feat: Phase 1 - Data models and migrations (T-004 to T-009)

Implements all database models for the Aegis platform with full
Alembic migration support.

Models created:
- User: Authentication with role-based access control
- Technique: MITRE ATT&CK techniques with coverage status tracking
- Test: Security tests with validation workflow (draft/review/validated)
- Evidence: File metadata for test evidence (stored in MinIO)
- IntelItem: Threat intelligence items linked to techniques
- AuditLog: System-wide audit trail with JSONB details

Enumerations:
- TechniqueStatus: not_evaluated, in_progress, validated, partial, etc.
- TestState: draft, in_review, validated, rejected
- TestResult: detected, not_detected, partially_detected

Services:
- audit_service.py: log_action() helper for audit logging

All models include proper foreign key relationships and PostgreSQL
enum types are managed correctly in migrations (create/drop).
This commit is contained in:
2026-02-06 12:26:26 +01:00
parent b479acdea0
commit ec65991ac1
18 changed files with 561 additions and 1 deletions

View File

@@ -0,0 +1,54 @@
"""add_techniques_table
Revision ID: 476930a8d86e
Revises: 4671fccfa705
Create Date: 2026-02-06 10:37:17.777106
"""
from typing import Sequence, Union
from alembic import op
import sqlalchemy as sa
from sqlalchemy.dialects import postgresql
# revision identifiers, used by Alembic.
revision: str = '476930a8d86e'
down_revision: Union[str, Sequence[str], None] = '4671fccfa705'
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None
def upgrade() -> None:
"""Upgrade schema."""
# Create enum type explicitly
techniquestatus_enum = postgresql.ENUM(
'not_evaluated', 'in_progress', 'validated', 'partial', 'not_covered', 'review_required',
name='techniquestatus'
)
techniquestatus_enum.create(op.get_bind(), checkfirst=True)
# Create table with create_type=False since we already created the enum
op.create_table('techniques',
sa.Column('id', sa.UUID(), nullable=False),
sa.Column('mitre_id', sa.String(), nullable=False),
sa.Column('name', sa.String(), nullable=False),
sa.Column('description', sa.Text(), nullable=True),
sa.Column('tactic', sa.String(), nullable=True),
sa.Column('platforms', postgresql.JSONB(astext_type=sa.Text()), nullable=True),
sa.Column('mitre_version', sa.String(), nullable=True),
sa.Column('mitre_last_modified', sa.DateTime(), nullable=True),
sa.Column('is_subtechnique', sa.Boolean(), nullable=True),
sa.Column('parent_mitre_id', sa.String(), nullable=True),
sa.Column('status_global', postgresql.ENUM('not_evaluated', 'in_progress', 'validated', 'partial', 'not_covered', 'review_required', name='techniquestatus', create_type=False), nullable=True),
sa.Column('review_required', sa.Boolean(), nullable=True),
sa.Column('last_review_date', sa.DateTime(), nullable=True),
sa.PrimaryKeyConstraint('id'),
sa.UniqueConstraint('mitre_id')
)
def downgrade() -> None:
"""Downgrade schema."""
op.drop_table('techniques')
# Drop enum type after dropping table
postgresql.ENUM(name='techniquestatus').drop(op.get_bind(), checkfirst=True)