Documentation
¶
Overview ¶
Package httpapi is the HTTP driving adapter: it maps routes to use case services.
Index ¶
- Constants
- func Instrument(next http.Handler, log *slog.Logger, accessLogEnabled bool, ...) http.Handler
- func IsPlatformAdmin(ctx context.Context) bool
- func LoggerFrom(ctx context.Context) (*slog.Logger, bool)
- func NewEgressGrantHandler(token string, authorizer EgressGrantAuthorizer) (http.Handler, error)
- func PrincipalFrom(ctx context.Context) string
- func RequestIDFrom(ctx context.Context) (string, bool)
- func TenantFrom(ctx context.Context) string
- type Authenticator
- type EgressGrantAuthorizer
- type HTTPObserver
- type OIDCAuthorization
- type OIDCPrincipal
- type OIDCService
- type OIDCSession
- type Principal
- type ReadinessCheck
- type Resolver
- type RouteRegistration
- type Router
- func (rt *Router) EnableAgent(orch *orchestrator.Orchestrator, sessions ports.AgentSessionStore, ...)
- func (rt *Router) Handler() http.Handler
- func (rt *Router) SetAITriageReviews(s aiTriageReviewService)
- func (rt *Router) SetAccuracyReader(r accuracyRunReader)
- func (rt *Router) SetAgentDecisionStore(ds ports.DecisionStore)
- func (rt *Router) SetAgentPlanStore(ps ports.PlanStore)
- func (rt *Router) SetAgentRunContext(ctx context.Context)
- func (rt *Router) SetAlerts(s alertService)
- func (rt *Router) SetAssessmentComparisons(service *comparisonuc.Service)
- func (rt *Router) SetAssessmentCycles(service *cycleuc.APIService, apiEnabled bool, dualWrite func(string) bool)
- func (rt *Router) SetAssessmentLifecycleRollout(readEnabled, uiEnabled func(string) bool)
- func (rt *Router) SetAssessmentRelationships(service *relationshipuc.Service)
- func (rt *Router) SetAssessmentSnapshots(service *snapshotuc.Service)
- func (rt *Router) SetAssets(s assetService)
- func (rt *Router) SetAttackPaths(s attackPathService)
- func (rt *Router) SetAutoVerifier(s autoVerifierService)
- func (rt *Router) SetBehaviorRebaseliner(r behaviorRebaseliner)
- func (rt *Router) SetBusinessAssets(service businessAssetService)
- func (rt *Router) SetCSPM(service *cspm.Service)
- func (rt *Router) SetCapabilities(c capabilityCatalog)
- func (rt *Router) SetChainRehearsal(r chainRehearser)
- func (rt *Router) SetConnectors(svc connectorService)
- func (rt *Router) SetCoverageWindowReader(reader coverageWindowReader)
- func (rt *Router) SetDASTRunner(s dastRunService)
- func (rt *Router) SetDASTScan(s dastScanService)
- func (rt *Router) SetDASTWorkflow(s dastWorkflowService)
- func (rt *Router) SetDataPurge(p dataPurger)
- func (rt *Router) SetDesiredCapabilities(s desiredCapabilityService)
- func (rt *Router) SetDetectionProvenanceReader(r detectionProvenanceReader)
- func (rt *Router) SetDetectionReader(r detectionReader)
- func (rt *Router) SetEndpointProcesses(s endpointProcessStore)
- func (rt *Router) SetEndpointTimeline(r endpointTimelineReader)
- func (rt *Router) SetExploitation(v findingVerifier)
- func (rt *Router) SetFindingSummaries(r ports.FindingSummaryReader)
- func (rt *Router) SetFleet(agents fleetAgentService, work fleetWorkService, now func() time.Time, ...)
- func (rt *Router) SetFleetAdmin(s fleetAdminService)
- func (rt *Router) SetFleetClientCertHost(host string)
- func (rt *Router) SetFleetClusterInventory(s fleetClusterInventory)
- func (rt *Router) SetFleetCoverage(s coverageService)
- func (rt *Router) SetFleetDetectionIngest(s fleetDetectionIngest)
- func (rt *Router) SetFleetEnrollmentHost(host string)
- func (rt *Router) SetFleetHostInventory(s fleetHostInventory)
- func (rt *Router) SetFleetKeyAdmin(s fleetKeyAdmin)
- func (rt *Router) SetFleetKeyRegistration(s fleetKeyRegistration)
- func (rt *Router) SetFleetPrivacyPolicyReader(reader fleetPrivacyPolicyReader)
- func (rt *Router) SetFleetProcessReport(s fleetProcessReport)
- func (rt *Router) SetFleetResponseHaltReader(reader fleetResponseHaltReader)
- func (rt *Router) SetFleetResponseObserverBindings(reader fleetResponseObserverBindingReader)
- func (rt *Router) SetFleetResponseVerification(s fleetResponseVerificationIngest)
- func (rt *Router) SetFleetRollout(d fleetRolloutDecider)
- func (rt *Router) SetFleetRolloutAdmin(s fleetRolloutService)
- func (rt *Router) SetFleetRuntimeEvidence(s fleetRuntimeEvidence)
- func (rt *Router) SetFleetTelemetry(s fleetTelemetryIngest)
- func (rt *Router) SetFleetVersionPolicy(minAgentVersion, cpVersion string)
- func (rt *Router) SetHostAssetVerifier(v hostAssetVerifier)
