from __future__ import annotations from govoplan_core.core.access import CAPABILITY_AUTH_PERMISSION_EVALUATOR, CAPABILITY_AUTH_PRINCIPAL_RESOLVER from govoplan_core.core.modules import DocumentationLink, DocumentationTopic, ModuleManifest, PermissionDefinition, RoleTemplate MODULE_ID = "approvals" MODULE_NAME = "Approvals" MODULE_VERSION = "0.1.6" READ_SCOPE = "approvals:workspace:read" WRITE_SCOPE = "approvals:workspace:write" ADMIN_SCOPE = "approvals:workspace:admin" OPTIONAL_DEPENDENCIES = ( "workflow", "audit", "files", "notifications", ) def _permission(scope: str, label: str, description: str) -> PermissionDefinition: module_id, resource, action = scope.split(":", 2) return PermissionDefinition( scope=scope, label=label, description=description, category="Approvals", level="tenant", module_id=module_id, resource=resource, action=action, ) PERMISSIONS = ( _permission(READ_SCOPE, "View approvals workspace", "Read approvals records, configuration, and workflow context."), _permission(WRITE_SCOPE, "Manage approvals workspace", "Create and update approvals records and workflow state."), _permission(ADMIN_SCOPE, "Administer approvals workspace", "Configure approvals policies, templates, and tenant-level administration."), ) ROLE_TEMPLATES = ( RoleTemplate( slug="approvals_manager", name="Approvals manager", description="Manage approvals records and workflow state.", permissions=(READ_SCOPE, WRITE_SCOPE), ), RoleTemplate( slug="approvals_viewer", name="Approvals viewer", description="Read approvals records and workflow context.", permissions=(READ_SCOPE,), ), ) DOCUMENTATION = ( DocumentationTopic( id=f"{MODULE_ID}.module-boundary", title=f"{MODULE_NAME} module boundary", summary="Generic approval and sign-off chains with delegation, substitution, four-eyes principle, escalation, and signatures.", body=( "This repository is currently a platform module seed. It registers the domain boundary, " "permission surface, role templates, and documentation metadata before runtime APIs, " "database models, migrations, and WebUI routes are introduced." ), layer="available", documentation_types=("admin",), audience=("operator", "module_admin", "product_owner"), order=100, related_modules=OPTIONAL_DEPENDENCIES, links=( DocumentationLink( label="Repository domain boundary", href="govoplan-approvals/docs/APPROVALS_DOMAIN_BOUNDARY.md", kind="repository", ), ), metadata={ "seed": True, "domain_objects": ['approval requests', 'sign-off chains', 'delegation and substitution facts', 'four-eyes constraints', 'escalation state', 'signature references'], "first_slice": "Define reusable approval request, step, actor, delegation, substitution, and decision result contracts for consuming modules.", }, ), ) manifest = ModuleManifest( id=MODULE_ID, name=MODULE_NAME, version=MODULE_VERSION, dependencies=("access",), optional_dependencies=OPTIONAL_DEPENDENCIES, required_capabilities=(CAPABILITY_AUTH_PRINCIPAL_RESOLVER, CAPABILITY_AUTH_PERMISSION_EVALUATOR), permissions=PERMISSIONS, role_templates=ROLE_TEMPLATES, documentation=DOCUMENTATION, ) def get_manifest() -> ModuleManifest: return manifest