Commit Graph

32 Commits

Author SHA1 Message Date
GraceSolutions 409ae42bc7 feat(dashboard): add aggregated dashboard summary endpoint
New DashboardService aggregates entity counts (rules, connections, credentials, schedules, users, api keys), rolling rule-run statistics (last 24h and 7d), the 10 most recent rule runs, and per-connection health based on last_tested_utc/last_test_result. Exposed via GET /api/v1/dashboard/summary and wired through server.Dependencies + cli.RunForeground.
2026-04-23 13:22:04 -04:00
GraceSolutions 99a0589a2c feat(settings): add CRUD API for the app_settings key-value store
New SettingsService provides List/Get/Upsert/Delete over the app_settings table. SettingsHandler exposes GET /api/v1/settings, GET/PUT/DELETE /api/v1/settings/{key} and redacts sensitive values in responses. Changes are recorded as ConfigChange audit events. The service is wired into server.Dependencies and constructed in cli.RunForeground.
2026-04-23 13:19:18 -04:00
GraceSolutions e8556b3c16 feat(audit): expose read-only audit event query API
Add Filter-based List and GetByID methods to audit.Service backed by a shared rowScanner so both sql.Row and sql.Rows can be decoded into an Event. Add a new AuditHandler with GET /api/v1/audit and GET /api/v1/audit/{id} wired into the router. Filters accepted via query string: eventType, userId, username, resourceType, resourceId, action, success, startUtc, endUtc.
2026-04-23 13:17:50 -04:00
GraceSolutions 8cb09a7086 fix(cli): instantiate audit.Service and include it in server.Dependencies
Previously the audit service was never constructed, so every emitAudit call across the handlers was a silent no-op. Build an audit.Service in RunForeground, add it to the Dependencies struct, and log a ServiceStart event on startup so the audit trail is bootstrapped.
2026-04-23 13:16:25 -04:00
GraceSolutions 2a6df8e874 feat(audit): integrate audit logging across management API handlers
Introduce a shared audit_helpers.emitAudit utility that extracts user identity, IP, and User-Agent from the request context and forwards events to audit.Service. Wire an auditService dependency into all management handlers (auth, credentials, connections, schedules, rules, backups, api-keys, users) and emit audit events for login, CRUD, test, preview, run, backup, restore, API key create/revoke, and user lifecycle operations. Both successful and failed paths log with appropriate event types, resource IDs, and sanitized detail maps.
2026-04-23 12:52:20 -04:00
GraceSolutions d8f45fe863 feat(connections): add LDAP query preview endpoint
- New ConnectionService.QueryPreview runs an ad-hoc LDAP search against an
  existing AD connection. Caller supplies filter, optional baseDn (defaults
  to the connection's rootDn), scope, attributes, and limit (capped at 500,
  defaulting to 100) and gets back the matched entries as DN + attribute map
  along with a truncated flag.
- Scope strings are mapped through goldap.Scope* constants so base, one,
  and sub values all work.
- Wire POST /api/v1/ad-connections/{id}/query-preview to
  ConnectionsHandler.QueryPreview and require a non-empty filter.
2026-04-23 12:41:49 -04:00
GraceSolutions 958f2bf501 feat(credentials): add credential test endpoint
- New CredentialService.Test method that decrypts the stored secret and
  performs an LDAP bind against a user-supplied host/port/TLS target.
- Persists the outcome on the credential via UpdateTestResult so the
  last_tested_utc and last_test_result columns stay current.
- Wire POST /api/v1/credentials/{id}/test to CredentialsHandler.Test,
  which accepts the connection parameters in the request body and maps
  'credential not found' to 404.
2026-04-23 12:39:06 -04:00
GraceSolutions 29a8a0b503 feat(backups): add database backup and restore endpoints
- New BackupsHandler exposing list, create, and restore over
  /api/v1/backups, backed by services.BackupService.
- Create records who triggered the backup (username from context or
  'api') and defaults the backup type to 'manual'.
- Restore resolves the {id} path parameter against the list of available
  backups so clients can reference backups by filename, or pass an
  explicit filePath in the body.
- Inject BackupService via server.Dependencies and initialize it in
  cli.RunForeground under <DataPath>/backups with retention 10.
2026-04-23 12:37:31 -04:00
GraceSolutions 76469eb401 feat(api-keys): add API key administration endpoints
- New APIKeysHandler exposing list, create, revoke, and delete over
  /api/v1/api-keys, backed by services.APIKeyService.
- Create returns the full plaintext key once; list/get responses only
  surface the prefix and metadata.