- func (rt *Router) SetHostVulnerabilities(s hostVulnerabilityService)
- func (rt *Router) SetImportedFindings(r sarifReader)
- func (rt *Router) SetIncidentCorrelator(c incidentCorrelator)
- func (rt *Router) SetIncidentResponseCoordinator(c incidentResponseCoordinator)
- func (rt *Router) SetIncidentRiskReassessor(r incidentRiskReassessor)
- func (rt *Router) SetIncidentTriage(t incidentTriager)
- func (rt *Router) SetIncidents(r incidentReader)
- func (rt *Router) SetIntegrations(service *integrationuc.Service)
- func (rt *Router) SetJudgments(s judgmentService)
- func (rt *Router) SetLegalHolds(s legalHoldService)
- func (rt *Router) SetNotifications(service *notificationuc.Service)
- func (rt *Router) SetOIDC(service OIDCService, frontendURL string)
- func (rt *Router) SetObservability(accessLogEnabled bool, observer HTTPObserver)
- func (rt *Router) SetOffensiveKillSwitch(ks offensiveKillSwitch)
- func (rt *Router) SetOffensivePolicy(register *offensivepolicy.Register)
- func (rt *Router) SetOwnership(s *ownershipuc.Service, mode, reason string)
- func (rt *Router) SetPrivacyExport(e privacyExporter)
- func (rt *Router) SetPrivacyPolicyService(service privacyPolicyService)
- func (rt *Router) SetProcessLearner(l processLearner)
- func (rt *Router) SetProjects(s projectService)
- func (rt *Router) SetPurpleCoverageReader(r purpleCoverageReader)
- func (rt *Router) SetPurpleTeam(r purpleTeamRunner)
- func (rt *Router) SetQualityGates(s qualityGateService)
- func (rt *Router) SetQualityProfiles(s qualityProfileService)
- func (rt *Router) SetReadinessChecks(checks map[string]ReadinessCheck)
- func (rt *Router) SetResponse(svc responseService, ids ports.IDGenerator)
- func (rt *Router) SetResponseObserverAdmin(service responseObserverAdmin)
- func (rt *Router) SetRetroHunter(h retroHunter)
- func (rt *Router) SetRiskStoryReader(r riskStoryReader)
- func (rt *Router) SetRules(s rulesService)
- func (rt *Router) SetRuntimeVerifier(s runtimeVerifierService)
- func (rt *Router) SetSARIFIngest(s sarifIngester)
- func (rt *Router) SetSLA(service *slauc.Service)
- func (rt *Router) SetScanJobs(s ports.ScanJobStore)
- func (rt *Router) SetScanRunHistory(history scanRunHistoryReader)
- func (rt *Router) SetThreatModel(s threatModelService)
- func (rt *Router) SetVulnerabilityActions(actions *vulnerabilityactionuc.Service)
- func (rt *Router) SetVulnerabilityAudit(audit ports.AuditLogger)
- func (rt *Router) SetVulnerabilityIntelligence(sources *vulnerabilitysourceuc.Service, monitor *vulnerabilitymonitor.Service)
- func (rt *Router) SetVulnerabilityReadModel(service *vulnerabilityinteluc.Service)
- func (rt *Router) SetVulnerabilityReconciliation(service *vulnerabilityreconciliation.Service)
- func (rt *Router) SetWriteupDrafts(s writeupDraftService)
- type SessionResolver
Constants ¶
const DefaultFleetTenant = shared.DefaultTenant
DefaultFleetTenant is the non-empty tenant id used when the principal is on the empty-string default tenant (single-tenant deployments). RLS-protected fleet tables cannot use the empty string, because under the 0057 policy the empty string is DENY, not a tenant. Mapping the empty default to a real, non-empty tenant here is what lets the fleet asset model work in a single-tenant deployment while still being isolated at the database. Migration 0058 seeds this tenant row so the fleet_assets FK to tenants is satisfied. It aliases shared.DefaultTenant (the inner-layer canonical value) so the two cannot drift.
const (
EgressGrantPath = "/internal/v1/egress-grants"
)
const FleetProtoVersion = "1"
FleetProtoVersion is the only agent protocol version this server supports. An agent must send it in X-Synapse-Fleet-Proto; a different value is refused rather than handled best-effort.
const PrincipalOperator = "operator"
PrincipalOperator is the fallback principal id (the bootstrap admin also uses it, so historical "operator" attribution stays coherent). Once auth is wired, the real authenticated user is stamped into the context per request.
Variables ¶
This section is empty.
Functions ¶
func Instrument ¶ added in v0.2.0
func Instrument(next http.Handler, log *slog.Logger, accessLogEnabled bool, observer HTTPObserver) http.Handler
Instrument wraps the complete normalized API handler exactly once. It avoids recording unbounded request data and emits a single access event after every request when enabled.
func IsPlatformAdmin ¶ added in v0.2.0
IsPlatformAdmin reports whether the request principal operates the deployment itself rather than a single tenant.
