Compare commits
12
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5f77dae587 | ||
|
|
8d936ffdaa | ||
|
|
990db61ba7 | ||
|
|
5402bc179c | ||
|
|
2b60f8e51f | ||
|
|
07139324a3 | ||
|
|
0d1e2825e5 | ||
|
|
cf1c77489d | ||
|
|
404454d270 | ||
|
|
771450d46d | ||
|
|
c21becd5b9 | ||
|
|
7ceb22d46d |
+6
-6
@@ -201,17 +201,17 @@ _Split from the original S-09 — scoped to the portal only; the approval flow i
|
||||
|
||||
Split (issue #11 closed) into two independently-demoable slices per §13 — the original spanned six net-new surfaces including a new ZGW boundary:
|
||||
|
||||
#### S-10a · Document-wait task + 30-day timeout cancellation (workflow spine) — #102
|
||||
#### S-10a · Document-wait task + 30-day timeout cancellation + provision trigger — #102
|
||||
|
||||
**Outcome:** BPMN gains a `WachtOpDocumenten` user task with a 30-day (P30D) interrupting boundary timer. On timeout the case is cancelled — the timer runs to a dedicated cancel end-event and the domain aggregate moves to a new terminal status via an external-worker (mirrors S-14 escalation / S-11 withdrawal). Backend only, no frontend.
|
||||
**Outcome:** BPMN gains a `WachtOpDocumenten` user task with a 30-day (P30D) interrupting boundary timer. On timeout the case is cancelled — the timer runs to a dedicated cancel end-event and the domain aggregate moves to a new terminal status `Verlopen` via an external-worker (mirrors S-14 escalation / S-11 withdrawal). "Documents received" is wired end-to-end (domain endpoint + BFF + a "Documenten aanleveren" button on the self-service page) so the walking-skeleton e2e stays green — but the document is **not yet stored** in ZGW; that is S-10b.
|
||||
|
||||
**Acceptance:** BDD both branches (documents-in-time vs timeout-cancel); live timer-fire via the management-API "move" idiom.
|
||||
**Acceptance:** BDD both branches (documents-in-time vs timeout-cancel); live timer-fire via the management-API "move" idiom; the registration e2e provides documents before the behandelaar step.
|
||||
|
||||
#### S-10b · Diploma upload via ACL Documenten API + self-service portal — #103
|
||||
#### S-10b · Real diploma upload stored via the ACL Documenten API — #103
|
||||
|
||||
**Outcome:** the self-service portal supports diploma upload; the document is stored in the ZGW Documenten (DRC) API and related to the zaak, with all document calls routed through the ACL (§8.1). A successful upload completes the `WachtOpDocumenten` task from S-10a. Depends on #102.
|
||||
**Outcome:** the self-service "Documenten aanleveren" action becomes a real file upload; the document is stored in the ZGW Documenten (DRC) API and related to the zaak, with all document calls routed through the ACL (§8.1), and the zaak is set to a cancellation status on timeout expiry. Builds on the S-10a trigger/wait. Depends on #102.
|
||||
|
||||
**Acceptance:** BDD upload-completes-wait-task; Playwright e2e upload journey.
|
||||
**Acceptance:** ACL Documenten gateway integration test; Playwright e2e uploads a real document; the openbaar/zaak reflects the stored document.
|
||||
|
||||
### S-11 · Withdrawal (Flow 3)
|
||||
|
||||
|
||||
@@ -11,6 +11,24 @@
|
||||
<p utrecht-paragraph role="status">
|
||||
Uw registratie is ontvangen. Referentie: {{ reference() }}.
|
||||
</p>
|
||||
@if (documentsProvided()) {
|
||||
<p utrecht-paragraph role="status">Uw documenten zijn aangeleverd.</p>
|
||||
} @else {
|
||||
@if (provideDocumentsFailed()) {
|
||||
<p utrecht-paragraph role="alert">
|
||||
Het aanleveren van uw documenten is niet gelukt. Probeer het opnieuw.
|
||||
</p>
|
||||
}
|
||||
<button
|
||||
utrecht-button
|
||||
appearance="primary-action-button"
|
||||
type="button"
|
||||
[disabled]="providingDocuments()"
|
||||
(click)="provideDocuments()"
|
||||
>
|
||||
Documenten aanleveren
|
||||
</button>
|
||||
}
|
||||
@if (withdrawFailed()) {
|
||||
<p utrecht-paragraph role="alert">
|
||||
Het intrekken van uw registratie is niet gelukt. Probeer het opnieuw.
|
||||
|
||||
@@ -20,10 +20,12 @@ class FakeAuth extends AuthService {
|
||||
function providers(
|
||||
post = vi.fn().mockReturnValue(of({ registrationId: 'reg-9', status: 'Ingediend' })),
|
||||
withdraw = vi.fn().mockReturnValue(of(undefined)),
|
||||
provideDocuments = vi.fn().mockReturnValue(of(undefined)),
|
||||
) {
|
||||
return {
|
||||
post,
|
||||
withdraw,
|
||||
provideDocuments,
|
||||
providers: [
|
||||
{ provide: AuthService, useClass: FakeAuth },
|
||||
{
|
||||
@@ -31,6 +33,7 @@ function providers(
|
||||
useValue: {
|
||||
postSelfServiceRegistrations: post,
|
||||
postSelfServiceRegistrationsIdWithdraw: withdraw,
|
||||
postSelfServiceRegistrationsIdDocuments: provideDocuments,
|
||||
},
|
||||
},
|
||||
],
|
||||
@@ -80,6 +83,37 @@ describe('RegistrationPage', () => {
|
||||
expect(await screen.findByText(/ingetrokken/i)).toBeTruthy();
|
||||
});
|
||||
|
||||
it('offers to provide documents after submitting, and doing so confirms', async () => {
|
||||
const { provideDocuments, providers: p } = providers();
|
||||
await render(RegistrationPage, { providers: p });
|
||||
|
||||
fireEvent.click(screen.getByRole('button', { name: /indienen/i }));
|
||||
await screen.findByText(/ontvangen/i);
|
||||
|
||||
fireEvent.click(await screen.findByRole('button', { name: /documenten aanleveren/i }));
|
||||
|
||||
// The provide-documents call is keyed by the reference the submit returned, and the page confirms.
