From aaa7135fb1c8930da5840b48329b116b044998a3 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 11:53:59 +0200 Subject: [PATCH 01/15] test(acl): gateway stores a diploma as an enkelvoudiginformatieobject + relates it (refs #103) RED: StoreDocumentAsync creates the informatieobject in the Documenten API (base64 inhoud, bestandsomvang, definitief) with a Bearer token and a buffered (non-chunked) body and no CRS headers, then relates it to the zaak via zaakinformatieobjecten, and surfaces an OpenZaak rejection. Co-Authored-By: Claude Opus 4.8 (1M context) --- .../acl/Acl.Tests/OpenZaakGatewayTests.cs | 107 ++++++++++++++++++ 1 file changed, 107 insertions(+) diff --git a/services/acl/Acl.Tests/OpenZaakGatewayTests.cs b/services/acl/Acl.Tests/OpenZaakGatewayTests.cs index af568c8..e5974b1 100644 --- a/services/acl/Acl.Tests/OpenZaakGatewayTests.cs +++ b/services/acl/Acl.Tests/OpenZaakGatewayTests.cs @@ -432,4 +432,111 @@ public class OpenZaakGatewayTests b64 = (b64.Length % 4) switch { 2 => b64 + "==", 3 => b64 + "=", _ => b64 }; return Encoding.UTF8.GetString(Convert.FromBase64String(b64)); } + + // --- StoreDocumentAsync (diploma upload / S-10b) --- + + private static readonly Uri Informatieobjecttype = + new("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"); + + private static DocumentRequest SampleDocument(byte[]? inhoud = null) => new( + Bronorganisatie: "517439943", + Informatieobjecttype: Informatieobjecttype, + Vertrouwelijkheidaanduiding: "openbaar", + Zaak: new Uri(ZaakUrl), + Creatiedatum: new DateOnly(2026, 6, 4), + Titel: "Diploma", + Auteur: "zorgprofessional", + Taal: "nld", + Bestandsnaam: "diploma.pdf", + Formaat: "application/pdf", + Inhoud: inhoud ?? [1, 2, 3, 4]); + + // Routes the two document calls: POST /enkelvoudiginformatieobjecten (documenten) then + // POST /zaakinformatieobjecten (zaken). + private static StubHandler DocumentStub(Recorder rec) => new(async req => + { + rec.Requests.Add(req); + rec.ContentLengths.Add(req.Content?.Headers.ContentLength); + rec.Bodies.Add(req.Content is null ? null : await req.Content.ReadAsStringAsync()); + + return req.RequestUri!.ToString().Contains("/enkelvoudiginformatieobjecten") + ? Json(HttpStatusCode.Created, """{"url":"http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc-1"}""") + : Json(HttpStatusCode.Created, """{"url":"http://openzaak/zaken/api/v1/zaakinformatieobjecten/rel-1"}"""); + }); + + [Fact] + public async Task Storing_a_document_creates_the_informatieobject_then_relates_it_to_the_zaak() + { + var rec = new Recorder(); + + var url = await Gateway(DocumentStub(rec)).StoreDocumentAsync(SampleDocument([10, 20, 30])); + + Assert.Equal("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc-1", url.ToString()); + + // 1. Create the enkelvoudiginformatieobject in the Documenten API. + var create = rec.Sent("/enkelvoudiginformatieobjecten"); + Assert.Equal(HttpMethod.Post, create.Request.Method); + Assert.Equal("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten", + create.Request.RequestUri!.ToString()); + Assert.Equal("Bearer", create.Request.Headers.Authorization!.Scheme); + Assert.Contains("\"bronorganisatie\":\"517439943\"", create.Body); + Assert.Contains("\"informatieobjecttype\":\"http://openzaak/catalogi/api/v1/informatieobjecttypen/dip\"", create.Body); + Assert.Contains("\"creatiedatum\":\"2026-06-04\"", create.Body); + Assert.Contains("\"titel\":\"Diploma\"", create.Body); + Assert.Contains("\"auteur\":\"zorgprofessional\"", create.Body); + Assert.Contains("\"taal\":\"nld\"", create.Body); + Assert.Contains("\"bestandsnaam\":\"diploma.pdf\"", create.Body); + Assert.Contains("\"formaat\":\"application/pdf\"", create.Body); + Assert.Contains("\"vertrouwelijkheidaanduiding\":\"openbaar\"", create.Body); + Assert.Contains("\"status\":\"definitief\"", create.Body); + // The file content is base64-encoded into `inhoud`, with its byte length in `bestandsomvang`. + Assert.Contains($"\"inhoud\":\"{Convert.ToBase64String([10, 20, 30])}\"", create.Body); + Assert.Contains("\"bestandsomvang\":3", create.Body); + + // 2. Relate that informatieobject to the zaak (Zaken API — no CRS). + var relate = rec.Sent("/zaakinformatieobjecten"); + Assert.Equal(HttpMethod.Post, relate.Request.Method); + Assert.Equal("http://openzaak/zaken/api/v1/zaakinformatieobjecten", + relate.Request.RequestUri!.ToString()); + Assert.Contains($"\"zaak\":\"{ZaakUrl}\"", relate.Body); + Assert.Contains("\"informatieobject\":\"http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc-1\"", relate.Body); + } + + [Fact] + public async Task Storing_a_document_buffers_the_body_and_sends_no_crs_headers() + { + // uwsgi rejects a chunked body (Content-Length must be present); the Documenten API is not a + // geo API, so no CRS headers (unlike the Zaken zaak-create). + var rec = new Recorder(); + + await Gateway(DocumentStub(rec)).StoreDocumentAsync(SampleDocument()); + + var create = rec.Sent("/enkelvoudiginformatieobjecten"); + Assert.NotNull(create.Length); + Assert.True(create.Length > 0); + Assert.False(create.Request.Headers.Contains("Accept-Crs")); + Assert.False(create.Request.Content!.Headers.Contains("Content-Crs")); + } + + [Fact] + public async Task Storing_a_document_surfaces_an_openzaak_rejection() + { + var handler = new StubHandler(_ => + Task.FromResult(new HttpResponseMessage(HttpStatusCode.BadRequest) + { + Content = new StringContent("""{"detail":"bad"}""", Encoding.UTF8, "application/json"), + })); + + var ex = await Assert.ThrowsAsync( + () => Gateway(handler).StoreDocumentAsync(SampleDocument())); + Assert.Contains("bad", ex.Message); + } + + [Fact] + public async Task Storing_a_document_rejects_a_null_request() + { + var handler = new StubHandler(_ => throw new InvalidOperationException("should not be sent")); + + await Assert.ThrowsAsync(() => Gateway(handler).StoreDocumentAsync(null!)); + } } -- 2.54.0 From dca9455bb5a5a1a841979bbe1ab7681845e4ca22 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 11:57:39 +0200 Subject: [PATCH 02/15] feat(acl): store a diploma in the Documenten API and relate it to the zaak (refs #103) IZaakGateway.StoreDocumentAsync creates an enkelvoudiginformatieobject (base64 inhoud, buffered non-chunked body, no CRS) and relates it via zaakinformatieobjecten; AclService.StoreDiplomaAsync default-fills the ZGW document fields (informatieobjecttype, bronorganisatie, taal nld, creatiedatum); POST /documenten exposes it. Adds the InformatieobjecttypeUrl default (wired in a following infra commit). Co-Authored-By: Claude Opus 4.8 (1M context) --- services/acl/Acl.Api/Program.cs | 11 +++ services/acl/Acl.Application/AclDefaults.cs | 4 ++ services/acl/Acl.Application/AclService.cs | 29 ++++++++ .../acl/Acl.Application/DocumentRequest.cs | 17 +++++ services/acl/Acl.Application/IZaakGateway.cs | 7 ++ .../acl/Acl.Infrastructure/OpenZaakGateway.cs | 71 +++++++++++++++++++ services/acl/Acl.Tests/AclServiceTests.cs | 47 ++++++++++++ 7 files changed, 186 insertions(+) create mode 100644 services/acl/Acl.Application/DocumentRequest.cs diff --git a/services/acl/Acl.Api/Program.cs b/services/acl/Acl.Api/Program.cs index f220cb1..9581455 100644 --- a/services/acl/Acl.Api/Program.cs +++ b/services/acl/Acl.Api/Program.cs @@ -40,6 +40,15 @@ app.MapPost("/zaken/reference", async (ZaakReferenceRequest body, AclService acl return Results.Ok(new { reference }); }); +// Store an uploaded diploma against a zaak (S-10b): the domain sends the file as base64; the ACL +// creates the ZGW enkelvoudiginformatieobject and relates it to the zaak (§8.1). Returns its URL. +app.MapPost("/documenten", async (StoreDocumentRequest body, AclService acl, CancellationToken