It reads the authenticated principal directly instead of going through PrincipalFrom, which falls back to the operator id when no principal is bound. That fallback keeps historical attribution coherent, but as an authorization test it would fail open for any request that somehow reached a handler without passing the authenticator.
func LoggerFrom ¶ added in v0.2.0
LoggerFrom returns the request-scoped logger, which includes the request ID. It returns false for contexts not created by Instrument.
func NewEgressGrantHandler ¶ added in v0.2.0
func NewEgressGrantHandler(token string, authorizer EgressGrantAuthorizer) (http.Handler, error)
NewEgressGrantHandler exposes one machine-authenticated issuance route. It is intended for a private listener and does not pass through human API or AUP auth.
func PrincipalFrom ¶
PrincipalFrom returns the authenticated principal's id from ctx (the value used as the actor on every attributable action), defaulting to operator if unset.
func RequestIDFrom ¶ added in v0.2.0
RequestIDFrom returns the server-generated request correlation ID.
func TenantFrom ¶
TenantFrom returns the authenticated principal's tenant from ctx – the tenant that scopes the request's data and stamps new records. Empty = the single default tenant (single-tenant mode).
Types ¶
type Authenticator ¶
type Authenticator struct {
// contains filtered or unexported fields
}
func NewAuthenticator ¶
func NewAuthenticator(resolve Resolver) *Authenticator
NewAuthenticator builds an authenticator from a token resolver.
func (*Authenticator) Middleware ¶
Middleware enforces a valid bearer token on every route except publicPaths (no anonymous access) and stamps the authenticated principal into the context.
func (*Authenticator) SetSessionResolver ¶ added in v0.2.0
func (a *Authenticator) SetSessionResolver(resolve SessionResolver)
SetSessionResolver enables the OIDC BFF cookie session fallback while retaining bearer authentication.
type EgressGrantAuthorizer ¶ added in v0.2.0
type HTTPObserver ¶ added in v0.2.0
type HTTPObserver interface {
ObserveHTTPRequest(method, route, statusClass string, duration time.Duration)
}
HTTPObserver receives bounded HTTP request measurements. It deliberately has no Prometheus dependency so the HTTP adapter remains transport-neutral.
type OIDCAuthorization ¶ added in v0.2.0
type OIDCAuthorization struct{ URL, Nonce string }
OIDCService is the narrow HTTP boundary for the OIDC BFF use-case.
type OIDCPrincipal ¶ added in v0.2.0
type OIDCPrincipal struct{ ID, Name, Role, TenantID string }
type OIDCService ¶ added in v0.2.0
type OIDCService interface {
Begin(context.Context) (OIDCAuthorization, error)
Complete(context.Context, string, string, string) (OIDCSession, error)
Discover(context.Context, string) (OIDCSession, error)
Authenticate(context.Context, string, string, bool) (OIDCPrincipal, error)
Logout(context.Context, string) error
}
func NewOIDCService ¶ added in v0.2.0
func NewOIDCService(begin func(context.Context) (OIDCAuthorization, error), complete func(context.Context, string, string, string) (OIDCSession, error), discover func(context.Context, string) (OIDCSession, error), authenticate func(context.Context, string, string, bool) (OIDCPrincipal, error), logout func(context.Context, string) error) (OIDCService, error)
type OIDCSession ¶ added in v0.2.0
type OIDCSession struct {
Token, CSRFToken string
Principal OIDCPrincipal
}
type Principal ¶
type Principal struct {
ID string
Name string
Role string
// TenantID is the tenant the principal belongs to – it scopes the request's data and stamps
// new records. Empty = the single default tenant (single-tenant mode).
TenantID string
}
Principal is the authenticated subject for a request.
type ReadinessCheck ¶ added in v0.2.0
ReadinessCheck verifies one dependency required to serve production traffic. The endpoint exposes only the check name and pass/fail state, never the returned error.
type Resolver ¶
Resolver maps a presented bearer token to a Principal. ok=false means the token is unknown/disabled (→ 401). Implemented over the users service in the wiring.
type RouteRegistration ¶ added in v0.2.0
type RouteRegistration struct {
// Pattern is the ServeMux pattern, for example "GET /api/v1/engagements/{id}".
Pattern string
// Guard names the outermost wrapper applied to the handler, for example "rt.authz". Empty
// when the handler is passed through unwrapped.
Guard string
// Line is the line in router.go the registration sits on.
Line int
}
RouteRegistration is one route as the router actually registers it.
func ParseRouteRegistrations ¶ added in v0.2.0
func ParseRouteRegistrations(filename string) ([]RouteRegistration, error)
ParseRouteRegistrations reads a router source file and returns every route it registers.
It walks the syntax tree rather than matching text, so a registration cannot hide from it by spanning several lines, by being written as mux.Handle, or by mentioning the guard's name inside a comment or an unrelated argument. A registration whose pattern is not a plain string literal, or that uses a form this parser does not model, is returned as an error: an inventory that quietly skips what it cannot read is worse than no inventory, because it reads as a pass.
type Router ¶
type Router struct {
// contains filtered or unexported fields
}
Router wires HTTP routes to use case services.
func NewRouter ¶
func NewRouter(log *slog.Logger, auth *Authenticator, eng *enguc.Service, sca *scauc.Service, aup *aupuc.Service, findings *findingsuc.Service, export *exportuc.Service, report *reportuc.Service, evidence *evidenceuc.Service, recon *reconuc.Service, logs ports.LogStream, transfer *transferuc.Service, audit *audituc.Service, vex *vexuc.Service, users *usersuc.Service, credentials *credentialsuc.Service) *Router
NewRouter builds the HTTP router.
