docs: demo note and backlog mirror for S-28/S-29 (refs #192)
CI / lint (pull_request) Skipped
CI / build (pull_request) Skipped
CI / unit (pull_request) Skipped
CI / frontend (pull_request) Skipped
CI / mutation (pull_request) Skipped

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
not
2026-10-02 09:30:05 +02:00
co-authored by Claude Opus 5.5
parent f703ab264a
commit 5fd24f4e81
2 changed files with 33 additions and 0 deletions
+25
View File
@@ -878,3 +878,28 @@ Keycloak's stock conditional-OTP subflow — no custom browser flow. The fixture
committed on purpose so the checks can compute codes; a real deployment enrols per-user authenticators
(ADR-0031).
---
## S-29 — Uploaded diplomas are virus-scanned (#192, ADR-0036)
**Outcome:** a diploma upload is stored only when it is a PDF that **ClamAV** scans clean. If the file
is infected, or not a PDF, the citizen is told why and the registration keeps waiting for a valid
diploma. If the scanner is down the upload is refused (fail closed) and the citizen is asked to retry.
```bash
# 1. Manual: submit a registration in the self-service portal, then upload as the diploma:
# - any real PDF → "Uw documenten zijn aangeleverd."
# - the EICAR test file (below) → "Er is een virus gevonden in dit bestand…"
# - a renamed .png → "Dit bestand is geen PDF…"
printf '%s%s' 'X5O!P%@AP[4\PZX54(P^)7CC)7}$' 'EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' > /tmp/eicar.pdf
#
# 2. Automated: clamd itself (EICAR → FOUND, clean → OK) and the use case at every refusal:
make verify-clamav
dotnet test tests/acceptance --filter "FullyQualifiedName~EenDiplomaAanleveren"
```
**The path:** portal → BFF → Domain `ProvideDocuments`. The domain asks `IDocumentScanner`
(clamd over INSTREAM) first and checks `%PDF-` second, because clamd only spots EICAR at the start of
a file. Only a clean PDF goes on to the ACL and into ZGW. Refusals come back as 422 with a reason, a
scanner outage as 503 (ADR-0036).