## What & why S-10b: the self-service **diploma upload** is now real. After submitting, the citizen picks a PDF and uploads it; the portal base64-encodes it client-side → BFF → domain → **ACL**, which stores it in the ZGW **Documenten (DRC) API** as an `enkelvoudiginformatieobject` and relates it to the zaak, then the `WachtOpDocumenten` wait completes and the case advances to beoordeling. Per §8.1 only the ACL talks to ZGW. Closes #103 Mechanism in **ADR-0018** (proposal #107). Builds on S-10a (#102). The zaak-close-on-expiry item is carved to **#106 (S-10c)**. ## Definition of Done - [x] Linked Gitea issue (above). - [x] Failing test committed before the implementation (red→green per layer). - [x] Conventional Commits referencing the issue (`refs #103`). - [ ] CI green — all Gitea Actions jobs (pending on this PR). - [x] `docker compose up` health unaffected (ACL boots on a placeholder informatieobjecttype URL; the real one is injected by verify-domain). - [x] Docs updated (ADR-0018, demo-script, BACKLOG + S-10c). - [x] ADR added (`docs/architecture/adr-0018-diploma-upload-via-acl-documenten.md`). - [x] Demo note in `docs/demo-script.md`. ## Notes for reviewers - **ACL** (`OpenZaakGateway.StoreDocumentAsync` + `AclService.StoreDiplomaAsync` + `POST /documenten`) reuses the existing gateway patterns (ZGW Bearer, buffered non-chunked body, **no CRS** — Documenten isn't geo). Unit-tested via the stub handler; an **integration test** stores a real document against live OpenZaak (verify-acl). - **Transport:** base64 JSON on every hop (portal encodes client-side) — I deviated from proposal #107's multipart to keep one contract shape and avoid `IFormFile`/antiforgery/multipart-client plumbing; fine at diploma size (ADR-0018 §Alternatives). - **Infra:** `seed_catalogus.py` seeds + publishes a "Diploma" `informatieobjecttype` and relates it to the zaaktype (while both concept); `verify-domain` injects its URL into the ACL. No new ZGW scopes (seed applicatie has `heeft_alle_autorisaties`). - **e2e:** uploads a real PDF (`setInputFiles`) after the openbaar INGEDIEND row confirms the zaak is open (so storage doesn't race the OpenZaak worker). - **Scope boundary:** the ZGW zaak is not set to a cancellation status on 30-day expiry — that's #106 (S-10c). 🤖 Generated with [Claude Code](https://claude.com/claude-code) Reviewed-on: #108
This commit was merged in pull request #108.
This commit is contained in:
@@ -124,6 +124,58 @@ def publish_zaaktype(zt):
|
||||
print("skip publish (already published)")
|
||||
|
||||
|
||||
def seed_informatieobjecttype(cat, zt):
|
||||
"""Create the "Diploma" informatieobjecttype and relate it to the zaaktype (both idempotent).
|
||||
|
||||
A diploma uploaded in S-10b is filed under this informatieobjecttype; OpenZaak only accepts a
|
||||
document (and its zaak relation) once the informatieobjecttype is published AND allowed for the
|
||||
zaak's zaaktype (a zaaktype-informatieobjecttype relation). Both the relation and this call must run
|
||||
while the zaaktype is still a concept, so seed this *before* publishing the zaaktype. Returns the
|
||||
informatieobjecttype dict.
|
||||
"""
|
||||
iots = [i for i in find(f"/informatieobjecttypen?catalogus={cat['url']}&status=alles")
|
||||
if i.get("omschrijving") == "Diploma"]
|
||||
if iots:
|
||||
iot = iots[0]
|
||||
print(f"skip informatieobjecttype Diploma ({iot['url']}) concept={iot.get('concept')}")
|
||||
else:
|
||||
st, iot = api("POST", "/informatieobjecttypen", {
|
||||
"catalogus": cat["url"],
|
||||
"omschrijving": "Diploma",
|
||||
"vertrouwelijkheidaanduiding": "openbaar",
|
||||
"informatieobjectcategorie": "diploma",
|
||||
"beginGeldigheid": "2026-01-01",
|
||||
})
|
||||
if st != 201:
|
||||
sys.exit(f"create informatieobjecttype -> {st}: {json.dumps(iot, indent=2)}")
|
||||
print(f"create informatieobjecttype Diploma ({iot['url']})")