|
||||
expect(provideDocuments).toHaveBeenCalledWith('reg-9');
|
||||
expect(await screen.findByText(/documenten.*aangeleverd/i)).toBeTruthy();
|
||||
});
|
||||
|
||||
it('surfaces a provide-documents failure and keeps the action available', async () => {
|
||||
const { providers: p } = providers(
|
||||
vi.fn().mockReturnValue(of({ registrationId: 'reg-9', status: 'Ingediend' })),
|
||||
vi.fn().mockReturnValue(of(undefined)),
|
||||
vi.fn().mockReturnValue(throwError(() => new Error('documents rejected'))),
|
||||
);
|
||||
await render(RegistrationPage, { providers: p });
|
||||
|
||||
fireEvent.click(screen.getByRole('button', { name: /indienen/i }));
|
||||
await screen.findByText(/ontvangen/i);
|
||||
fireEvent.click(await screen.findByRole('button', { name: /documenten aanleveren/i }));
|
||||
|
||||
expect(await screen.findByRole('alert')).toBeTruthy();
|
||||
expect(screen.queryByText(/aangeleverd/i)).toBeNull();
|
||||
expect(screen.getByRole('button', { name: /documenten aanleveren/i })).toBeTruthy();
|
||||
});
|
||||
|
||||
it('surfaces a withdraw failure and keeps the action available', async () => {
|
||||
const { providers: p } = providers(
|
||||
vi.fn().mockReturnValue(of({ registrationId: 'reg-9', status: 'Ingediend' })),
|
||||
|
||||
@@ -26,6 +26,9 @@ export class RegistrationPage {
|
||||
protected readonly withdrawing = signal(false);
|
||||
protected readonly withdrawn = signal(false);
|
||||
protected readonly withdrawFailed = signal(false);
|
||||
protected readonly providingDocuments = signal(false);
|
||||
protected readonly documentsProvided = signal(false);
|
||||
protected readonly provideDocumentsFailed = signal(false);
|
||||
|
||||
submit(): void {
|
||||
this.submitting.set(true);
|
||||
@@ -44,6 +47,26 @@ export class RegistrationPage {
|
||||
});
|
||||
}
|
||||
|
||||
provideDocuments(): void {
|
||||
const reference = this.reference();
|
||||
if (!reference) {
|
||||
return;
|
||||
}
|
||||
this.providingDocuments.set(true);
|
||||
this.provideDocumentsFailed.set(false);
|
||||
this.bff.postSelfServiceRegistrationsIdDocuments(reference).subscribe({
|
||||
next: () => {
|
||||
this.documentsProvided.set(true);
|
||||
this.providingDocuments.set(false);
|
||||
},
|
||||
// Surface the failure instead of swallowing it: keep the action so the user can retry.
|
||||
error: () => {
|
||||
this.provideDocumentsFailed.set(true);
|
||||
this.providingDocuments.set(false);
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
withdraw(): void {
|
||||
const reference = this.reference();
|
||||
if (!reference) {
|
||||
|
||||
@@ -42,9 +42,16 @@ worker expires the correlated aggregate to a new terminal status `Verlopen`.**
|
||||
- **Documents-in-time transition.** `IWorkflowClient.CompleteDocumentWaitAsync(processInstanceId)`
|
||||
completes the `WachtOpDocumenten` task (the Workflow Client remains the only code that talks to
|
||||
Flowable, §8.2). It is best-effort — a no-op if the instance already left the wait (continued, or
|
||||
timed out). The *trigger* that calls it (the portal upload) is wired in S-10b; S-10a builds and tests
|
||||
the completion path with the trigger stubbed (the live check completes the task directly to prove the
|
||||
in-time branch, and the domain acceptance drives the worker against an in-memory stand-in).
|
||||
timed out). The trigger is wired end-to-end in S-10a: a `ProvideDocuments` application use case behind
|
||||
an owner-scoped domain endpoint `POST /registrations/{id}/documents`, a BFF passthrough
|
||||
`POST /self-service/registrations/{id}/documents` (bsn from the DigiD token), and a "Documenten
|
||||
aanleveren" action on the self-service page — so the walking-skeleton e2e stays green (a registration
|
||||
can still reach the behandelaar). **S-10b replaces the stub trigger with a real file upload stored in
|
||||
the ZGW Documenten (DRC) API via the ACL**; the completion of the wait is unchanged.
|
||||
- *Why the trigger lives here, not in S-10b:* inserting the `WachtOpDocumenten` gate without any way
|
||||
to pass it breaks the submit→beoordeling e2e (a merge gate). Splitting "gate" from "means to pass
|
||||
the gate" across slices would leave `main` red, so S-10a owns both; S-10b is purely the ZGW storage
|
||||
behind the same action.
|
||||
|
||||
## Consequences
|
||||
|
||||
@@ -60,12 +67,16 @@ worker expires the correlated aggregate to a new terminal status `Verlopen`.**
|
||||
|
||||
**Negative / costs**
|
||||
|
||||
- Every registration now parks at `WachtOpDocumenten` before Beoordelen, so the other live-check blocks
|
||||
(S-11/S-12b/S-13/S-14) must complete that task first — a small, explicit step standing in for the
|
||||
S-10b upload until it lands.