func (*Router) EnableAgent ¶
func (rt *Router) EnableAgent(orch *orchestrator.Orchestrator, sessions ports.AgentSessionStore, approvals *approval.Service, approvalStore ports.ApprovalStore, queue ports.JobQueue, concurrency, queueDepth int)
EnableAgent wires the AI agent routes. concurrency bounds inline (non-durable) runs; queueDepth bounds the DURABLE path – the max number of not-yet-terminal agent jobs admitted before the API returns 503 (with Retry-After), so a flood / retry-storm / dead-letter re-drive cannot grow the jobs table without bound. Call after NewRouter; if never called the agent endpoints are not registered (fail-safe: SYNAPSE_AGENT_ENABLED=false leaves off).
func (*Router) SetAITriageReviews ¶ added in v0.1.8
func (rt *Router) SetAITriageReviews(s aiTriageReviewService)
SetAITriageReviews wires the tenant-scoped human review queue.
func (*Router) SetAccuracyReader ¶ added in v0.2.0
func (rt *Router) SetAccuracyReader(r accuracyRunReader)
SetAccuracyReader wires the read route for the engine-accuracy trend (EPIC #860 D8.6). Left unset, the route returns an empty list rather than 500 — the nightly job is simply not enabled.
func (*Router) SetAgentDecisionStore ¶
func (rt *Router) SetAgentDecisionStore(ds ports.DecisionStore)
SetAgentDecisionStore wires the read-only decision log behind GET …/decisions.
func (*Router) SetAgentPlanStore ¶
SetAgentPlanStore wires the read-only execution-plan view behind GET …/plan.
func (*Router) SetAgentRunContext ¶
SetAgentRunContext binds inline agent runs to a server-lifetime context (cancelled on shutdown) so a SIGTERM stops in-flight runs instead of leaving detached goroutines.
func (*Router) SetAlerts ¶ added in v0.2.0
func (rt *Router) SetAlerts(s alertService)
SetAlerts wires operator alerting and enables its routes.
func (*Router) SetAssessmentComparisons ¶ added in v0.2.0
func (rt *Router) SetAssessmentComparisons(service *comparisonuc.Service)
func (*Router) SetAssessmentCycles ¶ added in v0.2.0
func (*Router) SetAssessmentLifecycleRollout ¶ added in v0.2.0
func (*Router) SetAssessmentRelationships ¶ added in v0.2.0
func (rt *Router) SetAssessmentRelationships(service *relationshipuc.Service)
func (*Router) SetAssessmentSnapshots ¶ added in v0.2.0
func (rt *Router) SetAssessmentSnapshots(service *snapshotuc.Service)
func (*Router) SetAssets ¶ added in v0.1.8
func (rt *Router) SetAssets(s assetService)
SetAssets wires the asset service and enables the asset routes.
func (*Router) SetAttackPaths ¶ added in v0.1.8
func (rt *Router) SetAttackPaths(s attackPathService)
func (*Router) SetAutoVerifier ¶
func (rt *Router) SetAutoVerifier(s autoVerifierService)
SetAutoVerifier wires the optional automated LLM judgment-verifier (nil ⇒ the auto-verify route is not registered). It seals a distinct-verifier verdict on each proposed gated judgment.
func (*Router) SetBehaviorRebaseliner ¶ added in v0.2.0
func (rt *Router) SetBehaviorRebaseliner(r behaviorRebaseliner)
SetBehaviorRebaseliner wires the behavior-baseline re-baseline route (nil ⇒ the route is not registered). A drifted or poisoned baseline abstains until an operator re-baselines it here.
func (*Router) SetBusinessAssets ¶ added in v0.1.8
func (rt *Router) SetBusinessAssets(service businessAssetService)
func (*Router) SetCapabilities ¶ added in v0.2.0
func (rt *Router) SetCapabilities(c capabilityCatalog)
SetCapabilities wires the deployment capability catalog. nil means the route is not registered.
func (*Router) SetChainRehearsal ¶ added in v0.2.0
func (rt *Router) SetChainRehearsal(r chainRehearser)
SetChainRehearsal wires the exploitation chain-rehearsal route. The rehearsal executes with a no-host simulation executor and a distinct system verifier, so it proves the chain is policy-admissible and its custody chain is sound without touching a host. Left unset, the route is not registered.
func (*Router) SetConnectors ¶ added in v0.2.0
func (rt *Router) SetConnectors(svc connectorService)
SetConnectors wires the source-control connector routes. The token entered on create is sealed by the store and never returned, so these routes need PermAdminister (below, in the router).
func (*Router) SetCoverageWindowReader ¶ added in v0.2.0
func (rt *Router) SetCoverageWindowReader(reader coverageWindowReader)
func (*Router) SetDASTRunner ¶ added in v0.2.0
func (rt *Router) SetDASTRunner(s dastRunService)
SetDASTRunner wires durable DAST verification execution: the run route enqueues a job and a status route reads it. nil ⇒ the run route executes the probe synchronously (dev / in-memory).
func (*Router) SetDASTScan ¶ added in v0.1.8
func (rt *Router) SetDASTScan(s dastScanService)
SetDASTScan wires secret-free authenticated DAST scan endpoints.
