diff --git a/Core/src/org/sleuthkit/autopsy/actions/DeleteContentTagAction.java b/Core/src/org/sleuthkit/autopsy/actions/DeleteContentTagAction.java index b7ff3a73a0..b6c882cd5e 100644 --- a/Core/src/org/sleuthkit/autopsy/actions/DeleteContentTagAction.java +++ b/Core/src/org/sleuthkit/autopsy/actions/DeleteContentTagAction.java @@ -29,6 +29,9 @@ import org.openide.util.Utilities; import org.openide.windows.WindowManager; import org.sleuthkit.autopsy.casemodule.Case; import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException; +import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager; +import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager.ContentViewerTag; +import org.sleuthkit.autopsy.contentviewers.imagetagging.ImageTagRegion; import org.sleuthkit.autopsy.coreutils.Logger; import org.sleuthkit.datamodel.ContentTag; import org.sleuthkit.datamodel.TskCoreException; @@ -72,6 +75,12 @@ public class DeleteContentTagAction extends AbstractAction { new Thread(() -> { for (ContentTag tag : selectedTags) { try { + // Check if there is an image tag before deleting the content tag. + ContentViewerTag imageTag = ContentViewerTagManager.getTag(tag, ImageTagRegion.class); + if(imageTag != null) { + ContentViewerTagManager.deleteTag(imageTag); + } + Case.getCurrentCaseThrows().getServices().getTagsManager().deleteContentTag(tag); } catch (TskCoreException | NoCurrentCaseException ex) { Logger.getLogger(DeleteContentTagAction.class.getName()).log(Level.SEVERE, "Error deleting tag", ex); //NON-NLS diff --git a/Core/src/org/sleuthkit/autopsy/actions/DeleteFileContentTagAction.java b/Core/src/org/sleuthkit/autopsy/actions/DeleteFileContentTagAction.java index cb719e2f0a..4141e3d29d 100644 --- a/Core/src/org/sleuthkit/autopsy/actions/DeleteFileContentTagAction.java +++ b/Core/src/org/sleuthkit/autopsy/actions/DeleteFileContentTagAction.java @@ -39,6 +39,9 @@ import org.openide.util.actions.Presenter; import org.sleuthkit.autopsy.casemodule.Case; import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException; import org.sleuthkit.autopsy.casemodule.services.TagsManager; +import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager; +import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager.ContentViewerTag; +import org.sleuthkit.autopsy.contentviewers.imagetagging.ImageTagRegion; import org.sleuthkit.autopsy.coreutils.Logger; import org.sleuthkit.autopsy.tags.TagUtils; import org.sleuthkit.datamodel.AbstractFile; @@ -123,6 +126,13 @@ public class DeleteFileContentTagAction extends AbstractAction implements Presen try { logger.log(Level.INFO, "Removing tag {0} from {1}", new Object[]{tagName.getDisplayName(), contentTag.getContent().getName()}); //NON-NLS + + // Check if there is an image tag before deleting the content tag. + ContentViewerTag imageTag = ContentViewerTagManager.getTag(contentTag, ImageTagRegion.class); + if(imageTag != null) { + ContentViewerTagManager.deleteTag(imageTag); + } + tagsManager.deleteContentTag(contentTag); } catch (TskCoreException tskCoreException) { logger.log(Level.SEVERE, "Error untagging file", tskCoreException); //NON-NLS diff --git a/Core/src/org/sleuthkit/autopsy/actions/ReplaceContentTagAction.java b/Core/src/org/sleuthkit/autopsy/actions/ReplaceContentTagAction.java index 51b898eb84..1c69bc133c 100644 --- a/Core/src/org/sleuthkit/autopsy/actions/ReplaceContentTagAction.java +++ b/Core/src/org/sleuthkit/autopsy/actions/ReplaceContentTagAction.java @@ -29,6 +29,9 @@ import org.openide.util.Utilities; import org.sleuthkit.autopsy.casemodule.Case; import org.sleuthkit.autopsy.casemodule.NoCurrentCaseException; import org.sleuthkit.autopsy.casemodule.services.TagsManager; +import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager; +import org.sleuthkit.autopsy.casemodule.services.contentviewertags.ContentViewerTagManager.ContentViewerTag; +import org.sleuthkit.autopsy.contentviewers.imagetagging.ImageTagRegion; import org.sleuthkit.autopsy.coreutils.Logger; import org.sleuthkit.datamodel.ContentTag; import org.sleuthkit.datamodel.TagName; @@ -83,9 +86,19 @@ public final class ReplaceContentTagAction extends ReplaceTagAction try { logger.log(Level.INFO, "Replacing tag {0} with tag {1} for artifact {2}", new Object[]{oldTag.getName().getDisplayName(), newTagName.getDisplayName(), oldTag.getContent().getName()}); //NON-NLS + // Check if there is an image tag before deleting the content tag. + ContentViewerTag imageTag = ContentViewerTagManager.getTag(oldTag, ImageTagRegion.class); + if(imageTag != null) { + ContentViewerTagManager.deleteTag(imageTag); + } + tagsManager.deleteContentTag(oldTag); - tagsManager.addContentTag(oldTag.getContent(), newTagName, newComment); - + ContentTag newTag = tagsManager.addContentTag(oldTag.getContent(), newTagName, newComment); + + // Resave the image tag if present. + if(imageTag != null) { + ContentViewerTagManager.saveTag(newTag, imageTag.getDetails()); + } } catch (TskCoreException tskCoreException) { logger.log(Level.SEVERE, "Error replacing artifact tag", tskCoreException); //NON-NLS Platform.runLater(() diff --git a/Core/src/org/sleuthkit/autopsy/modules/hashdatabase/HashDbManager.java b/Core/src/org/sleuthkit/autopsy/modules/hashdatabase/HashDbManager.java index adc453c65f..139edb8ec7 100644 --- a/Core/src/org/sleuthkit/autopsy/modules/hashdatabase/HashDbManager.java +++ b/Core/src/org/sleuthkit/autopsy/modules/hashdatabase/HashDbManager.java @@ -433,7 +433,7 @@ public class HashDbManager implements PropertyChangeListener { void save() throws HashDbManagerException { try { - if (!HashLookupSettings.writeSettings(new HashLookupSettings(HashLookupSettings.convertHashSetList(getNonOfficialHashSets())))) { + if (!HashLookupSettings.writeSettings(new HashLookupSettings(HashLookupSettings.convertHashSetList(this.hashSets)))) { throw new HashDbManagerException(NbBundle.getMessage(this.getClass(), "HashDbManager.saveErrorExceptionMsg")); } } catch (HashLookupSettings.HashLookupSettingsException ex) { @@ -492,13 +492,6 @@ public class HashDbManager implements PropertyChangeListener { return getUpdateableHashSets(getAllHashSets()); } - private List getNonOfficialHashSets() { - return getAllHashSets() - .stream() - .filter((HashDb db) -> (db instanceof SleuthkitHashSet && ((SleuthkitHashSet) db).isOfficialSet()) ? false : true) - .collect(Collectors.toList()); - } - private List getUpdateableHashSets(List hashDbs) { return hashDbs .stream() @@ -539,7 +532,7 @@ public class HashDbManager implements PropertyChangeListener { * cancellation of configuration panels. */ public synchronized void loadLastSavedConfiguration() { - closeHashDatabases(getAllHashSets()); + closeHashDatabases(this.hashSets); hashSetNames.clear(); hashSetPaths.clear(); @@ -765,7 +758,7 @@ public class HashDbManager implements PropertyChangeListener { */ if (!allDatabasesLoadedCorrectly && RuntimeProperties.runningWithGUI()) { try { - HashLookupSettings.writeSettings(new HashLookupSettings(HashLookupSettings.convertHashSetList(getNonOfficialHashSets()))); + HashLookupSettings.writeSettings(new HashLookupSettings(HashLookupSettings.convertHashSetList(this.hashSets))); allDatabasesLoadedCorrectly = true; } catch (HashLookupSettings.HashLookupSettingsException ex) { allDatabasesLoadedCorrectly = false; @@ -839,7 +832,7 @@ public class HashDbManager implements PropertyChangeListener { } private boolean hashDbInfoIsNew(HashDbInfo dbInfo) { - for (HashDb db : getAllHashSets()) { + for (HashDb db : this.hashSets) { if (dbInfo.matches(db)) { return false; } diff --git a/Core/src/org/sleuthkit/autopsy/report/infrastructure/Bundle.properties-MERGED b/Core/src/org/sleuthkit/autopsy/report/infrastructure/Bundle.properties-MERGED index 14e603e61b..40dc146e1d 100755 --- a/Core/src/org/sleuthkit/autopsy/report/infrastructure/Bundle.properties-MERGED +++ b/Core/src/org/sleuthkit/autopsy/report/infrastructure/Bundle.properties-MERGED @@ -19,7 +19,7 @@ ReportProgressIndicator.switchToIndeterminateMessage=Report generation progress ReportWizardDataSourceSelectionPanel.confirmEmptySelection=Are you sure you want to proceed with no