|
||||
- Every registration now parks at `WachtOpDocumenten` before Beoordelen, so the other flows must supply
|
||||
documents first: the live-check blocks (S-11/S-12b/S-13/S-14) complete the task via Flowable, and the
|
||||
registration e2e clicks "Documenten aanleveren". A small, explicit step, but it touches every path
|
||||
through the process.
|
||||
- On expiry S-10a cancels the *process* and marks the aggregate `Verlopen` but does **not** set the ZGW
|
||||
*zaak* to a cancellation status — that needs a new ACL method + statustype seeding, which overlaps
|
||||
S-10b's ACL/infra work. Deferred to S-10b (or a follow-up); noted here as the S-10a/S-10b boundary.
|
||||
- Withdrawing while parked at `WachtOpDocumenten` marks the aggregate `Ingetrokken` but does not cancel
|
||||
the process (the withdrawal message boundary is on `Beoordelen`); the timeout worker tolerates this
|
||||
by no-op'ing on an already-resolved aggregate. Extending withdrawal to the wait state is a follow-up.
|
||||
|
||||
## Alternatives considered
|
||||
|
||||
|
||||
+4
-3
@@ -395,9 +395,10 @@ for the citizen's documents (their diploma). Two things can happen:
|
||||
`RegistratieVerlopen` external task, and the domain expires the registration to the terminal status
|
||||
**VERLOPEN** (the case is cancelled).
|
||||
|
||||
The real upload trigger (portal → BFF → domain → ACL → Documenten API) is S-10b; until then the
|
||||
"documents received" step is completing the task in Flowable, and the timeout is demonstrated by
|
||||
firing the timer early via the management API.
|
||||
The "documents received" trigger is wired end-to-end in S-10a: the self-service page shows a
|
||||
**"Documenten aanleveren"** button after submit (portal → BFF → domain → completes the wait). S-10b
|
||||
turns that into a real file upload stored in the ZGW Documenten API via the ACL. The timeout branch is
|
||||
demonstrated by firing the 30-day timer early via the management API.
|
||||
|
||||
```bash
|
||||
DOM=http://localhost:8080 # domain service
|
||||
|
||||
@@ -226,6 +226,40 @@ export class BffApiV1Service {
|
||||
);
|
||||
}
|
||||
|
||||
postSelfServiceRegistrationsIdDocuments<TData = void>(id: string, options?: HttpClientBodyOptions): Observable<TData>;
|
||||
postSelfServiceRegistrationsIdDocuments<TData = void>(id: string, options?: HttpClientEventOptions): Observable<HttpEvent<TData>>;
|
||||
postSelfServiceRegistrationsIdDocuments<TData = void>(id: string, options?: HttpClientResponseOptions): Observable<AngularHttpResponse<TData>>;
|
||||
postSelfServiceRegistrationsIdDocuments<TData = void>(
|
||||
id: string, options?: HttpClientObserveOptions): Observable<TData | HttpEvent<TData> | AngularHttpResponse<TData>> {
|
||||
if (options?.observe === 'events') {
|
||||
return this.http.post<TData>(
|
||||
`/self-service/registrations/${id}/documents`,
|
||||
undefined,{
|
||||
...(options as Omit<NonNullable<typeof options>, 'observe'>),
|
||||
observe: 'events',
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
if (options?.observe === 'response') {
|
||||
return this.http.post<TData>(
|
||||
`/self-service/registrations/${id}/documents`,
|
||||
undefined,{
|
||||
...(options as Omit<NonNullable<typeof options>, 'observe'>),
|
||||
observe: 'response',
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
return this.http.post<TData>(
|
||||
`/self-service/registrations/${id}/documents`,
|
||||
undefined,{
|
||||
...(options as Omit<NonNullable<typeof options>, 'observe'>),
|
||||
observe: 'body',
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
getOpenbaarRegister<TData = OpenbaarEntry[]>(params?: GetOpenbaarRegisterParams, options?: HttpClientBodyOptions): Observable<TData>;
|
||||
getOpenbaarRegister<TData = OpenbaarEntry[]>(params?: GetOpenbaarRegisterParams, options?: HttpClientEventOptions): Observable<HttpEvent<TData>>;
|
||||
getOpenbaarRegister<TData = OpenbaarEntry[]>(params?: GetOpenbaarRegisterParams, options?: HttpClientResponseOptions): Observable<AngularHttpResponse<TData>>;
|
||||
|
||||
@@ -27,6 +27,11 @@ public interface IDomainClient
|
||||
/// unknown or not the caller's (404), so the BFF can relay a 404 rather than a 500.</summary>
|
||||
Task<bool> WithdrawRegistrationAsync(string registrationId, string bsn, CancellationToken ct = default);
|
||||
|
||||
/// <summary>Provide the documents the caller's own registration is waiting for ("documenten
|
||||
/// aanleveren"). Owner-scoped by <paramref name="bsn"/>. Returns <c>false</c> when the domain
|
||||
/// reports the registration is unknown or not the caller's (404), so the BFF can relay a 404.</summary>
|
||||
Task<bool> ProvideDocumentsAsync(string registrationId, string bsn, CancellationToken ct = default);
|
||||
|
||||
/// <summary>The behandelaar's werkbak — registrations awaiting beoordeling.</summary>
|
||||
Task<IReadOnlyList<WerkbakItem>> GetWerkbakAsync(CancellationToken ct = default);
|
||||
|
||||
@@ -63,6 +68,17 @@ public sealed class DomainClient(HttpClient http) : IDomainClient
|
||||
return true;
|
||||
}
|
||||
|
||||
public async Task<bool> ProvideDocumentsAsync(string registrationId, string bsn, CancellationToken ct = default)
|
||||
{
|
||||
using var response = await http.PostAsJsonAsync(
|
||||
$"registrations/{registrationId}/documents", new { bsn }, ct);
|
||||
// The domain 404s an unknown or not-owned registration; relay that rather than fail hard.