- When userId is omitted, the handler falls back to the authenticated
  principal pulled from context so callers can self-service tokens.
- Inject APIKeyService via server.Dependencies and initialize it in
  cli.RunForeground.
2026-04-23 12:36:06 -04:00
GraceSolutions 8b3cf48bba feat(users): add user administration CRUD endpoints
- Add UserRepository.List with pagination and non-deleted filtering.
- New UsersHandler with List/Get/Create/Update/Delete; Create hashes
  passwords via crypto.HashPassword and Update re-hashes on rotation.
- Responses omit password material; username conflict returns 409.
- Inject UserRepo via server.Dependencies and wire /api/v1/users routes.
2026-04-23 12:34:19 -04:00
GraceSolutions a4473ba77e feat(api): wire live auth and credentials handlers
- Extend server.Dependencies with AuthService and CredService, and
  initialize them in cli.RunForeground using the derived AES key.
- Replace the handleNotImplemented stubs on /auth and /credentials with
  the existing AuthHandler and CredentialsHandler routes.
- Guard /auth/me behind api.AuthMiddleware so it only resolves when a
  valid session token is presented.
2026-04-23 12:32:13 -04:00
GraceSolutions 6a044dcb1b feat(rule-runs): expose rule execution history endpoints
- Add RuleRunRepository.List for paging across runs regardless of rule.
- New RuleRunsHandler with List/Get/ListByRule, returning run summaries
  and per-action detail via RuleRunDetailResponse.
- Register GET /api/v1/rule-runs, GET /api/v1/rule-runs/{runId}, and
  GET /api/v1/rules/{id}/runs.
2026-04-23 12:30:40 -04:00
GraceSolutions 1c50828b9c feat(schedules): add full CRUD endpoints for schedule resource
- New SchedulesHandler backed by the existing ScheduleRepository, with
  request/response DTOs matching the schedules model (kind, easy/cron,
  timezone mode).
- Register List/Get/Create/Update/Delete routes on /api/v1/schedules.
- Extend server.Dependencies with ScheduleRepo and wire it from
  cli.RunForeground.
2026-04-23 12:29:19 -04:00
GraceSolutions 6af0ffff9d feat(connections): wire full CRUD endpoints for AD connections
- Add Create/Update/Delete handlers on ConnectionsHandler backed by the
  existing ConnectionRepository (soft-delete preserves audit history).
- Register List/Get/Create/Update/Delete/Test routes on /ad-connections
  so the resource is no longer stubbed out.
2026-04-23 12:27:59 -04:00
GraceSolutions c117d6d546 feat(rules): complete CRUD endpoints for rules resource
- Extend RuleRepository with List/Update/SoftDelete/UpdateEnabled and
  upsert helpers for condition groups, conditions, and actions.
- Extend RuleService with Create/GetByID/List/Update/Delete/Enable/Disable.
- Add List/Get/Create/Update/Delete/Enable/Disable handlers on RulesHandler
  with request/response DTOs that decouple the API from storage models.
- Register the full CRUD route set on /api/v1/rules.
- Inject RuleService into server.Dependencies from cli.RunForeground.
2026-04-23 12:26:50 -04:00
GraceSolutions 5e67d48f34 test(rules): add unit tests for variable expansion and engine helpers
Covers Expander.Expand / ExpandStrict behaviour for object, rule, custom,
and now sources, including error paths and template listing. Covers engine
helpers resolveBaseDN, resolveScope, collectAttributes, buildConditionGroups,
and parentDN.
2026-04-23 12:18:12 -04:00
GraceSolutions 807b95e92a feat(api): add rule preview and run endpoints
Adds RulesHandler exposing POST /api/v1/rules/{id}/preview and
POST /api/v1/rules/{id}/run. Preview returns the generated LDAP filter,
matched objects, and planned actions. Run triggers an immediate execution
via the Runner using the X-Triggered-By header (defaults to 'api').

Also adds Runner.PreviewRule so the handler can delegate without having to
load the rule, connection, and LDAP client itself.
2026-04-23 12:16:37 -04:00
GraceSolutions 2376daf91c feat(startup): wire runner, engine, and scheduler into foreground mode
Derives a 32-byte AES key from the configured secret via SHA-256, constructs
the ConnectionService, Runner, and Engine, and starts the Scheduler so
enabled rules fire automatically. Injects the shared services into the HTTP
server via a new Dependencies struct so API handlers can reuse them.
