From 4e7e0526b2c7d4dfcf1e94962da43c2c9191b6a5 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Fri, 2 Oct 2026 09:29:56 +0200 Subject: [PATCH] feat(domain): scan before the PDF check so malware is always reported as infected (refs #192) Co-Authored-By: Claude Opus 5.5 (1M context) --- services/domain/Big.Application/ProvideDocuments.cs | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/services/domain/Big.Application/ProvideDocuments.cs b/services/domain/Big.Application/ProvideDocuments.cs index ea56df9..95e07fe 100644 --- a/services/domain/Big.Application/ProvideDocuments.cs +++ b/services/domain/Big.Application/ProvideDocuments.cs @@ -50,16 +50,17 @@ public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient w return ProvideDocumentsOutcome.NotFound; // Only a clean PDF goes any further (S-29, ADR-0036): checked after ownership, so a stranger - // learns nothing about the file, and before anything is stored or the wait is completed. - if (!command.Content.AsSpan().StartsWith("%PDF-"u8)) - return ProvideDocumentsOutcome.NotAPdf; - + // learns nothing about the file, and before anything is stored or the wait is completed. Scan + // before the PDF check, so malware is reported as malware whatever it claims to be. switch (await scanner.ScanAsync(command.Content, ct)) { case ScanVerdict.Infected: return ProvideDocumentsOutcome.Infected; case ScanVerdict.Unavailable: return ProvideDocumentsOutcome.ScannerUnavailable; } + if (!command.Content.AsSpan().StartsWith("%PDF-"u8)) + return ProvideDocumentsOutcome.NotAPdf; + // Store the diploma against the zaak (once it is opened) — the ACL is the only ZGW caller (§8.1). if (registration.ZaakUrl is not null) await acl.StoreDiplomaAsync(