selections? ReportWizardDataSourceSelectionPanel.finishButton.text=Finish ReportWizardDataSourceSelectionPanel.nextButton.text=Next -ReportWizardDataSourceSelectionPanel.title=Select which datasource(s) to include +ReportWizardDataSourceSelectionPanel.title=Select which data source(s) to include ReportWizardFileOptionsVisualPanel.jLabel1.text=Select items to include in File Report: ReportWizardFileOptionsVisualPanel.deselectAllButton.text=Deselect All ReportWizardFileOptionsVisualPanel.selectAllButton.text=Select All diff --git a/Core/src/org/sleuthkit/autopsy/report/infrastructure/ReportWizardDataSourceSelectionPanel.java b/Core/src/org/sleuthkit/autopsy/report/infrastructure/ReportWizardDataSourceSelectionPanel.java index bfdd1dc5c1..1bfccb688a 100755 --- a/Core/src/org/sleuthkit/autopsy/report/infrastructure/ReportWizardDataSourceSelectionPanel.java +++ b/Core/src/org/sleuthkit/autopsy/report/infrastructure/ReportWizardDataSourceSelectionPanel.java @@ -87,7 +87,7 @@ public class ReportWizardDataSourceSelectionPanel implements WizardDescriptor.Fi } @NbBundle.Messages({ - "ReportWizardDataSourceSelectionPanel.title=Select which datasource(s) to include" + "ReportWizardDataSourceSelectionPanel.title=Select which data source(s) to include" }) @Override public CheckBoxListPanel getComponent() { diff --git a/docs/doxygen-user/central_repo.dox b/docs/doxygen-user/central_repo.dox index af217ad9ca..3841854106 100644 --- a/docs/doxygen-user/central_repo.dox +++ b/docs/doxygen-user/central_repo.dox @@ -218,12 +218,6 @@ the Case -> Case Properties menu. This shows how common the selected file is. The value is the percentage of case/data source tuples that have the selected property. -\subsection central_repo_comment Add/Edit Comment - -If you want instead to edit the comment of a node, it can be done by right clicking on the original item in the result viewer and selecting "Add/Edit Central Repository Comment". - -\image html central_repo_comment_menu.png - \subsection cr_interesting_items Interesting Items In the Results tree of an open case is an entry called Interesting Items. When this module is enabled, all of the enabled diff --git a/docs/doxygen-user/images/central_repo_comment_menu.png b/docs/doxygen-user/images/central_repo_comment_menu.png deleted file mode 100644 index 0f3c46e08f..0000000000 Binary files a/docs/doxygen-user/images/central_repo_comment_menu.png and /dev/null differ diff --git a/docs/doxygen-user/images/reports_datasource_select.png b/docs/doxygen-user/images/reports_datasource_select.png new file mode 100644 index 0000000000..3c93abcf66 Binary files /dev/null and b/docs/doxygen-user/images/reports_datasource_select.png differ diff --git a/docs/doxygen-user/images/tagging_comment_anno.png b/docs/doxygen-user/images/tagging_comment_anno.png new file mode 100644 index 0000000000..24c906a457 Binary files /dev/null and b/docs/doxygen-user/images/tagging_comment_anno.png differ diff --git a/docs/doxygen-user/images/tagging_comment_context.png b/docs/doxygen-user/images/tagging_comment_context.png new file mode 100644 index 0000000000..b0b25d86ef Binary files /dev/null and b/docs/doxygen-user/images/tagging_comment_context.png differ diff --git a/docs/doxygen-user/images/tagging_comment_icon.png b/docs/doxygen-user/images/tagging_comment_icon.png new file mode 100644 index 0000000000..7b55aaf571 Binary files /dev/null and b/docs/doxygen-user/images/tagging_comment_icon.png differ diff --git a/docs/doxygen-user/images/tagging_comment_in_result_viewer.png b/docs/doxygen-user/images/tagging_comment_in_result_viewer.png new file mode 100644 index 0000000000..274b8ff574 Binary files /dev/null and b/docs/doxygen-user/images/tagging_comment_in_result_viewer.png differ diff --git a/docs/doxygen-user/images/tagging_cr_comment.png b/docs/doxygen-user/images/tagging_cr_comment.png new file mode 100644 index 0000000000..1c5f14393b Binary files /dev/null and b/docs/doxygen-user/images/tagging_cr_comment.png differ diff --git a/docs/doxygen-user/reporting.dox b/docs/doxygen-user/reporting.dox index