Compare commits

...
10 Commits
Author SHA1 Message Date
zemion 11598b7b5b fix(ui): align campaign tables, recipient sizing and contextual help
Verified with the coordinated workspace changes by devkit full run
2026-09-08T225814-186389-0000-3e3ed7cd (all seven phases passed).
This shared UI pass does not mark the individual module reviews complete.
2026-09-09 02:03:36 +02:00
zemion 19437ce378 perf(campaign): share linear collision-safe attachment naming
Module Package Release / publish-packages (push) Successful in 13s
Release v0.1.29. Coordinated integrity review: GovOPlaN/govoplan-core#298.
2026-09-08 12:20:33 +02:00
zemion 8bca4fc728 perf(campaign): share linear collision-safe attachment naming
Release v0.1.29. Coordinated integrity review: GovOPlaN/govoplan-core#298.
2026-09-08 12:19:37 +02:00
zemion c51fc180fb Release govoplan-campaign v0.1.28: stabilize saving, review and delivery recovery
Module Package Release / publish-packages (push) Successful in 12s
2026-09-08 01:32:26 +02:00
zemion 1b32427813 fix(webui): bind consequential campaign controls to help
Module Package Release / publish-packages (push) Successful in 12s
2026-08-24 11:36:33 +02:00
zemion c21fb4cf7c docs: complete German structured documentation
Module Package Release / publish-packages (push) Successful in 12s
2026-08-24 01:15:32 +02:00
zemion b41f23c901 docs(campaign): complete German reference coverage
Module Package Release / publish-packages (push) Successful in 13s
2026-08-23 21:09:38 +02:00
zemion 3934e7fedb feat(campaigns): add portable campaign transfers
Module Package Release / publish-packages (push) Successful in 12s
2026-08-22 04:01:39 +02:00
zemion 1bd24f9b5b feat: orchestrate accountable Campaign work
Module Package Release / publish-packages (push) Successful in 13s
2026-08-22 02:14:35 +02:00
zemion 4f52f010ee fix(campaigns): declare work view surface
Module Package Release / publish-packages (push) Successful in 12s
2026-08-22 00:56:37 +02:00
138 changed files with 12449 additions and 1043 deletions
+12
View File
@@ -73,6 +73,18 @@ has a remaining occurrence, including while it is paused; once the schedule
finishes, already accepted Mail commands retain their own encrypted payload and
evidence under Mail policy.
Campaign versions can also be exported as versioned portable JSON packages and
imported as independently owned drafts. The privacy-safe export default is
metadata plus template/configuration. Recipients, attachment rules, aggregate
review state, and recipient-level delivery history are separate scopes with
their existing fine-grained permissions. Packages include source provenance,
scope/item/redaction manifests, and a SHA-256 integrity digest. They never
contain attachment bytes, transport secrets, credential references,
password-field values, local storage locators, shares, or ownership grants.
Import previews schema and checksum compatibility plus every created/skipped
domain. It clears deployment-bound Mail references and never replays locks,
approvals, review decisions, jobs, attempts, or sent state.
Public campaign, version, job, and report responses expose business data and
delivery evidence, but never process-local paths, storage-backend keys, or
worker claim tokens. Operational troubleshooting uses the dedicated job
+131 -14
View File
@@ -29,7 +29,7 @@ import tomllib
from collections import Counter
from contextlib import contextmanager
from dataclasses import dataclass
from datetime import datetime, timezone
from datetime import datetime, timedelta, timezone
from pathlib import Path
from typing import Any, Callable, Iterator, Mapping, Protocol
from uuid import uuid4
@@ -66,6 +66,7 @@ SEND_RESULT_STATUSES = frozenset(
{
"already_accepted",
"already_claimed",
"already_sending",
"cancelled",
"dry_run",
"failed",
@@ -135,11 +136,21 @@ SMTP_FAULT_MODES = frozenset(
}
)
WORKER_TASK_CODE = """
import os
import sys
from govoplan_core.celery_app import send_email
from types import SimpleNamespace
from govoplan_core.celery_app import send_email, _worker_runtime_identity
from govoplan_core.core.runtime_coordination import register_runtime_node
from govoplan_core.db.session import get_database
identity = _worker_runtime_identity(SimpleNamespace(hostname=f"campaign-acceptance-{os.getpid()}"))
with get_database().SessionLocal() as session:
register_runtime_node(session, identity, metadata={"acceptance_worker_pid": os.getpid()})
session.commit()
result = send_email.run(sys.argv[1])
if not isinstance(result, dict) or result.get("status") not in {
"already_sending",
"outcome_unknown",
"smtp_accepted",
}:
@@ -1206,6 +1217,92 @@ def _wait_for_worker_process(process: subprocess.Popen[bytes], *, timeout_second
raise AcceptanceError("Restarted Campaign worker task failed")
def recover_stopped_fixture_claim(
client: ApiClient, headers: Mapping[str, str], *, database: Any,
runtime_root: Path, campaign_id: str, version_id: str,
stopped_process: subprocess.Popen[bytes],
) -> dict[str, bool]:
"""Model supervisor proof ONLY in this runner's disposable SQLite fixture.
No job, attempt or recovery-operation state is edited here. After proving
the exact fixture process exited, expire only its lease and mark its own
runtime stopped. The real fenced HTTP action performs domain recovery.
"""
from sqlalchemy.engine import make_url
from sqlalchemy.exc import ArgumentError
from govoplan_core.core.runtime_coordination import DistributedLease, RuntimeNode, process_runtime_identity
from govoplan_campaign.backend.db.models import CampaignJob
from govoplan_campaign.backend.services.delivery_recovery import job_recovery_metadata
root = runtime_root.resolve()
expected_database = root / "acceptance.db"
allowed_parents = {Path(tempfile.gettempdir()).resolve(), Path("/tmp").resolve()}
if (
os.environ.get("APP_ENV") != "test"
or root.parent not in allowed_parents
or not root.name.startswith(("govoplan-campaign-greenmail-", "govoplan-campaign-celery-redelivery-"))
or not expected_database.is_file() or expected_database.is_symlink()
or database.engine.url.get_backend_name() != "sqlite"
or not database.engine.url.database
or Path(database.engine.url.database).resolve() != expected_database
):
raise AcceptanceError("Claim proof is restricted to the runner's isolated temporary SQLite fixture")
try:
environment_url = make_url(os.environ.get("DATABASE_URL", ""))
except ArgumentError:
raise AcceptanceError("Claim proof requires the isolated fixture database environment") from None
if (
environment_url.get_backend_name() != "sqlite" or not environment_url.database
or Path(environment_url.database).resolve() != expected_database
):
raise AcceptanceError("Claim proof database does not match the isolated fixture environment")
if stopped_process.poll() is None or stopped_process.returncode is None:
raise AcceptanceError("Claim proof requires the exact fixture worker to have exited")
identity = process_runtime_identity()
with database.SessionLocal() as session:
jobs = session.query(CampaignJob).filter(
CampaignJob.campaign_id == campaign_id,
CampaignJob.campaign_version_id == version_id,
).all()
if len(jobs) != 1 or jobs[0].send_status != "sending" or not jobs[0].claim_token:
raise AcceptanceError("Claim proof requires exactly one unfinished fixture send")
job = jobs[0]
lease = session.query(DistributedLease).filter(
DistributedLease.installation_id == identity.installation_id,
DistributedLease.resource_key == f"campaign:delivery:{job.tenant_id}:{job.id}",
).one_or_none()
node = session.query(RuntimeNode).filter(
RuntimeNode.installation_id == identity.installation_id,
RuntimeNode.node_id == lease.holder_node_id,
).one_or_none() if lease else None
if (
lease is None or node is None or node.incarnation != lease.holder_incarnation
or (node.metadata_ or {}).get("acceptance_worker_pid") != stopped_process.pid
):
raise AcceptanceError("Stopped fixture process does not own this exact runtime claim")
node.state = "stopped"
node.stopped_at = datetime.now(timezone.utc)
lease.expires_at = datetime.now(timezone.utc) - timedelta(seconds=1)
session.commit()
metadata = job_recovery_metadata(session, [job])[job.id]["smtp"]
if not metadata["eligible"]:
raise AcceptanceError("Proven stopped fixture claim is not eligible for fenced recovery")
job_id = job.id
revision = metadata["revision"]
payload = _expect(client.post(
f"/api/v1/campaigns/{campaign_id}/jobs/{job_id}/recover-claim",
headers=dict(headers),
json={
"channel": "smtp", "expected_revision": revision,
"note": "Verified isolated fixture worker exited after DATA; expired its test lease. Mailbox/provider reconciliation is still required.",
},
), 200, "Explicit fenced fixture claim recovery")
result = payload.get("result") if isinstance(payload.get("result"), dict) else {}
if result.get("send_status") != "outcome_unknown" or result.get("reconciliation_required") is not True:
raise AcceptanceError("Fenced recovery did not preserve the unknown SMTP outcome")
return {"stopped_process_verified": True, "fixture_lease_expired": True, "explicit_fenced_recovery": True}
def execute_worker_interruption_scenario(
client: ApiClient,
headers: Mapping[str, str],
@@ -1218,6 +1315,7 @@ def execute_worker_interruption_scenario(
audit_probe: Callable[[str, str], Mapping[str, int]],
delivery_probe: Callable[[str, str], Mapping[str, Any]],
worker_job_probe: Callable[[str], str],
recover_claim: Callable[[str, str, subprocess.Popen[bytes]], Mapping[str, Any]],
) -> dict[str, Any]:
prepared = prepare_campaign_scenario(
client,
@@ -1286,23 +1384,30 @@ def execute_worker_interruption_scenario(
restarted_state = _durable_state_evidence(
delivery_probe(prepared.campaign_id, prepared.version_id)
)
expected_restarted_state = {
if restarted_state != interrupted_state:
raise AcceptanceError("Duplicate task changed an unfinished SMTP attempt without stopped-runtime proof")
protocol_evidence = endpoint.evidence()
expected_protocol = {
"connection_count": 1,
"accepted_rcpt_commands": 1,
"refused_rcpt_commands": 0,
"data_transactions": 1,
}
if protocol_evidence != expected_protocol:
raise AcceptanceError("Restarted worker contacted SMTP or produced an unexpected transaction")
recovery_evidence = dict(recover_claim(prepared.campaign_id, prepared.version_id, first_worker))
recovered_state = _durable_state_evidence(delivery_probe(prepared.campaign_id, prepared.version_id))
expected_recovered_state = {
"job_count": 1,
"send_status_counts": {"outcome_unknown": 1},
"attempt_status_counts": {"outcome_unknown": 1},
"unfinished_attempt_count": 0,
}
if restarted_state != expected_restarted_state:
raise AcceptanceError("Restarted worker did not freeze the unfinished SMTP attempt")
protocol_evidence = endpoint.evidence()
if protocol_evidence != {
"connection_count": 1,
"accepted_rcpt_commands": 1,
"refused_rcpt_commands": 0,
"data_transactions": 1,
}:
raise AcceptanceError("Restarted worker contacted SMTP or produced an unexpected transaction")
if recovered_state != expected_recovered_state:
raise AcceptanceError("Explicit fenced recovery did not freeze the unfinished SMTP attempt")
if endpoint.evidence() != expected_protocol:
raise AcceptanceError("Explicit claim recovery contacted SMTP")
report = _expect(
client.get(
@@ -1333,12 +1438,15 @@ def execute_worker_interruption_scenario(
"queue": queue_evidence,
"interrupted_durable_state": interrupted_state,
"restarted_durable_state": restarted_state,
"recovered_durable_state": recovered_state,
"claim_recovery": recovery_evidence,
"protocol": protocol_evidence,
"report": report_evidence,
"audit_actions": audit_actions,
"process_boundary": {
"dedicated_task_process_terminated_after_data": True,
"fresh_task_process_completed": True,
"duplicate_task_left_sending_unchanged": True,
"duplicate_smtp_transaction_prevented": True,
"celery_broker_redelivery_exercised": False,
},
@@ -1355,6 +1463,7 @@ def run_acceptance(
audit_probe: Callable[[str, str], Mapping[str, int]],
delivery_probe: Callable[[str, str], Mapping[str, Any]],
worker_job_probe: Callable[[str], str],
recover_claim: Callable[[str, str, subprocess.Popen[bytes]], Mapping[str, Any]],
include_failure_drills: bool,
module_versions: Mapping[str, str],
) -> dict[str, Any]:
@@ -1619,6 +1728,7 @@ def run_acceptance(
audit_probe=audit_probe,
delivery_probe=delivery_probe,
worker_job_probe=worker_job_probe,
recover_claim=recover_claim,
)
drills["worker_interruption"] = worker_interruption
@@ -1647,6 +1757,8 @@ def run_acceptance(
"post_data_connection_loss_outcome_unknown": include_failure_drills,
"source_artifact_provenance": False,
"worker_restart_interruption": include_failure_drills,
"duplicate_worker_leaves_active_claim_unchanged": include_failure_drills,
"explicit_stopped_runtime_fenced_recovery": include_failure_drills,
"celery_broker_redelivery": False,
},
}
@@ -1888,6 +2000,11 @@ def _bootstrap_and_run(
audit_probe=audit_probe,
delivery_probe=delivery_probe,
worker_job_probe=worker_job_probe,
recover_claim=lambda campaign_id, version_id, process: recover_stopped_fixture_claim(
client, {"Authorization": f"Bearer {access_token}"}, database=database,
runtime_root=runtime_root, campaign_id=campaign_id, version_id=version_id,
stopped_process=process,
),
include_failure_drills=include_failure_drills,
module_versions=module_versions,
)
@@ -5,8 +5,9 @@ The default run starts an isolated Redis Compose service, two successive real
Celery worker processes, and a controlled loopback SMTP endpoint. It kills the
first worker after complete DATA but before a final SMTP response. The same
unacknowledged broker task must be delivered to the replacement worker, which
must freeze the unfinished durable attempt as ``outcome_unknown`` without a
second SMTP connection or DATA transaction.
must leave the unfinished durable attempt unchanged without a second SMTP
connection or DATA transaction. Only then does explicit fenced recovery use
verified process exit and an expired fixture lease to record outcome-unknown.
"""
from __future__ import annotations
@@ -52,6 +53,7 @@ from run_campaign_acceptance import ( # noqa: E402
create_mail_profile,
prepare_campaign_scenario,
required_composition_versions,
recover_stopped_fixture_claim,
smtp_fault_endpoint,
)
@@ -72,6 +74,13 @@ import os
import sys
from govoplan_core.celery_app import celery
from govoplan_core import celery_app as worker_runtime
# Test-only process identity evidence, confined to this disposable child.
original_worker_metadata = worker_runtime._worker_metadata
worker_runtime._worker_metadata = lambda: {
**original_worker_metadata(), "acceptance_worker_pid": os.getpid(),
}
visibility_timeout = int(os.environ["GOVOPLAN_CAMPAIGN_TEST_REDIS_VISIBILITY_TIMEOUT_SECONDS"])
celery.conf.broker_transport_options = {
@@ -408,6 +417,7 @@ def execute_redelivery_scenario(
snapshot_probe: Callable[[str], tuple[Mapping[str, Any], Mapping[str, Any]]],
audit_probe: Callable[[str, str], Mapping[str, int]],
delivery_probe: Callable[[str, str], Mapping[str, Any]],
recover_claim: Callable[[str, str, subprocess.Popen[bytes]], Mapping[str, Any]],
) -> dict[str, Any]:
profile_id = create_mail_profile(
client,
@@ -488,9 +498,23 @@ def execute_redelivery_scenario(
task_id=redelivered_task_id,
timeout_seconds=settings.provider_timeout_seconds,
)
recovered_state = _durable_state_evidence(
redelivered_state = _durable_state_evidence(
delivery_probe(prepared.campaign_id, prepared.version_id)
)
if redelivered_state != interrupted_state:
raise AcceptanceError("Redelivered task changed an unfinished attempt without stopped-runtime proof")
expected_protocol = {
"connection_count": 1,
"accepted_rcpt_commands": 1,
"refused_rcpt_commands": 0,
"data_transactions": 1,
}
if endpoint.evidence() != expected_protocol:
raise AcceptanceError("Broker redelivery caused an unexpected SMTP transaction")
recovery_evidence = dict(recover_claim(
prepared.campaign_id, prepared.version_id, first_worker.process,
))
recovered_state = _durable_state_evidence(delivery_probe(prepared.campaign_id, prepared.version_id))
expected_recovered = {
"job_count": 1,
"send_status_counts": {"outcome_unknown": 1},
@@ -498,17 +522,11 @@ def execute_redelivery_scenario(
"unfinished_attempt_count": 0,
}
if recovered_state != expected_recovered:
raise AcceptanceError("Redelivered task did not freeze the unfinished attempt")
raise AcceptanceError("Explicit fenced recovery did not freeze the unfinished attempt")
protocol = endpoint.evidence()
expected_protocol = {
"connection_count": 1,
"accepted_rcpt_commands": 1,
"refused_rcpt_commands": 0,
"data_transactions": 1,
}
if protocol != expected_protocol:
raise AcceptanceError("Broker redelivery caused an unexpected SMTP transaction")
raise AcceptanceError("Explicit claim recovery caused an unexpected SMTP transaction")
broker_after = _wait_for_broker_drained(
redis_url,
timeout_seconds=settings.provider_timeout_seconds,
@@ -549,7 +567,9 @@ def execute_redelivery_scenario(
**prepared.public_evidence(),
"queue": queue_evidence,
"interrupted_durable_state": interrupted_state,
"redelivered_durable_state": redelivered_state,
"recovered_durable_state": recovered_state,
"claim_recovery": recovery_evidence,
"protocol": protocol,
"report": report,
"audit_actions": audit_actions,
@@ -566,6 +586,7 @@ def execute_redelivery_scenario(
"first_worker_forced_exit": first_exit_code != 0,
"replacement_worker_started": True,
"replacement_worker_completed_redelivery": True,
"duplicate_task_left_sending_unchanged": True,
},
}
finally:
@@ -743,6 +764,11 @@ def _bootstrap_and_run(
snapshot_probe=snapshot_probe,
audit_probe=audit_probe,
delivery_probe=delivery_probe,
recover_claim=lambda campaign_id, version_id, process: recover_stopped_fixture_claim(
client, {"Authorization": f"Bearer {access_token}"}, database=database,
runtime_root=runtime_root, campaign_id=campaign_id, version_id=version_id,
stopped_process=process,
),
)
evidence = {
@@ -766,6 +792,8 @@ def _bootstrap_and_run(
"celery_worker_processes": True,
"forced_worker_loss_after_complete_data": True,
"same_task_broker_redelivery": True,
"redelivery_leaves_active_claim_unchanged": True,
"explicit_stopped_runtime_fenced_recovery": True,
"durable_outcome_unknown_recovery": True,
"duplicate_smtp_transaction_prevented": True,
"production_daemon_supervisor": False,
+104 -13
View File
@@ -30,9 +30,24 @@ been validated, built, reviewed, and locked.
for attempts, outcomes, and reconciliation.
- Confirm the effective Send now recipient-job limit. The safe default is 25;
use Queue for workers for ordinary batches or any run above that limit.
System administrators can explicitly configure 0500 under Administration →
SYSTEM → Campaign delivery; an explicit deployment ceiling remains binding,
and TENANT policy may only narrow the inherited limit. This setting affects
one synchronous request, not campaign size. It is audited and never sends
messages; large interactive requests may encounter proxy timeouts.
## Deliverability Preflight
The Mail server connection test checks that selected server and credential. It
does not authorize the campaign's sender, recipients, or resource selection.
SMTP runtime checks require the selected SMTP credential when policy forbids
inheritance, independently of IMAP. Sent-folder append checks IMAP credentials
independently; full campaign validation still checks both required selections.
Preflight errors distinguish Mail profile/credential policy, SMTP configuration,
authentication, and connectivity. Do not change TLS or credential policies merely
because a campaign preflight failed. A preflight rejection leaves staged jobs
uncommitted and starts no message delivery.
Before the first live send for a sender domain or mail-server profile:
- Confirm the selected SMTP identity matches the visible From/envelope sender
@@ -50,18 +65,25 @@ Before the first live send for a sender domain or mail-server profile:
## Queue And Send
1. Validate the version with file checks enabled.
1. Link all required managed files, then validate the version with file checks
enabled. Locking waits for a fresh attachment preview and asks for explicit
**Link and lock** confirmation when matches are not linked. A locked version
cannot change attachment links: use an editable version and repeat validation,
build and review rather than assuming unlinked files were included.
2. Build the version and inspect all blocking review items.
3. Queue only after the selected version is the intended immutable execution
version. Select **Queue for workers**, then verify the committed and
published counts.
4. Use **Send now** only if the exact eligible count is non-zero and at or below
the effective deployment/tenant limit shown on the page.
the effective deployment/system/tenant limit shown on the page.
5. In worker mode, verify queue counters move from queued/claimed/sending to a
terminal SMTP state.
6. If a synchronous request is used, keep Review and send open: it polls the
durable counters while the request runs. A rejection occurs before SMTP and
directs oversized runs to workers.
6. If a synchronous request is used, keep its blocking progress dialog open.
Only its small version-scoped persisted counters refresh; the workspace,
recipient list, attachment preview and full summary stay unchanged. Read-only
refresh failure retains the last counters and does not prove delivery failed.
A disconnected request may still be executing; never repeat it blindly.
Oversized initial runs are rejected before SMTP and directed to workers.
7. Review the SMTP batch line. `ready` means DNS/connectivity/TLS/auth preflight
succeeded. Connection and reconnect counts explain reuse. `paused` means a
systemic transport failure stopped the remaining jobs before their SMTP
@@ -97,9 +119,10 @@ unknown provider attempt merely to repair the other layer's state.
unavailable connectivity affect the batch rather than one recipient.
- `outcome_unknown`: Do not retry directly. Check SMTP logs, mailbox evidence, or
provider control panels, then reconcile as accepted or not sent.
- `claimed` or `sending` that does not progress: treat as a worker interruption.
Re-run worker handling or reconcile if SMTP may already have accepted the
message.
- `claimed` or `sending` that does not progress: investigate the owning runtime.
Duplicate worker handling leaves active state unchanged. Never infer from
elapsed time alone that SMTP did not accept the message. Use the fenced
**Recover interrupted claim** action described below when it is available.
- IMAP `appending`: A worker owns the durable append claim. Do not start a
second append; if the worker cannot finish, reconcile only after checking the
mailbox.
@@ -117,6 +140,65 @@ unknown provider attempt merely to repair the other layer's state.
- Add a note that identifies the evidence used, for example SMTP log line,
provider message ID, or operator ticket.
For pure-Mail SMTP and channel-specific IMAP operations, reconciliation updates
the original Campaign attempt, matching Campaign recovery operation and audit
record atomically under a fresh lease. A SMTP-only decision cannot resolve an
entire compound Mail/Postbox/Print operation; that ledger remains separately
unresolved until all of its effects are established. Campaign does
not rewrite Mail-owned nested provider-effect operations: those remain Mail's
separate evidence and operational responsibility. A failed audit or conflicting
claim must leave the prior unknown state intact.
### Recovery without workers
The Report offers explicit inline retry and continuation when workers are not
configured. Retry uses `campaigns:campaign:retry` plus
`campaigns:campaign:send`; continuation uses `campaigns:campaign:queue` plus
`campaigns:campaign:send`. Both use the canonical immutable jobs and ordinary
attempt ledger, not a separate one-message resend. Current Mail authorization,
review/approval, execution integrity, retry limits and rate limits still apply.
Each call is bounded by the effective synchronous recipient-job limit and
reports remaining eligible work. Continue explicitly until none remains; it
never selects accepted, excluded, active, uncertain or known failed jobs.
Known failures have their own explicit retry action. These actions do not
turn a long HTTP request into a background worker or guarantee exactly-once
SMTP when a provider acknowledgement is lost.
For an abandoned active SMTP or IMAP claim, the report exposes recovery only
after the original durable lease expires **and** the runtime registry proves
that its owner stopped or was replaced. A stale heartbeat is insufficient.
The opaque claim revision and original recovery evidence are rechecked under a
fresh lease. Recovery records the effect as **outcome unknown**, never not sent.
Then separately inspect external evidence and reconcile with a factual note
before any retry. This requires `campaigns:campaign:reconcile`. If the original
lease, evidence, or stopped-owner proof is missing, preserve the records and
investigate through Ops; do not edit delivery rows or force a lease expiry in
a real installation.
### Progress totals and Sent-folder batching
For each channel, **processed** includes successful, failed, uncertain and
cancelled outcomes. **In progress** is separate from pending, so the currently
sending/appending message remains visible. Paused SMTP work is also separate.
Excluded/non-requested channel work is outside the denominator. The endpoint
requires campaign read and object access and returns no recipient addresses,
message bodies, attachments or credentials. It is not the privacy-thresholded
aggregate Reports view and does not grant that view recipient access.
Append-to-Sent targets the selected campaign version, not all historical
versions. Each message remains a separately fenced, sequential IMAP APPEND.
Mail reuses the authenticated session and resolved folder for at most 100
messages or 300 seconds by default, then rotates the connection. Current
authorization, frozen transport revisions, credentials and recovery checks
still run for every message. A stale idle connection is checked before another
APPEND; an uncertain APPEND is never replayed. This removes repeated
connect/login/folder-list round trips, not the time needed to upload each EML.
It is not an atomic MULTIAPPEND transaction or parallel delivery.
SMTP and IMAP use the same progress dialog. An acknowledged operation remains
successful even if loading its follow-up diagnostics fails: use Reload to
refresh display, not to repeat the external effect.
## Fault Injection Checklist
Use mock infrastructure first, then repeat against the non-production real test
@@ -141,17 +223,21 @@ deliberately excluded.
The runner also terminates a dedicated OS process executing the registered
Campaign send task after complete DATA, then invokes the task in a fresh
process. The unfinished durable attempt must become `outcome_unknown` and the
endpoint must observe no second connection or DATA transaction. This covers
the worker task/process boundary but not a broker or daemon.
process. Redelivery must leave the active claim unchanged and the endpoint
must observe no second connection or DATA transaction. Only a subsequent
explicit, fenced recovery with test-fixture stopped-owner and expired-lease
proof may change the unfinished attempt to `outcome_unknown`. This covers the
worker task/process boundary but not a broker or daemon.
Run `dev/mail-testbed/run_celery_redelivery_acceptance.py` for the maintained
Redis/Celery delivery and broker redelivery boundary. It starts an isolated
Redis Compose service and real Celery workers, kills the first solo worker after complete DATA while the
late-ack task is unacknowledged, and requires the same task identity to reach a
replacement worker after Redis visibility recovery. Passing evidence also
requires durable `outcome_unknown`, an empty broker queue/unacked set, and
exactly one SMTP connection and DATA transaction. Raw worker logs and task,
requires unchanged active state on duplicate delivery, followed by explicit
fenced recovery to `outcome_unknown`, an empty broker queue/unacked set, and
exactly one SMTP connection and DATA transaction. Lease expiration is simulated
only in the isolated fixture after its owner was stopped. Raw worker logs and task,
database, endpoint, and credential identifiers are never retained.
That second runner proves local runner-supervised process replacement, not the
@@ -190,6 +276,11 @@ and retention.
## Reporting Checks
- The recipient-aware report shows every frozen To/Cc/Bcc address in authored
order, with a primary-address fallback only for old rows without that snapshot.
SMTP envelope evidence, not the old primary-only UI, establishes how many
recipients were actually offered to the provider. SMTP and IMAP diagnostics
use list filters and consistent translated labels.
- Partial delivery must show accepted, failed, and unknown counts separately.
- Excluded messages must show SMTP and IMAP as `skipped`, with skipped counts
and filters separate from unattempted or failed delivery.
+273 -5
View File
@@ -138,6 +138,35 @@ Notifications. The thread displays only human discussion; approvals, workflow
state, delivery events, and durable system evidence remain on their owning
surfaces and in Tenant audit.
### Assign accountable campaign work
Open **Work** to assign one bounded purpose to an account, group, or
organization function that already has Campaign access. Assignment records
responsibility only: it never creates a share, transfers ownership, or grants a
permission. Assignees may accept, complete, or reject their work; rejection is
distinct from administrative cancellation. Managers may reassign or cancel
open work, and every transition retains the expected revision, actor snapshot,
typed target, and append-only event history.
Workflow may create or reference a Campaign and open the same assignment through
the optional `campaigns.workOrchestration` capability. Those assignments pin the
Campaign version and store the Workflow instance, step, correlation, and
idempotency provenance. Campaign emits `campaign.work.changed` for assignment,
acceptance, start, reassignment, completion, rejection, and cancellation.
Workflow uses the assignment ID and event revision, rechecks current Campaign
access, and then resumes the matching durable external hand-off without browser
polling. A missing Tasks or Notifications capability only removes the optional
projection or notification. A missing Campaign provider, revoked Campaign
access, or stale event revision keeps the Workflow blocked and inspectable.
Campaign also contributes the opt-in **Accountable Campaign work hand-off**
Workflow template. It is deliberately not activated on installation. A
configurator must copy or activate it and supply either `campaign_id` or
`create_campaign`; unused optional input keys must be present with `null`
values. The template prepares the assignment idempotently, opens the exact
Campaign work URL, and waits for completion, rejection, cancellation, or the
configured timeout. Opening the link never completes the Workflow.
### Prepare a campaign
1. Create a campaign and confirm its owner or owning group.
@@ -157,6 +186,11 @@ surfaces and in Tenant audit.
password generator keeps its candidate separate from the form until **Use
password** is explicitly confirmed. Copying a candidate does not save or
submit it.
If legacy transport data is reported, choose **Migrate selected Mail
profile**, including when the existing profile selection is unchanged.
Follow a locked version's supported unlock or editable-successor action
before migration. Migration is explicit and audited, never sends mail, and
requires validation, build, and review again.
6. Save the editable version, validate the relevant sections, and resolve every
blocking issue. Warnings remain explicit review decisions.
7. Build the exact messages and inspect recipient, addressing, template,
@@ -166,11 +200,77 @@ If a selected optional module is absent, Campaign remains loadable and explains
which function is unavailable. It must not fail startup because Mail, Files, or
Addresses is not installed.
Opening or leaving Template without editing does not change the saved HTML or
mark the page dirty. Visual/source inspection and read-only changes likewise
do not require a save. Actual saves send only client-owned editor metadata. Review
and approval evidence remains server-owned and cannot be overwritten by an
ordinary editor save. Omitting that readable evidence from a save does not
delete it; normal version-lock and invalidation rules remain authoritative.
### Preserve recipient address order
In an individual or global address dialog, use the up/down actions to arrange
the addresses, then choose **Save** in the dialog. The campaign draft keeps that
order; saving no longer alphabetically sorts it. Duplicate email addresses keep
their first position, and pasted addresses append in their entered order.
The first individual To address is also the primary name/email shown in the
recipient row. Use the page's **Save** to persist the campaign draft. A rejected
page save keeps the reordered draft for an explicit retry. **Cancel** in the
dialog discards only its unconfirmed changes.
### Permit Legacy ZipCrypto as an explicit compatibility exception
AES remains the secure default. Campaign **Settings**, **Policies**, and
**Attachments** expose the effective archive policy, configuration links for
authorized administrators, and **Reload archive policy**.
1. A policy administrator opens **Administration → SYSTEM → Campaign archive
encryption**, enables **Legacy ZipCrypto**, and saves. The controls work
before the first system override exists; opening defaults alone does not
create an override or unsaved changes. Changing this global ceiling requires
both `system:settings:write` and `admin:policies:write`; tenant policy
authority alone cannot loosen it.
2. Check tenant and owner policy restrictions. Lower scopes may narrow, never
loosen, inherited methods and password-delivery channels.
3. The Campaign actor also needs `campaigns:archive:use_legacy_zipcrypto` and
edit access to the selected version. Policy administration does not replace
that dedicated permission.
