Files
breakpilot-compliance/backend-compliance/compliance/api/use_case_controls_routes.py
T
Benjamin Admin 7aabfbe5b5 feat(controls): Mandanten-Suppression — per-tenant Applicability-Override
Geteilte Schicht für alle Surfaces (Workspace-Anwälte, Cyber-Risiko-Projekt,
Admin): ein Mandant markiert ein Control als "nicht anwendbar" → in seinen
Use-Case-Ansichten (und künftig Repo-Scans) ausgeblendet.

- Migration 156: compliance.control_suppressions (PK tenant_id+control_uuid),
  reversibel (active + reverted_*), auditierbar (actor/reason/created_at).
  [migration-approved]
- Service control_suppression: suppress/revert/list_suppressions +
  suppressed_control_uuids (geteilter Filter).
- Routes: GET/POST /v1/controls/suppressions + POST .../{uuid}/revert (X-Tenant-ID).
- controls_for_use_case: optionaler X-Tenant-ID + include_suppressed; suppressed
  per Default versteckt (nie gelöscht), suppressed_count, suppressed-Flag pro
  Control. Agenten/CRA ohne Tenant unberührt.
- Tests: Request-Validierung + import-safety (E2E-Zyklus gegen macmini bewiesen).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-16 16:35:38 +02:00

82 lines
3.2 KiB
Python

"""Use-Case → Controls API — the shared retrieval layer.
GET /v1/controls/use-cases — registry + mapped counts
GET /v1/controls/use-cases/{use_case}/controls — ranked controls of a topic
Consumed by the document specialist agents and the CRA finding-mapper so both
draw from ONE controls index instead of separate retrievals. Read-only.
"""
from __future__ import annotations
from typing import Any, Optional
from fastapi import APIRouter, Depends, Header, Query
from sqlalchemy.orm import Session
from classroom_engine.database import get_db
from compliance.api._http_errors import translate_domain_errors
from compliance.services.corpus_overview import corpus_overview
from compliance.services.use_case_controls import UseCaseControlsService
router = APIRouter(prefix="/v1/controls", tags=["use-case-controls"])
def get_use_case_controls_service(
db: Session = Depends(get_db),
) -> UseCaseControlsService:
return UseCaseControlsService(db)
@router.get("/use-cases")
async def list_use_cases(
svc: UseCaseControlsService = Depends(get_use_case_controls_service),
) -> list[dict[str, Any]]:
"""All enabled use-cases (topics) with their live mapped-control counts."""
with translate_domain_errors():
return svc.list_use_cases()
@router.get("/corpus")
async def corpus(db: Session = Depends(get_db)) -> dict[str, Any]:
"""Korpus-Übersicht: Quell-Dokumente (source_regulation) mit Lizenz-Tier +
Atom-Count + gemapptem Use Case, plus den kuratierten Lizenz-Katalog
(canonical_control_sources ⋈ licenses) mit Nutzungsrechten."""
with translate_domain_errors():
return corpus_overview(db)
@router.get("/use-cases/{use_case}/controls")
async def controls_for_use_case(
use_case: str,
primary_only: bool = Query(False, description="master-grain Fallback: nur Primaerzweck"),
sub_topic: Optional[str] = Query(None, description="atom-grain: nur dieses Sub-Thema"),
tier: str = Query(
"core",
pattern="^(core|all)$",
description="atom-grain: 'core'=nur validierte Kern-Pflichten (Default), "
"'all'=alle inkl. 'zur Prüfung'-Stufe",
),
include_out_of_scope: bool = Query(
False,
description="atom-grain: out-of-scope-Adressaten (Aufsichtsbefugnis/"
"Mitgliedstaat/Dritter/meta) einblenden (Default: advisory ausgeblendet)",
),
include_suppressed: bool = Query(
False,
description="atom-grain: vom Mandanten als unanwendbar markierte Controls "
"einblenden (Default: ausgeblendet)",
),
x_tenant_id: Optional[str] = Header(None, alias="X-Tenant-ID"),
limit: int = Query(50, ge=1, le=200),
offset: int = Query(0, ge=0),
svc: UseCaseControlsService = Depends(get_use_case_controls_service),
) -> dict[str, Any]:
"""Controls for a topic. Atom-grain (Haiku: relevant + sub_topic) wenn vorhanden,
sonst master-grain Seed. Mandanten-Suppression greift nur mit X-Tenant-ID."""
with translate_domain_errors():
return svc.controls_for_use_case(
use_case, primary_only, limit, offset, sub_topic, tier,
include_out_of_scope, x_tenant_id, include_suppressed,
)