func (*Router) SetDASTWorkflow ¶
func (rt *Router) SetDASTWorkflow(s dastWorkflowService)
SetDASTWorkflow wires the governed safe-DAST proposal/approval/run endpoints.
func (*Router) SetDataPurge ¶ added in v0.2.0
func (rt *Router) SetDataPurge(p dataPurger)
SetDataPurge wires the on-demand data-deletion surface (nil ⇒ the route is not registered).
func (*Router) SetDesiredCapabilities ¶ added in v0.2.0
func (rt *Router) SetDesiredCapabilities(s desiredCapabilityService)
SetDesiredCapabilities wires the desired-vs-observed surface (nil ⇒ the routes are not registered).
func (*Router) SetDetectionProvenanceReader ¶ added in v0.2.0
func (rt *Router) SetDetectionProvenanceReader(r detectionProvenanceReader)
SetDetectionProvenanceReader wires detection provenance read routes.
func (*Router) SetDetectionReader ¶ added in v0.1.8
func (rt *Router) SetDetectionReader(r detectionReader)
SetDetectionReader wires the detection read routes (#423). Left unset, the routes report an empty ledger rather than 500 — the feature is simply not enabled.
func (*Router) SetEndpointProcesses ¶ added in v0.2.0
func (rt *Router) SetEndpointProcesses(s endpointProcessStore)
SetEndpointProcesses wires the process-projection surface (nil ⇒ the routes are not registered).
func (*Router) SetEndpointTimeline ¶ added in v0.2.0
func (rt *Router) SetEndpointTimeline(r endpointTimelineReader)
SetEndpointTimeline wires the State-Timeline read surface (nil ⇒ the routes are not registered).
func (*Router) SetExploitation ¶
func (rt *Router) SetExploitation(v findingVerifier)
SetExploitation wires the evidence-gated finding-verify endpoint.
func (*Router) SetFindingSummaries ¶ added in v0.2.0
func (rt *Router) SetFindingSummaries(r ports.FindingSummaryReader)
SetFindingSummaries wires the batched finding counter the engagement list uses for its Findings column. Optional: without it rows carry no findings_count.
func (*Router) SetFleet ¶ added in v0.1.8
func (rt *Router) SetFleet(agents fleetAgentService, work fleetWorkService, now func() time.Time, clientCertHeader string)
SetFleet wires the untrusted agent transport plane. When nil, /api/v1/fleet is not served. clientCertHeader, when non-empty, is the header a trusted mutual-TLS-terminating proxy uses to pass the verified client certificate. Configuring it makes post-enrollment routes certificate-only; empty permits bearer authentication for explicitly non-production development and tests.
func (*Router) SetFleetAdmin ¶ added in v0.1.8
func (rt *Router) SetFleetAdmin(s fleetAdminService)
SetFleetAdmin wires the operator agent-admin routes (mint enrolment token, list, revoke).
func (*Router) SetFleetClientCertHost ¶ added in v0.2.0
SetFleetClientCertHost binds fleet traffic to a dedicated virtual host whose ingress verifies client certificates and overwrites the forwarded certificate header.
func (*Router) SetFleetClusterInventory ¶ added in v0.1.8
func (rt *Router) SetFleetClusterInventory(s fleetClusterInventory)
SetFleetClusterInventory wires the cluster snapshot ingest use case onto the agent transport plane. It must be called after SetFleet; a nil fleet (transport disabled) makes it a no-op.
func (*Router) SetFleetCoverage ¶ added in v0.1.8
func (rt *Router) SetFleetCoverage(s coverageService)
SetFleetCoverage wires the coverage read model and enables the coverage/agent-view routes.
func (*Router) SetFleetDetectionIngest ¶ added in v0.2.0
func (rt *Router) SetFleetDetectionIngest(s fleetDetectionIngest)
SetFleetDetectionIngest wires the agent-plane detection batch ingest (A4 #625). When nil (or unset), POST /api/v1/fleet/detections returns 404. It must be called after SetFleet.
func (*Router) SetFleetEnrollmentHost ¶ added in v0.2.0
SetFleetEnrollmentHost binds the one-time bearer enrollment exchange to a TLS-only virtual host separate from the mTLS host. ingress-nginx applies client-certificate authentication per host.
func (*Router) SetFleetHostInventory ¶ added in v0.1.8
func (rt *Router) SetFleetHostInventory(s fleetHostInventory)
SetFleetHostInventory wires the VM host inventory ingest use case onto the agent transport plane. It must be called after SetFleet; a nil fleet (transport disabled) makes it a no-op.
func (*Router) SetFleetKeyAdmin ¶ added in v0.2.0
func (rt *Router) SetFleetKeyAdmin(s fleetKeyAdmin)
SetFleetKeyAdmin wires the operator (human, RBAC-gated) signing-key management routes (list + revoke). When nil, those routes are not registered.
func (*Router) SetFleetKeyRegistration ¶ added in v0.2.0
func (rt *Router) SetFleetKeyRegistration(s fleetKeyRegistration)
SetFleetKeyRegistration wires the agent-plane signing-key registration (A4 #625, A0.2). When nil (or unset), POST /api/v1/fleet/keys returns 404. It must be called after SetFleet.