ct) => +{ + var url = await acl.StoreDiplomaAsync( + new Uri(body.ZaakUrl), Convert.FromBase64String(body.ContentBase64), body.FileName, body.ContentType, ct); + return Results.Ok(new { informatieobjectUrl = url.ToString() }); +}); + app.Run(); public sealed record OpenZaakRequest(string Bsn, string Reference); @@ -48,4 +57,6 @@ public sealed record SetStatusRequest(string ZaakUrl); public sealed record ZaakReferenceRequest(string ZaakUrl); +public sealed record StoreDocumentRequest(string ZaakUrl, string ContentBase64, string FileName, string ContentType); + public partial class Program; diff --git a/services/acl/Acl.Application/AclDefaults.cs b/services/acl/Acl.Application/AclDefaults.cs index 232d3a4..d378c8c 100644 --- a/services/acl/Acl.Application/AclDefaults.cs +++ b/services/acl/Acl.Application/AclDefaults.cs @@ -7,4 +7,8 @@ public sealed class AclDefaults public required string VerantwoordelijkeOrganisatie { get; init; } public required string Vertrouwelijkheidaanduiding { get; init; } public required Uri ZaaktypeUrl { get; init; } + + /// The informatieobjecttype an uploaded diploma is filed under (S-10b). Seeded in the + /// catalogus and injected like . + public required Uri InformatieobjecttypeUrl { get; init; } } diff --git a/services/acl/Acl.Application/AclService.cs b/services/acl/Acl.Application/AclService.cs index a70e7ca..f692041 100644 --- a/services/acl/Acl.Application/AclService.cs +++ b/services/acl/Acl.Application/AclService.cs @@ -37,4 +37,33 @@ public sealed class AclService(IZaakGateway gateway, AclDefaults defaults, ICloc return gateway.GetZaakIdentificatieAsync(zaakUrl, ct); } + + /// + /// Store an uploaded diploma against the zaak (S-10b): default-fill the ZGW-mandatory document + /// fields (informatieobjecttype, bronorganisatie, vertrouwelijkheidaanduiding, taal, creatiedatum) + /// and hand the file to the gateway, which creates the informatieobject and relates it to the zaak. + /// The domain supplies only the zaak, the bytes, and the file's name/type (§8.1). + /// + public Task StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default) + { + ArgumentNullException.ThrowIfNull(zaakUrl); + ArgumentNullException.ThrowIfNull(content); + ArgumentException.ThrowIfNullOrWhiteSpace(fileName); + ArgumentException.ThrowIfNullOrWhiteSpace(contentType); + + var request = new DocumentRequest( + defaults.Bronorganisatie, + defaults.InformatieobjecttypeUrl, + defaults.Vertrouwelijkheidaanduiding, + zaakUrl, + clock.Today, + Titel: "Diploma", + Auteur: "zorgprofessional", + Taal: "nld", + Bestandsnaam: fileName, + Formaat: contentType, + Inhoud: content); + + return gateway.StoreDocumentAsync(request, ct); + } } diff --git a/services/acl/Acl.Application/DocumentRequest.cs b/services/acl/Acl.Application/DocumentRequest.cs new file mode 100644 index 0000000..885148f --- /dev/null +++ b/services/acl/Acl.Application/DocumentRequest.cs @@ -0,0 +1,17 @@ +namespace Acl.Application; + +/// The fully default-filled diploma document the gateway will create in the ZGW Documenten +/// API and relate to the zaak (S-10b). is the raw file content; the gateway +/// base64-encodes it into the ZGW inhoud field. +public sealed record DocumentRequest( + string Bronorganisatie, + Uri Informatieobjecttype, + string Vertrouwelijkheidaanduiding, + Uri Zaak, + DateOnly Creatiedatum, + string Titel, + string Auteur, + string Taal, + string Bestandsnaam, + string Formaat, + byte[] Inhoud); diff --git a/services/acl/Acl.Application/IZaakGateway.cs b/services/acl/Acl.Application/IZaakGateway.cs index 583baf5..73903f0 100644 --- a/services/acl/Acl.Application/IZaakGateway.cs +++ b/services/acl/Acl.Application/IZaakGateway.cs @@ -16,4 +16,11 @@ public interface IZaakGateway /// Read the zaak's identificatie — the public-safe reference the register shows. /// The Event Subscriber calls this through the ACL rather than reading ZGW itself (§8.1, #78). Task GetZaakIdentificatieAsync(Uri zaakUrl, CancellationToken ct = default); + + /// + /// Store a diploma document (S-10b): create an enkelvoudiginformatieobject in the ZGW + /// Documenten API and relate it to the zaak via a zaakinformatieobject. Returns the URL of + /// the created informatieobject. + /// + Task StoreDocumentAsync(DocumentRequest request, CancellationToken ct = default); } diff --git a/services/acl/Acl.Infrastructure/OpenZaakGateway.cs b/services/acl/Acl.Infrastructure/OpenZaakGateway.cs index 92d85ea..cee0c9a 100644 --- a/services/acl/Acl.Infrastructure/OpenZaakGateway.cs +++ b/services/acl/Acl.Infrastructure/OpenZaakGateway.cs @@ -80,6 +80,36 @@ public sealed class OpenZaakGateway(HttpClient http, OpenZaakOptions options) : return zaak.Identificatie; } + public async Task StoreDocumentAsync(DocumentRequest request, CancellationToken ct = default) + { + ArgumentNullException.ThrowIfNull(request); + + // 1. Create the enkelvoudiginformatieobject in the Documenten API (not a geo API — no CRS). + var created = await PostForUrlAsync( + "/documenten/api/v1/enkelvoudiginformatieobjecten", + new EnkelvoudigInformatieobjectDto( + request.Bronorganisatie, + request.Creatiedatum.ToString("yyyy-MM-dd"), + request.Titel, + request.Auteur, + request.Taal, + request.Informatieobjecttype.ToString(), + Convert.ToBase64String(request.Inhoud), + request.Bestandsnaam, + request.Inhoud.Length, + request.Vertrouwelijkheidaanduiding, + request.Formaat, + "definitief"), + "Creating the informatieobject", ct); + + // 2. Relate it to the zaak (Zaken API — no CRS). + await PostAsync("/zaken/api/v1/zaakinformatieobjecten", + new ZaakInformatieobjectDto(request.Zaak.ToString(), created.ToString()), + "Relating the informatieobject to the zaak", ct); + + return created; + } + // POSTs a non-geo ZGW resource (resultaat/status — no CRS headers). Buffers the body so uwsgi gets // a Content-Length instead of a chunked body (as with zaak-create). private async Task PostAsync(string path, object dto, string action, CancellationToken ct) @@ -96,6 +126,26 @@ public sealed class OpenZaakGateway(HttpClient http, OpenZaakOptions options) : await EnsureSuccessAsync(response, action, ct); } + // POSTs a non-geo ZGW resource and returns the created resource's URL (as PostAsync, but reads back + // the `url` of the created object). Buffers the body so uwsgi gets a Content-Length. + private async Task PostForUrlAsync(string path, object dto, string action, CancellationToken ct) + { + using var message = new HttpRequestMessage(HttpMethod.Post, new Uri(options.BaseUrl, path)) + { + Content = JsonContent.Create(dto), + }; + message.Headers.Authorization = + new AuthenticationHeaderValue("Bearer", ZgwToken.Mint(options.ClientId, options.Secret)); + await message.Content.LoadIntoBufferAsync(ct); + + using var response = await http.SendAsync(message, ct); + await EnsureSuccessAsync(response, action, ct); + + var created = await response.Content.ReadFromJsonAsync(ct) + ?? throw new InvalidOperationException($"OpenZaak returned an empty response for {action}"); + return new Uri(created.Url); + } + // EnsureSuccessStatusCode discards the response body; ZGW returns a JSON problem detail on 400 that // is essential for diagnosing a rejected request, so surface it in the exception. private static async Task EnsureSuccessAsync(HttpResponseMessage response, string action, CancellationToken ct) @@ -182,4 +232,25 @@ public sealed class OpenZaakGateway(HttpClient http, OpenZaakOptions options) : private sealed record ResultaattypeDto( [property: JsonPropertyName("url")] string Url); + + private sealed record CreatedDto( + [property: JsonPropertyName("url")] string Url); + + private sealed record EnkelvoudigInformatieobjectDto( + [property: