Rewire the console and visitor resolvers onto the management and visitor services with compliance-portal authorization. Rename the GraphQL and MCP ComplianceExternalURL type to ComplianceCustomLink, expose trust center profile fields, default and custom domains, public URL, and the managed flag, and drop the profile fields from the organization surface. Signed-off-by: Bryan Frimin <bryan@probo.com>
272 lines
8.4 KiB
Go
272 lines
8.4 KiB
Go
package trust_v1
|
|
|
|
// This file will be automatically regenerated based on the schema, any resolver
|
|
// implementations
|
|
// will be copied through when generating and any unknown code will be moved to the end.
|
|
// Code generated by github.com/99designs/gqlgen version v0.17.93
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"strings"
|
|
|
|
"go.gearno.de/kit/log"
|
|
trust "go.probo.inc/probo/pkg/complianceportal/visitor"
|
|
"go.probo.inc/probo/pkg/coredata"
|
|
"go.probo.inc/probo/pkg/gid"
|
|
"go.probo.inc/probo/pkg/page"
|
|
"go.probo.inc/probo/pkg/server/api/authn"
|
|
"go.probo.inc/probo/pkg/server/api/complianceportal"
|
|
"go.probo.inc/probo/pkg/server/api/trust/v1/schema"
|
|
"go.probo.inc/probo/pkg/server/api/trust/v1/types"
|
|
"go.probo.inc/probo/pkg/server/gqlutils"
|
|
)
|
|
|
|
// Viewer is the resolver for the viewer field.
|
|
func (r *queryResolver) Viewer(ctx context.Context) (*types.Identity, error) {
|
|
identity := authn.IdentityFromContext(ctx)
|
|
|
|
if identity == nil {
|
|
return nil, nil
|
|
}
|
|
|
|
return &types.Identity{
|
|
ID: identity.ID,
|
|
Email: identity.EmailAddress,
|
|
FullName: identity.FullName,
|
|
EmailVerified: identity.EmailAddressVerified,
|
|
CreatedAt: identity.CreatedAt,
|
|
UpdatedAt: identity.UpdatedAt,
|
|
}, nil
|
|
}
|
|
|
|
// Node is the resolver for the node field.
|
|
func (r *queryResolver) Node(ctx context.Context, id gid.GID) (types.Node, error) {
|
|
scope := coredata.NewScopeFromObjectID(id)
|
|
trustService := r.trust
|
|
|
|
switch id.EntityType() {
|
|
case coredata.OrganizationEntityType:
|
|
organization, err := trustService.GetOrganization(ctx, scope, id)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot get organization", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewOrganization(organization), nil
|
|
|
|
case coredata.DocumentEntityType:
|
|
trustCenter := complianceportal.CompliancePageFromContext(ctx)
|
|
|
|
document, err := trustService.GetDocument(ctx, scope, trustCenter.OrganizationID, id)
|
|
if err != nil {
|
|
if errors.Is(err, trust.ErrDocumentNotFound) || errors.Is(err, trust.ErrDocumentNotVisible) || errors.Is(err, coredata.ErrResourceNotFound) {
|
|
return nil, gqlutils.NotFoundf(ctx, "node %q not found", id)
|
|
}
|
|
|
|
if _, ok := errors.AsType[*trust.ErrDocumentArchived](err); ok {
|
|
return nil, gqlutils.NotFoundf(ctx, "node %q not found", id)
|
|
}
|
|
|
|
r.logger.ErrorCtx(ctx, "cannot get document", log.Error(err))
|
|
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewDocument(document), nil
|
|
|
|
case coredata.FrameworkEntityType:
|
|
framework, err := trustService.GetFramework(ctx, scope, id)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot get framework", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewFramework(framework), nil
|
|
|
|
case coredata.FileEntityType:
|
|
trustCenter := complianceportal.CompliancePageFromContext(ctx)
|
|
|
|
file, err := trustService.GetReport(ctx, scope, trustCenter.OrganizationID, id)
|
|
if err != nil {
|
|
if errors.Is(err, trust.ErrReportNotFound) || errors.Is(err, coredata.ErrResourceNotFound) {
|
|
return nil, gqlutils.NotFoundf(ctx, "node %q not found", id)
|
|
}
|
|
|
|
r.logger.ErrorCtx(ctx, "cannot get audit report file", log.Error(err))
|
|
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewAuditReport(file), nil
|
|
|
|
case coredata.AuditEntityType:
|
|
audit, err := trustService.GetAudit(ctx, scope, id)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot get audit", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewAudit(audit), nil
|
|
|
|
case coredata.ThirdPartyEntityType:
|
|
thirdParty, err := trustService.GetThirdParty(ctx, scope, id)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot get thirdParty", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewSubprocessor(thirdParty), nil
|
|
|
|
case coredata.TrustCenterEntityType:
|
|
trustCenter, err := trustService.GetPortal(ctx, scope, id)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot get trust center", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewTrustCenter(trustCenter), nil
|
|
|
|
case coredata.TrustCenterReferenceEntityType:
|
|
reference, err := trustService.GetPortalReference(ctx, scope, id)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot get trust center reference", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewTrustCenterReference(reference), nil
|
|
|
|
case coredata.TrustCenterFileEntityType:
|
|
trustCenter := complianceportal.CompliancePageFromContext(ctx)
|
|
|
|
trustCenterFile, err := trustService.GetPortalFile(ctx, scope, trustCenter.OrganizationID, id)
|
|
if err != nil {
|
|
if errors.Is(err, trust.ErrTrustCenterFileNotFound) || errors.Is(err, trust.ErrTrustCenterFileNotVisible) {
|
|
return nil, gqlutils.NotFoundf(ctx, "node %q not found", id)
|
|
}
|
|
|
|
r.logger.ErrorCtx(ctx, "cannot get trust center file", log.Error(err))
|
|
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewTrustCenterFile(trustCenterFile), nil
|
|
|
|
default:
|
|
return nil, gqlutils.NotFoundf(ctx, "node %q not found", id)
|
|
}
|
|
}
|
|
|
|
// AliasedNode is the resolver for the aliasedNode field.