4. Return to Campaign, reload archive policy, and select **Legacy ZipCrypto**
under **Attachments → ZIP attachments**. Acknowledge weak encryption, enter
an operational reason of at least 10 characters, and select an allowed
separate password-delivery channel.
5. Save, validate, build, and review. Policy/configuration saves never send
mail; delivery remains a separate action.
Legacy remains blocked while Policy is unavailable. Neither an encryption
error nor an incompatible client causes automatic fallback from AES to
ZipCrypto. The build retains policy and acknowledgement evidence but never the
password; see the manifest topic `campaigns.archive-encryption-governance`.
Mail migration and ZIP corrections can be saved in either order. A Mail-only
migration preserves unchanged ZIP settings without granting permission to use
them or adding acknowledgement evidence. An archive correction with unchanged
Mail references preserves legacy transport server-side until its separate,
explicit migration. Changes to ZIP settings still require the current policy
and any dedicated legacy permission; changes to Mail references still require
authorized migration. Validate, build and review again after both repairs.
A save and the following workspace refresh are separate operations. A failed
refresh does not undo a committed save or clear the last usable workspace.
Keep any newer unsaved edits, inspect the refresh error, and use Reload to fetch
the current state. Responses for an earlier campaign, version or signed-in
identity cannot overwrite the current workspace.
### Review and complete review
The reviewer should verify the immutable candidate that will be delivered, not
just the authoring form:
If a legacy Mail migration notice appears, follow **Open Mail settings** for
that exact version, complete migration, and validate and build again. Review
stays read-only until migration is resolved and does not repeatedly request
an attachment preview that the legacy transport boundary must reject.
1. Confirm purpose, owner, selected version, and recipient count.
2. Inspect blocking errors, warnings, exclusions, and recipients requiring
review.
@@ -194,6 +294,67 @@ the required action, the responsible role, and the workspace to open. The
review summary keeps reviewed and remaining counts visible; a completed review
acknowledges the group items and remains bound to the current build token.
Save each individual acceptance to persist its reason and reviewed state before
completing the entire review. Wait for acknowledgement; reloading then resumes
that build's saved progress. If saving fails or conflicts, the pending note
remains available for an explicit retry rather than becoming a false success.
This small save only loads the selected persisted jobs: it does not rebuild
messages, materialize attachments, or reload the whole workspace. Another
reviewer's existing decisions and attribution remain intact. Partial progress
does not enable delivery; final completion still checks the complete build.
Use **Accept similar review conditions** to record the same decision for a
counted selection of currently loaded matching messages. The server defines
eligible categories from the complete combination of overridable conditions;
the UI does not interpret a warning badge as permission to override. Select
one category, inspect the listed recipients, deselect any exceptions and enter
a common reason (required for attachment exceptions). A submission contains
at most 200 explicit message IDs. When more remain, save this selection and
reopen the dialog; the counts never imply acceptance of unloaded messages or
other categories. The reason is recorded separately against each selected
message's frozen evidence. A failed save retains the selection and reason for
an explicit retry, while a changed build prevents stale acceptance. This
action neither sends messages nor completes the final review gate. Hard
blockers cannot be accepted this way. Deliberate policy exclusions and
attachment rules that explicitly permit zero matches remain informational
and do not require review decisions.
An optional rule with explicit `missing_behavior: continue` may yield no files
without creating review work; that outcome remains informational evidence.
Required attachment and hard-block policies cannot be weakened by this setting.
The separate policy for sending a wholly attachment-free message still applies.
Rebuild existing messages after changing attachment policy; historical build
evidence is not rewritten.
The incremental review API uses `merge_progress: true`, the acknowledged
`base_revision`, and `build_token` set to the public `review_build_token`.
It merges exact reviewed keys/decision job IDs for the current build, with an
optional `decision_category_key` to bind a grouped acceptance. The safe review
reference is available without diagnostic access; raw build tokens remain
diagnostic data. Stale build/revision or simultaneous writes return HTTP 409
without overwriting progress. Normal review authorization and audit apply.
Accepted or expected attachment conditions remain satisfied in **Confirm and
send** for the same build. Raw missing/ambiguous source counts remain visible
for context; they are not a second approval gate. Reviewed-stage mock delivery
uses `use_reviewed_build: true`: it verifies the existing execution seal,
completed review, frozen job issues and EML integrity, and current Mail transport
before capturing anything in the mock mailbox. It uses those stored messages,
not freshly rendered replacements, and never mutates Campaign delivery state.
Stale review, changed inputs, changed bytes or changed transport stop the test
before captures or requested mailbox clearing. The authoring/mock-preview API
keeps its existing transient-build default; `include_needs_review` does not
bypass frozen review checks.
Validation details and repeated-file lists use the shared DataGrid pagination
controls so every item is reachable. Related missing-rule causes and their
attachment-free policy outcomes appear together, with the technical evidence
still expandable. Built messages have four operational states: **Ready**,
**Needs review**, **Blocked**, and **Excluded**, plus an explanatory column.
Accepted explicit decisions are Ready; warnings awaiting acknowledgment remain
Needs review. This presentation does not remove or rewrite frozen issues or
audit evidence.
This evidence is the Campaign input to separation-of-duties policy. Generic
approve/reject chains, delegation, substitutions, escalation, and signatures
belong to the optional Approvals capability. Campaign must not claim an
@@ -250,7 +411,7 @@ At a minimum:
ordinary batches; the durable progress remains visible after leaving and
returning to Review and send.
2. Use **Send now** only when the exact persisted eligible build is within the
effective synchronous limit shown by the UI. The default deployment limit
effective synchronous limit shown by the UI. The unchanged default limit
is 25 recipient jobs. The backend repeats the count and preflights every
message and the Mail profile revision before contacting SMTP.
3. Treat `smtp_accepted` as protected from ordinary retry.
@@ -273,10 +434,24 @@ Pause stops new eligible work but cannot undo a provider effect already in
progress. Cancel marks work that has not yet produced a protected SMTP outcome;
it cannot recall accepted mail.
The deployment ceiling is configured with
`GOVOPLAN_CAMPAIGN_SYNCHRONOUS_SEND_MAX_RECIPIENTS` (0 disables Send now; the
accepted range is 0500). A tenant may only narrow that ceiling with
`tenant.settings.campaign_delivery_policy.synchronous_send_max_recipients`.
Configure **Administration → SYSTEM → Campaign delivery** with
`system:settings:read/write`. The default stays 25, but an administrator may
explicitly choose 0500, for example 200 for a 183-recipient-job run. Zero disables
Send now. **TENANT → Campaign delivery** uses `admin:policies:read/write` and may
only narrow the inherited system policy. Clearing an override restores
inheritance. An explicitly configured deployment ceiling
`GOVOPLAN_CAMPAIGN_SYNCHRONOUS_SEND_MAX_RECIPIENTS` remains authoritative; the
implicit default does not prevent a system administrator choosing a larger
bounded value. Save changes only this setting, preserves unrelated settings,
checks a revision token including inherited policy, and records before/after
configuration history and audit. Failed saves retain the draft; conflicting
saves require explicit reload/reconciliation. Policy edits never send mail or
change existing reviews or approval requirements.
This limit applies to one interactive Send now request, not campaign size or
worker batching. Larger interactive requests run longer and can meet proxy
timeouts. Queue for workers is independent and requires enabled, healthy
Redis/Celery infrastructure; changing the numeric limit does not start workers.
The effective value and source are returned by the protected delivery-options
API, recorded for successful/rejected synchronous commands, and stated in the
configured handbook topic.
@@ -303,6 +478,32 @@ default.
## Data and evidence model
### Portable Campaign transfer
Campaign offers two reuse paths with different boundaries. **Copy campaign**
creates another campaign inside the same installation and can reuse selected
local shares, policies, and Mail profile references. **Export package** creates
a versioned JSON hand-off whose selected scopes can cross an installation
boundary; **Import package** always creates a separately owned draft.
The export dialog starts with only metadata and template/configuration. Add
recipients, attachment rules, review state, or delivery history only when the
handoff requires them and the destination and retention are approved. Recipient
and delivery scopes remain protected by recipient/report export permissions.
Transport secrets, credential references, password-field values, local storage
locators, and attachment bytes are always removed. The manifest records scope
counts and redactions, while the envelope carries source Campaign/version
provenance and a SHA-256 digest.
Import verifies format, scope, checksum, schema, and destination identity before
showing the plan. Editing the destination identity or selected scopes makes the
preview stale and requires a new check. The apply step clears source Mail
references, creates one editable draft, and stores a bounded source/package and
created/skipped receipt. Historical validation/build summaries, review state,
approvals, delivery jobs, attempts, and sent outcomes are never replayed. File
content is never embedded, so reconnect managed files and local Mail profiles,
then validate, build, review, and approve normally.
### Versions and snapshots
Editable campaign JSON is versioned. Build creates recipient jobs and an
@@ -411,6 +612,73 @@ create an editable successor.
## Operations and recovery
### Interactive delivery and Sent-folder progress
Send now and workerless Report retry/continue use a compact blocking progress
dialog, as does inline append-to-Sent. It refreshes saved counters only, not the
whole campaign behind the overlay. Successful, pending, in-progress, failed,
uncertain and excluded messages are shown separately; a currently sending or
appending message therefore does not disappear between totals. Read errors keep
the last known counters. After a connection interruption, processing may still
be running; inspect saved evidence before repeating any action. A successful
write is not reclassified as failed when its later display refresh fails.
The recipient-aware Report shows all frozen To, Cc and Bcc addresses, not only
the primary row identity. Address order and recipient-read authorization remain
unchanged. SMTP/IMAP diagnostics use translated status-list filters.
Without workers, explicitly retry eligible failures or continue unattempted
jobs through Report. Each request uses the canonical job/attempt recovery
boundary and is limited by the effective synchronous policy. Accepted and
uncertain SMTP outcomes remain protected. Active abandoned claims require an
expired durable lease, proven stopped/replaced owner, current revision and
valid original evidence before recovery can mark them unknown. A separate
evidence-note reconciliation is required before retrying. A timeout alone is
never proof of non-delivery. See the delivery runbook for required permissions
and operational limitations.
Append-to-Sent is scoped to the selected version and reuses a bounded Mail-owned
connection/folder resolution (default 100 messages or 300 seconds), while
performing one sequential APPEND and all current checks per message. Uncertain
appends are never automatically repeated, and repairing Sent never resends SMTP.
Link required files before locking. Lock and validate waits for attachment
matches, rechecks them immediately before locking, and asks for Link and lock
confirmation if new unlinked files are found. A locked version cannot acquire
new attachment links; use an editable version and validate/build/review again.
### Fortschritt, Wiederherstellung und Dateiverknüpfungen
Jetzt senden, synchrone Wiederholung/Fortsetzung im Bericht und Kopieren nach
Gesendet verwenden einen kompakten sperrenden Fortschrittsdialog. Nur gespeicherte
Zähler werden aktualisiert, nicht der Arbeitsbereich im Hintergrund. Erfolgreich,
ausstehend, in Bearbeitung, fehlgeschlagen, ungewiss und ausgeschlossen bleiben
getrennt sichtbar. Bei Lesefehlern bleiben die letzten Werte erhalten. Nach einer
getrennten Verbindung kann die Verarbeitung weiterlaufen; prüfen Sie Nachweise,
bevor Sie erneut handeln. Ein bestätigter Versand wird durch einen nachfolgenden
Anzeigefehler nicht nachträglich als fehlgeschlagen dargestellt.
Der empfängerbezogene Bericht zeigt alle eingefrorenen An-, Cc- und Bcc-Adressen
in ihrer Reihenfolge. Leseberechtigungen bleiben unverändert. SMTP und IMAP
verwenden übersetzte Zustandslisten zum Filtern.
Ohne Worker können bekannte Fehler ausdrücklich wiederholt und unversuchte
Aufträge begrenzt fortgesetzt werden. Die wirksame synchrone Grenze, gespeicherte
Aufträge, Prüfungen, Freigaben und Wiederherstellungsnachweise bleiben verbindlich.
Angenommene und ungewisse SMTP-Ergebnisse werden nicht blind wiederholt. Die
Wiederherstellung aktiver, verlassener Aufträge benötigt eine abgelaufene Sperre,
nachweislich gestoppte/ersetzte Laufzeit und gültige ursprüngliche Nachweise. Sie
setzt ausschließlich auf ungewiss; vor Wiederholung sind externe Nachweise und
ein getrennter Abgleich mit Notiz erforderlich. Zeitablauf allein genügt nicht.
Kopieren nach Gesendet betrifft nur die ausgewählte Version. Mail verwendet die
Verbindung und Ordnerauflösung begrenzt wieder (Standard: 100 Nachrichten oder
300 Sekunden), prüft aber jede Nachricht erneut und führt APPEND nacheinander
aus. Ungewisse Ergebnisse werden nicht automatisch wiederholt. Verknüpfen Sie
benötigte Dateien vor dem Sperren; eine frische Prüfung fragt bei unverknüpften
Treffern nach Verknüpfen und sperren. Gesperrte Versionen benötigen zum Ändern
eine bearbeitbare Version mit erneuter Validierung, Build und Prüfung.
### Health to observe
- database and migration health;
+60 -1
View File
@@ -68,7 +68,9 @@ material and does not delete or rewrite the stored audit rows automatically:
`mail_profile_migration_required` marker.
- validation, build, queue, retry, and delivery fail closed with an actionable
profile-migration error;
- unrelated edits cannot silently scrub the legacy fields;
- unrelated edits preserve the exact stored legacy server object when the
submitted public Mail references are unchanged; they cannot silently scrub,
edit, or re-submit legacy fields or credentials;
- an editable version is migrated only through an explicit Mail-settings save
with an authorized profile; and
- a locked version remains unchanged. Creating its editable successor records
@@ -81,6 +83,63 @@ database as a whole; the product does not define a separate historical-JSON or
inline-secret recovery workflow. A restored legacy row remains inert and
fail-closed under the same rules.
### Migrate from the Campaign UI
Open **Mail settings** from the migration notice for the selected version.
Select an authorized Mail profile and choose **Migrate selected Mail profile**.
The migration action is available even when that profile was already selected
and the draft has no other unsaved changes. If the version is locked, first use
its supported unlock or editable-successor action; protected source evidence is
not rewritten. Reopen the settings and confirm that the migration notice has
gone, then validate, build, and review before separately authorizing delivery.
Migration itself never sends mail.
Mail migration and ZIP policy repairs can be saved in either order. An exact,
unchanged ZIP configuration does not require a new acknowledgement merely to
save a Mail migration, even if the existing ZIP policy or actor's permission is
no longer valid. No actor, timestamp, or consent is invented. Any ZIP change
still requires the complete current archive policy and, for ZipCrypto, the
dedicated permission and reasoned acknowledgement. Conversely, saving an
archive correction with unchanged public Mail references retains the exact
legacy transport server-side, without using or reauthorizing the old profile.
The migration notice remains until the explicit authorized migration succeeds.
Changing any Mail profile, server, or credential reference is not an unrelated
repair. Inline transport is rejected even if a caller echoes stored values.
The same edit-time separation applies after migration: retaining an unchanged
Mail selection does not invoke use-policy while saving an unrelated correction,
even if a later policy requires an explicit credential. Selecting a new resource
or explicitly migrating still checks Mail permission and current policy; actual
validation and delivery always recheck them, regardless of save history.
Both repair orders invalidate build/execution evidence; validation, build,
review and delivery remain blocked until all outstanding conditions are valid.
Successful saves and subsequent refreshes are separate outcomes. A committed
save is not undone by a failed workspace refresh. The workspace retains its
last usable same-campaign/version data and displays the refresh error; retry
Reload to fetch the current server state. Obsolete responses from an earlier
campaign, version, signed-in identity, or reload cannot replace newer data.
The normal profile selector requests only campaign-authorized profiles. The
administrative profile catalogue is requested separately on **Mail policy**;
failure or lack of authority there does not empty the usable profile selector.
Profile-list errors remain visible next to the affected settings.
While migration is required, **Review and send** remains read-only and links to
the exact version's Mail settings. It does not repeatedly attempt incompatible
attachment-preview requests. These UI affordances do not relax backend
validation, build, queue, retry, or delivery enforcement.
### Editor metadata and trusted evidence
Read responses may contain server-owned `review_send` and `approval_gate`
evidence. Ordinary version mutations send only client-owned `created_from`,
`field_overrides`, and `opt_ins` editor metadata. The client omits review and
approval evidence; the server rejects attempts to write it through an editor
mutation and preserves its existing trusted value during metadata updates.
Supported unlock, successor-version, and build invalidation rules still remove
stale evidence when required. Opening or leaving the Template editor must not
require manually deleting server review metadata.
## Operator checks
Before live delivery, confirm that:
+2 -2
View File
@@ -1,6 +1,6 @@
{
"name": "@govoplan/campaign-webui",
"version": "0.1.18",
"version": "0.1.29",
"private": true,
"type": "module",
"main": "webui/src/index.ts",
@@ -22,7 +22,7 @@
"read-excel-file": "9.2.0"
},
"peerDependencies": {
"@govoplan/core-webui": "^0.1.18",
"@govoplan/core-webui": "^0.1.45",
"lucide-react": "^1.23.0",
"react": ">=19.2.7 <20",
"react-dom": ">=19.2.7 <20",
+2 -2
View File
@@ -4,14 +4,14 @@ build-backend = "setuptools.build_meta"
[project]
name = "govoplan-campaign"
version = "0.1.21"
version = "0.1.29"
description = "GovOPlaN campaigns module with backend and WebUI integration."
readme = "README.md"
requires-python = ">=3.12"
license = { file = "LICENSE" }
authors = [{ name = "GovOPlaN" }]
dependencies = [
"govoplan-core>=0.1.18",
"govoplan-core>=0.1.46",
"jsonschema>=4,<5",
"pydantic>=2,<3",
"SQLAlchemy>=2,<3",
@@ -192,6 +192,16 @@ def stamp_legacy_zipcrypto_acknowledgements(
if candidate_raw_json is None:
return None, []
candidate = copy.deepcopy(candidate_raw_json)
current_attachments = current_raw_json.get("attachments")
candidate_attachments = candidate.get("attachments")
current_zip = current_attachments.get("zip") if isinstance(current_attachments, Mapping) else None
candidate_zip = candidate_attachments.get("zip") if isinstance(candidate_attachments, Mapping) else None
if json.dumps(current_zip, sort_keys=True) == json.dumps(candidate_zip, sort_keys=True):
# Saving an unrelated repair does not authorize use of an existing
# archive or invent an acknowledgement. Preserve the exact stored ZIP
# configuration, including missing evidence or now-revoked policy.
# Build/review/delivery still validate the complete configuration.
return candidate, []
current_by_id = {
str(item.get("id") or index): item
for index, item in enumerate(_archive_configs(current_raw_json))
@@ -243,6 +253,9 @@ def stamp_legacy_zipcrypto_acknowledgements(
"policy_hash": policy.policy_hash,
}
)
# Modified archive settings must satisfy the complete current policy, not
# only the special ZipCrypto acknowledgement checks above.
assert_archive_encryption_allowed(session, campaign, candidate, principal=principal)
return candidate, acknowledgements
@@ -233,15 +233,20 @@ def _missing_policy_decision(
candidates,
key=lambda behavior: _MISSING_BEHAVIOR_STRENGTH[behavior],
)
legacy_drop_normalized = configured == Behavior.DROP
if legacy_drop_normalized:
configured = Behavior.BLOCK if config.required else Behavior.ASK
if Behavior.BLOCK in candidates:
configured = Behavior.BLOCK
elif not config.required and config.missing_behavior == Behavior.CONTINUE:
# An explicitly optional, allowed-empty rule is an expected outcome,
# not an exception to accept. Hard blocking policy still wins above.
configured = Behavior.CONTINUE
elif Behavior.DROP in candidates:
configured = Behavior.DROP
return AttachmentPolicyDecision(
requirement_policy=requirement_policy,
campaign_policy=campaign_config.attachments.missing_behavior,
rule_policy=config.missing_behavior,
effective_behavior=configured,
legacy_drop_normalized=legacy_drop_normalized,
legacy_drop_normalized=False,
)
@@ -410,7 +415,10 @@ def _issue_for_missing(
) -> AttachmentIssue:
code = "missing_required_attachment" if config.required else "missing_optional_attachment"
behavior = policy.effective_behavior
severity = ResolutionSeverity.ERROR if behavior == Behavior.BLOCK else ResolutionSeverity.WARNING
severity = (
ResolutionSeverity.ERROR if behavior == Behavior.BLOCK else
ResolutionSeverity.INFO if behavior in {Behavior.CONTINUE, Behavior.DROP} else ResolutionSeverity.WARNING
)
return AttachmentIssue(
severity=severity,
code=code,
@@ -434,9 +442,9 @@ def effective_send_without_attachments_behavior(config: CampaignConfig) -> Behav
configured = config.attachments.send_without_attachments_behavior or (
Behavior.CONTINUE if config.attachments.send_without_attachments else Behavior.BLOCK
)
# Recipient exclusion must be an explicit reviewed action, not an implicit
# consequence of a legacy attachment policy value.
return Behavior.ASK if configured == Behavior.DROP else configured
# Configured exclusion is already an explicit policy decision. It must not
# be converted into an acceptance prompt that would send the excluded mail.
return configured
def _issue_for_missing_attachment_coverage(behavior: Behavior) -> AttachmentIssue:
@@ -447,7 +455,7 @@ def _issue_for_missing_attachment_coverage(behavior: Behavior) -> AttachmentIssu
Behavior.WARN: "No attachment file was resolved for this message. Campaign policy allows sending with a warning.",
}
return AttachmentIssue(
severity=ResolutionSeverity.ERROR if behavior == Behavior.BLOCK else ResolutionSeverity.WARNING,
severity=(ResolutionSeverity.ERROR if behavior == Behavior.BLOCK else ResolutionSeverity.INFO if behavior == Behavior.DROP else ResolutionSeverity.WARNING),
code="missing_attachment_coverage",
message=messages.get(behavior, "No attachment file was resolved for this message."),
behavior=behavior,
@@ -1,6 +1,7 @@
from __future__ import annotations
import copy
import hashlib
from typing import Any
@@ -50,6 +51,12 @@ class CampaignMailProfileBoundaryError(ValueError):
"""
def campaign_review_reference(version_id: str, build_token: Any) -> str | None:
"""A public concurrency reference, not a raw diagnostic/build claim token."""
token = str(build_token or "").strip()
return hashlib.sha256(f"campaign-review:{version_id}:{token}".encode()).hexdigest() if token else None
def _validated_opt_ins(value: Any) -> dict[str, bool]:
if not isinstance(value, dict) or any(
key not in CAMPAIGN_OPT_IN_KEYS for key in value
@@ -198,6 +205,24 @@ def campaign_editor_state_for_edit(value: Any) -> dict[str, Any]:
return state
def campaign_editor_state_with_client_update(
stored: Any, client_state: dict[str, Any]
) -> dict[str, Any]:
"""Replace client metadata without accepting or erasing server evidence.
Read responses contain review and approval state, but ordinary editor saves
may only supply client-owned fields. Their omission must not delete trusted
server evidence; content/build invalidation remains owned by its lifecycle.
"""
result = validate_campaign_editor_state(client_state)
server_state = public_campaign_editor_state(stored, include_diagnostics=True)
for key in ("review_send", "approval_gate"):
if key in server_state:
result[key] = server_state[key]
return result
def _validated_server_approval_gate(value: Any) -> dict[str, Any]:
if not isinstance(value, dict) or any(
key not in CAMPAIGN_APPROVAL_GATE_KEYS for key in value
@@ -483,3 +508,23 @@ def public_campaign_mail_server(raw_json: dict[str, Any] | None) -> dict[str, st
for key, value in campaign_mail_resource_ids(raw_json).items()
if value
}
def campaign_mail_references_unchanged(
current: dict[str, Any] | None, candidate: dict[str, Any] | None
) -> bool:
"""Recognize an unchanged public selection, never client-owned transport."""
return (
isinstance(candidate, dict)
and not campaign_mail_profile_boundary_violations(candidate)
and candidate.get("server", {}) == public_campaign_mail_server(current)
)
def campaign_preserves_legacy_mail_settings(
current: dict[str, Any] | None, candidate: dict[str, Any] | None
) -> bool:
"""Keep stored legacy transport inert without accepting it from a client."""
return bool(campaign_mail_profile_boundary_violations(current)) and campaign_mail_references_unchanged(current, candidate)
@@ -0,0 +1,730 @@
from __future__ import annotations
import copy
import hashlib
import json
from collections import Counter
from collections.abc import Iterable, Mapping
from dataclasses import dataclass
from datetime import UTC, datetime
from typing import Any
from uuid import uuid4
from govoplan_campaign.backend.campaign.loader import validate_against_schema
from govoplan_campaign.backend.db.models import (
Campaign,
CampaignIssue,
CampaignJob,
CampaignVersion,
)
from govoplan_campaign.backend.persistence.versions import minimal_campaign_json
from govoplan_campaign.backend.response_security import (
public_campaign_configuration,
public_campaign_payload,
)
PORTABLE_CAMPAIGN_FORMAT = "govoplan.campaign-portable"
PORTABLE_CAMPAIGN_FORMAT_VERSION = "1.0"
PORTABLE_CAMPAIGN_SCOPE_ORDER = (
"metadata",
"template_config",
"recipients",
"attachments",
"review_state",
"delivery_history",
)
DEFAULT_PORTABLE_CAMPAIGN_SCOPES = ("metadata", "template_config")
OPERATIONAL_EVIDENCE_SCOPES = frozenset(("review_state", "delivery_history"))
_CONFIG_STRUCTURAL_KEYS = frozenset(
("version", "campaign", "recipients", "entries", "attachments")
)
_SENSITIVE_SETTING_FRAGMENTS = (
"api_key",
"credential",
"password",
"private_key",
"secret",
"token",
)
class CampaignTransferError(ValueError):
pass
@dataclass(frozen=True, slots=True)
class CampaignImportInspection:
preview: dict[str, Any]
configuration: dict[str, Any] | None
portable_settings: dict[str, Any]
def canonical_sha256(value: object) -> str:
encoded = json.dumps(
value,
sort_keys=True,
separators=(",", ":"),
ensure_ascii=False,
allow_nan=False,
).encode("utf-8")
return hashlib.sha256(encoded).hexdigest()
def normalize_transfer_scopes(scopes: Iterable[str]) -> tuple[str, ...]:
selected = set(scopes)
invalid = sorted(selected.difference(PORTABLE_CAMPAIGN_SCOPE_ORDER))
if invalid:
raise CampaignTransferError(
f"Unsupported campaign transfer scope(s): {', '.join(invalid)}"
)
if not selected:
raise CampaignTransferError("Select at least one campaign transfer scope.")
return tuple(scope for scope in PORTABLE_CAMPAIGN_SCOPE_ORDER if scope in selected)
def build_campaign_portable_package(
*,
campaign: Campaign,
version: CampaignVersion,
scopes: Iterable[str],
jobs: Iterable[CampaignJob] = (),
issues: Iterable[CampaignIssue] = (),
module_version: str,
) -> dict[str, Any]:
selected = normalize_transfer_scopes(scopes)
configuration = public_campaign_configuration(version.raw_json)
if not isinstance(configuration, dict):
raise CampaignTransferError("The campaign configuration is not portable JSON.")
configuration, password_redactions = _redact_password_field_values(configuration)
payload: dict[str, Any] = {}
item_counts: dict[str, int] = {}
redactions: Counter[str] = Counter(password_redactions)
if "metadata" in selected:
payload["metadata"] = {
"external_id": campaign.external_id,
"name": campaign.name,
"description": campaign.description,
"source_status": campaign.status,
}
item_counts["metadata"] = 1
if "template_config" in selected:
settings, setting_redactions = _redact_sensitive_settings(
campaign.settings or {}
)
mail_policy, mail_policy_redactions = _redact_sensitive_settings(
campaign.mail_profile_policy or {}
)
template_configuration = {
key: copy.deepcopy(value)
for key, value in configuration.items()
if key not in _CONFIG_STRUCTURAL_KEYS
}
server = template_configuration.get("server")
if isinstance(server, dict):
for key in ("smtp_credential_id", "imap_credential_id"):
if server.pop(key, None) is not None:
redactions["deployment_credential_reference"] += 1
payload["template_config"] = {
"schema_version": version.schema_version,
"configuration": template_configuration,
"campaign_settings": settings,
"mail_profile_policy": mail_policy,
}
redactions.update(setting_redactions)
redactions.update(mail_policy_redactions)
item_counts["template_config"] = len(template_configuration)
if "recipients" in selected:
entries = copy.deepcopy(configuration.get("entries") or {})
_remove_entry_attachments(entries)
payload["recipients"] = {
"recipients": copy.deepcopy(configuration.get("recipients") or {}),
"entries": entries,
}
item_counts["recipients"] = _recipient_entry_count(entries)
if "attachments" in selected:
entry_attachments = _entry_attachment_projection(
configuration.get("entries")
)
payload["attachments"] = {
"configuration": copy.deepcopy(configuration.get("attachments") or {}),
"entry_attachments": entry_attachments,
"content_included": False,
}
item_counts["attachments"] = _attachment_rule_count(
payload["attachments"]
)
issue_rows = tuple(issues)
if "review_state" in selected:
review_state = _review_state_projection(version, issue_rows)
payload["review_state"] = review_state
item_counts["review_state"] = int(review_state["decision_count"])
job_rows = tuple(jobs)
if "delivery_history" in selected:
payload["delivery_history"] = {
"jobs": [_delivery_job_projection(job) for job in job_rows],
"counts": _delivery_counts(job_rows),
}
item_counts["delivery_history"] = len(job_rows)
exported_at = datetime.now(UTC)
package: dict[str, Any] = {
"format": PORTABLE_CAMPAIGN_FORMAT,
"format_version": PORTABLE_CAMPAIGN_FORMAT_VERSION,
"package_id": str(uuid4()),
"exported_at": exported_at.isoformat(),
"source": {
"module": "campaigns",
"module_version": module_version,
"tenant_ref_sha256": hashlib.sha256(
campaign.tenant_id.encode("utf-8")
).hexdigest(),
"campaign_id": campaign.id,
"campaign_external_id": campaign.external_id,
"campaign_name": campaign.name,
"version_id": version.id,
"version_number": version.version_number,
"campaign_schema_version": version.schema_version,
},
"scopes": list(selected),
"manifest": {
"item_counts": item_counts,
"redactions": dict(sorted(redactions.items())),
"privacy_default_scopes": list(DEFAULT_PORTABLE_CAMPAIGN_SCOPES),
"attachments_are_references_only": True,
"operational_evidence_is_not_replayed": True,
"secrets_included": False,
},
"payload": payload,
}
package["integrity"] = {
"algorithm": "sha256",
"package_sha256": canonical_sha256(package),
}
return package
def inspect_campaign_portable_package(
package: Mapping[str, Any],
*,
selected_scopes: Iterable[str] | None,
external_id: str,
name: str,
) -> CampaignImportInspection:
errors: list[str] = []
warnings: list[str] = []
package_dict = copy.deepcopy(dict(package))
package_id = _optional_text(package_dict.get("package_id"))
format_version = _optional_text(package_dict.get("format_version"))
source = package_dict.get("source")
source_dict = copy.deepcopy(source) if isinstance(source, dict) else {}
integrity = package_dict.get("integrity")
expected_hash = (
_optional_text(integrity.get("package_sha256"))
if isinstance(integrity, dict)
else None
)
hash_input = copy.deepcopy(package_dict)
hash_input.pop("integrity", None)
actual_hash = canonical_sha256(hash_input)
if package_dict.get("format") != PORTABLE_CAMPAIGN_FORMAT:
errors.append("The file is not a GovOPlaN portable Campaign package.")
if format_version != PORTABLE_CAMPAIGN_FORMAT_VERSION:
errors.append(
"The Campaign package format version is not supported by this installation."