|
||||
|
||||
# Relate it to the zaaktype (must be done while both are concept).
|
||||
relations = find(f"/zaaktype-informatieobjecttypen?zaaktype={zt['url']}&status=alles")
|
||||
if any(r.get("informatieobjecttype") == iot["url"] for r in relations):
|
||||
print("skip zaaktype-informatieobjecttype Diploma")
|
||||
else:
|
||||
st, body = api("POST", "/zaaktype-informatieobjecttypen", {
|
||||
"zaaktype": zt["url"], "informatieobjecttype": iot["url"],
|
||||
"volgnummer": 1, "richting": "inkomend"})
|
||||
if st != 201:
|
||||
sys.exit(f"relate zaaktype-informatieobjecttype -> {st}: {json.dumps(body, indent=2)}")
|
||||
print("create zaaktype-informatieobjecttype Diploma")
|
||||
|
||||
return iot
|
||||
|
||||
|
||||
def publish_informatieobjecttype(iot):
|
||||
"""Publish the informatieobjecttype (idempotent) so documents may reference it."""
|
||||
if iot.get("concept", True):
|
||||
st, body = api("POST", f"{iot['url']}/publish")
|
||||
if st != 200:
|
||||
sys.exit(f"publish informatieobjecttype -> {st}: {json.dumps(body, indent=2)}")
|
||||
print(f"publish informatieobjecttype Diploma ({iot['url']})")
|
||||
else:
|
||||
print("skip publish informatieobjecttype (already published)")
|
||||
|
||||
|
||||
def main():
|
||||
# 1. Catalogus
|
||||
existing = [c for c in find(f"/catalogussen?domein=BIG") if c.get("domein") == "BIG"]
|
||||
@@ -198,10 +250,16 @@ def main():
|
||||
# schema-mandatory" zaaktype S-01 asks for (ADR-0002). Set OZ_PUBLISH=1 to add
|
||||
# those relations and publish — needed so a real zaak POST is accepted, which
|
||||
# the ACL integration test (S-04a, #46) exercises. See ADR-0006.
|
||||
iot = None
|
||||
if PUBLISH:
|
||||
# Re-fetch: the bsn-eigenschap branch above may hold a stale concept flag.
|
||||
zt = next(z for z in find(f"/zaaktypen?catalogus={cat['url']}&status=alles")
|
||||
if z.get("identificatie") == "BIG-REGISTRATIE")
|
||||
# Seed + relate the Diploma informatieobjecttype (S-10b) while the zaaktype is still concept,
|
||||
# then publish both. Publish the informatieobjecttype before the zaaktype so the zaaktype's
|
||||
# relations reference a published type.
|
||||
iot = seed_informatieobjecttype(cat, zt)
|
||||
publish_informatieobjecttype(iot)
|
||||
publish_zaaktype(zt)
|
||||
|
||||
# 5. Verify the JWT client can list the zaaktype (concepts included).
|
||||
@@ -214,6 +272,10 @@ def main():
|
||||
# zaaktype URL to configure the ACL's default-fill (ADR-0003/0009).
|
||||
zt_url = next(z["url"] for z in zaaktypen if z.get("identificatie") == "BIG-REGISTRATIE")
|
||||
print(f"ZAAKTYPE_URL {zt_url}")
|
||||
# Machine-readable informatieobjecttype URL (S-10b) so callers can configure the ACL's document
|
||||
# default-fill. Only emitted when publishing — a concept informatieobjecttype can't back a document.
|
||||
if iot is not None:
|
||||
print(f"INFORMATIEOBJECTTYPE_URL {iot['url']}")
|
||||
print(f"OK — BIG catalogus seeded (BIG-REGISTRATIE {state} + bsn eigenschap)")
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user