WP-20/21: contract and failing tests for vulnerability management
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
84
backend/crates/application/src/vuln_service.rs
Normal file
84
backend/crates/application/src/vuln_service.rs
Normal file
@ -0,0 +1,84 @@
|
||||
//! Vulnerability scanning: diffs scanner results against stored findings,
|
||||
//! notifies about new ones by mail.
|
||||
use std::sync::Arc;
|
||||
|
||||
use async_trait::async_trait;
|
||||
use domain::ports::{ClusterGateway, FindingRepository, VulnerabilityScanner};
|
||||
use domain::vuln::{
|
||||
Finding, FindingFilter, FindingStatus, ScanReport, Severity, SeverityCounts, TargetKind,
|
||||
};
|
||||
use domain::DomainError;
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::jobs::{JobHandler, JobLog};
|
||||
use crate::SettingsService;
|
||||
|
||||
pub struct VulnerabilityService {
|
||||
pub(crate) scanner: Arc<dyn VulnerabilityScanner>,
|
||||
pub(crate) findings: Arc<dyn FindingRepository>,
|
||||
pub(crate) cluster: Arc<dyn ClusterGateway>,
|
||||
pub(crate) settings: Arc<SettingsService>,
|
||||
}
|
||||
|
||||
impl VulnerabilityService {
|
||||
pub fn new(
|
||||
scanner: Arc<dyn VulnerabilityScanner>,
|
||||
findings: Arc<dyn FindingRepository>,
|
||||
cluster: Arc<dyn ClusterGateway>,
|
||||
settings: Arc<SettingsService>,
|
||||
) -> Self {
|
||||
Self {
|
||||
scanner,
|
||||
findings,
|
||||
cluster,
|
||||
settings,
|
||||
}
|
||||
}
|
||||
|
||||
/// Scan the OS and all cluster images, persist the diff, notify about new findings.
|
||||
pub async fn scan(&self, _log: &dyn JobLog) -> Result<ScanReport, DomainError> {
|
||||
todo!()
|
||||
}
|
||||
|
||||
pub async fn list(&self, _filter: FindingFilter) -> Result<Vec<Finding>, DomainError> {
|
||||
todo!()
|
||||
}
|
||||
|
||||
pub async fn summary(&self) -> Result<Summary, DomainError> {
|
||||
todo!()
|
||||
}
|
||||
|
||||
/// Only open <-> acknowledged transitions are allowed by users.
|
||||
pub async fn set_status(
|
||||
&self,
|
||||
_id: Uuid,
|
||||
_status: FindingStatus,
|
||||
) -> Result<Finding, DomainError> {
|
||||
todo!()
|
||||
}
|
||||
|
||||
pub async fn scanner_version(&self) -> Result<String, DomainError> {
|
||||
self.scanner.version().await
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, Default, PartialEq, Eq, serde::Serialize)]
|
||||
pub struct Summary {
|
||||
pub total: SeverityCounts,
|
||||
pub os: SeverityCounts,
|
||||
pub images: SeverityCounts,
|
||||
pub last_scan: Option<chrono::DateTime<chrono::Utc>>,
|
||||
}
|
||||
|
||||
pub struct VulnerabilityScanJob(pub Arc<VulnerabilityService>);
|
||||
|
||||
#[async_trait]
|
||||
impl JobHandler for VulnerabilityScanJob {
|
||||
async fn run(&self, _params: Option<String>, _log: &dyn JobLog) -> Result<(), String> {
|
||||
todo!()
|
||||
}
|
||||
}
|
||||
|
||||
/// Key of the notification threshold setting.
|
||||
pub const KEY_NOTIFY_MIN_SEVERITY: &str = "vuln.notify_min_severity";
|
||||
pub const DEFAULT_NOTIFY_MIN_SEVERITY: Severity = Severity::High;
|
||||
Reference in New Issue
Block a user