JsonPropertyName("bronorganisatie")] string Bronorganisatie, + [property: JsonPropertyName("creatiedatum")] string Creatiedatum, + [property: JsonPropertyName("titel")] string Titel, + [property: JsonPropertyName("auteur")] string Auteur, + [property: JsonPropertyName("taal")] string Taal, + [property: JsonPropertyName("informatieobjecttype")] string Informatieobjecttype, + [property: JsonPropertyName("inhoud")] string Inhoud, + [property: JsonPropertyName("bestandsnaam")] string Bestandsnaam, + [property: JsonPropertyName("bestandsomvang")] int Bestandsomvang, + [property: JsonPropertyName("vertrouwelijkheidaanduiding")] string Vertrouwelijkheidaanduiding, + [property: JsonPropertyName("formaat")] string Formaat, + [property: JsonPropertyName("status")] string Status); + + private sealed record ZaakInformatieobjectDto( + [property: JsonPropertyName("zaak")] string Zaak, + [property: JsonPropertyName("informatieobject")] string Informatieobject); } diff --git a/services/acl/Acl.Tests/AclServiceTests.cs b/services/acl/Acl.Tests/AclServiceTests.cs index 2e74c8f..fe2a81a 100644 --- a/services/acl/Acl.Tests/AclServiceTests.cs +++ b/services/acl/Acl.Tests/AclServiceTests.cs @@ -30,6 +30,15 @@ public class AclServiceTests ReadReferenceFor = zaakUrl; return Task.FromResult("REG-FROM-ZAAK"); } + + public DocumentRequest? StoredDocument; + public Uri DocumentResult { get; } = new("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc-1"); + + public Task StoreDocumentAsync(DocumentRequest request, CancellationToken ct = default) + { + StoredDocument = request; + return Task.FromResult(DocumentResult); + } } private static AclDefaults Defaults() => new() @@ -38,6 +47,7 @@ public class AclServiceTests VerantwoordelijkeOrganisatie = "517439943", Vertrouwelijkheidaanduiding = "openbaar", ZaaktypeUrl = new("http://openzaak/catalogi/api/v1/zaaktypen/big"), + InformatieobjecttypeUrl = new("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"), }; private sealed class FixedClock(DateOnly today) : IClock @@ -55,6 +65,7 @@ public class AclServiceTests VerantwoordelijkeOrganisatie = "517439943", Vertrouwelijkheidaanduiding = "openbaar", ZaaktypeUrl = new("http://openzaak/catalogi/api/v1/zaaktypen/big"), + InformatieobjecttypeUrl = new("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"), }; var service = new AclService(gateway, defaults, new FixedClock(new DateOnly(2026, 6, 4))); @@ -81,6 +92,7 @@ public class AclServiceTests VerantwoordelijkeOrganisatie = "517439943", Vertrouwelijkheidaanduiding = "openbaar", ZaaktypeUrl = new("http://openzaak/catalogi/api/v1/zaaktypen/big"), + InformatieobjecttypeUrl = new("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"), }; var service = new AclService(gateway, defaults, new FixedClock(new DateOnly(2026, 6, 4))); @@ -114,6 +126,41 @@ public class AclServiceTests Assert.Null(gateway.Approved); } + [Fact] + public async Task Storing_a_diploma_default_fills_the_document_fields_and_returns_its_url() + { + var gateway = new FakeGateway(); + var defaults = Defaults(); + var service = new AclService(gateway, defaults, new FixedClock(new DateOnly(2026, 6, 4))); + var zaak = new Uri("http://openzaak/zaken/api/v1/zaken/abc"); + + var url = await service.StoreDiplomaAsync(zaak, [1, 2, 3], "diploma.pdf", "application/pdf"); + + Assert.Equal(gateway.DocumentResult, url); + var req = gateway.StoredDocument!; + Assert.Equal(zaak, req.Zaak); + Assert.Equal(defaults.InformatieobjecttypeUrl, req.Informatieobjecttype); + Assert.Equal("517439943", req.Bronorganisatie); + Assert.Equal("openbaar", req.Vertrouwelijkheidaanduiding); + Assert.Equal(new DateOnly(2026, 6, 4), req.Creatiedatum); + Assert.Equal("nld", req.Taal); + Assert.Equal("diploma.pdf", req.Bestandsnaam); + Assert.Equal("application/pdf", req.Formaat); + Assert.Equal(new byte[] { 1, 2, 3 }, req.Inhoud); + } + + [Fact] + public async Task Storing_a_diploma_rejects_null_or_blank_arguments() + { + var service = new AclService(new FakeGateway(), Defaults(), new FixedClock(new DateOnly(2026, 6, 4))); + var zaak = new Uri("http://openzaak/zaken/api/v1/zaken/abc"); + + await Assert.ThrowsAsync(() => service.StoreDiplomaAsync(null!, [1], "d.pdf", "application/pdf")); + await Assert.ThrowsAsync(() => service.StoreDiplomaAsync(zaak, null!, "d.pdf", "application/pdf")); + await Assert.ThrowsAnyAsync(() => service.StoreDiplomaAsync(zaak, [1], " ", "application/pdf")); + await Assert.ThrowsAnyAsync(() => service.StoreDiplomaAsync(zaak, [1], "d.pdf", " ")); + } + [Fact] public async Task Reading_a_zaak_reference_returns_the_zaaks_identificatie() { -- 2.54.0 From 4b4b58b486beb005d1234b67b462e15ada69c6a6 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 12:00:48 +0200 Subject: [PATCH 03/15] feat(infra): seed the Diploma informatieobjecttype + wire the ACL default (refs #103) seed_catalogus.py (OZ_PUBLISH) creates a "Diploma" informatieobjecttype, relates it to the zaaktype (zaaktype-informatieobjecttypen, while both concept), publishes both, and prints INFORMATIEOBJECTTYPE_URL. verify-domain captures it and recreates the ACL with Acl__Defaults__InformatieobjecttypeUrl (placeholder default in compose otherwise). Co-Authored-By: Claude Opus 4.8 (1M context) --- infra/docker-compose.yml | 3 ++ infra/openzaak/seed_catalogus.py | 62 ++++++++++++++++++++++++++++++++ infra/run-domain-check.sh | 11 ++++-- 3 files changed, 73 insertions(+), 3 deletions(-) diff --git a/infra/docker-compose.yml b/infra/docker-compose.yml index 2529274..ce76cdf 100644 --- a/infra/docker-compose.yml +++ b/infra/docker-compose.yml @@ -306,6 +306,9 @@ services: Acl__Defaults__Vertrouwelijkheidaanduiding: openbaar # Override with the real zaaktype URL after running seed_catalogus.py. Acl__Defaults__ZaaktypeUrl: ${ACL_ZAAKTYPE_URL:-http://openzaak:8000/catalogi/api/v1/zaaktypen/00000000-0000-0000-0000-000000000000} + # The informatieobjecttype a diploma is filed under (S-10b). Placeholder until seed_catalogus.py + # (OZ_PUBLISH=1) reports the real URL, which verify-domain injects like the zaaktype URL. + Acl__Defaults__InformatieobjecttypeUrl: ${ACL_INFORMATIEOBJECTTYPE_URL:-http://openzaak:8000/catalogi/api/v1/informatieobjecttypen/00000000-0000-0000-0000-000000000000} ports: - "8100:8080" healthcheck: diff --git a/infra/openzaak/seed_catalogus.py b/infra/openzaak/seed_catalogus.py index 5dc15a8..ed4ad67 100644 --- a/infra/openzaak/seed_catalogus.py +++ b/infra/openzaak/seed_catalogus.py @@ -124,6 +124,58 @@ def publish_zaaktype(zt): print("skip publish (already published)") +def seed_informatieobjecttype(cat, zt): + """Create the "Diploma" informatieobjecttype and relate it to the zaaktype (both idempotent). + + A diploma uploaded in S-10b is filed under this informatieobjecttype; OpenZaak only accepts a + document (and its zaak relation) once the informatieobjecttype is published AND allowed for the + zaak's zaaktype (a zaaktype-informatieobjecttype relation). Both the relation and this call must run + while the zaaktype is still a concept, so seed this *before* publishing the zaaktype. Returns the + informatieobjecttype dict. + """ + iots = [i for i in find(f"/informatieobjecttypen?catalogus={cat['url']}&status=alles") + if i.get("omschrijving") == "Diploma"] + if iots: + iot = iots[0] + print(f"skip informatieobjecttype Diploma ({iot['url']}) concept={iot.get('concept')}") + else: + st, iot = api("POST", "/informatieobjecttypen", { + "catalogus": cat["url"], + "omschrijving": "Diploma", + "vertrouwelijkheidaanduiding": "openbaar", + "informatieobjectcategorie": "diploma", + "beginGeldigheid": "2026-01-01", + }) + if st != 201: + sys.exit(f"create informatieobjecttype -> {st}: {json.dumps(iot, indent=2)}") + print(f"create