Documentation
¶
Overview ¶
Package slauc coordinates tenant policy versions, immutable SLA assessments, and human-owned remediation transitions. The scoring algorithm stays in domain/sla; this package owns clocks, identifiers, persistence, and cross-domain input mapping.
Index ¶
- func InputsFromFinding(item finding.Finding) sla.Inputs
- func InputsFromRiskAssessment(item vulnerabilityrisk.Assessment) sla.Inputs
- type Service
- func (s *Service) ActivatePolicy(ctx context.Context, tenantID shared.ID, cfg sla.Config, actor string) (sla.Policy, bool, error)
- func (s *Service) ActivePolicy(ctx context.Context, tenantID shared.ID) (sla.Policy, error)
- func (s *Service) Assess(ctx context.Context, input sla.AssessmentInput) (sla.View, error)
- func (s *Service) AssessFinding(ctx context.Context, tenantID shared.ID, item finding.Finding) (sla.View, error)
- func (s *Service) AssessmentHistory(ctx context.Context, tenantID, engagementID, findingID shared.ID) ([]sla.Assessment, error)
- func (s *Service) Get(ctx context.Context, tenantID, engagementID, findingID shared.ID) (sla.View, error)
- func (s *Service) LifecycleEvents(ctx context.Context, tenantID, engagementID, findingID shared.ID) ([]sla.LifecycleEvent, error)
- func (s *Service) List(ctx context.Context, tenantID, engagementID shared.ID) ([]sla.View, error)
- func (s *Service) Policies(ctx context.Context, tenantID shared.ID) ([]sla.Policy, error)
- func (s *Service) Transition(ctx context.Context, tenantID, engagementID, findingID shared.ID, ...) (sla.View, error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func InputsFromFinding ¶
InputsFromFinding maps durable finding facts into SLA risk signals without inventing asset criticality or network exposure. RiskScore is EPSS*CVSS in the finding model, so EPSS can be recovered when a valid CVSS vector is present. Unknown context remains neutral by domain design.
func InputsFromRiskAssessment ¶
func InputsFromRiskAssessment(item vulnerabilityrisk.Assessment) sla.Inputs
InputsFromRiskAssessment preserves continuous-intelligence signals that are not projected onto the finding row (public PoC and active exploitation). Asset context is intentionally left unknown.
Types ¶
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service is safe to share between scan, continuous-intelligence, HTTP, and CLI entry points. The store owns transaction/concurrency semantics; all time and IDs enter through ports for replayable tests.
func NewService ¶
func (*Service) ActivatePolicy ¶
func (s *Service) ActivatePolicy(ctx context.Context, tenantID shared.ID, cfg sla.Config, actor string) (sla.Policy, bool, error)
ActivatePolicy appends a validated tenant policy and atomically selects it for future assessments. Existing assessments are not rewritten; callers can explicitly reassess findings to adopt it.
func (*Service) ActivePolicy ¶
ActivePolicy returns the selected tenant policy, installing the built-in version on first use.
func (*Service) Assess ¶
Assess evaluates and promotes a current SLA assessment. An idempotent replay returns the existing immutable artifact and does not move its deadlines. A materially changed input advances the current pointer while the store preserves every human lifecycle field.
func (*Service) AssessFinding ¶
func (s *Service) AssessFinding(ctx context.Context, tenantID shared.ID, item finding.Finding) (sla.View, error)
AssessFinding derives the reproducible subset of SLA inputs available on a finding row.
func (*Service) AssessmentHistory ¶
func (*Service) Get ¶
func (s *Service) Get(ctx context.Context, tenantID, engagementID, findingID shared.ID) (sla.View, error)
Get returns the live overdue/acceptance-expiry projection for one finding.
func (*Service) LifecycleEvents ¶
func (*Service) List ¶
List returns current SLA views in the deterministic order supplied by the store.
func (*Service) Transition ¶
func (s *Service) Transition(ctx context.Context, tenantID, engagementID, findingID shared.ID, cmd sla.TransitionCommand) (sla.View, error)
Transition applies a human decision under optimistic concurrency and persists its audit event in the same store transaction. AI/machine identities are rejected by the domain even if a caller bypasses an HTTP permission check.