c1065983e7..4f7bb11a9a 100644 --- a/docs/doxygen-user/reporting.dox +++ b/docs/doxygen-user/reporting.dox @@ -8,6 +8,10 @@ of any coordinates found to load into software like Google Earth. \image html reports_select.png +Most report types will allow you to select which data sources to include in the report. Note that the names of excluded data sources may still be present in the report. For example, the \ref report_html will list all data sources in the case on the main page but will not contain results, tagged files, etc. from the excluded data source(s). + +\image html reports_datasource_select.png + The different types of reports will be described below. The majority of the report modules will generate a report file which will be displayed in the case under the "Reports" node of the \ref tree_viewer_page. diff --git a/docs/doxygen-user/tagging.dox b/docs/doxygen-user/tagging.dox index e4bccc77a6..0111140414 100644 --- a/docs/doxygen-user/tagging.dox +++ b/docs/doxygen-user/tagging.dox @@ -1,6 +1,6 @@ -/*! \page tagging_page Tagging +/*! \page tagging_page Tagging and Commenting -Tagging (or Bookmarking) allows you to create a reference to a file or object and easily find it later or include it in a \ref reporting_page "report". Tagging is also used by the \ref central_repo_page "central repository" to mark items as notable. +Tagging (or Bookmarking) allows you to create a reference to a file or object and easily find it later or include it in a \ref reporting_page "report". Tagging is also used by the \ref central_repo_page "central repository" to mark items as notable. You can add comments to files and results using tags or through the central repository. \section tagging_items Tagging items @@ -99,7 +99,7 @@ If using the central repository, changing the notable status will effect tagged - If "File A" is tagged with "Tag A", which is not notable, and then "Tag A" is switched to notable, "File A" will be marked as notable in the central repository - If "File B" is tagged with "Tag B", which is notable, and then "Tag B" is switched to non-notable, if there are no other notable tags on "File B" then its notable status in the central repository will be removed. -\section user_tags Hiding tags from other users +\subsection user_tags Hiding tags from other users Tags are associated with the account name of the user that tagged them. This information is visible through selecting items under the "Tags" section of the directory tree: @@ -113,4 +113,26 @@ It is possible to hide all tagged files and results in the "Tags" area of the tr \image html tagging_view_options.png +\section tagging_commenting Commenting + +There are two methods to adding comments to files and results. The first method was discussed in the \ref tagging_items section. Right click on the file or result of interest, choose "Add File Tag" or "Add Result Tag" and then "Tag and Comment". This allows you to add a comment about the item. You can add multiple tags with comments to the same file or result. + +\image html tagging_comment_context.png + +If you have a \ref central_repo_page "central repository" enabled, you can also use it to save comments about files. Right click on the file and select "Add/Edit Central Repository Comment". If there was already a comment for this file it will appear in the dialog and can be changed - only one central repository comment can be stored at a time. + +\image html tagging_cr_comment.png + +If a file or result has a comment associated with it, you'll see a notepad icon in the "C" column of the result viewer. Hovering over it will tell you what type of comments are on the item. + +\image html tagging_comment_icon.png + +You can view comments associated with tags by going to the "Tags" section of the tree viewer and selecting one of your tags. Any comments will appear in the "Comment" column in the results viewer. + +\image html tagging_comment_in_result_viewer.png + +You can view all comments on an item through the "Annotation" tab in the content viewer. + +\image html tagging_comment_anno.png + */