test(domain): only a clean PDF diploma is stored and unblocks beoordeling (refs #192)
Red: ProvideDocuments takes the new IDocumentScanner port but ignores it, so infected, non-PDF and scanner-unavailable uploads are still Accepted. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
# language: en
|
||||
# Drives S-29 (#192, ADR-0036). A zorgprofessional uploads the diploma their registration waits for
|
||||
# ("documenten aanleveren"). Only a clean PDF is stored against the zaak and unblocks beoordeling; an
|
||||
# infected file, a non-PDF, or an unreachable scanner is refused and the registration keeps waiting.
|
||||
# Exercised against in-memory ports; the live clamd scan is verified by verify-clamav.
|
||||
Feature: Een diploma aanleveren
|
||||
Als BIG-register wil ik alleen veilige PDF-diploma's opslaan
|
||||
zodat een behandelaar nooit een besmet bestand opent.
|
||||
|
||||
Scenario: Een schoon PDF-diploma wordt opgeslagen
|
||||
Given a registration waiting for documents
|
||||
When the zorgprofessional uploads a clean PDF diploma
|
||||
Then the upload is accepted
|
||||
And the diploma is stored against the zaak
|
||||
And the registration no longer waits for documents
|
||||
|
||||
Scenario: Een besmet diploma wordt geweigerd
|
||||
Given a registration waiting for documents
|
||||
When the zorgprofessional uploads a PDF that the scanner reports infected
|
||||
Then the upload is refused as "Infected"
|
||||
And no document is stored against the zaak
|
||||
And the registration still waits for documents
|
||||
|
||||
Scenario: Een bestand dat geen PDF is wordt geweigerd
|
||||
Given a registration waiting for documents
|
||||
When the zorgprofessional uploads a file that is not a PDF
|
||||
Then the upload is refused as "NotAPdf"
|
||||
And no document is stored against the zaak
|
||||
And the registration still waits for documents
|
||||
|
||||
Scenario: De virusscanner is niet bereikbaar
|
||||
Given a registration waiting for documents
|
||||
When the zorgprofessional uploads a PDF while the scanner is unavailable
|
||||
Then the upload is refused as "ScannerUnavailable"
|
||||
And no document is stored against the zaak
|
||||
And the registration still waits for documents
|
||||
@@ -0,0 +1,68 @@
|
||||
using Acceptance.Support;
|
||||
using Big.Application;
|
||||
using Big.Domain;
|
||||
using Reqnroll;
|
||||
using Xunit;
|
||||
|
||||
namespace Acceptance.Steps;
|
||||
|
||||
/// <summary>Bindings for <c>EenDiplomaAanleveren.feature</c> (S-29). Submits a registration, attaches
|
||||
/// its zaak, then applies the ProvideDocuments use case with a scanner stand-in that returns the verdict
|
||||
/// the scenario names; one instance per scenario.</summary>
|
||||
[Binding]
|
||||
[Scope(Feature = "Een diploma aanleveren")]
|
||||
public sealed class EenDiplomaAanleverenSteps
|
||||
{
|
||||
private const string OwnerBsn = "123456782";
|
||||
private static readonly byte[] Pdf = "%PDF-1.4 diploma"u8.ToArray();
|
||||
|
||||
private readonly InMemoryRegistrationStore _store = new();
|
||||
private readonly InMemoryWorkflowClient _workflow = new();
|
||||
private readonly InMemoryAclClient _acl = new();
|
||||
private RegistrationId _id;
|
||||
private ProvideDocumentsOutcome _outcome;
|
||||
|
||||
[Given("a registration waiting for documents")]
|
||||
public async Task GivenARegistrationWaitingForDocuments()
|
||||
{
|
||||
_id = await new SubmitRegistration(_store, _workflow).HandleAsync(new SubmitRegistrationCommand(OwnerBsn));
|
||||
var registration = (await _store.GetAsync(_id))!;
|
||||
registration.AttachZaak(InMemoryAclClient.OpenedZaakUrl);
|
||||
await _store.SaveAsync(registration);
|
||||
}
|
||||
|
||||
[When("the zorgprofessional uploads a clean PDF diploma")]
|
||||
public Task WhenCleanPdf() => Upload(Pdf, ScanVerdict.Clean);
|
||||
|
||||
[When("the zorgprofessional uploads a PDF that the scanner reports infected")]
|
||||
public Task WhenInfected() => Upload(Pdf, ScanVerdict.Infected);
|
||||
|
||||
[When("the zorgprofessional uploads a file that is not a PDF")]
|
||||
public Task WhenNotAPdf() => Upload("MZ not a pdf"u8.ToArray(), ScanVerdict.Clean);
|
||||
|
||||
[When("the zorgprofessional uploads a PDF while the scanner is unavailable")]
|
||||
public Task WhenScannerUnavailable() => Upload(Pdf, ScanVerdict.Unavailable);
|
||||
|
||||
private async Task Upload(byte[] content, ScanVerdict verdict)
|
||||
=> _outcome = await new ProvideDocuments(_store, _workflow, _acl, new InMemoryDocumentScanner(verdict))
|
||||
.HandleAsync(new ProvideDocumentsCommand(_id, OwnerBsn, content, "diploma.pdf", "application/pdf"));
|
||||
|
||||
[Then("the upload is accepted")]
|
||||
public void ThenAccepted() => Assert.Equal(ProvideDocumentsOutcome.Accepted, _outcome);
|
||||
|
||||
[Then("the upload is refused as \"(.*)\"")]
|
||||
public void ThenRefusedAs(string expected) => Assert.Equal(expected, _outcome.ToString());
|
||||
|
||||
[Then("the diploma is stored against the zaak")]
|
||||
public void ThenStored() => Assert.Equal(InMemoryAclClient.OpenedZaakUrl, _acl.StoredDiploma?.ZaakUrl);
|
||||
|
||||
[Then("no document is stored against the zaak")]
|
||||
public void ThenNotStored() => Assert.Null(_acl.StoredDiploma);
|
||||
|
||||
[Then("the registration no longer waits for documents")]
|
||||
public void ThenWaitCompleted()
|
||||
=> Assert.Equal(InMemoryWorkflowClient.StartedProcessInstanceId, _workflow.CompletedDocumentWaitFor);
|
||||
|
||||
[Then("the registration still waits for documents")]
|
||||
public void ThenStillWaiting() => Assert.Null(_workflow.CompletedDocumentWaitFor);
|
||||
}
|
||||
@@ -77,6 +77,13 @@ public sealed class InMemoryAclClient : IAclClient
|
||||
}
|
||||
}
|
||||
|
||||
/// <summary>A scanner stand-in that returns the verdict the scenario names (S-29) — the live clamd
|
||||
/// INSTREAM scan is verified by verify-clamav.</summary>
|
||||
public sealed class InMemoryDocumentScanner(ScanVerdict verdict) : IDocumentScanner
|
||||
{
|
||||
public Task<ScanVerdict> ScanAsync(byte[] content, CancellationToken ct = default) => Task.FromResult(verdict);
|
||||
}
|
||||
|
||||
/// <summary>An in-memory user-task client for the beoordeling acceptance scenario: it holds one open
|
||||
/// Beoordelen task per registration and records the besluit each is completed with.</summary>
|
||||
public sealed class InMemoryUserTaskClient : IUserTaskClient
|
||||
|
||||
Reference in New Issue
Block a user