TenantAtlas/app/Services/Baselines/Evidence/ResolvedEvidence.php
ahmido f08924525d Spec 117: Baseline Drift Engine + evidence fidelity/provenance (#142)
Implements Spec 117 (Golden Master Baseline Drift Engine):

- Adds provider-chain resolver for current state hashes (content evidence via PolicyVersion, meta evidence via inventory)
- Updates baseline capture + compare jobs to use resolver and persist provenance + fidelity
- Adds evidence_fidelity column/index + Filament UI badge/filter/provenance display for findings
- Adds performance guard test + integration tests for drift, fidelity semantics, provenance, filter behavior
- UX fix: Policies list shows "Sync from Intune" header action only when records exist; empty-state CTA remains and is functional

Tests:
- `vendor/bin/sail artisan test --compact tests/Feature/Filament/PolicySyncCtaPlacementTest.php`
- `vendor/bin/sail artisan test --compact --filter=Baseline`

Checklist:
- specs/117-baseline-drift-engine/checklists/requirements.md ✓

Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de>
Reviewed-on: #142
2026-03-03 07:23:01 +00:00

59 lines
1.4 KiB
PHP

<?php
declare(strict_types=1);
namespace App\Services\Baselines\Evidence;
use Carbon\CarbonImmutable;
final class ResolvedEvidence
{
/**
* @param array<string, mixed> $meta
*/
public function __construct(
public readonly string $policyType,
public readonly string $subjectExternalId,
public readonly string $hash,
public readonly string $fidelity,
public readonly string $source,
public readonly ?CarbonImmutable $observedAt,
public readonly ?int $observedOperationRunId = null,
public readonly array $meta = [],
) {}
public function key(): string
{
return $this->policyType.'|'.$this->subjectExternalId;
}
/**
* @return array{
* fidelity: string,
* source: string,
* observed_at: ?string,
* observed_operation_run_id: ?int
* }
*/
public function provenance(): array
{
return EvidenceProvenance::build(
fidelity: $this->fidelity,
source: $this->source,
observedAt: $this->observedAt,
observedOperationRunId: $this->observedOperationRunId,
);
}
/**
* @return array{hash: string, provenance: array<string, mixed>}
*/
public function toFindingSideEvidence(): array
{
return [
'hash' => $this->hash,
'provenance' => $this->provenance(),
];
}
}