informatieobjecttype Diploma ({iot['url']})") + + # Relate it to the zaaktype (must be done while both are concept). + relations = find(f"/zaaktype-informatieobjecttypen?zaaktype={zt['url']}&status=alles") + if any(r.get("informatieobjecttype") == iot["url"] for r in relations): + print("skip zaaktype-informatieobjecttype Diploma") + else: + st, body = api("POST", "/zaaktype-informatieobjecttypen", { + "zaaktype": zt["url"], "informatieobjecttype": iot["url"], + "volgnummer": 1, "richting": "inkomend"}) + if st != 201: + sys.exit(f"relate zaaktype-informatieobjecttype -> {st}: {json.dumps(body, indent=2)}") + print("create zaaktype-informatieobjecttype Diploma") + + return iot + + +def publish_informatieobjecttype(iot): + """Publish the informatieobjecttype (idempotent) so documents may reference it.""" + if iot.get("concept", True): + st, body = api("POST", f"{iot['url']}/publish") + if st != 200: + sys.exit(f"publish informatieobjecttype -> {st}: {json.dumps(body, indent=2)}") + print(f"publish informatieobjecttype Diploma ({iot['url']})") + else: + print("skip publish informatieobjecttype (already published)") + + def main(): # 1. Catalogus existing = [c for c in find(f"/catalogussen?domein=BIG") if c.get("domein") == "BIG"] @@ -198,10 +250,16 @@ def main(): # schema-mandatory" zaaktype S-01 asks for (ADR-0002). Set OZ_PUBLISH=1 to add # those relations and publish — needed so a real zaak POST is accepted, which # the ACL integration test (S-04a, #46) exercises. See ADR-0006. + iot = None if PUBLISH: # Re-fetch: the bsn-eigenschap branch above may hold a stale concept flag. zt = next(z for z in find(f"/zaaktypen?catalogus={cat['url']}&status=alles") if z.get("identificatie") == "BIG-REGISTRATIE") + # Seed + relate the Diploma informatieobjecttype (S-10b) while the zaaktype is still concept, + # then publish both. Publish the informatieobjecttype before the zaaktype so the zaaktype's + # relations reference a published type. + iot = seed_informatieobjecttype(cat, zt) + publish_informatieobjecttype(iot) publish_zaaktype(zt) # 5. Verify the JWT client can list the zaaktype (concepts included). @@ -214,6 +272,10 @@ def main(): # zaaktype URL to configure the ACL's default-fill (ADR-0003/0009). zt_url = next(z["url"] for z in zaaktypen if z.get("identificatie") == "BIG-REGISTRATIE") print(f"ZAAKTYPE_URL {zt_url}") + # Machine-readable informatieobjecttype URL (S-10b) so callers can configure the ACL's document + # default-fill. Only emitted when publishing — a concept informatieobjecttype can't back a document. + if iot is not None: + print(f"INFORMATIEOBJECTTYPE_URL {iot['url']}") print(f"OK — BIG catalogus seeded (BIG-REGISTRATIE {state} + bsn eigenschap)") diff --git a/infra/run-domain-check.sh b/infra/run-domain-check.sh index 7294c54..359f65c 100755 --- a/infra/run-domain-check.sh +++ b/infra/run-domain-check.sh @@ -33,13 +33,18 @@ echo ">> openzaak=$oz_ip domain=$dom_ip network=$net" echo ">> seeding a published BIG zaaktype (idempotent) and capturing its URL" sid="$(docker create --network "$net" -e "OZ_BASE=$oz_base" -e OZ_PUBLISH=1 python:3-slim python /seed.py)" docker cp "$here/openzaak/seed_catalogus.py" "$sid:/seed.py" >/dev/null -zt_url="$(docker start -a "$sid" | sed -n 's/^ZAAKTYPE_URL //p' | head -1)" +seed_out="$(docker start -a "$sid")" +zt_url="$(printf '%s\n' "$seed_out" | sed -n 's/^ZAAKTYPE_URL //p' | head -1)" +iot_url="$(printf '%s\n' "$seed_out" | sed -n 's/^INFORMATIEOBJECTTYPE_URL //p' | head -1)" docker rm -f "$sid" >/dev/null [ -n "$zt_url" ] || { echo "ERROR: seed did not report a ZAAKTYPE_URL" >&2; exit 1; } +[ -n "$iot_url" ] || { echo "ERROR: seed did not report an INFORMATIEOBJECTTYPE_URL" >&2; exit 1; } echo ">> zaaktype: $zt_url" +echo ">> informatieobjecttype: $iot_url" -echo ">> recreating the acl service pointed at the seeded zaaktype (host-consistent)" -ACL_ZAAKTYPE_URL="$zt_url" ACL_OPENZAAK_BASEURL="$oz_base/" docker compose -f "$compose" up -d acl +echo ">> recreating the acl service pointed at the seeded zaaktype + informatieobjecttype (host-consistent)" +ACL_ZAAKTYPE_URL="$zt_url" ACL_INFORMATIEOBJECTTYPE_URL="$iot_url" ACL_OPENZAAK_BASEURL="$oz_base/" \ + docker compose -f "$compose" up -d acl WAIT_TIMEOUT="${WAIT_TIMEOUT:-120}" bash "$here/wait-healthy.sh" acl echo ">> submitting a registration to the domain" -- 2.54.0 From ecad42873cee5711b036e660e72e10162bdac220 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 12:02:32 +0200 Subject: [PATCH 04/15] test(domain): providing documents stores the diploma via the ACL then completes the wait (refs #103) RED: ProvideDocuments now carries the file bytes, stores them against the zaak via IAclClient before completing the WachtOpDocumenten wait; owner-scoped; best-effort when no zaak/process exists yet. Co-Authored-By: Claude Opus 4.8 (1M context) --- services/domain/Big.Tests/Fakes.cs | 9 ++++ .../domain/Big.Tests/ProvideDocumentsTests.cs | 47 ++++++++++++------- 2 files changed, 38 insertions(+), 18 deletions(-) diff --git a/services/domain/Big.Tests/Fakes.cs b/services/domain/Big.Tests/Fakes.cs index f183fda..ef539ef 100644 --- a/services/domain/Big.Tests/Fakes.cs +++ b/services/domain/Big.Tests/Fakes.cs @@ -110,4 +110,13 @@ internal sealed class FakeAclClient(Uri? zaakUrl = null) : IAclClient ApprovedZaakUrl = zaakUrl; return Task.CompletedTask; } + + public (Uri ZaakUrl, byte[] Content, string FileName, string ContentType)? StoredDiploma { get; private set; } + public static readonly Uri DefaultDocumentUrl = new("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/doc"); + + public Task StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default) + { + StoredDiploma = (zaakUrl, content, fileName, contentType); + return Task.FromResult(DefaultDocumentUrl); + } } diff --git a/services/domain/Big.Tests/ProvideDocumentsTests.cs b/services/domain/Big.Tests/ProvideDocumentsTests.cs index 308d863..ed956e6 100644 --- a/services/domain/Big.Tests/ProvideDocumentsTests.cs +++ b/services/domain/Big.Tests/ProvideDocumentsTests.cs @@ -3,52 +3,60 @@ using Big.Domain; namespace Big.Tests; -// S-10a (#102): the "documents received" use case. A zorgprofessional supplies the documents their -// registration is waiting for; the handler completes the WachtOpDocumenten task via the Workflow Client -// so the process leaves the 30-day wait and continues to beoordeling. Owner-scoped by the caller's bsn, -// like WithdrawRegistration. (The real file upload + ZGW storage is S-10b; this is the trigger path.) +// S-10a/S-10b (#102/#103): the "documents received" use case. A zorgprofessional supplies the diploma +// their registration is waiting for; the handler stores it in ZGW via the ACL and completes the +// WachtOpDocumenten task via the Workflow Client so the process continues to beoordeling. Owner-scoped +// by the caller's bsn, like WithdrawRegistration. public class ProvideDocumentsTests { private const string Bsn = "123456782"; + private static readonly Uri Zaak = new("http://openzaak/zaken/api/v1/zaken/abc"); private static Registration Submitted(string processInstanceId = "proc-1") { var registration = Registration.Submit(Bsn); registration.RecordProcessStarted(processInstanceId); + registration.AttachZaak(Zaak); return registration; } - private static ProvideDocumentsCommand Command(RegistrationId id, string bsn = Bsn) => new(id, bsn); + private static ProvideDocumentsCommand Command(RegistrationId id, string bsn = Bsn) => + new(id, bsn, [1, 2, 3], "diploma.pdf", "application/pdf"); [Fact] - public async Task Providing_documents_completes_the_document_wait() + public async Task Providing_documents_stores_the_diploma_and_completes_the_wait() { var