Compare commits
11
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d943b54ce8 | ||
|
|
00c5077fe4 | ||
|
|
5180253826 | ||
|
|
9bd71f1e78 | ||
|
|
3f04cb856f | ||
|
|
9421aa007a | ||
|
|
c536c965de | ||
|
|
5add817c10 | ||
|
|
11ef26d8cc | ||
|
|
f39ec2afa3 | ||
|
|
67a60e7f63 |
+6
-10
@@ -201,21 +201,17 @@ _Split from the original S-09 — scoped to the portal only; the approval flow i
|
||||
|
||||
Split (issue #11 closed) into two independently-demoable slices per §13 — the original spanned six net-new surfaces including a new ZGW boundary:
|
||||
|
||||
#### S-10a · Document-wait task + 30-day timeout cancellation + provision trigger — #102
|
||||
#### S-10a · Document-wait task + 30-day timeout cancellation (workflow spine) — #102
|
||||
|
||||
**Outcome:** BPMN gains a `WachtOpDocumenten` user task with a 30-day (P30D) interrupting boundary timer. On timeout the case is cancelled — the timer runs to a dedicated cancel end-event and the domain aggregate moves to a new terminal status `Verlopen` via an external-worker (mirrors S-14 escalation / S-11 withdrawal). "Documents received" is wired end-to-end (domain endpoint + BFF + a "Documenten aanleveren" button on the self-service page) so the walking-skeleton e2e stays green — but the document is **not yet stored** in ZGW; that is S-10b.
|
||||
**Outcome:** BPMN gains a `WachtOpDocumenten` user task with a 30-day (P30D) interrupting boundary timer. On timeout the case is cancelled — the timer runs to a dedicated cancel end-event and the domain aggregate moves to a new terminal status via an external-worker (mirrors S-14 escalation / S-11 withdrawal). Backend only, no frontend.
|
||||
|
||||
**Acceptance:** BDD both branches (documents-in-time vs timeout-cancel); live timer-fire via the management-API "move" idiom; the registration e2e provides documents before the behandelaar step.
|
||||
**Acceptance:** BDD both branches (documents-in-time vs timeout-cancel); live timer-fire via the management-API "move" idiom.
|
||||
|
||||
#### S-10b · Real diploma upload stored via the ACL Documenten API — #103
|
||||
#### S-10b · Diploma upload via ACL Documenten API + self-service portal — #103
|
||||
|
||||
**Outcome:** the self-service "Documenten aanleveren" action becomes a real file upload; the file (base64-encoded end-to-end) is stored in the ZGW Documenten (DRC) API as an `enkelvoudiginformatieobject` and related to the zaak, with all document calls routed through the ACL (§8.1, ADR-0018). Builds on the S-10a trigger/wait. Depends on #102.
|
||||
**Outcome:** the self-service portal supports diploma upload; the document is stored in the ZGW Documenten (DRC) API and related to the zaak, with all document calls routed through the ACL (§8.1). A successful upload completes the `WachtOpDocumenten` task from S-10a. Depends on #102.
|
||||
|
||||
**Acceptance:** ACL Documenten gateway integration test (real OpenZaak); Playwright e2e uploads a real PDF.
|
||||
|
||||
#### S-10c · Close the ZGW zaak on document-timeout expiry — #106
|
||||
|
||||
**Outcome:** when the 30-day term lapses (S-10a `RegistratieVerlopen`), the ZGW zaak is set to a cancellation status (not just the domain aggregate → `Verlopen`). Adds a cancellation statustype/resultaattype to the seed + an ACL method + expiry-worker wiring. Carved from S-10b (ADR-0017/0018). Depends on #103.
|
||||
**Acceptance:** BDD upload-completes-wait-task; Playwright e2e upload journey.
|
||||
|
||||
### S-11 · Withdrawal (Flow 3)
|
||||
|
||||
|
||||
@@ -11,33 +11,6 @@
|
||||
<p utrecht-paragraph role="status">
|
||||
Uw registratie is ontvangen. Referentie: {{ reference() }}.
|
||||
</p>
|
||||
@if (documentsProvided()) {
|
||||
<p utrecht-paragraph role="status">Uw documenten zijn aangeleverd.</p>
|
||||
} @else {
|
||||
@if (provideDocumentsFailed()) {
|
||||
<p utrecht-paragraph role="alert">
|
||||
Het aanleveren van uw documenten is niet gelukt. Probeer het opnieuw.
|
||||
</p>
|
||||
}
|
||||
<p utrecht-paragraph>Lever uw diploma aan (PDF).</p>
|
||||
<label utrecht-form-label for="diploma">Diploma</label>
|
||||
<input
|
||||
id="diploma"
|
||||
type="file"
|
||||
accept="application/pdf"
|
||||
[disabled]="providingDocuments()"
|
||||
(change)="onFileSelected($event)"
|
||||
/>
|
||||
<button
|
||||
utrecht-button
|
||||
appearance="primary-action-button"
|
||||
type="button"
|
||||
[disabled]="providingDocuments() || !selectedFile()"
|
||||
(click)="provideDocuments()"
|
||||
>
|
||||
Documenten aanleveren
|
||||
</button>
|
||||
}
|
||||
@if (withdrawFailed()) {
|
||||
<p utrecht-paragraph role="alert">
|
||||
Het intrekken van uw registratie is niet gelukt. Probeer het opnieuw.
|
||||
|
||||
@@ -20,12 +20,10 @@ class FakeAuth extends AuthService {
|
||||
function providers(
|
||||
post = vi.fn().mockReturnValue(of({ registrationId: 'reg-9', status: 'Ingediend' })),
|
||||
withdraw = vi.fn().mockReturnValue(of(undefined)),
|
||||
provideDocuments = vi.fn().mockReturnValue(of(undefined)),
|
||||
) {
|
||||
return {
|
||||
post,
|
||||
withdraw,
|
||||
provideDocuments,
|
||||
providers: [
|
||||
{ provide: AuthService, useClass: FakeAuth },
|
||||
{
|
||||
@@ -33,7 +31,6 @@ function providers(
|
||||
useValue: {
|
||||
postSelfServiceRegistrations: post,
|
||||
postSelfServiceRegistrationsIdWithdraw: withdraw,
|
||||
postSelfServiceRegistrationsIdDocuments: provideDocuments,
|
||||
},
|
||||
},
|
||||
],
|
||||
@@ -83,46 +80,6 @@ describe('RegistrationPage', () => {
|
||||
expect(await screen.findByText(/ingetrokken/i)).toBeTruthy();
|
||||
});
|
||||
|
||||
// A small PDF file the citizen "uploads"; the component base64-encodes it client-side.
|
||||
const diploma = () => new File([new Uint8Array([1, 2, 3])], 'diploma.pdf', { type: 'application/pdf' });
|
||||
|
||||
it('uploads a chosen diploma after submitting, and doing so confirms', async () => {
|
||||
const { provideDocuments, providers: p } = providers();
|
||||
await render(RegistrationPage, { providers: p });
|
||||
|
||||
fireEvent.click(screen.getByRole('button', { name: /indienen/i }));
|
||||
await screen.findByText(/ontvangen/i);
|
||||
|
||||
// Choose the file, then upload it.
|
||||
fireEvent.change(screen.getByLabelText(/diploma/i), { target: { files: [diploma()] } });
|
||||
fireEvent.click(await screen.findByRole('button', { name: /documenten aanleveren/i }));
|
||||
|
||||
// The upload is keyed by the reference and carries the base64 file + its name; the page confirms.
|
||||
expect(await screen.findByText(/documenten.*aangeleverd/i)).toBeTruthy();
|
||||
expect(provideDocuments).toHaveBeenCalledWith(
|
||||
'reg-9',
|
||||
expect.objectContaining({ fileName: 'diploma.pdf', contentType: 'application/pdf', contentBase64: expect.any(String) }),
|
||||
);
|
||||
});
|
||||
|
||||
it('surfaces a diploma-upload failure and keeps the action available', async () => {
|
||||
const { providers: p } = providers(
|
||||
vi.fn().mockReturnValue(of({ registrationId: 'reg-9', status: 'Ingediend' })),
|
||||
vi.fn().mockReturnValue(of(undefined)),
|
||||
vi.fn().mockReturnValue(throwError(() => new Error('documents rejected'))),
|
||||
);
|
||||
await render(RegistrationPage, { providers: p });
|
||||
|
||||
fireEvent.click(screen.getByRole('button', { name: /indienen/i }));
|
||||
await screen.findByText(/ontvangen/i);
|
||||
fireEvent.change(screen.getByLabelText(/diploma/i), { target: { files: [diploma()] } });
|
||||
fireEvent.click(await screen.findByRole('button', { name: /documenten aanleveren/i }));
|
||||
|
||||
expect(await screen.findByRole('alert')).toBeTruthy();
|
||||
expect(screen.queryByText(/aangeleverd/i)).toBeNull();
|
||||
expect(screen.getByRole('button', { name: /documenten aanleveren/i })).toBeTruthy();
|
||||
});
|
||||
|
||||
it('surfaces a withdraw failure and keeps the action available', async () => {
|
||||
const { providers: p } = providers(
|
||||
vi.fn().mockReturnValue(of({ registrationId: 'reg-9', status: 'Ingediend' })),
|
||||
|
||||
@@ -26,10 +26,6 @@ export class RegistrationPage {
|
||||
protected readonly withdrawing = signal(false);
|
||||
protected readonly withdrawn = signal(false);
|
||||
protected readonly withdrawFailed = signal(false);
|
||||
protected readonly providingDocuments = signal(false);
|
||||
protected readonly documentsProvided = signal(false);
|
||||
protected readonly provideDocumentsFailed = signal(false);
|
||||
protected readonly selectedFile = signal<File | undefined>(undefined);
|
||||
|
||||
submit(): void {
|
||||
this.submitting.set(true);
|
||||
@@ -48,46 +44,6 @@ export class RegistrationPage {
|
||||
});
|
||||
}
|
||||
|
||||
onFileSelected(event: Event): void {
|
||||
const input = event.target as HTMLInputElement;
|
||||
this.selectedFile.set(input.files?.[0] ?? undefined);
|
||||
}
|
||||
|
||||
async provideDocuments(): Promise<void> {
|
||||
const reference = this.reference();
|
||||
const file = this.selectedFile();
|
||||
if (!reference || !file) {
|
||||
return;
|
||||
}
|
||||
this.providingDocuments.set(true);
|
||||
this.provideDocumentsFailed.set(false);
|
||||
let contentBase64: string;
|
||||
try {
|
||||
contentBase64 = await readAsBase64(file);
|
||||
} catch {
|
||||
this.provideDocumentsFailed.set(true);
|
||||
this.providingDocuments.set(false);
|
||||
return;
|
||||
}
|
||||
this.bff
|
||||
.postSelfServiceRegistrationsIdDocuments(reference, {
|
||||
contentBase64,
|
||||
fileName: file.name,
|
||||
contentType: file.type || 'application/pdf',
|
||||
})
|
||||
.subscribe({
|
||||
next: () => {
|
||||
this.documentsProvided.set(true);
|
||||
this.providingDocuments.set(false);
|
||||
},
|
||||
// Surface the failure instead of swallowing it: keep the action so the user can retry.
|
||||
error: () => {
|
||||
this.provideDocumentsFailed.set(true);
|
||||
this.providingDocuments.set(false);
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
withdraw(): void {
|
||||
const reference = this.reference();
|
||||
if (!reference) {
|
||||
@@ -108,13 +64,3 @@ export class RegistrationPage {
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
/** Read a file's bytes as a base64 string (without the `data:...;base64,` prefix). */
|
||||
function readAsBase64(file: File): Promise<string> {
|
||||
return new Promise<string>((resolve, reject) => {
|
||||
const reader = new FileReader();
|
||||
reader.onload = () => resolve(((reader.result as string) ?? '').split(',', 2)[1] ?? '');
|
||||
reader.onerror = () => reject(reader.error ?? new Error('Could not read the file.'));
|
||||
reader.readAsDataURL(file);
|
||||
});
|
||||
}
|
||||
|
||||
@@ -42,16 +42,9 @@ worker expires the correlated aggregate to a new terminal status `Verlopen`.**
|
||||
- **Documents-in-time transition.** `IWorkflowClient.CompleteDocumentWaitAsync(processInstanceId)`
|
||||
completes the `WachtOpDocumenten` task (the Workflow Client remains the only code that talks to
|
||||
Flowable, §8.2). It is best-effort — a no-op if the instance already left the wait (continued, or
|
||||
timed out). The trigger is wired end-to-end in S-10a: a `ProvideDocuments` application use case behind
|
||||
an owner-scoped domain endpoint `POST /registrations/{id}/documents`, a BFF passthrough
|
||||
`POST /self-service/registrations/{id}/documents` (bsn from the DigiD token), and a "Documenten
|
||||
aanleveren" action on the self-service page — so the walking-skeleton e2e stays green (a registration
|
||||
can still reach the behandelaar). **S-10b replaces the stub trigger with a real file upload stored in
|
||||
the ZGW Documenten (DRC) API via the ACL**; the completion of the wait is unchanged.