)
if not package_id:
errors.append("The Campaign package has no package identifier.")
if not expected_hash or expected_hash != actual_hash:
errors.append("The Campaign package integrity checksum does not match its content.")
if not isinstance(integrity, dict) or integrity.get("algorithm") != "sha256":
errors.append("The Campaign package does not use the supported SHA-256 integrity algorithm.")
if not source_dict:
errors.append("The Campaign package has no source provenance.")
elif source_dict.get("campaign_schema_version") != "1.0":
errors.append("The Campaign configuration schema version is not supported by this installation.")
available: tuple[str, ...] = ()
try:
raw_scopes = package_dict.get("scopes")
if not isinstance(raw_scopes, list):
raise CampaignTransferError("The Campaign package has no valid scope list.")
available = normalize_transfer_scopes(str(item) for item in raw_scopes)
except CampaignTransferError as exc:
errors.append(str(exc))
try:
selected = normalize_transfer_scopes(
available if selected_scopes is None else selected_scopes
)
except CampaignTransferError as exc:
errors.append(str(exc))
selected = ()
unavailable = sorted(set(selected).difference(available))
if unavailable:
errors.append(
f"Selected scope(s) are absent from the package: {', '.join(unavailable)}"
)
payload = package_dict.get("payload")
payload_dict = payload if isinstance(payload, dict) else {}
if not isinstance(payload, dict):
errors.append("The Campaign package has no valid payload object.")
if not isinstance(package_dict.get("manifest"), dict):
errors.append("The Campaign package has no valid manifest.")
for scope in available:
if scope not in payload_dict:
errors.append(f"The Campaign package payload is missing scope '{scope}'.")
elif not isinstance(payload_dict[scope], dict):
errors.append(f"The Campaign package scope '{scope}' is not a valid object.")
template_scope = payload_dict.get("template_config")
if (
"template_config" in available
and isinstance(template_scope, dict)
and template_scope.get("schema_version") != "1.0"
):
errors.append("The portable template/configuration schema version is not supported.")
configuration: dict[str, Any] | None = None
portable_settings: dict[str, Any] = {}
will_create: list[dict[str, Any]] = []
will_skip: list[dict[str, Any]] = []
if not errors:
configuration, portable_settings, created, skipped, materialize_warnings = (
_materialize_import(
payload_dict,
available=available,
selected=selected,
external_id=external_id,
name=name,
)
)
will_create.extend(created)
will_skip.extend(skipped)
warnings.extend(materialize_warnings)
try:
validate_against_schema(configuration)
except Exception as exc:
errors.append(f"The imported Campaign configuration is incompatible: {exc}")
configuration = None
manifest = package_dict.get("manifest")
if isinstance(manifest, dict) and manifest.get("redactions"):
warnings.append(
"The source export redacted sensitive or deployment-bound values; review the package manifest and reconfigure them locally."
)
preview = {
"compatible": not errors,
"package_id": package_id,
"package_sha256": actual_hash,
"format_version": format_version,
"source": source_dict,
"available_scopes": list(available),
"selected_scopes": list(selected),
"destination": {
"external_id": external_id,
"name": name,
"status": "draft",
},
"will_create": will_create,
"will_skip": will_skip,
"warnings": list(dict.fromkeys(warnings)),
"errors": list(dict.fromkeys(errors)),
}
return CampaignImportInspection(
preview=preview,
configuration=configuration,
portable_settings=portable_settings,
)
def _materialize_import(
payload: Mapping[str, Any],
*,
available: tuple[str, ...],
selected: tuple[str, ...],
external_id: str,
name: str,
) -> tuple[
dict[str, Any],
dict[str, Any],
list[dict[str, Any]],
list[dict[str, Any]],
list[str],
]:
selected_set = set(selected)
configuration = minimal_campaign_json(external_id=external_id, name=name)
portable_settings: dict[str, Any] = {}
created: list[dict[str, Any]] = [
_plan_item("metadata", "campaign_draft", "A new Campaign draft and editable version will be created.", 1)
]
skipped: list[dict[str, Any]] = []
warnings: list[str] = []
metadata = payload.get("metadata")
if "metadata" in selected_set and isinstance(metadata, dict):
description = metadata.get("description")
if isinstance(description, str):
configuration["campaign"]["description"] = description
template_payload = payload.get("template_config")
if "template_config" in selected_set and isinstance(template_payload, dict):
source_configuration = template_payload.get("configuration")
if isinstance(source_configuration, dict):
for key, value in source_configuration.items():
if key in _CONFIG_STRUCTURAL_KEYS:
continue
configuration[key] = copy.deepcopy(value)
source_server = configuration.get("server")
if isinstance(source_server, dict) and source_server:
configuration["server"] = {}
skipped.append(
_plan_item(
"template_config",
"deployment_bound_mail_profile",
"Mail profile and server references are not applied across installations; select local Mail resources after import.",
len(source_server),
)
)
settings = template_payload.get("campaign_settings")
if isinstance(settings, dict):
portable_settings = copy.deepcopy(settings)
created.append(
_plan_item(
"template_config",
"editable_configuration",
"Portable fields, template, delivery settings, and validation policy will be applied to the draft.",
len(source_configuration),
)
)
recipients_payload = payload.get("recipients")
if "recipients" in selected_set and isinstance(recipients_payload, dict):
recipients = recipients_payload.get("recipients")
entries = recipients_payload.get("entries")
if isinstance(recipients, dict):
configuration["recipients"] = copy.deepcopy(recipients)
if isinstance(entries, dict):
configuration["entries"] = copy.deepcopy(entries)
created.append(
_plan_item(
"recipients",
"recipient_rows",
"Campaign-local recipient rows and source provenance will be copied into the draft.",
_recipient_entry_count(entries),
)
)
attachments_payload = payload.get("attachments")
if "attachments" in selected_set and isinstance(attachments_payload, dict):
attachment_configuration = attachments_payload.get("configuration")
if isinstance(attachment_configuration, dict):
configuration["attachments"] = copy.deepcopy(attachment_configuration)
per_entry = attachments_payload.get("entry_attachments")
applied_entry_rules = 0
if "recipients" in selected_set and isinstance(per_entry, list):
inline = configuration.get("entries", {}).get("inline", [])
if isinstance(inline, list):
for item in per_entry:
if not isinstance(item, dict):
continue
index = item.get("entry_index")
rules = item.get("attachments")
if (
isinstance(index, int)
and 0 <= index < len(inline)
and isinstance(inline[index], dict)
and isinstance(rules, list)
):
inline[index]["attachments"] = copy.deepcopy(rules)
applied_entry_rules += len(rules)
elif isinstance(per_entry, list) and per_entry:
skipped.append(
_plan_item(
"attachments",
"recipient_scope_required",
"Per-recipient attachment rules are skipped unless recipient rows are also imported.",
sum(
len(item.get("attachments") or [])
for item in per_entry
if isinstance(item, dict)
),
)
)
created.append(
_plan_item(
"attachments",
"attachment_references",
"Portable attachment rules will be applied; file content is never embedded in the package.",
_attachment_rule_count(attachments_payload) - max(0, _entry_rule_count(per_entry) - applied_entry_rules),
)
)
warnings.append(
"Attachment rules contain references only. Reconnect or upload the required files and validate the draft before use."
)
for scope in PORTABLE_CAMPAIGN_SCOPE_ORDER:
if scope not in OPERATIONAL_EVIDENCE_SCOPES:
continue
if scope in selected_set:
item_count = _manifest_scope_count(payload.get(scope))
skipped.append(
_plan_item(
scope,
"operational_evidence_not_replayed",
"Historical review or delivery evidence remains in the source package and import receipt but is never replayed as live Campaign state.",
item_count,
)
)
for scope in available:
if scope not in selected_set:
skipped.append(
_plan_item(
scope,
"scope_not_selected",
"This available package scope was not selected for import.",
_manifest_scope_count(payload.get(scope)),
)
)
campaign_metadata = configuration.get("campaign")
if not isinstance(campaign_metadata, dict):
raise CampaignTransferError("The imported Campaign metadata is invalid.")
campaign_metadata.update({"id": external_id, "name": name, "mode": "draft"})
return configuration, portable_settings, created, skipped, warnings
def _review_state_projection(
version: CampaignVersion, issues: tuple[CampaignIssue, ...]
) -> dict[str, Any]:
editor_state = version.editor_state if isinstance(version.editor_state, dict) else {}
review = editor_state.get("review_send")
review = review if isinstance(review, dict) else {}
decisions = [
item
for item in (review.get("issue_decisions") or [])
if isinstance(item, dict)
]
decision_evidence = [
{
"decision": item.get("decision"),
"issue_codes": sorted(str(code) for code in item.get("issue_codes") or []),
"issue_fingerprint": item.get("issue_fingerprint"),
"message_sha256": item.get("message_sha256"),
"reason_recorded": bool(str(item.get("reason") or "").strip()),
}
for item in decisions
]
issue_counts = Counter(str(issue.severity) for issue in issues)
return {
"workflow_state": version.workflow_state,
"inspection_complete": bool(review.get("inspection_complete")),
"reviewed_message_count": len(review.get("reviewed_message_keys") or []),
"decision_count": len(decisions),
"decision_evidence_sha256": canonical_sha256(decision_evidence),
"issue_counts": dict(sorted(issue_counts.items())),
"validation_summary": public_campaign_payload(version.validation_summary or {}),
"build_summary": public_campaign_payload(version.build_summary or {}),
}
def _delivery_job_projection(job: CampaignJob) -> dict[str, Any]:
return {
"job_id": job.id,
"entry_index": job.entry_index,
"entry_id": job.entry_id,
"recipient_email": job.recipient_email,
"message_id_header": job.message_id_header,
"message_sha256": job.eml_sha256,
"build_status": job.build_status,
"validation_status": job.validation_status,
"queue_status": job.queue_status,
"send_status": job.send_status,
"postbox_status": job.postbox_status,
"print_status": job.print_status,
"imap_status": job.imap_status,
"attempt_count": job.attempt_count,
"sent_at": _isoformat(job.sent_at),
"outcome_unknown_at": _isoformat(job.outcome_unknown_at),
"delivery_provenance": public_campaign_payload(job.delivery_provenance or {}),
}
def _delivery_counts(jobs: tuple[CampaignJob, ...]) -> dict[str, dict[str, int]]:
return {
field: dict(
sorted(Counter(str(getattr(job, field) or "unknown") for job in jobs).items())
)
for field in ("validation_status", "queue_status", "send_status")
}
def _redact_sensitive_settings(
value: Mapping[str, Any],
) -> tuple[dict[str, Any], Counter[str]]:
redactions: Counter[str] = Counter()
def visit(item: Any) -> Any:
if isinstance(item, dict):
result: dict[str, Any] = {}
for raw_key, child in item.items():
key = str(raw_key)
normalized = key.lower().replace("-", "_")
if any(fragment in normalized for fragment in _SENSITIVE_SETTING_FRAGMENTS):
redactions["sensitive_setting"] += 1
continue
result[key] = visit(child)
return result
if isinstance(item, list):
return [visit(child) for child in item]
return copy.deepcopy(item)
return visit(dict(value)), redactions
def _redact_password_field_values(
configuration: dict[str, Any],
) -> tuple[dict[str, Any], Counter[str]]:
result = copy.deepcopy(configuration)
password_fields = {
str(field.get("name"))
for field in result.get("fields") or []
if isinstance(field, dict)
and field.get("type") == "password"
and field.get("name")
}
redactions: Counter[str] = Counter()
if not password_fields:
return result, redactions
global_values = result.get("global_values")
if isinstance(global_values, dict):
for key in password_fields:
if global_values.pop(key, None) is not None:
redactions["password_field_value"] += 1
entries = result.get("entries")
if isinstance(entries, dict):
for entry in entries.get("inline") or []:
if not isinstance(entry, dict):
continue
fields = entry.get("fields")
if not isinstance(fields, dict):
continue
for key in password_fields:
if fields.pop(key, None) is not None:
redactions["password_field_value"] += 1
return result, redactions
def _remove_entry_attachments(entries: Any) -> None:
if not isinstance(entries, dict):
return
for entry in entries.get("inline") or []:
if isinstance(entry, dict):
entry["attachments"] = []
defaults = entries.get("defaults")
if isinstance(defaults, dict):
defaults["attachments"] = []
def _entry_attachment_projection(entries: Any) -> list[dict[str, Any]]:
if not isinstance(entries, dict):
return []
result: list[dict[str, Any]] = []
for index, entry in enumerate(entries.get("inline") or []):
if not isinstance(entry, dict):
continue
rules = entry.get("attachments")
if isinstance(rules, list) and rules:
result.append(
{
"entry_index": index,
"attachments": copy.deepcopy(rules),
}
)
return result
def _recipient_entry_count(entries: Any) -> int:
if not isinstance(entries, dict):
return 0
inline = entries.get("inline")
return len(inline) if isinstance(inline, list) else 0
def _attachment_rule_count(value: Any) -> int:
if not isinstance(value, dict):
return 0
configuration = value.get("configuration")
global_rules = (
configuration.get("global") if isinstance(configuration, dict) else []
)
return (len(global_rules) if isinstance(global_rules, list) else 0) + _entry_rule_count(
value.get("entry_attachments")
)
def _entry_rule_count(value: Any) -> int:
if not isinstance(value, list):
return 0
return sum(
len(item.get("attachments") or [])
for item in value
if isinstance(item, dict)
)
def _manifest_scope_count(value: Any) -> int:
if not isinstance(value, dict):
return 0
if isinstance(value.get("jobs"), list):
return len(value["jobs"])
if "decision_count" in value:
return int(value.get("decision_count") or 0)
if "entries" in value:
return _recipient_entry_count(value.get("entries"))
return 1
def _plan_item(
scope: str, code: str, summary: str, item_count: int | None
) -> dict[str, Any]:
return {
"scope": scope,
"code": code,
"summary": summary,
"item_count": item_count,
}
def _optional_text(value: object) -> str | None:
text = str(value or "").strip()
return text or None
def _isoformat(value: datetime | None) -> str | None:
return value.isoformat() if value is not None else None
__all__ = [
"CampaignImportInspection",
"CampaignTransferError",
"DEFAULT_PORTABLE_CAMPAIGN_SCOPES",
"OPERATIONAL_EVIDENCE_SCOPES",
"PORTABLE_CAMPAIGN_FORMAT",
"PORTABLE_CAMPAIGN_FORMAT_VERSION",
"PORTABLE_CAMPAIGN_SCOPE_ORDER",
"build_campaign_portable_package",
"canonical_sha256",
"inspect_campaign_portable_package",
"normalize_transfer_scopes",
]
@@ -27,7 +27,6 @@ from .models import (
effective_delivery_channel_policy,
effective_postbox_targets,
)
from ..attachments.resolver import resolve_campaign_attachments
class Severity(StrEnum):
@@ -877,6 +876,10 @@ def _attachment_file_check_issues(config: CampaignConfig, campaign_path: Path) -
def _attachment_resolution_check_issues(config: CampaignConfig, campaign_path: Path) -> list[SemanticIssue]:
# The resolver consumes campaign models/entries. Import it only when file
# validation is requested so either public entry point can initialize first.
from ..attachments.resolver import resolve_campaign_attachments
try:
report = resolve_campaign_attachments(config, campaign_file=campaign_path)
except Exception as exc:
@@ -226,6 +226,11 @@ class CampaignCollaborationEntry(Base, TimestampMixin):
class CampaignWorkAssignment(Base, TimestampMixin):
__tablename__ = "campaign_work_assignments"
__table_args__ = (
UniqueConstraint(
"tenant_id",
"orchestration_idempotency_key",
name="uq_campaign_work_assignment_orchestration_key",
),
Index(
"ix_campaign_work_assignments_campaign_status",
"tenant_id",
@@ -275,6 +280,21 @@ class CampaignWorkAssignment(Base, TimestampMixin):
)
task_mirror_error: Mapped[str | None] = mapped_column(String(500), nullable=True)
task_mirrored_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True), nullable=True)
orchestration_idempotency_key: Mapped[str | None] = mapped_column(
String(255), nullable=True, index=True
)
orchestration_request_sha256: Mapped[str | None] = mapped_column(
String(64), nullable=True
)
orchestration_correlation_id: Mapped[str | None] = mapped_column(
String(128), nullable=True, index=True
)
workflow_instance_id: Mapped[str | None] = mapped_column(
String(36), nullable=True, index=True
)
workflow_step_id: Mapped[str | None] = mapped_column(
String(36), nullable=True, index=True
)
resource_revision: Mapped[int] = mapped_column(Integer, default=1, nullable=False)
@@ -520,6 +540,12 @@ class CampaignVersion(Base, TimestampMixin):
"version_id_col": edit_revision,
}
@property
def review_build_token(self) -> str | None:
from govoplan_campaign.backend.campaign.mail_profile_boundary import campaign_review_reference
summary = self.build_summary if isinstance(self.build_summary, dict) else {}
return campaign_review_reference(self.id, summary.get("build_token") or summary.get("built_at"))
@property
def strong_etag(self) -> str:
return strong_resource_etag(
@@ -6,6 +6,8 @@ from typing import Any, Mapping
from sqlalchemy.orm import Session
from govoplan_core.admin.models import SystemSettings
from govoplan_core.admin.settings import SYSTEM_SETTINGS_ID
from govoplan_core.tenancy.scope import Tenant
@@ -26,6 +28,8 @@ class SynchronousSendPolicy:
source: str
deployment_max_recipient_jobs: int
tenant_max_recipient_jobs: int | None = None
system_max_recipient_jobs: int | None = None
deployment_ceiling_explicit: bool = False
def as_dict(self) -> dict[str, Any]:
return {
@@ -33,6 +37,9 @@ class SynchronousSendPolicy:
"source": self.source,
"deployment_max_recipient_jobs": self.deployment_max_recipient_jobs,
"tenant_max_recipient_jobs": self.tenant_max_recipient_jobs,
"system_max_recipient_jobs": self.system_max_recipient_jobs,
"deployment_ceiling_explicit": self.deployment_ceiling_explicit,
"system_setting": f"system.settings.{CAMPAIGN_DELIVERY_POLICY_SETTINGS_KEY}.{SYNCHRONOUS_SEND_MAX_SETTINGS_KEY}",
"deployment_setting": SYNCHRONOUS_SEND_MAX_ENV,
"tenant_setting": (
f"tenant.settings.{CAMPAIGN_DELIVERY_POLICY_SETTINGS_KEY}."
@@ -46,20 +53,36 @@ def effective_synchronous_send_policy(
*,
tenant_id: str,
environ: Mapping[str, str] | None = None,
apply_tenant_override: bool = True,
) -> SynchronousSendPolicy:
env = os.environ if environ is None else environ
deployment_raw = env.get(SYNCHRONOUS_SEND_MAX_ENV)
deployment_explicit = deployment_raw is not None and (not isinstance(deployment_raw, str) or bool(deployment_raw.strip()))
deployment_value = _configured_limit(
env.get(SYNCHRONOUS_SEND_MAX_ENV),
source=SYNCHRONOUS_SEND_MAX_ENV,
default=DEFAULT_SYNCHRONOUS_SEND_MAX_RECIPIENT_JOBS,
default=ABSOLUTE_SYNCHRONOUS_SEND_MAX_RECIPIENT_JOBS,
)
tenant = session.get(Tenant, tenant_id)
system = session.get(SystemSettings, SYSTEM_SETTINGS_ID)
system_raw = _tenant_limit_value(system.settings if system is not None else None)
system_value = _configured_limit(system_raw, source="system campaign delivery policy") if system_raw is not None else None
# Preserve explicit deployment configuration, but an implicit default is not
# an administrator ceiling. No override still retains the conservative 25.
inherited = min(deployment_value, system_value) if system_value is not None else (
deployment_value if deployment_explicit else DEFAULT_SYNCHRONOUS_SEND_MAX_RECIPIENT_JOBS
)
inherited_source = ("system" if system_value <= deployment_value else "deployment_ceiling") if system_value is not None else (
"deployment" if deployment_explicit else "deployment_default"
)
tenant = session.get(Tenant, tenant_id) if apply_tenant_override else None
tenant_raw = _tenant_limit_value(tenant.settings if tenant is not None else None)
if tenant_raw is None:
return SynchronousSendPolicy(
max_recipient_jobs=deployment_value,
source=("deployment" if env.get(SYNCHRONOUS_SEND_MAX_ENV) not in (None, "") else "deployment_default"),
max_recipient_jobs=inherited,
source=inherited_source,
deployment_max_recipient_jobs=deployment_value,
system_max_recipient_jobs=system_value,
deployment_ceiling_explicit=deployment_explicit,
)
tenant_value = _configured_limit(
@@ -69,12 +92,14 @@ def effective_synchronous_send_policy(
f"{SYNCHRONOUS_SEND_MAX_SETTINGS_KEY}"
),
)
effective_value = min(deployment_value, tenant_value)
effective_value = min(inherited, tenant_value)
return SynchronousSendPolicy(
max_recipient_jobs=effective_value,
source="tenant" if tenant_value <= deployment_value else "deployment_ceiling",
source="tenant" if tenant_value <= inherited else ("system_ceiling" if inherited_source == "system" else "deployment_ceiling"),
deployment_max_recipient_jobs=deployment_value,
tenant_max_recipient_jobs=tenant_value,
system_max_recipient_jobs=system_value,
deployment_ceiling_explicit=deployment_explicit,
)
@@ -3,16 +3,19 @@ from __future__ import annotations
from dataclasses import dataclass
from email import policy
from email.message import EmailMessage
from email.parser import BytesParser
from types import SimpleNamespace
from typing import Any
from sqlalchemy.orm import Session
from govoplan_campaign.backend.db.models import Campaign, CampaignVersion
from govoplan_campaign.backend.db.models import Campaign, CampaignJob, CampaignVersion
from govoplan_campaign.backend.campaign.loader import load_campaign_json
from govoplan_campaign.backend.campaign.validation import validate_campaign_config
from govoplan_campaign.backend.campaign.models import DeliveryChannelPolicy
from govoplan_campaign.backend.campaign.validation import SemanticReport, validate_campaign_config
from govoplan_campaign.backend.persistence.campaigns import load_campaign_config_from_json
from govoplan_campaign.backend.messages.builder import build_campaign_messages
from govoplan_campaign.backend.messages.models import MessageAddress, MessageDraft, MessageValidationStatus
from govoplan_campaign.backend.messages.builder import BuiltMessage, CampaignBuildResult, build_campaign_messages
from govoplan_campaign.backend.messages.models import CampaignBuildReport, MessageAddress, MessageAttachmentSummary, MessageDraft, MessageValidationStatus
from govoplan_campaign.backend.integrations import files_integration, mail_integration
from govoplan_campaign.backend.path_security import assert_server_safe_campaign_paths
@@ -151,6 +154,7 @@ def _mock_send_batch(
include_warnings: bool,
include_needs_review: bool,
append_sent: bool,
reviewed_keys: set[str] | None = None,
) -> _MockSendBatch:
batch = _MockSendBatch(results=[])
for built in built_messages:
@@ -160,7 +164,7 @@ def _mock_send_batch(
mailbox=mailbox,
send=send,
include_warnings=include_warnings,
include_needs_review=include_needs_review,
include_needs_review=include_needs_review or str(built.draft.entry_id or built.draft.entry_index) in (reviewed_keys or set()),
append_sent=append_sent,
)
batch.results.append(outcome.row)
@@ -391,6 +395,96 @@ def _build_mock_campaign_run(
return validation_report, build_result, send_batch
def _build_reviewed_mock_run(
session: Session, *, tenant_id: str, campaign: Campaign, version: CampaignVersion,
mailbox: Any | None, send: bool, include_warnings: bool, append_sent: bool,
clear_mailbox: bool = False,
) -> tuple[Any, Any, _MockSendBatch]:
"""Mock the sealed EML, never approve a new transient rendering by entry ID."""
from govoplan_campaign.backend.persistence.versions import _complete_campaign_review
from govoplan_campaign.backend.sending.execution import ensure_execution_snapshot, profile_delivery_summary
from govoplan_campaign.backend.sending.jobs import _load_eml_bytes_for_job
if not isinstance(version.execution_snapshot, dict) or not version.execution_snapshot_hash:
raise MockCampaignSendError("Build the campaign with frozen execution evidence before testing reviewed messages.")
# Do not invoke the legacy snapshot-creation fallback: this test must not
# alter Campaign state or create approval evidence as a side effect.
snapshot = ensure_execution_snapshot(session, version)
build = version.build_summary if isinstance(version.build_summary, dict) else {}
token = str(build.get("build_token") or build.get("built_at") or "")
if not token or token != str(snapshot.build_token or snapshot.built_at or ""):
raise MockCampaignSendError("The frozen execution no longer matches the current message build. Rebuild and review again.")
jobs = session.query(CampaignJob).filter(
CampaignJob.tenant_id == tenant_id, CampaignJob.campaign_version_id == version.id,
).order_by(CampaignJob.entry_index.asc()).all()
if not jobs:
raise MockCampaignSendError("The reviewed build contains no messages.")
state = (version.editor_state or {}).get("review_send", {})
complete = isinstance(state, dict) and state.get("inspection_complete") is True and state.get("build_token") == token
if any(job.validation_status in {"needs_review", "warning"} for job in jobs) and not complete:
raise MockCampaignSendError("Complete review for the exact current build before testing accepted exceptions.")
reviewed_keys = list(state.get("reviewed_message_keys", [])) if complete else []
decisions = list(state.get("issue_decisions", [])) if complete else []
_, normalized = _complete_campaign_review(session, version, reviewed_keys, decisions, user_id=None, build_token=token)
by_id = {item.get("job_id"): item for item in decisions}
for item in normalized:
prior = by_id.get(item["job_id"], {})
if any(prior.get(key) != item.get(key) for key in ("build_token", "message_sha256", "issue_fingerprint")):
raise MockCampaignSendError("Review evidence no longer matches the frozen message issues. Rebuild and review again.")
if snapshot.uses_mail:
current = profile_delivery_summary(session, version)
if current.get("smtp_transport_revision") != snapshot.smtp_transport_revision or (
append_sent and current.get("imap_transport_revision") != snapshot.imap_transport_revision
):
raise MockCampaignSendError("The selected Mail transport changed after build. Rebuild and review before testing these messages.")
built_messages = []
for job in jobs:
recipients = job.resolved_recipients or {}
attachments = [MessageAttachmentSummary.model_validate({
"status": "missing", "required": False, "allow_multiple": False, "zip_enabled": False,
"file_filter": "", "directory": "",
**{key: value for key, value in item.items() if key in MessageAttachmentSummary.model_fields},
}) for item in (job.resolved_attachments or []) if isinstance(item, dict)]
inactive = job.validation_status == "inactive"
excluded = job.validation_status == "excluded" or inactive
draft = MessageDraft(
entry_index=job.entry_index, entry_id=job.entry_id, active=not inactive,
build_status="built" if job.build_status == "built" else "build_failed",
validation_status=job.validation_status, send_status="skipped" if excluded else "draft",
imap_status="skipped" if excluded else "not_requested", subject=job.subject,
delivery_channel_policy=job.delivery_channel_policy,
**{key: recipients.get(key) for key in ("from",) if recipients.get(key)},
**{key: recipients.get(key) or [] for key in ("from_all", "to", "cc", "bcc", "reply_to", "bounce_to", "disposition_notification_to")},
issues=job.issues_snapshot or [], attachments=attachments,
attachment_count=sum(len(item.managed_matches or item.matches) for item in attachments),
eml_size_bytes=job.eml_size_bytes,
)
mime = None
if not excluded and DeliveryChannelPolicy(job.delivery_channel_policy).uses_mail:
if not job.eml_sha256:
raise MockCampaignSendError("Frozen EML checksum is missing; rebuild before testing reviewed messages.")
# The shared reader checks byte length, digest and Message-ID before
# any mock capture occurs. All messages preflight before the batch.
try:
mime = BytesParser(policy=policy.default).parsebytes(_load_eml_bytes_for_job(job))
except Exception as exc:
raise MockCampaignSendError("Frozen message bytes are unavailable or no longer match their integrity evidence. Rebuild and review before testing.") from exc
built_messages.append(BuiltMessage(draft=draft, mime=mime))
report = CampaignBuildReport(campaign_id=campaign.external_id, campaign_name=campaign.name,
campaign_file="", entries_count=len(jobs), messages=[item.draft for item in built_messages])
validation = SemanticReport(campaign_id=campaign.external_id, campaign_name=campaign.name,
entries_mode="frozen_build", entries_count=len(jobs), attachments_base_path="", rate_limit="frozen",
imap_append_enabled=snapshot.delivery.imap_append_sent.enabled)
config = SimpleNamespace(delivery=snapshot.delivery, server=SimpleNamespace(imap=None))
if clear_mailbox and mailbox is not None:
mailbox.clear_records()
batch = _mock_send_batch(config=config, built_messages=built_messages, mailbox=mailbox, send=send,
include_warnings=include_warnings, include_needs_review=False, append_sent=append_sent,
reviewed_keys=set(reviewed_keys))
return validation, CampaignBuildResult(report=report, built_messages=built_messages), batch
def _mock_validation_payload(validation_report: Any) -> dict[str, Any]:
payload = validation_report.model_dump(mode="json")
payload.update(
@@ -542,6 +636,7 @@ def run_mock_campaign_send(
append_sent: bool = True,
clear_mailbox: bool = False,
check_files: bool = False,
use_reviewed_build: bool = False,
) -> dict[str, Any]:
"""Validate, build and optionally mock-send a version without mutating it.
