@@ -23,10 +23,10 @@ import (
2323
2424// Graph represents a directed acyclic graph for dependency resolution.
2525type Graph struct {
26- nodes map [string ]bool
27- edges map [string ]map [string ]bool // edges[A][B] = true means A depends on B
28- reverse map [string ]map [string ]bool // reverse[B][A] = true means B is depended upon by A
29- ordered []string // insertion order for deterministic output
26+ nodes map [string ]bool
27+ edges map [string ]map [string ]bool // edges[A][B] = true means A depends on B
28+ reverse map [string ]map [string ]bool // reverse[B][A] = true means B is depended upon by A
29+ ordered []string // insertion order for deterministic output
3030}
3131
3232// New creates an empty graph.
@@ -240,8 +240,8 @@ func (g *Graph) Subgraph(nodes map[string]bool) *Graph {
240240
241241// dagJSON is the serialization format for ExportJSON.
242242type dagJSON struct {
243- Layers [][]string `json:"layers"`
244- Edges map [string ][]string `json:"edges"`
243+ Layers [][]string `json:"layers"`
244+ Edges map [string ][]string `json:"edges"`
245245}
246246
247247// ExportJSON exports the graph as JSON with layers and edges.
@@ -323,54 +323,69 @@ func FrameworkGraph() *Graph {
323323
324324 // Aliases for readability
325325 const (
326- parent = "fireflyframework-parent"
327- bom = "fireflyframework-bom"
328- kernel = "fireflyframework-kernel"
329- utils = "fireflyframework-utils"
330- validators = "fireflyframework-validators"
331- plugins = "fireflyframework-plugins"
332- cache = "fireflyframework-cache"
333- cacheRedis = "fireflyframework-cache-redis"
334- cacheHazelcast = "fireflyframework-cache-hazelcast"
335- cacheJCache = "fireflyframework-cache-jcache"
336- cachePostgres = "fireflyframework-cache-postgres"
337- r2dbc = "fireflyframework-r2dbc"
338- eda = "fireflyframework-eda"
339- edaKafka = "fireflyframework-eda-kafka"
340- edaRabbitMQ = "fireflyframework-eda-rabbitmq"
341- edaPostgres = "fireflyframework-eda-postgres"
342- cqrs = "fireflyframework-cqrs"
343- eventsourcing = "fireflyframework-eventsourcing"
344- orchestration = "fireflyframework-orchestration"
345- client = "fireflyframework-client"
346- web = "fireflyframework-web"
347- core = "fireflyframework-starter-core"
348- domain = "fireflyframework-starter-domain"
349- data = "fireflyframework-starter-data"
350- ecm = "fireflyframework-ecm"
351- ecmEsigAdobe = "fireflyframework-ecm-esignature-adobe-sign"
352- ecmEsigDocusign = "fireflyframework-ecm-esignature-docusign"
353- ecmEsigLogalty = "fireflyframework-ecm-esignature-logalty"
354- ecmStorageAWS = "fireflyframework-ecm-storage-aws"
355- ecmStorageAzure = "fireflyframework-ecm-storage-azure"
356- idp = "fireflyframework-idp"
357- idpCognito = "fireflyframework-idp-aws-cognito"
358- idpInternalDB = "fireflyframework-idp-internal-db"
359- idpKeycloak = "fireflyframework-idp-keycloak"
360- idpAzureAD = "fireflyframework-idp-azure-ad"
361- notifications = "fireflyframework-notifications"
362- notifFirebase = "fireflyframework-notifications-firebase"
363- notifResend = "fireflyframework-notifications-resend"
364- notifSendgrid = "fireflyframework-notifications-sendgrid"
365- notifTwilio = "fireflyframework-notifications-twilio"
366- ruleEngine = "fireflyframework-rule-engine"
367- webhooks = "fireflyframework-webhooks"
368- callbacks = "fireflyframework-callbacks"
369- configServer = "fireflyframework-config-server"
370- application = "fireflyframework-starter-application"
371- backoffice = "fireflyframework-backoffice"
372- observability = "fireflyframework-observability"
373- agenticBridge = "fireflyframework-agentic-bridge"
326+ parent = "fireflyframework-parent"
327+ bom = "fireflyframework-bom"
328+ kernel = "fireflyframework-kernel"
329+ utils = "fireflyframework-utils"
330+ validators = "fireflyframework-validators"
331+ plugins = "fireflyframework-plugins"
332+ cache = "fireflyframework-cache"
333+ cacheRedis = "fireflyframework-cache-redis"
334+ cacheHazelcast = "fireflyframework-cache-hazelcast"
335+ cacheJCache = "fireflyframework-cache-jcache"
336+ cachePostgres = "fireflyframework-cache-postgres"
337+ r2dbc = "fireflyframework-r2dbc"
338+ eda = "fireflyframework-eda"
339+ edaKafka = "fireflyframework-eda-kafka"
340+ edaRabbitMQ = "fireflyframework-eda-rabbitmq"
