fix(e2e): assert the register record where a real approval happens (refs #149)
CI / build (pull_request) Successful in 1m6s
CI / lint (pull_request) Successful in 1m19s
CI / unit (pull_request) Successful in 1m24s
CI / frontend (pull_request) Successful in 2m57s
CI / mutation (pull_request) Successful in 6m7s
CI / verify-stack (pull_request) Successful in 7m49s
CI / build (pull_request) Successful in 1m6s
CI / lint (pull_request) Successful in 1m19s
CI / unit (pull_request) Successful in 1m24s
CI / frontend (pull_request) Successful in 2m57s
CI / mutation (pull_request) Successful in 6m7s
CI / verify-stack (pull_request) Successful in 7m49s
verify-domain was the wrong home for the assertion, and CI was right to fail it. That check completes the Beoordelen task straight through Flowable REST — on purpose, it exists to exercise the Workflow Client's REST contract — which bypasses the domain `decide` path that calls the ACL. No approval reached the ACL there, so no record was ever written. The Playwright happy path is the only check that drives a real approval (behandel portal → BFF → domain → ACL), and it already knows its own reference. Assert there instead: exactly one RegisterRecord for that reference, INGESCHREVEN, carrying nothing outside the public-safe schema. Drops register-record-check.py and the verify-domain block. The helper was run under real Playwright against a live Objecten before committing — one record found, none for an unknown reference.
This commit is contained in:
@@ -142,36 +142,6 @@ still="$(printf '%s' "$resp" | task_for_reg "$reg_id")"
|
||||
[ -z "$still" ] || { echo "FAIL — Beoordelen task $still still active after completion" >&2; exit 1; }
|
||||
echo "OK — behandelaar claimed and completed the Beoordelen task; the registratie process finished"
|
||||
|
||||
# ── S-19a: the same approval also wrote the canonical register record to Objecten (ADR-0028).
|
||||
# Assert it for THIS registration (matched on its reference) rather than "some INGESCHREVEN record":
|
||||
# the shared verify stack carries records from earlier runs. The container-name filters are anchored
|
||||
# on the compose replica suffix so they don't also match objecten-db / objecttypen-db.
|
||||
#
|
||||
# Unlike every other check here, these two are reached by SERVICE NAME, not container IP. Objecttypen
|
||||
# echoes the request Host into the objecttype `url`, and Objecten only accepts the objecttype URL that
|
||||
# matches its configured api_root (http://objecttypen:8000/api/v2/) — an IP-addressed lookup yields a
|
||||
# URL Objecten rejects with 400 (ADR-0028). Compose DNS resolves both names on this network, and
|
||||
# neither request has OpenZaak's URL-validity constraint.
|
||||
echo ">> asserting the approval wrote the register record to Objecten (S-19a)"
|
||||
obj="$(docker ps -q --filter 'name=objecten[-_][0-9]+$' | head -1)"
|
||||
objt="$(docker ps -q --filter 'name=objecttypen[-_][0-9]+$' | head -1)"
|
||||
[ -n "$obj" ] || { echo "FAIL — no running objecten container" >&2; exit 1; }
|
||||
[ -n "$objt" ] || { echo "FAIL — no running objecttypen container" >&2; exit 1; }
|
||||
rr="$(docker create --network "$net" \
|
||||
-e "OBJECTEN=http://objecten:8000" \
|
||||
-e "OBJECTEN_TOKEN=${OBJECTEN_TOKEN:-1234567890abcdef1234567890abcdef12345678}" \
|
||||
-e "OBJECTTYPEN=http://objecttypen:8000" \
|
||||
-e "OBJECTTYPEN_TOKEN=${OBJECTTYPEN_TOKEN:-0123456789abcdef0123456789abcdef01234567}" \
|
||||
-e "REGISTRATION_REFERENCE=$reg_id" \
|
||||
python:3-slim python /register-record-check.py)"
|
||||
docker cp "$here/register-record-check.py" "$rr:/register-record-check.py" >/dev/null
|
||||
rr_rc=0; docker start -a "$rr" || rr_rc=$?
|
||||
docker rm -f "$rr" >/dev/null
|
||||
if [ "$rr_rc" -ne 0 ]; then
|
||||
acl="$(docker ps -q --filter 'name=[-_]acl[-_]' | head -1)"
|
||||
[ -n "$acl" ] && { echo "--- acl log ---" >&2; docker logs "$acl" 2>&1 | tail -20 >&2; }
|
||||
exit "$rr_rc"
|
||||
fi
|
||||
|
||||
# ── S-11: withdrawal. A second registration parks at Beoordelen; the citizen withdraws it via the
|
||||
# domain, which delivers the RegistratieIngetrokken message to the task's execution, tripping the
|
||||
|
||||
Reference in New Issue
Block a user