store = new FakeRegistrationStore(); var registration = Submitted("proc-42"); store.Seed(registration); var workflow = new FakeWorkflowClient(); - var handler = new ProvideDocuments(store, workflow); + var acl = new FakeAclClient(); + var handler = new ProvideDocuments(store, workflow, acl); var outcome = await handler.HandleAsync(Command(registration.Id)); Assert.Equal(ProvideDocumentsOutcome.Accepted, outcome); + // Stored against the registration's zaak, carrying the uploaded bytes + file metadata. + Assert.Equal((Zaak, new byte[] { 1, 2, 3 }, "diploma.pdf", "application/pdf"), acl.StoredDiploma); + // …and the wait is completed so beoordeling can proceed. Assert.Equal("proc-42", workflow.CompletedDocumentWaitFor); } [Fact] public async Task A_different_bsn_cannot_provide_documents() { - // Owner-scoping: only the registration's own bsn may supply its documents. Another bsn is told - // NotFound (existence not revealed) and the wait is not completed. + // Owner-scoping: another bsn is told NotFound; nothing is stored or completed. var store = new FakeRegistrationStore(); var registration = Submitted(); store.Seed(registration); var workflow = new FakeWorkflowClient(); - var handler = new ProvideDocuments(store, workflow); + var acl = new FakeAclClient(); + var handler = new ProvideDocuments(store, workflow, acl); var outcome = await handler.HandleAsync(Command(registration.Id, bsn: "999999990")); Assert.Equal(ProvideDocumentsOutcome.NotFound, outcome); + Assert.Null(acl.StoredDiploma); Assert.Null(workflow.CompletedDocumentWaitFor); } @@ -56,30 +64,33 @@ public class ProvideDocumentsTests public async Task Providing_for_an_unknown_registration_is_not_found() { var store = new FakeRegistrationStore(); - var handler = new ProvideDocuments(store, new FakeWorkflowClient()); + var handler = new ProvideDocuments(store, new FakeWorkflowClient(), new FakeAclClient()); Assert.Equal(ProvideDocumentsOutcome.NotFound, await handler.HandleAsync(Command(RegistrationId.New()))); } [Fact] - public async Task Providing_before_a_process_started_is_accepted_without_calling_the_workflow() + public async Task Providing_before_a_zaak_is_opened_does_not_store_but_still_completes_the_wait() { - // No process yet → no wait task to complete; the request still stands (best-effort, mirroring - // WithdrawRegistration) and the Workflow Client is not called. + // No zaak yet → nothing to file the document against, but the request still stands (best-effort, + // mirroring WithdrawRegistration). The wait is completed if a process is running. var store = new FakeRegistrationStore(); - var registration = Registration.Submit(Bsn); // no RecordProcessStarted + var registration = Registration.Submit(Bsn); + registration.RecordProcessStarted("proc-9"); // process started, but no zaak attached store.Seed(registration); var workflow = new FakeWorkflowClient(); - var handler = new ProvideDocuments(store, workflow); + var acl = new FakeAclClient(); + var handler = new ProvideDocuments(store, workflow, acl); var outcome = await handler.HandleAsync(Command(registration.Id)); Assert.Equal(ProvideDocumentsOutcome.Accepted, outcome); - Assert.Null(workflow.CompletedDocumentWaitFor); + Assert.Null(acl.StoredDiploma); + Assert.Equal("proc-9", workflow.CompletedDocumentWaitFor); } [Fact] public async Task Rejects_a_null_command() => await Assert.ThrowsAsync(() => - new ProvideDocuments(new FakeRegistrationStore(), new FakeWorkflowClient()).HandleAsync(null!)); + new ProvideDocuments(new FakeRegistrationStore(), new FakeWorkflowClient(), new FakeAclClient()).HandleAsync(null!)); } -- 2.54.0 From 3c344caa2986ef438ebd14a321149d98b9a695bd Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 12:05:40 +0200 Subject: [PATCH 05/15] feat(domain): ProvideDocuments stores the diploma via the ACL then completes the wait (refs #103) IAclClient.StoreDiplomaAsync + AclHttpClient (base64 JSON to the ACL /documenten endpoint). ProvideDocuments stores the uploaded bytes against the zaak (when opened) before completing WachtOpDocumenten; the domain endpoint accepts the file base64-encoded. Co-Authored-By: Claude Opus 4.8 (1M context) --- services/domain/Big.Api/Program.cs | 13 +++++++-- services/domain/Big.Application/Ports.cs | 7 +++++ .../Big.Application/ProvideDocuments.cs | 29 ++++++++++++------- .../Big.Infrastructure/AclHttpClient.cs | 26 +++++++++++++++++ tests/acceptance/Steps/EenZaakOpenenSteps.cs | 1 + .../acceptance/Support/InMemoryDomainPorts.cs | 8 +++++ .../acceptance/Support/InMemoryZaakGateway.cs | 3 ++ 7 files changed, 74 insertions(+), 13 deletions(-) diff --git a/services/domain/Big.Api/Program.cs b/services/domain/Big.Api/Program.cs index c78e79b..56d6791 100644 --- a/services/domain/Big.Api/Program.cs +++ b/services/domain/Big.Api/Program.cs @@ -120,8 +120,17 @@ app.MapPost("/registrations/{id}/documents", async (string id, ProvideDocumentsR if (string.IsNullOrWhiteSpace(body?.Bsn)) return Results.BadRequest(new { error = "A bsn is required to provide documents." }); + if (string.IsNullOrWhiteSpace(body.ContentBase64)) + return Results.BadRequest(new { error = "A document is required." }); - var outcome = await provide.HandleAsync(new ProvideDocumentsCommand(new RegistrationId(guid), body.Bsn), ct); + byte[] content; + try { content = Convert.FromBase64String(body.ContentBase64); } + catch (FormatException) { return Results.BadRequest(new { error = "The document content is not valid base64." }); } + + var command = new ProvideDocumentsCommand( + new RegistrationId(guid), body.Bsn, content, + body.FileName ?? "diploma.pdf", body.ContentType ?? "application/pdf"); + var outcome = await provide.HandleAsync(command, ct); return outcome == ProvideDocumentsOutcome.Accepted ? Results.NoContent() : Results.NotFound(); }); @@ -152,7 +161,7 @@ public sealed record DecideRequest(string Besluit); public sealed record WithdrawRequest(string Bsn); -public sealed record ProvideDocumentsRequest(string Bsn); +public sealed record ProvideDocumentsRequest(string Bsn, string ContentBase64, string? FileName = null, string? ContentType = null); public sealed record RegistrationResponse(string RegistrationId, string Status, string? ZaakUrl); diff --git a/services/domain/Big.Application/Ports.cs b/services/domain/Big.Application/Ports.cs index af12888..9d2c5e7 100644 --- a/services/domain/Big.Application/Ports.cs +++ b/services/domain/Big.Application/Ports.cs @@ -52,6 +52,13 @@ public interface IAclClient /// the zaak's final status — which OpenZaak notifies over NRC; the domain never names statustypen. /// Task ApproveZaakAsync(Uri zaakUrl, CancellationToken ct = default); + + /// + /// Store an uploaded diploma against the zaak (S-10b). The domain hands over the zaak, the raw file + /// bytes, and the file's name/type; the ACL creates the ZGW informatieobject and relates it to the + /// zaak (§8.1). Returns the stored document's URL. + /// + Task StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default); } /// diff --git a/services/domain/Big.Application/ProvideDocuments.cs b/services/domain/Big.Application/ProvideDocuments.cs index c5cdcce..59d997f 100644 --- a/services/domain/Big.Application/ProvideDocuments.cs +++ b/services/domain/Big.Application/ProvideDocuments.cs @@ -2,10 +2,12 @@ using Big.Domain; namespace Big.Application; -/// A zorgprofessional's signal that they have supplied the documents their registration is -/// waiting for ("documenten aanleveren"). is the authenticated caller (from the -/// DigiD token, forwarded by the BFF): only the registration's own bsn may provide its documents. -public sealed record ProvideDocumentsCommand(RegistrationId RegistrationId, string