Documentation
¶
Overview ¶
Package threatmodel exports a sas.Architecture as the system-under-analysis for github.com/grokify/threat-model-spec: a DFD (data flow diagram) of components, boundaries, and flows, so a threat model never re-describes the system it analyzes. Threat reasoning — attacks, STRIDE threats, mitigations, detections, response actions — is intentionally not exported; that stays in Threat Model Spec, which references SAS IDs directly since Export preserves them unchanged.
SAS does not take a Go module dependency on threat-model-spec. The types here are a narrow, local mirror of the fields threat-model-spec's schema/diagram.schema.json (DiagramIR) actually requires from a system-under-analysis, verified against that schema directly, so Export's output is valid (a subset of) a DiagramIR document without importing threat-model-spec's Go types.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Boundary ¶
type Boundary struct {
ID string `json:"id"`
Label string `json:"label"`
Type string `json:"type"`
}
Boundary mirrors threat-model-spec's Boundary: a trust or network boundary (browser, localhost, network, cloud, breached, container, sandbox, agent, or origin).
type DiagramIR ¶
type DiagramIR struct {
// Type is always "dfd": SAS's static architecture model maps
// naturally onto a data flow diagram, not an attack-chain, sequence,
// or attack-tree diagram.
Type string `json:"type"`
Title string `json:"title"`
Description string `json:"description,omitempty"`
Elements []Element `json:"elements,omitempty"`
Boundaries []Boundary `json:"boundaries,omitempty"`
Flows []Flow `json:"flows,omitempty"`
}
DiagramIR mirrors the system-under-analysis fields of threat-model-spec's DiagramIR: type, title, elements, boundaries, and flows. Threat-modeling fields (attacks, threats, mitigations, detections, responseActions, actors, phases, messages, attackTree) are out of scope for this bridge and therefore absent from this type.
func Export ¶
func Export(arch *sas.Architecture) DiagramIR
Export translates arch into a DiagramIR system-under-analysis. Every element, boundary, and flow ID is preserved unchanged from the SAS document, so a threat model built from this export can reference SAS IDs directly.
type Element ¶
type Element struct {
ID string `json:"id"`
Label string `json:"label"`
Type string `json:"type"`
ParentID string `json:"parentId,omitempty"`
}
Element mirrors threat-model-spec's Element: a component in the diagram (process, datastore, external-entity, gateway, browser, agent, or api).
type Flow ¶
type Flow struct {
From string `json:"from"`
To string `json:"to"`
Label string `json:"label,omitempty"`
Type string `json:"type,omitempty"`
Protocol string `json:"protocol,omitempty"`
Encrypted *bool `json:"encrypted,omitempty"`
Authenticated *bool `json:"authenticated,omitempty"`
}
Flow mirrors threat-model-spec's Flow: a directed edge between elements.