2026-04-23 12:14:50 -04:00
GraceSolutions bca862ca01 feat(rules): implement end-to-end rule execution pipeline
- Add engine.Execute() that searches AD, iterates matches, runs actions,
  honors StopOnError and PreviewOnly, and supports context cancellation
- Resolve base DN and search scope from rule override then connection defaults
- Add actionExecutor covering AddToGroup, AddGroupToGroup, EnsureGroupExists,
  MoveToOu, and RemoveFromGroupIfNoLongerMatched with dynamic DN expansion
- Add RuleRunRepository persisting rule_runs and rule_run_actions
- Add Runner coordinator that loads rule+connection, builds an LDAP client,
  invokes the engine, and records the run + per-action outcomes
- Expose ConnectionService.BuildClient / BuildLDAPConfig for reuse
- Scheduler now accepts a RuleRunner and invokes it when a scheduled rule fires
2026-04-23 12:12:59 -04:00
GraceSolutions 8986fc9325 chore: Flatten frontend, remove figma/docs (88MB saved)
- Moved main package contents to frontend root
- Removed figma-file directory (88MB)
- Removed docs directory
- Removed unused package variants
2026-04-19 10:22:23 -04:00
GraceSolutions 9acf3b8289 Merge commit '1652dad4f7b69d8375596d27e514513e4a970470' as 'frontend' 2026-04-19 10:20:39 -04:00
GraceSolutions 1652dad4f7 Squashed 'frontend/' content from commit dd8b361
git-subtree-dir: frontend
git-subtree-split: dd8b361b4469f8656dba9b8c4ecf65689a64f975
2026-04-19 10:20:39 -04:00
GraceSolutions 65dc1e15a4 chore: Remove scaffold frontend, will use Spike template via subtree 2026-04-19 10:20:24 -04:00
GraceSolutions 46fc0409ad feat: Add Next.js 14 frontend scaffold
- Next.js 14 with App Router
- TypeScript strict mode
- Tailwind CSS with dark mode support
- React Query for server state
- NextAuth.js integration ready
- Dashboard layout with sidebar navigation
- API client with error handling
- Core type definitions for all entities
- Utility functions for dates and classnames
2026-04-19 10:19:40 -04:00
GraceSolutions 148841d77c feat: Add credentials and connections API handlers 2026-04-19 10:16:44 -04:00
GraceSolutions 7b574db88c feat: Add variable expansion, API key service, and validation 2026-04-19 10:15:23 -04:00
GraceSolutions 060094ce7a feat: Add rule engine, services, and business logic
- Rule engine with preview and condition evaluation
- LDAP filter generation from rule conditions
- Connection service with full test workflow
- Credential service with encryption/decryption
- Rule service with validation
- Backup service with retention management
- Integration between services and repositories
2026-04-19 10:13:29 -04:00
GraceSolutions 4e6ed52e51 feat: Add API handlers, LDAP client, and repositories
- API response helpers and error codes
- Authentication handlers (login, logout, me, csrf)
- Auth middleware (session validation, role checks, CSRF)
- LDAP client with TLS/StartTLS support
- LDAP filter construction from conditions
- AD operations (group membership, move, create group/OU)
- Credentials repository (CRUD, test results, usage check)
- AD connections repository (CRUD, test results)
- Schedules repository (CRUD, next run tracking)
- Rules repository with nested condition groups and actions
- go-ldap/ldap/v3 dependency added
2026-04-19 10:11:16 -04:00
GraceSolutions 09a09d4a68 feat: Initial backend scaffold - Go service, database, CLI, API structure
Phase 1 foundations:
- Go backend with Chi router framework
- SQLite database with WAL mode and foreign keys
- Database migrations for users, roles, credentials, AD connections, schedules, rules, and audit
- CLI commands: init, run, install, uninstall, start, stop, migrate, backup, restore, doctor
- Configuration loading from environment variables
- Centralized logging with file rotation (lumberjack)
- Crypto package for Argon2id password hashing and AES-GCM encryption
- Auth service with session management
- Audit service for event logging
- Scheduler with 6-field cron support
- REST API routes scaffolded for all major resources
- CORS support with localhost defaults for development
- Docker support with Dockerfile and docker-compose.yml
- Multi-platform build script (PowerShell)
- Project structure per design specification

Version format: yyyy.MM.dd.HHmm
All PKs are UUIDv4, all timestamps UTC
2026-04-19 10:07:21 -04:00
freedbygrace efe9f76812 Rename project to OrchestrAD and enhance README
Updated project name and provided detailed overview and features.
2026-04-15 15:24:52 -04:00
GraceSolutions 617a849457 Add Design Specifications
Add the main, and template design specifications.
2026-04-15 14:51:53 -04:00
GraceSolutions 91088d748a Initial commit 2026-04-15 14:23:32 -04:00