## What & why S-10b: the self-service **diploma upload** is now real. After submitting, the citizen picks a PDF and uploads it; the portal base64-encodes it client-side → BFF → domain → **ACL**, which stores it in the ZGW **Documenten (DRC) API** as an `enkelvoudiginformatieobject` and relates it to the zaak, then the `WachtOpDocumenten` wait completes and the case advances to beoordeling. Per §8.1 only the ACL talks to ZGW. Closes #103 Mechanism in **ADR-0018** (proposal #107). Builds on S-10a (#102). The zaak-close-on-expiry item is carved to **#106 (S-10c)**. ## Definition of Done - [x] Linked Gitea issue (above). - [x] Failing test committed before the implementation (red→green per layer). - [x] Conventional Commits referencing the issue (`refs #103`). - [ ] CI green — all Gitea Actions jobs (pending on this PR). - [x] `docker compose up` health unaffected (ACL boots on a placeholder informatieobjecttype URL; the real one is injected by verify-domain). - [x] Docs updated (ADR-0018, demo-script, BACKLOG + S-10c). - [x] ADR added (`docs/architecture/adr-0018-diploma-upload-via-acl-documenten.md`). - [x] Demo note in `docs/demo-script.md`. ## Notes for reviewers - **ACL** (`OpenZaakGateway.StoreDocumentAsync` + `AclService.StoreDiplomaAsync` + `POST /documenten`) reuses the existing gateway patterns (ZGW Bearer, buffered non-chunked body, **no CRS** — Documenten isn't geo). Unit-tested via the stub handler; an **integration test** stores a real document against live OpenZaak (verify-acl). - **Transport:** base64 JSON on every hop (portal encodes client-side) — I deviated from proposal #107's multipart to keep one contract shape and avoid `IFormFile`/antiforgery/multipart-client plumbing; fine at diploma size (ADR-0018 §Alternatives). - **Infra:** `seed_catalogus.py` seeds + publishes a "Diploma" `informatieobjecttype` and relates it to the zaaktype (while both concept); `verify-domain` injects its URL into the ACL. No new ZGW scopes (seed applicatie has `heeft_alle_autorisaties`). - **e2e:** uploads a real PDF (`setInputFiles`) after the openbaar INGEDIEND row confirms the zaak is open (so storage doesn't race the OpenZaak worker). - **Scope boundary:** the ZGW zaak is not set to a cancellation status on 30-day expiry — that's #106 (S-10c). 🤖 Generated with [Claude Code](https://claude.com/claude-code) Reviewed-on: #108
121 lines
6.4 KiB
C#
121 lines
6.4 KiB
C#
using Big.Domain;
|
|
|
|
namespace Big.Application;
|
|
|
|
/// <summary>
|
|
/// The port to the workflow engine. Implemented by the Workflow Client in Infrastructure — the
|
|
/// <em>only</em> code that talks to Flowable (CLAUDE.md §8.2). The application asks it to start the
|
|
/// registratie process; it never knows Flowable exists.
|
|
/// </summary>
|
|
public interface IWorkflowClient
|
|
{
|
|
/// <summary>
|
|
/// Start one <c>registratie</c> process instance for the given registration, carrying the
|
|
/// registration id (so the <c>OpenZaakAanmaken</c> external task can be correlated back to its
|
|
/// aggregate) and the diploma origin (so the workflow's DMN can route foreign diplomas through
|
|
/// CBGV-advies, S-13). Returns the process instance id.
|
|
/// </summary>
|
|
Task<string> StartRegistrationProcessAsync(
|
|
RegistrationId registrationId, DiplomaOrigin diplomaOrigin, CancellationToken ct = default);
|
|
|
|
/// <summary>
|
|
/// Cancel a running <c>registratie</c> process on withdrawal (S-11): correlate the
|
|
/// <c>RegistratieIngetrokken</c> message to the instance, tripping the interrupting message event
|
|
/// that ends it (ADR-0014). Best-effort — if the instance is not waiting on that message (already
|
|
/// ended, or not yet parked) it is a no-op; the aggregate is INGETROKKEN regardless.
|
|
/// </summary>
|
|
Task WithdrawProcessAsync(string processInstanceId, CancellationToken ct = default);
|
|
|
|
/// <summary>
|
|
/// Signal that the required documents have arrived (S-10a): complete the <c>WachtOpDocumenten</c>
|
|
/// user task in the instance so the process leaves the 30-day wait state and continues to
|
|
/// beoordeling (ADR-0017). Best-effort — if the instance is not parked at that task (already
|
|
/// continued, or timed out) it is a no-op. The upload trigger that calls this is wired in S-10b.
|
|
/// </summary>
|
|
Task CompleteDocumentWaitAsync(string processInstanceId, CancellationToken ct = default);
|
|
}
|
|
|
|
/// <summary>
|
|
/// The port to the Anti-Corruption Layer. Implemented in Infrastructure by an HTTP client to the
|
|
/// ACL service — the <em>only</em> code that talks to ZGW (CLAUDE.md §8.1). The domain hands over a
|
|
/// bsn; the ACL default-fills the ZGW-mandatory fields (ADR-0003) and returns the created zaak URL.