@@ -557,22 +652,29 @@ def run_mock_campaign_send(
campaign_id=campaign_id,
version_id=version_id,
)
mailbox = _mock_mailbox_for_run(send=send, clear_mailbox=clear_mailbox)
validation_report, build_result, send_batch = _build_mock_campaign_run(
session,
tenant_id=tenant_id,
campaign=campaign,
version=version,
mailbox=mailbox,
send=send,
include_warnings=include_warnings,
include_needs_review=include_needs_review,
append_sent=append_sent,
check_files=check_files,
)
mailbox = _mock_mailbox_for_run(send=send, clear_mailbox=clear_mailbox and not use_reviewed_build)
if use_reviewed_build:
validation_report, build_result, send_batch = _build_reviewed_mock_run(
session, tenant_id=tenant_id, campaign=campaign, version=version,
mailbox=mailbox, send=send, include_warnings=include_warnings, append_sent=append_sent,
clear_mailbox=clear_mailbox,
)
else:
validation_report, build_result, send_batch = _build_mock_campaign_run(
session,
tenant_id=tenant_id,
campaign=campaign,
version=version,
mailbox=mailbox,
send=send,
include_warnings=include_warnings,
include_needs_review=include_needs_review,
append_sent=append_sent,
check_files=check_files,
)
validation_payload = _mock_validation_payload(validation_report)
build_payload = _mock_build_payload(build_result)
return _mock_campaign_send_response(
result = _mock_campaign_send_response(
campaign=campaign,
version=version,
mailbox=mailbox,
@@ -586,3 +688,9 @@ def run_mock_campaign_send(
include_needs_review=include_needs_review,
append_sent=append_sent,
)
result["use_reviewed_build"] = use_reviewed_build
if use_reviewed_build:
result["steps"][0].update(label="Verify frozen execution inputs", status="ok")
result["steps"][1].update(label="Use reviewed frozen messages", status="ok")
result["build"]["review_satisfied"] = True
return result
+57 -11
View File
@@ -6,6 +6,9 @@ from govoplan_campaign.backend.delivery_policy import (
CampaignDeliveryPolicyError,
effective_synchronous_send_policy,
)
from govoplan_campaign.backend.german_documentation import (
localize_documentation_topics,
)
_CAMPAIGN_USER_SCOPES = (
@@ -13,6 +16,8 @@ _CAMPAIGN_USER_SCOPES = (
"campaigns:campaign:create",
"campaigns:campaign:update",
"campaigns:campaign:copy",
"campaigns:campaign:export",
"campaigns:campaign:import",
"campaigns:campaign:archive",
"campaigns:campaign:delete",
"campaigns:campaign:share",
@@ -123,12 +128,12 @@ def _workflow_topic(
)
CAMPAIGN_USER_DOCUMENTATION = (
CAMPAIGN_USER_DOCUMENTATION = localize_documentation_topics((
_workflow_topic(
topic_id="campaigns.workflow.create-campaign",
title="Create a campaign",
summary="Start a governed campaign as an editable draft and complete its purpose and ownership before adding delivery data.",
body="A new campaign starts with one editable working version. Campaign editors report saved, unsaved, and saving state in the page action bar; Discard remains immediately before Save, and leaving a dirty draft invokes the shared save-or-discard guard. Destructive campaign lifecycle actions are visually separated from ordinary actions. Creating a campaign does not grant access to Mail profiles, managed files, address sources, or delivery actions; those remain separately authorized.",
body="A new campaign starts with one editable working version. Campaign editors report saved, unsaved, and saving state in the page action bar; Discard remains immediately before Save, and leaving a dirty draft invokes the shared save-or-discard guard. Destructive campaign lifecycle actions are visually separated from ordinary actions. Creating a campaign does not grant access to Mail profiles, managed files, address sources, or delivery actions; those remain separately authorized. Saved changes are acknowledged separately from the follow-up refresh. A failed write or cancelled conflict keeps the draft; repeated Save clicks share one pending operation. Typing during a save keeps newer work unsaved instead of overwriting it with the older acknowledgement. A failed or superseded Discard refresh retains the draft. Unchanged ZIP configuration does not disable saving unrelated attachment source or rule edits. Shared attachment Add actions remain compact. If the Files chooser is temporarily unavailable, the editor explains this instead of silently treating a managed path as manual text; missing rule sources must be selected again. Keyboard Enter or Space opens chooser-backed path fields.",
order=30,
audience=("campaign_manager", "campaign_author"),
required_scopes=("campaigns:campaign:read", "campaigns:campaign:create"),
@@ -204,6 +209,39 @@ CAMPAIGN_USER_DOCUMENTATION = (
}
},
),
_workflow_topic(
topic_id="campaigns.workflow.transfer-campaign-package",
title="Export and import a portable Campaign package",
summary="Move selected Campaign configuration into a separately owned draft with an integrity check, compatibility preview, and explicit privacy scopes.",
body="Portable Campaign packages are versioned JSON envelopes. Export defaults to metadata plus template/configuration and excludes recipients, attachments, review state, and delivery history until they are explicitly selected. Recipient and delivery scopes require their existing fine-grained export permissions. Transport secrets, credential references, password-field values, local storage paths, and attachment bytes are not exported. Import verifies the SHA-256 package integrity, previews every scope that will be created or skipped, and always creates a new editable draft. Deployment-bound Mail references must be selected locally. Review, approval, and delivery evidence remains historical package provenance and is never replayed as live state.",
order=33,
audience=("campaign_manager", "campaign_configurator", "campaign_migration_operator"),
required_scopes=("campaigns:campaign:read", "campaigns:campaign:export"),
route="/campaigns/{campaign_id}",
screen="Campaign overview and Campaign list",
help_contexts=("campaign.overview", "campaigns.action.export-package", "campaigns.action.import-package"),
prerequisites=(
"You may export the source Campaign; importing additionally requires Campaign create and portable-import authority.",
"Recipient and delivery scopes have an approved purpose and destination and the corresponding recipient/report export permissions.",
),
steps=(
"Open the source Campaign overview, select Export package, and keep the privacy-safe metadata plus template/configuration default unless more data is necessary.",
"Select any additional recipient, attachment, review, or delivery scopes explicitly and download the integrity-protected JSON package to an approved location.",
"On the destination Campaign list select Import package, choose the file, and review compatibility, redactions, destination identity, created scopes, and skipped evidence.",
"Change the destination identity or selected scopes as needed, refresh the preview, and create the draft only when the preview is current and compatible.",
"Open the draft, reconnect local Mail and file resources, validate recipients and attachments, and complete ordinary review before any delivery.",
),
outcome="A separately owned Campaign draft containing only the selected portable configuration, with source/package provenance and no replayed operational state.",
verification="The destination is a new draft with a distinct ID; its settings retain the package ID, SHA-256, source and created/skipped receipt, while Audit records the matching export/import hashes without storing package content.",
related_topic_ids=("campaigns.workflow.copy-campaign", "campaigns.workflow.prepare-validate-and-build", "campaigns.workflow.export-delivery-report"),
translations={
"de": {
"title": "Portables Campaign-Paket exportieren und importieren",
"summary": "Ausgewaehlte Campaign-Konfiguration mit Integritaetspruefung, Kompatibilitaetsvorschau und expliziten Datenschutzumfaengen in einen eigenstaendigen Entwurf uebernehmen.",
"body": "Portable Campaign-Pakete sind versionierte JSON-Umschlaege. Der Export umfasst standardmaessig nur Metadaten sowie Vorlage und Konfiguration. Empfaenger, Anlagen, Pruefstatus und Zustellhistorie werden erst nach expliziter Auswahl aufgenommen und bleiben getrennt berechtigt. Transportgeheimnisse, Zugangsdatenverweise, Passwortfeldwerte, lokale Speicherpfade und Dateiinhalte werden nicht exportiert. Der Import prueft die SHA-256-Integritaet, zeigt alle erzeugten und uebersprungenen Umfaenge und erstellt immer einen neuen bearbeitbaren Entwurf. Mail-Verweise muessen lokal neu gewaehlt werden; historische Pruef-, Freigabe- und Zustellnachweise werden nie als aktiver Zustand wiedergegeben.",
}
},
),
_workflow_topic(
topic_id="campaigns.workflow.collaborate-on-campaign",
title="Discuss campaign work without changing its evidence",
@@ -252,7 +290,7 @@ CAMPAIGN_USER_DOCUMENTATION = (
topic_id="campaigns.workflow.assign-accountable-work",
title="Assign accountable Campaign work without granting access",
summary="Record bounded work for an account, group, or organization function while keeping authorization and Campaign ownership separate.",
body="Campaign work assignments record responsibility, not authority. Every reader and actor must still pass the parent Campaign access check, and a new account, group, or organization-function target is accepted only when it already resolves to active principals with Campaign access. Each assignment retains its purpose, optional due date, assigner, typed assignee reference, human-readable snapshot, current resolution state, stable Campaign or child reference, optimistic revision, and append-only transition history. Assignees with the separate completion permission can start and complete their own work; managers can reassign or cancel it. Reconciliation records vacancy, deactivation, or restored resolution without deleting history or transferring ownership. Notifications and Tasks mirroring are optional and cannot make the Campaign transaction fail.",
body="Campaign work assignments record responsibility, not authority. Every reader and actor must still pass the parent Campaign access check, and a new account, group, or organization-function target is accepted only when it already resolves to active principals with Campaign access. Each assignment retains its purpose, optional due date, assigner, typed assignee reference, human-readable snapshot, current resolution state, stable Campaign or child reference, optimistic revision, and append-only transition history. Assignees with the separate completion permission can accept, complete, or reject their own work; rejection is distinct from manager cancellation. Managers can also reassign or cancel it. Workflow-opened work additionally retains the correlation, idempotency, Workflow instance and step, exact Campaign version, and emits a common revision-bearing lifecycle event for assignment, acceptance, start, reassignment, completion, rejection, or cancellation. Workflow rechecks Campaign access before it resumes; the assignment itself never grants access. Reconciliation records vacancy, deactivation, or restored resolution without deleting history or transferring ownership. Notifications and Tasks mirroring are optional and cannot make the Campaign transaction fail.",
order=34,
audience=("campaign_manager", "campaign_reviewer", "campaign_sender"),
required_scopes=("campaigns:campaign:read", "campaigns:assignment:read"),
@@ -263,6 +301,7 @@ CAMPAIGN_USER_DOCUMENTATION = (
"campaign.work.create",
"campaign.work.action.start",
"campaign.work.action.complete",
"campaign.work.action.reject",
"campaign.work.action.reassign",
"campaign.work.action.cancel",
"campaign.work.history",
@@ -276,11 +315,11 @@ CAMPAIGN_USER_DOCUMENTATION = (
"Open Work in the selected Campaign workspace and choose Add assignment.",
"Enter a bounded purpose, optional due date, typed target, and optional stable Campaign evidence reference.",
"Resolve any authorization-neutral rejection by granting access through the separate Campaign sharing workflow or choosing another assignee; creating the assignment itself never grants access.",
"Start and complete your own assignment, or use manager actions to reassign or cancel open work.",
"Accept and complete your own assignment, reject it explicitly when it cannot be taken on, or use manager actions to reassign or cancel open work.",
"Reload and reconcile assignments after account, group, organization-function, or incumbency changes; inspect the retained history before acting on unavailable work.",
),
outcome="A durable accountability record whose lifecycle is independent from Campaign ownership, authorization, and delivery state.",
verification="Reload Work, inspect the typed target, resolution provenance, revision and history, and confirm Campaign shares and ownership did not change. When Tasks is installed, confirm the optional mirror links back to this Campaign assignment.",
verification="Reload Work, inspect the typed target, resolution provenance, revision and history, and confirm Campaign shares and ownership did not change. For Workflow-opened work, follow the focused assignment link and verify the exact terminal event and revision resume only the pinned Workflow step. When Tasks is installed, confirm the optional mirror links back to this Campaign assignment.",
related_modules=("access", "organizations", "idm", "tasks", "notifications", "audit", "policy"),
limitations=(
"Organizations and IDM are optional; organization-function assignment is unavailable until both directory and incumbency capabilities are active.",
@@ -291,7 +330,7 @@ CAMPAIGN_USER_DOCUMENTATION = (
"de": {
"title": "Verantwortliche Kampagnenarbeit zuweisen, ohne Zugriff zu vergeben",
"summary": "Begrenzte Arbeit für Konto, Gruppe oder Organisationsfunktion erfassen und Berechtigung sowie Kampagneneigentum getrennt halten.",
"body": "Kampagnenzuweisungen dokumentieren Verantwortung, nicht Berechtigung. Lesende und Handelnde müssen weiterhin den Zugriff auf die übergeordnete Kampagne nachweisen. Neue Ziele werden nur angenommen, wenn Konto, Gruppe oder alle aktuellen Funktionsinhabenden bereits Kampagnenzugriff besitzen. Zweck, optionale Fälligkeit, zuweisende Person, typisierte Referenz, lesbarer Schnappschuss, aktueller Auflösungszustand, Revision und unveränderliche Übergangshistorie bleiben erhalten. Deaktivierung oder Vakanz wird beim Abgleich als nicht verfügbar dokumentiert. Optionale Benachrichtigungen und Tasks-Spiegelungen dürfen die Kampagnentransaktion nicht blockieren.",
"body": "Kampagnenzuweisungen dokumentieren Verantwortung, nicht Berechtigung. Lesende und Handelnde müssen weiterhin den Zugriff auf die übergeordnete Kampagne nachweisen. Neue Ziele werden nur angenommen, wenn Konto, Gruppe oder alle aktuellen Funktionsinhabenden bereits Kampagnenzugriff besitzen. Zweck, optionale Fälligkeit, zuweisende Person, typisierte Referenz, lesbarer Schnappschuss, aktueller Auflösungszustand, Revision und unveränderliche Übergangshistorie bleiben erhalten. Zugewiesene Personen können Arbeit annehmen, abschließen oder ausdrücklich ablehnen; Ablehnung bleibt von einer administrativen Stornierung getrennt. Durch Workflow eröffnete Arbeit bewahrt Korrelation, Idempotenz, Workflow-Instanz und -Schritt sowie die genaue Kampagnenversion und erzeugt revisionsgebundene Lebenszyklusereignisse. Workflow prüft den Kampagnenzugriff vor der Fortsetzung erneut. Deaktivierung oder Vakanz wird beim Abgleich als nicht verfügbar dokumentiert. Optionale Benachrichtigungen und Tasks-Spiegelungen dürfen die Kampagnentransaktion nicht blockieren.",
}
},
),
@@ -519,7 +558,7 @@ CAMPAIGN_USER_DOCUMENTATION = (
topic_id="campaigns.workflow.use-managed-attachments",
title="Use managed files as campaign attachments",
summary="Select governed file versions, preview rule matches, and preserve exactly which files were used for the campaign build.",
body="Managed attachments remain owned by Files. Campaign stores governed references and frozen build evidence; it does not copy Files administration authority or accept arbitrary server paths.",
body="Managed attachments remain owned by Files. Campaign stores governed references and frozen build evidence; it does not copy Files administration authority or accept arbitrary server paths. Link required files before locking. Review and send explains why a locked version cannot change its file links. Locking is unavailable while the preview is loading and rechecks current matches at the action boundary. Newly unlinked matches require explicit Link and lock confirmation; a failed check leaves the version unlocked. Link missing files in an editable version, then validate, build and review again.",
order=34,
audience=("campaign_manager", "campaign_author"),
required_modules=("campaigns", "files"),
@@ -658,7 +697,9 @@ CAMPAIGN_USER_DOCUMENTATION = (
verification="The Campaign job shows accepted delivery, a mirrored Calendar event ID, and the current attendee status; repeated mailbox ingestion does not duplicate the response effect.",
related_topic_ids=("campaigns.workflow.prepare-validate-and-build", "campaigns.workflow.view-delivery-report"),
related_modules=("mail", "calendar"),
limitations=("Recurring Campaign invitation series require a separate series workflow; this slice creates individual VEVENT requests."),
limitations=(
"Recurring Campaign invitation series require a separate series workflow; this slice creates individual VEVENT requests.",
),
),
_workflow_topic(
topic_id="campaigns.workflow.queue-delivery",
@@ -702,7 +743,7 @@ CAMPAIGN_USER_DOCUMENTATION = (
topic_id="campaigns.workflow.send-small-controlled-run",
title="Send a campaign immediately",
summary="Run the eligible jobs synchronously only after deliberately confirming that the reviewed campaign is small enough for an interactive request.",
body="Send now is protected by an effective deployment/tenant recipient-job maximum. The server counts the exact persisted eligible build, rejects an oversized or empty run before SMTP, and preflights every message and the Mail profile revision before the first provider effect.",
body="Send now is protected by an effective deployment/system/tenant recipient-job maximum, not a campaign-size limit. The default is 25. Administration → SYSTEM → Campaign delivery can configure 0500 within any explicit deployment ceiling; TENANT may only narrow the inherited limit. The server counts the exact persisted eligible build, rejects an oversized or empty run before SMTP, and preflights every message and the Mail profile revision before the first provider effect. Worker delivery remains independent and requires working background infrastructure. A successful Mail server test proves that connection only, not the campaign's resource selection or sender/recipient authorization. Preflight distinguishes Mail profile/credential policy, SMTP configuration, authentication, and connectivity failures without exposing secret or raw provider details. SMTP checks its own credential selection; IMAP independently checks its selection when appending to Sent. Full campaign validation still checks all required selections.",
order=36,
audience=("campaign_sender", "campaign_operator"),
required_modules=("campaigns", "mail"),
@@ -759,7 +800,10 @@ CAMPAIGN_USER_DOCUMENTATION = (
topic_id="campaigns.workflow.view-delivery-report",
title="Review campaign delivery details",
summary="Inspect delivery totals and recipient-level job evidence in the current Campaign Report UI.",
body="The recipient-aware Campaign Report requires campaign-read, report-read, and recipient-read authority. Infrastructure diagnostics remain separately authorized, and the server checks every direct detail route independently of the interface.",
body=("The recipient-aware Campaign Report requires campaign-read, report-read, and recipient-read authority. Infrastructure diagnostics remain separately authorized, and the server checks every direct detail route independently of the interface. "
"Each job shows all frozen To, Cc and Bcc addresses in their authored order; legacy jobs without a recipient snapshot fall back to the primary recipient. A primary address is a row identity, not proof that only one addressee was sent. The compact list includes recipient data only with recipient-read authority; the separate aggregate report remains address-free. SMTP and IMAP status columns use selectable lists with shared labels. "
"Send now, inline retry/continue and inline append-to-Sent share a blocking progress dialog. It polls only a small, campaign-read and object-authorized version-scoped counter endpoint, not the workspace, recipients, attachments or full summary. Processed includes accepted/appended, failed, uncertain and cancelled outcomes; active work is separate from pending so no message disappears between counts. Excluded or non-requested channel work is outside its denominator. A failed progress read retains the last counters and does not imply a failed operation. A disconnected request may still be running: do not repeat it blindly. Acknowledged results survive later refresh failures. "
"Append Sent acts on the selected version, never silently on every historical version. Mail reuses a bounded authenticated connection and folder lookup across sequential APPEND commands, with current policy, references, credentials and recovery fences checked per message. Default bounds are 100 APPENDs or 300 seconds per connection; this is connection reuse, not an all-or-nothing mailbox transaction. Unknown APPEND results require evidence-backed reconciliation, never automatic replay."),
order=38,
audience=("campaign_reader", "campaign_manager", "campaign_reviewer", "campaign_sender"),
required_scopes=("campaigns:campaign:read", "campaigns:report:read", "campaigns:recipient:read"),
@@ -913,7 +957,7 @@ CAMPAIGN_USER_DOCUMENTATION = (
verification="Show archived displays the same version number and original workflow state with its archival timestamp.",
related_topic_ids=("campaigns.workflow.archive-campaign", "campaigns.workflow.view-delivery-report"),
),
)
))
def documentation_topics(context: DocumentationContext) -> tuple[DocumentationTopic, ...]:
@@ -980,6 +1024,8 @@ def _actor_capabilities(principal: object, *, mail_available: bool) -> tuple[str
_append_if(capabilities, principal, ("campaigns:campaign:create",), "Create new campaigns.")
_append_if(capabilities, principal, ("campaigns:campaign:update",), "Edit eligible working campaign versions.")
_append_if(capabilities, principal, ("campaigns:campaign:copy",), "Create an editable successor from an eligible existing version.")
_append_if(capabilities, principal, ("campaigns:campaign:export",), "Export privacy-scoped portable Campaign packages.")
_append_if(capabilities, principal, ("campaigns:campaign:import", "campaigns:campaign:create"), "Preview and import compatible portable Campaign packages as new drafts.", require_all=True)
_append_if(capabilities, principal, ("campaigns:recipient:read",), "Inspect recipients and recipient-specific campaign data.")
_append_if(capabilities, principal, ("campaigns:recipient:write",), "Add and edit recipient rows.")
_append_if(capabilities, principal, ("campaigns:recipient:import",), "Import recipient snapshots.")
@@ -0,0 +1,260 @@
from __future__ import annotations
from typing import Iterable
from govoplan_core.core.modules import DocumentationTopic, localize_documentation_topics as _localize_topics
_TRANSLATIONS = {
"campaigns.admin.delivery-policy": {
"title": "Die Grenze für interaktiven Campaign-Versand konfigurieren",
"summary": "Eine auditierte Systemgrenze für „Jetzt senden“ und engere Mandantengrenzen festlegen, ohne Kampagnen zu ändern oder Nachrichten zu senden.",
"body": "Administration → SYSTEM → Campaign-Versand erlaubt mit system:settings:read das Lesen und mit system:settings:write das Speichern der Empfängerauftragsgrenze. Der unveränderte Standard bleibt 25; Systemadministrierende dürfen ausdrücklich 0500 wählen, etwa 200 für einen Lauf mit 183 Aufträgen. Administration → TENANT → Campaign-Versand benötigt admin:policies:read/write und darf die geerbte Systemgrenze nur einschränken. Das Entfernen einer Überschreibung stellt Vererbung wieder her. Eine ausdrücklich gesetzte GOVOPLAN_CAMPAIGN_SYNCHRONOUS_SEND_MAX_RECIPIENTS bleibt einschließlich null eine verbindliche Bereitstellungsgrenze. Ohne diesen Wert verhindert der implizite Standard keine autorisierte Systemüberschreibung. Größere interaktive Läufe dauern länger und können Proxy- oder Anfragezeitlimits erreichen; für große Kampagnen bleiben Hintergrund-Worker mit CELERY_ENABLED und funktionierender Redis-/Celery-Infrastruktur die bevorzugte getrennte Betriebsart. Diese Einstellung begrenzt genau einen gespeicherten geeigneten Lauf für „Jetzt senden“, nicht die Kampagnengröße oder Worker-Verteilung. Speichern ändert ausschließlich die gewählte Einstellung mit Revisionskonfliktschutz, Vorher-/Nachher-Konfigurationshistorie und Audit. Es versendet nichts, ändert keine gespeicherten Prüfungen und umgeht weder Mail-, Prüf-, Freigabe- noch Ausführungsintegritätsprüfungen. Bei Fehlern bleibt der Entwurf erhalten. Neuladen verwendet den zentralen Schutz ungespeicherter Änderungen und liest die frische gespeicherte Richtlinie.",
},
"campaigns.workflow.create-campaign": {
"title": "Eine Kampagne anlegen",
"summary": "Eine gesteuerte Kampagne als bearbeitbaren Entwurf beginnen und Zweck sowie Eigentum vor Zustelldaten festlegen.",
"body": (
"Eine neue Kampagne beginnt mit einer bearbeitbaren Arbeitsversion. Die Aktionsleiste zeigt gespeichert, ungespeichert oder speichernd; Verwerfen steht direkt vor Speichern, und beim Verlassen eines geänderten Entwurfs greift der zentrale Speichern-oder-Verwerfen-Schutz. Destruktive Lebenszyklusaktionen sind von gewöhnlichen Aktionen getrennt. Das Anlegen gewährt keinen Zugriff auf Mail-Profile, verwaltete Dateien, Adressquellen oder Zustellaktionen; diese bleiben eigenständig autorisiert. Bestätigtes Speichern und anschließendes Neuladen sind getrennte Ergebnisse. Ein fehlgeschlagener Schreibvorgang oder abgebrochener Konflikt erhält den Entwurf; wiederholtes Speichern teilt sich einen laufenden Vorgang. Eingaben während des Speicherns bleiben als neuere ungespeicherte Arbeit erhalten. Fehlgeschlagenes oder durch neuere Änderungen überholtes Neuladen beim Verwerfen erhält den Entwurf. Unveränderte ZIP-Konfiguration sperrt nicht das Speichern unabhängiger Anlagenquellen oder Regeln. Hinzufügen-Aktionen bleiben kompakt. Eine vorübergehend fehlende Dateiauswahl wird erklärt und verwandelt verwaltete Pfade nicht stillschweigend in Texteingaben; fehlende Regelquellen müssen neu gewählt werden. Eingabe oder Leertaste öffnet die Auswahl am fokussierten Pfadfeld."
),
},
"campaigns.workflow.create-editable-successor": {
"title": "Eine bearbeitbare Nachfolgeversion anlegen",
"summary": "Nach einer dauerhaften oder zustellungsbedingten Sperre weiterarbeiten, ohne die bewahrte Version umzuschreiben.",
"body": (
"„Bearbeitbare Kopie anlegen“ erzeugt die nächste Arbeitsversion der Kampagne. Validierungssperren und vorübergehende Benutzersperren werden dagegen an der bestehenden Version aufgehoben und dürfen keine parallelen Entwürfe erzeugen."
),
},
"campaigns.workflow.import-address-source": {
"title": "Eine Adressquelle importieren",
"summary": "Ein erlaubtes wiederverwendbares Adressbuch oder eine Liste als nachvollziehbaren versionierten Snapshot in die Kampagne kopieren.",
"body": (
"Campaign folgt der Adressquelle nicht live. Es speichert die ausgewählte Quellrevision und warnt bei einer neueren Revision. Eine erneute Übernahme ist deshalb immer eine ausdrückliche Aktion der verfassenden Person."
),
},
"campaigns.workflow.import-distribution-list": {
"title": "Eine Verteilerliste übernehmen",
"summary": "Eine wiederverwendbare Zielgruppe auflösen, Kanal- und Policy-Entscheidungen prüfen und einen unveränderlichen Snapshot in die aktuelle Version kopieren.",
"body": (
"Eine Verteilerliste bleibt in ihrem verantwortlichen Modul live und versioniert. Campaign friert genau eine Auflösung ein; spätere Listen- oder Provideränderungen erzeugen nur eine Driftwarnung und schreiben gespeicherte Empfänger niemals um."
),
},
"campaigns.workflow.import-recipients": {
"title": "Empfänger importieren",
"summary": "Text-, CSV- oder Tabellendaten mit Quellprovenienz in geprüfte kampagnenlokale Empfängerzeilen überführen.",
"body": (
"Der Import kopiert gültige Zeilen in die bearbeitbare Kampagnenversion. Ungültige Zeilen bleiben in der Vorschau sichtbar, statt still zu verschwinden. Spätere Änderungen der Quelldatei ändern die gespeicherte Kampagne nicht automatisch."
),
},
"campaigns.workflow.prepare-printable-delivery": {
"title": "Eine druckbare Zustellung vorbereiten",
"summary": "Eine veröffentlichte Ausgabevorlage wählen, ein deterministisches Artefakt bauen und Route sowie Hash-Nachweis vor Post- oder Hauspostzustellung prüfen.",
"body": (
"Druckbare Zustellung ist optional und anbieterneutral. Campaign friert die Routenentscheidungen je Empfänger ein, während Templates Kompatibilität und Rendering verantwortet; Files kann das erzeugte Artefakt verwalten. Eine geordnete Ausweichroute wird nur nach bestätigter Ablehnung vor Annahme verwendet, niemals nach einer angenommenen oder im Ergebnis unbekannten digitalen Wirkung."
),
},
"campaigns.workflow.use-managed-attachments": {
"title": "Verwaltete Dateien als Kampagnenanhänge verwenden",
"summary": "Gesteuerte Dateiversionen wählen, Regelzuordnungen prüfen und exakt verwendete Dateien im Build-Nachweis bewahren.",
"body": (
"Verwaltete Anhänge bleiben Eigentum von Files. Campaign speichert gesteuerte Referenzen und eingefrorene Build-Nachweise; es übernimmt keine Files-Administrationsbefugnis und akzeptiert keine beliebigen Serverpfade."
" Verknüpfen Sie benötigte Dateien vor dem Sperren. Prüfen und Senden erklärt die Reihenfolge und warum eine gesperrte Version keine Dateiverknüpfungen mehr ändern darf. Während die Anhangsvorschau lädt, ist Sperren nicht verfügbar. Vor der Sperraktion werden Treffer frisch geprüft; neue unverbundene Treffer benötigen die ausdrückliche Bestätigung Verknüpfen und sperren. Bei fehlgeschlagener Prüfung bleibt die Version ungesperrt. Verknüpfen Sie fehlende Dateien in einer bearbeitbaren Version und validieren, bauen und prüfen Sie erneut."
),
},
"campaigns.workflow.queue-delivery": {
"title": "Eine Zustellung einreihen",
"summary": "Einen exakt geprüften Build in die Worker-Warteschlange stellen und Empfängerzustände sowie Wiederholungsschutz bewahren.",
"body": (
"Das Einreihen ist eine kontrollierte Zustandsänderung, kein Zustellnachweis. Gewöhnliche Stapel sollen Hintergrund-Worker verwenden. Angenommene und im Ergebnis unbekannte Wirkungen bleiben vor blinder Wiederholung geschützt."
),
},
"campaigns.workflow.send-calendar-invitations": {
"title": "Personalisierte Kalendereinladungen senden",
"summary": "Je Empfänger eine iCalendar-Anfrage einfrieren, über Mail zustellen und aktuelle Antworten aus Calendar prüfen.",
"body": (
"Campaign verantwortet Empfängerauflösung, exakte Einladungsanfrage, Zustellnachweis und Bericht. Calendar verantwortet gespiegeltes VEVENT und Antwortstatus. Der Spiegel entsteht erst, nachdem ein Kanal die Nachricht angenommen hat; ein Calendar-Fehler schreibt angenommenen Mail-Nachweis nie um. Mail kann METHOD:REPLY-Teile aus einer konfigurierten IMAP-Quelle für Zustellstatus weiterreichen."
),
},
"campaigns.workflow.send-small-controlled-run": {
"title": "Einen kleinen kontrollierten Lauf sofort senden",
"summary": "Geeignete Aufträge nur nach bewusster Bestätigung synchron ausführen, dass die geprüfte Kampagne klein genug ist.",
"body": (
"„Jetzt senden“ ist durch die wirksame maximale Anzahl von Empfängeraufträgen aus Bereitstellung, System und Mandant geschützt, nicht durch eine Grenze der Kampagnengröße. Standard ist 25. Administration → SYSTEM → Campaign-Versand erlaubt 0500 innerhalb einer ausdrücklichen Bereitstellungsgrenze; TENANT darf die geerbte Grenze nur einschränken. Der Server zählt den exakt gespeicherten geeigneten Build, lehnt einen zu großen oder leeren Lauf vor SMTP ab und prüft jede Nachricht sowie die Mail-Profilrevision vor der ersten Providerwirkung. Worker-Versand bleibt unabhängig und benötigt funktionierende Hintergrundinfrastruktur."
" Ein erfolgreicher Mail-Servertest belegt nur diese Verbindung, nicht die Ressourcenauswahl oder Absender-/Empfängerberechtigung der Kampagne. Die Vorprüfung unterscheidet Mail-Profil-/Zugangsdatenrichtlinien, SMTP-Konfiguration, Authentifizierung und Verbindung, ohne Geheimnisse oder rohe Providerdetails anzuzeigen. SMTP prüft seine eigene Zugangsdatenwahl; IMAP prüft seine Auswahl getrennt beim Ablegen in Gesendet. Die vollständige Kampagnenvalidierung prüft weiterhin alle erforderlichen Auswahlen."
),
},
"campaigns.workflow.view-aggregate-delivery-report": {
"title": "Aggregierte Kampagnenergebnisse prüfen",
"summary": "Datenschutzgeschützte Summen ohne Empfängerzeilen, Nachrichteninhalte, Zustelldiagnosen oder Exportbefugnis einsehen.",
"body": (
"Die aggregierte Berichtssicht zeigt nur freigegebene fachliche Kampagnenergebnisse. Positive Zellen unterhalb des konfigurierten Schwellwerts werden zusammen mit einem ergänzenden Wert oder erforderlichenfalls dem Nenner unterdrückt, damit kleine Gruppen nicht durch Subtraktion rekonstruiert werden können."
),
},
"campaigns.workflow.view-delivery-report": {
"title": "Detaillierte Zustellergebnisse prüfen",
"summary": "Zustellsummen und empfängerbezogene Auftragsnachweise in der aktuellen Campaign-Berichtsoberfläche einsehen.",
"body": (
"Der empfängerbezogene Bericht erfordert Lesezugriff auf Kampagne, Bericht und Empfänger. Infrastrukturdiagnosen bleiben getrennt autorisiert; der Server prüft jede direkte Detailroute unabhängig von der Oberfläche."
" Jeder Auftrag zeigt alle eingefrorenen An-, Cc- und Bcc-Adressen in gespeicherter Reihenfolge; ältere Aufträge ohne Empfängersnapshot verwenden die primäre Adresse. Diese identifiziert die Zeile und beweist nicht, dass nur eine Adresse angeschrieben wurde. Die kompakte Liste erfordert weiterhin Empfänger-Leseberechtigung; der getrennte aggregierte Bericht bleibt ohne Adressen. SMTP- und IMAP-Zustände verwenden Auswahllisten mit gemeinsamen Bezeichnungen."
