feat(domain,bff): current-registration lookup for self-service resume (refs #111)

Backend half of S-26. The domain gains IRegistrationStore.FindOpenByBsnAsync (the
citizen's non-terminal INGEDIEND/IN_BEHANDELING registration) + GET
/registrations/current?bsn=; the BFF adds owner-scoped GET /self-service/registrations
(bsn from the DigiD token) returning that registration or 204 when none. Regenerated
services/bff/openapi.json for the new endpoint (the api-client is generated from it).
Store + BFF endpoint unit tests; acceptance/BFF fakes updated for the new members.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
not
2026-07-22 17:04:35 +02:00
co-authored by Claude Opus 4.8
parent 5de8c1e292
commit 24927b1e80
12 changed files with 229 additions and 0 deletions
+18
View File
@@ -86,6 +86,24 @@ app.MapPost("/self-service/registrations", async (ClaimsPrincipal user, IDomainC
.Produces(StatusCodes.Status400BadRequest)
.Produces(StatusCodes.Status401Unauthorized);
// Self-service resume (S-26): the signed-in zorgprofessional's current open registration, so the
// portal can restore its reference + actions after a page refresh. The bsn comes from the DigiD token;
// 204 when the citizen has none in flight (so the portal shows the submit form).
app.MapGet("/self-service/registrations", async (ClaimsPrincipal user, IDomainClient domain, CancellationToken ct) =>
{
var bsn = user.FindFirstValue("bsn");
if (string.IsNullOrWhiteSpace(bsn))
return Results.BadRequest("The token carries no bsn claim.");
var current = await domain.GetCurrentRegistrationAsync(bsn, ct);
return current is null ? Results.NoContent() : Results.Ok(current);
})
.RequireAuthorization()
.Produces<CurrentRegistration>(StatusCodes.Status200OK)
.Produces(StatusCodes.Status204NoContent)
.Produces(StatusCodes.Status400BadRequest)
.Produces(StatusCodes.Status401Unauthorized);
// Self-service withdrawal (S-11): the signed-in zorgprofessional withdraws their own registration.
// The bsn comes from the DigiD token and is forwarded to the domain, which owner-scopes the action;
// a registration that is unknown or not the caller's comes back 404 (ownership is not revealed).