|
||||
if (response.StatusCode == System.Net.HttpStatusCode.NotFound)
|
||||
return false;
|
||||
response.EnsureSuccessStatusCode();
|
||||
return true;
|
||||
}
|
||||
|
||||
public async Task<IReadOnlyList<WerkbakItem>> GetWerkbakAsync(CancellationToken ct = default)
|
||||
=> await http.GetFromJsonAsync<List<WerkbakItem>>("behandel/werkbak", ct) ?? [];
|
||||
|
||||
|
||||
@@ -104,6 +104,26 @@ app.MapPost("/self-service/registrations/{id}/withdraw", async (string id, Claim
|
||||
.Produces(StatusCodes.Status401Unauthorized)
|
||||
.Produces(StatusCodes.Status404NotFound);
|
||||
|
||||
// Self-service provide-documents (S-10a): the signed-in zorgprofessional supplies the documents their
|
||||
// registration is waiting for ("documenten aanleveren"). The bsn comes from the DigiD token and is
|
||||
// forwarded to the domain, which owner-scopes the action and completes the WachtOpDocumenten task; a
|
||||
// registration that is unknown or not the caller's comes back 404. The real file upload + ZGW storage
|
||||
// is S-10b — this is the trigger that unblocks the process.
|
||||
app.MapPost("/self-service/registrations/{id}/documents", async (string id, ClaimsPrincipal user, IDomainClient domain, CancellationToken ct) =>
|
||||
{
|
||||
var bsn = user.FindFirstValue("bsn");
|
||||
if (string.IsNullOrWhiteSpace(bsn))
|
||||
return Results.BadRequest("The token carries no bsn claim.");
|
||||
|
||||
var provided = await domain.ProvideDocumentsAsync(id, bsn, ct);
|
||||
return provided ? Results.NoContent() : Results.NotFound();
|
||||
})
|
||||
.RequireAuthorization()
|
||||
.Produces(StatusCodes.Status204NoContent)
|
||||
.Produces(StatusCodes.Status400BadRequest)
|
||||
.Produces(StatusCodes.Status401Unauthorized)
|
||||
.Produces(StatusCodes.Status404NotFound);
|
||||
|
||||
// Openbaar register: an anonymous public lookup that exposes only public-safe fields (S-09).
|
||||
app.MapGet("/openbaar/register", async (string? q, IProjectionClient projection, CancellationToken ct) =>
|
||||
{
|
||||
|
||||
@@ -94,6 +94,18 @@ internal sealed class FakeDomainClient : IDomainClient
|
||||
return Task.FromResult(WithdrawSucceeds);
|
||||
}
|
||||
|
||||
public (string RegistrationId, string Bsn)? DocumentsProvidedFor { get; private set; }
|
||||
|
||||
/// <summary>Whether the fake domain reports the provide-documents as done (true → 204) or
|
||||
/// not-found/not-owned (false → 404). Tests set this to exercise the relay.</summary>
|
||||
public bool ProvideDocumentsSucceeds { get; set; } = true;
|
||||
|
||||
public Task<bool> ProvideDocumentsAsync(string registrationId, string bsn, CancellationToken ct = default)
|
||||
{
|
||||
DocumentsProvidedFor = (registrationId, bsn);
|
||||
return Task.FromResult(ProvideDocumentsSucceeds);
|
||||
}
|
||||
|
||||
public (string RegistrationId, string Besluit)? Decided { get; private set; }
|
||||
|
||||
public Task<IReadOnlyList<WerkbakItem>> GetWerkbakAsync(CancellationToken ct = default)
|
||||
|
||||
@@ -112,5 +112,46 @@ public class SelfServiceEndpointTests
|
||||
Assert.Equal(HttpStatusCode.NotFound, response.StatusCode);
|
||||
}
|
||||
|
||||
private static HttpRequestMessage ProvideDocuments(string? bearer, string id = "reg-123")
|
||||
{
|
||||
var request = new HttpRequestMessage(HttpMethod.Post, $"/self-service/registrations/{id}/documents");
|
||||
if (bearer is not null)
|
||||
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", bearer);
|
||||
return request;
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Rejects_providing_documents_without_a_token()
|
||||
{
|
||||
using var factory = new BffFactory();
|
||||
|
||||
var response = await factory.CreateClient().SendAsync(ProvideDocuments(bearer: null));
|
||||
|
||||
Assert.Equal(HttpStatusCode.Unauthorized, response.StatusCode);
|
||||
Assert.Null(factory.Domain.DocumentsProvidedFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Provides_documents_for_the_callers_registration_forwarding_the_id_and_bsn()
|
||||
{
|
||||
using var factory = new BffFactory();
|
||||
|
||||
var response = await factory.CreateClient().SendAsync(ProvideDocuments(TestTokens.Valid("123456782"), "reg-9"));
|
||||
|
||||
Assert.Equal(HttpStatusCode.NoContent, response.StatusCode);
|
||||
Assert.Equal(("reg-9", "123456782"), factory.Domain.DocumentsProvidedFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Relays_not_found_providing_documents_for_an_unknown_or_not_owned_registration()
|
||||
{
|
||||
using var factory = new BffFactory();
|
||||
factory.Domain.ProvideDocumentsSucceeds = false;
|
||||
|
||||
var response = await factory.CreateClient().SendAsync(ProvideDocuments(TestTokens.Valid("123456782")));
|
||||
|
||||
Assert.Equal(HttpStatusCode.NotFound, response.StatusCode);
|
||||
}
|
||||
|
||||
private sealed record SubmitAcceptedDto(string RegistrationId, string Status);
|
||||
}
|
||||
|
||||
@@ -61,6 +61,37 @@
|
||||
}
|
||||
}
|