" Jetzt senden, synchrone Wiederholung/Fortsetzung und Kopieren nach Gesendet verwenden denselben sperrenden Fortschrittsdialog. Er liest ausschließlich kleine versionsbezogene Zähler mit Kampagnen-Lese- und Objektberechtigung, nicht Arbeitsbereich, Empfänger, Anhänge oder vollständige Zusammenfassung. Verarbeitet umfasst angenommene/kopierte, fehlgeschlagene, ungewisse und abgebrochene Ergebnisse. Laufende Aufträge werden getrennt von ausstehenden gezählt; ausgeschlossene oder nicht angeforderte Kanäle gehören nicht zum Nenner. Bei Lesefehlern bleiben die letzten Zähler erhalten; dies bedeutet keinen fehlgeschlagenen Versand. Nach einer getrennten Anfrage kann die Verarbeitung weiterlaufen: Wiederholen Sie sie nicht blind. Bestätigte Ergebnisse bleiben bei späteren Aktualisierungsfehlern erhalten."
" Kopieren nach Gesendet betrifft nur die ausgewählte Version, nicht stillschweigend historische Versionen. Mail verwendet eine begrenzte authentifizierte Verbindung und Ordnerauflösung für nacheinander ausgeführte APPEND-Befehle; Richtlinie, Referenzen, Zugangsdaten und Wiederherstellungsschutz werden je Nachricht neu geprüft. Standardgrenzen sind 100 APPENDs oder 300 Sekunden pro Verbindung. Dies ist Verbindungswiederverwendung, keine atomare Postfachtransaktion. Ungewisse APPEND-Ergebnisse benötigen nachweisgestützten Abgleich und werden niemals automatisch wiederholt."
),
},
"campaigns.workflow.export-delivery-report": {
"title": "Zustellergebnisse exportieren",
"summary": "Einen autorisierten CSV-Snapshot empfängerbezogener Zustellergebnisse für kontrollierte Weiterverwendung herunterladen.",
"body": (
"Ein Berichtsexport enthält personenbezogene Daten und Zustellnachweise. Er ist entsprechend dem Kampagnenzweck sowie den geltenden Export- und Aufbewahrungsrichtlinien zu speichern, zu übertragen, aufzubewahren und zu löschen."
),
},
"campaigns.workflow.share-campaign": {
"title": "Eine Kampagne freigeben",
"summary": "Einer Person oder Gruppe ausdrücklichen Lese- oder Schreibzugriff auf eine Kampagne geben, ohne Plattformberechtigungen auszuweiten.",
"body": (
"Eine Freigabe kann den Zugriff nur innerhalb der bestehenden Rolle auf die ausgewählte Kampagne eingrenzen. Sie gewährt niemals Mail-Profilnutzung, Files-Befugnisse, mandantenweiten Empfängerzugriff oder eine fehlende Campaign-Aktion."
),
},
"campaigns.workflow.archive-campaign": {
"title": "Eine Kampagne archivieren",
"summary": "Eine abgeschlossene Kampagne aus der aktiven Arbeit entfernen und Versionen, Ergebnisse sowie Audit-Nachweise bewahren.",
"body": (
"Eine Kampagne darf erst archiviert werden, nachdem eingereihte, sendende und im Ergebnis unbekannte Arbeiten geklärt sind. Archivierung bewahrt Nachweise und ist für jede Kampagne mit Build-, Sperr- oder Zustellhistorie die richtige Lebenszyklusaktion."
),
},
"campaigns.admin.collaboration-governance": {
"title": "Campaign-Zusammenarbeit und Aufbewahrung steuern",
"summary": "Diskussionszugriff getrennt von Kampagnenbearbeitung konfigurieren und auditierbare Moderations-Tombstones bewahren.",
"body": (
"Campaign-Zusammenarbeit verwendet neben dem Lesezugriff auf die Kampagne getrennte Berechtigungen zum Lesen, Schreiben und Moderieren. Die integrierte Managerrolle darf moderieren; Prüf- und Senderollen dürfen lesen und schreiben, ohne Bearbeitungsrechte zu erhalten. Eine Lesefreigabe genügt als übergeordnete Ressourcengewährung; Kommentare werten sie nicht auf. Nur für Moderationen sichtbare Inhalte werden serverseitig gefiltert. Beiträge besitzen keine Bearbeitungs-API. Rückzug und Schwärzung entfernen die Anzeige, erhalten jedoch stabilen Eintrag, SHA-256-Nachweis, Akteursnapshot, Zeitpunkt, typisierte Referenz, Tombstone und begrenztes Audit-Ereignis. Erwähnt werden dürfen nur aktive Personen mit Eigentums- oder Freigabezugriff. Optionale Notifications erhalten inhaltsfreie Hinweise; Providerfehler macht Notifications nicht zur Pflichtabhängigkeit. Institutionelle Aufbewahrungs- und Datenschutzrichtlinien müssen Kollaborationszeilen und Audit-Nachweise gemeinsam behandeln. Kommentare sind weder Freigaben noch Workflow-Übergänge oder Systemereignisse."
),
},
"campaigns.workflow.delete-untouched-draft": {
"title": "Einen unberührten Kampagnenentwurf löschen",
"summary": "Einen Entwurf ohne geschützte Build-, Sperr-, Veröffentlichungs-, Snapshot- oder Zustellnachweise sofort entfernen.",
"body": (
"Löschen ist bewusst enger als Archivieren. Es markiert einen geeigneten Entwurf als gelöscht und erzeugt einen Audit-Eintrag. Eine Kampagne mit bereits aufbewahrungspflichtigen Nachweisen kann dadurch nicht entfernt werden."
),
},
"campaigns.privacy.data-subject-requests": {
"title": "Campaign-Daten in einer Datenschutzanfrage prüfen",
"summary": "Empfänger-, Kollaborations-, Versions-, Zustell-, Berichts- und Artefaktmetadaten ermitteln, ohne unveränderliche Nachweise umzuschreiben.",
"body": (
"Der Campaign-DSAR-Anbieter sucht im wirksamen Mandanten nach normalisierter Empfänger-E-Mail, direkten Mitgliedschaftsreferenzen und namensraumbezogenen Campaign-Kennungen. Er isoliert passende Inline-Empfängerfelder und Auftragsmetadaten und meldet gebaute Versionen, Zustellversuche, Postbox- und Druckergebnisse, Korrekturen, empfängerbezogene Berichte, Nachrichtendigests, Anhangsmetadaten und betroffene Kollaboration. Eigener Beitragstext wird ausgegeben; fremder Text nicht allein wegen einer Erwähnung. EML-Bytes, Objekt- oder lokale Pfade, Providerziele, Worker-Claims, Idempotenzdaten, Geheimnisse, Zugangsdaten und fremde Empfängeradressen bleiben ausgeschlossen. Gebaute, gesperrte, veröffentlichte, abgeschlossene, zugestellte, korrigierte, zurückgezogene oder geschwärzte Datensätze bleiben begründet erhalten. Tombstones, Hashwerte und Audit-Nachweise sind unveränderlich. Entwurfsempfänger und benutzereigene Anhänge benötigen koordinierte manuelle Prüfung. Der Provider kann ein persönliches Import-Mappingprofil idempotent löschen und eine aktive Freigabe für die betroffene Person widerrufen; zugestellte Nachweise und erzeugte Artefakte werden nie direkt gelöscht."
),
},
"campaigns.workflow.archive-historical-version": {
"title": "Eine historische Kampagnenversion archivieren",
"summary": "Eine nicht aktuelle Version aus der Standardhistorie ausblenden, ohne aufbewahrte Nachweise zu ändern oder zu löschen.",
"body": (
"Die Archivierung einer historischen Version betrifft nur ihre Darstellung. Ursprünglicher Workflow-Zustand, Konfiguration, Berichte, Zustellergebnisse und Audit-Nachweise bleiben für autorisierte Personen lesbar und werden bei eingeblendeten archivierten Versionen mitgeführt."
),
},
"campaigns.search.campaigns": {
"title": "Autorisierte Kampagnen durchsuchen",
"summary": "Kampagnenidentität und Lebenszyklusmetadaten für die berechtigungsbewusste Plattformsuche bereitstellen.",
"body": (
"Wenn Search installiert ist, trägt Campaign aktuelle Namen, externe Kennungen, Beschreibungen und Lebenszykluszustände bei. Vor einem Ergebnis werden Mandant, Eigentum, Gruppeneigentum, ausdrückliche Freigaben, Widerruf, Löschung und Campaign-Leseberechtigung erneut geprüft. Bestätigte Kampagnen- und Freigabeänderungen aktualisieren den abgeleiteten Index über den dauerhaften Plattform-Ereignispfad; ein Neuaufbau verändert keine Campaign-Nachweise."
),
},
"campaigns.postbox-delivery": {
"title": "Campaign-Nachrichten an Postboxen zustellen",
"summary": "Je Empfängerzeile eine oder mehrere exakte oder organisationsabgeleitete Postboxen allein oder neben Mail adressieren.",
"body": (
"Konfiguriert werden kampagnenweite Ziele und optionale Ergänzungen oder Ersetzungen je Zeile. Abgeleitete Ziele lösen eine veröffentlichte Postbox-Vorlage mit Organisationseinheit, Funktion und optionalen Kontextwerten auf; Werte dürfen aus Campaign-Feldern stammen. Ziele werden beim Build eingefroren. Ein Ausweichen zum zweiten Kanal erfolgt nur nach bestätigter Ablehnung vor Annahme; angenommene oder im Ergebnis unbekannte Wirkungen lösen kein Fallback aus."
),
},
"campaigns.mail-profile-user-journey": {
"title": "Ein Mail-Profil für die Kampagnenzustellung wählen",
"summary": "Campaign referenziert ein autorisiertes Mail-Profil und speichert niemals SMTP-/IMAP-Einstellungen oder Zugangsdaten.",
"body": (
"Mail-Einstellungen → Wiederverwendbares Mail-Profil → SMTP-Zugangsdaten (bei Nutzung auch IMAP-Zugangsdaten) speichert eine ausdrückliche Zugangsdatenkennung. Eine leere Auswahl bedeutet Vererbung nur soweit die Mail-Richtlinie dies erlaubt; ein Profilstandard ist keine gespeicherte Kampagnenauswahl. Fehlende oder inaktive gespeicherte Profile, Server und Zugangsdaten bleiben sichtbar nicht verfügbar und werden nicht stillschweigend ersetzt. "
"In den Mail-Einstellungen der Kampagne wird ein verfügbares Profil ausgewählt, über Mail getestet und gespeichert. Bei gemeldeten kampagnenlokalen Alt-Transportdaten wählen Sie nach der autorisierten Profilauswahl „Ausgewähltes Mail-Profil migrieren“. Diese ausdrückliche Aktion funktioniert auch bei unveränderter Profilauswahl und unberührtem Entwurf. Gesperrte historische Nachweise bleiben erhalten; verwenden Sie zuvor die angebotene Entsperrung oder bearbeitbare Nachfolgeversion. „Prüfen und Senden“ zeigt den Migrationsblocker mit Rückweg zu den Mail-Einstellungen, statt wiederholt eine ungültige Anhangsvorschau anzufordern. Die Profilauswahl lädt nur für die Kampagne autorisierte Profile; ein Fehler beim getrennten administrativen Richtlinienkatalog leert sie nicht. Validierung und Zustellung prüfen die Profilberechtigung erneut. Migration speichert Konfiguration, versendet aber keine E-Mail. Validieren, bauen und prüfen Sie die resultierende Version vor der Zustellung erneut."
" Mail-Migration und ZIP-Richtlinienkorrekturen lassen sich in beliebiger Reihenfolge speichern. Unveränderte ZIP-Einstellungen blockieren die Migration nicht und erhalten keinen neuen Zustimmungsnachweis. Eine Archiv- oder Inhaltskorrektur mit unveränderten Mail-Referenzen erhält den alten Transport serverseitig und zeigt weiterhin den Migrationshinweis; es erfolgt keine stillschweigende Migration. Ein bestätigtes Speichern und das anschließende Neuladen des Arbeitsbereichs sind getrennte Ergebnisse: Bei fehlgeschlagenem Neuladen bleiben die letzten nutzbaren Daten derselben Kampagne und Version sichtbar, ergänzt um den Fehler. Wiederholen Sie Neuladen; veraltete Antworten einer anderen Kampagne, Version, Identität oder früheren Aktualisierung dürfen den aktuellen Arbeitsbereich nicht ersetzen."
),
},
"campaigns.mail-profile-governance": {
"title": "Campaign-zu-Mail-Profilreferenzen steuern",
"summary": "Mail besitzt Transportdefinitionen und verschlüsselte Zugangsdaten; Campaign nur die Profilreferenz und Zustellnachweise.",
"body": (
"Kampagnenverfassende erhalten mail:profile:use; verfügbare Profile werden über Mail-Policy begrenzt und es wird ausdrücklich festgelegt, ob Profil-Zugangsdaten geerbt werden dürfen oder eine Kampagne Mail-eigene Zugangsdaten auswählen muss. Die Mail-Richtlinienseite zeigt die SMTP-/IMAP-Zugangsdatenvererbung mit lokalen, geerbten und wirksamen Werten sowie übergeordneten Sperren. Inline-Transportfelder werden abgelehnt und niemals samt Zugangsdaten an den Browser zurückgegeben. Altbestände bleiben unverändert, bis eine ausdrückliche auditierte Profilmigration eine bearbeitbare Version erzeugt oder aktualisiert. Dafür genügt auch das schon referenzierte Profil, wenn „Ausgewähltes Mail-Profil migrieren“ verwendet wird. Mail-Einstellungen laden nur die für diese Kampagne nutzbaren Profile; der administrative Richtlinienkatalog wird getrennt auf der Mail-Richtlinienseite angefordert und Fehler bleiben dort sichtbar. Diese Trennung verleiht keine Profiladministration und umgeht weder Eigentümer-, Mandanten- noch Mail-Autorisierung. Migration versendet keine E-Mail und stellt keinen alten Ausführungssnapshot wieder her."
" Unabhängige Entwurfskorrekturen dürfen das exakt gespeicherte alte Serverobjekt nur bei unveränderten öffentlichen Mail-Referenzen erhalten; Inline-Transport darf nicht mitgesendet werden. Dabei wird Inhalt gespeichert, kein Profil ausgewählt oder genutzt, auch nach Entzug seiner Berechtigung. Ausdrückliche Migration benötigt weiterhin mail:profile:use und aktuelle Mail-Policy. Der Versions-Auditnachweis unterscheidet legacy_mail_settings_preserved und legacy_mail_settings_migrated. Unveränderte ZIP-Konfiguration wird nicht erneut bestätigt; geänderte ZIP-Einstellungen unterliegen allen Richtlinienprüfungen. Erfolgreiche Korrekturen entwerten bisherige Build- und Ausführungsnachweise und lockern weder Validierung noch Prüfung oder Versand."
" Bereits migrierte Entwürfe folgen derselben Regel für unveränderte Referenzen: Eine spätere Pflicht zur ausdrücklichen SMTP-/IMAP-Zugangsdatenwahl verhindert keine unabhängige Archiv- oder Inhaltskorrektur. Jede geänderte Mail-Ressourcenauswahl benötigt weiterhin Mail-Berechtigung und aktuelle Richtlinie; verbindliche Validierung und Zustellung prüfen stets die vollständige Auswahl erneut."
),
},
"campaigns.mail-profile-operations": {
"title": "Profilbasierte Kampagnenzustellung betreiben",
"summary": "Worker autorisieren und lösen Mail-Profile bei Ausführung neu auf; Campaign bewahrt nur undurchsichtige Mail-Revisionen und Ergebnisse.",
"body": (
"SMTP- und IMAP-Laufzeitaktionen prüfen die Zugangsdatenpflicht getrennt je Protokoll; ein SMTP-Aufruf benötigt keine IMAP-Parameter und umgekehrt. Vollständige Kampagnenvalidierung und Build-Zusammenfassung prüfen weiterhin beide erforderlichen Auswahlen. Die Vorprüfung unterscheidet Mail-Profil-/Zugangsdatenrichtlinienfehler von SMTP-Konfigurations-, Authentifizierungs- und Verbindungsfehlern. Ein erfolgreicher Servertest ersetzt keine kampagnenspezifische Autorisierung. "
"Ein Altsnapshot, unautorisiertes oder inaktives Profil, Referenzkonflikt oder eine geänderte SMTP-/IMAP-Revision stoppt die Zustellung. Synchrone Stapel prüfen DNS, Verbindung, TLS und Authentifizierung vor der ersten Wirkung, verwenden eine begrenzte gesunde SMTP-Verbindung wieder und verbinden bei Alterung neu. Oberfläche und Bericht zeigen Stapel-, Verbindungs-, Wiederverbindungs-, Fehler- und Pausenzahlen. Systemische Authentifizierungs-, Absender- oder Verbindungsfehler pausieren übrige Aufträge mit stabilem Grund; das Profil ist zu korrigieren und zu testen, bevor ausdrücklich fortgesetzt wird. Verbindungsverlust nach Beginn von DATA bleibt ergebnisoffen und wird nicht automatisch wiederholt. Der Datensatz wird bewahrt, Profilwahl korrigiert, erneut validiert und gebaut und erst dann neu eingereiht. Reine Passwortrotation kopiert keine Geheimnisse nach Campaign. Unsichere SMTP-/IMAP-Wirkungen bleiben bis zum evidenzbasierten Betriebsabgleich blockiert. Wird Campaign nach Annahme eines Auftrags für den Mandanten unzugänglich, bleibt er unangetastet und wird als Betriebsaktion gemeldet."
),
},
"campaigns.workflow.prepare-validate-and-build": {
"title": "Eine Kampagne vorbereiten, validieren und bauen",
"summary": "Gesteuerte Empfänger-, Vorlagen-, Anhangs- und Mail-Profil-Eingaben in exakte Nachrichten zur Prüfung überführen.",
"body": (
"Jede Eingabe wird in ihrer verantwortlichen Oberfläche vorbereitet, alle blockierenden Validierungsprobleme werden gelöst und exakte Empfängernachrichten vor der Prüfung gebaut. Empfängerzeilen können als eine ausdrücklich bestätigte Entwurfsänderung gesammelt aktiviert oder deaktiviert werden; Speichern erzeugt normale Versionsnachweise und verwirft veraltete Validierungs-, Build- und Prüfzustände. Passwortfelder verwenden den zentralen sicheren Generator, dessen Vorschlag erst nach „Passwort verwenden“ übernommen wird. Campaign friert Empfänger- und Anhangsnachweise für die ausgewählte Version ein; spätere Quelländerungen ändern den Build nicht. Kennzahlen bieten nur dann einen benannten Drill-down, wenn eine autorisierte Quellsammlung, gefilterte Prüftabelle, Anhangsvorschau oder ein Bericht eine Handlung ermöglicht. Datenschutzunterdrückte Aggregate bleiben nicht interaktiv. Ist Templates installiert, besitzt dessen einziger Navigationseintrag die wiederverwendbare Bibliothek; kampagnenspezifische Komposition bleibt im Arbeitsbereich."
" In individuellen und globalen Adressdialogen bestimmen die Auf-/Ab-Aktionen die gespeicherte Adressreihenfolge. Speichern im Dialog übernimmt diese Reihenfolge ohne alphabetische Neusortierung in den Kampagnenentwurf; doppelte E-Mail-Adressen behalten ihre erste Position. Eingefügte Adressen werden in Eingabereihenfolge angehängt, ohne vorhandene Adressen umzuordnen. Die erste individuelle An-Adresse bleibt der primäre Name und die E-Mail-Adresse der Empfängerzeile. Speichern Sie anschließend die Kampagnenseite, um den Entwurf dauerhaft zu übernehmen; bei einem Fehler bleibt die Reihenfolge für einen ausdrücklichen neuen Speicherversuch erhalten. Abbrechen verwirft gezielt nur die noch unbestätigten Dialogänderungen."
),
},
"campaigns.workflow.complete-review": {
"title": "Die Kampagnenprüfung abschließen",
"summary": "Kritische Blocker lösen, einzelne Nachrichten entscheiden und unkritische Punkte für genau einen Build bestätigen.",
"body": (
"Das Öffnen der Vorlage ohne Bearbeitung, Änderungen des Schreibschutzes und der Wechsel zwischen visueller Ansicht und Quelltext erhalten das gespeicherte HTML unverändert und erfordern beim Verlassen kein Speichern. Der Prüfabschluss bleibt an aktuellen Build-Token, geprüfte Nachrichtenschlüssel, dokumentierte Problementscheidungen und Nachrichtennachweise gebunden. Normales Speichern sendet nur die clientverantworteten Metadaten created_from, field_overrides und opt_ins; review_send und approval_gate sind lesbare Servernachweise, aber keine schreibbaren Editorfelder. Werden sie bei einem Metadaten-Speichern ausgelassen, bleiben sie serverseitig erhalten. Die vorgesehenen Regeln für Entsperrung, Nachfolgeversionen und Build-Invalidierung entfernen veraltete Nachweise weiterhin. Bei notwendiger Mail-Altdatenmigration bleibt „Prüfen und Senden“ schreibgeschützt, unterdrückt inkompatible Anhangsvorschau-Anfragen und bietet „Mail-Einstellungen öffnen“ für genau die ausgewählte Version. Migrieren, validieren, bauen und prüfen Sie vor dem Senden erneut. Ausdrückliche Aktionen auf handlungsfähigen Empfänger-, Anhangs-, Validierungs- und Prüfkennzahlen öffnen Quellseite, Nachweisvorschau oder gefilterte Nachrichtentabelle. Reine Information und datenschutzunterdrückte Werte werden nicht zu versteckten Klickzielen. Änderungen an Empfängern, Inhalt, Anhängen, Eigentümerkontext oder nicht geheimer Transportidentität erfordern erneut Validierung, Build und Prüfung."
" Gleichartige Prüfbedingungen bestätigen gruppiert ausschließlich vom Server zugelassene, ungeprüfte Nachrichten aus der aktuell geladenen passenden Auswahl. Wählen Sie eine verständlich benannte Kategorie, prüfen Sie die gezählte Empfängerauswahl und geben Sie bei Anhangsausnahmen eine gemeinsame Begründung an. Jede Anfrage benennt höchstens 200 konkrete Nachrichten und prüft aktuellen Build und Kategorie; wiederholen Sie dies für verbleibende Nachrichten, statt andere Kategorien oder nicht geladene Nachrichten als mitbestätigt anzusehen. Jede ausgewählte Nachricht erhält einen eigenen eingefrorenen, zuordenbaren Entscheidungsnachweis. Bei fehlgeschlagenem Speichern bleiben Begründung und Auswahl für einen ausdrücklichen Wiederholungsversuch erhalten; ein geänderter Build verhindert veraltete Bestätigungen. Die Gruppenbestätigung sendet keine Nachrichten und schließt die abschließende Prüfung nicht ab. Harte Blocker können nicht übergangen werden. Beabsichtigte richtlinienbedingte Ausschlüsse und ausdrücklich erlaubte Anhangsregeln ohne Treffer bleiben informativ und benötigen keine Prüfentscheidung."
" Eine einzelne Annahme speichert Begründung und Prüfstatus sofort, schon vor dem vollständigen Prüfabschluss; Neuladen setzt den bestätigten Fortschritt desselben Builds fort. Bei fehlgeschlagenem Speichern oder einem Konflikt bleibt die Begründung für einen ausdrücklichen neuen Versuch erhalten; die Nachricht gilt noch nicht als geprüft. Jeder Speichervorgang ergänzt nur ausgewählte Nachrichten und erhält fremde Prüfnachweise, ohne Nachrichten neu zu bauen, Anhangsdateien zu prüfen oder den gesamten Arbeitsbereich neu zu laden. Teilfortschritt erlaubt keinen Versand; der abschließende Prüfabschluss kontrolliert weiterhin alle erforderlichen Entscheidungen und harten Blocker. Pflichtanhänge und harte Sperrrichtlinien bleiben gegenüber optional erlaubten leeren Treffern vorrangig; auch die getrennte Kampagnenrichtlinie für vollständig anhangslose Nachrichten gilt weiterhin."
" Speichern benötigt die Campaign-Prüfberechtigung, die aktuelle Versionsrevision und den sicheren operativen Bezug review_build_token; Diagnoseberechtigung ist nicht erforderlich. Veraltete Builds oder gleichzeitige Änderungen führen zu einem Konflikt ohne Überschreiben gespeicherten Fortschritts."
" Bestätigte oder erwartete Anhangsbedingungen bleiben für denselben Build auch bei „Bestätigen und senden“ erfüllt; fehlende oder mehrdeutige Quelltreffer bleiben als Kontext sichtbar, erzeugen aber keine zweite Bestätigungspflicht. Der Mock-Test nach der Prüfung verwendet verifizierte eingefrorene Nachrichten und abgeschlossene Entscheidungen statt einer Neuerstellung. Geänderte Eingaben, Problemnachweise, Nachrichtenbytes oder Mail-Transport stoppen den Test vor der Mock-Aufzeichnung; Entwurfsvorschauen behalten ihren getrennten vorläufigen Build."
" Validierungsdetails und Listen mehrfach verwendeter Dateien zeigen alle Einträge über die zentrale DataGrid-Seitensteuerung. Zusammengehörige fehlende Regeltreffer und die Richtlinienfolge einer anhangslosen Nachricht werden gemeinsam erklärt; aufklappbare technische Nachweise bleiben erhalten. Nachrichtentabelle und Filter verwenden vier operative Zustände: Bereit, Prüfung erforderlich, Blockiert und Ausgeschlossen. Angenommene ausdrückliche Entscheidungen werden Bereit; noch unbestätigte Warnungen bleiben Prüfung erforderlich. Eine zweite Spalte erklärt den Zustand. Diese Darstellung löscht oder verändert keine eingefrorenen Probleme oder Auditnachweise."
),
},
"campaigns.workflow.retry-and-reconcile": {
"title": "Fehler wiederholen und unsichere Wirkungen abgleichen",
"summary": "Sicher wiederholbare Fehler von Mail-, Postbox- oder IMAP-Wirkungen mit unbekanntem Ergebnis trennen.",
"body": (
"Eine Wiederholung erzeugt neuen Versuchsnachweis und ist nur für ausdrücklich geeignete Zustände zulässig. Unbekannte Mail-, Postbox- oder IMAP-Wirkungen dürfen nie blind wiederholt werden. Externe Nachweise sind zu prüfen und der betroffene Kanal vor dem Fortsetzen abzugleichen. Angenommene Mail-Versuche und Postbox-Ziele bleiben bei Teilwiederholungen unveränderlich; die Reparatur von „Gesendet“ versendet angenommene Mail nicht erneut."
" Ohne Worker bietet der Bericht ausdrücklich bestätigte, begrenzte Wiederholung und Fortsetzung über dieselben unveränderlichen Aufträge, Ausführungsprüfungen, Prüfnachweise, Freigaben, Mail-Berechtigungen, Ratenbegrenzungen und Wiederherstellungsnachweise wie Jetzt senden. Jede Anfrage bleibt innerhalb der wirksamen synchronen Grenze und meldet verbleibende Arbeit; bereits angenommene, ausgeschlossene, aktive und ungewisse Aufträge werden nicht erneut gesendet. Wiederholung benötigt campaigns:campaign:retry und synchron zusätzlich campaigns:campaign:send; Fortsetzen benötigt campaigns:campaign:queue und campaigns:campaign:send. Abgleich benötigt campaigns:campaign:reconcile und eine sachliche Nachweisnotiz; er sendet nichts."
" Ein festhängender übernommener, sendender oder kopierender Auftrag ist nicht allein durch Zeitablauf sicher. Der Bericht bietet die Wiederherstellung eines unterbrochenen Auftrags nur bei abgelaufener dauerhafter Sperre und nachweislich gestoppter oder ersetzter ursprünglicher Laufzeit. Die mitgesendete sichere Revision muss noch passen, und ursprüngliche Wiederherstellungsnachweise müssen gültig sein. Die Aktion setzt das Ergebnis ausschließlich auf ungewiss. Prüfen Sie Provider- beziehungsweise Postfachnachweise und gleichen Sie angenommen/nicht gesendet oder kopiert/nicht kopiert getrennt ab, bevor Sie ausdrücklich wiederholen. Fehlende Sperr- oder Versuchsnachweise und unbestätigte Besitzer bleiben zur betrieblichen Untersuchung gesperrt. Ein doppelter Worker-Aufruf verändert aktive Zustände nicht."
),
},
"campaigns.reference.composition-assurance": {
"title": "Die Campaign-Referenzkomposition absichern",
"summary": "Campaign nur mit abgestimmten Verträgen, rollensicheren Oberflächen, dauerhaften Wirkungsnachweisen, optionaler Modultrennung und wiederherstellbaren Daten freigeben.",
"body": (
"Freigabeprüfungen müssen Campaign-Validierung und Anhangsauflösung unabhängig in frischen Prozessen initialisieren, ohne einen früheren Seiten- oder Testimport vorauszusetzen. Diese lokalen Einstiegspunkte bleiben ohne installiertes Mail oder Files nutzbar; ihr Import startet keinen Versand und lockert keine Pfadberechtigungen für verwaltete Dateien. "
"Campaign ist nur dann Referenzkomposition, wenn Core, Mail, Files, Addresses, Worker, Speicher, Policies und Dokumentation in genau der installierten Kombination geprüft sind. Gewöhnliche Lesende sehen Fachzustand statt Pfaden, Speicherschlüsseln, Worker-Claims oder rohen Providerdiagnosen; Diagnose- und Exportbefugnis bleiben getrennt."
" Prüfen Sie, dass einzelne Begründungen und Prüfzustände schon vor dem vollständigen Abschluss Neuladen überstehen. Teilfortschritt benötigt campaigns:campaign:review und Schreibzugriff, ergänzt genau ausgewählte Nachrichten des aktuellen Builds mit Revisionsprüfung und protokolliert Annahmen ohne fremde Prüfnachweise zu ersetzen. Der operative review_build_token legt keine rohen Diagnosetoken offen. Teilfortschritt erlaubt keinen Versand; harte Blocker sind nicht bestätigbar. Richtlinienbedingte Ausschlüsse und ausdrücklich erlaubte leere optionale Anhangsregeln erzeugen keine neue Prüfpflicht; Pflichtanhänge und globale harte Sperren bleiben wirksam. Diese Auflösungsänderungen gelten nur für neue Builds: Eine bewusste Neuerstellung klassifiziert vorhandene Nachrichten neu und entwertet frühere Prüf- und Freigabenachweise. Eingefrorene historische Auftragsprobleme dürfen nicht aus veränderlichen Richtlinien umgeschrieben werden."
" Der ausdrückliche Mock-Modus use_reviewed_build benötigt einen vorhandenen versiegelten Ausführungsnachweis und bei prüfpflichtigen Nachrichten den Abschluss desselben Builds. Vor jeder Mock-Aufzeichnung oder angeforderten Leerung des Mock-Postfachs prüft er Auftrags- und Problemnachweise, EML-Länge, Digest, Message-ID und aktuellen Mail-Transport. Er sendet kein SMTP, verändert keinen Campaign-Zustellstatus und erzeugt keinen fehlenden Altdaten-Snapshot. include_needs_review ist in diesem Modus keine pauschale Umgehung."
),
},
"campaigns.reference.shared-build-artifacts": {
"title": "Gemeinsam genutzte Campaign-Build-Artefakte betreiben",
"summary": "Erzeugte Nachrichten in gemeinsamem Objektspeicher ablegen und vor der Zustellung verifizieren.",
"body": (
"Campaign speichert erzeugte EML unter undurchsichtigen gemeinsamen Objektschlüsseln und protokolliert erwartete Größe, SHA-256-Digest und Message-ID je Auftrag. Worker auf anderen Knoten prüfen diesen Nachweis vor Zustellung. Vor Objekt- oder Files-Ausgaben zeichnet eine lease-gebundene Core-Recovery-Operation Quelle, validierte Version und reserviertes Präfix auf, prüft das Objekt und erneuert die Sperre vor dem Fach-Commit. Eine getrennte auftragsgebundene Operation erfasst vor realer Mail-, Postbox- oder Druckwirkung unveränderliche Nachrichten- und Empfängerdigests und verifiziert später den autoritativen Kanalversuch. Ablehnung, Annahme, unbekanntes Ergebnis und Recovery-Bedarf bleiben unterscheidbar. Objektfehler weisen Kompensation nach; Files-Ausgaben und unsichere Bereinigung bleiben Vorwärts-Recovery. Aufbewahrung ändert Locator kontrolliert und prüft Abwesenheit unabhängig. Ein reiner Betriebsabgleich inventarisiert begrenzte Mandantenpräfixe, schützt aktive Builds und mindestens 24 Stunden Karenz und löscht nur weiterhin unreferenzierte Objekte. Laufzeitobjektschlüssel sind keine Fachdaten."