Bsn); +/// A zorgprofessional's upload of the diploma their registration is waiting for ("documenten +/// aanleveren"). is the authenticated caller (from the DigiD token, forwarded by +/// the BFF): only the registration's own bsn may provide its documents. is +/// the raw file, with its and . +public sealed record ProvideDocumentsCommand( + RegistrationId RegistrationId, string Bsn, byte[] Content, string FileName, string ContentType); /// The outcome of a provide-documents request. public enum ProvideDocumentsOutcome @@ -19,14 +21,14 @@ public enum ProvideDocumentsOutcome } /// -/// The provide-documents use case (S-10a): a zorgprofessional supplies the documents their registration -/// is parked waiting for, completing the WachtOpDocumenten task so the registratie process leaves the -/// 30-day wait and continues to beoordeling (ADR-0017). Owner-scoped by bsn. Completing the wait is -/// best-effort: if the registration never started a process (or already left the wait), the request -/// still stands, mirroring how cancels best-effort. The actual file -/// upload and its ZGW storage via the ACL is S-10b; this is the trigger that unblocks the process. +/// The provide-documents use case (S-10a/S-10b): a zorgprofessional uploads the diploma their +/// registration is parked waiting for. The document is stored in ZGW via the ACL (§8.1), then the +/// WachtOpDocumenten task is completed so the registratie process leaves the 30-day wait and continues +/// to beoordeling (ADR-0017). Owner-scoped by bsn. Both steps are best-effort about missing preconditions +/// (mirroring ): storage needs an opened zaak, and completion needs a +/// running process — a request that arrives before either still stands, storing/completing what it can. /// -public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient workflow) +public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient workflow, IAclClient acl) { public async Task HandleAsync(ProvideDocumentsCommand command, CancellationToken ct = default) { @@ -38,6 +40,11 @@ public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient w if (registration is null || registration.Bsn != command.Bsn) return ProvideDocumentsOutcome.NotFound; + // Store the diploma against the zaak (once it is opened) — the ACL is the only ZGW caller (§8.1). + if (registration.ZaakUrl is not null) + await acl.StoreDiplomaAsync( + registration.ZaakUrl, command.Content, command.FileName, command.ContentType, ct); + // Complete the document wait (if a process is running) so beoordeling can proceed. if (registration.ProcessInstanceId is not null) await workflow.CompleteDocumentWaitAsync(registration.ProcessInstanceId, ct); diff --git a/services/domain/Big.Infrastructure/AclHttpClient.cs b/services/domain/Big.Infrastructure/AclHttpClient.cs index 217f9dc..22c235c 100644 --- a/services/domain/Big.Infrastructure/AclHttpClient.cs +++ b/services/domain/Big.Infrastructure/AclHttpClient.cs @@ -31,6 +31,23 @@ public sealed class AclHttpClient(HttpClient http, AclOptions options) : IAclCli response.EnsureSuccessStatusCode(); } + public async Task StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default) + { + ArgumentNullException.ThrowIfNull(zaakUrl); + ArgumentNullException.ThrowIfNull(content); + + // The file crosses this boundary base64-encoded in JSON — the domain and ACL contracts are + // JSON, and a diploma is small (S-10b, ADR). The ACL turns it into a ZGW informatieobject. + using var response = await http.PostAsJsonAsync( + new Uri(options.BaseUrl, "documenten"), + new StoreDocumentRequest(zaakUrl.ToString(), Convert.ToBase64String(content), fileName, contentType), ct); + response.EnsureSuccessStatusCode(); + + var stored = await response.Content.ReadFromJsonAsync(ct) + ?? throw new InvalidOperationException("The ACL returned an empty document response."); + return new Uri(stored.InformatieobjectUrl); + } + private sealed record OpenZaakRequest( [property: JsonPropertyName("bsn")] string Bsn, [property: JsonPropertyName("reference")] string Reference); @@ -38,4 +55,13 @@ public sealed class AclHttpClient(HttpClient http, AclOptions options) : IAclCli private sealed record OpenZaakResponse([property: JsonPropertyName("zaakUrl")] string ZaakUrl); private sealed record SetStatusRequest([property: JsonPropertyName("zaakUrl")] string ZaakUrl); + + private sealed record StoreDocumentRequest( + [property: JsonPropertyName("zaakUrl")] string ZaakUrl, + [property: JsonPropertyName("contentBase64")] string ContentBase64, + [property: JsonPropertyName("fileName")] string FileName, + [property: JsonPropertyName("contentType")] string ContentType); + + private sealed record StoreDocumentResponse( + [property: JsonPropertyName("informatieobjectUrl")] string InformatieobjectUrl); } diff --git a/tests/acceptance/Steps/EenZaakOpenenSteps.cs b/tests/acceptance/Steps/EenZaakOpenenSteps.cs index 04780e1..6dd2fc4 100644 --- a/tests/acceptance/Steps/EenZaakOpenenSteps.cs +++ b/tests/acceptance/Steps/EenZaakOpenenSteps.cs @@ -30,6 +30,7 @@ public sealed class EenZaakOpenenSteps VerantwoordelijkeOrganisatie = values["verantwoordelijkeOrganisatie"], Vertrouwelijkheidaanduiding = values["vertrouwelijkheidaanduiding"], ZaaktypeUrl = new Uri(values["zaaktype"]), + InformatieobjecttypeUrl = new Uri("http://openzaak/catalogi/api/v1/informatieobjecttypen/dip"), }; } diff --git a/tests/acceptance/Support/InMemoryDomainPorts.cs b/tests/acceptance/Support/InMemoryDomainPorts.cs index f480320..c63b05e 100644 --- a/tests/acceptance/Support/InMemoryDomainPorts.cs +++ b/tests/acceptance/Support/InMemoryDomainPorts.cs @@ -59,6 +59,14 @@ public sealed class InMemoryAclClient : IAclClient ApprovedZaakUrl = zaakUrl; return Task.CompletedTask; } + + public (Uri ZaakUrl, string FileName)? StoredDiploma { get; private set; } + + public Task StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default) + { + StoredDiploma = (zaakUrl, fileName); + return Task.FromResult(new Uri("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/acc-doc")); + } } /// An in-memory user-task client for the beoordeling acceptance scenario: it holds one open diff --git a/tests/acceptance/Support/InMemoryZaakGateway.cs b/tests/acceptance/Support/InMemoryZaakGateway.cs index 09c6414..e9e205d 100644 --- a/tests/acceptance/Support/InMemoryZaakGateway.cs +++ b/tests/acceptance/Support/InMemoryZaakGateway.cs @@ -27,4 +27,7 @@ public sealed class InMemoryZaakGateway : IZaakGateway public Task GetZaakIdentificatieAsync(Uri zaakUrl, CancellationToken ct = default) => Task.FromResult("ACC-REF-1"); + + public Task StoreDocumentAsync(DocumentRequest request, CancellationToken ct = default) + => Task.FromResult(new Uri("http://openzaak/documenten/api/v1/enkelvoudiginformatieobjecten/acc-doc")); } -- 2.54.0 From 9d327bbd81848be5d1a4c195dbd02b171da78581 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 12:07:42 +0200 Subject: [PATCH 06/15] test(bff): documents endpoint forwards the base64 file to the domain (refs #103) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit RED: the self-service documents endpoint takes the base64 file (+ fileName/contentType) as JSON — the portal encodes client-side — with the bsn from the token, and forwards all of it to the domain. IDomainClient.ProvideDocumentsAsync grows accordingly. Co-Authored-By: Claude Opus 4.8 (1M context) --- services/bff/Bff.Tests/BffFactory.cs | 6 +++--- .../bff/Bff.Tests/SelfServiceEndpointTests.cs | 21 ++++++++++++++++--- 2 files changed, 21 insertions(+), 6 deletions(-) diff --git a/services/bff/Bff.Tests/BffFactory.cs b/services/bff/Bff.Tests/BffFactory.cs index 492ab05..e1b5132 100644 --- a/services/bff/Bff.Tests/BffFactory.cs +++ b/services/bff/Bff.Tests/BffFactory.cs @@ -94,15 +94,15 @@ internal sealed class FakeDomainClient : IDomainClient return Task.FromResult(WithdrawSucceeds); } - public (string RegistrationId, string Bsn)? DocumentsProvidedFor { get; private set; } + public (string RegistrationId, string Bsn, string ContentBase64, string? FileName, string? ContentType)? DocumentsProvidedFor { get; private set; } /// Whether the fake domain reports the provide-documents as done (true → 204) or /// not-found/not-owned (false → 404). Tests set this to exercise the relay. public bool ProvideDocumentsSucceeds { get; set; } = true; - public Task ProvideDocumentsAsync(string registrationId, string bsn, CancellationToken ct = default) + public Task ProvideDocumentsAsync(string registrationId, string bsn, string contentBase64, string? fileName, string? contentType, CancellationToken ct = default) { - DocumentsProvidedFor = (registrationId, bsn); + DocumentsProvidedFor = (registrationId, bsn, contentBase64, fileName, contentType); return Task.FromResult(ProvideDocumentsSucceeds); } diff --git a/services/bff/Bff.Tests/SelfServiceEndpointTests.cs b/services/bff/Bff.Tests/SelfServiceEndpointTests.cs index c8e0ccd..3b23b7b 100644 --- a/services/bff/Bff.Tests/SelfServiceEndpointTests.cs +++ b/services/bff/Bff.Tests/SelfServiceEndpointTests.cs @@ -114,7 +114,17 @@ public class SelfServiceEndpointTests private static HttpRequestMessage ProvideDocuments(string? bearer, string id = "reg-123") { - var request = new HttpRequestMessage(HttpMethod.Post, $"/self-service/registrations/{id}/documents"); + var request = new HttpRequestMessage(HttpMethod.Post, $"/self-service/registrations/{id}/documents") + { + // The portal base64-encodes the file client-side and posts it as JSON (S-10b); the bsn is + // never in the body — it comes from the DigiD token. + Content = JsonContent.Create(new + { + contentBase64 = Convert.ToBase64String([1, 2, 3]), + fileName = "diploma.pdf", + contentType = "application/pdf", + }), + }; if (bearer is not null) request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", bearer); return request; @@ -132,14 +142,19 @@ public class SelfServiceEndpointTests } [Fact] - public async Task Provides_documents_for_the_callers_registration_forwarding_the_id_and_bsn() + public async Task Provides_documents_for_the_callers_registration_forwarding_id_bsn_and_file() { using var factory = new BffFactory(); var response = await factory.CreateClient().SendAsync(ProvideDocuments(TestTokens.Valid("123456782"), "reg-9")); Assert.Equal(HttpStatusCode.NoContent, response.StatusCode); - Assert.Equal(("reg-9", "123456782"), factory.Domain.DocumentsProvidedFor); + var provided = factory.Domain.DocumentsProvidedFor; + Assert.NotNull(provided); + Assert.Equal("reg-9", provided!.Value.RegistrationId); + Assert.Equal("123456782", provided.Value.Bsn); + Assert.Equal(Convert.ToBase64String([1, 2, 3]), provided.Value.ContentBase64); + Assert.Equal("diploma.pdf", provided.Value.FileName); } [Fact] -- 2.54.0 From 4c516cdad34144ae4550e0dd8d54b454f88966af Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 12:13:10 +0200 Subject: [PATCH 07/15] feat(bff): documents endpoint accepts the base64 file and forwards it to the domain (refs #103) The self-service documents endpoint takes { contentBase64, fileName, contentType } as JSON (bsn from the token) and forwards it via IDomainClient.ProvideDocumentsAsync. Regenerates openapi.json + the Angular client (postSelfServiceRegistrationsIdDocuments now takes a ProvideDocumentsRequest body). Co-Authored-By: Claude Opus 4.8 (1M context) --- libs/api-client/src/lib/generated/bff-api.ts | 26 ++++++++++----- services/bff/Bff.Api/DownstreamClients.cs | 15 +++++---- services/bff/Bff.Api/Program.cs | 10 ++++-- services/bff/openapi.json | 33 ++++++++++++++++++++ 4 files changed, 69 insertions(+), 15 deletions(-) diff --git a/libs/api-client/src/lib/generated/bff-api.ts b/libs/api-client/src/lib/generated/bff-api.ts index f5d35d7..3ac28e9 100644 --- a/libs/api-client/src/lib/generated/bff-api.ts +++ b/libs/api-client/src/lib/generated/bff-api.ts @@ -35,6 +35,14 @@ export interface OpenbaarEntry { reference: string | null; } +export interface ProvideDocumentsRequest { + contentBase64: string; + /** @nullable */ + fileName?: string | null; + /** @nullable */ + contentType?: string | null; +} + export interface SubmitAccepted { registrationId: string; status: string; @@ -226,15 +234,19 @@ export class BffApiV1Service { ); } - postSelfServiceRegistrationsIdDocuments(id: string, options?: HttpClientBodyOptions): Observable; - postSelfServiceRegistrationsIdDocuments(id: string, options?: HttpClientEventOptions): Observable>; - postSelfServiceRegistrationsIdDocuments(id: string, options?: HttpClientResponseOptions): Observable>; + postSelfServiceRegistrationsIdDocuments(id: string, + provideDocumentsRequest: ProvideDocumentsRequest, options?: HttpClientBodyOptions): Observable; + postSelfServiceRegistrationsIdDocuments(id: string, + provideDocumentsRequest: ProvideDocumentsRequest, options?: HttpClientEventOptions): Observable>; + postSelfServiceRegistrationsIdDocuments(id: string, + provideDocumentsRequest: ProvideDocumentsRequest, options?: HttpClientResponseOptions): Observable>; postSelfServiceRegistrationsIdDocuments( - id: string, options?: HttpClientObserveOptions): Observable | AngularHttpResponse> { + id: string, + provideDocumentsRequest: ProvideDocumentsRequest, options?: HttpClientObserveOptions): Observable | AngularHttpResponse> { if (options?.observe === 'events') { return this.http.post( `/self-service/registrations/${id}/documents`, - undefined,{ + provideDocumentsRequest,{ ...(options as Omit, 'observe'>), observe: 'events', } @@ -244,7 +256,7 @@ export class BffApiV1Service { if (options?.observe === 'response') { return this.http.post( `/self-service/registrations/${id}/documents`, - undefined,{ + provideDocumentsRequest,{ ...(options as Omit, 'observe'>), observe: 'response', } @@ -253,7 +265,7 @@ export class BffApiV1Service { return this.http.post( `/self-service/registrations/${id}/documents`, - undefined,{ + provideDocumentsRequest,{ ...(options as Omit, 'observe'>), observe: 'body', } diff --git a/services/bff/Bff.Api/DownstreamClients.cs b/services/bff/Bff.Api/DownstreamClients.cs index f935247..cf0e448 100644 --- a/services/bff/Bff.Api/DownstreamClients.cs +++ b/services/bff/Bff.Api/DownstreamClients.cs @@ -27,10 +27,11 @@ public interface IDomainClient /// unknown or not the caller's (404), so the BFF can relay a 404 rather than a 500. Task WithdrawRegistrationAsync(string registrationId, string bsn, CancellationToken ct = default); - /// Provide the documents the caller's own registration is waiting for ("documenten - /// aanleveren"). Owner-scoped by . Returns false when the domain - /// reports the registration is unknown or not the caller's (404), so the BFF can relay a 404. - Task ProvideDocumentsAsync(string registrationId, string bsn, CancellationToken ct = default); + /// Provide (upload) the diploma the caller's own registration is waiting for ("documenten + /// aanleveren"). The file is carried base64-encoded. Owner-scoped by . Returns + /// false when the domain reports the registration is unknown or not the caller's (404). + Task ProvideDocumentsAsync( + string registrationId, string bsn, string contentBase64, string? fileName, string? contentType, CancellationToken ct = default); /// The behandelaar's werkbak — registrations awaiting beoordeling. Task> GetWerkbakAsync(CancellationToken ct = default); @@ -68,10 +69,12 @@ public sealed class DomainClient(HttpClient http) : IDomainClient return true; } - public