||||
},
|
||||
"/self-service/registrations/{id}/documents": {
|
||||
"post": {
|
||||
"tags": [
|
||||
"Bff.Api"
|
||||
],
|
||||
"parameters": [
|
||||
{
|
||||
"name": "id",
|
||||
"in": "path",
|
||||
"required": true,
|
||||
"schema": {
|
||||
"type": "string"
|
||||
}
|
||||
}
|
||||
],
|
||||
"responses": {
|
||||
"204": {
|
||||
"description": "No Content"
|
||||
},
|
||||
"400": {
|
||||
"description": "Bad Request"
|
||||
},
|
||||
"401": {
|
||||
"description": "Unauthorized"
|
||||
},
|
||||
"404": {
|
||||
"description": "Not Found"
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"/openbaar/register": {
|
||||
"get": {
|
||||
"tags": [
|
||||
|
||||
@@ -29,6 +29,7 @@ builder.Services.AddScoped<SubmitRegistration>();
|
||||
builder.Services.AddScoped<ApproveRegistration>();
|
||||
builder.Services.AddScoped<BeoordeelRegistratie>();
|
||||
builder.Services.AddScoped<WithdrawRegistration>();
|
||||
builder.Services.AddScoped<ProvideDocuments>();
|
||||
builder.Services.AddScoped<Werkbak>();
|
||||
builder.Services.AddScoped<OpenZaakWorker>();
|
||||
builder.Services.AddScoped<OpenZaakJobProcessor>();
|
||||
@@ -107,6 +108,23 @@ app.MapPost("/registrations/{id}/withdraw", async (string id, WithdrawRequest bo
|
||||
return outcome == WithdrawOutcome.Withdrawn ? Results.NoContent() : Results.NotFound();
|
||||
});
|
||||
|
||||
// Provide documents (S-10a): the zorgprofessional supplies the documents their registration is parked
|
||||
// waiting for, completing the WachtOpDocumenten task so the process advances to beoordeling (ADR-0017).
|
||||
// Owner-scoped by the caller's bsn (the BFF forwards it from the DigiD token); unknown or not-the-
|
||||
// caller's is 404 (indistinguishable). Idempotent — completing an already-left wait is a no-op. The
|
||||
// real file upload + ZGW storage is S-10b; this endpoint is the trigger that unblocks the process.
|
||||
app.MapPost("/registrations/{id}/documents", async (string id, ProvideDocumentsRequest body, ProvideDocuments provide, CancellationToken ct) =>
|
||||
{
|
||||
if (!Guid.TryParse(id, out var guid))
|
||||
return Results.NotFound();
|
||||
|
||||
if (string.IsNullOrWhiteSpace(body?.Bsn))
|
||||
return Results.BadRequest(new { error = "A bsn is required to provide documents." });
|
||||
|
||||
var outcome = await provide.HandleAsync(new ProvideDocumentsCommand(new RegistrationId(guid), body.Bsn), ct);
|
||||
return outcome == ProvideDocumentsOutcome.Accepted ? Results.NoContent() : Results.NotFound();
|
||||
});
|
||||
|
||||
// The behandelaar's werkbak (S-12): the registrations awaiting beoordeling, read from the open
|
||||
// Beoordelen user tasks (§8.2) and enriched with bsn + status. The BFF proxies this behind
|
||||
// medewerker-realm + behandelaar-role authorization; the domain trusts its callers (§8.3).
|
||||
@@ -134,6 +152,8 @@ public sealed record DecideRequest(string Besluit);
|
||||
|
||||
public sealed record WithdrawRequest(string Bsn);
|
||||
|
||||
public sealed record ProvideDocumentsRequest(string Bsn);
|
||||
|
||||
public sealed record RegistrationResponse(string RegistrationId, string Status, string? ZaakUrl);
|
||||
|
||||
public partial class Program;
|
||||
|
||||
@@ -12,9 +12,11 @@ namespace Big.Application;
|
||||
public sealed class ExpireRegistrationWorker(IRegistrationStore store)
|
||||
{
|
||||
/// <summary>
|
||||
/// Process the job. Idempotent: a redelivered job whose registration is already VERLOPEN is a
|
||||
/// no-op — not persisted again (§8.6, at-least-once delivery). An unknown registration is an error:
|
||||
/// it throws, leaving the job un-completed for Flowable to redeliver.
|
||||
/// Process the job. Idempotent and tolerant of races (§8.6, at-least-once delivery): a job whose
|
||||
/// registration is already resolved — a redelivered expiry (VERLOPEN), or one withdrawn/decided
|
||||
/// while it waited (INGETROKKEN/INGESCHREVEN/AFGEWEZEN) — is a no-op, so the job still completes
|
||||
/// rather than throwing into a redelivery loop. Only a still-open registration is expired. An
|
||||
/// unknown registration is an error: it throws, leaving the job un-completed for Flowable to redeliver.
|
||||
/// </summary>
|
||||
public async Task HandleAsync(RegistratieVerlopenJob job, CancellationToken ct = default)
|
||||
{
|
||||
@@ -24,8 +26,9 @@ public sealed class ExpireRegistrationWorker(IRegistrationStore store)
|
||||
?? throw new InvalidOperationException(
|
||||
$"No registration {job.RegistrationId} for RegistratieVerlopen job {job.JobId}.");
|
||||
|
||||
// A redelivered job whose registration is already VERLOPEN completes without persisting again.
|
||||
if (registration.Status == RegistrationStatus.Verlopen)
|
||||
// Only a still-open registration lapses; an already-resolved one (expired, or withdrawn/decided
|
||||
// while it waited) is left untouched so the job can complete without violating the aggregate.
