test(domain): only a clean PDF diploma is stored and unblocks beoordeling (refs #192)
Red: ProvideDocuments takes the new IDocumentScanner port but ignores it, so infected, non-PDF and scanner-unavailable uploads are still Accepted. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -136,3 +136,22 @@ public sealed record EscalatieJob(string JobId, string ProcessInstanceId);
|
||||
/// cancels the case (ADR-0017).
|
||||
/// </summary>
|
||||
public sealed record RegistratieVerlopenJob(string JobId, RegistrationId RegistrationId);
|
||||
|
||||
/// <summary>What a malware scan of an uploaded document found (S-29, ADR-0036).</summary>
|
||||
public enum ScanVerdict
|
||||
{
|
||||
Clean,
|
||||
Infected,
|
||||
|
||||
/// <summary>The scanner could not be reached or did not answer — the upload is refused (fail closed).</summary>
|
||||
Unavailable,
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// The port to the malware scanner (S-29, ADR-0036). Implemented in Infrastructure over clamd's INSTREAM
|
||||
/// protocol. Never throws for a scanner outage: an unreachable scanner is <see cref="ScanVerdict.Unavailable"/>.
|
||||
/// </summary>
|
||||
public interface IDocumentScanner
|
||||
{
|
||||
Task<ScanVerdict> ScanAsync(byte[] content, CancellationToken ct = default);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user