TenantAtlas/app/Services/Baselines/Evidence/ResolvedEvidence.php
ahmido 92704a2f7e Spec 118: Resumable baseline evidence capture + snapshot UX (#143)
Implements Spec 118 baseline drift engine improvements:

- Resumable, budget-aware evidence capture for baseline capture/compare runs (resume token + UI action)
- “Why no findings?” reason-code driven explanations and richer run context panels
- Baseline Snapshot resource (list/detail) with fidelity visibility
- Retention command + schedule for pruning baseline-purpose PolicyVersions
- i18n strings for Baseline Compare landing

Verification:
- `vendor/bin/sail bin pint --dirty --format agent`
- `vendor/bin/sail artisan test --compact --filter=Baseline` (159 passed)

Note:
- `docs/audits/redaction-audit-2026-03-04.md` left untracked (not part of PR).

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #143
2026-03-04 22:34:13 +00:00

71 lines
1.8 KiB
PHP

<?php
declare(strict_types=1);
namespace App\Services\Baselines\Evidence;
use Carbon\CarbonImmutable;
final class ResolvedEvidence
{
/**
* @param array<string, mixed> $meta
*/
public function __construct(
public readonly string $policyType,
public readonly string $subjectExternalId,
public readonly string $hash,
public readonly string $fidelity,
public readonly string $source,
public readonly ?CarbonImmutable $observedAt,
public readonly ?int $observedOperationRunId = null,
public readonly array $meta = [],
) {}
public function key(): string
{
return $this->policyType.'|'.$this->subjectExternalId;
}
/**
* @return array{
* fidelity: string,
* source: string,
* observed_at: ?string,
* observed_operation_run_id: ?int
* }
*/
public function provenance(): array
{
return EvidenceProvenance::build(
fidelity: $this->fidelity,
source: $this->source,
observedAt: $this->observedAt,
observedOperationRunId: $this->observedOperationRunId,
);
}
/**
* Tenant-scoped provenance including additional metadata (e.g. policy_version_id).
*
* Do NOT use this for workspace-owned baseline snapshot items.
*
* @return array<string, mixed>
*/
public function tenantProvenance(): array
{
return array_merge($this->provenance(), $this->meta);
}
/**
* @return array{hash: string, provenance: array<string, mixed>}
*/
public function toFindingSideEvidence(): array
{
return [
'hash' => $this->hash,
'provenance' => $this->tenantProvenance(),
];
}
}