341+ edaPostgres = "fireflyframework-eda-postgres"
342+ cqrs = "fireflyframework-cqrs"
343+ eventsourcing = "fireflyframework-eventsourcing"
344+ orchestration = "fireflyframework-orchestration"
345+ client = "fireflyframework-client"
346+ web = "fireflyframework-web"
347+ core = "fireflyframework-starter-core"
348+ domain = "fireflyframework-starter-domain"
349+ data = "fireflyframework-starter-data"
350+ ecm = "fireflyframework-ecm"
351+ ecmEsigAdobe = "fireflyframework-ecm-esignature-adobe-sign"
352+ ecmEsigDocusign = "fireflyframework-ecm-esignature-docusign"
353+ ecmEsigLogalty = "fireflyframework-ecm-esignature-logalty"
354+ ecmStorageAWS = "fireflyframework-ecm-storage-aws"
355+ ecmStorageAzure = "fireflyframework-ecm-storage-azure"
356+ idp = "fireflyframework-security-idp"
357+ idpCognito = "fireflyframework-security-idp-aws-cognito"
358+ idpInternalDB = "fireflyframework-security-idp-internal-db"
359+ idpKeycloak = "fireflyframework-security-idp-keycloak"
360+ idpAzureAD = "fireflyframework-security-idp-azure-ad"
361+ // Security platform — hexagon core + delivery modules + SPI adapters
362+ secApi = "fireflyframework-security-api"
363+ secSpi = "fireflyframework-security-spi"
364+ secCore = "fireflyframework-security-core"
365+ secWebflux = "fireflyframework-security-webflux"
366+ secResource = "fireflyframework-security-resource-server"
367+ secMethod = "fireflyframework-security-method-policy"
368+ secOauth2 = "fireflyframework-security-oauth2-client"
369+ secAuthz = "fireflyframework-security-authorization-server"
370+ secTest = "fireflyframework-security-test"
371+ secAdapterOpa = "fireflyframework-security-adapter-opa"
372+ secAdapterCerbos = "fireflyframework-security-adapter-cerbos"
373+ secAdapterOpenfga = "fireflyframework-security-adapter-openfga"
374+ secAdapterVault = "fireflyframework-security-adapter-vault"
375+ secAdapterR2dbc = "fireflyframework-security-adapter-r2dbc"
376+ notifications = "fireflyframework-notifications"
377+ notifFirebase = "fireflyframework-notifications-firebase"
378+ notifResend = "fireflyframework-notifications-resend"
379+ notifSendgrid = "fireflyframework-notifications-sendgrid"
380+ notifTwilio = "fireflyframework-notifications-twilio"
381+ ruleEngine = "fireflyframework-rule-engine"
382+ webhooks = "fireflyframework-webhooks"
383+ callbacks = "fireflyframework-callbacks"
384+ configServer = "fireflyframework-config-server"
385+ application = "fireflyframework-starter-application"
386+ backoffice = "fireflyframework-backoffice"
387+ observability = "fireflyframework-observability"
388+ agenticBridge = "fireflyframework-agentic-bridge"
374389 )
375390
376391 // ── Layer 0: root ──────────────────────────────────────────────────
@@ -555,5 +570,34 @@ func FrameworkGraph() *Graph {
555570 // notifications-resend uses the client module
556571 g .AddEdge (notifResend , client )
557572
573+ // ── Security platform — hexagon, wired from actual pom.xml deps ────
574+ // Core hexagon: api ← spi ← core ← webflux ← delivery
575+ g .AddEdge (secApi , parent )
576+ g .AddEdge (secApi , kernel )
577+ g .AddEdge (secSpi , secApi )
578+ g .AddEdge (secCore , secApi )
579+ g .AddEdge (secCore , secSpi )
580+ g .AddEdge (secWebflux , secApi )
581+ g .AddEdge (secWebflux , secCore )
582+ // Delivery modules
583+ g .AddEdge (secResource , secWebflux )
584+ g .AddEdge (secMethod , secCore )
585+ g .AddEdge (secMethod , secWebflux )
586+ g .AddEdge (secAuthz , secCore )
587+ g .AddEdge (secAuthz , secSpi )
588+ g .AddEdge (secOauth2 , parent ) // no internal fireflyframework deps (Spring-only)
589+ g .AddEdge (secTest , secApi )
590+ g .AddEdge (secTest , secSpi )
591+ g .AddEdge (secTest , secWebflux )
592+ // SPI adapters depend only on api + spi
593+ for _ , ad := range []string {secAdapterOpa , secAdapterCerbos , secAdapterOpenfga , secAdapterVault , secAdapterR2dbc } {
594+ g .AddEdge (ad , secApi )
595+ g .AddEdge (ad , secSpi )
596+ }
597+ // (security-idp base already depends on kernel via the kernel loop and observability via the reconcile block)
598+ // The application starter is locked down by the resource server + reactive method policy
599+ g .AddEdge (application , secResource )
600+ g .AddEdge (application , secMethod )
601+
558602 return g
559603}
0 commit comments