feat(portal-beheer): ACL default-fill configuration editor (closes #131) (#138)
CI / build (push) Successful in 1m34s
CI / lint (push) Successful in 1m36s
CI / unit (push) Successful in 1m45s
CI / frontend (push) Successful in 3m37s
CI / mutation (push) Successful in 6m25s
CI / verify-stack (push) Successful in 7m56s

## What & why

S-15b, second of the S-15 (#16) split, on top of S-15a (#133). A beheerder edits the ACL's ZGW **default-fill** values from the beheer portal, and the next zaak is stamped with the new values — no restart.

Closes #131

### The vertical

portal → BFF `GET/PUT /beheer/default-fill` (medewerker realm + `beheerder` role) → ACL `GET/PUT /default-fill` → a runtime-mutable in-memory store the ACL reads **per zaak**.

- **ACL**: `IDefaultFillStore` / `InMemoryDefaultFillStore` (thread-safe, seeded from `Acl:Defaults`); `AclService` reads `fill.Current` per zaak (not cached at construction); `GET`/`PUT /default-fill` with required-field validation.
- **BFF**: `IAclClient` gains `GetDefaultFillAsync`/`UpdateDefaultFillAsync`; `GET`/`PUT /beheer/default-fill` behind the `beheerder` policy. OpenAPI + generated client regenerated.
- **Frontend**: a *Default-fill* editor page in the beheer app (load → edit → save, with saved/failure states) + nav between Catalogus and Default-fill.

### Scope decision → ADR-0026

Only the **three ZGW fill fields** (bronorganisatie, verantwoordelijke organisatie, vertrouwelijkheidaanduiding) are editable. The S-27 catalog-resolution keys stay **static config** — editing them would desync the zaaktype-URL cache (ADR-0021), and they're catalogus wiring, not "default fill". The store is **in-memory** (seeded from config): an edit reverts on restart. That's the reference-app-appropriate ceiling (no DB added to the stateless ACL); upgrade path documented. Recorded in **ADR-0026**.

## Verified locally

lint (`dotnet format`) ✓ · .NET unit — acl 60 / bff 45 / domain 152 / event-subscriber 19 / acceptance 17 ✓ · frontend lint+test (8 projects) ✓ · beheer build ✓. Clean full-solution build (caught + fixed the acceptance `AclService` ctor drift). TDD red→green per layer (ACL store, ACL endpoints, BFF, frontend).

## Definition of Done

- [x] Failing test committed before each implementation (red→green per layer).
- [x] Conventional Commits referencing #131.
- [ ] CI green — see note below.
- [x] Docs: ADR-0026 + S-15b demo note.
- [x] Demo note in `docs/demo-script.md`.

## Note on CI

The bulk validates in the fast jobs (lint/build/unit/frontend/mutation). The **verify-stack e2e** (incl. the new `default-fill.spec.ts`) can't go green until the pre-existing **verify-stack bring-up failure on the 1.27/2.0.0 runner** is resolved (that fails on plain `main` too — unrelated to this PR). Additive change; no existing e2e touched.

🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #138
This commit was merged in pull request #138.
This commit is contained in:
not
2026-07-24 14:22:22 +00:00
parent fff88ca23d
commit 0494730223
22 changed files with 759 additions and 7 deletions
+27 -3
View File
@@ -59,12 +59,26 @@ public interface IProjectionClient
/// internal reference, not shown in the portal.</summary>
public sealed record BeheerZaaktype(string Identificatie, string Omschrijving);
/// <summary>Port to the ACL for read-only catalogus queries (beheer portal, S-15a). The BFF reaches the
/// ACL directly for this read: the catalogus isn't a domain concern, and the ACL is the only code
/// allowed to read the ZGW Catalogi API (§8.1, ADR-0025).</summary>
/// <summary>The ACL default-fill settings the beheer portal reads + edits (S-15b): the three ZGW-mandatory
/// fields the ACL stamps on every zaak (ADR-0003).</summary>
public sealed record BeheerDefaultFill(
string Bronorganisatie,
string VerantwoordelijkeOrganisatie,
string Vertrouwelijkheidaanduiding);
/// <summary>Port to the ACL for beheer queries (beheer portal). The BFF reaches the ACL directly: these
/// aren't a domain concern, and the ACL is the only code allowed to read/own the ZGW-facing config
/// (§8.1, ADR-0025).</summary>
public interface IAclClient
{
/// <summary>The published catalogus zaaktypen, read-only (S-15a).</summary>
Task<IReadOnlyList<BeheerZaaktype>> GetZaaktypenAsync(CancellationToken ct = default);
/// <summary>The current default-fill settings (S-15b).</summary>
Task<BeheerDefaultFill> GetDefaultFillAsync(CancellationToken ct = default);
/// <summary>Replace the default-fill settings (S-15b).</summary>
Task UpdateDefaultFillAsync(BeheerDefaultFill settings, CancellationToken ct = default);
}
/// <summary>Calls the Domain Service's <c>POST /registrations</c>.</summary>
@@ -141,4 +155,14 @@ public sealed class AclClient(HttpClient http) : IAclClient
{
public async Task<IReadOnlyList<BeheerZaaktype>> GetZaaktypenAsync(CancellationToken ct = default)
=> await http.GetFromJsonAsync<List<BeheerZaaktype>>("catalogi/zaaktypen", ct) ?? [];
public async Task<BeheerDefaultFill> GetDefaultFillAsync(CancellationToken ct = default)
=> await http.GetFromJsonAsync<BeheerDefaultFill>("default-fill", ct)
?? throw new InvalidOperationException("The ACL returned an empty default-fill response.");
public async Task UpdateDefaultFillAsync(BeheerDefaultFill settings, CancellationToken ct = default)
{
using var response = await http.PutAsJsonAsync("default-fill", settings, ct);
response.EnsureSuccessStatusCode();
}
}
+19
View File
@@ -228,6 +228,25 @@ app.MapGet("/beheer/catalogi/zaaktypen", async (IAclClient acl, CancellationToke
.Produces(StatusCodes.Status401Unauthorized)
.Produces(StatusCodes.Status403Forbidden);
// Beheer default-fill config (S-15b): read + edit the ACL's default-fill values. Behind medewerker-
// realm + beheerder authorization; the BFF proxies the ACL (ADR-0025). The ACL validates the values.
app.MapGet("/beheer/default-fill", async (IAclClient acl, CancellationToken ct) =>
Results.Ok(await acl.GetDefaultFillAsync(ct)))
.RequireAuthorization(BeheerAuth.Policy)
.Produces<BeheerDefaultFill>(StatusCodes.Status200OK)
.Produces(StatusCodes.Status401Unauthorized)
.Produces(StatusCodes.Status403Forbidden);
app.MapPut("/beheer/default-fill", async (BeheerDefaultFill body, IAclClient acl, CancellationToken ct) =>
{
await acl.UpdateDefaultFillAsync(body, ct);
return Results.NoContent();
})
.RequireAuthorization(BeheerAuth.Policy)
.Produces(StatusCodes.Status204NoContent)
.Produces(StatusCodes.Status401Unauthorized)
.Produces(StatusCodes.Status403Forbidden);
app.Run();
/// <summary>The behandelaar's decision on a registration.</summary>
@@ -0,0 +1,84 @@
using System.Net;
using System.Net.Http.Headers;
using System.Net.Http.Json;
using Bff.Api;
namespace Bff.Tests;
/// <summary>
/// The beheer default-fill config endpoints (S-15b): read (GET) and edit (PUT) the ACL's default-fill,
/// reached only with a medewerker-realm token carrying the <c>beheerder</c> role. Missing token → 401;
/// a medewerker without the role → 403; a beheerder reads and updates via the ACL client.
/// </summary>
public class BeheerDefaultFillEndpointTests
{
private static HttpRequestMessage Get(string? bearer)
{
var r = new HttpRequestMessage(HttpMethod.Get, "/beheer/default-fill");
if (bearer is not null) r.Headers.Authorization = new AuthenticationHeaderValue("Bearer", bearer);
return r;
}
private static HttpRequestMessage Put(string? bearer, object body)
{
var r = new HttpRequestMessage(HttpMethod.Put, "/beheer/default-fill") { Content = JsonContent.Create(body) };
if (bearer is not null) r.Headers.Authorization = new AuthenticationHeaderValue("Bearer", bearer);
return r;
}
[Fact]
public async Task Rejects_read_without_a_token()
{
using var factory = new BffFactory();
var response = await factory.CreateClient().SendAsync(Get(bearer: null));
Assert.Equal(HttpStatusCode.Unauthorized, response.StatusCode);
}
[Fact]
public async Task Rejects_a_medewerker_without_the_beheerder_role()
{
using var factory = new BffFactory();
var response = await factory.CreateClient().SendAsync(Get(TestTokens.Medewerker("behandelaar")));
Assert.Equal(HttpStatusCode.Forbidden, response.StatusCode);
}
[Fact]
public async Task Serves_the_current_default_fill_to_a_beheerder()
{
using var factory = new BffFactory();
factory.Acl.DefaultFill = new BeheerDefaultFill("517439943", "517439943", "openbaar");
var response = await factory.CreateClient().SendAsync(Get(TestTokens.Medewerker("beheerder")));
Assert.Equal(HttpStatusCode.OK, response.StatusCode);
var body = await response.Content.ReadFromJsonAsync<BeheerDefaultFill>();
Assert.Equal("517439943", body!.Bronorganisatie);
Assert.Equal("openbaar", body.Vertrouwelijkheidaanduiding);
}
[Fact]
public async Task Updates_the_default_fill_via_the_acl_for_a_beheerder()
{
using var factory = new BffFactory();
var response = await factory.CreateClient().SendAsync(
Put(TestTokens.Medewerker("beheerder"),
new { bronorganisatie = "999999999", verantwoordelijkeOrganisatie = "888888888", vertrouwelijkheidaanduiding = "vertrouwelijk" }));
Assert.Equal(HttpStatusCode.NoContent, response.StatusCode);
Assert.Equal("999999999", factory.Acl.Updated!.Bronorganisatie);
Assert.Equal("vertrouwelijk", factory.Acl.Updated.Vertrouwelijkheidaanduiding);
}
[Fact]
public async Task Rejects_an_update_from_a_non_beheerder()
{
using var factory = new BffFactory();
var response = await factory.CreateClient().SendAsync(
Put(TestTokens.Medewerker("behandelaar"), new { bronorganisatie = "1", verantwoordelijkeOrganisatie = "2", vertrouwelijkheidaanduiding = "openbaar" }));
Assert.Equal(HttpStatusCode.Forbidden, response.StatusCode);
Assert.Null(factory.Acl.Updated);
}
}
+14 -1
View File
@@ -142,11 +142,24 @@ internal sealed class FakeProjectionClient : IProjectionClient
=> Task.FromResult<IReadOnlyList<ProjectionEntry>>(Entries);
}
/// <summary>Serves a configurable set of catalogus zaaktypen (beheer viewer, S-15a).</summary>
/// <summary>Serves catalogus zaaktypen (S-15a) and holds the default-fill settings (S-15b).</summary>
internal sealed class FakeAclClient : IAclClient
{
public List<BeheerZaaktype> Zaaktypen { get; } = [];
public Task<IReadOnlyList<BeheerZaaktype>> GetZaaktypenAsync(CancellationToken ct = default)
=> Task.FromResult<IReadOnlyList<BeheerZaaktype>>(Zaaktypen);
public BeheerDefaultFill DefaultFill { get; set; } = new("517439943", "517439943", "openbaar");
public BeheerDefaultFill? Updated { get; private set; }
public Task<BeheerDefaultFill> GetDefaultFillAsync(CancellationToken ct = default)
=> Task.FromResult(DefaultFill);
public Task UpdateDefaultFillAsync(BeheerDefaultFill settings, CancellationToken ct = default)
{
Updated = settings;
DefaultFill = settings;
return Task.CompletedTask;
}
}
+70
View File
@@ -255,10 +255,80 @@
}
}
}
},
"/beheer/default-fill": {
"get": {
"tags": [
"Bff.Api"
],
"responses": {
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/BeheerDefaultFill"
}
}
}
},
"401": {
"description": "Unauthorized"
},
"403": {
"description": "Forbidden"
}
}
},
"put": {
"tags": [
"Bff.Api"
],
"requestBody": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/BeheerDefaultFill"
}
}
},
"required": true
},
"responses": {
"204": {
"description": "No Content"
},
"401": {
"description": "Unauthorized"
},
"403": {
"description": "Forbidden"
}
}
}
}
},
"components": {
"schemas": {
"BeheerDefaultFill": {
"required": [
"bronorganisatie",
"verantwoordelijkeOrganisatie",
"vertrouwelijkheidaanduiding"
],
"type": "object",
"properties": {
"bronorganisatie": {
"type": "string"
},
"verantwoordelijkeOrganisatie": {
"type": "string"
},
"vertrouwelijkheidaanduiding": {
"type": "string"
}
}
},
"BeheerZaaktype": {
"required": [
"identificatie",