test(domain): only a clean PDF diploma is stored and unblocks beoordeling (refs #192)

Red: ProvideDocuments takes the new IDocumentScanner port but ignores it, so
infected, non-PDF and scanner-unavailable uploads are still Accepted.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
not
2026-10-02 09:30:05 +02:00
co-authored by Claude Opus 5.5
parent f93b4a4426
commit dea5df090f
7 changed files with 231 additions and 9 deletions
+19
View File
@@ -136,3 +136,22 @@ public sealed record EscalatieJob(string JobId, string ProcessInstanceId);
/// cancels the case (ADR-0017).
/// </summary>
public sealed record RegistratieVerlopenJob(string JobId, RegistrationId RegistrationId);
/// <summary>What a malware scan of an uploaded document found (S-29, ADR-0036).</summary>
public enum ScanVerdict
{
Clean,
Infected,
/// <summary>The scanner could not be reached or did not answer — the upload is refused (fail closed).</summary>
Unavailable,
}
/// <summary>
/// The port to the malware scanner (S-29, ADR-0036). Implemented in Infrastructure over clamd's INSTREAM
/// protocol. Never throws for a scanner outage: an unreachable scanner is <see cref="ScanVerdict.Unavailable"/>.
/// </summary>
public interface IDocumentScanner
{
Task<ScanVerdict> ScanAsync(byte[] content, CancellationToken ct = default);
}
@@ -18,6 +18,15 @@ public enum ProvideDocumentsOutcome
/// <summary>No registration with that id belongs to the caller — unknown, or owned by someone else
/// (the two are deliberately indistinguishable, so the endpoint reveals neither).</summary>
NotFound,
/// <summary>The file does not start with the PDF signature (<c>%PDF-</c>); nothing was stored.</summary>
NotAPdf,
/// <summary>The malware scan found something; nothing was stored and the wait stays open.</summary>
Infected,
/// <summary>The scanner could not be reached — refused rather than storing an unscanned file.</summary>
ScannerUnavailable,
}
/// <summary>
@@ -28,7 +37,7 @@ public enum ProvideDocumentsOutcome
/// (mirroring <see cref="WithdrawRegistration"/>): storage needs an opened zaak, and completion needs a
/// running process — a request that arrives before either still stands, storing/completing what it can.
/// </summary>
public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient workflow, IAclClient acl)
public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient workflow, IAclClient acl, IDocumentScanner scanner)
{
public async Task<ProvideDocumentsOutcome> HandleAsync(ProvideDocumentsCommand command, CancellationToken ct = default)
{