feat(domain,bff): current-registration lookup for self-service resume (refs #111)
Backend half of S-26. The domain gains IRegistrationStore.FindOpenByBsnAsync (the citizen's non-terminal INGEDIEND/IN_BEHANDELING registration) + GET /registrations/current?bsn=; the BFF adds owner-scoped GET /self-service/registrations (bsn from the DigiD token) returning that registration or 204 when none. Regenerated services/bff/openapi.json for the new endpoint (the api-client is generated from it). Store + BFF endpoint unit tests; acceptance/BFF fakes updated for the new members. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -86,6 +86,24 @@ app.MapPost("/self-service/registrations", async (ClaimsPrincipal user, IDomainC
|
||||
.Produces(StatusCodes.Status400BadRequest)
|
||||
.Produces(StatusCodes.Status401Unauthorized);
|
||||
|
||||
// Self-service resume (S-26): the signed-in zorgprofessional's current open registration, so the
|
||||
// portal can restore its reference + actions after a page refresh. The bsn comes from the DigiD token;
|
||||
// 204 when the citizen has none in flight (so the portal shows the submit form).
|
||||
app.MapGet("/self-service/registrations", async (ClaimsPrincipal user, IDomainClient domain, CancellationToken ct) =>
|
||||
{
|
||||
var bsn = user.FindFirstValue("bsn");
|
||||
if (string.IsNullOrWhiteSpace(bsn))
|
||||
return Results.BadRequest("The token carries no bsn claim.");
|
||||
|
||||
var current = await domain.GetCurrentRegistrationAsync(bsn, ct);
|
||||
return current is null ? Results.NoContent() : Results.Ok(current);
|
||||
})
|
||||
.RequireAuthorization()
|
||||
.Produces<CurrentRegistration>(StatusCodes.Status200OK)
|
||||
.Produces(StatusCodes.Status204NoContent)
|
||||
.Produces(StatusCodes.Status400BadRequest)
|
||||
.Produces(StatusCodes.Status401Unauthorized);
|
||||
|
||||
// Self-service withdrawal (S-11): the signed-in zorgprofessional withdraws their own registration.
|
||||
// The bsn comes from the DigiD token and is forwarded to the domain, which owner-scopes the action;
|
||||
// a registration that is unknown or not the caller's comes back 404 (ownership is not revealed).
|
||||
|
||||
Reference in New Issue
Block a user