The source headers, LICENSE files, and license metadata had drifted apart. Align the entire project to MIT: - Convert every source-file header to the MIT text across all comment styles (Go, TS, TSX, JS, MJS, SQL, CSS, GraphQL, shell), including SPDX-License-Identifier tags - Set the root and cookie-banner LICENSE files to the MIT text with a "MIT License" title line - Switch the package.json license fields, Docker image label, and cookie-banner README to MIT - Update docs and the genmodels header generator accordingly - Normalize copyright lines to a single format (Copyright (c) <year(s)> Probo Inc <hello@probo.com>.): unify the hello@getprobo.com and hello@probo.inc emails to hello@probo.com and the comma-separated years to a hyphenated range Genuine third-party references are intentionally left untouched: the Lucide icon attributions (Lucide is ISC) and the trivy dependency license allowlist. Signed-off-by: Sacha Al Himdani <sacha@probo.com>
171 lines
7.0 KiB
Go
171 lines
7.0 KiB
Go
// Copyright (c) 2026 Probo Inc <hello@probo.com>.
|
|
//
|
|
// Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
// of this software and associated documentation files (the "Software"), to deal
|
|
// in the Software without restriction, including without limitation the rights
|
|
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
// copies of the Software, and to permit persons to whom the Software is
|
|
// furnished to do so, subject to the following conditions:
|
|
//
|
|
// The above copyright notice and this permission notice shall be included in
|
|
// all copies or substantial portions of the Software.
|
|
//
|
|
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
// SOFTWARE.
|
|
|
|
package vetting
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"time"
|
|
|
|
"go.gearno.de/kit/pg"
|
|
"go.probo.inc/probo/pkg/agent"
|
|
"go.probo.inc/probo/pkg/coredata"
|
|
"go.probo.inc/probo/pkg/gid"
|
|
)
|
|
|
|
type (
|
|
saveThirdPartyInfoToolParams struct {
|
|
Name string `json:"name" jsonschema:"Third party display name"`
|
|
Description string `json:"description" jsonschema:"One-sentence description"`
|
|
Category string `json:"category" jsonschema:"Category: ANALYTICS, CLOUD_PROVIDER, SECURITY, etc."`
|
|
HeadquarterAddress string `json:"headquarter_address" jsonschema:"Headquarters city and country"`
|
|
LegalName string `json:"legal_name" jsonschema:"Legal entity name"`
|
|
PrivacyPolicyURL string `json:"privacy_policy_url" jsonschema:"Privacy policy URL"`
|
|
ServiceLevelAgreementURL string `json:"service_level_agreement_url" jsonschema:"SLA URL"`
|
|
DataProcessingAgreementURL string `json:"data_processing_agreement_url" jsonschema:"DPA URL"`
|
|
BusinessAssociateAgreementURL string `json:"business_associate_agreement_url" jsonschema:"BAA URL"`
|
|
SubprocessorsListURL string `json:"subprocessors_list_url" jsonschema:"Subprocessors list URL"`
|
|
SecurityPageURL string `json:"security_page_url" jsonschema:"Security page URL"`
|
|
TrustPageURL string `json:"trust_page_url" jsonschema:"Trust center URL"`
|
|
TermsOfServiceURL string `json:"terms_of_service_url" jsonschema:"Terms of service URL"`
|
|
StatusPageURL string `json:"status_page_url" jsonschema:"Status page URL"`
|
|
Certifications []string `json:"certifications" jsonschema:"Compliance certifications found"`
|
|
}
|
|
|
|
saveThirdPartyInfoParams struct {
|
|
saveThirdPartyInfoToolParams
|
|
Countries coredata.CountryCodes
|
|
}
|
|
|
|
linkSubThirdPartyParams struct {
|
|
Name string `json:"name" jsonschema:"Sub-third-party company name"`
|
|
Description string `json:"description,omitempty" jsonschema:"One-sentence description of what this third party does"`
|
|
Category string `json:"category,omitempty" jsonschema:"Category: ANALYTICS, CLOUD_PROVIDER, SECURITY, etc."`
|
|
WebsiteURL string `json:"website_url,omitempty" jsonschema:"Website URL if known"`
|
|
Country string `json:"country,omitempty" jsonschema:"Country where the sub-third-party operates"`
|
|
Purpose string `json:"purpose,omitempty" jsonschema:"Purpose or role of this sub-third-party"`
|
|
}
|
|
|
|
// PersistenceContext holds the DB and entity references the tools need.