|
||||
- *Why the trigger lives here, not in S-10b:* inserting the `WachtOpDocumenten` gate without any way
|
||||
to pass it breaks the submit→beoordeling e2e (a merge gate). Splitting "gate" from "means to pass
|
||||
the gate" across slices would leave `main` red, so S-10a owns both; S-10b is purely the ZGW storage
|
||||
behind the same action.
|
||||
timed out). The *trigger* that calls it (the portal upload) is wired in S-10b; S-10a builds and tests
|
||||
the completion path with the trigger stubbed (the live check completes the task directly to prove the
|
||||
in-time branch, and the domain acceptance drives the worker against an in-memory stand-in).
|
||||
|
||||
## Consequences
|
||||
|
||||
@@ -67,16 +60,12 @@ worker expires the correlated aggregate to a new terminal status `Verlopen`.**
|
||||
|
||||
**Negative / costs**
|
||||
|
||||
- Every registration now parks at `WachtOpDocumenten` before Beoordelen, so the other flows must supply
|
||||
documents first: the live-check blocks (S-11/S-12b/S-13/S-14) complete the task via Flowable, and the
|
||||
registration e2e clicks "Documenten aanleveren". A small, explicit step, but it touches every path
|
||||
through the process.
|
||||
- Every registration now parks at `WachtOpDocumenten` before Beoordelen, so the other live-check blocks
|
||||
(S-11/S-12b/S-13/S-14) must complete that task first — a small, explicit step standing in for the
|
||||
S-10b upload until it lands.
|
||||
- On expiry S-10a cancels the *process* and marks the aggregate `Verlopen` but does **not** set the ZGW
|
||||
*zaak* to a cancellation status — that needs a new ACL method + statustype seeding, which overlaps
|
||||
S-10b's ACL/infra work. Deferred to S-10b (or a follow-up); noted here as the S-10a/S-10b boundary.
|
||||
- Withdrawing while parked at `WachtOpDocumenten` marks the aggregate `Ingetrokken` but does not cancel
|
||||
the process (the withdrawal message boundary is on `Beoordelen`); the timeout worker tolerates this
|
||||
by no-op'ing on an already-resolved aggregate. Extending withdrawal to the wait state is a follow-up.
|
||||
|
||||
## Alternatives considered
|
||||
|
||||
|
||||
@@ -1,74 +0,0 @@
|
||||
# ADR-0018: Diploma upload is stored in the ZGW Documenten API, fronted by the ACL
|
||||
|
||||
- **Status:** Accepted
|
||||
- **Date:** 2026-07-20
|
||||
- **Deciders:** Respellion engineering
|
||||
- **Relates to:** S-10b (#103); proposal #107. Builds on ADR-0001 (ACL is the only ZGW caller),
|
||||
ADR-0003 (ACL default-fill), ADR-0017 (document-wait + provision trigger). Carves the zaak-close on
|
||||
expiry to #106 (S-10c).
|
||||
|
||||
## Context
|
||||
|
||||
S-10a wired the "documenten aanleveren" trigger (portal → BFF → domain → complete the WachtOpDocumenten
|
||||
wait) with the file itself stubbed. S-10b makes the upload real: the diploma must be **stored in the
|
||||
ZGW Documenten (DRC) API** and related to the zaak. §8.1 makes the ACL the only code that talks to ZGW.
|
||||
The DRC API is served by the same OpenZaak container as the Zaken/Catalogi APIs.
|
||||
|
||||
## Decision
|
||||
|
||||
**The ACL fronts the Documenten API: it creates an `enkelvoudiginformatieobject` and relates it to the
|
||||
zaak. The file travels base64-encoded in JSON across every hop (the portal encodes it client-side); a
|
||||
"Diploma" `informatieobjecttype` is seeded in the catalogus and injected into the ACL like the
|
||||
zaaktype.**
|
||||
|
||||
- **ACL gateway.** `OpenZaakGateway.StoreDocumentAsync` POSTs the `enkelvoudiginformatieobject`
|
||||
(`/documenten/api/v1/enkelvoudiginformatieobjecten`, base64 `inhoud`, `bestandsomvang`,
|
||||
`status=definitief`) then relates it to the zaak (`/zaken/api/v1/zaakinformatieobjecten`), reusing the
|
||||
established gateway patterns (ZGW Bearer JWT, buffered non-chunked body for uwsgi, **no CRS headers** —
|
||||
the Documenten API is not geo, unlike zaak-create). `AclService.StoreDiplomaAsync` default-fills the
|
||||
ZGW-mandatory fields (informatieobjecttype, bronorganisatie, vertrouwelijkheidaanduiding, `taal=nld`,
|
||||
creatiedatum); the domain hands over only the zaak, the bytes, and the file's name/type. No new ZGW
|
||||
scopes were needed — the seed applicatie holds `heeft_alle_autorisaties`.
|
||||
- **The file travels as base64 JSON end-to-end.** The portal reads the chosen file client-side
|
||||
(`FileReader`) and posts `{ contentBase64, fileName, contentType }` as JSON to the BFF; the BFF
|
||||
forwards it to the domain, and the domain to the ACL, all as JSON. This deviates from proposal #107's
|
||||
"multipart on the portal→BFF hop": base64 JSON keeps **one** contract shape across all four services
|
||||
(no `IFormFile`/antiforgery plumbing, no multipart in the generated client), and a diploma is a small
|
||||
placeholder PDF, so the ~33% base64 overhead is immaterial. The ACL turns the base64 back into the
|
||||
ZGW `inhoud`.
|
||||
- **Storing precedes completing the wait.** `ProvideDocuments` (from S-10a) now stores the diploma via
|
||||
the ACL — once the zaak is opened — and then completes the `WachtOpDocumenten` task, so a registration
|
||||
reaches beoordeling only after its diploma is stored. Both steps stay best-effort about missing
|
||||
preconditions (no zaak yet → skip storage; no process yet → skip completion), mirroring withdrawal.
|
||||
- **Catalogus.** `seed_catalogus.py` (OZ_PUBLISH) creates a "Diploma" `informatieobjecttype`, relates it
|
||||
to the zaaktype (`zaaktype-informatieobjecttypen`, while both concept), publishes both, and prints
|
||||
`INFORMATIEOBJECTTYPE_URL`; verify-domain injects it as `Acl__Defaults__InformatieobjecttypeUrl`
|
||||
(a zeros-uuid placeholder otherwise, so the ACL still boots).
|
||||
|
||||
## Consequences
|
||||
|
||||
**Positive**
|
||||
|
||||
- §8.1 stays intact: the ACL is still the only ZGW caller; the portal only talks to the BFF; the domain
|
||||
only crosses the ACL boundary. Adding a document was almost entirely additive (one gateway method, one
|
||||
default, one seed block).
|
||||
- One JSON contract shape across portal/BFF/domain/ACL keeps the generated client and the service
|
||||
contracts uniform; the upload is exercised live (ACL integration test against real OpenZaak; the
|
||||
Playwright journey uploads a real PDF).
|
||||
|
||||
**Negative / costs**
|
||||
|
||||
- Base64 inflates the payload ~33% and holds the whole file in memory at each hop — fine for a small
|
||||
diploma, but not a pattern to reuse for large documents without streaming/multipart.
|
||||
- The zaak is **not** set to a cancellation status when the 30-day term lapses — carved to #106 (S-10c),
|
||||
which adds the cancellation statustype/resultaattype + ACL method + expiry-worker wiring.
|
||||
- Providing documents before the zaak is opened silently skips storage (best-effort); the e2e/live flow
|
||||
avoids this by uploading only after the openbaar register shows the zaak (INGEDIEND).
|
||||
|
||||
## Alternatives considered
|
||||
|
||||
- **Multipart on the portal→BFF hop** (proposal #107). Rejected: it splits the transport into two shapes
|
||||
(multipart then JSON), needs `IFormFile` + antiforgery handling and a multipart method in the generated
|
||||
client, for no benefit at diploma size.
|
||||
- **The domain talks to the Documenten API directly.** Rejected outright: violates §8.1 (only the ACL
|
||||
talks to ZGW).
|
||||
+3
-32
@@ -395,10 +395,9 @@ for the citizen's documents (their diploma). Two things can happen:
|
||||
`RegistratieVerlopen` external task, and the domain expires the registration to the terminal status
|
||||
**VERLOPEN** (the case is cancelled).
|
||||
|
||||
The "documents received" trigger is wired end-to-end in S-10a: the self-service page shows a
|
||||
**"Documenten aanleveren"** button after submit (portal → BFF → domain → completes the wait). S-10b
|
||||
turns that into a real file upload stored in the ZGW Documenten API via the ACL. The timeout branch is
|
||||
demonstrated by firing the 30-day timer early via the management API.
|
||||
The real upload trigger (portal → BFF → domain → ACL → Documenten API) is S-10b; until then the
|
||||
"documents received" step is completing the task in Flowable, and the timeout is demonstrated by
|
||||
firing the timer early via the management API.
|
||||
|
||||
```bash
|
||||
DOM=http://localhost:8080 # domain service
|
||||
@@ -434,31 +433,3 @@ routing → `Beoordelen`), OR the `P30D` interrupting timer fires → `Registrat
|
||||
> Both branches are covered by the `Een documenttermijn laten verlopen` acceptance scenarios (worker +
|
||||
> aggregate) and unit tests; the wait completion and the 30-day timer firing are asserted live by the
|
||||
> verify-domain check.
|
||||
|
||||
## S-10b — Diploma upload stored in the ZGW Documenten API (#103, ADR-0018)
|
||||
|
||||
The self-service "Documenten aanleveren" action (S-10a) is now a **real file upload**: after submitting,
|
||||
the citizen picks a PDF and uploads it. The portal base64-encodes the file client-side and posts it to
|
||||
the BFF; the BFF forwards it to the domain, which stores it via the **ACL** as a ZGW
|
||||
`enkelvoudiginformatieobject` in the **Documenten (DRC) API** and relates it to the zaak — then completes
|
||||
the `WachtOpDocumenten` wait so beoordeling can proceed. Per §8.1 only the ACL talks to ZGW.
|
||||
|
||||
```bash
|
||||
make up
|
||||
# 1. Log in as jan-burger / test123, submit, then — once the openbaar register shows the row —
|
||||
# choose a PDF under "Documenten aanleveren" and upload it. The page confirms "aangeleverd".
|
||||
open http://localhost:8140
|
||||
#
|
||||
# 2. Automated: the walking-skeleton e2e now uploads a real PDF before the behandelaar approves.
|
||||
make verify-e2e
|
||||
#
|
||||
# 3. The ACL integration test proves the document is really created in the Documenten API and
|
||||
# related to the zaak (against a live OpenZaak):
|
||||
make verify-acl # → "Storing a diploma creates a real informatieobject related to the zaak"
|
||||
```
|
||||
|
||||
**The path:** portal (base64) → BFF `POST /self-service/registrations/{id}/documents` → domain
|
||||
`ProvideDocuments` → ACL `POST /documenten` → ZGW `enkelvoudiginformatieobjecten` +
|
||||
`zaakinformatieobjecten`; the wait is then completed and the case advances to Beoordelen (§8.1, ADR-0018).
|
||||
|
||||
> Setting the ZGW zaak to a cancellation status on 30-day expiry is a follow-up (S-10c, #106).
|
||||
|
||||
@@ -306,9 +306,6 @@ services:
|
||||
Acl__Defaults__Vertrouwelijkheidaanduiding: openbaar
|
||||
# Override with the real zaaktype URL after running seed_catalogus.py.
|
||||
Acl__Defaults__ZaaktypeUrl: ${ACL_ZAAKTYPE_URL:-http://openzaak:8000/catalogi/api/v1/zaaktypen/00000000-0000-0000-0000-000000000000}
|
||||
# The informatieobjecttype a diploma is filed under (S-10b). Placeholder until seed_catalogus.py
|
||||
# (OZ_PUBLISH=1) reports the real URL, which verify-domain injects like the zaaktype URL.
|
||||
Acl__Defaults__InformatieobjecttypeUrl: ${ACL_INFORMATIEOBJECTTYPE_URL:-http://openzaak:8000/catalogi/api/v1/informatieobjecttypen/00000000-0000-0000-0000-000000000000}
|
||||
ports:
|
||||
- "8100:8080"
|
||||
healthcheck:
|
||||
|
||||
@@ -124,58 +124,6 @@ def publish_zaaktype(zt):
|
||||
print("skip publish (already published)")
|
||||
|
||||
|
||||
def seed_informatieobjecttype(cat, zt):
|
||||
"""Create the "Diploma" informatieobjecttype and relate it to the zaaktype (both idempotent).
|
||||
|
||||
A diploma uploaded in S-10b is filed under this informatieobjecttype; OpenZaak only accepts a
|
||||
document (and its zaak relation) once the informatieobjecttype is published AND allowed for the
|
||||
zaak's zaaktype (a zaaktype-informatieobjecttype relation). Both the relation and this call must run
|
||||
while the zaaktype is still a concept, so seed this *before* publishing the zaaktype. Returns the
|
||||
informatieobjecttype dict.
