Skip to content

Milestone 18g: STIG Library (benchmark list + detail + Rule/CCI lookup + XCCDF import) - #35

Merged
Exonical merged 1 commit into
mainfrom
devin/1779466224-milestone-18g-stig-library
May 22, 2026
Merged

Exonical merged 1 commit into
mainfrom
devin/1779466224-milestone-18g-stig-library

Conversation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Summary

Replaces the M18g /library stub with a real STIG Library workspace and ships the XCCDF Benchmark import flow.

New routes / pages

  • /library (<LibraryListPage/>) — searchable list of every imported benchmark (title contains, 200ms debounce), with per-row link to the detail page and a delete affordance for stig-manager:stig. Two right-rail cards: Rule lookup (paste SV-…r1_rule) and CCI lookup (paste 000366 or CCI-000366). Lookups hit the per-id API endpoints and render the projection inline with collapsible Vulnerability Discussion / Check / Fix sections.
  • /library/:benchmarkId (<LibraryDetailPage/>) — metadata projection (benchmark id, latest revision, revision date, rule count, marking, status) + revisions list.
  • Import dialog (<ImportStigDialog/>) — multipart upload of a DISA XCCDF file with optional clobber. Wired off the navbar's Library entry for any caller holding stig-manager:stig.

API client (web/src/lib/api/index.ts)

  • New types: STIGSummary, STIGDetail, STIGsFilter, RuleDetail, CciDetail, ImportBenchmarkInput, ImportBenchmarkResult.
  • New fetch fns: fetchSTIGs / fetchSTIG / fetchRuleByRuleId / fetchCci / importBenchmark / deleteSTIG.
  • importBenchmark is a bare fetch() (not the openapi-fetch client) because the typed client's multipart binding adds more friction than value for one endpoint; auth + base URL + filename extraction follow the same helpers fetchBlob already uses.

TanStack Query hooks (web/src/lib/api/hooks.ts)

  • New QUERY_KEYS: stigs / stig / rule / cci. New hooks: useSTIGs / useSTIG / useRuleByRuleId / useCci / useImportBenchmark / useDeleteSTIG. Lookup hooks pass retry: false so 404s surface inline rather than spinning forever.

Playwright (e2e/tests/web.spec.ts)

  • 4 new tests bringing the suite to 29/29: library landing renders with both lookup cards + Import button, Rule lookup surfaces the API's 404 inline, CCI lookup surfaces the API's 404 inline, Import dialog opens with all controls and disables Submit until a file is chosen.

Roadmap: every milestone through 18 is now at least In Review. M18g completes the SPA build-out of every implemented backend surface. The remaining unimplemented endpoints (per-revision rule/group listings, /stigs/scap-maps) are out of scope for the UI until those backend handlers are wired off Unimplemented.

Review & Testing Checklist for Human

  • Sign in as admin; navigate to /library. The page renders with an empty benchmark list, both lookup cards on the right, and an Import XCCDF button in the header.
  • Click Import XCCDF, choose a real DISA XCCDF file (any benchmark export will work — e.g. one of the xccdf/*.xml files in the api/internal/xccdf/testdata corpus). Submit. A success card should render with the inserted benchmarkId + revision. The benchmark should then appear in the list table when the dialog closes.
  • After import, click the new row to reach /library/:benchmarkId. Metadata + revisions list render.
  • Rule lookup: paste a rule ID from a real STIG (e.g. SV-258243r958459_rule from RHEL 9). Confirm title, severity, version, Vulnerability Discussion, Check, Fix, and CCIs render.
  • CCI lookup: paste 000366. Confirm definition + status + type render.
  • Sign in as evaluator. /library is still visible (reads), but the Import XCCDF button and per-row delete buttons are hidden.

Notes

  • The library detail page does not yet drill into per-revision rule/group lists; that requires /stigs/{benchmarkId}/revisions/{revisionStr}/rules (and siblings) which are still Unimplemented 501s on the backend.
  • useRuleByRuleId and useCci both set retry: false. A typo in a rule ID surfaces a clean error inline rather than three exponential-backoff retries.

Link to Devin session: https://app.devin.ai/sessions/022810763c4643c0848ba894c1512b92
Requested by: @Exonical

…p + XCCDF import)

Co-Authored-By: Bryce Anglin <brycemanglin@gmail.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

@Exonical
Exonical merged commit aafa0c0 into main May 22, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant