b6f23f385d
fix(analytics): restrict operators endpoint to admin [FASE-2.5]
...
Align with BI security spec and add flat JSON API tests for coverage, tests, and operators.
2026-05-18 14:00:47 +02:00
6ab950ec42
feat(reports): add quarterly and technique download routes [FASE-2.4]
...
Expose GET endpoints for quarterly-summary and technique reports with PDF, DOCX, and HTML formats.
2026-05-18 14:00:46 +02:00
ed2c34ef28
feat(reports): extend report generation service [FASE-2.3]
...
Add quarterly summary and technique detail builders with UUID-safe lookups and unit tests for purple campaign context.
2026-05-18 14:00:42 +02:00
96fdd9fa85
feat(reports): add quarterly and technique HTML templates [FASE-2.2]
...
Introduce quarterly_summary and technique_detail Jinja layouts; use SVG logo asset across report covers.
2026-05-18 14:00:40 +02:00
c28a47c43b
test(reports): add ReportEngine unit tests [FASE-2.1]
...
Stub WeasyPrint for CI-friendly PDF generation and verify HTML render, PDF path, and HTML file output.
2026-05-18 14:00:37 +02:00
0d4c404f08
test(jira): add hourly sync job tests [FASE-1.7]
...
Aegis CI / lint-and-test (push) Has been cancelled
Verify skip when disabled, per-link sync invocation, and continued batch on single-link failures.
2026-05-18 13:36:26 +02:00
03d7d1cc80
feat(tempo): harden worklog sync and add tests [FASE-1.4]
...
Add tempo-api-python-client dependency, TEMPO_API_VERSION setting, enum-safe Jira link lookup, work type on create_worklog, and mocked auto_log tests.
2026-05-18 13:36:26 +02:00
b8c9c4ac6a
test(jira): add hourly sync job tests [FASE-1.7]
...
Aegis CI / lint-and-test (push) Has been cancelled
Verify skip when disabled, per-link sync invocation, and continued batch on single-link failures.
2026-05-18 13:33:40 +02:00
73867d3990
test(jira): add jira_service unit tests [FASE-1.2]
...
Cover disabled client guard, issue search mapping, and sync_aegis_to_jira comment posting with mocks.
2026-05-18 13:33:27 +02:00
f45b7ea926
ci: add GitHub Actions lint and test pipeline [FASE-0.6]
...
Aegis CI / lint-and-test (push) Has been cancelled
Run ruff and pytest against Postgres and Redis service containers; document CI in README.
2026-05-18 13:19:29 +02:00
6b28934f05
test: stabilize Phase 0 API and workflow tests [FASE-0.4]
...
Assert INVALID_TRANSITION JSON code on duplicate start, remove sys.modules stubs from T-106 tests, and complete boto3 stubs in integration tests.
2026-05-18 13:19:27 +02:00
6f35d85a97
feat(db): add Phase 0 composite indexes migration [FASE-0.3]
...
Add idempotent Alembic revision b028 for campaign_tests (campaign_id, test_id) to support campaign-scoped queries.
2026-05-18 13:19:20 +02:00
c5eb6f6dc1
feat(auth): move JWT blacklist to Redis with TTL [FASE-0.2]
...
Revoke tokens by jti in a dedicated Redis DB, honor TTL from JWT exp on logout, reject revoked tokens in get_current_user, and add FakeRedis-backed API tests.
2026-05-18 13:19:15 +02:00
9b70655b7e
feat(infra): add Redis service and client for Phase 0 [FASE-0.1]
...
Add Redis 7 to Docker Compose with healthcheck and persistence, separate logical DBs for blacklist and cache, singleton redis client helpers, and unit tests with fakeredis.
2026-05-18 13:18:45 +02:00
821c4ac5ec
test(jira): add JiraLink model and jira_service tests [FASE-1.1]
...
Model and migration b020 were already present; adds regression coverage for persistence, schema validation, and link CRUD with Jira disabled.