|
||||
"""
|
||||
iots = [i for i in find(f"/informatieobjecttypen?catalogus={cat['url']}&status=alles")
|
||||
if i.get("omschrijving") == "Diploma"]
|
||||
if iots:
|
||||
iot = iots[0]
|
||||
print(f"skip informatieobjecttype Diploma ({iot['url']}) concept={iot.get('concept')}")
|
||||
else:
|
||||
st, iot = api("POST", "/informatieobjecttypen", {
|
||||
"catalogus": cat["url"],
|
||||
"omschrijving": "Diploma",
|
||||
"vertrouwelijkheidaanduiding": "openbaar",
|
||||
"informatieobjectcategorie": "diploma",
|
||||
"beginGeldigheid": "2026-01-01",
|
||||
})
|
||||
if st != 201:
|
||||
sys.exit(f"create informatieobjecttype -> {st}: {json.dumps(iot, indent=2)}")
|
||||
print(f"create informatieobjecttype Diploma ({iot['url']})")
|
||||
|
||||
# Relate it to the zaaktype (must be done while both are concept).
|
||||
relations = find(f"/zaaktype-informatieobjecttypen?zaaktype={zt['url']}&status=alles")
|
||||
if any(r.get("informatieobjecttype") == iot["url"] for r in relations):
|
||||
print("skip zaaktype-informatieobjecttype Diploma")
|
||||
else:
|
||||
st, body = api("POST", "/zaaktype-informatieobjecttypen", {
|
||||
"zaaktype": zt["url"], "informatieobjecttype": iot["url"],
|
||||
"volgnummer": 1, "richting": "inkomend"})
|
||||
if st != 201:
|
||||
sys.exit(f"relate zaaktype-informatieobjecttype -> {st}: {json.dumps(body, indent=2)}")
|
||||
print("create zaaktype-informatieobjecttype Diploma")
|
||||
|
||||
return iot
|
||||
|
||||
|
||||
def publish_informatieobjecttype(iot):
|
||||
"""Publish the informatieobjecttype (idempotent) so documents may reference it."""
|
||||
if iot.get("concept", True):
|
||||
st, body = api("POST", f"{iot['url']}/publish")
|
||||
if st != 200:
|
||||
sys.exit(f"publish informatieobjecttype -> {st}: {json.dumps(body, indent=2)}")
|
||||
print(f"publish informatieobjecttype Diploma ({iot['url']})")
|
||||
else:
|
||||
print("skip publish informatieobjecttype (already published)")
|
||||
|
||||
|
||||
def main():
|
||||
# 1. Catalogus
|
||||
existing = [c for c in find(f"/catalogussen?domein=BIG") if c.get("domein") == "BIG"]
|
||||
@@ -250,16 +198,10 @@ def main():
|
||||
# schema-mandatory" zaaktype S-01 asks for (ADR-0002). Set OZ_PUBLISH=1 to add
|
||||
# those relations and publish — needed so a real zaak POST is accepted, which
|
||||
# the ACL integration test (S-04a, #46) exercises. See ADR-0006.
|
||||
iot = None
|
||||
if PUBLISH:
|
||||
# Re-fetch: the bsn-eigenschap branch above may hold a stale concept flag.
|
||||
zt = next(z for z in find(f"/zaaktypen?catalogus={cat['url']}&status=alles")
|
||||
if z.get("identificatie") == "BIG-REGISTRATIE")
|
||||
# Seed + relate the Diploma informatieobjecttype (S-10b) while the zaaktype is still concept,
|
||||
# then publish both. Publish the informatieobjecttype before the zaaktype so the zaaktype's
|
||||
# relations reference a published type.
|
||||
iot = seed_informatieobjecttype(cat, zt)
|
||||
publish_informatieobjecttype(iot)
|
||||
publish_zaaktype(zt)
|
||||
|
||||
# 5. Verify the JWT client can list the zaaktype (concepts included).
|
||||
@@ -272,10 +214,6 @@ def main():
|
||||
# zaaktype URL to configure the ACL's default-fill (ADR-0003/0009).
|
||||
zt_url = next(z["url"] for z in zaaktypen if z.get("identificatie") == "BIG-REGISTRATIE")
|
||||
print(f"ZAAKTYPE_URL {zt_url}")
|
||||
# Machine-readable informatieobjecttype URL (S-10b) so callers can configure the ACL's document
|
||||
# default-fill. Only emitted when publishing — a concept informatieobjecttype can't back a document.
|
||||
if iot is not None:
|
||||
print(f"INFORMATIEOBJECTTYPE_URL {iot['url']}")
|
||||
print(f"OK — BIG catalogus seeded (BIG-REGISTRATIE {state} + bsn eigenschap)")
|
||||
|
||||
|
||||
|
||||
@@ -33,18 +33,13 @@ echo ">> openzaak=$oz_ip domain=$dom_ip network=$net"
|
||||
echo ">> seeding a published BIG zaaktype (idempotent) and capturing its URL"
|
||||
sid="$(docker create --network "$net" -e "OZ_BASE=$oz_base" -e OZ_PUBLISH=1 python:3-slim python /seed.py)"
|
||||
docker cp "$here/openzaak/seed_catalogus.py" "$sid:/seed.py" >/dev/null
|
||||
seed_out="$(docker start -a "$sid")"
|
||||
zt_url="$(printf '%s\n' "$seed_out" | sed -n 's/^ZAAKTYPE_URL //p' | head -1)"
|
||||
iot_url="$(printf '%s\n' "$seed_out" | sed -n 's/^INFORMATIEOBJECTTYPE_URL //p' | head -1)"
|
||||
zt_url="$(docker start -a "$sid" | sed -n 's/^ZAAKTYPE_URL //p' | head -1)"
|
||||
docker rm -f "$sid" >/dev/null
|
||||
[ -n "$zt_url" ] || { echo "ERROR: seed did not report a ZAAKTYPE_URL" >&2; exit 1; }
|
||||
[ -n "$iot_url" ] || { echo "ERROR: seed did not report an INFORMATIEOBJECTTYPE_URL" >&2; exit 1; }
|
||||
echo ">> zaaktype: $zt_url"
|
||||
echo ">> informatieobjecttype: $iot_url"
|
||||
|
||||
echo ">> recreating the acl service pointed at the seeded zaaktype + informatieobjecttype (host-consistent)"
|
||||
ACL_ZAAKTYPE_URL="$zt_url" ACL_INFORMATIEOBJECTTYPE_URL="$iot_url" ACL_OPENZAAK_BASEURL="$oz_base/" \
|
||||
docker compose -f "$compose" up -d acl
|
||||
echo ">> recreating the acl service pointed at the seeded zaaktype (host-consistent)"
|
||||
ACL_ZAAKTYPE_URL="$zt_url" ACL_OPENZAAK_BASEURL="$oz_base/" docker compose -f "$compose" up -d acl
|
||||
WAIT_TIMEOUT="${WAIT_TIMEOUT:-120}" bash "$here/wait-healthy.sh" acl
|
||||
|
||||
echo ">> submitting a registration to the domain"
|
||||
|
||||
@@ -35,14 +35,6 @@ export interface OpenbaarEntry {
|
||||
reference: string | null;
|
||||
}
|
||||
|
||||
export interface ProvideDocumentsRequest {
|
||||
contentBase64: string;
|
||||
/** @nullable */
|
||||
fileName?: string | null;
|
||||
/** @nullable */
|
||||
contentType?: string | null;
|
||||
}
|
||||
|
||||
export interface SubmitAccepted {
|
||||
registrationId: string;
|
||||
status: string;
|
||||
@@ -234,44 +226,6 @@ export class BffApiV1Service {
|
||||
);
|
||||
}
|
||||
|
||||
postSelfServiceRegistrationsIdDocuments<TData = void>(id: string,
|
||||
provideDocumentsRequest: ProvideDocumentsRequest, options?: HttpClientBodyOptions): Observable<TData>;
|
||||
postSelfServiceRegistrationsIdDocuments<TData = void>(id: string,
|
||||
provideDocumentsRequest: ProvideDocumentsRequest, options?: HttpClientEventOptions): Observable<HttpEvent<TData>>;
|
||||
postSelfServiceRegistrationsIdDocuments<TData = void>(id: string,
|
||||
provideDocumentsRequest: ProvideDocumentsRequest, options?: HttpClientResponseOptions): Observable<AngularHttpResponse<TData>>;
|
||||
postSelfServiceRegistrationsIdDocuments<TData = void>(
|
||||
id: string,
|
||||
provideDocumentsRequest: ProvideDocumentsRequest, options?: HttpClientObserveOptions): Observable<TData | HttpEvent<TData> | AngularHttpResponse<TData>> {
|
||||
if (options?.observe === 'events') {
|
||||
return this.http.post<TData>(
|
||||
`/self-service/registrations/${id}/documents`,
|
||||
provideDocumentsRequest,{
|
||||
...(options as Omit<NonNullable<typeof options>, 'observe'>),
|
||||
observe: 'events',
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
if (options?.observe === 'response') {
|
||||
return this.http.post<TData>(
|
||||
`/self-service/registrations/${id}/documents`,
|
||||
provideDocumentsRequest,{
|
||||
...(options as Omit<NonNullable<typeof options>, 'observe'>),
|
||||
observe: 'response',
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
return this.http.post<TData>(
|
||||
`/self-service/registrations/${id}/documents`,
|
||||
provideDocumentsRequest,{
|
||||
...(options as Omit<NonNullable<typeof options>, 'observe'>),
|
||||
observe: 'body',
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
getOpenbaarRegister<TData = OpenbaarEntry[]>(params?: GetOpenbaarRegisterParams, options?: HttpClientBodyOptions): Observable<TData>;
|
||||
getOpenbaarRegister<TData = OpenbaarEntry[]>(params?: GetOpenbaarRegisterParams, options?: HttpClientEventOptions): Observable<HttpEvent<TData>>;
|
||||
getOpenbaarRegister<TData = OpenbaarEntry[]>(params?: GetOpenbaarRegisterParams, options?: HttpClientResponseOptions): Observable<AngularHttpResponse<TData>>;
|
||||
|
||||
@@ -40,15 +40,6 @@ app.MapPost("/zaken/reference", async (ZaakReferenceRequest body, AclService acl
|
||||
return Results.Ok(new { reference });
|
||||
});
|
||||
|
||||
// Store an uploaded diploma against a zaak (S-10b): the domain sends the file as base64; the ACL
|
||||
// creates the ZGW enkelvoudiginformatieobject and relates it to the zaak (§8.1). Returns its URL.
|
||||
app.MapPost("/documenten", async (StoreDocumentRequest body, AclService acl, CancellationToken ct) =>
|
||||
{
|
||||
var url = await acl.StoreDiplomaAsync(
|
||||
new Uri(body.ZaakUrl), Convert.FromBase64String(body.ContentBase64), body.FileName, body.ContentType, ct);
|
||||
return Results.Ok(new { informatieobjectUrl = url.ToString() });
|
||||
});
|
||||
|
||||
app.Run();
|
||||
|
||||
public sealed record OpenZaakRequest(string Bsn, string Reference);
|
||||
@@ -57,6 +48,4 @@ public sealed record SetStatusRequest(string ZaakUrl);
|
||||
|
||||
public sealed record ZaakReferenceRequest(string ZaakUrl);
|
||||
|
||||
public sealed record StoreDocumentRequest(string ZaakUrl, string ContentBase64, string FileName, string ContentType);
|
||||
|
||||
public partial class Program;
|
||||
|
||||
@@ -7,8 +7,4 @@ public sealed class AclDefaults
|
||||
public required string VerantwoordelijkeOrganisatie { get; init; }
|
||||
public required string Vertrouwelijkheidaanduiding { get; init; }
|
||||
public required Uri ZaaktypeUrl { get; init; }
|
||||
|
||||
/// <summary>The informatieobjecttype an uploaded diploma is filed under (S-10b). Seeded in the
|
||||
/// catalogus and injected like <see cref="ZaaktypeUrl"/>.</summary>
|
||||
public required Uri InformatieobjecttypeUrl { get; init; }
|
||||
}
|
||||
|
||||
@@ -37,33 +37,4 @@ public sealed class AclService(IZaakGateway gateway, AclDefaults defaults, ICloc
|
||||
|
||||
return gateway.GetZaakIdentificatieAsync(zaakUrl, ct);
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Store an uploaded diploma against the zaak (S-10b): default-fill the ZGW-mandatory document
|
||||
/// fields (informatieobjecttype, bronorganisatie, vertrouwelijkheidaanduiding, taal, creatiedatum)
|
||||
/// and hand the file to the gateway, which creates the informatieobject and relates it to the zaak.
|
||||
/// The domain supplies only the zaak, the bytes, and the file's name/type (§8.1).
