: drop snapshotId from the Risk GraphQL type
and RiskFilter; remove RiskSnapshotter, Risks.Snapshot,
InsertRiskSnapshots, and the SnapshotID/SourceID fields on Risk; delete
Snapshot, ControlSnapshot, SnapshotsType, SnapshotOrderField,
Snapshottable, the SnapshotService, the Snapshot console resolvers and
GraphQL schema, the Snapshot MCP types and operations
(list/get/take/listControlSnapshots), the snapshot CLI (prb snapshot),
the snapshot frontend pages, routes, banner, LinkedSnapshotsCard,
SnapshotGraph, snapshot helpers, and the snapshot n8n resource and
control link/unlink snapshot operations. The snapshot_id columns remain
in the database but are now filtered out with snapshot_id IS NULL.

Add Get/Upsert/Clear GeneratedDocumentID methods on Risk backed by a new
risks_document_id column on generated_documents, matching the
ProcessingActivity/Finding/Vendor pattern. The migration command
migrate-risk-snapshots-to-documents uses raw SQL queries instead of the
Go snapshot types, since those are gone.

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-05-04 14:13:42 +02:00

270 lines
6.3 KiB
GraphQL

enum RiskTreatment
@goModel(model: "go.probo.inc/probo/pkg/coredata.RiskTreatment") {
MITIGATED
@goEnum(value: "go.probo.inc/probo/pkg/coredata.RiskTreatmentMitigated")
ACCEPTED
@goEnum(value: "go.probo.inc/probo/pkg/coredata.RiskTreatmentAccepted")
AVOIDED
@goEnum(value: "go.probo.inc/probo/pkg/coredata.RiskTreatmentAvoided")
TRANSFERRED
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.RiskTreatmentTransferred"
)
}
enum RiskOrderField
@goModel(model: "go.probo.inc/probo/pkg/coredata.RiskOrderField") {
CREATED_AT
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.RiskOrderFieldCreatedAt"
)
UPDATED_AT
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.RiskOrderFieldUpdatedAt"
)
NAME @goEnum(value: "go.probo.inc/probo/pkg/coredata.RiskOrderFieldName")
CATEGORY
@goEnum(value: "go.probo.inc/probo/pkg/coredata.RiskOrderFieldCategory")
TREATMENT
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.RiskOrderFieldTreatment"
)
INHERENT_RISK_SCORE
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.RiskOrderFieldInherentRiskScore"
)
RESIDUAL_RISK_SCORE
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.RiskOrderFieldResidualRiskScore"
)
OWNER_FULL_NAME
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.RiskOrderFieldOwnerFullName"
)
}
input RiskOrder
@goModel(
model: "go.probo.inc/probo/pkg/server/api/console/v1/types.RiskOrderBy"
) {
direction: OrderDirection!
field: RiskOrderField!
}
input RiskFilter {
query: String
}
type Risk implements Node {
id: ID!
name: String!
description: String
category: String!
treatment: RiskTreatment!
inherentLikelihood: Int!
inherentImpact: Int!
inherentRiskScore: Int!
residualLikelihood: Int!
residualImpact: Int!
residualRiskScore: Int!
note: String!
owner: Profile @goField(forceResolver: true)
organization: Organization! @goField(forceResolver: true)
measures(
first: Int
after: CursorKey
last: Int
before: CursorKey
orderBy: MeasureOrder
filter: MeasureFilter
): MeasureConnection! @goField(forceResolver: true)
documents(
first: Int
after: CursorKey
last: Int
before: CursorKey
orderBy: DocumentOrder
filter: DocumentFilter
): DocumentConnection! @goField(forceResolver: true)
controls(
first: Int
after: CursorKey