|
||||
if (registration.Status is not (RegistrationStatus.Ingediend or RegistrationStatus.InBehandeling))
|
||||
return;
|
||||
|
||||
registration.Expire();
|
||||
|
||||
@@ -0,0 +1,47 @@
|
||||
using Big.Domain;
|
||||
|
||||
namespace Big.Application;
|
||||
|
||||
/// <summary>A zorgprofessional's signal that they have supplied the documents their registration is
|
||||
/// waiting for ("documenten aanleveren"). <paramref name="Bsn"/> is the authenticated caller (from the
|
||||
/// DigiD token, forwarded by the BFF): only the registration's own bsn may provide its documents.</summary>
|
||||
public sealed record ProvideDocumentsCommand(RegistrationId RegistrationId, string Bsn);
|
||||
|
||||
/// <summary>The outcome of a provide-documents request.</summary>
|
||||
public enum ProvideDocumentsOutcome
|
||||
{
|
||||
/// <summary>The documents were accepted; the process's document wait was completed (if any).</summary>
|
||||
Accepted,
|
||||
|
||||
/// <summary>No registration with that id belongs to the caller — unknown, or owned by someone else
|
||||
/// (the two are deliberately indistinguishable, so the endpoint reveals neither).</summary>
|
||||
NotFound,
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// The provide-documents use case (S-10a): a zorgprofessional supplies the documents their registration
|
||||
/// is parked waiting for, completing the WachtOpDocumenten task so the registratie process leaves the
|
||||
/// 30-day wait and continues to beoordeling (ADR-0017). Owner-scoped by bsn. Completing the wait is
|
||||
/// best-effort: if the registration never started a process (or already left the wait), the request
|
||||
/// still stands, mirroring how <see cref="WithdrawRegistration"/> cancels best-effort. The actual file
|
||||
/// upload and its ZGW storage via the ACL is S-10b; this is the trigger that unblocks the process.
|
||||
/// </summary>
|
||||
public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient workflow)
|
||||
{
|
||||
public async Task<ProvideDocumentsOutcome> HandleAsync(ProvideDocumentsCommand command, CancellationToken ct = default)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(command);
|
||||
|
||||
var registration = await store.GetAsync(command.RegistrationId, ct);
|
||||
|
||||
// Unknown, or not the caller's registration: report NotFound either way (don't reveal which).
|
||||
if (registration is null || registration.Bsn != command.Bsn)
|
||||
return ProvideDocumentsOutcome.NotFound;
|
||||
|
||||
// Complete the document wait (if a process is running) so beoordeling can proceed.
|
||||
if (registration.ProcessInstanceId is not null)
|
||||
await workflow.CompleteDocumentWaitAsync(registration.ProcessInstanceId, ct);
|
||||
|
||||
return ProvideDocumentsOutcome.Accepted;
|
||||
}
|
||||
}
|
||||
@@ -48,6 +48,25 @@ public class ExpireRegistrationWorkerTests
|
||||
Assert.Equal(RegistrationStatus.Verlopen, (await store.GetAsync(registration.Id))!.Status);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task An_already_resolved_registration_is_left_alone_and_the_job_completes()
|
||||
{
|
||||
// Race with S-11: the citizen withdrew while parked at WachtOpDocumenten, so the aggregate is
|
||||
// already terminal (INGETROKKEN) when the timer's job arrives. Expiring it would violate the
|
||||
// aggregate's invariant; the worker must instead no-op (and let the job complete), not throw
|
||||
// into a redelivery loop.
|
||||
var store = new FakeRegistrationStore();
|
||||
var registration = Submitted();
|
||||
registration.Withdraw();
|
||||
store.Seed(registration);
|
||||
|
||||
await new ExpireRegistrationWorker(store).HandleAsync(
|
||||
new RegistratieVerlopenJob("job-7", registration.Id));
|
||||
|
||||
Assert.Equal(0, store.SaveCount);
|
||||
Assert.Equal(RegistrationStatus.Ingetrokken, (await store.GetAsync(registration.Id))!.Status);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task An_unknown_registration_throws_so_the_job_is_redelivered()
|
||||
{
|
||||
|
||||
@@ -0,0 +1,85 @@
|
||||
using Big.Application;
|
||||
using Big.Domain;
|
||||
|
||||
namespace Big.Tests;
|
||||
|
||||
// S-10a (#102): the "documents received" use case. A zorgprofessional supplies the documents their
|
||||
// registration is waiting for; the handler completes the WachtOpDocumenten task via the Workflow Client
|
||||
// so the process leaves the 30-day wait and continues to beoordeling. Owner-scoped by the caller's bsn,
|
||||
// like WithdrawRegistration. (The real file upload + ZGW storage is S-10b; this is the trigger path.)
|
||||
public class ProvideDocumentsTests
|
||||
{
|
||||
private const string Bsn = "123456782";
|
||||
|
||||
private static Registration Submitted(string processInstanceId = "proc-1")
|
||||
{
|
||||
var registration = Registration.Submit(Bsn);
|
||||
registration.RecordProcessStarted(processInstanceId);
|
||||
return registration;
|
||||
}
|
||||
|
||||
private static ProvideDocumentsCommand Command(RegistrationId id, string bsn = Bsn) => new(id, bsn);
|
||||
|
||||
[Fact]
|
||||
public async Task Providing_documents_completes_the_document_wait()
|
||||
{
|
||||
var store = new FakeRegistrationStore();
|
||||
var registration = Submitted("proc-42");
|
||||
store.Seed(registration);
|
||||
var workflow = new FakeWorkflowClient();
|
||||
var handler = new ProvideDocuments(store, workflow);
|
||||
|
||||
var outcome = await handler.HandleAsync(Command(registration.Id));
|
||||
|
||||
Assert.Equal(ProvideDocumentsOutcome.Accepted, outcome);
|
||||
Assert.Equal("proc-42", workflow.CompletedDocumentWaitFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task A_different_bsn_cannot_provide_documents()
|
||||
{
|
||||
// Owner-scoping: only the registration's own bsn may supply its documents. Another bsn is told
|
||||
// NotFound (existence not revealed) and the wait is not completed.