|
||||
/// </summary>
|
||||
public Task<Uri> StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(zaakUrl);
|
||||
ArgumentNullException.ThrowIfNull(content);
|
||||
ArgumentException.ThrowIfNullOrWhiteSpace(fileName);
|
||||
ArgumentException.ThrowIfNullOrWhiteSpace(contentType);
|
||||
|
||||
var request = new DocumentRequest(
|
||||
defaults.Bronorganisatie,
|
||||
defaults.InformatieobjecttypeUrl,
|
||||
defaults.Vertrouwelijkheidaanduiding,
|
||||
zaakUrl,
|
||||
clock.Today,
|
||||
Titel: "Diploma",
|
||||
Auteur: "zorgprofessional",
|
||||
Taal: "nld",
|
||||
Bestandsnaam: fileName,
|
||||
Formaat: contentType,
|
||||
Inhoud: content);
|
||||
|
||||
return gateway.StoreDocumentAsync(request, ct);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,17 +0,0 @@
|
||||
namespace Acl.Application;
|
||||
|
||||
/// <summary>The fully default-filled diploma document the gateway will create in the ZGW Documenten
|
||||
/// API and relate to the zaak (S-10b). <see cref="Inhoud"/> is the raw file content; the gateway
|
||||
/// base64-encodes it into the ZGW <c>inhoud</c> field.</summary>
|
||||
public sealed record DocumentRequest(
|
||||
string Bronorganisatie,
|
||||
Uri Informatieobjecttype,
|
||||
string Vertrouwelijkheidaanduiding,
|
||||
Uri Zaak,
|
||||
DateOnly Creatiedatum,
|
||||
string Titel,
|
||||
string Auteur,
|
||||
string Taal,
|
||||
string Bestandsnaam,
|
||||
string Formaat,
|
||||
byte[] Inhoud);
|
||||
@@ -16,11 +16,4 @@ public interface IZaakGateway
|
||||
/// <summary>Read the zaak's <c>identificatie</c> — the public-safe reference the register shows.
|
||||
/// The Event Subscriber calls this through the ACL rather than reading ZGW itself (§8.1, #78).</summary>
|
||||
Task<string> GetZaakIdentificatieAsync(Uri zaakUrl, CancellationToken ct = default);
|
||||
|
||||
/// <summary>
|
||||
/// Store a diploma document (S-10b): create an <c>enkelvoudiginformatieobject</c> in the ZGW
|
||||
/// Documenten API and relate it to the zaak via a <c>zaakinformatieobject</c>. Returns the URL of
|
||||
/// the created informatieobject.
|
||||
/// </summary>
|
||||
Task<Uri> StoreDocumentAsync(DocumentRequest request, CancellationToken ct = default);
|
||||
}
|
||||
|
||||
@@ -80,39 +80,6 @@ public sealed class OpenZaakGateway(HttpClient http, OpenZaakOptions options) :
|
||||
return zaak.Identificatie;
|
||||
}
|
||||
|
||||
public async Task<Uri> StoreDocumentAsync(DocumentRequest request, CancellationToken ct = default)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(request);
|
||||
|
||||
// 1. Create the enkelvoudiginformatieobject in the Documenten API (not a geo API — no CRS).
|
||||
var created = await PostForUrlAsync(
|
||||
"/documenten/api/v1/enkelvoudiginformatieobjecten",
|
||||
new EnkelvoudigInformatieobjectDto(
|
||||
request.Bronorganisatie,
|
||||
request.Creatiedatum.ToString("yyyy-MM-dd"),
|
||||
request.Titel,
|
||||
request.Auteur,
|
||||
request.Taal,
|
||||
request.Informatieobjecttype.ToString(),
|
||||
Convert.ToBase64String(request.Inhoud),
|
||||
request.Bestandsnaam,
|
||||
request.Inhoud.Length,
|
||||
request.Vertrouwelijkheidaanduiding,
|
||||
request.Formaat,
|
||||
"definitief",
|
||||
// No usage-rights restrictions apply. Left null, OpenZaak rejects closing the related
|
||||
// zaak with "indicatiegebruiksrecht-unset"; false records the deliberate "none" answer.
|
||||
false),
|
||||
"Creating the informatieobject", ct);
|
||||
|
||||
// 2. Relate it to the zaak (Zaken API — no CRS).
|
||||
await PostAsync("/zaken/api/v1/zaakinformatieobjecten",
|
||||
new ZaakInformatieobjectDto(request.Zaak.ToString(), created.ToString()),
|
||||
"Relating the informatieobject to the zaak", ct);
|
||||
|
||||
return created;
|
||||
}
|
||||
|
||||
// POSTs a non-geo ZGW resource (resultaat/status — no CRS headers). Buffers the body so uwsgi gets
|
||||
// a Content-Length instead of a chunked body (as with zaak-create).
|
||||
private async Task PostAsync(string path, object dto, string action, CancellationToken ct)
|
||||
@@ -129,26 +96,6 @@ public sealed class OpenZaakGateway(HttpClient http, OpenZaakOptions options) :
|
||||
await EnsureSuccessAsync(response, action, ct);
|
||||
}
|
||||
|
||||
// POSTs a non-geo ZGW resource and returns the created resource's URL (as PostAsync, but reads back
|
||||
// the `url` of the created object). Buffers the body so uwsgi gets a Content-Length.
|
||||
private async Task<Uri> PostForUrlAsync(string path, object dto, string action, CancellationToken ct)
|
||||
{
|
||||
using var message = new HttpRequestMessage(HttpMethod.Post, new Uri(options.BaseUrl, path))
|
||||
{
|
||||
Content = JsonContent.Create(dto),
|
||||
};
|
||||
message.Headers.Authorization =
|
||||
new AuthenticationHeaderValue("Bearer", ZgwToken.Mint(options.ClientId, options.Secret));
|
||||
await message.Content.LoadIntoBufferAsync(ct);
|
||||
|
||||
using var response = await http.SendAsync(message, ct);
|
||||
await EnsureSuccessAsync(response, action, ct);
|
||||
|
||||
var created = await response.Content.ReadFromJsonAsync<CreatedDto>(ct)
|
||||
?? throw new InvalidOperationException($"OpenZaak returned an empty response for {action}");
|
||||
return new Uri(created.Url);
|
||||
}
|
||||
|
||||
// EnsureSuccessStatusCode discards the response body; ZGW returns a JSON problem detail on 400 that
|
||||
// is essential for diagnosing a rejected request, so surface it in the exception.
|
||||
private static async Task EnsureSuccessAsync(HttpResponseMessage response, string action, CancellationToken ct)
|
||||
@@ -235,26 +182,4 @@ public sealed class OpenZaakGateway(HttpClient http, OpenZaakOptions options) :
|
||||
|
||||
private sealed record ResultaattypeDto(
|
||||
[property: JsonPropertyName("url")] string Url);
|
||||
|
||||
private sealed record CreatedDto(
|
||||
[property: JsonPropertyName("url")] string Url);
|
||||
|
||||
private sealed record EnkelvoudigInformatieobjectDto(
|
||||
[property: JsonPropertyName("bronorganisatie")] string Bronorganisatie,
|
||||
[property: JsonPropertyName("creatiedatum")] string Creatiedatum,
|
||||
[property: JsonPropertyName("titel")] string Titel,
|
||||
[property: JsonPropertyName("auteur")] string Auteur,
|
||||
[property: JsonPropertyName("taal")] string Taal,
|
||||
[property: JsonPropertyName("informatieobjecttype")] string Informatieobjecttype,
|
||||
[property: JsonPropertyName("inhoud")] string Inhoud,
|
||||
[property: JsonPropertyName("bestandsnaam")] string Bestandsnaam,
|
||||
[property: JsonPropertyName("bestandsomvang")] int Bestandsomvang,
|
||||
[property: JsonPropertyName("vertrouwelijkheidaanduiding")] string Vertrouwelijkheidaanduiding,
|
||||
[property: JsonPropertyName("formaat")] string Formaat,
|
||||
[property: JsonPropertyName("status")] string Status,
|
||||
[property: JsonPropertyName("indicatieGebruiksrecht")] bool IndicatieGebruiksrecht);
|
||||
|
||||
private sealed record ZaakInformatieobjectDto(
|
||||
[property: JsonPropertyName("zaak")] string Zaak,
|
||||
[property: JsonPropertyName("informatieobject")] string Informatieobject);
|
||||
}
|
||||
|
||||
@@ -77,18 +77,6 @@ public sealed class OpenZaakFixture : IDisposable
|
||||
return JsonDocument.Parse(json).RootElement.Clone();
|
||||
}
|
||||
|
||||
/// <summary>The URL of the published "Diploma" informatieobjecttype (S-10b), or null when the
|
||||
/// stack has not been seeded with OZ_PUBLISH=1. `status=definitief` returns published types only.</summary>
|
||||
public async Task<Uri?> FindPublishedDiplomaInformatieobjecttypeAsync(CancellationToken ct = default)
|
||||
{
|
||||
var query = new Uri(BaseUrl, "/catalogi/api/v1/informatieobjecttypen?status=definitief");
|
||||
var page = await GetJsonAsync(query, ct);
|
||||
foreach (var iot in page.GetProperty("results").EnumerateArray())
|
||||
if (iot.TryGetProperty("omschrijving", out var o) && o.GetString() == "Diploma")
|
||||
return new Uri(iot.GetProperty("url").GetString()!);
|
||||
return null;
|
||||
}
|
||||
|
||||
/// <summary>The zaaktype's eindstatus (terminal statustype) URL — the one an approval sets.</summary>
|
||||
public async Task<Uri> FindEindstatustypeAsync(Uri zaaktypeUrl, CancellationToken ct = default)
|
||||
{
|
||||
|
||||
@@ -74,58 +74,4 @@ public sealed class OpenZaakGatewayIntegrationTests(OpenZaakFixture stack)
|
||||
var eindstatustype = await stack.FindEindstatustypeAsync(zaaktype!);
|
||||
Assert.Equal(eindstatustype.ToString(), status.GetProperty("statustype").GetString());
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Storing_a_diploma_creates_a_real_informatieobject_related_to_the_zaak()
|
||||
{
|
||||
var zaaktype = await stack.FindPublishedBigZaaktypeAsync();
|
||||
Assert.True(zaaktype is not null,
|
||||
"No published BIG-REGISTRATIE zaaktype found — seed the stack with OZ_PUBLISH=1.");
|
||||
var informatieobjecttype = await stack.FindPublishedDiplomaInformatieobjecttypeAsync();
|
||||
Assert.True(informatieobjecttype is not null,
|
||||
"No published Diploma informatieobjecttype found — seed the stack with OZ_PUBLISH=1.");
|
||||
|
||||
var gateway = new OpenZaakGateway(stack.Http, stack.Options);
|
||||
var zaakUrl = await gateway.OpenZaakAsync(new ZaakRequest(
|
||||
Bronorganisatie: "517439943",
|
||||
VerantwoordelijkeOrganisatie: "517439943",
|
||||
Vertrouwelijkheidaanduiding: "openbaar",
|
||||
Zaaktype: zaaktype!,
|
||||
Startdatum: DateOnly.FromDateTime(DateTime.UtcNow),
|
||||
Identificatie: Guid.NewGuid().ToString()));
|
||||
|
||||
var content = System.Text.Encoding.UTF8.GetBytes("%PDF-1.4 synthetic diploma\n");
|
||||
var documentUrl = await gateway.StoreDocumentAsync(new DocumentRequest(
|
||||
Bronorganisatie: "517439943",
|
||||
Informatieobjecttype: informatieobjecttype!,
|
||||
Vertrouwelijkheidaanduiding: "openbaar",
|
||||
Zaak: zaakUrl,
|
||||
Creatiedatum: DateOnly.FromDateTime(DateTime.UtcNow),
|
||||
Titel: "Diploma",
|
||||
Auteur: "zorgprofessional",
|
||||
Taal: "nld",
|
||||
Bestandsnaam: "diploma.pdf",
|
||||
Formaat: "application/pdf",
|
||||
Inhoud: content));
|
||||
|
||||
// The gateway returns the canonical informatieobject URL...
|
||||
Assert.StartsWith(
|
||||
new Uri(stack.BaseUrl, "/documenten/api/v1/enkelvoudiginformatieobjecten/").ToString(),
|
||||
documentUrl.ToString());
|
||||
|
||||
// ...the document is really persisted with the default-filled fields...
|
||||
var doc = await stack.GetJsonAsync(documentUrl);
|
||||
Assert.Equal("diploma.pdf", doc.GetProperty("bestandsnaam").GetString());
|
||||
Assert.Equal(informatieobjecttype.ToString(), doc.GetProperty("informatieobjecttype").GetString());
|
||||
Assert.Equal(content.Length, doc.GetProperty("bestandsomvang").GetInt32());
|
||||
// indicatieGebruiksrecht is recorded as "no restrictions"; left null, OpenZaak would refuse to
|
||||
// close the zaak this document is related to (the S-10b regression that broke the e2e flow).
|
||||
Assert.False(doc.GetProperty("indicatieGebruiksrecht").GetBoolean());
|
||||
|
||||
// ...and it is related to the zaak (a zaakinformatieobject links the two).
