978052b5a2
Fix B of the pre-#59 semantic correction. The Silent Pass had only TWO effective states though the data
carries three: a `detected` mapping (a concrete artifact) AND a `partial` mapping (an indicative signal,
e.g. a CI pipeline -> secure-development-lifecycle) both flowed through capability_ids() and were fed to
the Advisor as already-present — so a weak indication silently removed a question, exactly the Welt-1/
Welt-2 transparency we want to keep.
Now three distinct states:
- detected -> reduces the delta immediately (auto_detected, not asked). [unchanged]
- partial -> raises assumption strength but does NOT replace the question (surfaced as `indications`,
the capability stays in the delta and is still asked).
- requirement-> describes a target, never the present state (already handled by Fix A's kind split).
Changes (data + thin wiring, no new architecture):
- SilentIntakeResult.capability_ids() returns only relationship==detected; new indicative_capability_ids()
returns the partial ones.
- advisor_start() gains indicative_capabilities (NOT fed into the profile) and surfaces result.indications
= indicative ∩ required − auto_detected.
- AdvisorResult / AdvisorResponse gain `indications` (additive, contract-safe); the service passes the
indicative ids through.
Tests: a partial CI signal is indicative-not-detected and does NOT shrink the delta; end-to-end it appears
in `indications`, not `auto_detected`, and the gap is still asked. 28 onboarding tests pass, mypy --strict
clean on the onboarding modules, demo runs, check-loc 0. Runtime effect -> deploy + smoke.
75 lines
3.4 KiB
Python
75 lines
3.4 KiB
Python
"""Onboarding Advisor endpoint — exposes the existing Smart Onboarding Advisor at runtime.
|
|
|
|
This adds NO new reasoning logic. It exposes the already-built, tested orchestration (Signal Producers
|
|
-> Normalizer -> Silent Knowledge Pass -> Advisor) through one runtime endpoint. No DB, no persistence.
|
|
|
|
POST /onboarding/advisor-start — (company + certs + target + scanner findings) -> advisory payload
|
|
GET /onboarding/targets — the supported target ids
|
|
"""
|
|
|
|
import logging
|
|
from typing import List, Optional
|
|
|
|
from fastapi import APIRouter, HTTPException
|
|
from pydantic import BaseModel, Field
|
|
|
|
from compliance.onboarding import (
|
|
AdvisorMeasure,
|
|
AdvisorQuestion,
|
|
InferredAssumption,
|
|
ProducedSignal,
|
|
RejectedAssumption,
|
|
)
|
|
from compliance.services.onboarding_service import run_advisor, supported_targets
|
|
|
|
logger = logging.getLogger(__name__)
|
|
router = APIRouter(prefix="/onboarding", tags=["onboarding"])
|
|
|
|
|
|
class OnboardingAdvisorRequest(BaseModel):
|
|
company: str = ""
|
|
industry: Optional[str] = None
|
|
products: List[str] = Field(default_factory=list)
|
|
markets: List[str] = Field(default_factory=list)
|
|
certifications: List[str] = Field(default_factory=list)
|
|
known_evidence: List[str] = Field(default_factory=list)
|
|
target: str = "CRA"
|
|
scanner_findings: List[ProducedSignal] = Field(default_factory=list) # adapters upstream produced these
|
|
|
|
|
|
class AdvisorResponse(BaseModel):
|
|
silent_intake_summary: str = ""
|
|
headline: str = ""
|
|
auto_detected: List[str] = Field(default_factory=list)
|
|
indications: List[str] = Field(default_factory=list) # partial signal: raises strength, still asked
|
|
inferred_assumptions: List[InferredAssumption] = Field(default_factory=list)
|
|
rejected_assumptions: List[RejectedAssumption] = Field(default_factory=list)
|
|
top_5_questions: List[AdvisorQuestion] = Field(default_factory=list)
|
|
capability_delta: List[str] = Field(default_factory=list)
|
|
top_measures: List[AdvisorMeasure] = Field(default_factory=list)
|
|
evidence_requests: List[str] = Field(default_factory=list)
|
|
unsupported_domains: List[str] = Field(default_factory=list)
|
|
completeness_summary: str = ""
|
|
|
|
|
|
@router.get("/targets")
|
|
def list_targets() -> dict:
|
|
return {"targets": supported_targets()}
|
|
|
|
|
|
@router.post("/advisor-start", response_model=AdvisorResponse)
|
|
def advisor_start_endpoint(req: OnboardingAdvisorRequest) -> AdvisorResponse:
|
|
if req.target not in supported_targets():
|
|
raise HTTPException(status_code=404, detail="unsupported target '%s'; supported: %s" % (req.target, supported_targets()))
|
|
result, si_summary = run_advisor(
|
|
company=req.company, certifications=req.certifications, target=req.target,
|
|
signals=req.scanner_findings, known_evidence=req.known_evidence,
|
|
products=req.products, markets=req.markets, industry=req.industry or "")
|
|
return AdvisorResponse(
|
|
silent_intake_summary=si_summary, headline=result.headline, auto_detected=result.auto_detected,
|
|
indications=result.indications,
|
|
inferred_assumptions=result.inferred_assumptions, rejected_assumptions=result.rejected_assumptions,
|
|
top_5_questions=result.next_best_questions, capability_delta=result.capability_delta,
|
|
top_measures=result.top_measures, evidence_requests=result.evidence_requests,
|
|
unsupported_domains=result.unsupported_domains, completeness_summary=result.completeness_summary)
|