2026-05-18 12:02:21 +02:00
abef2a45e0
fix: production detection only triggers on AEGIS_ENV=production, not SECRET_KEY presence
Aegis CI / lint-and-test (push) Has been cancelled
2026-02-20 17:20:48 +01:00
309b3bc02d
docs: finalize ARCHITECTURE.md with complete layered structure and zero remaining tech debt
Aegis CI / lint-and-test (push) Has been cancelled
2026-02-20 16:16:22 +01:00
0148bf28dc
chore: clean repo for public release, remove internal audit docs and plan artifacts, update README
2026-02-20 16:15:26 +01:00
79a4772ab5
feat: make heatmap layers extensible via LayerRegistry (OCP)
2026-02-20 16:07:36 +01:00
a9255e15ce
refactor: remove db.commit() from audit_service.log_action, all callers use UoW
2026-02-20 15:33:23 +01:00
0c526c48f9
docs: update ARCHITECTURE.md, ARCHITECTURAL_ANALYSIS.md, and skill file with Tier 1-4 changes
Aegis CI / lint-and-test (push) Has been cancelled
2026-02-20 15:14:07 +01:00
0d211d5156
feat: add ThreatActorEntity domain entity with coverage analysis (Tier 4)
2026-02-20 15:02:38 +01:00
14d995b40c
refactor: remove db.commit() from business services, callers use UnitOfWork (Tier 3)
2026-02-20 14:42:20 +01:00
339d669498
feat: move all remaining inline logic from routers to services (Tier 2)
2026-02-20 14:34:24 +01:00
9e22fde746
feat: extract advanced_metrics, analytics, test_templates, and auth to services (Tier 1 complete)
2026-02-20 14:28:52 +01:00
bbc2dddd86
docs: update ARCHITECTURE.md and ARCHITECTURAL_ANALYSIS.md to reflect all low-priority items completed (LP-8)
2026-02-20 13:39:55 +01:00
d77075272e
feat: add ImportService protocol and registry for OCP-compliant import extensibility (LP-7)
2026-02-20 13:31:18 +01:00
c0c6cda11d
feat: add Campaign/Compliance domain entities and extract users/audit/data_sources to services (LP-2 through LP-6)
2026-02-20 13:28:14 +01:00
44621364be
docs: update ARCHITECTURAL_ANALYSIS.md to reflect all completed refactoring (service extractions, scoring persistence, logging, N+1 fixes)
Aegis CI / lint-and-test (push) Has been cancelled
2026-02-20 12:55:26 +01:00
0eff48c768
docs: complete architectural refactoring tracker, create aegis-architecture skill for future agents
Aegis CI / lint-and-test (push) Has been cancelled
2026-02-19 19:15:31 +01:00
764a2f7579
feat(logging): add structured JSON logging for production, human-readable text for development
2026-02-19 19:07:08 +01:00
f4c74230ec
refactor(campaigns): extract CRUD/business logic to campaign_crud_service, use domain exceptions
2026-02-19 19:04:32 +01:00
50b70704ae
refactor(evidence): extract permission validation and queries to evidence_service, use domain exceptions
2026-02-19 19:02:36 +01:00
20738d11b3
refactor(tests): extract CRUD/query logic to test_crud_service, router delegates to service with domain exceptions
2026-02-19 18:35:09 +01:00
4e3787d091
refactor(scoring): persist weights in DB table, replace mutable Settings with scoring_config_service
2026-02-19 17:46:02 +01:00
93fde55389
refactor(threat-actors): extract query/business logic to threat_actor_service, fix N+1 with grouped subqueries
Aegis CI / lint-and-test (push) Has been cancelled
2026-02-19 17:40:00 +01:00
560fc0c9f0
refactor(detection-rules): extract query/business logic to detection_rule_service, router is thin HTTP adapter
2026-02-19 17:39:31 +01:00
d305db8794
refactor(compliance): extract business logic to compliance_service, use domain exceptions instead of HTTPException
2026-02-19 17:06:32 +01:00
25fddad17c
refactor(metrics): extract query logic to metrics_query_service, thin down router to HTTP adapter
2026-02-19 17:06:07 +01:00
8d5c5fa80e
refactor(reports): extract query and aggregation logic to coverage_report_service, fix N+1 test-count pattern
2026-02-19 15:56:42 +01:00
42a9f4dcd4
refactor(status): consolidate status_service to delegate to TechniqueEntity.recalculate_status() eliminating duplicated business logic
2026-02-19 15:23:01 +01:00
2b6d9090c9
refactor(techniques): wire TechniqueRepository into techniques router replacing direct db.query() with repo pattern, domain exceptions, and UnitOfWork
2026-02-19 15:13:52 +01:00
0b65f51d1c
docs: update architecture analysis and tech debt docs to reflect resolved items
Aegis CI / lint-and-test (push) Has been cancelled
2026-02-18 19:27:52 +01:00
f41b8fd8c2
fix(security): add username validation, constant-time login, default credential rejection, and tooling
2026-02-18 19:11:14 +01:00
1521005b62
feat(infra): add repository implementations, mappers, FastAPI wiring, and technique indexes
2026-02-18 19:10:50 +01:00
5c55e7c17f
feat(domain): add domain layer foundation -- enums, value objects, TechniqueEntity, repository ports
2026-02-18 19:10:31 +01:00
e651ef8a8c
refactor(heatmap): extract business logic to dedicated service
...
Aegis CI / lint-and-test (push) Has been cancelled
Move layer dispatch, entity-not-found checks, and validation from router to heatmap_service. Router now only validates requests, calls service, and formats responses (no HTTPException, no business logic). Service raises EntityNotFoundError/BusinessRuleViolation instead of returning None. Add build_navigator_export() for centralized dispatch. 29 new tests (253 total, 0 failures).
2026-02-18 16:09:51 +01:00
1338d52cd0
fix(workflow): enforce domain state machine in dual validation path
...
validate_as_red/blue_lead now delegate to TestEntity. check_dual_validation routes through entity instead of assigning test.state directly. Side effects dispatched via domain events. Entity raises InvalidOperationError for backward compat. Removed 4 dead V1 xfail tests, fixed 2 real test issues. 224 passed, 0 xfailed.
2026-02-18 15:49:59 +01:00
576705d61d
refactor(workflow): delegate start_execution to TestEntity
...
Replace manual state+field mutation with entity.start_execution() and apply_to(), keeping audit logging and notifications at the service layer.
2026-02-18 15:29:36 +01:00
9e204b78ec
test: add TestEntity tests and fix test infrastructure (222 green)
...
- Add test_test_entity.py with 46 pure unit tests covering the full domain entity
- Fix _FakeSettings in 11 test files (REPORT_TEMPLATES_DIR, JIRA, TEMPO)
- Fix stale db.commit assertions to db.flush after UoW refactor
- Add missing mock fields for TestEntity.from_orm compatibility
- Make database.py skip pool args for SQLite in test environment
- Disable slowapi rate limiter in test client fixture
- Inject test engine into app.database to fix threading errors
- Update role assertions to match current require_any_role policy
- Mark 6 legacy V1 endpoint tests as xfail (replaced by V2 workflow)
2026-02-18 15:29:24 +01:00