async Task ProvideDocumentsAsync(string registrationId, string bsn, CancellationToken ct = default) + public async Task ProvideDocumentsAsync( + string registrationId, string bsn, string contentBase64, string? fileName, string? contentType, CancellationToken ct = default) { using var response = await http.PostAsJsonAsync( - $"registrations/{registrationId}/documents", new { bsn }, ct); + $"registrations/{registrationId}/documents", + new { bsn, contentBase64, fileName, contentType }, ct); // The domain 404s an unknown or not-owned registration; relay that rather than fail hard. if (response.StatusCode == System.Net.HttpStatusCode.NotFound) return false; diff --git a/services/bff/Bff.Api/Program.cs b/services/bff/Bff.Api/Program.cs index 940d5f2..f2a660a 100644 --- a/services/bff/Bff.Api/Program.cs +++ b/services/bff/Bff.Api/Program.cs @@ -109,13 +109,15 @@ app.MapPost("/self-service/registrations/{id}/withdraw", async (string id, Claim // forwarded to the domain, which owner-scopes the action and completes the WachtOpDocumenten task; a // registration that is unknown or not the caller's comes back 404. The real file upload + ZGW storage // is S-10b — this is the trigger that unblocks the process. -app.MapPost("/self-service/registrations/{id}/documents", async (string id, ClaimsPrincipal user, IDomainClient domain, CancellationToken ct) => +app.MapPost("/self-service/registrations/{id}/documents", async (string id, ProvideDocumentsRequest body, ClaimsPrincipal user, IDomainClient domain, CancellationToken ct) => { var bsn = user.FindFirstValue("bsn"); if (string.IsNullOrWhiteSpace(bsn)) return Results.BadRequest("The token carries no bsn claim."); + if (string.IsNullOrWhiteSpace(body?.ContentBase64)) + return Results.BadRequest("A document is required."); - var provided = await domain.ProvideDocumentsAsync(id, bsn, ct); + var provided = await domain.ProvideDocumentsAsync(id, bsn, body.ContentBase64, body.FileName, body.ContentType, ct); return provided ? Results.NoContent() : Results.NotFound(); }) .RequireAuthorization() @@ -163,6 +165,10 @@ app.Run(); /// The behandelaar's decision on a registration. public sealed record DecideRequest(string Besluit); +/// A diploma upload from the self-service portal — the file base64-encoded client-side, with +/// its name and MIME type. The bsn is taken from the DigiD token, not this body. +public sealed record ProvideDocumentsRequest(string ContentBase64, string? FileName = null, string? ContentType = null); + // Behandel (medewerker-realm) authentication + authorization wiring (ADR-0013). internal static class BehandelAuth { diff --git a/services/bff/openapi.json b/services/bff/openapi.json index fd2101a..02359e1 100644 --- a/services/bff/openapi.json +++ b/services/bff/openapi.json @@ -76,6 +76,16 @@ } } ], + "requestBody": { + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/ProvideDocumentsRequest" + } + } + }, + "required": true + }, "responses": { "204": { "description": "No Content" @@ -228,6 +238,29 @@ } } }, + "ProvideDocumentsRequest": { + "required": [ + "contentBase64" + ], + "type": "object", + "properties": { + "contentBase64": { + "type": "string" + }, + "fileName": { + "type": [ + "null", + "string" + ] + }, + "contentType": { + "type": [ + "null", + "string" + ] + } + } + }, "SubmitAccepted": { "required": [ "registrationId", -- 2.54.0 From d354fe507aa4522ef9f14b8a224e6243182f396a Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 12:14:36 +0200 Subject: [PATCH 08/15] test(portal): self-service uploads a chosen diploma file (refs #103) RED: after submitting, the citizen picks a PDF and uploads it; the component base64- encodes it client-side and posts { contentBase64, fileName, contentType } keyed by the reference, then confirms. Replaces the S-10a stub button. Co-Authored-By: Claude Opus 4.8 (1M context) --- .../app/registration/registration-page.spec.ts | 17 +++++++++++++---- 1 file changed, 13 insertions(+), 4 deletions(-) diff --git a/apps/self-service/src/app/registration/registration-page.spec.ts b/apps/self-service/src/app/registration/registration-page.spec.ts index f17ff06..8e8cff9 100644 --- a/apps/self-service/src/app/registration/registration-page.spec.ts +++ b/apps/self-service/src/app/registration/registration-page.spec.ts @@ -83,21 +83,29 @@ describe('RegistrationPage', () => { expect(await screen.findByText(/ingetrokken/i)).toBeTruthy(); }); - it('offers to provide documents after submitting, and doing so confirms', async () => { + // A small PDF file the citizen "uploads"; the component base64-encodes it client-side. + const diploma = () => new File([new Uint8Array([1, 2, 3])], 'diploma.pdf', { type: 'application/pdf' }); + + it('uploads a chosen diploma after submitting, and doing so confirms', async () => { const { provideDocuments, providers: p } = providers(); await render(RegistrationPage, { providers: p }); fireEvent.click(screen.getByRole('button', { name: /indienen/i })); await screen.findByText(/ontvangen/i); + // Choose the file, then upload it. + fireEvent.change(screen.getByLabelText(/diploma/i), { target: { files: [diploma()] } }); fireEvent.click(await screen.findByRole('button', { name: /documenten aanleveren/i })); - // The provide-documents call is keyed by the reference the submit returned, and the page confirms. - expect(provideDocuments).toHaveBeenCalledWith('reg-9'); + // The upload is keyed by the reference and carries the base64 file + its name; the page confirms. expect(await screen.findByText(/documenten.*aangeleverd/i)).toBeTruthy(); + expect(provideDocuments).toHaveBeenCalledWith( + 'reg-9', + expect.objectContaining({ fileName: 'diploma.pdf', contentType: 'application/pdf', contentBase64: expect.any(String) }), + ); }); - it('surfaces a provide-documents failure and keeps the action available', async () => { + it('surfaces a diploma-upload failure and keeps the action available', async () => { const { providers: p } = providers( vi.fn().mockReturnValue(of({ registrationId: 'reg-9', status: 'Ingediend' })), vi.fn().mockReturnValue(of(undefined)), @@ -107,6 +115,7 @@ describe('RegistrationPage', () => { fireEvent.click(screen.getByRole('button', { name: /indienen/i })); await screen.findByText(/ontvangen/i); + fireEvent.change(screen.getByLabelText(/diploma/i), { target: { files: [diploma()] } }); fireEvent.click(await screen.findByRole('button', { name: /documenten aanleveren/i })); expect(await screen.findByRole('alert')).toBeTruthy(); -- 2.54.0 From 1abd4b6472b9cf1ec99d6a4b21bfdc41637c8742 Mon Sep 17 00:00:00 2001 From: Niek Otten Date: Mon, 20 Jul 2026 12:15:49 +0200 Subject: [PATCH 09/15] feat(portal): real diploma file upload on the self-service page (refs #103) Replaces the S-10a stub button with a labelled file input (accept application/pdf); the component base64-encodes the chosen file client-side and posts it (with its name and type) keyed by the reference, confirming on success and surfacing a retryable failure. The upload button stays disabled until a file is chosen. Co-Authored-By: Claude Opus 4.8 (1M context) --- .../app/registration/registration-page.html | 11 +++- .../src/app/registration/registration-page.ts | 57 ++++++++++++++----- 2 files changed, 54 insertions(+), 14 deletions(-) diff --git a/apps/self-service/src/app/registration/registration-page.html b/apps/self-service/src/app/registration/registration-page.html index 6910880..255dba4 100644 --- a/apps/self-service/src/app/registration/registration-page.html +++ b/apps/self-service/src/app/registration/registration-page.html @@ -19,11 +19,20 @@ Het aanleveren van uw documenten is niet gelukt. Probeer het opnieuw.

} +

Lever uw diploma aan (PDF).

+ +