),
},
"campaigns.archive-encryption-governance": {
"title": "Passwortgeschützte ZIP-Anhänge gesteuert verwenden",
"summary": "Standardmäßig AES einsetzen und schwaches Windows-kompatibles ZipCrypto nur mit Policy, Berechtigung, Bestätigung und Nachweis wählen.",
"body": (
"Campaign löst Archivverschlüsselung über Policy auf System-, Mandanten-, Eigentümer- und Kampagnenebene auf. Passwortgeschützte Archive verwenden AES, außer die vollständig vererbte Richtlinie erlaubt Legacy ZipCrypto ausdrücklich und die handelnde Person besitzt campaigns:archive:use_legacy_zipcrypto. Die Legacy-Auswahl benötigt eine begründete Bestätigung. Passwörter erscheinen weder im Campaign-Nachweis noch in der Nachricht und müssen über den getrennt ausgewählten, per Policy erlaubten Kanal übermittelt werden. Jeder Build friert Archiv- und Mitglied-Hashes, Implementierungsversion, Policy-Hash und -Quellpfad, bestätigende Person, Begründung, Zeitpunkt und Build-Identität ein. Eine später strengere Policy blockiert Einreihen und Senden bis zum Neubau; nach Fehlern wird nie von AES auf ZipCrypto zurückgefallen. Temporärer Klartext und Archive bleiben im begrenzten Build-Verzeichnis und werden nach Erfolg oder Fehler entfernt."
" Kampagneneinstellungen, Richtlinien und Anhänge zeigen die wirksame Richtlinie und führen berechtigte Administrierende direkt zu Administration → SYSTEM → Campaign archive encryption. Aktivieren Sie dort Legacy ZipCrypto und speichern Sie. Frische Systemstandardwerte sind bearbeitbar, ohne dass das bloße Öffnen bereits eine Ausnahme erzeugt. Mandanten- und Eigentümerrichtlinien können das Ergebnis weiter einschränken. Laden Sie anschließend in Campaign die Archivrichtlinie neu, wählen Sie Legacy ZipCrypto unter Anhänge → ZIP-Anhänge, bestätigen Sie die schwache Verschlüsselung und geben Sie eine betriebliche Begründung mit mindestens 10 Zeichen an. Ohne Policy bleibt Legacy gesperrt. Weder Richtlinien- noch Anhangskonfiguration versendet beim Speichern eine E-Mail."
" Mail-Migration und Archivkorrekturen lassen sich unabhängig in beliebiger Reihenfolge speichern. Eine exakt unveränderte ZIP-Konfiguration bleibt bei einer anderen Korrektur ohne erneute Bestätigung erhalten, auch nach Entzug von Richtlinie oder Berechtigung; ihre Nutzung wird dadurch nicht erlaubt. Jede geänderte ZIP-Konfiguration muss aktuelle Methoden, Passwortkanäle und Legacy-Berechtigungs- sowie Bestätigungsvorgaben erfüllen. Eine Archivkorrektur mit unveränderten öffentlichen Mail-Referenzen erhält den alten Transport exakt serverseitig bis zur ausdrücklichen autorisierten Migration. Clients dürfen dabei weder Inline-Transport einführen oder zurücksenden noch Mail-Referenzen ändern oder Bestätigungsnachweise erfinden. Beide Korrekturen entwerten Ausführungs- und Build-Nachweise; Validierung, Prüfung, Erstellung und Versand bleiben bis zur Erfüllung aller Bedingungen gesperrt."
),
},
"campaigns.workflow.link-exact-campaign-to-case": {
"title": "Eine exakte Kampagnenreferenz mit einem aktiven Fall verknüpfen",
"summary": "Eine autorisierte Kampagne und ihre aktuelle unveränderliche Version über Quick Access zurückgeben, ohne Kampagneninhalt zu kopieren.",
"body": (
"Ist ein Fall das aktive Objekt, stellt Campaigns in Quick Access eine begrenzte Auswahl bereit. Die normale Kampagnenliste prüft Mandant, Eigentum, Gruppe, Freigaben und Administrationszugriff vor der Anzeige. Die Auswahl liefert über den versionierten Ergebnisvertrag nur Eigentümermodul, stabile Kampagnen-ID, aktuelle Versions-ID, Anzeigetext, Mandant und Eigentümerroute. Cases verwirft den Anzeigetext und speichert keine Empfänger-, Nachrichten-, Anhangs-, Zustell-, Berichts- oder Konfigurationsinhalte. Beim Öffnen prüft Campaigns den Zugriff erneut. Deaktivierung, Widerruf oder Entfernung lässt daher nur eine nicht verfügbare historische Fallreferenz zurück und macht Fallzugriff nie zu Kampagnenzugriff."
),
},
}
def localize_documentation_topics(
topics: Iterable[DocumentationTopic],
) -> tuple[DocumentationTopic, ...]:
return _localize_topics(topics, locale="de", translations=_TRANSLATIONS)
File diff suppressed because it is too large Load Diff
@@ -343,6 +343,28 @@ class MailCampaignIntegration:
except getattr(delegate, "MailProfileError", MailProfileError) as exc:
raise MailProfileError(str(exc)) from exc
@contextmanager
def campaign_imap_batch(self, *, tenant_id: str, campaign_id: str) -> Iterator[Any]:
"""Use Mail-owned connection reuse when the installed capability offers it."""
delegate = self._require()
method = getattr(delegate, "campaign_imap_batch", None)
if not callable(method):
yield None
return
try:
with method(tenant_id=tenant_id, campaign_id=campaign_id) as state:
yield state
except getattr(delegate, "ImapAppendError", ImapAppendError) as exc:
raise ImapAppendError(
str(exc),
temporary=getattr(exc, "temporary", None),
outcome_unknown=bool(getattr(exc, "outcome_unknown", False)),
) from exc
except getattr(delegate, "ImapConfigurationError", ImapConfigurationError) as exc:
raise ImapConfigurationError(str(exc)) from exc
except getattr(delegate, "MailProfileError", MailProfileError) as exc:
raise MailProfileError(str(exc)) from exc
def append_campaign_message_to_sent(self, *args: Any, **kwargs: Any) -> Any:
delegate = self._require()
try:
+285 -18
View File
@@ -1,5 +1,8 @@
from __future__ import annotations
from govoplan_core.core.modules import with_documentation_structured_translations
from govoplan_campaign.backend.german_structured_documentation import GERMAN_STRUCTURED_TRANSLATIONS
from pathlib import Path
from govoplan_core.core.access import (
@@ -14,6 +17,7 @@ from govoplan_core.core.campaigns import (
CAPABILITY_CAMPAIGNS_POLICY_CONTEXT,
CAPABILITY_CAMPAIGNS_RETENTION,
CAPABILITY_CAMPAIGNS_SCHEDULES,
CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION,
)
from govoplan_core.core.calendar import CAPABILITY_CALENDAR_INVITATIONS
from govoplan_core.core.module_guards import (
@@ -70,8 +74,14 @@ from govoplan_campaign.backend.documentation import (
CAMPAIGN_USER_DOCUMENTATION,
documentation_topics,
)
from govoplan_campaign.backend.german_documentation import (
localize_documentation_topics,
)
from govoplan_campaign.backend.dsar_provider import CAMPAIGN_DSAR_CAPABILITY
from govoplan_campaign.backend.search_source import create_campaign_search_source
from govoplan_campaign.backend.workflow_definitions import (
campaign_workflow_definitions,
)
register_campaign_change_tracking()
@@ -133,13 +143,13 @@ PERMISSIONS = (
_permission(
"campaigns:assignment:manage",
"Manage campaign work assignments",
"Create, reassign, cancel, and reconcile authorization-neutral campaign work assignments.",
"Create, reassign, cancel, and reconcile authorization-neutral campaign work assignments, including Workflow-opened hand-offs.",
"Campaign work",
),
_permission(
"campaigns:assignment:complete",
"Complete assigned campaign work",
"Start or complete campaign work assigned to the current account, group, or organization function.",
"Accept, complete, or reject campaign work assigned to the current account, group, or organization function.",
"Campaign work",
),
_permission(
@@ -160,6 +170,18 @@ PERMISSIONS = (
"Create campaigns or working versions from existing campaigns.",
"Campaigns",
),
_permission(
"campaigns:campaign:export",
"Export portable campaigns",
"Create integrity-protected portable Campaign packages with explicitly selected data scopes.",
"Campaigns",
),
_permission(
"campaigns:campaign:import",
"Import portable campaigns",
"Preview and create new Campaign drafts from compatible portable packages.",
"Campaigns",
),
_permission(
"campaigns:campaign:schedule",
"Schedule campaigns",
@@ -338,6 +360,8 @@ ROLE_TEMPLATES = (
"campaigns:campaign:create",
"campaigns:campaign:update",
"campaigns:campaign:copy",
"campaigns:campaign:export",
"campaigns:campaign:import",
"campaigns:campaign:schedule",
"campaigns:campaign:validate",
"campaigns:campaign:build",
@@ -436,10 +460,13 @@ def _campaigns_router(context: ModuleContext):
return aggregate
MODULE_VERSION = "0.1.29"
manifest = ModuleManifest(
id="campaigns",
name="Campaigns",
version="0.1.21",
version=MODULE_VERSION,
workflow_definitions=campaign_workflow_definitions(module_version=MODULE_VERSION),
required_capabilities=(
CAPABILITY_AUTH_PRINCIPAL_RESOLVER,
CAPABILITY_AUTH_PERMISSION_EVALUATOR,
@@ -475,6 +502,10 @@ manifest = ModuleManifest(
ModuleInterfaceProvider(name="campaigns.mail_policy_context", version="0.1.6"),
ModuleInterfaceProvider(name="campaigns.policy_context", version="0.1.6"),
ModuleInterfaceProvider(name="campaigns.retention", version="0.1.6"),
ModuleInterfaceProvider(
name="campaigns.work_orchestration",
version="1.0.0",
),
ModuleInterfaceProvider(
name=REPORT_PROVIDER_CAPABILITY_PREFIX + "campaigns",
version="1.0.0",
@@ -691,12 +722,28 @@ manifest = ModuleManifest(
"campaigns.route.operator-redirect",
OPERATOR_QUEUE_SURFACE_ID,
REPORTS_SURFACE_ID,
"campaigns.page.work",
"campaigns.page.activity",
),
order=40,
),
),
view_surfaces=(
ViewSurface(
id="campaigns.admin.system-delivery", module_id="campaigns",
kind="section", label="System Campaign delivery", order=76,
),
ViewSurface(
id="campaigns.admin.tenant-delivery", module_id="campaigns",
kind="section", label="Tenant Campaign delivery", order=76,
),
ViewSurface(
id="campaigns.page.work",
module_id="campaigns",
kind="page",
label="Campaign work",
order=44,
),
ViewSurface(
id="campaigns.page.activity",
module_id="campaigns",
@@ -788,7 +835,83 @@ manifest = ModuleManifest(
label="Campaigns",
),
),
documentation=(
documentation=localize_documentation_topics((
DocumentationTopic(
id="campaigns.module-navigation-and-table-layout",
title="Distinguish module reports from one campaign's report",
summary="Use accurate module breadcrumbs and shared edge-to-edge report and attachment tables.",
body=(
"The Campaign audit documentation book sits immediately to the right of the Recent audit "
"events heading. "
"The Campaigns module has separate Reports (/campaigns/reports) and Operator queue (/campaigns/queue) views. "
"Their breadcrumbs name the module section, not a campaign record. A selected campaign's own report remains under "
"/campaigns/{campaign_id}/report (including its reports alias) with the singular Campaign and Report context. "
"The legacy /operator link still redirects to the queue; report selection query parameters, editor deep links and "
"Quick Access return-to-origin history behavior remain unchanged. These labels grant no extra report or delivery permissions. "
"The Campaign reports available to you and Global Attachments cards use the shared table-body layout: tables reach "
"the card boundary, including while loading, without module-local negative margins. Global Attachments remains collapsible; "
"chooser warnings, row actions, empty-state actions and existing filters remain available. Layout changes do not change "
"recipients, attachment rules or bytes, report privacy suppression, saved data, exports or delivery state. "
"In Recipient data, automatic fitting prefers at most 640/480 pixels for Recipient(s)/Delivery and 360 pixels "
"for configurable fields before distributing spare space. These are starting-layout preferences, not manual "
"resize limits: all three kinds of column can be widened further and reduced again. "
"The table scrolls horizontally while manual resizing keeps the non-resizable Active and Attachments columns "
"at their current widths. These are personal "
"browser layout changes, not campaign autosaves. Recipient and global-attachment grids wait for the initial draft "
"before restoring their saved column layout, so a reload does not replace personal widths with temporary loading columns."
),
layer="available",
documentation_types=("user", "admin"),
audience=("campaign_manager", "campaign_operator", "campaign_admin"),
order=19,
conditions=(DocumentationCondition(required_modules=("campaigns",), any_scopes=CAMPAIGN_MODULE_REQUIRED_ANY),),
links=(
DocumentationLink(label="Campaigns", href="/campaigns", kind="runtime"),
DocumentationLink(label="Reports", href="/campaigns/reports", kind="runtime"),
DocumentationLink(label="Operator queue", href="/campaigns/queue", kind="runtime"),
),
metadata={"kind": "reference", "related_topic_ids": ["campaigns.workflow.prepare-validate-and-build"]},
translations={"de": {
"title": "Modulberichte vom Bericht einer einzelnen Kampagne unterscheiden",
"summary": "Eindeutige Modul-Breadcrumbs sowie gemeinsame, bündige Berichts- und Anhangstabellen verwenden.",
"body": (
"Das Dokumentationsbuch im Kampagnen-Audit steht unmittelbar rechts neben der Überschrift "
"Letzte Audit-Ereignisse. "
"Das Modul Kampagnen besitzt getrennte Ansichten für Berichte (/campaigns/reports) und die Operator-Warteschlange "
"(/campaigns/queue). Ihre Breadcrumbs benennen den Modulbereich und keinen Kampagnendatensatz. Der Bericht einer "
"ausgewählten Kampagne bleibt unter /campaigns/{campaign_id}/report (einschließlich des reports-Alias) im Kontext "
"Kampagne und Bericht. Der bisherige Link /operator leitet weiterhin zur Warteschlange um; Auswahlparameter für "
"Berichte, Editor-Deep-Links und die Rückkehr zum Ursprung über Quick Access bleiben unverändert. Die Beschriftung "
"vergibt keine zusätzlichen Berichts- oder Versandberechtigungen. Die Karten für verfügbare Kampagnenberichte und "
"globale Anhänge verwenden das gemeinsame Tabellenlayout: Tabellen reichen auch beim Laden bis an den Kartenrand, "
"ohne negative modulspezifische Abstände. Globale Anhänge bleiben einklappbar; Auswahlwarnungen, Zeilenaktionen, "
"Aktionen für leere Tabellen und vorhandene Filter bleiben verfügbar. Das Layout ändert weder Empfänger, "
"Anhangsregeln oder Bytes noch Datenschutzunterdrückung, gespeicherte Daten, Exporte oder Versandzustand. "
"In den Empfängerdaten bevorzugt die automatische Anpassung zunächst höchstens 640/480 Pixel für Empfänger/Zustellung "
"und 360 Pixel für konfigurierbare Felder, bevor sie freien Platz verteilt. Diese Werte bestimmen nur das "
"Ausgangslayout und begrenzen nicht die manuelle Größenänderung: Alle drei Spaltenarten lassen sich weiter "
"verbreitern und wieder verkleinern. Die Tabelle wird horizontal scrollbar; bei der manuellen Größenänderung "
"behalten die nicht verstellbaren Spalten Aktiv und Anhänge ihre aktuellen Breiten. Dies sind persönliche "
"Browser-Einstellungen und keine automatische Speicherung der Kampagne. "
"Empfänger- und globale Anhangstabellen warten beim ersten Laden auf den Entwurf, bevor sie gespeicherte "
"Spaltenbreiten wiederherstellen. Vorläufige Ladespalten überschreiben dadurch beim Neuladen keine persönlichen Breiten."
),
}},
),
DocumentationTopic(
id="campaigns.attachment-filename-fidelity",
title="Deterministic attachment and ZIP names",
summary="Resolve repeated names efficiently without dropping or reordering attachments.",
body="Message attachments and ZIP members share a first-free suffix allocator. Repeated names retain the established case-insensitive collision rule and exact numbered suffixes, including names already containing suffixes, Unicode case folding and multiple extensions. Each message/archive has independent allocation state. Large groups of identical requested names no longer restart every suffix search from two. This changes naming work only: intended attachment bytes, recipients, order, existing duplicate-file review policy and ZIP encryption remain unchanged.",
layer="available", documentation_types=("user", "admin"), audience=("campaign_manager", "campaign_admin"), order=18,
conditions=(DocumentationCondition(required_modules=("campaigns",), any_scopes=("campaigns:campaign:read", "campaigns:campaign:write")),),
links=(DocumentationLink(label="Campaigns", href="/campaigns", kind="runtime"),),
translations={"de": {
"title": "Deterministische Namen für Anhänge und ZIP-Einträge",
"summary": "Wiederholte Namen effizient auflösen, ohne Anhänge auszulassen oder umzuordnen.",
"body": "Nachrichtenanhänge und ZIP-Einträge verwenden dieselbe Vergabe des ersten freien nummerierten Suffixes. Die bisherige groß-/kleinschreibungsunabhängige Kollisionsregel und exakte Nummerierung bleiben erhalten, auch bei vorhandenen Nummernsuffixen, Unicode-Groß-/Kleinschreibung und mehrfachen Erweiterungen. Jede Nachricht und jedes Archiv besitzt einen getrennten Vergabezustand. Große Gruppen gleicher gewünschter Namen beginnen die Suffixsuche nicht mehr jeweils bei zwei. Nur der Suchaufwand ändert sich: vorgesehene Bytes, Empfänger, Reihenfolge, bestehende Prüfung mehrfach verwendeter Dateien und ZIP-Verschlüsselung bleiben unverändert.",
}},
),
*CAMPAIGN_USER_DOCUMENTATION,
DocumentationTopic(
id="campaigns.workflow.link-exact-campaign-to-case",
@@ -832,6 +955,67 @@ manifest = ModuleManifest(
"help_contexts": ["campaigns.quick_access.campaigns"],
},
),
DocumentationTopic(
id="campaigns.admin.portable-transfer-governance",
title="Govern portable Campaign export and import",
summary="Separate configuration portability from recipient and delivery-data export, and verify every import as a new draft.",
body=(
"Portable Campaign export and import use separate campaign-level permissions. The built-in Campaign manager can move configuration, but recipient rows additionally require recipient read/export on export and recipient write/import on import. Review-state export requires report read; recipient-level delivery history requires report export plus recipient read/export. The UI and API default export to metadata plus template/configuration only. Every package records its format, source Campaign/version, selected scopes, item counts, redaction counts, and SHA-256 integrity digest. Campaign removes transport secrets, credential-envelope references, password-field values, infrastructure paths, and attachment bytes. Import fails closed on format, checksum, schema, scope, or destination-ID conflicts; its preview identifies every created and skipped domain. It always creates a separately owned draft, clears deployment-bound Mail references, and never recreates shares, locks, approvals, review decisions, delivery jobs, attempts, or sent state. The destination retains a bounded import receipt and matching Audit evidence. Operators must govern downloaded package storage and deletion outside GovOPlaN according to the selected data scopes."
),
layer="configured",
documentation_types=("admin",),
audience=("module_admin", "security_reviewer", "privacy_officer", "campaign_manager"),
order=40,
conditions=(
DocumentationCondition(
required_modules=("campaigns",),
any_scopes=(
"campaigns:campaign:export",
"campaigns:campaign:import",
"access:roles:manage",
),
),
),
links=(
DocumentationLink(label="Campaigns", href="/campaigns", kind="runtime"),
DocumentationLink(
label="Campaign handbook",
href="govoplan-campaign/docs/CAMPAIGN_HANDBOOK.md",
kind="repository",
),
),
related_modules=("access", "audit", "files", "mail"),
translations={
"de": {
"title": "Portablen Campaign-Export und -Import steuern",
"summary": "Konfigurationsportabilitaet vom Export von Empfaenger- und Zustelldaten trennen und jeden Import als neuen Entwurf pruefen.",
"body": (
"Portabler Campaign-Export und -Import verwenden getrennte Campaign-Berechtigungen. Empfaengerzeilen erfordern beim Export zusaetzlich Empfaenger-Lese- und Exportrecht sowie beim Import Empfaenger-Schreib- und Importrecht. Pruefstatus erfordert Berichtsleserecht; Zustellhistorie erfordert Berichtsexport sowie Empfaenger-Lese- und Exportrecht. Standardmaessig werden nur Metadaten sowie Vorlage und Konfiguration exportiert. Jedes Paket enthaelt Format, Quelle, ausgewaehlte Umfaenge, Zaehler, Redaktionen und SHA-256-Integritaet. Transportgeheimnisse, Zugangsdatenverweise, Passwortfeldwerte, Infrastrukturpfade und Dateiinhalte werden entfernt. Der Import schlaegt bei Format-, Pruefsummen-, Schema-, Umfangs- oder Kennungskonflikten geschlossen fehl und erstellt immer einen eigenstaendigen Entwurf. Freigaben, Sperren, Genehmigungen, Pruefentscheidungen, Zustellauftraege und Sendezustaende werden nie wiedergegeben."
),
}
},
metadata={
"kind": "configuration",
"route": "/campaigns",
"screen": "Campaign portable transfer",
"help_contexts": [
"campaigns.action.export-package",
"campaigns.action.import-package",
],
"permission_scopes": [
"campaigns:campaign:export",
"campaigns:campaign:import",
"campaigns:recipient:read",
"campaigns:recipient:write",
"campaigns:recipient:import",
"campaigns:recipient:export",
"campaigns:report:read",
"campaigns:report:export",
],
"privacy_default_scopes": ["metadata", "template_config"],
"verification": "Export the default scopes as a Campaign manager, verify a recipient scope is denied without recipient-export, tamper with the JSON and verify preview rejects it, then import a valid package and confirm a new draft plus matching Audit hashes without jobs or approval state.",
},
),
DocumentationTopic(
id="campaigns.admin.collaboration-governance",
title="Govern Campaign collaboration permissions and retention",
@@ -1100,7 +1284,11 @@ manifest = ModuleManifest(
id="campaigns.mail-profile-user-journey",
title="Choose a Mail profile for campaign delivery",
summary="Campaigns reference an authorized Mail profile and never store SMTP/IMAP settings or credentials.",
body="Open the campaign Mail settings, select an available profile, test it through Mail, and save. Validation and delivery recheck profile authorization. A changed transport identity requires a new validation and build.",
body=(
"Mail settings → Reusable mail profile → SMTP credential (and IMAP credential when used) records an explicit credential identifier. An empty selection means inheritance only if Mail policy permits it; a displayed profile default is not a stored campaign choice. Missing or inactive saved profiles, servers and credentials remain visibly unavailable rather than being silently replaced. "
"Open the campaign Mail settings, select an available profile, test it through Mail, and save. If legacy campaign-local transport data is reported, use Migrate selected Mail profile after selecting an authorized profile; this explicit action also works when the existing selection is unchanged and the draft is clean. Locked historical evidence is retained: follow the version's unlock or editable-successor action before migrating. Review and send displays the migration blocker and links back to Mail settings instead of repeatedly requesting an invalid attachment preview. The profile selector loads only campaign-authorized profiles; a separate administrative policy-list failure does not empty it. Validation and delivery recheck profile authorization. Migration saves configuration but never sends mail; validate, build, and review the resulting version again before delivery."
" Mail migration and ZIP policy corrections can be saved in either order. Unchanged ZIP settings do not block migration or acquire new consent evidence. An archive or content correction with unchanged Mail references preserves the old transport server-side and retains the migration notice; no implicit migration occurs. A committed save and the following workspace refresh are separate outcomes: failed refresh keeps the last usable same-campaign/version data and displays an error. Retry Reload; obsolete responses from another campaign, version, identity or earlier refresh cannot replace the current workspace."
),
layer="available",
documentation_types=("user",),
audience=("campaign_manager", "campaign_reviewer", "campaign_sender"),
@@ -1138,11 +1326,12 @@ manifest = ModuleManifest(
"steps": [
"Open the campaign and go to Mail settings.",
"Select an available Mail profile; Campaign stores only its stable identifier.",
"If migration is required, choose Migrate selected Mail profile even if the selected profile has not changed. For a locked version, first follow its supported unlock or editable-successor action.",
"Test SMTP and, when configured, IMAP through the Mail module.",
"Save, validate, and build the campaign before queueing delivery.",
],
"outcome": "The editable campaign version references an authorized Mail-owned delivery profile without copying transport settings or credentials.",
"verification": "Reopen Mail settings, confirm the selected profile, then run validation and verify that the build completes without profile-drift errors.",
"verification": "Reopen Mail settings and confirm the selected profile and absence of the migration notice; then validate, build, and review. Saving or migrating must not create a delivery effect.",
"related_topic_ids": [
"campaigns.mail-profile-governance",
"campaigns.mail-profile-operations",
@@ -1154,7 +1343,11 @@ manifest = ModuleManifest(
id="campaigns.mail-profile-governance",
title="Govern Campaign-to-Mail profile references",
summary="Mail owns transport definitions and encrypted credentials; Campaign owns only the selected profile reference and delivery evidence.",
body="Grant mail:profile:use to campaign authors, constrain profile availability through Mail policy, and keep effective credential inheritance enabled. Inline transport fields are rejected. Legacy records remain unchanged until an explicit, audited profile migration creates or updates an editable version.",
body=(
"Grant mail:profile:use to campaign authors, constrain profile availability through Mail policy, and explicitly configure whether profile credentials may be inherited or a campaign must select a Mail-owned credential. SMTP/IMAP credential inheritance controls appear on the Mail policy page, with local, inherited and effective values and ancestor locks. Inline transport fields are rejected and are never returned with credentials to the browser. Legacy transport remains unchanged until an explicit, audited profile migration creates or updates an editable version; selecting the same already referenced profile is sufficient when the operator uses Migrate selected Mail profile. Campaign Mail settings request only the usable campaign-scoped profile list; administrative Mail policy enumeration is a separate request on the Mail policy page and its errors remain local to that surface. This separation does not grant profile administration or bypass owner, tenant, or Mail authorization. Migration never sends mail or restores an old execution snapshot."
" Independent draft corrections may retain the exact stored legacy server object only while public Mail references remain unchanged and no inline transport is submitted. This saves content without selecting or using a profile, even if its authorization was revoked. Explicit migration still requires mail:profile:use and current Mail policy. Version-save audit details distinguish legacy_mail_settings_preserved from legacy_mail_settings_migrated. Unchanged ZIP configuration is not re-acknowledged; modified ZIP settings retain full policy checks. Successful repair saves invalidate prior build/execution evidence and do not relax validation, review or delivery."
" Already migrated drafts follow the same unchanged-selection rule: a later requirement for explicit SMTP/IMAP credentials does not prevent saving unrelated archive or content corrections. Changing any selected Mail resource still enforces Mail permission and current policy, and authoritative validation/delivery always recheck the full selection."
),
layer="configured",
documentation_types=("admin",),
audience=("tenant_admin", "mail_admin", "campaign_admin"),
@@ -1202,7 +1395,7 @@ manifest = ModuleManifest(
id="campaigns.mail-profile-operations",
title="Operate profile-backed campaign delivery",
summary="Workers re-authorize and resolve Mail profiles at execution time while Campaign retains only opaque Mail-owned revisions and outcomes.",
body="A legacy snapshot, unauthorized or inactive profile, profile-reference mismatch, or changed SMTP/IMAP transport revision stops delivery. Synchronous Mail batches preflight DNS, connectivity, TLS, and authentication before their first effect, reuse a bounded healthy SMTP connection, and reconnect before a later message when the old connection is stale. Review and send shows batch, connection, reconnect, failure, and pause counts. A systemic authentication, sender, or connectivity failure pauses remaining queued jobs with a stable reason code; correct and test the Mail profile before explicitly resuming. A connection loss after DATA begins stays outcome-unknown and is never replayed automatically. Preserve a stopped record, migrate or correct the profile selection, revalidate, rebuild, and only then queue again. Password-only rotation remains possible without copying secrets into Campaign. Uncertain SMTP and IMAP effects remain blocked until an evidence-backed operator reconciliation. If Campaign becomes unavailable to the tenant after a job was accepted, the worker leaves the job untouched and reports an operator action instead of sending or dropping it.",
body="SMTP and IMAP runtime actions enforce credential-selection requirements independently for their own protocol; SMTP calls do not need IMAP parameters and vice versa. Full campaign validation and build summaries continue checking both required selections. Preflight distinguishes Mail profile/credential policy from SMTP configuration, authentication, and connectivity failures; a successful server connection test does not replace campaign authorization. A legacy snapshot, unauthorized or inactive profile, profile-reference mismatch, or changed SMTP/IMAP transport revision stops delivery. Synchronous Mail batches preflight DNS, connectivity, TLS, and authentication before their first effect, reuse a bounded healthy SMTP connection, and reconnect before a later message when the old connection is stale. Review and send shows batch, connection, reconnect, failure, and pause counts. A systemic authentication, sender, or connectivity failure pauses remaining queued jobs with a stable reason code; correct and test the Mail profile before explicitly resuming. A connection loss after DATA begins stays outcome-unknown and is never replayed automatically. Preserve a stopped record, migrate or correct the profile selection, revalidate, rebuild, and only then queue again. Password-only rotation remains possible without copying secrets into Campaign. Uncertain SMTP and IMAP effects remain blocked until an evidence-backed operator reconciliation. If Campaign becomes unavailable to the tenant after a job was accepted, the worker leaves the job untouched and reports an operator action instead of sending or dropping it.",
layer="configured",
documentation_types=("admin",),
audience=("campaign_sender", "campaign_operator", "mail_admin"),
@@ -1250,7 +1443,10 @@ manifest = ModuleManifest(
id="campaigns.workflow.prepare-validate-and-build",
title="Prepare, validate, and build a campaign",
summary="Turn governed recipient, template, attachment, and Mail-profile inputs into exact built messages for review.",
body="Prepare each input in its owning surface, resolve every blocking validation issue, and build exact recipient messages before review. Recipient data can activate or deactivate every currently opposite-state row as one explicitly confirmed draft change; saving it creates the normal Campaign version evidence and invalidates stale validation, build, and review state. New campaign credentials and password-valued fields offer the shared secure generator; its candidate remains separate until Use password is confirmed. Campaign freezes recipient and attachment evidence for the selected version; later source changes do not silently alter that build. Summary metrics expose a named drill-down only when an authorized source collection, filtered review table, attachment preview, or report helps the user inspect and act on the count. Privacy-suppressed aggregate reports remain non-interactive because an unsuppressed subgroup would violate their disclosure boundary. When the Templates module is installed, its single Templates navigation entry owns the reusable library while campaign-specific composition remains in the campaign workspace.",
body=(
"Prepare each input in its owning surface, resolve every blocking validation issue, and build exact recipient messages before review. Recipient data can activate or deactivate every currently opposite-state row as one explicitly confirmed draft change; saving it creates the normal Campaign version evidence and invalidates stale validation, build, and review state. New campaign credentials and password-valued fields offer the shared secure generator; its candidate remains separate until Use password is confirmed. Campaign freezes recipient and attachment evidence for the selected version; later source changes do not silently alter that build. Summary metrics expose a named drill-down only when an authorized source collection, filtered review table, attachment preview, or report helps the user inspect and act on the count. Privacy-suppressed aggregate reports remain non-interactive because an unsuppressed subgroup would violate their disclosure boundary. When the Templates module is installed, its single Templates navigation entry owns the reusable library while campaign-specific composition remains in the campaign workspace."