|
||||
var relations = await stack.GetJsonAsync(new Uri(stack.BaseUrl,
|
||||
"/zaken/api/v1/zaakinformatieobjecten?informatieobject=" + Uri.EscapeDataString(documentUrl.ToString())));
|
||||
Assert.Contains(relations.EnumerateArray(),
|
||||
r => r.GetProperty("zaak").GetString() == zaakUrl.ToString());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -30,15 +30,6 @@ public class AclServiceTests
|
||||
ReadReferenceFor = zaakUrl;
|
||||
return Task.FromResult("REG-FROM-ZAAK");
|
||||
}
|
||||
|
||||
public DocumentRequest? StoredDocument;
|
||||
public Uri DocumentResult { get; } = new("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc-1");
|
||||
|
||||
public Task<Uri> StoreDocumentAsync(DocumentRequest request, CancellationToken ct = default)
|
||||
{
|
||||
StoredDocument = request;
|
||||
return Task.FromResult(DocumentResult);
|
||||
}
|
||||
}
|
||||
|
||||
private static AclDefaults Defaults() => new()
|
||||
@@ -47,7 +38,6 @@ public class AclServiceTests
|
||||
VerantwoordelijkeOrganisatie = "517439943",
|
||||
Vertrouwelijkheidaanduiding = "openbaar",
|
||||
ZaaktypeUrl = new("http://openzaak/catalogi/api/v1/zaaktypen/big"),
|
||||
InformatieobjecttypeUrl = new("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"),
|
||||
};
|
||||
|
||||
private sealed class FixedClock(DateOnly today) : IClock
|
||||
@@ -65,7 +55,6 @@ public class AclServiceTests
|
||||
VerantwoordelijkeOrganisatie = "517439943",
|
||||
Vertrouwelijkheidaanduiding = "openbaar",
|
||||
ZaaktypeUrl = new("http://openzaak/catalogi/api/v1/zaaktypen/big"),
|
||||
InformatieobjecttypeUrl = new("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"),
|
||||
};
|
||||
var service = new AclService(gateway, defaults, new FixedClock(new DateOnly(2026, 6, 4)));
|
||||
|
||||
@@ -92,7 +81,6 @@ public class AclServiceTests
|
||||
VerantwoordelijkeOrganisatie = "517439943",
|
||||
Vertrouwelijkheidaanduiding = "openbaar",
|
||||
ZaaktypeUrl = new("http://openzaak/catalogi/api/v1/zaaktypen/big"),
|
||||
InformatieobjecttypeUrl = new("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"),
|
||||
};
|
||||
var service = new AclService(gateway, defaults, new FixedClock(new DateOnly(2026, 6, 4)));
|
||||
|
||||
@@ -126,41 +114,6 @@ public class AclServiceTests
|
||||
Assert.Null(gateway.Approved);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Storing_a_diploma_default_fills_the_document_fields_and_returns_its_url()
|
||||
{
|
||||
var gateway = new FakeGateway();
|
||||
var defaults = Defaults();
|
||||
var service = new AclService(gateway, defaults, new FixedClock(new DateOnly(2026, 6, 4)));
|
||||
var zaak = new Uri("http://openzaak/zaken/api/v1/zaken/abc");
|
||||
|
||||
var url = await service.StoreDiplomaAsync(zaak, [1, 2, 3], "diploma.pdf", "application/pdf");
|
||||
|
||||
Assert.Equal(gateway.DocumentResult, url);
|
||||
var req = gateway.StoredDocument!;
|
||||
Assert.Equal(zaak, req.Zaak);
|
||||
Assert.Equal(defaults.InformatieobjecttypeUrl, req.Informatieobjecttype);
|
||||
Assert.Equal("517439943", req.Bronorganisatie);
|
||||
Assert.Equal("openbaar", req.Vertrouwelijkheidaanduiding);
|
||||
Assert.Equal(new DateOnly(2026, 6, 4), req.Creatiedatum);
|
||||
Assert.Equal("nld", req.Taal);
|
||||
Assert.Equal("diploma.pdf", req.Bestandsnaam);
|
||||
Assert.Equal("application/pdf", req.Formaat);
|
||||
Assert.Equal(new byte[] { 1, 2, 3 }, req.Inhoud);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Storing_a_diploma_rejects_null_or_blank_arguments()
|
||||
{
|
||||
var service = new AclService(new FakeGateway(), Defaults(), new FixedClock(new DateOnly(2026, 6, 4)));
|
||||
var zaak = new Uri("http://openzaak/zaken/api/v1/zaken/abc");
|
||||
|
||||
await Assert.ThrowsAsync<ArgumentNullException>(() => service.StoreDiplomaAsync(null!, [1], "d.pdf", "application/pdf"));
|
||||
await Assert.ThrowsAsync<ArgumentNullException>(() => service.StoreDiplomaAsync(zaak, null!, "d.pdf", "application/pdf"));
|
||||
await Assert.ThrowsAnyAsync<ArgumentException>(() => service.StoreDiplomaAsync(zaak, [1], " ", "application/pdf"));
|
||||
await Assert.ThrowsAnyAsync<ArgumentException>(() => service.StoreDiplomaAsync(zaak, [1], "d.pdf", " "));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Reading_a_zaak_reference_returns_the_zaaks_identificatie()
|
||||
{
|
||||
|
||||
@@ -432,114 +432,4 @@ public class OpenZaakGatewayTests
|
||||
b64 = (b64.Length % 4) switch { 2 => b64 + "==", 3 => b64 + "=", _ => b64 };
|
||||
return Encoding.UTF8.GetString(Convert.FromBase64String(b64));
|
||||
}
|
||||
|
||||
// --- StoreDocumentAsync (diploma upload / S-10b) ---
|
||||
|
||||
private static readonly Uri Informatieobjecttype =
|
||||
new("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip");
|
||||
|
||||
private static DocumentRequest SampleDocument(byte[]? inhoud = null) => new(
|
||||
Bronorganisatie: "517439943",
|
||||
Informatieobjecttype: Informatieobjecttype,
|
||||
Vertrouwelijkheidaanduiding: "openbaar",
|
||||
Zaak: new Uri(ZaakUrl),
|
||||
Creatiedatum: new DateOnly(2026, 6, 4),
|
||||
Titel: "Diploma",
|
||||
Auteur: "zorgprofessional",
|
||||
Taal: "nld",
|
||||
Bestandsnaam: "diploma.pdf",
|
||||
Formaat: "application/pdf",
|
||||
Inhoud: inhoud ?? [1, 2, 3, 4]);
|
||||
|
||||
// Routes the two document calls: POST /enkelvoudiginformatieobjecten (documenten) then
|
||||
// POST /zaakinformatieobjecten (zaken).
|
||||
private static StubHandler DocumentStub(Recorder rec) => new(async req =>
|
||||
{
|
||||
rec.Requests.Add(req);
|
||||
rec.ContentLengths.Add(req.Content?.Headers.ContentLength);
|
||||
rec.Bodies.Add(req.Content is null ? null : await req.Content.ReadAsStringAsync());
|
||||
|
||||
return req.RequestUri!.ToString().Contains("/enkelvoudiginformatieobjecten")
|
||||
? Json(HttpStatusCode.Created, """{"url":"http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc-1"}""")
|
||||
: Json(HttpStatusCode.Created, """{"url":"http://openzaak/zaken/api/v1/zaakinformatieobjecten/rel-1"}""");
|
||||
});
|
||||
|
||||
[Fact]
|
||||
public async Task Storing_a_document_creates_the_informatieobject_then_relates_it_to_the_zaak()
|
||||
{
|
||||
var rec = new Recorder();
|
||||
|
||||
var url = await Gateway(DocumentStub(rec)).StoreDocumentAsync(SampleDocument([10, 20, 30]));
|
||||
|
||||
Assert.Equal("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc-1", url.ToString());
|
||||
|
||||
// 1. Create the enkelvoudiginformatieobject in the Documenten API.
|
||||
var create = rec.Sent("/enkelvoudiginformatieobjecten");
|
||||
Assert.Equal(HttpMethod.Post, create.Request.Method);
|
||||
Assert.Equal("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten",
|
||||
create.Request.RequestUri!.ToString());
|
||||
Assert.Equal("Bearer", create.Request.Headers.Authorization!.Scheme);
|
||||
Assert.Contains("\"bronorganisatie\":\"517439943\"", create.Body);
|
||||
Assert.Contains("\"informatieobjecttype\":\"http://openzaak/catalogi/api/v1/informatieobjecttypen/dip\"", create.Body);
|
||||
Assert.Contains("\"creatiedatum\":\"2026-06-04\"", create.Body);
|
||||
Assert.Contains("\"titel\":\"Diploma\"", create.Body);
|
||||
Assert.Contains("\"auteur\":\"zorgprofessional\"", create.Body);
|
||||
Assert.Contains("\"taal\":\"nld\"", create.Body);
|
||||
Assert.Contains("\"bestandsnaam\":\"diploma.pdf\"", create.Body);
|
||||
Assert.Contains("\"formaat\":\"application/pdf\"", create.Body);
|
||||
Assert.Contains("\"vertrouwelijkheidaanduiding\":\"openbaar\"", create.Body);
|
||||
Assert.Contains("\"status\":\"definitief\"", create.Body);
|
||||
// indicatieGebruiksrecht must be set explicitly (false = no usage restrictions); left null,
|
||||
// OpenZaak refuses to close the zaak this document is related to ("indicatiegebruiksrecht-unset").
|
||||
Assert.Contains("\"indicatieGebruiksrecht\":false", create.Body);
|
||||
// The file content is base64-encoded into `inhoud`, with its byte length in `bestandsomvang`.
|
||||
Assert.Contains($"\"inhoud\":\"{Convert.ToBase64String([10, 20, 30])}\"", create.Body);
|
||||
Assert.Contains("\"bestandsomvang\":3", create.Body);
|
||||
|
||||
// 2. Relate that informatieobject to the zaak (Zaken API — no CRS).
|
||||
var relate = rec.Sent("/zaakinformatieobjecten");
|
||||
Assert.Equal(HttpMethod.Post, relate.Request.Method);
|
||||
Assert.Equal("http://openzaak/zaken/api/v1/zaakinformatieobjecten",
|
||||
relate.Request.RequestUri!.ToString());
|
||||
Assert.Contains($"\"zaak\":\"{ZaakUrl}\"", relate.Body);
|
||||
Assert.Contains("\"informatieobject\":\"http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc-1\"", relate.Body);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Storing_a_document_buffers_the_body_and_sends_no_crs_headers()
|
||||
{
|
||||
// uwsgi rejects a chunked body (Content-Length must be present); the Documenten API is not a
|
||||
// geo API, so no CRS headers (unlike the Zaken zaak-create).
|
||||
var rec = new Recorder();
|
||||
|
||||
await Gateway(DocumentStub(rec)).StoreDocumentAsync(SampleDocument());
|
||||
|
||||
var create = rec.Sent("/enkelvoudiginformatieobjecten");
|
||||
Assert.NotNull(create.Length);
|
||||
Assert.True(create.Length > 0);
|
||||
Assert.False(create.Request.Headers.Contains("Accept-Crs"));
|
||||
Assert.False(create.Request.Content!.Headers.Contains("Content-Crs"));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Storing_a_document_surfaces_an_openzaak_rejection()
|
||||
{
|
||||
var handler = new StubHandler(_ =>
|
||||
Task.FromResult(new HttpResponseMessage(HttpStatusCode.BadRequest)
|
||||
{
|
||||
Content = new StringContent("""{"detail":"bad"}""", Encoding.UTF8, "application/json"),
|
||||
}));
|
||||
|
||||
var ex = await Assert.ThrowsAsync<HttpRequestException>(
|
||||
() => Gateway(handler).StoreDocumentAsync(SampleDocument()));
|
||||
Assert.Contains("bad", ex.Message);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Storing_a_document_rejects_a_null_request()
|
||||
{
|
||||
var handler = new StubHandler(_ => throw new InvalidOperationException("should not be sent"));
|
||||
|
||||
await Assert.ThrowsAsync<ArgumentNullException>(() => Gateway(handler).StoreDocumentAsync(null!));
|
||||
}
|
||||
}
|
||||
|
||||
@@ -27,12 +27,6 @@ public interface IDomainClient
|
||||
/// unknown or not the caller's (404), so the BFF can relay a 404 rather than a 500.</summary>
|
||||
Task<bool> WithdrawRegistrationAsync(string registrationId, string bsn, CancellationToken ct = default);
|
||||
|
||||
/// <summary>Provide (upload) the diploma the caller's own registration is waiting for ("documenten
|
||||
/// aanleveren"). The file is carried base64-encoded. Owner-scoped by <paramref name="bsn"/>. Returns
|
||||
/// <c>false</c> when the domain reports the registration is unknown or not the caller's (404).</summary>
|
||||
Task<bool> ProvideDocumentsAsync(
|
||||
string registrationId, string bsn, string contentBase64, string? fileName, string? contentType, CancellationToken ct = default);
|
||||
|
||||
/// <summary>The behandelaar's werkbak — registrations awaiting beoordeling.</summary>
|
||||
Task<IReadOnlyList<WerkbakItem>> GetWerkbakAsync(CancellationToken ct = default);
|
||||
|
||||
@@ -69,19 +63,6 @@ public sealed class DomainClient(HttpClient http) : IDomainClient
|
||||
return true;
|
||||
}
|
||||
|
||||
public async Task<bool> ProvideDocumentsAsync(
|
||||
string registrationId, string bsn, string contentBase64, string? fileName, string? contentType, CancellationToken ct = default)
|
||||
{
|
||||
using var response = await http.PostAsJsonAsync(
|
||||
$"registrations/{registrationId}/documents",
|
||||
new { bsn, contentBase64, fileName, contentType }, ct);
|
||||
// The domain 404s an unknown or not-owned registration; relay that rather than fail hard.