func (*Router) SetFleetPrivacyPolicyReader ¶ added in v0.2.0
func (rt *Router) SetFleetPrivacyPolicyReader(reader fleetPrivacyPolicyReader)
SetFleetPrivacyPolicyReader enables read-only active-policy delivery to authenticated agents.
func (*Router) SetFleetProcessReport ¶ added in v0.2.0
func (rt *Router) SetFleetProcessReport(s fleetProcessReport)
SetFleetProcessReport wires the agent-plane running-process report (#594 D input). When nil (or unset), POST /api/v1/fleet/processes returns 404. It must be called after SetFleet.
func (*Router) SetFleetResponseHaltReader ¶ added in v0.2.0
func (rt *Router) SetFleetResponseHaltReader(reader fleetResponseHaltReader)
SetFleetResponseHaltReader makes the durable tenant halt generation available before every claim.
func (*Router) SetFleetResponseObserverBindings ¶ added in v0.2.0
func (rt *Router) SetFleetResponseObserverBindings(reader fleetResponseObserverBindingReader)
SetFleetResponseObserverBindings makes a server-owned secondary asset assignment available at heartbeat.
func (*Router) SetFleetResponseVerification ¶ added in v0.2.0
func (rt *Router) SetFleetResponseVerification(s fleetResponseVerificationIngest)
SetFleetResponseVerification wires the purpose-signed response post-condition ingest route.
func (*Router) SetFleetRollout ¶ added in v0.1.8
func (rt *Router) SetFleetRollout(d fleetRolloutDecider)
SetFleetRollout wires the operator-controlled update rollout (#412 req 9). Optional: with no decider wired the heartbeat offers no update at all, which is the fail-closed default — an absent rollout service must never read as permission to update.
func (*Router) SetFleetRolloutAdmin ¶ added in v0.1.8
func (rt *Router) SetFleetRolloutAdmin(s fleetRolloutService)
SetFleetRolloutAdmin wires the operator routes. Optional: when nil they are not registered.
func (*Router) SetFleetRuntimeEvidence ¶ added in v0.2.0
func (rt *Router) SetFleetRuntimeEvidence(s fleetRuntimeEvidence)
SetFleetRuntimeEvidence wires the agent-plane runtime-reachability evidence ingest (#1060/#1061). When nil (or unset), POST /api/v1/fleet/inventory/runtime returns 404. It must be called after SetFleet.
func (*Router) SetFleetTelemetry ¶ added in v0.2.0
func (rt *Router) SetFleetTelemetry(s fleetTelemetryIngest)
SetFleetTelemetry wires the agent-plane telemetry batch ingest (A3 #624). When nil (or unset), POST /api/v1/fleet/telemetry returns 404. It must be called after SetFleet.
func (*Router) SetFleetVersionPolicy ¶ added in v0.1.8
SetFleetVersionPolicy wires the version-skew policy (#412): minAgentVersion is the minimum agent version allowed to claim work (empty = no floor), and cpVersion is the control-plane version advertised to agents so they can enforce their own minimum control-plane requirement. Must be called after SetFleet.
func (*Router) SetHostAssetVerifier ¶ added in v0.2.0
func (rt *Router) SetHostAssetVerifier(v hostAssetVerifier)
SetHostAssetVerifier wires the host-asset check for the operator process/rebaseline routes. Optional: when unset the routes do not pre-verify the asset (the tenant-scoped stores still isolate tenants).
func (*Router) SetHostVulnerabilities ¶ added in v0.2.0
func (rt *Router) SetHostVulnerabilities(s hostVulnerabilityService)
SetHostVulnerabilities wires the host vulnerability reader and enables its routes.
func (*Router) SetImportedFindings ¶ added in v0.1.8
func (rt *Router) SetImportedFindings(r sarifReader)
SetImportedFindings wires the imported-finding read. Optional: when nil the route is not registered.
func (*Router) SetIncidentCorrelator ¶ added in v0.2.0
func (rt *Router) SetIncidentCorrelator(c incidentCorrelator)
SetIncidentCorrelator wires the correlation surface (nil ⇒ the route is not registered).
func (*Router) SetIncidentResponseCoordinator ¶ added in v0.2.0
func (rt *Router) SetIncidentResponseCoordinator(c incidentResponseCoordinator)
SetIncidentResponseCoordinator wires the incident-scoped governed response apply route. The action ID generator is supplied with the standard response service, so this setter cannot expose a client-chosen ID.
func (*Router) SetIncidentRiskReassessor ¶ added in v0.2.0
func (rt *Router) SetIncidentRiskReassessor(r incidentRiskReassessor)
SetIncidentRiskReassessor wires the tri-score reassessment surface (nil ⇒ the route is not registered).
func (*Router) SetIncidentTriage ¶ added in v0.2.0
func (rt *Router) SetIncidentTriage(t incidentTriager)
SetIncidentTriage wires the incident triage surface (nil ⇒ the triage routes are not registered).
func (*Router) SetIncidents ¶ added in v0.2.0
func (rt *Router) SetIncidents(r incidentReader)
SetIncidents wires the incident read surface (nil ⇒ the routes are not registered).
func (*Router) SetIntegrations ¶ added in v0.2.0
func (rt *Router) SetIntegrations(service *integrationuc.Service)
SetIntegrations wires the CI/CD integration API.
