Repository navigation
feat: add displaying of evidence subjects, and support for selecting … - #320
Conversation
…subject on evidence
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (32)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It is a broad, multi-view feature whose correctness depends on unverifiable API contracts (/api/subjects, /api/evidence/config) and subtle subject-replacement semantics on evidence re-submission, warranting human review.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
This PR adds first-class support for evidence subjects (what a piece of evidence is about) across the evidence UI, plus related admin-side configuration for subject templates. Subjects are displayed on the evidence list, the evidence detail page, and can be picked when creating/updating evidence and used as a list filter. A shared useSubjectSearch composable talks to GET /api/subjects, and feature detection gracefully hides all subject UI on older APIs that don't return subjects. The PR also extracts link-sanitization helpers into src/utils/links.ts and adds displayPriority/componentType to subject templates.
Changes:
- New subject types/helpers (
src/types/subjects.ts),useSubjectSearch/useEvidenceConfigcomposables, and components (SubjectPicker,SubjectFilter,SubjectsSection) wired into evidence Index/View/Create/Update views andEvidenceList. - Subject-based list filtering via a
?subject=<uuid>route param, plus optional "manual subject required" validation driven byGET /api/evidence/config. - Subject-template admin additions (
displayPriority,componentType) with payload normalization, and extraction ofnormalizeLinkHref/isInternalLink/getSafeExternalHrefinto a testedutils/links.ts.
| File | Description |
|---|---|
| src/types/subjects.ts | New subject summary type + subjectSource/subjectTemplate/describeSubject helpers (one unused). |
| src/types/subject-templates.ts | Adds component-type options, display-priority normalization, and payload fields. |
| src/stores/evidence.ts | Adds DeclaredSubject and optional subjectReferences to Evidence. |
| src/composables/subjects/useSubjectSearch.ts | Search/lookup against /api/subjects with 404→unsupported detection. |
| src/composables/evidence/useEvidenceConfig.ts | Reads manualSubjectRequired from /api/evidence/config. |
| src/components/evidence/SubjectPicker.vue | Multi-select subject picker with per-SSP narrowing. |
| src/components/evidence/SubjectFilter.vue | Single-subject list filter autocomplete. |
| src/components/evidence/SubjectsSection.vue | Renders evidence subjects with linked-SSP details and safe links. |
| src/components/EvidenceList.vue | New Subjects column with chips, "+N more" popover, and Unattributed state. |
| src/views/evidence/IndexView.vue | Subject route filter sync, capability detection, and search param. |
| src/views/evidence/ViewView.vue | Subjects card beside Current State; imports extracted link helpers. |
| src/views/evidence/CreateView.vue, UpdateView.vue | Pass picked subjects into the evidence submit payload. |
| src/views/evidence/partial/EvidenceForm.vue | Subject picker + required-subject validation and emit. |
| src/views/admin/SubjectTemplatesView.vue, SubjectTemplateDetailView.vue | Display-priority and component-type form/detail fields. |
| src/utils/links.ts | Extracted, now-shared link normalization/sanitization helpers. |
| src/**/__tests__/*.spec.ts, *.spec.ts | Extensive new unit tests for the above. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
added size-exception label as this PR was created before the review standardization. |
- SubjectPicker: only fetch the SSP list (and show the SSP dropdown) when the user can read SSPs, so evidence submitters without ssp:read don't get a 403 toast. - useSubjectSearch: ignore search responses that resolve after a newer search, so stale results can't replace the current suggestions. - Add CreateView and UpdateView specs asserting the POST body carries the picked subjects as subjects[].subject-uuid, replacing the previous revision's subjects. - Remove the unused subjectTemplate() helper. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

…subject on evidence
Summary by CodeRabbit