Files
shopdb-flask/plugins/geenforce/models/__init__.py
cproudlock 6dc31c6149
All checks were successful
CI / backend (push) Successful in 1m37s
CI / naming (push) Successful in 1s
CI / frontend (push) Successful in 8s
Add GE-Enforce observed-state reporting: receipt + self-heal from PCs
PCs now report enforcement results back to shopdb, closing the desired-vs-observed
loop.

- POST /api/geenforce/report (geenforce.report service token): each cycle a PC
  posts the published version it applied, install/skip/fail/filtered counts, and
  per-entry outcomes.
- Two tables: manifestenforcementreports (latest-per-host + history: applied
  version, enforcer version, counts, derived status ok/selfhealed/failed) and
  manifestenforcementresults (per entry: action installed/skipped/failed,
  selfhealed flag, exit code, warning/error message).
- RECEIVED: reports carry the applied version; the admin view derives
  receivedlatest by comparing it to the scope's current published version, so
  the fleet view shows which PCs picked up an update.
- SELF-HEAL: per-entry action captures drift correction (installed when it
  should already be present) vs skipped (already good) vs failed, with messages.
- Admin reads: GET /reports (fleet compliance rollup) and GET /reports/<id>
  (per-entry detail). New geenforce.report permission.
- Tables added to the (undeployed) 0001 baseline; geenforce.post_report is a
  service-token endpoint so it is exempt from the JWT authz sweep, like the
  collector blueprint. 8 reporting tests; full suite green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 17:04:07 -04:00

46 lines
978 B
Python

"""GE-Enforce plugin models."""
from .manifest import (
ManifestScope,
ManifestEntry,
ManifestEntryPcType,
ManifestEntryHostname,
ManifestEntryMachineNumber,
ManifestInUseCheck,
ManifestInUseCheckProcess,
ManifestPublishedVersion,
ManifestPayload,
ManifestEnforcementReport,
ManifestEnforcementResult,
PcTypeAlias,
PHASES,
ENTRY_TYPES,
REG_TYPES,
PAYLOAD_SOURCES,
DETECTION_METHODS,
APPLY_MODES,
INUSE_BEHAVIORS,
)
__all__ = [
'ManifestScope',
'ManifestEntry',
'ManifestEntryPcType',
'ManifestEntryHostname',
'ManifestEntryMachineNumber',
'ManifestInUseCheck',
'ManifestInUseCheckProcess',
'ManifestPublishedVersion',
'ManifestPayload',
'ManifestEnforcementReport',
'ManifestEnforcementResult',
'PcTypeAlias',
'PHASES',
'ENTRY_TYPES',
'REG_TYPES',
'PAYLOAD_SOURCES',
'DETECTION_METHODS',
'APPLY_MODES',
'INUSE_BEHAVIORS',
]