Originally created by: LeeMangold
Fixes [#285]. Also addresses the root cause reported in [#264].
Problems
- Checklist templates could be used for vendor assessments. The Assess Risk, Send Survey, and vendor Surveys pickers listed every active template, including checklist templates, which have no risk weights. Assessments built on them could never be scored.
- Yes/No answers always displayed "Yes". Boolean answers are stored as
'yes'/'no', but AnswersRelationManager rendered them with $value ? 'Yes' : 'No', and 'no' is truthy. Scoring was unaffected.
- Unscorable surveys reported 0/100. With no weighted questions,
calculateSurveyScore() returned 0, which reads as "no risk". The Score Survey page also claimed all questions were automatically scored.
- Built-in vendor survey templates were missing on fresh installs. The seed migrations skip when no user exists, and
opengrc:install never ran VendorSurveyTemplatesSeeder, so installs made with install.sh never received them.
Changes
- Add
SurveyTemplate::forVendorAssessment() (active, non-checklist) and use it in all three vendor pickers, with helper text pointing to Vendor Management → Survey Templates for weights. The vendor Surveys tab still shows an existing survey's current template.
- Add
SurveyAnswer::booleanValue(), which normalizes 'yes'/'no', real booleans and legacy ['value' => …] answers, and use it for both answer displays.
calculateSurveyScore() now returns null when nothing is scorable and leaves the stored score untouched. All callers show a "not calculated" warning instead of 0/100.
- The Score Survey page now distinguishes "template has no weights" from "no manual scoring needed".
VendorSurveyTemplatesSeeder only adds templates that are missing (soft-deleted templates count as present), so re-running it never overwrites customized weights or resurrects deleted templates.
opengrc:install runs the seeder after creating the admin user, and a backfill migration seeds the templates on existing installs.
Ticket changed by: LeeMangold