feat(onboarding): unified multi-target model + scan matrix foundation
CI / Check (pull_request) Failing after 4m28s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped

Backend foundation for the artifact-aware onboarding redesign (epic #118),
replacing the git-only TrackedRepository / DastTarget split with a unified
OnboardedTarget classified by target type and carrying its artifacts.

compliance-core:
- OnboardedTarget model: TargetType (9 families), ArtifactKind (8 kinds),
  Artifact with per-kind config, ArtifactAuth (folds git auth + DastAuthConfig),
  Classification, TargetScanConfig (reuses pentest + tracker config).
- Table-driven scan-applicability matrix: applicable_scans / rules_for /
  supports_pentest, with SAST umbrella + firmware/PLC/mobile/DAST gated on
  artifact presence.
- TargetClassifier port trait, mirroring the Scanner trait.
- Additive ScanType/ScanPhase variants (firmware/PLC/mobile/container);
  ScanType is now Copy.

compliance-agent:
- onboarded_targets collection accessor + indexes (artifacts.source_ref,
  artifacts.kind, target_type).
- Drop a now-redundant ScanType clone surfaced by the Copy derive.

Foundation only (steps 1-2 of the approved plan); legacy scan paths untouched.
17 new unit tests; passes fmt + clippy -D warnings (agent, dashboard, mcp).

Refs #118, #119, #122, #121.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Sharang Parnerkar
2026-07-10 12:23:51 +02:00
co-authored by Claude Fable 5
parent aed551231c
commit def7371d6a
9 changed files with 1083 additions and 2 deletions
+37
View File
@@ -428,6 +428,36 @@ impl Database {
)
.await?;
// onboarded_targets: multikey on artifact source ref (webhook + dedupe
// lookup). Non-unique — "one git URL per tenant" is enforced in the
// create handler, since a unique multikey index on an array field has
// null-collision caveats.
self.onboarded_targets()
.create_index(
IndexModel::builder()
.keys(doc! { "artifacts.source_ref": 1 })
.build(),
)
.await?;
// onboarded_targets: multikey on artifact kind
self.onboarded_targets()
.create_index(
IndexModel::builder()
.keys(doc! { "artifacts.kind": 1 })
.build(),
)
.await?;
// onboarded_targets: target_type filter
self.onboarded_targets()
.create_index(
IndexModel::builder()
.keys(doc! { "target_type": 1 })
.build(),
)
.await?;
tracing::info!("Database indexes ensured");
Ok(())
}
@@ -484,6 +514,13 @@ impl Database {
self.inner.collection("dast_targets")
}
/// The unified onboarding targets that replace `repositories` and
/// `dast_targets`. Ids are preserved from the legacy collections during
/// migration so downstream `repo_id` / `target_id` references keep resolving.
pub fn onboarded_targets(&self) -> Collection<OnboardedTarget> {
self.inner.collection("onboarded_targets")
}
pub fn dast_scan_runs(&self) -> Collection<DastScanRun> {
self.inner.collection("dast_scan_runs")
}
+1 -1
View File
@@ -215,7 +215,7 @@ fn scan_with_patterns(
repo_id.to_string(),
fingerprint,
scanner_name.to_string(),
scan_type.clone(),
scan_type,
pattern.title.clone(),
pattern.description.clone(),
pattern.severity.clone(),