Skip to content

feat: owasp threat dragon threat model import support - #115

Merged
Hacks4Snacks merged 2 commits into
mainfrom
hacks4snacks/threatdragonsupport
Sep 18, 2026
Merged

Hacks4Snacks merged 2 commits into
mainfrom
hacks4snacks/threatdragonsupport

Conversation

@Hacks4Snacks

Copy link
Copy Markdown
Owner

Summary

Add bounded OWASP Threat Dragon v2 JSON import across the CLI, HTTP API,
MCP, and Studio's API/WASM engines.

This enables users to bring supported existing models into tmforge without
recreating diagrams or losing authored threat treatment. Unsupported
semantics are rejected rather than silently changed.

Changes

  • Register an import-only threat-dragon provider with content-based
    detection, explicit version checks, and bounded JSON/graph processing.
  • Import named pages, actors, processes, stores, rectangular trust
    boundaries, and directed page-local flows with stable identities.
  • Preserve authored threats as manual entries, including categories,
    mitigation, priority, supported treatment states, scope, and provenance.
  • Carry model metadata and imported threat provenance through canonical
    JSON, engine operations, Studio persistence, and .tm7 exports.
  • Fix single-page identity loss and manual threats being assigned to
    the first page during canonical conversion.
  • Prevent Studio Save from overwriting read-only source files; offer a
    new .tmforge.json filename instead.
  • Preserve non-STRIDE categories during threat editing and return HTTP
    400 for malformed imports.
  • Add shared-fixture tests and document the import contract.

No new dependencies or separate threat evaluator are introduced.

Scope and Limitations

  • Import only: no native Threat Dragon export or lossless round trip.
  • Curved boundaries, bidirectional/detached/cross-page flows, fractional
    rectangles, unknown cell kinds, and unmappable threat states are refused.
  • Supported states: Open, Mitigated, Accepted.
  • Styling, thumbnails, and free-form connector routing are not retained.
  • Out-of-scope flags remain informational; they do not suppress tmforge
    analysis. Missing controls are not inferred as present.
  • The upstream demo contains curved boundaries and is intentionally
    refused by this initial implementation.

[DataRow("tm7")]
public void ThreatDragonImportSurvivesEngineOperations(string formatId)
{
byte[] bytes = File.ReadAllBytes(Path.Combine(AppContext.BaseDirectory, "Fixtures", "threat-dragon-v2.json"));
StringAssert.Contains(exception.Message, message);
}

private static JsonNode Fixture() => JsonNode.Parse(File.ReadAllText(Path.Combine(AppContext.BaseDirectory, "threat-dragon-v2.json")))
@Hacks4Snacks
Hacks4Snacks merged commit 4bcb012 into main Sep 18, 2026
11 checks passed
@Hacks4Snacks
Hacks4Snacks deleted the hacks4snacks/threatdragonsupport branch September 18, 2026 19:34
This was referenced Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants