Red: ProvideDocuments takes the new IDocumentScanner port but ignores it, so infected, non-PDF and scanner-unavailable uploads are still Accepted. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
169 lines
7.1 KiB
C#
169 lines
7.1 KiB
C#
using Big.Application;
|
|
using Big.Domain;
|
|
|
|
namespace Big.Tests;
|
|
|
|
// S-10a/S-10b (#102/#103): the "documents received" use case. A zorgprofessional supplies the diploma
|
|
// their registration is waiting for; the handler stores it in ZGW via the ACL and completes the
|
|
// WachtOpDocumenten task via the Workflow Client so the process continues to beoordeling. Owner-scoped
|
|
// by the caller's bsn, like WithdrawRegistration.
|
|
public class ProvideDocumentsTests
|
|
{
|
|
private const string Bsn = "123456782";
|
|
private static readonly Uri Zaak = new("http://openzaak/zaken/api/v1/zaken/abc");
|
|
|
|
private static Registration Submitted(string processInstanceId = "proc-1")
|
|
{
|
|
var registration = Registration.Submit(Bsn);
|
|
registration.RecordProcessStarted(processInstanceId);
|
|
registration.AttachZaak(Zaak);
|
|
return registration;
|
|
}
|
|
|
|
private static readonly byte[] Pdf = "%PDF-1.4 diploma"u8.ToArray();
|
|
|
|
private static ProvideDocumentsCommand Command(RegistrationId id, string bsn = Bsn, byte[]? content = null) =>
|
|
new(id, bsn, content ?? Pdf, "diploma.pdf", "application/pdf");
|
|
|
|
[Fact]
|
|
public async Task Providing_documents_stores_the_diploma_and_completes_the_wait()
|
|
{
|
|
var store = new FakeRegistrationStore();
|
|
var registration = Submitted("proc-42");
|
|
store.Seed(registration);
|
|
var workflow = new FakeWorkflowClient();
|
|
var acl = new FakeAclClient();
|
|
var handler = new ProvideDocuments(store, workflow, acl, new FakeDocumentScanner());
|
|
|
|
var outcome = await handler.HandleAsync(Command(registration.Id));
|
|
|
|
Assert.Equal(ProvideDocumentsOutcome.Accepted, outcome);
|
|
// Stored against the registration's zaak, carrying the uploaded bytes + file metadata.
|
|
Assert.Equal((Zaak, Pdf, "diploma.pdf", "application/pdf"), acl.StoredDiploma);
|
|
// …and the wait is completed so beoordeling can proceed.
|
|
Assert.Equal("proc-42", workflow.CompletedDocumentWaitFor);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task A_different_bsn_cannot_provide_documents()
|
|
{
|
|
// Owner-scoping: another bsn is told NotFound; nothing is stored or completed.
|
|
var store = new FakeRegistrationStore();
|
|
var registration = Submitted();
|
|
store.Seed(registration);
|
|
var workflow = new FakeWorkflowClient();
|
|
var acl = new FakeAclClient();
|
|
var handler = new ProvideDocuments(store, workflow, acl, new FakeDocumentScanner());
|
|
|
|
var outcome = await handler.HandleAsync(Command(registration.Id, bsn: "999999990"));
|
|
|
|
Assert.Equal(ProvideDocumentsOutcome.NotFound, outcome);
|
|
Assert.Null(acl.StoredDiploma);
|
|
Assert.Null(workflow.CompletedDocumentWaitFor);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task Providing_for_an_unknown_registration_is_not_found()
|
|
{
|
|
var store = new FakeRegistrationStore();
|
|
var handler = new ProvideDocuments(store, new FakeWorkflowClient(), new FakeAclClient(), new FakeDocumentScanner());
|
|
|
|
Assert.Equal(ProvideDocumentsOutcome.NotFound, await handler.HandleAsync(Command(RegistrationId.New())));
|
|
}
|
|
|
|
[Fact]
|
|
public async Task Providing_before_a_zaak_is_opened_does_not_store_but_still_completes_the_wait()
|
|
{
|
|
// No zaak yet → nothing to file the document against, but the request still stands (best-effort,
|
|
// mirroring WithdrawRegistration). The wait is completed if a process is running.
|
|
var store = new FakeRegistrationStore();
|
|
var registration = Registration.Submit(Bsn);
|
|
registration.RecordProcessStarted("proc-9"); // process started, but no zaak attached
|
|
store.Seed(registration);
|
|
var workflow = new FakeWorkflowClient();
|
|
var acl = new FakeAclClient();
|
|
var handler = new ProvideDocuments(store, workflow, acl, new FakeDocumentScanner());
|
|
|
|
var outcome = await handler.HandleAsync(Command(registration.Id));
|
|
|
|
Assert.Equal(ProvideDocumentsOutcome.Accepted, outcome);
|
|
Assert.Null(acl.StoredDiploma);
|
|
Assert.Equal("proc-9", workflow.CompletedDocumentWaitFor);
|
|
}
|
|
|
|
// S-29 (#192, ADR-0036): only a clean PDF is stored and unblocks beoordeling.
|
|
[Theory]
|
|
[InlineData(ScanVerdict.Infected, ProvideDocumentsOutcome.Infected)]
|
|
[InlineData(ScanVerdict.Unavailable, ProvideDocumentsOutcome.ScannerUnavailable)]
|
|
public async Task A_document_that_does_not_scan_clean_is_refused_and_the_wait_stays_open(
|
|
ScanVerdict verdict, ProvideDocumentsOutcome expected)
|
|
{
|
|
var store = new FakeRegistrationStore();
|
|
var registration = Submitted();
|
|
store.Seed(registration);
|
|
var workflow = new FakeWorkflowClient();
|
|
var acl = new FakeAclClient();
|
|
var handler = new ProvideDocuments(store, workflow, acl, new FakeDocumentScanner(verdict));
|
|
|
|
var outcome = await handler.HandleAsync(Command(registration.Id));
|
|
|
|
Assert.Equal(expected, outcome);
|
|
Assert.Null(acl.StoredDiploma);
|
|
Assert.Null(workflow.CompletedDocumentWaitFor);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task A_file_that_is_not_a_pdf_is_refused_without_being_scanned()
|
|
{
|
|
var store = new FakeRegistrationStore();
|
|
var registration = Submitted();
|
|
store.Seed(registration);
|
|
var workflow = new FakeWorkflowClient();
|
|
var acl = new FakeAclClient();
|
|
var scanner = new FakeDocumentScanner();
|
|
var handler = new ProvideDocuments(store, workflow, acl, scanner);
|
|
|
|
var outcome = await handler.HandleAsync(Command(registration.Id, content: "MZ not a pdf"u8.ToArray()));
|
|
|
|
Assert.Equal(ProvideDocumentsOutcome.NotAPdf, outcome);
|
|
Assert.Null(scanner.Scanned);
|
|
Assert.Null(acl.StoredDiploma);
|
|
Assert.Null(workflow.CompletedDocumentWaitFor);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task A_clean_pdf_is_scanned_before_it_is_stored()
|
|
{
|
|
var store = new FakeRegistrationStore();
|
|
var registration = Submitted();
|
|
store.Seed(registration);
|
|
var scanner = new FakeDocumentScanner();
|
|
var handler = new ProvideDocuments(store, new FakeWorkflowClient(), new FakeAclClient(), scanner);
|
|
|
|
await handler.HandleAsync(Command(registration.Id));
|
|
|
|
Assert.Equal(Pdf, scanner.Scanned);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task A_different_bsn_learns_nothing_about_the_scan()
|
|
{
|
|
// Ownership is checked first: someone else's registration is NotFound even for an infected file.
|
|
var store = new FakeRegistrationStore();
|
|
var registration = Submitted();
|
|
store.Seed(registration);
|
|
var scanner = new FakeDocumentScanner(ScanVerdict.Infected);
|
|
var handler = new ProvideDocuments(store, new FakeWorkflowClient(), new FakeAclClient(), scanner);
|
|
|
|
var outcome = await handler.HandleAsync(Command(registration.Id, bsn: "999999990"));
|
|
|
|
Assert.Equal(ProvideDocumentsOutcome.NotFound, outcome);
|
|
Assert.Null(scanner.Scanned);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task Rejects_a_null_command()
|
|
=> await Assert.ThrowsAsync<ArgumentNullException>(() =>
|
|
new ProvideDocuments(new FakeRegistrationStore(), new FakeWorkflowClient(), new FakeAclClient(), new FakeDocumentScanner()).HandleAsync(null!));
|
|
}
|