|
|
func (r *queryResolver) AliasedNode(ctx context.Context, alias string) (types.Node, error) {
|
|
resourceID, err := gid.ParseGID(alias)
|
|
if err != nil {
|
|
trustCenter := complianceportal.CompliancePageFromContext(ctx)
|
|
scope := coredata.NewScopeFromObjectID(trustCenter.ID)
|
|
|
|
resourceID, err = r.resourceAlias.ResolveAlias(
|
|
ctx,
|
|
scope,
|
|
alias,
|
|
)
|
|
if err != nil {
|
|
if errors.Is(err, coredata.ErrResourceNotFound) {
|
|
return nil, gqlutils.NotFoundf(ctx, "node %q not found", alias)
|
|
}
|
|
|
|
r.logger.ErrorCtx(ctx, "cannot resolve resource alias", log.Error(err))
|
|
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
}
|
|
|
|
return r.Node(ctx, resourceID)
|
|
}
|
|
|
|
// CurrentTrustCenter is the resolver for the currentTrustCenter field.
|
|
func (r *queryResolver) CurrentTrustCenter(ctx context.Context) (*types.TrustCenter, error) {
|
|
trustCenter := complianceportal.CompliancePageFromContext(ctx)
|
|
|
|
scope := coredata.NewScopeFromObjectID(trustCenter.ID)
|
|
trustService := r.trust
|
|
|
|
org, err := trustService.GetOrganization(ctx, scope, trustCenter.OrganizationID)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot get organization", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
trustCenter, err = trustService.GetPortal(ctx, scope, trustCenter.ID)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot get trust center", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
response := types.NewTrustCenter(trustCenter)
|
|
response.Organization = types.NewOrganization(org)
|
|
|
|
return response, nil
|
|
}
|
|
|
|
// OidcProviders is the resolver for the oidcProviders field.
|
|
func (r *queryResolver) OidcProviders(ctx context.Context) ([]*types.OIDCProviderInfo, error) {
|
|
providers := r.iam.OIDCService.EnabledProviders()
|
|
result := make([]*types.OIDCProviderInfo, 0, len(providers))
|
|
|
|
for _, p := range providers {
|
|
name := strings.ToLower(p.String())
|
|
result = append(
|
|
result,
|
|
&types.OIDCProviderInfo{
|
|
Name: name,
|
|
LoginURL: r.baseURL.WithPath("/api/connect/v1/oidc/" + name + "/login").MustString(),
|
|
},
|
|
)
|
|
}
|
|
|
|
return result, nil
|
|
}
|
|
|
|
// MyRightsRequests is the resolver for the myRightsRequests field.
|
|
func (r *queryResolver) MyRightsRequests(ctx context.Context, first *int, after *page.CursorKey, last *int, before *page.CursorKey) (*types.RightsRequestConnection, error) {
|
|
pageOrderBy := page.OrderBy[coredata.RightsRequestOrderField]{
|
|
Field: coredata.RightsRequestOrderFieldCreatedAt,
|
|
Direction: page.OrderDirectionDesc,
|
|
}
|
|
cursor := types.NewCursor(first, after, last, before, pageOrderBy)
|
|
|
|
identity := authn.IdentityFromContext(ctx)
|
|
if identity == nil {
|
|
emptyPage := page.NewPage([]*coredata.RightsRequest{}, cursor)
|
|
return types.NewRightsRequestConnection(emptyPage), nil
|
|
}
|
|
|
|
compliancePage := compliancepage.CompliancePageFromContext(ctx)
|
|
scope := coredata.NewScopeFromObjectID(compliancePage.OrganizationID)
|
|
|
|
result, err := r.trust.RightsRequests.ListForOrganizationIDAndContact(
|
|
ctx,
|
|
scope,
|
|
compliancePage.OrganizationID,
|
|
identity.EmailAddress.String(),
|
|
cursor,
|
|
)
|
|
if err != nil {
|
|
r.logger.ErrorCtx(ctx, "cannot list rights requests", log.Error(err))
|
|
return nil, gqlutils.Internal(ctx)
|
|
}
|
|
|
|
return types.NewRightsRequestConnection(result), nil
|
|
}
|
|
|
|
// Mutation returns schema.MutationResolver implementation.
|
|
func (r *Resolver) Mutation() schema.MutationResolver { return &mutationResolver{r} }
|
|
|
|
// Query returns schema.QueryResolver implementation.
|
|
func (r *Resolver) Query() schema.QueryResolver { return &queryResolver{r} }
|
|
|
|
type (
|
|
mutationResolver struct{ *Resolver }
|
|
queryResolver struct{ *Resolver }
|
|
)
|