## Summary - harden findings and finding-exception Filament surfaces so workflow state, governance validity, overdue urgency, and next action are operator-first - add tenant stats widgets, segmented tabs, richer governance warnings, and baseline/dashboard attention propagation for overdue and lapsed governance states - add Spec 166 artifacts plus regression coverage for findings, badges, baseline summaries, tenantless operation viewer behavior, and critical table standards ## Verification - `vendor/bin/sail bin pint --dirty --format agent` - `vendor/bin/sail artisan test --compact` ## Filament Notes - Livewire v4.0+ compliance: yes, implementation stays on Filament v5 / Livewire v4 APIs only - Provider registration: unchanged, Laravel 12 panel/provider registration remains in `bootstrap/providers.php` - Global search: unchanged in this slice; `FindingExceptionResource` stays not globally searchable, no new globally searchable resource was introduced - Destructive actions: existing revoke/reject/approve/renew/workflow mutations remain capability-gated and confirmation-gated where already defined - Asset strategy: no new assets added; existing deploy process remains unchanged, including `php artisan filament:assets` when registered assets are used - Testing plan delivered: findings list/detail, exception register, dashboard attention, baseline summary, badge semantics, and tenantless operation viewer coverage Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de> Reviewed-on: #197
82 lines
3.2 KiB
PHP
82 lines
3.2 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Support\Baselines;
|
|
|
|
use App\Support\Ui\OperatorExplanation\ExplanationFamily;
|
|
use App\Support\Ui\OperatorExplanation\TrustworthinessLevel;
|
|
|
|
enum BaselineCompareReasonCode: string
|
|
{
|
|
case NoSubjectsInScope = 'no_subjects_in_scope';
|
|
case CoverageUnproven = 'coverage_unproven';
|
|
case EvidenceCaptureIncomplete = 'evidence_capture_incomplete';
|
|
case RolloutDisabled = 'rollout_disabled';
|
|
case NoDriftDetected = 'no_drift_detected';
|
|
case OverdueFindingsRemain = 'overdue_findings_remain';
|
|
case GovernanceExpiring = 'governance_expiring';
|
|
case GovernanceLapsed = 'governance_lapsed';
|
|
|
|
public function message(): string
|
|
{
|
|
return match ($this) {
|
|
self::NoSubjectsInScope => 'No subjects were in scope for this comparison.',
|
|
self::CoverageUnproven => 'Coverage proof was missing or incomplete, so some findings were suppressed for safety.',
|
|
self::EvidenceCaptureIncomplete => 'Evidence capture was incomplete, so some drift evaluation may have been suppressed.',
|
|
self::RolloutDisabled => 'Full-content baseline compare is currently disabled by rollout configuration.',
|
|
self::NoDriftDetected => 'No drift was detected for in-scope subjects.',
|
|
self::OverdueFindingsRemain => 'Overdue findings still need action even though the latest compare did not produce new drift.',
|
|
self::GovernanceExpiring => 'Accepted-risk governance is nearing expiry and needs review.',
|
|
self::GovernanceLapsed => 'Accepted-risk governance has lapsed and needs follow-up.',
|
|
};
|
|
}
|
|
|
|
public function explanationFamily(): ExplanationFamily
|
|
{
|
|
return match ($this) {
|
|
self::NoDriftDetected => ExplanationFamily::NoIssuesDetected,
|
|
self::CoverageUnproven,
|
|
self::EvidenceCaptureIncomplete,
|
|
self::RolloutDisabled,
|
|
self::OverdueFindingsRemain,
|
|
self::GovernanceExpiring,
|
|
self::GovernanceLapsed => ExplanationFamily::CompletedButLimited,
|
|
self::NoSubjectsInScope => ExplanationFamily::MissingInput,
|
|
};
|
|
}
|
|
|
|
public function trustworthinessLevel(): TrustworthinessLevel
|
|
{
|
|
return match ($this) {
|
|
self::NoDriftDetected => TrustworthinessLevel::Trustworthy,
|
|
self::CoverageUnproven,
|
|
self::EvidenceCaptureIncomplete,
|
|
self::OverdueFindingsRemain,
|
|
self::GovernanceExpiring,
|
|
self::GovernanceLapsed => TrustworthinessLevel::LimitedConfidence,
|
|
self::RolloutDisabled,
|
|
self::NoSubjectsInScope => TrustworthinessLevel::Unusable,
|
|
};
|
|
}
|
|
|
|
public function absencePattern(): ?string
|
|
{
|
|
return match ($this) {
|
|
self::NoDriftDetected => 'true_no_result',
|
|
self::CoverageUnproven,
|
|
self::EvidenceCaptureIncomplete,
|
|
self::OverdueFindingsRemain,
|
|
self::GovernanceExpiring,
|
|
self::GovernanceLapsed => 'suppressed_output',
|
|
self::RolloutDisabled => 'blocked_prerequisite',
|
|
self::NoSubjectsInScope => 'missing_input',
|
|
};
|
|
}
|
|
|
|
public function supportsPositiveClaim(): bool
|
|
{
|
|
return $this === self::NoDriftDetected;
|
|
}
|
|
}
|