|
||||
if (response.StatusCode == System.Net.HttpStatusCode.NotFound)
|
||||
return false;
|
||||
response.EnsureSuccessStatusCode();
|
||||
return true;
|
||||
}
|
||||
|
||||
public async Task<IReadOnlyList<WerkbakItem>> GetWerkbakAsync(CancellationToken ct = default)
|
||||
=> await http.GetFromJsonAsync<List<WerkbakItem>>("behandel/werkbak", ct) ?? [];
|
||||
|
||||
|
||||
@@ -104,28 +104,6 @@ app.MapPost("/self-service/registrations/{id}/withdraw", async (string id, Claim
|
||||
.Produces(StatusCodes.Status401Unauthorized)
|
||||
.Produces(StatusCodes.Status404NotFound);
|
||||
|
||||
// Self-service provide-documents (S-10a): the signed-in zorgprofessional supplies the documents their
|
||||
// registration is waiting for ("documenten aanleveren"). The bsn comes from the DigiD token and is
|
||||
// forwarded to the domain, which owner-scopes the action and completes the WachtOpDocumenten task; a
|
||||
// registration that is unknown or not the caller's comes back 404. The real file upload + ZGW storage
|
||||
// is S-10b — this is the trigger that unblocks the process.
|
||||
app.MapPost("/self-service/registrations/{id}/documents", async (string id, ProvideDocumentsRequest body, ClaimsPrincipal user, IDomainClient domain, CancellationToken ct) =>
|
||||
{
|
||||
var bsn = user.FindFirstValue("bsn");
|
||||
if (string.IsNullOrWhiteSpace(bsn))
|
||||
return Results.BadRequest("The token carries no bsn claim.");
|
||||
if (string.IsNullOrWhiteSpace(body?.ContentBase64))
|
||||
return Results.BadRequest("A document is required.");
|
||||
|
||||
var provided = await domain.ProvideDocumentsAsync(id, bsn, body.ContentBase64, body.FileName, body.ContentType, ct);
|
||||
return provided ? Results.NoContent() : Results.NotFound();
|
||||
})
|
||||
.RequireAuthorization()
|
||||
.Produces(StatusCodes.Status204NoContent)
|
||||
.Produces(StatusCodes.Status400BadRequest)
|
||||
.Produces(StatusCodes.Status401Unauthorized)
|
||||
.Produces(StatusCodes.Status404NotFound);
|
||||
|
||||
// Openbaar register: an anonymous public lookup that exposes only public-safe fields (S-09).
|
||||
app.MapGet("/openbaar/register", async (string? q, IProjectionClient projection, CancellationToken ct) =>
|
||||
{
|
||||
@@ -165,10 +143,6 @@ app.Run();
|
||||
/// <summary>The behandelaar's decision on a registration.</summary>
|
||||
public sealed record DecideRequest(string Besluit);
|
||||
|
||||
/// <summary>A diploma upload from the self-service portal — the file base64-encoded client-side, with
|
||||
/// its name and MIME type. The bsn is taken from the DigiD token, not this body.</summary>
|
||||
public sealed record ProvideDocumentsRequest(string ContentBase64, string? FileName = null, string? ContentType = null);
|
||||
|
||||
// Behandel (medewerker-realm) authentication + authorization wiring (ADR-0013).
|
||||
internal static class BehandelAuth
|
||||
{
|
||||
|
||||
@@ -94,18 +94,6 @@ internal sealed class FakeDomainClient : IDomainClient
|
||||
return Task.FromResult(WithdrawSucceeds);
|
||||
}
|
||||
|
||||
public (string RegistrationId, string Bsn, string ContentBase64, string? FileName, string? ContentType)? DocumentsProvidedFor { get; private set; }
|
||||
|
||||
/// <summary>Whether the fake domain reports the provide-documents as done (true → 204) or
|
||||
/// not-found/not-owned (false → 404). Tests set this to exercise the relay.</summary>
|
||||
public bool ProvideDocumentsSucceeds { get; set; } = true;
|
||||
|
||||
public Task<bool> ProvideDocumentsAsync(string registrationId, string bsn, string contentBase64, string? fileName, string? contentType, CancellationToken ct = default)
|
||||
{
|
||||
DocumentsProvidedFor = (registrationId, bsn, contentBase64, fileName, contentType);
|
||||
return Task.FromResult(ProvideDocumentsSucceeds);
|
||||
}
|
||||
|
||||
public (string RegistrationId, string Besluit)? Decided { get; private set; }
|
||||
|
||||
public Task<IReadOnlyList<WerkbakItem>> GetWerkbakAsync(CancellationToken ct = default)
|
||||
|
||||
@@ -112,61 +112,5 @@ public class SelfServiceEndpointTests
|
||||
Assert.Equal(HttpStatusCode.NotFound, response.StatusCode);
|
||||
}
|
||||
|
||||
private static HttpRequestMessage ProvideDocuments(string? bearer, string id = "reg-123")
|
||||
{
|
||||
var request = new HttpRequestMessage(HttpMethod.Post, $"/self-service/registrations/{id}/documents")
|
||||
{
|
||||
// The portal base64-encodes the file client-side and posts it as JSON (S-10b); the bsn is
|
||||
// never in the body — it comes from the DigiD token.
|
||||
Content = JsonContent.Create(new
|
||||
{
|
||||
contentBase64 = Convert.ToBase64String([1, 2, 3]),
|
||||
fileName = "diploma.pdf",
|
||||
contentType = "application/pdf",
|
||||
}),
|
||||
};
|
||||
if (bearer is not null)
|
||||
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", bearer);
|
||||
return request;
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Rejects_providing_documents_without_a_token()
|
||||
{
|
||||
using var factory = new BffFactory();
|
||||
|
||||
var response = await factory.CreateClient().SendAsync(ProvideDocuments(bearer: null));
|
||||
|
||||
Assert.Equal(HttpStatusCode.Unauthorized, response.StatusCode);
|
||||
Assert.Null(factory.Domain.DocumentsProvidedFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Provides_documents_for_the_callers_registration_forwarding_id_bsn_and_file()
|
||||
{
|
||||
using var factory = new BffFactory();
|
||||
|
||||
var response = await factory.CreateClient().SendAsync(ProvideDocuments(TestTokens.Valid("123456782"), "reg-9"));
|
||||
|
||||
Assert.Equal(HttpStatusCode.NoContent, response.StatusCode);
|
||||
var provided = factory.Domain.DocumentsProvidedFor;
|
||||
Assert.NotNull(provided);
|
||||
Assert.Equal("reg-9", provided!.Value.RegistrationId);
|
||||
Assert.Equal("123456782", provided.Value.Bsn);
|
||||
Assert.Equal(Convert.ToBase64String([1, 2, 3]), provided.Value.ContentBase64);
|
||||
Assert.Equal("diploma.pdf", provided.Value.FileName);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Relays_not_found_providing_documents_for_an_unknown_or_not_owned_registration()
|
||||
{
|
||||
using var factory = new BffFactory();
|
||||
factory.Domain.ProvideDocumentsSucceeds = false;
|
||||
|
||||
var response = await factory.CreateClient().SendAsync(ProvideDocuments(TestTokens.Valid("123456782")));
|
||||
|
||||
Assert.Equal(HttpStatusCode.NotFound, response.StatusCode);
|
||||
}
|
||||
|
||||
private sealed record SubmitAcceptedDto(string RegistrationId, string Status);
|
||||
}
|
||||
|
||||
@@ -61,47 +61,6 @@
|
||||
}
|
||||
}
|
||||
},
|
||||
"/self-service/registrations/{id}/documents": {
|
||||
"post": {
|
||||
"tags": [
|
||||
"Bff.Api"
|
||||
],
|
||||
"parameters": [
|
||||
{
|
||||
"name": "id",
|
||||
"in": "path",
|
||||
"required": true,
|
||||
"schema": {
|
||||
"type": "string"
|
||||
}
|
||||
}
|
||||
],
|
||||
"requestBody": {
|
||||
"content": {
|
||||
"application/json": {
|
||||
"schema": {
|
||||
"$ref": "#/components/schemas/ProvideDocumentsRequest"
|
||||
}
|
||||
}
|
||||
},
|
||||
"required": true
|
||||
},
|
||||
"responses": {
|
||||
"204": {
|
||||
"description": "No Content"
|
||||
},
|
||||
"400": {
|
||||
"description": "Bad Request"
|
||||
},
|
||||
"401": {
|
||||
"description": "Unauthorized"
|
||||
},
|
||||
"404": {
|
||||
"description": "Not Found"
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"/openbaar/register": {
|
||||
"get": {
|
||||
"tags": [
|
||||
@@ -238,29 +197,6 @@
|
||||
}
|
||||
}
|
||||
},
|
||||
"ProvideDocumentsRequest": {
|
||||
"required": [
|
||||
"contentBase64"
|
||||
],
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"contentBase64": {
|
||||
"type": "string"
|
||||
},
|
||||
"fileName": {
|
||||
"type": [
|
||||
"null",
|
||||
"string"
|
||||
]
|
||||
},
|
||||
"contentType": {
|
||||
"type": [
|
||||
"null",
|
||||
"string"
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
"SubmitAccepted": {
|
||||
"required": [
|
||||
"registrationId",
|
||||
|
||||
@@ -29,7 +29,6 @@ builder.Services.AddScoped<SubmitRegistration>();
|
||||
builder.Services.AddScoped<ApproveRegistration>();
|
||||
builder.Services.AddScoped<BeoordeelRegistratie>();
|
||||
builder.Services.AddScoped<WithdrawRegistration>();
|
||||
builder.Services.AddScoped<ProvideDocuments>();
|
||||
builder.Services.AddScoped<Werkbak>();
|
||||
builder.Services.AddScoped<OpenZaakWorker>();
|
||||
builder.Services.AddScoped<OpenZaakJobProcessor>();
|
||||
@@ -108,32 +107,6 @@ app.MapPost("/registrations/{id}/withdraw", async (string id, WithdrawRequest bo
|
||||
return outcome == WithdrawOutcome.Withdrawn ? Results.NoContent() : Results.NotFound();
|
||||
});
|
||||
|
||||
// Provide documents (S-10a): the zorgprofessional supplies the documents their registration is parked
|
||||
// waiting for, completing the WachtOpDocumenten task so the process advances to beoordeling (ADR-0017).
|
||||
// Owner-scoped by the caller's bsn (the BFF forwards it from the DigiD token); unknown or not-the-
|
||||
// caller's is 404 (indistinguishable). Idempotent — completing an already-left wait is a no-op. The
|
||||
// real file upload + ZGW storage is S-10b; this endpoint is the trigger that unblocks the process.
|
||||
app.MapPost("/registrations/{id}/documents", async (string id, ProvideDocumentsRequest body, ProvideDocuments provide, CancellationToken ct) =>
|
||||
{
|
||||
if (!Guid.TryParse(id, out var guid))
|
||||
return Results.NotFound();
|
||||
|
||||
if (string.IsNullOrWhiteSpace(body?.Bsn))
|
||||
return Results.BadRequest(new { error = "A bsn is required to provide documents." });
|
||||
if (string.IsNullOrWhiteSpace(body.ContentBase64))
|
||||
return Results.BadRequest(new { error = "A document is required." });
|
||||
|
||||
byte[] content;
|
||||
try { content = Convert.FromBase64String(body.ContentBase64); }
|
||||
catch (FormatException) { return Results.BadRequest(new { error = "The document content is not valid base64." }); }
|
||||
|
||||
var command = new ProvideDocumentsCommand(
|
||||
new RegistrationId(guid), body.Bsn, content,
|
||||
body.FileName ?? "diploma.pdf", body.ContentType ?? "application/pdf");
|
||||
var outcome = await provide.HandleAsync(command, ct);
|
||||
return outcome == ProvideDocumentsOutcome.Accepted ? Results.NoContent() : Results.NotFound();
|
||||
});
|
||||
|
||||
// The behandelaar's werkbak (S-12): the registrations awaiting beoordeling, read from the open
|
||||
// Beoordelen user tasks (§8.2) and enriched with bsn + status. The BFF proxies this behind
|
||||
// medewerker-realm + behandelaar-role authorization; the domain trusts its callers (§8.3).