" In individual and global address dialogs, the up/down actions set the saved address order. Dialog Save applies that order to the campaign draft without alphabetically sorting it; duplicate email addresses retain their first position. Pasted addresses append in their entered order without rearranging existing addresses. The first individual To address remains the primary name/email shown in the recipient row. Save the campaign page to persist the updated draft; a failed page save retains the order for an explicit retry. Dialog Cancel deliberately discards only its unconfirmed edits."
),
layer="configured",
documentation_types=("user",),
audience=("campaign_manager", "campaign_author"),
@@ -1326,6 +1522,8 @@ manifest = ModuleManifest(
summary="Use AES by default and select weak Windows-compatible ZipCrypto only with explicit policy, permission, acknowledgement, and evidence.",
body=(
"Campaign resolves archive encryption through Policy across system, tenant, owner user or group, and campaign scopes. Password-protected archives use AES unless the complete inherited policy permits Legacy ZipCrypto — Windows-compatible, weak encryption and the actor has campaigns:archive:use_legacy_zipcrypto. A legacy selection requires a reasoned acknowledgement. Passwords are never included in Campaign evidence or the campaign message and must be conveyed through the separately selected, policy-allowed channel. Each build freezes the archive and member hashes, implementation version, policy hash and source path, acknowledgement actor, reason and time, and build identity. A more restrictive later policy blocks queueing and sending until the campaign is rebuilt; Campaign never falls back from AES to ZipCrypto after an error. Temporary plaintext and archive material is confined to the bounded build directory and removed after success or failure."
" Campaign Settings, Policies, and Attachments show the effective policy and direct authorized administrators to Administration → SYSTEM → Campaign archive encryption. Enable Legacy ZipCrypto there and Save; fresh system defaults are editable without creating an override merely by opening the page. Tenant and owner policies may still narrow the result. Back in Campaign, Reload archive policy, select Legacy ZipCrypto under Attachments → ZIP attachments, acknowledge its weak encryption, and give an operational reason of at least 10 characters. Policy unavailability keeps Legacy blocked. Neither a policy save nor an attachment configuration save sends mail."
" Mail migration and archive corrections can be saved independently in either order. An exact unchanged ZIP configuration is retained without re-acknowledgement during an unrelated save, even after policy or permission revocation; it is not authorized for use. Any modified ZIP configuration must satisfy the current methods, password-delivery channels and legacy permission/acknowledgement requirements. An archive correction with unchanged public Mail references retains the exact legacy transport server-side until an explicit authorized migration. No client may introduce or echo inline transport, change Mail references under this exception, or fabricate acknowledgement evidence. Both repairs invalidate execution/build evidence; validation, review, building and delivery remain fail-closed until all conditions are satisfied."
),
documentation_types=("user", "admin"),
audience=("campaign_manager", "campaign_reviewer", "policy_admin"),
@@ -1345,13 +1543,36 @@ manifest = ModuleManifest(
"route": "/campaigns/{campaign_id}/files",
"screen": "Campaign attachments",
"help_contexts": ["campaign.archive-encryption"],
"prerequisites": [
"Policy is available; a policy administrator can read and write the system archive policy.",
"The Campaign actor has campaigns:archive:use_legacy_zipcrypto and may edit the selected version.",
],
"steps": [
"From Campaign Settings or Attachments, open the system archive policy under Administration → SYSTEM → Campaign archive encryption.",
"Explicitly permit Legacy ZipCrypto and Save; inspect tenant and owner restrictions if the effective Campaign policy still blocks it.",
"Return to Campaign and Reload archive policy; enable ZIP attachments and select Legacy ZipCrypto for the intended archive.",
"Acknowledge weak encryption, provide a reason of at least 10 characters, and choose an allowed separate password-delivery channel.",
"Save, validate, build, and review the exact version before separately authorizing delivery.",
],
"limitations": [
"AES remains the default; Legacy is an explicit compatibility exception, never an automatic fallback.",
"Child scopes cannot loosen a parent ceiling, and policy permission does not replace the dedicated Campaign permission.",
],
"verification": "Reopen the attachment settings and confirm the chosen method, allowed effective policy, separate password channel, and reasoned acknowledgment. Confirm build evidence records the policy hash and actor without the password.",
},
),
DocumentationTopic(
id="campaigns.workflow.complete-review",
title="Inspect built messages and complete review",
summary="Resolve critical blockers, record individual message decisions, and acknowledge non-critical review items for one exact build.",
body="Review completion remains bound to the current build token, inspected message keys, recorded issue decisions, and message evidence. Use the explicit actions on actionable recipient, attachment, validation, and review metrics to reveal the corresponding source page, evidence preview, or filtered built-message table. Informational and privacy-suppressed measures do not become hidden click targets. Changing recipients, content, attachments, owner context, or non-secret transport identity requires validation, building, and review again.",
body=(
"Opening Template without editing, changing read-only state, or switching visual/source inspection preserves saved HTML and does not mark the page dirty or require a save when leaving. Review completion remains bound to the current build token, inspected message keys, recorded issue decisions, and message evidence. Ordinary editor saves send only client-owned created_from, field_overrides, and opt_ins metadata; review_send and approval_gate are readable server evidence, not writable editor payloads. Omitting that evidence during a metadata save preserves it on the server; supported unlock, fork, and build invalidation rules still clear stale evidence when required. If the selected version requires legacy Mail migration, Review and send stays read-only, suppresses incompatible attachment-preview requests, and offers Open Mail settings with the exact selected version. Resolve the migration, validate, build, and review before sending. Use the explicit actions on actionable recipient, attachment, validation, and review metrics to reveal the corresponding source page, evidence preview, or filtered built-message table. Informational and privacy-suppressed measures do not become hidden click targets. Changing recipients, content, attachments, owner context, or non-secret transport identity requires validation, building, and review again."
" Accept similar review conditions groups only server-eligible, unreviewed messages from the currently loaded matching set. Choose one human-readable category, inspect the counted recipient selection and provide one shared reason when accepting attachment exceptions. Each request names at most 200 exact messages and verifies the current build and category; repeat for the remaining messages rather than assuming other categories or unloaded messages were included. Each selected message receives its own frozen, attributable decision evidence. A failed save retains the reason and selection for explicit retry, and a changed build blocks stale acceptance. Group acceptance neither sends messages nor completes the final review gate. Hard blockers cannot be overridden. Deliberate policy exclusions and explicitly allowed zero-match attachment rules remain informational and do not require review decisions."
" Saving an individual acceptance persists its reason and reviewed state immediately, before full review completion; reload resumes acknowledged progress for the same build. A failed or conflicting save retains the pending reason for explicit retry and does not mark the message reviewed. Each save merges only selected messages, preserving other reviewers' evidence, without rebuilding messages, inspecting attachment files, or reloading the entire workspace. Partial progress never authorizes delivery; final completion still checks every required decision and hard blocker. Required attachment and hard-block policies remain stronger than an optional rule allowing empty matches; the separate campaign policy for sending an entirely attachment-free message also remains authoritative."
" Review saves require campaign review permission, the current version revision, and a safe operational review_build_token; diagnostic scope is not required. Stale builds or concurrent changes return a conflict without overwriting stored progress."
" Accepted or expected attachment conditions remain satisfied for the same build in Confirm and send; missing/ambiguous source counts remain visible for context but create no second acceptance gate. The reviewed-stage mock uses verified frozen messages and completed decisions instead of regenerating them. Changed inputs, issue evidence, message bytes or Mail transport stop the test before mock capture; authoring previews retain their separate transient-build behavior."
" Validation details and repeated-file lists expose every item through the shared DataGrid pagination controls. A related missing-rule cause and attachment-free policy outcome are explained together while expandable technical evidence remains intact. Built-message filters and rows use four operational states: Ready, Needs review, Blocked and Excluded. Accepted explicit decisions become Ready; warnings awaiting acknowledgment remain Needs review. A second column explains the state. These are presentation changes, not deletion or rewriting of frozen issues or audit evidence."
),
layer="configured",
documentation_types=("user",),
audience=("campaign_reviewer",),
@@ -1388,13 +1609,14 @@ manifest = ModuleManifest(
],
"steps": [
"Open Review and send and inspect the Critical blockers, Individual review, and Group review summaries.",
"If a legacy Mail migration notice appears, use Open Mail settings for this version, complete the explicit migration, and validate and build again.",
"Correct every critical blocker in the named campaign workspace, then validate and build again.",
"Open each remaining individual review message and record its decision.",
"Open each remaining individual review message, save its reasoned acceptance and wait for the durable acknowledgement; reload can resume this partial progress.",
"When only non-critical group items remain, review their conditions and explicitly complete review.",
"Confirm that Reviewed equals the required review total and Remaining is zero before delivery.",
],
"outcome": "Review evidence for the exact current build, with no unresolved blocker or review decision.",
"verification": "Reload Review and send, confirm no critical blocker or remaining decision, and verify that the permitted delivery mode is unlocked for the same version and build.",
"verification": "Reload after an individual acceptance before completing the whole review and confirm its reason and reviewed state persist. After final completion, confirm no critical blocker or remaining decision and verify that delivery is unlocked only for the same version and build.",
"related_topic_ids": [
"campaigns.workflow.prepare-validate-and-build",
"campaigns.workflow.retry-and-reconcile",
@@ -1405,7 +1627,9 @@ manifest = ModuleManifest(
id="campaigns.workflow.retry-and-reconcile",
title="Retry only known failures and reconcile uncertain effects",
summary="Keep safe-to-retry failures separate from Mail, Postbox, or IMAP effects whose outcome is unknown.",
body="A retry creates new attempt evidence and is valid only for an explicitly eligible state. Never blindly retry an unknown Mail, Postbox, or IMAP effect. Inspect external evidence and reconcile the affected channel before continuing. Accepted Mail attempts and accepted Postbox targets are immutable during partial retries, and repairing Sent never resends accepted Mail.",
body=("A retry creates new attempt evidence and is valid only for an explicitly eligible state. Never blindly retry an unknown Mail, Postbox, or IMAP effect. Inspect external evidence and reconcile the affected channel before continuing. Accepted Mail attempts and accepted Postbox targets are immutable during partial retries, and repairing Sent never resends accepted Mail. "
"Without workers, Report offers explicit bounded retry and continuation using the same immutable jobs, execution checks, review evidence, approvals, Mail authorization, rate limits and recovery ledger as Send now. Each request is capped by the effective synchronous policy and returns remaining work; repeating continuation skips already accepted, excluded, active and uncertain jobs. Retry requires campaigns:campaign:retry plus campaigns:campaign:send for inline execution; continuation requires campaigns:campaign:queue plus campaigns:campaign:send. Reconciliation needs campaigns:campaign:reconcile and a factual evidence note; it never sends mail. "
"A stalled claimed/sending/appending job is not safe merely because time elapsed. Report exposes Recover interrupted claim only for an expired durable lease whose original runtime is proven stopped or replaced. The submitted opaque revision must still match and the original recovery evidence must be valid; the action changes the effect only to outcome-unknown. Inspect provider/mailbox evidence and separately reconcile accepted/not sent or appended/not appended before an explicit retry. Missing original leases/evidence and unconfirmed owners remain blocked for operator investigation. A duplicate worker task leaves active state unchanged."),
layer="evidence",
documentation_types=("admin", "user"),
audience=("campaign_sender", "campaign_operator"),
@@ -1450,9 +1674,9 @@ manifest = ModuleManifest(
"Provider, mailbox, worker, and campaign evidence has been preserved.",
],
"steps": [
"Classify the job and latest SMTP and IMAP attempts independently.",
"Retry only an explicitly temporary, permanent-with-override, or unattempted eligible state.",
"For an unknown effect, inspect provider or mailbox evidence and record the factual reconciliation with a note.",
"Open the selected version's Report and classify each job's SMTP and IMAP attempts independently.",
"Explicitly retry eligible failures or continue the unattempted jobs on this page; without workers, use the bounded Send now action and inspect remaining work.",
"For an abandoned active claim, recover only with expired-lease and stopped/replaced-owner proof; then inspect provider or mailbox evidence and reconcile the unknown effect with a factual note.",
"Verify the resulting protected state before allowing more work for that job.",
],
"outcome": "Every investigated job is either protected as effected, explicitly retryable, or still visibly unresolved.",
@@ -1463,11 +1687,35 @@ manifest = ModuleManifest(
],
},
),
DocumentationTopic(
id="campaigns.admin.delivery-policy",
title="Configure the interactive Campaign delivery limit",
summary="Set an audited system maximum for Send now and optional narrower tenant limits without changing any campaign or sending messages.",
body="Administration → SYSTEM → Campaign delivery permits system:settings:read to inspect and system:settings:write to save the synchronous recipient-job maximum. Its unchanged default is 25; an administrator may explicitly choose 0500, for example 200 for a 183-job run. Administration → TENANT → Campaign delivery requires admin:policies:read/write and may only narrow the inherited system limit. Clearing an override restores inheritance. An explicitly set GOVOPLAN_CAMPAIGN_SYNCHRONOUS_SEND_MAX_RECIPIENTS remains an authoritative deployment ceiling, including zero. With no deployment value, the implicit default does not prevent an authorized system override. Larger interactive batches take longer and may exceed proxy/request timeouts; background workers remain the preferred separate mode for large campaigns and require CELERY_ENABLED plus working Redis/Celery infrastructure. This setting limits one exact persisted eligible Send now run, not campaign size or worker dispatch. Save stores only this scoped setting with revision conflict protection, before/after configuration history and audit; it neither sends messages, alters saved review evidence, nor bypasses Mail, review, approval or execution-integrity gates. Failed saves retain the draft. Reload uses the shared unsaved-change guard and returns fresh saved policy.",
layer="configured", documentation_types=("admin",), audience=("administrator", "platform_operator"), order=51,
conditions=(DocumentationCondition(required_modules=("campaigns",), any_scopes=("system:settings:read", "admin:policies:read")),),
links=(DocumentationLink(label="System Campaign delivery", href="/admin?section=system-campaign-delivery", kind="runtime"),
DocumentationLink(label="Tenant Campaign delivery", href="/admin?section=tenant-campaign-delivery", kind="runtime")),
metadata={"kind": "workflow", "route": "/admin?section=system-campaign-delivery", "screen": "Campaign delivery",
"prerequisites": ["You hold the read and write permissions for the intended system or active tenant scope."],
"steps": ["Open Administration and select Campaign delivery in SYSTEM or TENANT.",
"Inspect the saved, inherited and maximum permitted values; disable inheritance to set a whole-number override.",
"Save and verify the saved effective limit, or retain the draft and resolve an explicit conflict before retrying.",
"Return to Review and send and reload delivery options before separately choosing a delivery action."],
"limitations": ["Tenant settings cannot raise system policy; an explicit deployment ceiling cannot be raised through this UI.",
"Zero disables Send now. Worker availability is independent; changing this setting never starts workers or sends messages."],
"verification": "Reload the administration section and confirm the effective value, then inspect before/after configuration history. Review and send must still enforce the exact eligible count and all delivery gates."},
),
DocumentationTopic(
id="campaigns.reference.composition-assurance",
title="Assure the Campaign reference composition",
summary="Release Campaign only with aligned contracts, role-safe surfaces, durable effect evidence, optional-module isolation, and recoverable data.",
body="Campaign is a reference composition only when Core, Mail, Files, Addresses, workers, storage, policies, and documentation are tested in the exact installed combination. Normal readers see business state rather than paths, storage keys, worker claims, or raw provider diagnostics; diagnostic and export authority remain separate.",
body=(
"Campaign is a reference composition only when Core, Mail, Files, Addresses, workers, storage, policies, and documentation are tested in the exact installed combination. Normal readers see business state rather than paths, storage keys, worker claims, or raw provider diagnostics; diagnostic and export authority remain separate."
" Release checks must initialize Campaign validation and attachment resolution independently in fresh processes, without relying on an earlier page or test import. These local entry points remain usable without installing Mail or Files; their import never starts delivery or relaxes managed-file path authorization."
" Verify that individual review reasons and reviewed state survive reload before final completion. Incremental review saves require campaigns:campaign:review and write access, merge exact selected current-build jobs under revision checks, and audit each acceptance without replacing other reviewers' evidence. The operational review_build_token does not expose raw diagnostic tokens. Partial progress never enables delivery, and hard blockers cannot be accepted. Policy-driven exclusions and explicitly allowed empty optional attachment rules create no new review obligation; required/global hard blocks remain enforced. These resolution changes apply to new builds only: an intentional rebuild is needed to reclassify existing messages and invalidates prior review and approval evidence. Frozen historical job issues must not be rewritten from mutable policy."
" The opt-in mock-send use_reviewed_build mode requires an existing sealed execution and same-build completed review when review is needed. It checks persisted job/issue input seals, EML length/digest/Message-ID and current Mail transport before any mock capture or requested mailbox clear. It never sends SMTP, alters Campaign delivery state, or creates a missing legacy snapshot. include_needs_review is not a blanket override in this mode."
),
layer="evidence",
documentation_types=("admin",),
audience=(
@@ -1562,7 +1810,7 @@ manifest = ModuleManifest(
],
},
),
),
)),
documentation_providers=(documentation_topics,),
ownership_providers=(
OwnershipProviderRegistration(
@@ -1598,6 +1846,10 @@ manifest = ModuleManifest(
"govoplan_campaign.backend.capabilities",
fromlist=["retention_capability"],
).retention_capability(context),
CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION: lambda context: __import__(
"govoplan_campaign.backend.work_orchestration",
fromlist=["SqlCampaignWorkOrchestrationProvider"],
).SqlCampaignWorkOrchestrationProvider(registry=context.registry),
REPORT_PROVIDER_CAPABILITY_PREFIX + "campaigns": lambda context: __import__(
"govoplan_campaign.backend.reports.provider",
fromlist=["CampaignAggregateReportProvider"],
@@ -1605,6 +1857,16 @@ manifest = ModuleManifest(
CAMPAIGN_DSAR_CAPABILITY: _dsar_provider,
},
capability_documentation={
CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION: CapabilityDocumentation(
label="Campaign work orchestration",
summary=(
"Creates or references Campaign work idempotently and exposes "
"revision-bearing lifecycle events without granting access."
),
contract_version="1.0",
documentation_types=("admin", "user"),
audience=("campaign_manager", "workflow_designer", "module_admin"),
),
REPORT_PROVIDER_CAPABILITY_PREFIX + "campaigns": CapabilityDocumentation(
label="Campaign aggregate report provider",
summary=(
@@ -1669,5 +1931,10 @@ manifest = ModuleManifest(
)
manifest = with_documentation_structured_translations(
manifest, locale="de", translations=GERMAN_STRUCTURED_TRANSLATIONS
)
def get_manifest() -> ModuleManifest:
return manifest
@@ -1,5 +1,7 @@
from __future__ import annotations
from govoplan_campaign.backend.services.filenames import FilenameAllocator
import mimetypes
import re
import tempfile
@@ -303,15 +305,8 @@ def _archive_filename(archive: ZipArchiveConfig, values: dict[str, Any], entry_i
return filename if filename.lower().endswith(".zip") else f"{filename}.zip"
def _unique_attachment_filename(filename: str, used: set[str]) -> str:
candidate = filename
path = Path(filename)
counter = 2
while candidate.casefold() in used:
candidate = f"{path.stem} ({counter}){path.suffix}"
counter += 1
used.add(candidate.casefold())
return candidate
def _unique_attachment_filename(filename: str, used: FilenameAllocator) -> str:
return used.allocate(filename)
def _deduplicated_archive_members(members: list[tuple[Path, str]]) -> list[tuple[Path, str]]:
@@ -381,8 +376,8 @@ def _attach_files(
evidence: list[dict[str, object]] = []
archive_members: dict[str, list[tuple[Path, str]]] = {}
archive_attachments: dict[str, list[ResolvedAttachment]] = {}
used_message_filenames: set[str] = set()
used_zip_member_filenames: dict[str, set[str]] = {}
used_message_filenames = FilenameAllocator()
used_zip_member_filenames: dict[str, FilenameAllocator] = {}
for attachment in resolution.attachments:
attachment.message_filenames = []
@@ -394,7 +389,7 @@ def _attach_files(
continue
match_paths = [Path(match) for match in attachment.matches]
if attachment.zip_enabled and attachment.zip_archive_id:
used_archive_names = used_zip_member_filenames.setdefault(attachment.zip_archive_id, set())
used_archive_names = used_zip_member_filenames.setdefault(attachment.zip_archive_id, FilenameAllocator())
for position, path in enumerate(match_paths, start=1):
requested = _render_attachment_filename(
template=attachment.zip_entry_name_template,
@@ -0,0 +1,103 @@
"""add durable Campaign work orchestration provenance
revision = "f3c7a9d2e6b1"
down_revision = "d8e9f0a1b2c3"
"""
from __future__ import annotations
import sqlalchemy as sa
from alembic import op
revision = "f3c7a9d2e6b1"
down_revision = "d8e9f0a1b2c3"
branch_labels = None
depends_on = None
_COLUMN_SPECS = (
("orchestration_idempotency_key", sa.String(length=255)),
("orchestration_request_sha256", sa.String(length=64)),
("orchestration_correlation_id", sa.String(length=128)),
("workflow_instance_id", sa.String(length=36)),
("workflow_step_id", sa.String(length=36)),
)
def upgrade() -> None:
inspector = sa.inspect(op.get_bind())
if not inspector.has_table("campaign_work_assignments"):
return
existing = {
item["name"]
for item in inspector.get_columns("campaign_work_assignments")
}
with op.batch_alter_table("campaign_work_assignments") as batch:
for name, column_type in _COLUMN_SPECS:
if name not in existing:
batch.add_column(sa.Column(name, column_type, nullable=True))
inspector = sa.inspect(op.get_bind())
indexes = {
item["name"]
for item in inspector.get_indexes("campaign_work_assignments")
}
for name, columns in (
(
"ix_campaign_work_assignments_orchestration_idempotency_key",
["orchestration_idempotency_key"],
),
(
"ix_campaign_work_assignments_orchestration_correlation_id",
["orchestration_correlation_id"],
),
(
"ix_campaign_work_assignments_workflow_instance_id",
["workflow_instance_id"],
),
(
"ix_campaign_work_assignments_workflow_step_id",
["workflow_step_id"],
),
(
"uq_campaign_work_assignment_orchestration_key",
["tenant_id", "orchestration_idempotency_key"],
),
):
if name not in indexes:
op.create_index(
name,
"campaign_work_assignments",
columns,
unique=name.startswith("uq_"),
)
def downgrade() -> None:
inspector = sa.inspect(op.get_bind())
if not inspector.has_table("campaign_work_assignments"):
return
indexes = {
item["name"]
for item in inspector.get_indexes("campaign_work_assignments")
}
for name in (
"uq_campaign_work_assignment_orchestration_key",
"ix_campaign_work_assignments_workflow_step_id",
"ix_campaign_work_assignments_workflow_instance_id",
"ix_campaign_work_assignments_orchestration_correlation_id",
"ix_campaign_work_assignments_orchestration_idempotency_key",
):
if name in indexes:
op.drop_index(name, table_name="campaign_work_assignments")
existing = {
item["name"]
for item in sa.inspect(op.get_bind()).get_columns(
"campaign_work_assignments"
)
}
with op.batch_alter_table("campaign_work_assignments") as batch:
for name, _column_type in reversed(_COLUMN_SPECS):
if name in existing:
batch.drop_column(name)
@@ -8,6 +8,7 @@ from datetime import UTC, datetime
from typing import Any
from uuid import uuid4
from sqlalchemy import String, and_, cast, or_
from sqlalchemy.orm import Session
from sqlalchemy.orm.exc import StaleDataError
@@ -28,8 +29,11 @@ from govoplan_campaign.backend.db.models import (
from govoplan_campaign.backend.sending.execution import clear_execution_snapshot
from govoplan_campaign.backend.campaign.mail_profile_boundary import (
campaign_editor_state_for_edit,
campaign_editor_state_with_client_update,
campaign_mail_profile_boundary_violations,
campaign_mail_profile_id,
campaign_mail_references_unchanged,
campaign_preserves_legacy_mail_settings,
assert_campaign_uses_mail_profile_reference,
public_campaign_mail_server,
validate_campaign_editor_state,
@@ -41,6 +45,7 @@ from govoplan_campaign.backend.persistence.campaigns import (
normalize_campaign_paths,
)
from govoplan_campaign.backend.path_security import assert_server_safe_campaign_paths
from govoplan_campaign.backend.services.review_decisions import review_decision_metadata
class LockedCampaignVersionError(CampaignPersistenceError):
@@ -701,6 +706,12 @@ def _updated_runtime_json(
campaign_mail_profile_boundary_violations(version.raw_json)
)
if requires_migration and not migrate_legacy_mail_settings:
if campaign_preserves_legacy_mail_settings(version.raw_json, runtime_json):
# The browser only knows the sanitized reference. Keep the exact
# stored transport here; never infer migration from its omission.
# No Mail resource is being selected/used by this content repair.
runtime_json["server"] = copy.deepcopy(version.raw_json["server"])
return runtime_json
raise CampaignPersistenceError(
"This version contains legacy campaign-local SMTP/IMAP settings. Select an authorized Mail "
"profile on the Mail settings page and explicitly save the migration; the stored legacy version "
@@ -712,6 +723,11 @@ def _updated_runtime_json(
"Migrating legacy campaign mail settings requires an authorized server.mail_profile_id. "
"Select a Mail profile before saving."
)
if not migrate_legacy_mail_settings and campaign_mail_references_unchanged(version.raw_json, runtime_json):
# Retaining a selection is not selecting or using a Mail resource. An
# unrelated repair must remain saveable after credential policy changes;
# validation/build/delivery still reauthorize the complete selection.
return runtime_json
mail_integration().assert_campaign_mail_policy_allows_json(
session,
tenant_id=tenant_id,
@@ -745,7 +761,9 @@ def _apply_version_field_updates(
if value is not None:
setattr(version, field_name, value)
if editor_state is not None:
version.editor_state = validate_campaign_editor_state(editor_state)
version.editor_state = campaign_editor_state_with_client_update(
version.editor_state, editor_state
)
if autosave:
version.autosaved_at = datetime.now(UTC)
@@ -908,6 +926,10 @@ def update_campaign_review_state(
reviewed_message_keys: list[str],
issue_decisions: list[dict[str, Any]] | None = None,
user_id: str | None,
merge_progress: bool = False,
expected_build_token: str | None = None,
expected_revision: int | None = None,
decision_category_key: str | None = None,
commit: bool = True,
) -> CampaignVersion:
"""Persist review acknowledgement without mutating the locked campaign data.
@@ -930,21 +952,64 @@ def update_campaign_review_state(
"Delivery has started; message review state can no longer be changed."
)
build_token = _campaign_review_build_token(version)
if merge_progress and (expected_build_token is None or expected_revision is None):
raise CampaignPersistenceError("Incremental review requires the current build token and revision.")
if expected_build_token is not None and expected_build_token not in {build_token, version.review_build_token}:
raise LockedCampaignVersionError("The message build changed. Reload the current build before recording review decisions.")
if expected_revision is not None and version.edit_revision != expected_revision:
raise RevisionConflictError(
resource_type="campaign_version", resource_id=version.id,
current_revision=version.edit_revision, submitted_base_revision=expected_revision,
refresh_path=f"/api/v1/campaigns/{campaign_id}/versions/{version.id}",
current_etag=version.strong_etag,
)
normalized_reviewed = list(
dict.fromkeys(
str(value) for value in reviewed_message_keys if str(value).strip()
)
)
normalized_decisions: list[dict[str, Any]] = []
requested = issue_decisions or []
if merge_progress and not inspection_complete and (len(normalized_reviewed) > 1_000 or len(requested) > 1_000):
raise CampaignPersistenceError("Save review progress in groups of at most 1000 messages.")
previous = (version.editor_state or {}).get("review_send", {})
previous = previous if isinstance(previous, dict) and previous.get("build_token") == build_token else {}
previous_decisions = [item for item in previous.get("issue_decisions", []) if isinstance(item, dict)]
if merge_progress:
normalized_reviewed = list(dict.fromkeys([*previous.get("reviewed_message_keys", []), *normalized_reviewed]))
merged_decisions = {str(item.get("job_id")): item for item in previous_decisions}
# Do not silently collapse duplicate client decisions; reject them below.
submitted_ids = [str(item.get("job_id") or "") for item in requested]
if len(submitted_ids) != len(set(submitted_ids)):
raise CampaignPersistenceError("Only one review decision may be recorded per built message.")
merged_decisions.update({str(item.get("job_id")): item for item in requested})
else:
merged_decisions = {}
if inspection_complete:
normalized_reviewed, normalized_decisions = _complete_campaign_review(
session,
version,
normalized_reviewed,
issue_decisions or [],
list(merged_decisions.values()) if merge_progress else requested,
user_id=user_id,
build_token=build_token,
)
else:
# A progress save inspects only explicitly submitted rows. In particular,
# it does not rebuild messages, resolve files or load every built body.
selected_keys = set(str(value) for value in reviewed_message_keys if str(value).strip())
jobs = _selected_review_jobs(session, version.id, selected_keys, requested)
_assert_review_selection(jobs, selected_keys, requested, decision_category_key)
decisions = _normalize_review_issue_decisions(jobs, requested, user_id=user_id, build_token=build_token)
normalized_reviewed = list(dict.fromkeys([*normalized_reviewed, *(item["review_key"] for item in decisions)]))
if merge_progress:
# Retain other reviewers' evidence verbatim; only submitted decisions
# may replace their own job's reason/evidence.
merged_decisions = {str(item.get("job_id")): item for item in previous_decisions}
merged_decisions.update({item["job_id"]: item for item in decisions})
normalized_decisions = list(merged_decisions.values())
else:
normalized_decisions = decisions
normalized_decisions = _preserve_unchanged_review_evidence(normalized_decisions, previous_decisions)
_write_campaign_review_state(
version,
build_token=build_token,
@@ -961,6 +1026,43 @@ def update_campaign_review_state(
return version
def _selected_review_jobs(session, version_id, keys, requested) -> list[CampaignJob]:
ids = [str(item.get("job_id") or "") for item in requested]
if not keys and not ids:
return []
return session.query(CampaignJob).filter(
CampaignJob.campaign_version_id == version_id,
or_(
CampaignJob.id.in_(ids), CampaignJob.entry_id.in_(keys),
and_(or_(CampaignJob.entry_id.is_(None), CampaignJob.entry_id == ""), cast(CampaignJob.entry_index, String).in_(keys)),
),
).order_by(CampaignJob.entry_index.asc()).all()
def _assert_review_selection(jobs, keys, requested, category_key) -> None:
available_keys = {str(job.entry_id or job.entry_index) for job in jobs}
if not keys.issubset(available_keys):
raise CampaignPersistenceError("A reviewed message references a message outside the current build.")
if any(job.build_status != "built" or job.validation_status in {"blocked", "excluded", "inactive"} for job in jobs):
raise CampaignPersistenceError("Only built, non-blocked delivery messages can be accepted for review.")
if any(any(isinstance(issue, dict) and str(issue.get("behavior") or "").lower() == "block" for issue in (job.issues_snapshot or [])) for job in jobs):
raise CampaignPersistenceError("Hard-blocking issues cannot be overridden by a review decision.")
if category_key is not None:
selected_ids = {str(item.get("job_id") or "") for item in requested}
if not selected_ids or any(review_decision_metadata(job)["category_key"] != category_key for job in jobs if job.id in selected_ids):
raise CampaignPersistenceError("The selected messages no longer share the requested review category.")
def _preserve_unchanged_review_evidence(decisions, previous) -> list[dict[str, Any]]:
prior_by_id = {item.get("job_id"): item for item in previous}
result = []
for decision in decisions:
prior = prior_by_id.get(decision.get("job_id"))
fields = ("decision", "reason", "build_token", "message_sha256", "issue_fingerprint", "review_key")
result.append(copy.deepcopy(prior) if prior and all(prior.get(key) == decision.get(key) for key in fields) else decision)
return result
def _campaign_review_build_token(version: CampaignVersion) -> str:
build_summary = (
version.build_summary if isinstance(version.build_summary, dict) else {}
@@ -997,7 +1099,9 @@ def _complete_campaign_review(
blocking = [
job
for job in jobs
if job.build_status != "built" or job.validation_status == "blocked"
if job.validation_status == "blocked"
or (job.build_status != "built" and job.validation_status not in {"excluded", "inactive"})
or any(isinstance(issue, dict) and str(issue.get("behavior") or "").lower() == "block" for issue in (job.issues_snapshot or []))
]
if blocking:
raise CampaignPersistenceError(
@@ -1039,7 +1143,7 @@ def _normalize_review_issue_decisions(
raise CampaignPersistenceError(
"A review decision references a message outside the current build."