|
||||
var store = new FakeRegistrationStore();
|
||||
var registration = Submitted();
|
||||
store.Seed(registration);
|
||||
var workflow = new FakeWorkflowClient();
|
||||
var handler = new ProvideDocuments(store, workflow);
|
||||
|
||||
var outcome = await handler.HandleAsync(Command(registration.Id, bsn: "999999990"));
|
||||
|
||||
Assert.Equal(ProvideDocumentsOutcome.NotFound, outcome);
|
||||
Assert.Null(workflow.CompletedDocumentWaitFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Providing_for_an_unknown_registration_is_not_found()
|
||||
{
|
||||
var store = new FakeRegistrationStore();
|
||||
var handler = new ProvideDocuments(store, new FakeWorkflowClient());
|
||||
|
||||
Assert.Equal(ProvideDocumentsOutcome.NotFound, await handler.HandleAsync(Command(RegistrationId.New())));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Providing_before_a_process_started_is_accepted_without_calling_the_workflow()
|
||||
{
|
||||
// No process yet → no wait task to complete; the request still stands (best-effort, mirroring
|
||||
// WithdrawRegistration) and the Workflow Client is not called.
|
||||
var store = new FakeRegistrationStore();
|
||||
var registration = Registration.Submit(Bsn); // no RecordProcessStarted
|
||||
store.Seed(registration);
|
||||
var workflow = new FakeWorkflowClient();
|
||||
var handler = new ProvideDocuments(store, workflow);
|
||||
|
||||
var outcome = await handler.HandleAsync(Command(registration.Id));
|
||||
|
||||
Assert.Equal(ProvideDocumentsOutcome.Accepted, outcome);
|
||||
Assert.Null(workflow.CompletedDocumentWaitFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Rejects_a_null_command()
|
||||
=> await Assert.ThrowsAsync<ArgumentNullException>(() =>
|
||||
new ProvideDocuments(new FakeRegistrationStore(), new FakeWorkflowClient()).HandleAsync(null!));
|
||||
}
|
||||
@@ -72,6 +72,9 @@ public sealed class CapturingDomainClient : IDomainClient
|
||||
public Task<bool> WithdrawRegistrationAsync(string registrationId, string bsn, CancellationToken ct = default)
|
||||
=> Task.FromResult(true);
|
||||
|
||||
public Task<bool> ProvideDocumentsAsync(string registrationId, string bsn, CancellationToken ct = default)
|
||||
=> Task.FromResult(true);
|
||||
|
||||
public Task<IReadOnlyList<WerkbakItem>> GetWerkbakAsync(CancellationToken ct = default)
|
||||
=> Task.FromResult<IReadOnlyList<WerkbakItem>>([]);
|
||||
|
||||
|
||||
@@ -1,11 +1,15 @@
|
||||
import { expect, test } from '@playwright/test';
|
||||
|
||||
// Walking-skeleton happy path (S-08d + S-09 + S-09b + S-12): a zorgprofessional logs in via mock
|
||||
// DigiD and submits through the self-service portal → BFF → domain; the entry appears in the openbaar
|
||||
// register as INGEDIEND; a behandelaar then logs in to the behandel portal, finds the registration in
|
||||
// the werkbak, and approves it (goedkeuren); the decision completes the Flowable Beoordelen task and
|
||||
// flows via the ACL → NRC → event-subscriber → projection, and the openbaar register shows INGESCHREVEN.
|
||||
test('DigiD submit → public INGEDIEND → behandelaar goedkeurt → public INGESCHREVEN', async ({ page }) => {
|
||||
// Walking-skeleton happy path (S-08d + S-09 + S-09b + S-12 + S-10a): a zorgprofessional logs in via
|
||||
// mock DigiD and submits through the self-service portal → BFF → domain; the entry appears in the
|
||||
// openbaar register as INGEDIEND; the citizen supplies the documents the process is waiting for
|
||||
// (S-10a); a behandelaar then logs in to the behandel portal, finds the registration in the werkbak,
|
||||
// and approves it (goedkeuren); the decision completes the Flowable Beoordelen task and flows via the
|
||||
// ACL → NRC → event-subscriber → projection, and the openbaar register shows INGESCHREVEN.
|
||||
test('DigiD submit → public INGEDIEND → documenten → behandelaar goedkeurt → public INGESCHREVEN', async ({
|
||||
page,
|
||||
context,
|
||||
}) => {
|
||||
// Visiting the guarded page redirects to the Keycloak (mock DigiD) login.
|
||||
await page.goto('/');
|
||||
|
||||
@@ -26,42 +30,53 @@ test('DigiD submit → public INGEDIEND → behandelaar goedkeurt → public ING
|
||||
expect(reference, 'the confirmation shows a registration reference').toBeTruthy();
|
||||
|
||||
// The openbaar register (anonymous, its own origin) shows the submitted entry once the projection
|
||||
// catches up. The projection updates asynchronously (NRC → event-subscriber), and the register loads
|
||||
// on open, so reload until *this* submission's row appears. We poll on the reference cell (not a
|
||||
// generic INGEDIEND cell): the shared verify stack already holds INGEDIEND rows from earlier checks,
|
||||
// so a status-only poll would short-circuit on a stale row before our row is projected.
|
||||
await page.goto('http://openbaar/');
|
||||
await expect(page.getByRole('heading', { name: /Openbaar BIG-register/i })).toBeVisible();
|
||||
// catches up. We check it on a SEPARATE page so the self-service tab keeps its (in-memory) submitted
|
||||
// state — the "Documenten aanleveren" action below acts on that same session. The projection updates
|
||||
// asynchronously (NRC → event-subscriber), so reload until *this* submission's row appears. We poll
|
||||
// on the reference cell (not a generic INGEDIEND cell): the shared verify stack already holds
|
||||
// INGEDIEND rows from earlier checks, so a status-only poll would short-circuit on a stale row.