|
||||
@@ -161,8 +134,6 @@ public sealed record DecideRequest(string Besluit);
|
||||
|
||||
public sealed record WithdrawRequest(string Bsn);
|
||||
|
||||
public sealed record ProvideDocumentsRequest(string Bsn, string ContentBase64, string? FileName = null, string? ContentType = null);
|
||||
|
||||
public sealed record RegistrationResponse(string RegistrationId, string Status, string? ZaakUrl);
|
||||
|
||||
public partial class Program;
|
||||
|
||||
@@ -12,11 +12,9 @@ namespace Big.Application;
|
||||
public sealed class ExpireRegistrationWorker(IRegistrationStore store)
|
||||
{
|
||||
/// <summary>
|
||||
/// Process the job. Idempotent and tolerant of races (§8.6, at-least-once delivery): a job whose
|
||||
/// registration is already resolved — a redelivered expiry (VERLOPEN), or one withdrawn/decided
|
||||
/// while it waited (INGETROKKEN/INGESCHREVEN/AFGEWEZEN) — is a no-op, so the job still completes
|
||||
/// rather than throwing into a redelivery loop. Only a still-open registration is expired. An
|
||||
/// unknown registration is an error: it throws, leaving the job un-completed for Flowable to redeliver.
|
||||
/// Process the job. Idempotent: a redelivered job whose registration is already VERLOPEN is a
|
||||
/// no-op — not persisted again (§8.6, at-least-once delivery). An unknown registration is an error:
|
||||
/// it throws, leaving the job un-completed for Flowable to redeliver.
|
||||
/// </summary>
|
||||
public async Task HandleAsync(RegistratieVerlopenJob job, CancellationToken ct = default)
|
||||
{
|
||||
@@ -26,9 +24,8 @@ public sealed class ExpireRegistrationWorker(IRegistrationStore store)
|
||||
?? throw new InvalidOperationException(
|
||||
$"No registration {job.RegistrationId} for RegistratieVerlopen job {job.JobId}.");
|
||||
|
||||
// Only a still-open registration lapses; an already-resolved one (expired, or withdrawn/decided
|
||||
// while it waited) is left untouched so the job can complete without violating the aggregate.
|
||||
if (registration.Status is not (RegistrationStatus.Ingediend or RegistrationStatus.InBehandeling))
|
||||
// A redelivered job whose registration is already VERLOPEN completes without persisting again.
|
||||
if (registration.Status == RegistrationStatus.Verlopen)
|
||||
return;
|
||||
|
||||
registration.Expire();
|
||||
|
||||
@@ -52,13 +52,6 @@ public interface IAclClient
|
||||
/// the zaak's final status — which OpenZaak notifies over NRC; the domain never names statustypen.
|
||||
/// </summary>
|
||||
Task ApproveZaakAsync(Uri zaakUrl, CancellationToken ct = default);
|
||||
|
||||
/// <summary>
|
||||
/// Store an uploaded diploma against the zaak (S-10b). The domain hands over the zaak, the raw file
|
||||
/// bytes, and the file's name/type; the ACL creates the ZGW informatieobject and relates it to the
|
||||
/// zaak (§8.1). Returns the stored document's URL.
|
||||
/// </summary>
|
||||
Task<Uri> StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default);
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
using Big.Domain;
|
||||
|
||||
namespace Big.Application;
|
||||
|
||||
/// <summary>A zorgprofessional's upload of the diploma their registration is waiting for ("documenten
|
||||
/// aanleveren"). <paramref name="Bsn"/> is the authenticated caller (from the DigiD token, forwarded by
|
||||
/// the BFF): only the registration's own bsn may provide its documents. <paramref name="Content"/> is
|
||||
/// the raw file, with its <paramref name="FileName"/> and <paramref name="ContentType"/>.</summary>
|
||||
public sealed record ProvideDocumentsCommand(
|
||||
RegistrationId RegistrationId, string Bsn, byte[] Content, string FileName, string ContentType);
|
||||
|
||||
/// <summary>The outcome of a provide-documents request.</summary>
|
||||
public enum ProvideDocumentsOutcome
|
||||
{
|
||||
/// <summary>The documents were accepted; the process's document wait was completed (if any).</summary>
|
||||
Accepted,
|
||||
|
||||
/// <summary>No registration with that id belongs to the caller — unknown, or owned by someone else
|
||||
/// (the two are deliberately indistinguishable, so the endpoint reveals neither).</summary>
|
||||
NotFound,
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// The provide-documents use case (S-10a/S-10b): a zorgprofessional uploads the diploma their
|
||||
/// registration is parked waiting for. The document is stored in ZGW via the ACL (§8.1), then the
|
||||
/// WachtOpDocumenten task is completed so the registratie process leaves the 30-day wait and continues
|
||||
/// to beoordeling (ADR-0017). Owner-scoped by bsn. Both steps are best-effort about missing preconditions
|
||||
/// (mirroring <see cref="WithdrawRegistration"/>): storage needs an opened zaak, and completion needs a
|
||||
/// running process — a request that arrives before either still stands, storing/completing what it can.
|
||||
/// </summary>
|
||||
public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient workflow, IAclClient acl)
|
||||
{
|
||||
public async Task<ProvideDocumentsOutcome> HandleAsync(ProvideDocumentsCommand command, CancellationToken ct = default)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(command);
|
||||
|
||||
var registration = await store.GetAsync(command.RegistrationId, ct);
|
||||
|
||||
// Unknown, or not the caller's registration: report NotFound either way (don't reveal which).
|
||||
if (registration is null || registration.Bsn != command.Bsn)
|
||||
return ProvideDocumentsOutcome.NotFound;
|
||||
|
||||
// Store the diploma against the zaak (once it is opened) — the ACL is the only ZGW caller (§8.1).
|
||||
if (registration.ZaakUrl is not null)
|
||||
await acl.StoreDiplomaAsync(
|
||||
registration.ZaakUrl, command.Content, command.FileName, command.ContentType, ct);
|
||||
|
||||
// Complete the document wait (if a process is running) so beoordeling can proceed.
|
||||
if (registration.ProcessInstanceId is not null)
|
||||
await workflow.CompleteDocumentWaitAsync(registration.ProcessInstanceId, ct);
|
||||
|
||||
return ProvideDocumentsOutcome.Accepted;
|
||||
}
|
||||
}
|
||||
@@ -31,23 +31,6 @@ public sealed class AclHttpClient(HttpClient http, AclOptions options) : IAclCli
|
||||
response.EnsureSuccessStatusCode();
|
||||
}
|
||||
|
||||
public async Task<Uri> StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(zaakUrl);
|
||||
ArgumentNullException.ThrowIfNull(content);
|
||||
|
||||
// The file crosses this boundary base64-encoded in JSON — the domain and ACL contracts are
|
||||
// JSON, and a diploma is small (S-10b, ADR). The ACL turns it into a ZGW informatieobject.
|
||||
using var response = await http.PostAsJsonAsync(
|
||||
new Uri(options.BaseUrl, "documenten"),
|
||||
new StoreDocumentRequest(zaakUrl.ToString(), Convert.ToBase64String(content), fileName, contentType), ct);
|
||||
response.EnsureSuccessStatusCode();
|
||||
|
||||
var stored = await response.Content.ReadFromJsonAsync<StoreDocumentResponse>(ct)
|
||||
?? throw new InvalidOperationException("The ACL returned an empty document response.");
|
||||
return new Uri(stored.InformatieobjectUrl);
|
||||
}
|
||||
|
||||
private sealed record OpenZaakRequest(
|
||||
[property: JsonPropertyName("bsn")] string Bsn,
|
||||
[property: JsonPropertyName("reference")] string Reference);
|
||||
@@ -55,13 +38,4 @@ public sealed class AclHttpClient(HttpClient http, AclOptions options) : IAclCli
|
||||
private sealed record OpenZaakResponse([property: JsonPropertyName("zaakUrl")] string ZaakUrl);
|
||||
|
||||
private sealed record SetStatusRequest([property: JsonPropertyName("zaakUrl")] string ZaakUrl);
|
||||
|
||||
private sealed record StoreDocumentRequest(
|
||||
[property: JsonPropertyName("zaakUrl")] string ZaakUrl,
|
||||
[property: JsonPropertyName("contentBase64")] string ContentBase64,
|
||||
[property: JsonPropertyName("fileName")] string FileName,
|
||||
[property: JsonPropertyName("contentType")] string ContentType);
|
||||
|
||||
private sealed record StoreDocumentResponse(
|
||||
[property: JsonPropertyName("informatieobjectUrl")] string InformatieobjectUrl);
|
||||
}
|
||||
|
||||
@@ -48,25 +48,6 @@ public class ExpireRegistrationWorkerTests
|
||||
Assert.Equal(RegistrationStatus.Verlopen, (await store.GetAsync(registration.Id))!.Status);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task An_already_resolved_registration_is_left_alone_and_the_job_completes()
|
||||
{
|
||||
// Race with S-11: the citizen withdrew while parked at WachtOpDocumenten, so the aggregate is
|
||||
// already terminal (INGETROKKEN) when the timer's job arrives. Expiring it would violate the
|
||||
// aggregate's invariant; the worker must instead no-op (and let the job complete), not throw
|
||||
// into a redelivery loop.
|
||||
var store = new FakeRegistrationStore();
|
||||
var registration = Submitted();
|
||||
registration.Withdraw();
|
||||
store.Seed(registration);
|
||||
|
||||
await new ExpireRegistrationWorker(store).HandleAsync(
|
||||
new RegistratieVerlopenJob("job-7", registration.Id));
|
||||
|
||||
Assert.Equal(0, store.SaveCount);
|
||||
Assert.Equal(RegistrationStatus.Ingetrokken, (await store.GetAsync(registration.Id))!.Status);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task An_unknown_registration_throws_so_the_job_is_redelivered()
|
||||
{
|
||||
|
||||
@@ -110,13 +110,4 @@ internal sealed class FakeAclClient(Uri? zaakUrl = null) : IAclClient
|
||||
ApprovedZaakUrl = zaakUrl;
|
||||
return Task.CompletedTask;
|
||||
}
|
||||
|
||||
public (Uri ZaakUrl, byte[] Content, string FileName, string ContentType)? StoredDiploma { get; private set; }
|
||||
public static readonly Uri DefaultDocumentUrl = new("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc");
|
||||
|
||||
public Task<Uri> StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default)
|
||||
{
|
||||
StoredDiploma = (zaakUrl, content, fileName, contentType);
|
||||
return Task.FromResult(DefaultDocumentUrl);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,96 +0,0 @@
|
||||
using Big.Application;
|
||||
using Big.Domain;
|
||||
|
||||
namespace Big.Tests;
|
||||
|
||||
// S-10a/S-10b (#102/#103): the "documents received" use case. A zorgprofessional supplies the diploma
|
||||
// their registration is waiting for; the handler stores it in ZGW via the ACL and completes the
|
||||
// WachtOpDocumenten task via the Workflow Client so the process continues to beoordeling. Owner-scoped
|
||||
// by the caller's bsn, like WithdrawRegistration.
|
||||
public class ProvideDocumentsTests
|
||||
{
|
||||
private const string Bsn = "123456782";
|
||||
private static readonly Uri Zaak = new("http://openzaak/zaken/api/v1/zaken/abc");
|
||||
|
||||
private static Registration Submitted(string processInstanceId = "proc-1")
|
||||
{
|
||||
var registration = Registration.Submit(Bsn);
|
||||
registration.RecordProcessStarted(processInstanceId);
|
||||
registration.AttachZaak(Zaak);
|
||||
return registration;
|
||||
}
|
||||
|
||||
private static ProvideDocumentsCommand Command(RegistrationId id, string bsn = Bsn) =>
|
||||
new(id, bsn, [1, 2, 3], "diploma.pdf", "application/pdf");
|
||||
|
||||
[Fact]
|
||||
public async Task Providing_documents_stores_the_diploma_and_completes_the_wait()
|
||||
{
|
||||
var store = new FakeRegistrationStore();
|
||||
var registration = Submitted("proc-42");
|
||||
store.Seed(registration);
|
||||
var workflow = new FakeWorkflowClient();
|
||||
var acl = new FakeAclClient();
|
||||
var handler = new ProvideDocuments(store, workflow, acl);
|
||||
|
||||
var outcome = await handler.HandleAsync(Command(registration.Id));
|
||||
|
||||
Assert.Equal(ProvideDocumentsOutcome.Accepted, outcome);
|
||||
// Stored against the registration's zaak, carrying the uploaded bytes + file metadata.
|
||||
Assert.Equal((Zaak, new byte[] { 1, 2, 3 }, "diploma.pdf", "application/pdf"), acl.StoredDiploma);
|
||||
// …and the wait is completed so beoordeling can proceed.
|
||||
Assert.Equal("proc-42", workflow.CompletedDocumentWaitFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task A_different_bsn_cannot_provide_documents()
|
||||
{
|
||||
// Owner-scoping: another bsn is told NotFound; nothing is stored or completed.
