Milestone 18g: STIG Library (benchmark list + detail + Rule/CCI lookup + XCCDF import) - #35
Merged
Conversation
…p + XCCDF import) Co-Authored-By: Bryce Anglin <brycemanglin@gmail.com>
Contributor
Author
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replaces the M18g
/librarystub with a real STIG Library workspace and ships the XCCDF Benchmark import flow.New routes / pages
/library(<LibraryListPage/>) — searchable list of every imported benchmark (title contains, 200ms debounce), with per-row link to the detail page and a delete affordance forstig-manager:stig. Two right-rail cards: Rule lookup (pasteSV-…r1_rule) and CCI lookup (paste000366orCCI-000366). Lookups hit the per-id API endpoints and render the projection inline with collapsible Vulnerability Discussion / Check / Fix sections./library/:benchmarkId(<LibraryDetailPage/>) — metadata projection (benchmark id, latest revision, revision date, rule count, marking, status) + revisions list.<ImportStigDialog/>) — multipart upload of a DISA XCCDF file with optional clobber. Wired off the navbar's Library entry for any caller holdingstig-manager:stig.API client (
web/src/lib/api/index.ts)STIGSummary,STIGDetail,STIGsFilter,RuleDetail,CciDetail,ImportBenchmarkInput,ImportBenchmarkResult.fetchSTIGs / fetchSTIG / fetchRuleByRuleId / fetchCci / importBenchmark / deleteSTIG.importBenchmarkis a barefetch()(not the openapi-fetch client) because the typed client's multipart binding adds more friction than value for one endpoint; auth + base URL + filename extraction follow the same helpersfetchBlobalready uses.TanStack Query hooks (
web/src/lib/api/hooks.ts)QUERY_KEYS:stigs / stig / rule / cci. New hooks:useSTIGs / useSTIG / useRuleByRuleId / useCci / useImportBenchmark / useDeleteSTIG. Lookup hooks passretry: falseso 404s surface inline rather than spinning forever.Playwright (
e2e/tests/web.spec.ts)Roadmap: every milestone through 18 is now at least In Review. M18g completes the SPA build-out of every implemented backend surface. The remaining unimplemented endpoints (per-revision rule/group listings,
/stigs/scap-maps) are out of scope for the UI until those backend handlers are wired offUnimplemented.Review & Testing Checklist for Human
admin; navigate to/library. The page renders with an empty benchmark list, both lookup cards on the right, and an Import XCCDF button in the header.xccdf/*.xmlfiles in theapi/internal/xccdf/testdatacorpus). Submit. A success card should render with the inserted benchmarkId + revision. The benchmark should then appear in the list table when the dialog closes./library/:benchmarkId. Metadata + revisions list render.SV-258243r958459_rulefrom RHEL 9). Confirm title, severity, version, Vulnerability Discussion, Check, Fix, and CCIs render.000366. Confirm definition + status + type render.evaluator./libraryis still visible (reads), but the Import XCCDF button and per-row delete buttons are hidden.Notes
/stigs/{benchmarkId}/revisions/{revisionStr}/rules(and siblings) which are stillUnimplemented501s on the backend.useRuleByRuleIdanduseCciboth setretry: false. A typo in a rule ID surfaces a clean error inline rather than three exponential-backoff retries.Link to Devin session: https://app.devin.ai/sessions/022810763c4643c0848ba894c1512b92
Requested by: @Exonical