func (*Router) SetJudgments ¶
func (rt *Router) SetJudgments(s judgmentService)
SetJudgments wires the AI judgment lifecycle endpoints. nil ⇒ routes are not registered.
func (*Router) SetLegalHolds ¶ added in v0.2.0
func (rt *Router) SetLegalHolds(s legalHoldService)
SetLegalHolds wires the legal-hold surface (nil ⇒ the routes are not registered).
func (*Router) SetNotifications ¶ added in v0.2.0
func (rt *Router) SetNotifications(service *notificationuc.Service)
SetNotifications wires tenant-managed channels, rules, and delivery history.
func (*Router) SetOIDC ¶ added in v0.2.0
func (rt *Router) SetOIDC(service OIDCService, frontendURL string)
SetOIDC installs the browser OIDC BFF and its fixed, validated frontend destination.
func (*Router) SetObservability ¶ added in v0.2.0
func (rt *Router) SetObservability(accessLogEnabled bool, observer HTTPObserver)
SetObservability installs the optional bounded HTTP observer and access-log policy. A nil observer disables metrics feed but access logging (if enabled) still runs.
func (*Router) SetOffensiveKillSwitch ¶ added in v0.1.8
func (rt *Router) SetOffensiveKillSwitch(ks offensiveKillSwitch)
SetOffensiveKillSwitch wires the red-team halt route (#418). Left unset, the route is not registered: an endpoint that accepts a halt and does nothing would be the worst possible failure for this control.
func (*Router) SetOffensivePolicy ¶ added in v0.2.0
func (rt *Router) SetOffensivePolicy(register *offensivepolicy.Register)
SetOffensivePolicy wires the offensive policy register the binary loaded and validated at startup, and enables the read route that shows operators exactly what the running binary enforces.
func (*Router) SetOwnership ¶ added in v0.2.0
func (rt *Router) SetOwnership(s *ownershipuc.Service, mode, reason string)
func (*Router) SetPrivacyExport ¶ added in v0.2.0
func (rt *Router) SetPrivacyExport(e privacyExporter)
SetPrivacyExport wires the data-export surface (nil ⇒ the route is not registered).
func (*Router) SetPrivacyPolicyService ¶ added in v0.2.0
func (rt *Router) SetPrivacyPolicyService(service privacyPolicyService)
SetPrivacyPolicyService wires tenant privacy-policy governance on the human RBAC plane.
func (*Router) SetProcessLearner ¶ added in v0.2.0
func (rt *Router) SetProcessLearner(l processLearner)
SetProcessLearner wires the behavioral-baseline learner (nil ⇒ reported processes are not learned).
func (*Router) SetProjects ¶
func (rt *Router) SetProjects(s projectService)
func (*Router) SetPurpleCoverageReader ¶ added in v0.1.8
func (rt *Router) SetPurpleCoverageReader(r purpleCoverageReader)
SetPurpleCoverageReader wires the purple-coverage read route (#426). Left unset, the route reports empty coverage rather than 500 — the feature is simply not enabled.
func (*Router) SetPurpleTeam ¶ added in v0.2.0
func (rt *Router) SetPurpleTeam(r purpleTeamRunner)
SetPurpleTeam wires the adversary-emulation run route (#426 producer). It requires the offensive policy and the emulation + coverage stores; left unset, the run route is not registered.
func (*Router) SetQualityGates ¶
func (rt *Router) SetQualityGates(s qualityGateService)
SetQualityGates wires quality gate management endpoints.
func (*Router) SetQualityProfiles ¶
func (rt *Router) SetQualityProfiles(s qualityProfileService)
SetQualityProfiles wires the quality-profile management endpoints. nil ⇒ routes are not registered.
func (*Router) SetReadinessChecks ¶ added in v0.2.0
func (rt *Router) SetReadinessChecks(checks map[string]ReadinessCheck)
SetReadinessChecks replaces the dependency checks used by GET /readyz. It copies the map so startup wiring cannot mutate the live probe configuration after the server begins serving. Protected by write-lock against concurrent probe execution (race safety).
func (*Router) SetResponse ¶ added in v0.2.0
func (rt *Router) SetResponse(svc responseService, ids ports.IDGenerator)
SetResponse wires the governed defensive-response routes (#425). Left unset, the routes are not registered — the feature is optional, exactly like every other subsystem the router gates on a nil dependency. ids mints the action id server-side so a client can never choose it.
func (*Router) SetResponseObserverAdmin ¶ added in v0.2.0
func (rt *Router) SetResponseObserverAdmin(service responseObserverAdmin)
func (*Router) SetRetroHunter ¶ added in v0.2.0
func (rt *Router) SetRetroHunter(h retroHunter)
SetRetroHunter wires the retro-hunt surface (nil ⇒ the route is not registered).
func (*Router) SetRiskStoryReader ¶ added in v0.1.8
func (rt *Router) SetRiskStoryReader(r riskStoryReader)
SetRiskStoryReader wires the risk-story read routes (#427). Left unset, the routes report an empty result rather than 500 — the correlation view is simply not enabled.
func (*Router) SetRules ¶
func (rt *Router) SetRules(s rulesService)
SetRules wires the rule catalog endpoints. nil ⇒ not registered.
func (*Router) SetRuntimeVerifier ¶
func (rt *Router) SetRuntimeVerifier(s runtimeVerifierService)
SetRuntimeVerifier wires typed runtime-verifier result ingestion. nil means the route is absent.