|
||||
var store = new FakeRegistrationStore();
|
||||
var registration = Submitted();
|
||||
store.Seed(registration);
|
||||
var workflow = new FakeWorkflowClient();
|
||||
var acl = new FakeAclClient();
|
||||
var handler = new ProvideDocuments(store, workflow, acl);
|
||||
|
||||
var outcome = await handler.HandleAsync(Command(registration.Id, bsn: "999999990"));
|
||||
|
||||
Assert.Equal(ProvideDocumentsOutcome.NotFound, outcome);
|
||||
Assert.Null(acl.StoredDiploma);
|
||||
Assert.Null(workflow.CompletedDocumentWaitFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Providing_for_an_unknown_registration_is_not_found()
|
||||
{
|
||||
var store = new FakeRegistrationStore();
|
||||
var handler = new ProvideDocuments(store, new FakeWorkflowClient(), new FakeAclClient());
|
||||
|
||||
Assert.Equal(ProvideDocumentsOutcome.NotFound, await handler.HandleAsync(Command(RegistrationId.New())));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Providing_before_a_zaak_is_opened_does_not_store_but_still_completes_the_wait()
|
||||
{
|
||||
// No zaak yet → nothing to file the document against, but the request still stands (best-effort,
|
||||
// mirroring WithdrawRegistration). The wait is completed if a process is running.
|
||||
var store = new FakeRegistrationStore();
|
||||
var registration = Registration.Submit(Bsn);
|
||||
registration.RecordProcessStarted("proc-9"); // process started, but no zaak attached
|
||||
store.Seed(registration);
|
||||
var workflow = new FakeWorkflowClient();
|
||||
var acl = new FakeAclClient();
|
||||
var handler = new ProvideDocuments(store, workflow, acl);
|
||||
|
||||
var outcome = await handler.HandleAsync(Command(registration.Id));
|
||||
|
||||
Assert.Equal(ProvideDocumentsOutcome.Accepted, outcome);
|
||||
Assert.Null(acl.StoredDiploma);
|
||||
Assert.Equal("proc-9", workflow.CompletedDocumentWaitFor);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task Rejects_a_null_command()
|
||||
=> await Assert.ThrowsAsync<ArgumentNullException>(() =>
|
||||
new ProvideDocuments(new FakeRegistrationStore(), new FakeWorkflowClient(), new FakeAclClient()).HandleAsync(null!));
|
||||
}
|
||||
@@ -30,7 +30,6 @@ public sealed class EenZaakOpenenSteps
|
||||
VerantwoordelijkeOrganisatie = values["verantwoordelijkeOrganisatie"],
|
||||
Vertrouwelijkheidaanduiding = values["vertrouwelijkheidaanduiding"],
|
||||
ZaaktypeUrl = new Uri(values["zaaktype"]),
|
||||
InformatieobjecttypeUrl = new Uri("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"),
|
||||
};
|
||||
}
|
||||
|
||||
|
||||
@@ -72,10 +72,6 @@ public sealed class CapturingDomainClient : IDomainClient
|
||||
public Task<bool> WithdrawRegistrationAsync(string registrationId, string bsn, CancellationToken ct = default)
|
||||
=> Task.FromResult(true);
|
||||
|
||||
public Task<bool> ProvideDocumentsAsync(
|
||||
string registrationId, string bsn, string contentBase64, string? fileName, string? contentType, CancellationToken ct = default)
|
||||
=> Task.FromResult(true);
|
||||
|
||||
public Task<IReadOnlyList<WerkbakItem>> GetWerkbakAsync(CancellationToken ct = default)
|
||||
=> Task.FromResult<IReadOnlyList<WerkbakItem>>([]);
|
||||
|
||||
|
||||
@@ -59,14 +59,6 @@ public sealed class InMemoryAclClient : IAclClient
|
||||
ApprovedZaakUrl = zaakUrl;
|
||||
return Task.CompletedTask;
|
||||
}
|
||||
|
||||
public (Uri ZaakUrl, string FileName)? StoredDiploma { get; private set; }
|
||||
|
||||
public Task<Uri> StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default)
|
||||
{
|
||||
StoredDiploma = (zaakUrl, fileName);
|
||||
return Task.FromResult(new Uri("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/acc-doc"));
|
||||
}
|
||||
}
|
||||
|
||||
/// <summary>An in-memory user-task client for the beoordeling acceptance scenario: it holds one open
|
||||
|
||||
@@ -27,7 +27,4 @@ public sealed class InMemoryZaakGateway : IZaakGateway
|
||||
|
||||
public Task<string> GetZaakIdentificatieAsync(Uri zaakUrl, CancellationToken ct = default)
|
||||
=> Task.FromResult("ACC-REF-1");
|
||||
|
||||
public Task<Uri> StoreDocumentAsync(DocumentRequest request, CancellationToken ct = default)
|
||||
=> Task.FromResult(new Uri("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/acc-doc"));
|
||||
}
|
||||
|
||||
@@ -1,15 +1,11 @@
|
||||
import { expect, test } from '@playwright/test';
|
||||
|
||||
// Walking-skeleton happy path (S-08d + S-09 + S-09b + S-12 + S-10a): a zorgprofessional logs in via
|
||||
// mock DigiD and submits through the self-service portal → BFF → domain; the entry appears in the
|
||||
// openbaar register as INGEDIEND; the citizen supplies the documents the process is waiting for
|
||||
// (S-10a); a behandelaar then logs in to the behandel portal, finds the registration in the werkbak,
|
||||
// and approves it (goedkeuren); the decision completes the Flowable Beoordelen task and flows via the
|
||||
// ACL → NRC → event-subscriber → projection, and the openbaar register shows INGESCHREVEN.
|
||||
test('DigiD submit → public INGEDIEND → documenten → behandelaar goedkeurt → public INGESCHREVEN', async ({
|
||||
page,
|
||||
context,
|
||||
}) => {
|
||||
// Walking-skeleton happy path (S-08d + S-09 + S-09b + S-12): a zorgprofessional logs in via mock
|
||||
// DigiD and submits through the self-service portal → BFF → domain; the entry appears in the openbaar
|
||||
// register as INGEDIEND; a behandelaar then logs in to the behandel portal, finds the registration in
|
||||
// the werkbak, and approves it (goedkeuren); the decision completes the Flowable Beoordelen task and
|
||||
// flows via the ACL → NRC → event-subscriber → projection, and the openbaar register shows INGESCHREVEN.
|
||||
test('DigiD submit → public INGEDIEND → behandelaar goedkeurt → public INGESCHREVEN', async ({ page }) => {
|
||||
// Visiting the guarded page redirects to the Keycloak (mock DigiD) login.
|
||||
await page.goto('/');
|
||||
|
||||
@@ -30,58 +26,42 @@ test('DigiD submit → public INGEDIEND → documenten → behandelaar goedkeurt
|
||||
expect(reference, 'the confirmation shows a registration reference').toBeTruthy();
|
||||
|
||||
// The openbaar register (anonymous, its own origin) shows the submitted entry once the projection
|
||||
// catches up. We check it on a SEPARATE page so the self-service tab keeps its (in-memory) submitted
|
||||
// state — the "Documenten aanleveren" action below acts on that same session. The projection updates
|
||||
// asynchronously (NRC → event-subscriber), so reload until *this* submission's row appears. We poll
|
||||
// on the reference cell (not a generic INGEDIEND cell): the shared verify stack already holds
|
||||
// INGEDIEND rows from earlier checks, so a status-only poll would short-circuit on a stale row.
|
||||
const staff = await context.newPage();
|
||||
await staff.goto('http://openbaar/');
|
||||
await expect(staff.getByRole('heading', { name: /Openbaar BIG-register/i })).toBeVisible();
|
||||
// catches up. The projection updates asynchronously (NRC → event-subscriber), and the register loads
|
||||
// on open, so reload until *this* submission's row appears. We poll on the reference cell (not a
|
||||
// generic INGEDIEND cell): the shared verify stack already holds INGEDIEND rows from earlier checks,
|
||||
// so a status-only poll would short-circuit on a stale row before our row is projected.
|
||||
await page.goto('http://openbaar/');
|
||||
await expect(page.getByRole('heading', { name: /Openbaar BIG-register/i })).toBeVisible();
|
||||
|
||||
// #78: the reference shown in the public register must be the exact one the citizen saw on the
|
||||
// submit confirmation — no mismatch between the two portals.
|
||||
await expect
|
||||
.poll(async () => {
|
||||
await staff.reload();
|
||||
return staff.getByRole('cell', { name: reference }).count();
|
||||
await page.reload();
|
||||
return page.getByRole('cell', { name: reference }).count();
|
||||
}, { timeout: 30_000, intervals: [1_000, 2_000, 3_000, 5_000] })
|
||||
.toBeGreaterThan(0);
|
||||
await expect(staff.getByRole('row', { name: reference }).getByRole('cell', { name: 'INGEDIEND' }))
|
||||
await expect(page.getByRole('row', { name: reference }).getByRole('cell', { name: 'INGEDIEND' }))
|
||||
.toBeVisible();
|
||||
|
||||
// Provide the documents the registration is waiting for (S-10a), on the still-open self-service tab.
|
||||
// The process parks at WachtOpDocumenten only after the zaak is opened; the INGEDIEND row above proves
|
||||
// the zaak exists — so the OpenZaak worker has completed and the process is now at the wait — which is
|
||||
// why we supply the documents here rather than right after submit, when the trigger would race the
|
||||
// wait and no-op. (S-10b turns this into a real file upload; here it is the trigger that unblocks
|
||||
// beoordeling.)
|
||||
await page.setInputFiles('#diploma', {
|
||||
name: 'diploma.pdf',
|
||||
mimeType: 'application/pdf',
|
||||
buffer: Buffer.from('%PDF-1.4 synthetic diploma\n'),
|
||||
});
|
||||
await page.getByRole('button', { name: /documenten aanleveren/i }).click();
|
||||
await expect(page.getByText(/documenten zijn aangeleverd/i)).toBeVisible();
|
||||
// A behandelaar picks the registration up in the behandel-portal werkbak and approves it
|
||||
// (goedkeuren) — the S-12 flow that replaces the temporary admin endpoint. Navigating here switches
|
||||
// to the medewerker realm (a different Keycloak realm than the citizen's digid session).
|
||||
await page.goto('http://behandel/');
|
||||
await page.locator('#username').fill('merel-behandelaar');
|
||||
await page.locator('#password').fill('test123');
|
||||
await page.locator('#kc-login').click();
|
||||
|
||||
// A behandelaar picks the registration up in the behandel-portal werkbak and approves it (goedkeuren)
|
||||
// — the S-12 flow that replaces the temporary admin endpoint. The staff tab switches to the
|
||||
// medewerker realm (a different Keycloak realm than the citizen's digid session).
|
||||
await staff.goto('http://behandel/');
|
||||
await staff.locator('#username').fill('merel-behandelaar');
|
||||
await staff.locator('#password').fill('test123');
|
||||
await staff.locator('#kc-login').click();
|
||||
await expect(page.getByRole('heading', { name: /Werkbak/i })).toBeVisible();
|
||||
|
||||
await expect(staff.getByRole('heading', { name: /Werkbak/i })).toBeVisible();
|
||||
|
||||
// The registration reaches the Beoordelen user task only after its documents are provided (above), so
|
||||
// The registration parks at the Beoordelen user task only after the worker has opened its zaak, so
|
||||
// it appears in the werkbak asynchronously — reload until this reference's row shows up. Target the
|
||||
// decide button by reference (not a generic "Goedkeuren"): the shared verify stack holds other open
|
||||
// tasks, so a positional match could act on someone else's registration.
|
||||
const goedkeuren = staff.getByRole('button', { name: `Goedkeuren ${reference}` });
|
||||
const goedkeuren = page.getByRole('button', { name: `Goedkeuren ${reference}` });
|
||||
await expect
|
||||
.poll(async () => {
|
||||
await staff.reload();
|
||||
await page.reload();
|
||||
return goedkeuren.count();
|
||||
}, { timeout: 30_000, intervals: [1_000, 2_000, 3_000, 5_000] })
|
||||
.toBeGreaterThan(0);
|
||||
@@ -89,7 +69,7 @@ test('DigiD submit → public INGEDIEND → documenten → behandelaar goedkeurt
|
||||
// Click and wait for the decide POST to finish (204) BEFORE leaving the page. `click()` only
|
||||
// dispatches the request; navigating away immediately cancels it in flight (nginx logs a 499) and
|
||||
// the decision never reaches the domain — so the registration would stay INGEDIEND.
|
||||
const decided = staff.waitForResponse(
|
||||
const decided = page.waitForResponse(
|
||||
(r) =>
|
||||
r.url().includes(`/behandel/registrations/${reference}/decide`) &&
|
||||
r.request().method() === 'POST',
|
||||
@@ -99,11 +79,11 @@ test('DigiD submit → public INGEDIEND → documenten → behandelaar goedkeurt
|
||||
|
||||
// The approval flows back to the projection; back on the openbaar register *our* row (matched by
|
||||
// its reference) now shows INGESCHREVEN.
|
||||
await staff.goto('http://openbaar/');
|
||||
await page.goto('http://openbaar/');
|
||||
await expect
|
||||
.poll(async () => {
|
||||
await staff.reload();
|
||||
return staff.getByRole('row', { name: reference }).getByRole('cell', { name: 'INGESCHREVEN' }).count();
|
||||
await page.reload();
|
||||
return page.getByRole('row', { name: reference }).getByRole('cell', { name: 'INGESCHREVEN' }).count();
|
||||
}, { timeout: 30_000, intervals: [1_000, 2_000, 3_000, 5_000] })
|
||||
.toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user