last: Int
before: CursorKey
orderBy: ControlOrder
filter: ControlFilter
): ControlConnection! @goField(forceResolver: true)
obligations(
first: Int
after: CursorKey
last: Int
before: CursorKey
orderBy: ObligationOrder
): ObligationConnection! @goField(forceResolver: true)
createdAt: Datetime!
updatedAt: Datetime!
permission(action: String!): Boolean! @goField(forceResolver: true)
}
type RiskConnection
@goModel(
model: "go.probo.inc/probo/pkg/server/api/console/v1/types.RiskConnection"
) {
totalCount: Int! @goField(forceResolver: true)
edges: [RiskEdge!]!
pageInfo: PageInfo!
}
type RiskEdge {
cursor: CursorKey!
node: Risk!
}
extend type Mutation {
createRisk(input: CreateRiskInput!): CreateRiskPayload!
updateRisk(input: UpdateRiskInput!): UpdateRiskPayload!
deleteRisk(input: DeleteRiskInput!): DeleteRiskPayload!
createRiskMeasureMapping(
input: CreateRiskMeasureMappingInput!
): CreateRiskMeasureMappingPayload!
deleteRiskMeasureMapping(
input: DeleteRiskMeasureMappingInput!
): DeleteRiskMeasureMappingPayload!
createRiskDocumentMapping(
input: CreateRiskDocumentMappingInput!
): CreateRiskDocumentMappingPayload!
deleteRiskDocumentMapping(
input: DeleteRiskDocumentMappingInput!
): DeleteRiskDocumentMappingPayload!
createRiskObligationMapping(
input: CreateRiskObligationMappingInput!
): CreateRiskObligationMappingPayload!
deleteRiskObligationMapping(
input: DeleteRiskObligationMappingInput!
): DeleteRiskObligationMappingPayload!
publishRiskList(
input: PublishRiskListInput!
): PublishRiskListPayload!
}
input PublishRiskListInput {
organizationId: ID!
approverIds: [ID!]
}
type PublishRiskListPayload {
documentEdge: DocumentEdge!
documentVersionEdge: DocumentVersionEdge!
}
input CreateRiskInput {
organizationId: ID!
name: String!
description: String
category: String!
ownerId: ID
treatment: RiskTreatment!
inherentLikelihood: Int!
inherentImpact: Int!
residualLikelihood: Int
residualImpact: Int
note: String
}
input UpdateRiskInput {
id: ID!
name: String
description: String @goField(omittable: true)
category: String
ownerId: ID @goField(omittable: true)
treatment: RiskTreatment
inherentLikelihood: Int
inherentImpact: Int
residualLikelihood: Int
residualImpact: Int
note: String
}
input DeleteRiskInput {
riskId: ID!
}
input CreateRiskMeasureMappingInput {
riskId: ID!
measureId: ID!
}
input DeleteRiskMeasureMappingInput {
riskId: ID!
measureId: ID!
}
input CreateRiskDocumentMappingInput {
riskId: ID!
documentId: ID!
}
input DeleteRiskDocumentMappingInput {
riskId: ID!
documentId: ID!
}
input CreateRiskObligationMappingInput {
riskId: ID!
obligationId: ID!
}
input DeleteRiskObligationMappingInput {
riskId: ID!
obligationId: ID!
}
type CreateRiskPayload {
riskEdge: RiskEdge!
}
type UpdateRiskPayload {
risk: Risk!
}
type DeleteRiskPayload {
deletedRiskId: ID!
}
type CreateRiskMeasureMappingPayload {
riskEdge: RiskEdge!
measureEdge: MeasureEdge!
}
type DeleteRiskMeasureMappingPayload {
deletedMeasureId: ID!
deletedRiskId: ID!
}
type CreateRiskDocumentMappingPayload {
riskEdge: RiskEdge!
documentEdge: DocumentEdge!
}
type DeleteRiskDocumentMappingPayload {
deletedRiskId: ID!
deletedDocumentId: ID!
}
type CreateRiskObligationMappingPayload {
riskEdge: RiskEdge!
obligationEdge: ObligationEdge!
}
type DeleteRiskObligationMappingPayload {
deletedRiskId: ID!
deletedObligationId: ID!
}