|
|
PersistenceContext struct {
|
|
PG *pg.Client
|
|
ThirdPartyID gid.GID
|
|
OrganizationID gid.GID
|
|
WebsiteURL string
|
|
}
|
|
)
|
|
|
|
func SaveThirdPartyInfoTool(pc *PersistenceContext) agent.Tool {
|
|
return vettingFunctionTool(
|
|
"save_third_party_info",
|
|
"Persist the discovered third party metadata to the database. Call this once after completing the analysis. Use an empty string for any field you could not discover.",
|
|
func(ctx context.Context, p saveThirdPartyInfoToolParams) (agent.ToolResult, error) {
|
|
scope := coredata.NewScopeFromObjectID(pc.ThirdPartyID)
|
|
|
|
err := pc.PG.WithTx(
|
|
ctx,
|
|
func(ctx context.Context, conn pg.Tx) error {
|
|
thirdParty := &coredata.ThirdParty{}
|
|
|
|
if err := thirdParty.LoadByID(ctx, conn, scope, pc.ThirdPartyID); err != nil {
|
|
return fmt.Errorf("cannot load third party: %w", err)
|
|
}
|
|
|
|
if p.Category != "" {
|
|
if _, err := parseThirdPartyCategory(p.Category); err != nil {
|
|
return err
|
|
}
|
|
}
|
|
|
|
ancestorBaseNames, err := loadAncestorBaseNames(ctx, conn, scope, thirdParty.ID)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
applySaveParams(thirdParty, pc.WebsiteURL, saveThirdPartyInfoParams{
|
|
saveThirdPartyInfoToolParams: p,
|
|
}, ancestorBaseNames)
|
|
thirdParty.UpdatedAt = time.Now()
|
|
|
|
if err := thirdParty.Update(ctx, conn, scope); err != nil {
|
|
return fmt.Errorf("cannot update third party: %w", err)
|
|
}
|
|
|
|
return nil
|
|
},
|
|
)
|
|
if err != nil {
|
|
return agent.ToolResult{}, fmt.Errorf("cannot save third party info: %w", err)
|
|
}
|
|
|
|
return agent.ToolResult{Content: "Third party info saved successfully."}, nil
|
|
},
|
|
)
|
|
}
|
|
|
|
func LinkSubThirdPartyTool(pc *PersistenceContext) agent.Tool {
|
|
return vettingFunctionTool(
|
|
"link_sub_third_party",
|
|
"Link a discovered sub-third-party (sub-processor, vendor dependency) to the parent. If a third party with the same name already exists in the organization it is linked as-is; otherwise a new one is created with the provided info. Call once per sub-third-party discovered.",
|
|
func(ctx context.Context, p linkSubThirdPartyParams) (agent.ToolResult, error) {
|
|
if p.Name == "" {
|
|
return agent.ToolResult{Content: "Skipped: empty name."}, nil
|
|
}
|
|
|
|
scope := coredata.NewScopeFromObjectID(pc.ThirdPartyID)
|
|
|
|
err := pc.PG.WithTx(
|
|
ctx,
|
|
func(ctx context.Context, conn pg.Tx) error {
|
|
parent := &coredata.ThirdParty{}
|
|
if err := parent.LoadByID(ctx, conn, scope, pc.ThirdPartyID); err != nil {
|
|
return fmt.Errorf("cannot load parent third party: %w", err)
|
|
}
|
|
|
|
ancestorBaseNames, err := loadAncestorBaseNames(ctx, conn, scope, pc.ThirdPartyID)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// Child suffix path is the parent's ancestors plus the parent itself.
|
|
childNamePath := append(ancestorBaseNames, baseThirdPartyName(parent.Name))
|
|
|
|
return linkSubThirdParty(ctx, conn, scope, pc, parent.Level, childNamePath, p)
|
|
},
|
|
)
|
|
if err != nil {
|
|
return agent.ToolResult{}, fmt.Errorf("cannot link sub third party: %w", err)
|
|
}
|
|
|
|
return agent.ToolResult{Content: fmt.Sprintf("Linked %q as sub third party.", p.Name)}, nil
|
|
},
|
|
)
|
|
}
|
|
|
|
func parseThirdPartyCategory(raw string) (coredata.ThirdPartyCategory, error) {
|
|
category := coredata.ThirdPartyCategory(raw)
|
|
if !category.IsValid() {
|
|
return "", fmt.Errorf("invalid third party category %q", raw)
|
|
}
|
|
|
|
return category, nil
|
|
}
|