func (*Router) SetSARIFIngest ¶ added in v0.1.8
func (rt *Router) SetSARIFIngest(s sarifIngester)
SetSARIFIngest wires the ingest usecase and enables the import route. Optional: when nil the route is not registered.
func (*Router) SetSLA ¶ added in v0.1.8
SetSLA wires the opt-in risk-based remediation governance API.
func (*Router) SetScanJobs ¶ added in v0.2.0
func (rt *Router) SetScanJobs(s ports.ScanJobStore)
SetScanJobs wires the scan job store the engagement list uses for its Last scan column. Optional: without it rows carry no last_scan_date.
func (*Router) SetScanRunHistory ¶ added in v0.2.0
func (rt *Router) SetScanRunHistory(history scanRunHistoryReader)
SetScanRunHistory wires normalized provenance into the existing scan-run history route.
func (*Router) SetThreatModel ¶
func (rt *Router) SetThreatModel(s threatModelService)
SetThreatModel wires the architecture threat-model ingest/read endpoints. nil ⇒ not registered.
func (*Router) SetVulnerabilityActions ¶ added in v0.1.8
func (rt *Router) SetVulnerabilityActions(actions *vulnerabilityactionuc.Service)
func (*Router) SetVulnerabilityAudit ¶ added in v0.1.8
func (rt *Router) SetVulnerabilityAudit(audit ports.AuditLogger)
func (*Router) SetVulnerabilityIntelligence ¶ added in v0.1.8
func (rt *Router) SetVulnerabilityIntelligence(sources *vulnerabilitysourceuc.Service, monitor *vulnerabilitymonitor.Service)
SetVulnerabilityIntelligence wires source management and durable sync routes.
func (*Router) SetVulnerabilityReadModel ¶ added in v0.1.8
func (rt *Router) SetVulnerabilityReadModel(service *vulnerabilityinteluc.Service)
func (*Router) SetVulnerabilityReconciliation ¶ added in v0.1.8
func (rt *Router) SetVulnerabilityReconciliation(service *vulnerabilityreconciliation.Service)
func (*Router) SetWriteupDrafts ¶
func (rt *Router) SetWriteupDrafts(s writeupDraftService)
SetWriteupDrafts wires the human sign-off endpoints for AI-proposed write-up drafts. nil ⇒ not registered.
type SessionResolver ¶ added in v0.2.0
type SessionResolver interface {
Authenticate(ctx context.Context, token, csrfToken string, unsafe bool) (Principal, error)
}
Authenticator validates the bearer token on each request via the Resolver and stamps the resolved principal into the request context for attribution. SessionResolver validates an opaque browser session. CSRF is passed only for cookie authentication.
Source Files
¶
- accuracy_handler.go
- agent_handler.go
- agent_readiness.go
- aitriage_observability_handler.go
- aitriage_review_handler.go
- alert_handler.go
- assessment_comparison_handler.go
- assessment_cycle_handler.go
- assessment_relationship_handler.go
- assessment_snapshot_handler.go
- asset_handler.go
- attackpath_handler.go
- aup_handler.go
- auth.go
- bodylimit.go
- business_asset_handler.go
- capability_handler.go
- codequality_handler.go
- coverage_window_handler.go
- credential_handler.go
- cspm_handler.go
- dashboard_handler.go
- dast_scan_handler.go
- dast_workflow_handler.go
- data_purge_handler.go
- desired_handler.go
- detection_handler.go
- detection_privacy.go
- detection_provenance_handler.go
- egress_grant_handler.go
- endpoint_process_handler.go
- engagement_handler.go
- evidence_handler.go
- exploitation_rehearsal_handler.go
- export_handler.go
- finding_handler.go
- fleet_coverage_handler.go
- fleet_detection_handler.go
- fleet_handler.go
- fleet_keys_handler.go
- fleet_rollout_handler.go
- fleet_telemetry_handler.go
- host_vulnerability_handler.go
- incident_handler.go
- integration_handler.go
- judgment_handler.go
- legal_hold_handler.go
- notification_handler.go
- observability.go
- offensive_policy_handler.go
- oidc_handler.go
- ownership_handler.go
- platform_admin.go
- privacy_export_handler.go
- privacy_policy_handler.go
- project_analysis_handler.go
- project_analysis_import_handler.go
- project_code_handler.go
- project_dependency_graph_handler.go
- project_handler.go
- project_hotspot_handler.go
- project_issue_handler.go
- project_measure_handler.go
- project_overview_handler.go
- project_source_publish_handler.go
- purple_handler.go
- quality_gate_handler.go
- quality_profile_handler.go
- readiness.go
- recon_handler.go
- redteam_halt_handler.go
- report_handler.go
- resource_view.go
- response.go
- response_handler.go
- response_observer_handler.go
- riskstory_handler.go
- route_inventory.go
- router.go
- rule_handler.go
- sarif_handler.go
- sca_handler.go
- scm_connector_handler.go
- sla_handler.go
- sse.go
- threat_model_handler.go
- timeline_handler.go
- transfer_handler.go
- user_handler.go
- vulnerability_action_handler.go
- vulnerability_handler.go
- vulnerability_read_handler.go
- vulnerability_reconcile_handler.go
- writeup_handler.go
- writeupdraft_handler.go