|
|
/// </summary>
|
|
public interface IAclClient
|
|
{
|
|
/// <summary>Open a zaak for the registration. <paramref name="reference"/> is the registration's
|
|
/// own reference (its id); the ACL records it as the zaak's identificatie so the openbaar register
|
|
/// can show the same reference the zorgprofessional was given (S-09b follow-up, adr-proposal #78).</summary>
|
|
Task<Uri> OpenZaakAsync(string bsn, string reference, CancellationToken ct = default);
|
|
|
|
/// <summary>
|
|
/// Record the approval on the given zaak. The ACL translates this to the ZGW concept — setting
|
|
/// the zaak's final status — which OpenZaak notifies over NRC; the domain never names statustypen.
|
|
/// </summary>
|
|
Task ApproveZaakAsync(Uri zaakUrl, CancellationToken ct = default);
|
|
|
|
/// <summary>
|
|
/// Store an uploaded diploma against the zaak (S-10b). The domain hands over the zaak, the raw file
|
|
/// bytes, and the file's name/type; the ACL creates the ZGW informatieobject and relates it to the
|
|
/// zaak (§8.1). Returns the stored document's URL.
|
|
/// </summary>
|
|
Task<Uri> StoreDiplomaAsync(Uri zaakUrl, byte[] content, string fileName, string contentType, CancellationToken ct = default);
|
|
}
|
|
|
|
/// <summary>
|
|
/// The port to the behandelaar's user tasks in the workflow engine (S-12). Implemented by the
|
|
/// Workflow Client — the only code that talks to Flowable (§8.2). The application lists the open
|
|
/// <c>Beoordelen</c> tasks (the werkbak), claims one for a behandelaar, and completes it with the
|
|
/// decision; it never names Flowable's REST shapes.
|
|
/// </summary>
|
|
public interface IUserTaskClient
|
|
{
|
|
/// <summary>The werkbak: the <c>Beoordelen</c> tasks awaiting a behandelaar, each with the
|
|
/// registration it belongs to.</summary>
|
|
Task<IReadOnlyList<BeoordelingTask>> GetOpenBeoordelingenAsync(CancellationToken ct = default);
|
|
|
|
/// <summary>Claim a beoordeling task for a behandelaar (assigns it to them).</summary>
|
|
Task ClaimAsync(string taskId, string behandelaar, CancellationToken ct = default);
|
|
|
|
/// <summary>Complete a beoordeling task, carrying the decision into the process as the
|
|
/// <c>besluit</c> variable so the workflow can continue on the chosen branch.</summary>
|
|
Task CompleteBeoordelingAsync(string taskId, BeoordelingsBesluit besluit, CancellationToken ct = default);
|
|
}
|
|
|
|
/// <summary>A <c>Beoordelen</c> user task in the werkbak: the Flowable task id (needed to claim and
|
|
/// complete it) and the registration it carries as a process variable.</summary>
|
|
public sealed record BeoordelingTask(string TaskId, RegistrationId RegistrationId);
|
|
|
|
/// <summary>
|
|
/// Persistence port for the <see cref="Registration"/> aggregate. In-memory for the minimal slice
|
|
/// (ADR-0009); an EF-backed store is a documented follow-up, and this port keeps that change additive.
|
|
/// </summary>
|
|
public interface IRegistrationStore
|
|
{
|
|
/// <summary>Insert or update the registration, keyed on its id.</summary>
|
|
Task SaveAsync(Registration registration, CancellationToken ct = default);
|
|
|
|
/// <summary>Load a registration by id, or <c>null</c> if none exists.</summary>
|
|
Task<Registration?> GetAsync(RegistrationId id, CancellationToken ct = default);
|
|
}
|
|
|
|
/// <summary>
|
|
/// An acquired <c>OpenZaakAanmaken</c> external-worker job: the Flowable job id (needed to complete
|
|
/// it) and the registration id it carries as a process variable.
|
|
/// </summary>
|
|
public sealed record OpenZaakJob(string JobId, RegistrationId RegistrationId);
|
|
|
|
/// <summary>
|
|
/// An acquired <c>BeoordelingEscaleren</c> escalation job (S-14): the Flowable job id and the process
|
|
/// instance whose still-open <c>Beoordelen</c> task must be reassigned from behandelaar to teamlead
|
|
/// once the 14-day boundary timer fires (ADR-0015).
|
|
/// </summary>
|
|
public sealed record EscalatieJob(string JobId, string ProcessInstanceId);
|
|
|
|
/// <summary>
|
|
/// An acquired <c>RegistratieVerlopen</c> job (S-10a): the Flowable job id and the registration id it
|
|
/// carries as a process variable. The 30-day boundary timer on <c>WachtOpDocumenten</c> spawns it when
|
|
/// the required documents were not supplied in time; expiring the correlated registration to VERLOPEN
|
|
/// cancels the case (ADR-0017).
|
|
/// </summary>
|
|
public sealed record RegistratieVerlopenJob(string JobId, RegistrationId RegistrationId);
|