|
||||
const staff = await context.newPage();
|
||||
await staff.goto('http://openbaar/');
|
||||
await expect(staff.getByRole('heading', { name: /Openbaar BIG-register/i })).toBeVisible();
|
||||
|
||||
// #78: the reference shown in the public register must be the exact one the citizen saw on the
|
||||
// submit confirmation — no mismatch between the two portals.
|
||||
await expect
|
||||
.poll(async () => {
|
||||
await page.reload();
|
||||
return page.getByRole('cell', { name: reference }).count();
|
||||
await staff.reload();
|
||||
return staff.getByRole('cell', { name: reference }).count();
|
||||
}, { timeout: 30_000, intervals: [1_000, 2_000, 3_000, 5_000] })
|
||||
.toBeGreaterThan(0);
|
||||
await expect(page.getByRole('row', { name: reference }).getByRole('cell', { name: 'INGEDIEND' }))
|
||||
await expect(staff.getByRole('row', { name: reference }).getByRole('cell', { name: 'INGEDIEND' }))
|
||||
.toBeVisible();
|
||||
|
||||
// A behandelaar picks the registration up in the behandel-portal werkbak and approves it
|
||||
// (goedkeuren) — the S-12 flow that replaces the temporary admin endpoint. Navigating here switches
|
||||
// to the medewerker realm (a different Keycloak realm than the citizen's digid session).
|
||||
await page.goto('http://behandel/');
|
||||
await page.locator('#username').fill('merel-behandelaar');
|
||||
await page.locator('#password').fill('test123');
|
||||
await page.locator('#kc-login').click();
|
||||
// Provide the documents the registration is waiting for (S-10a), on the still-open self-service tab.
|
||||
// The process parks at WachtOpDocumenten only after the zaak is opened; the INGEDIEND row above proves
|
||||
// the zaak exists — so the OpenZaak worker has completed and the process is now at the wait — which is
|
||||
// why we supply the documents here rather than right after submit, when the trigger would race the
|
||||
// wait and no-op. (S-10b turns this into a real file upload; here it is the trigger that unblocks
|
||||
// beoordeling.)
|
||||
await page.getByRole('button', { name: /documenten aanleveren/i }).click();
|
||||
await expect(page.getByText(/documenten zijn aangeleverd/i)).toBeVisible();
|
||||
|
||||
await expect(page.getByRole('heading', { name: /Werkbak/i })).toBeVisible();
|
||||
// A behandelaar picks the registration up in the behandel-portal werkbak and approves it (goedkeuren)
|
||||
// — the S-12 flow that replaces the temporary admin endpoint. The staff tab switches to the
|
||||
// medewerker realm (a different Keycloak realm than the citizen's digid session).
|
||||
await staff.goto('http://behandel/');
|
||||
await staff.locator('#username').fill('merel-behandelaar');
|
||||
await staff.locator('#password').fill('test123');
|
||||
await staff.locator('#kc-login').click();
|
||||
|
||||
// The registration parks at the Beoordelen user task only after the worker has opened its zaak, so
|
||||
await expect(staff.getByRole('heading', { name: /Werkbak/i })).toBeVisible();
|
||||
|
||||
// The registration reaches the Beoordelen user task only after its documents are provided (above), so
|
||||
// it appears in the werkbak asynchronously — reload until this reference's row shows up. Target the
|
||||
// decide button by reference (not a generic "Goedkeuren"): the shared verify stack holds other open
|
||||
// tasks, so a positional match could act on someone else's registration.
|
||||
const goedkeuren = page.getByRole('button', { name: `Goedkeuren ${reference}` });
|
||||
const goedkeuren = staff.getByRole('button', { name: `Goedkeuren ${reference}` });
|
||||
await expect
|
||||
.poll(async () => {
|
||||
await page.reload();
|
||||
await staff.reload();
|
||||
return goedkeuren.count();
|
||||
}, { timeout: 30_000, intervals: [1_000, 2_000, 3_000, 5_000] })
|
||||
.toBeGreaterThan(0);
|
||||
@@ -69,7 +84,7 @@ test('DigiD submit → public INGEDIEND → behandelaar goedkeurt → public ING
|
||||
// Click and wait for the decide POST to finish (204) BEFORE leaving the page. `click()` only
|
||||
// dispatches the request; navigating away immediately cancels it in flight (nginx logs a 499) and
|
||||
// the decision never reaches the domain — so the registration would stay INGEDIEND.
|
||||
const decided = page.waitForResponse(
|
||||
const decided = staff.waitForResponse(
|
||||
(r) =>
|
||||
r.url().includes(`/behandel/registrations/${reference}/decide`) &&
|
||||
r.request().method() === 'POST',
|
||||
@@ -79,11 +94,11 @@ test('DigiD submit → public INGEDIEND → behandelaar goedkeurt → public ING
|
||||
|
||||
// The approval flows back to the projection; back on the openbaar register *our* row (matched by
|
||||
// its reference) now shows INGESCHREVEN.
|
||||
await page.goto('http://openbaar/');
|
||||
await staff.goto('http://openbaar/');
|
||||
await expect
|
||||
.poll(async () => {
|
||||
await page.reload();
|
||||
return page.getByRole('row', { name: reference }).getByRole('cell', { name: 'INGESCHREVEN' }).count();
|
||||
await staff.reload();
|
||||
return staff.getByRole('row', { name: reference }).getByRole('cell', { name: 'INGESCHREVEN' }).count();
|
||||
}, { timeout: 30_000, intervals: [1_000, 2_000, 3_000, 5_000] })
|
||||
.toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user