)
if jobs_by_id[job_id].validation_status != "needs_review":
if not review_decision_metadata(jobs_by_id[job_id])["eligible"]:
raise CampaignPersistenceError(
"Review decisions are accepted only for messages requiring review."
)
@@ -1054,6 +1158,10 @@ def _normalize_review_issue_decisions(
timestamp = (decided_at or datetime.now(UTC)).isoformat()
normalized: list[dict[str, Any]] = []
for job in jobs:
if job.validation_status != "needs_review":
# Excluded jobs may retain the issues that triggered the deliberate
# drop. That evidence is not a request to override their exclusion.
continue
reviewable_issues = [
issue
for issue in (job.issues_snapshot or [])
@@ -1134,7 +1242,7 @@ def _bulk_acceptable_review_keys(jobs: list[CampaignJob]) -> list[str]:
return [
str(job.entry_id or job.entry_index)
for job in jobs
if job.validation_status in {"warning", "excluded"}
if job.validation_status == "warning"
]
@@ -76,6 +76,8 @@ _SYNCHRONOUS_POLICY_KEYS = (
"source",
"deployment_max_recipient_jobs",
"tenant_max_recipient_jobs",
"system_max_recipient_jobs",
"deployment_ceiling_explicit",
)
_VALIDATION_SUMMARY_KEYS = ("ok", "error_count", "warning_count")
_BUILD_SUMMARY_KEYS = (
+15 -1
View File
@@ -12,6 +12,8 @@ from sqlalchemy.orm import Session
from govoplan_campaign.backend.campaign.mail_profile_boundary import (
CAMPAIGN_MAIL_SERVER_KEYS,
campaign_mail_profile_id,
campaign_mail_references_unchanged,
campaign_preserves_legacy_mail_settings,
)
from govoplan_campaign.backend.archive_encryption import (
CampaignArchiveEncryptionError,
@@ -458,7 +460,18 @@ def _update_campaign_version_detail_response(
),
detail=str(exc),
) from exc
_require_mail_profile_use_if_needed(principal, payload.campaign_json)
preserves_legacy_mail = (
not payload.migrate_legacy_mail_settings
and campaign_preserves_legacy_mail_settings(
current_version.raw_json, payload.campaign_json
)
)
unchanged_mail_selection = (
not payload.migrate_legacy_mail_settings
and campaign_mail_references_unchanged(current_version.raw_json, payload.campaign_json)
)
if not unchanged_mail_selection:
_require_mail_profile_use_if_needed(principal, payload.campaign_json)
try:
result = _campaign_version_detail_response(
session,
@@ -499,6 +512,7 @@ def _update_campaign_version_detail_response(
}
),
"legacy_mail_settings_migrated": payload.migrate_legacy_mail_settings,
"legacy_mail_settings_preserved": preserves_legacy_mail,
"legacy_zipcrypto_acknowledgements": acknowledgements,
},
validation_error_status=status.HTTP_422_UNPROCESSABLE_CONTENT,
+4
View File
@@ -7,17 +7,21 @@ from govoplan_campaign.backend.routes.assignments import router as assignments_r
from govoplan_campaign.backend.routes.campaigns import router as campaigns_router
from govoplan_campaign.backend.routes.collaboration import router as collaboration_router
from govoplan_campaign.backend.routes.delivery import router as delivery_router
from govoplan_campaign.backend.routes.delivery_settings import router as delivery_settings_router
from govoplan_campaign.backend.routes.jobs import router as jobs_router
from govoplan_campaign.backend.routes.operations import router as operations_router
from govoplan_campaign.backend.routes.reports import router as reports_router
from govoplan_campaign.backend.routes.schedules import router as schedules_router
from govoplan_campaign.backend.routes.sharing import router as sharing_router
from govoplan_campaign.backend.routes.transfers import router as transfers_router
from govoplan_campaign.backend.routes.versions import router as versions_router
router = APIRouter()
for workflow_router in (
delivery_settings_router,
operations_router,
transfers_router,
campaigns_router,
assignments_router,
collaboration_router,
@@ -43,6 +43,13 @@ from govoplan_core.core.idm import (
CAPABILITY_IDM_FUNCTION_ASSIGNMENTS,
IdmFunctionAssignmentDirectory,
)
from govoplan_core.core.events import (
EventActorRef,
EventObjectRef,
EventTenantRef,
PlatformEvent,
emit_platform_event,
)
from govoplan_core.core.notifications import (
NotificationDispatchRequest,
notification_dispatch_provider,
@@ -127,7 +134,10 @@ def list_campaign_work_assignments(
campaign = _get_campaign_for_principal(session, campaign_id, principal)
_require_permission(principal, "campaigns:campaign:read")
statuses = tuple(dict.fromkeys(item.strip() for item in assignment_status if item.strip()))
if any(item not in {"open", "in_progress", "completed", "cancelled"} for item in statuses):
if any(
item not in {"open", "in_progress", "completed", "rejected", "cancelled"}
for item in statuses
):
raise HTTPException(status_code=422, detail="Unsupported assignment status filter.")
query = session.query(CampaignWorkAssignment).filter(
CampaignWorkAssignment.tenant_id == principal.tenant_id,
@@ -288,12 +298,20 @@ def transition_campaign_work_assignment(
if payload.action == "cancel":
raise HTTPException(status_code=403, detail="Only an assignment manager may cancel work.")
_require_revision(assignment, payload.expected_revision)
target_status = {"start": "in_progress", "complete": "completed", "cancel": "cancelled"}[payload.action]
target_status = {
"accept": "in_progress",
"start": "in_progress",
"complete": "completed",
"reject": "rejected",
"cancel": "cancelled",
}[payload.action]
if assignment.status == target_status:
return _assignment_response(assignment)
allowed = {
"accept": {"open"},
"start": {"open"},
"complete": {"open", "in_progress"},
"reject": {"open", "in_progress"},
"cancel": {"open", "in_progress"},
}
if assignment.status not in allowed[payload.action]:
@@ -306,7 +324,13 @@ def transition_campaign_work_assignment(
session,
assignment=assignment,
principal=principal,
event_kind={"start": "started", "complete": "completed", "cancel": "cancelled"}[payload.action],
event_kind={
"accept": "accepted",
"start": "started",
"complete": "completed",
"reject": "rejected",
"cancel": "cancelled",
}[payload.action],
details={"reason": payload.reason},
)
_notify_assignment(session, campaign=campaign, assignment=assignment, event_kind=payload.action)
@@ -697,6 +721,51 @@ def _record_event(
)
session.add(event)
session.flush()
emit_platform_event(
session,
PlatformEvent(
type="campaign.work.changed",
module_id="campaigns",
event_id=event.id,
occurred_at=event.created_at,
correlation_id=assignment.orchestration_correlation_id,
causation_id=assignment.workflow_step_id,
actor=EventActorRef(
type="account",
id=principal.account_id,
label=_actor_label(principal),
),
tenant=EventTenantRef(id=assignment.tenant_id),
subject=EventObjectRef(
type="campaign_work_assignment",
id=assignment.id,
),
resource=EventObjectRef(
type="campaign",
id=assignment.campaign_id,
),
classification="internal",
payload={
"campaign_id": assignment.campaign_id,
"campaign_version_id": assignment.campaign_version_id,
"assignment_id": assignment.id,
"assignment_revision": assignment.resource_revision,
"assignment_ref": (
"campaign-work-assignment:"
f"{assignment.id}:r{assignment.resource_revision}"
),
"outcome": event_kind,
"status": assignment.status,
"assignee_type": assignment.assignee_type,
"assignee_id": assignment.assignee_id,
"action_url": (
f"/campaigns/{assignment.campaign_id}/work"
f"?assignment={assignment.id}"
),
},
),
registry=get_registry(),
)
return event
@@ -12,6 +12,7 @@ from govoplan_campaign.backend.schemas import (
CampaignSendJobRequest,
CampaignSendUnattemptedRequest,
CampaignResolveOutcomeRequest,
CampaignRecoverClaimRequest,
CampaignDeliveryOptionsResponse,
MockCampaignSendRequest,
MockCampaignSendResponse,
@@ -84,6 +85,32 @@ router = APIRouter(prefix="/campaigns", tags=["campaigns"])
logger = logging.getLogger(__name__)
@router.get("/{campaign_id}/delivery-progress")
def get_campaign_delivery_progress(
campaign_id: str,
version_id: str | None = None,
session: Session = Depends(get_session),
principal: ApiPrincipal = Depends(require_scope("campaigns:campaign:read")),
):
from govoplan_campaign.backend.services.delivery_progress import campaign_delivery_progress
_get_campaign_for_principal(session, campaign_id, principal)
try:
return campaign_delivery_progress(session, tenant_id=principal.tenant_id, campaign_id=campaign_id, version_id=version_id)
except QueueingError as exc:
raise HTTPException(status_code=404, detail=str(exc)) from exc
def _public_recovery_result(result: dict) -> dict:
if not result.get("run_inline"):
return result
public = public_send_campaign_now_result(result, validation_summary={}, build_summary={})
for key in ("action", "selected_count", "remaining_count", "enqueued_count", "skipped", "run_inline"):
if key in result:
public[key] = result[key]
return public
@router.get(
"/{campaign_id}/delivery-options", response_model=CampaignDeliveryOptionsResponse
)
@@ -242,6 +269,8 @@ def retry_campaign_jobs(
_get_campaign_for_principal(session, campaign_id, principal, write=True)
_require_permission(principal, "campaigns:recipient:read")
payload = payload or CampaignRetryJobsRequest()
if payload.run_inline:
_require_permission(principal, "campaigns:campaign:send")
_require_campaign_profile_use_if_needed(
session, principal, campaign_id, payload.version_id
)
@@ -255,6 +284,7 @@ def retry_campaign_jobs(
include_permanent=payload.include_permanent,
force_max_attempts=payload.force_max_attempts,
enqueue_celery=payload.enqueue_celery,
run_inline=payload.run_inline,
dry_run=payload.dry_run,
)
audit_from_principal(
@@ -265,10 +295,10 @@ def retry_campaign_jobs(
else "campaign.jobs_retry_dry_run",
object_type="campaign",
object_id=campaign_id,
details=result,
details=_public_recovery_result(result),
commit=True,
)
return CampaignActionResponse(result=result)
return CampaignActionResponse(result=_public_recovery_result(result))
except (QueueingError, ExecutionSnapshotError) as exc:
raise HTTPException(
status_code=status.HTTP_422_UNPROCESSABLE_CONTENT, detail=str(exc)
@@ -287,6 +317,8 @@ def send_unattempted_campaign_jobs(
_get_campaign_for_principal(session, campaign_id, principal, write=True)
_require_permission(principal, "campaigns:recipient:read")
payload = payload or CampaignSendUnattemptedRequest()
if payload.run_inline:
_require_permission(principal, "campaigns:campaign:send")
_require_campaign_profile_use_if_needed(
session, principal, campaign_id, payload.version_id
)
@@ -298,6 +330,7 @@ def send_unattempted_campaign_jobs(
version_id=payload.version_id,
job_ids=payload.job_ids or None,
enqueue_celery=payload.enqueue_celery,
run_inline=payload.run_inline,
dry_run=payload.dry_run,
)
audit_from_principal(
@@ -308,10 +341,10 @@ def send_unattempted_campaign_jobs(
else "campaign.unattempted_jobs_dry_run",
object_type="campaign",
object_id=campaign_id,
details=result,
details=_public_recovery_result(result),
commit=True,
)
return CampaignActionResponse(result=result)
return CampaignActionResponse(result=_public_recovery_result(result))
except (QueueingError, ExecutionSnapshotError) as exc:
raise HTTPException(
status_code=status.HTTP_422_UNPROCESSABLE_CONTENT, detail=str(exc)
@@ -387,6 +420,34 @@ def send_single_campaign_job_endpoint(
) from exc
@router.post("/{campaign_id}/jobs/{job_id}/recover-claim", response_model=CampaignActionResponse)
def recover_campaign_job_claim(
campaign_id: str,
job_id: str,
payload: CampaignRecoverClaimRequest,
session: Session = Depends(get_session),
principal: ApiPrincipal = Depends(require_scope("campaigns:campaign:reconcile")),
):
from govoplan_campaign.backend.services.delivery_recovery import recover_stale_delivery_claim, RecoveryStateConflict
_get_campaign_for_principal(session, campaign_id, principal, write=True)
_require_permission(principal, "campaigns:recipient:read")
try:
result = recover_stale_delivery_claim(
session, tenant_id=principal.tenant_id, campaign_id=campaign_id,
job_id=job_id, channel=payload.channel,
expected_revision=payload.expected_revision, note=payload.note,
)
audit_from_principal(session, principal, action="campaign.job_claim_recovered", object_type="campaign_job", object_id=job_id, details=result, commit=True)
return CampaignActionResponse(result=result)
except (QueueingError, ExecutionSnapshotError) as exc:
session.rollback()
raise HTTPException(status_code=409 if isinstance(exc, RecoveryStateConflict) else 422, detail=str(exc)) from exc
except Exception:
session.rollback()
raise
@router.post(
"/{campaign_id}/jobs/{job_id}/resolve-outcome",
response_model=CampaignActionResponse,
@@ -440,8 +501,9 @@ def mock_send_campaign(
):
"""Run a fully visible mock delivery flow without mutating campaign state.
The route validates and builds the selected version, then optionally records
mock SMTP deliveries and mock IMAP appends. It never talks to the configured
Authoring previews validate and build transiently; reviewed-build mode
verifies frozen jobs/EML and completed review instead. Both optionally record
mock SMTP deliveries and mock IMAP appends. Neither talks to the configured
real SMTP/IMAP servers and it does not mark the version sent/final.
"""
_get_campaign_for_principal(session, campaign_id, principal, write=True)
@@ -460,6 +522,7 @@ def mock_send_campaign(
send=payload.send,
include_warnings=payload.include_warnings,
include_needs_review=payload.include_needs_review,
use_reviewed_build=payload.use_reviewed_build,
append_sent=payload.append_sent,
clear_mailbox=payload.clear_mailbox,
check_files=payload.check_files,
@@ -475,6 +538,7 @@ def mock_send_campaign(
details={
"version_id": result.get("version_id"),
"send_requested": payload.send,
"use_reviewed_build": payload.use_reviewed_build,
"sent_count": result.get("send", {}).get("sent_count"),
"failed_count": result.get("send", {}).get("failed_count"),
},
@@ -703,30 +767,16 @@ def append_sent(
session: Session = Depends(get_session),
principal: ApiPrincipal = Depends(require_scope("campaigns:campaign:send")),
):
_get_campaign_for_principal(session, campaign_id, principal, write=True)
campaign = _get_campaign_for_principal(session, campaign_id, principal, write=True)
payload = payload or AppendSentRequest()
version_ids = {
row[0]
for row in session.query(CampaignJob.campaign_version_id)
.filter(
CampaignJob.tenant_id == principal.tenant_id,
CampaignJob.campaign_id == campaign_id,
CampaignJob.send_status.in_(
[JobSendStatus.SMTP_ACCEPTED.value, JobSendStatus.SENT.value]
),
CampaignJob.imap_status.in_(
[JobImapStatus.PENDING.value, JobImapStatus.FAILED.value]
),
)
.distinct()
.all()
}
_require_campaign_versions_profile_use(session, principal, campaign_id, version_ids)
selected_version_id = payload.version_id or campaign.current_version_id
_require_campaign_profile_use_if_needed(session, principal, campaign_id, selected_version_id)
try:
result = enqueue_pending_imap_appends(
session,
tenant_id=principal.tenant_id,
campaign_id=campaign_id,
version_id=selected_version_id,
enqueue_celery=payload.enqueue_celery,
run_inline=payload.run_inline,
dry_run=payload.dry_run,
@@ -0,0 +1,138 @@
"""Audited, independently editable delivery limits; never a delivery command."""
from __future__ import annotations
from typing import Literal
from fastapi import APIRouter, Depends, HTTPException
from pydantic import BaseModel, ConfigDict, Field, StrictInt
from sqlalchemy.orm import Session
from govoplan_core.admin.models import SystemSettings
from govoplan_core.admin.settings import SYSTEM_SETTINGS_ID, get_system_settings
from govoplan_core.audit.logging import audit_from_principal
from govoplan_core.auth import ApiPrincipal, require_any_scope
from govoplan_core.core.configuration_control import (
ConfigurationControlError, configuration_value_digest,
ensure_configuration_change_allowed, record_configuration_change_applied,
)
from govoplan_core.db.session import get_session
from govoplan_core.tenancy.scope import Tenant
from govoplan_campaign.backend.delivery_policy import (
ABSOLUTE_SYNCHRONOUS_SEND_MAX_RECIPIENT_JOBS,
DEFAULT_SYNCHRONOUS_SEND_MAX_RECIPIENT_JOBS,
CAMPAIGN_DELIVERY_POLICY_SETTINGS_KEY, SYNCHRONOUS_SEND_MAX_SETTINGS_KEY,
CampaignDeliveryPolicyError, effective_synchronous_send_policy,
)
from govoplan_campaign.backend.route_support import _require_permission
router = APIRouter(prefix="/campaigns/settings/delivery-policy", tags=["campaigns"])
Scope = Literal["system", "tenant"]
class DeliveryPolicyUpdate(BaseModel):
model_config = ConfigDict(extra="forbid")
synchronous_send_max_recipients: StrictInt | None = Field(default=None, ge=0, le=500)
expected_revision: str = Field(pattern=r"^[0-9a-f]{64}$")
def _state(session: Session, principal: ApiPrincipal, scope: Scope) -> dict:
policy = effective_synchronous_send_policy(session, tenant_id=principal.tenant_id, apply_tenant_override=scope == "tenant")
system_limit = policy.system_max_recipient_jobs
# Resolve the parent without projecting the tenant's own override into it.
parent_limit = min(policy.deployment_max_recipient_jobs, system_limit) if system_limit is not None else (
policy.deployment_max_recipient_jobs if policy.deployment_ceiling_explicit else DEFAULT_SYNCHRONOUS_SEND_MAX_RECIPIENT_JOBS
)
own = system_limit if scope == "system" else policy.tenant_max_recipient_jobs
system = session.get(SystemSettings, SYSTEM_SETTINGS_ID)
tenant = session.get(Tenant, principal.tenant_id) if scope == "tenant" else None
def stored_revision(row):
return ((row.settings or {}).get(CAMPAIGN_DELIVERY_POLICY_SETTINGS_KEY) or {}).get("revision", 0) if row else 0
revision = configuration_value_digest({
"scope": scope, "tenant_id": principal.tenant_id if scope == "tenant" else None,
"own": own, "system": system_limit, "deployment": policy.deployment_max_recipient_jobs,
"explicit_deployment": policy.deployment_ceiling_explicit,
"system_revision": stored_revision(system), "tenant_revision": stored_revision(tenant),
})
return {
"scope": scope, "synchronous_send_max_recipients": own, "revision": revision,
"max_configurable_recipients": policy.deployment_max_recipient_jobs if scope == "system" else parent_limit,
"effective_max_recipients": parent_limit if scope == "system" else policy.max_recipient_jobs,
"inherited_max_recipients": (policy.deployment_max_recipient_jobs if policy.deployment_ceiling_explicit else DEFAULT_SYNCHRONOUS_SEND_MAX_RECIPIENT_JOBS) if scope == "system" else parent_limit,
"absolute_max_recipients": ABSOLUTE_SYNCHRONOUS_SEND_MAX_RECIPIENT_JOBS,
"deployment_ceiling_explicit": policy.deployment_ceiling_explicit,
"deployment_max_recipients": policy.deployment_max_recipient_jobs,
}
def _scope_permission(principal: ApiPrincipal, scope: Scope, operation: str) -> None:
_require_permission(principal, f"system:settings:{operation}" if scope == "system" else f"admin:policies:{operation}")
@router.get("/{scope}")
def read_delivery_policy(
scope: Scope, session: Session = Depends(get_session),
principal: ApiPrincipal = Depends(require_any_scope("system:settings:read", "admin:policies:read")),
):
_scope_permission(principal, scope, "read")
try:
return _state(session, principal, scope)
except CampaignDeliveryPolicyError as exc:
raise HTTPException(422, detail=str(exc)) from exc
@router.put("/{scope}")
def update_delivery_policy(
scope: Scope, payload: DeliveryPolicyUpdate, session: Session = Depends(get_session),
principal: ApiPrincipal = Depends(require_any_scope("system:settings:write", "admin:policies:write")),
):
_scope_permission(principal, scope, "write")
try:
# Always lock in the same order; history and system policy share one Core row.
system = session.query(SystemSettings).filter(SystemSettings.id == SYSTEM_SETTINGS_ID).populate_existing().with_for_update().one_or_none()
if system is None:
system = get_system_settings(session)
target = system
if scope == "tenant":
target = session.query(Tenant).filter(Tenant.id == principal.tenant_id).populate_existing().with_for_update().one_or_none()
if target is None:
raise HTTPException(404, detail="Tenant not found")
before = _state(session, principal, scope)
if payload.expected_revision != before["revision"]:
raise HTTPException(409, detail="Campaign delivery policy changed. Reload the saved policy before retrying; your draft has not been saved.")
value = payload.synchronous_send_max_recipients
if value is not None and value > before["max_configurable_recipients"]:
raise HTTPException(422, detail=f"This scope may configure at most {before['max_configurable_recipients']} recipient jobs; inherited or explicit deployment ceilings cannot be raised here.")
key = f"campaign_delivery_policy.{scope}"
after_value = {SYNCHRONOUS_SEND_MAX_SETTINGS_KEY: value}
approval = ensure_configuration_change_allowed(
session, key=key, value=after_value, actor_user_id=principal.user.id,
actor_scopes=tuple(principal.scopes), target={"scope": scope, "tenant_id": principal.tenant_id if scope == "tenant" else None},
)
settings = dict(target.settings or {})
saved_policy = dict(settings.get(CAMPAIGN_DELIVERY_POLICY_SETTINGS_KEY) or {})
saved_policy["revision"] = int(saved_policy.get("revision") or 0) + 1
if value is None:
saved_policy.pop(SYNCHRONOUS_SEND_MAX_SETTINGS_KEY, None)
else:
saved_policy[SYNCHRONOUS_SEND_MAX_SETTINGS_KEY] = value
settings[CAMPAIGN_DELIVERY_POLICY_SETTINGS_KEY] = saved_policy
target.settings = settings
session.flush()
record_configuration_change_applied(
session, key=key, before_value={SYNCHRONOUS_SEND_MAX_SETTINGS_KEY: before[SYNCHRONOUS_SEND_MAX_SETTINGS_KEY]},
after_value=after_value, actor_user_id=principal.user.id, approval=approval,
target={"scope": scope, "tenant_id": principal.tenant_id if scope == "tenant" else None},
audit_event="campaign.delivery_policy_updated",
)
result = _state(session, principal, scope)
audit_from_principal(session, principal, action="campaign.delivery_policy_updated", scope=scope, object_type="campaign_delivery_policy",
object_id=scope if scope == "system" else principal.tenant_id,
details={"scope": scope, "before": before[SYNCHRONOUS_SEND_MAX_SETTINGS_KEY], "after": value, "effective_max_recipients": result["effective_max_recipients"]}, commit=False)
session.commit()
return result
except (CampaignDeliveryPolicyError, ConfigurationControlError) as exc:
session.rollback()
raise HTTPException(422, detail=str(exc)) from exc
except Exception:
session.rollback()
raise
@@ -48,6 +48,7 @@ from govoplan_campaign.backend.services.job_queries import (
_job_attempts_payload,
_calendar_invitations_for_jobs,
_job_detail_payload,
_job_page_recovery_metadata,
_job_diagnostics_payload,
)
@@ -425,6 +426,7 @@ def get_job_detail(
return CampaignJobDetailResponse(
job=_job_detail_payload(
job,
recovery=_job_page_recovery_metadata(session, [job]).get(job.id),
calendar_invitation=_calendar_invitations_for_jobs(
session,
[job],
@@ -0,0 +1,378 @@
from __future__ import annotations
import copy
from importlib import metadata
from typing import Any
from fastapi import APIRouter, Depends, HTTPException, status
from sqlalchemy.orm import Session
from govoplan_campaign.backend.campaign.transfers import (
CampaignImportInspection,
CampaignTransferError,
build_campaign_portable_package,
inspect_campaign_portable_package,
)
from govoplan_campaign.backend.db.models import (
Campaign,
CampaignIssue,
CampaignJob,
CampaignVersion,
)
from govoplan_campaign.backend.persistence.campaigns import (
create_campaign_version_from_json,
)
from govoplan_campaign.backend.route_support import (
_campaign_response_context,
_get_campaign_for_principal,
_require_permission,
_write_current_version_snapshot_if_available,
)
from govoplan_campaign.backend.schemas import (
CampaignExportRequest,
CampaignImportApplyRequest,
CampaignImportApplyResponse,
CampaignImportPreviewRequest,
CampaignImportPreviewResponse,
CampaignPortablePackageResponse,
CampaignResponse,
CampaignVersionResponse,
)
from govoplan_core.audit.logging import audit_from_principal
from govoplan_core.auth import ApiPrincipal, require_scope
from govoplan_core.db.session import get_session
router = APIRouter(tags=["campaigns"])
@router.post(
"/campaigns/{campaign_id}/versions/{version_id}/exports",
response_model=CampaignPortablePackageResponse,
)
def export_campaign_package(
campaign_id: str,
version_id: str,
payload: CampaignExportRequest,
session: Session = Depends(get_session),
principal: ApiPrincipal = Depends(
require_scope("campaigns:campaign:export")
),
):
campaign = _get_campaign_for_principal(session, campaign_id, principal)
version = (
session.query(CampaignVersion)
.filter(
CampaignVersion.id == version_id,
CampaignVersion.campaign_id == campaign.id,
)
.one_or_none()
)
if version is None:
raise HTTPException(
status_code=status.HTTP_404_NOT_FOUND,
detail="Campaign version not found",
)
scopes = set(payload.scopes)
if "recipients" in scopes:
_require_permission(principal, "campaigns:recipient:read")
_require_permission(principal, "campaigns:recipient:export")
if "review_state" in scopes:
_require_permission(principal, "campaigns:report:read")
if "delivery_history" in scopes:
_require_permission(principal, "campaigns:report:export")
_require_permission(principal, "campaigns:recipient:read")
_require_permission(principal, "campaigns:recipient:export")
jobs = (
session.query(CampaignJob)
.filter(CampaignJob.campaign_version_id == version.id)
.order_by(CampaignJob.entry_index.asc(), CampaignJob.id.asc())
.all()
if "delivery_history" in scopes
else ()
)
issues = (
session.query(CampaignIssue)
.filter(CampaignIssue.campaign_version_id == version.id)
.order_by(CampaignIssue.id.asc())
.all()
if "review_state" in scopes
else ()
)
try:
package = build_campaign_portable_package(
campaign=campaign,
version=version,
scopes=payload.scopes,
jobs=jobs,
issues=issues,
module_version=_module_version(),
)
audit_from_principal(
session,
principal,
action="campaign.portable_export_created",
object_type="campaign_version",
object_id=version.id,
details={
"campaign_id": campaign.id,
"package_id": package["package_id"],
"package_sha256": package["integrity"]["package_sha256"],
"format_version": package["format_version"],
"scopes": package["scopes"],
"item_counts": package["manifest"]["item_counts"],
"redactions": package["manifest"]["redactions"],
},
commit=True,
)
except CampaignTransferError as exc:
session.rollback()
raise HTTPException(
status_code=status.HTTP_422_UNPROCESSABLE_CONTENT,
detail=str(exc),
) from exc
except Exception:
session.rollback()
raise
return package
@router.post(
"/campaign-transfers/imports/preview",
response_model=CampaignImportPreviewResponse,
)
def preview_campaign_import(
payload: CampaignImportPreviewRequest,
session: Session = Depends(get_session),
principal: ApiPrincipal = Depends(
require_scope("campaigns:campaign:import")
),
):
_require_permission(principal, "campaigns:campaign:create")
inspection = _inspect_import_request(
session,
principal,
package=payload.package,
selected_scopes=payload.selected_scopes,
external_id=payload.external_id,
name=payload.name,
)
return inspection.preview
@router.post(
"/campaign-transfers/imports",
response_model=CampaignImportApplyResponse,
status_code=status.HTTP_201_CREATED,
)
def import_campaign_package(
payload: CampaignImportApplyRequest,
session: Session = Depends(get_session),
principal: ApiPrincipal = Depends(
require_scope("campaigns:campaign:import")
),
):
_require_permission(principal, "campaigns:campaign:create")
inspection = _inspect_import_request(
session,
principal,
package=payload.package,
selected_scopes=payload.selected_scopes,
external_id=payload.external_id,
name=payload.name,
)
_require_import_scope_permissions(principal, inspection)
preview = inspection.preview
if payload.expected_package_sha256 != preview.get("package_sha256"):
raise HTTPException(
status_code=status.HTTP_409_CONFLICT,
detail="The Campaign package changed after preview. Preview it again before importing.",
)
if not preview["compatible"] or inspection.configuration is None:
raise HTTPException(
status_code=status.HTTP_422_UNPROCESSABLE_CONTENT,
detail={
"message": "The Campaign package is not compatible.",
"errors": preview["errors"],
},
)
destination = preview["destination"]
package_id = str(preview["package_id"])
package_sha256 = str(preview["package_sha256"])
receipt = {
"package_id": package_id,
"package_sha256": package_sha256,
"format_version": preview["format_version"],
"source": copy.deepcopy(preview["source"]),
"selected_scopes": list(preview["selected_scopes"]),
"created": copy.deepcopy(preview["will_create"]),
"skipped": copy.deepcopy(preview["will_skip"]),
}
try:
campaign, version = create_campaign_version_from_json(
session,
tenant_id=principal.tenant_id,
user_id=principal.user.id,
raw_json=inspection.configuration,
source_filename=f"{package_id}.govoplan-campaign.json",
source_base_path=None,
commit=False,
)
campaign.settings = {
**inspection.portable_settings,
"portable_import": receipt,
}
session.add(campaign)
audit_from_principal(
session,
principal,
action="campaign.portable_import_applied",
object_type="campaign",
object_id=campaign.id,
details={
"version_id": version.id,
"external_id": destination["external_id"],
"package_id": package_id,
"package_sha256": package_sha256,
"format_version": preview["format_version"],
"selected_scopes": preview["selected_scopes"],
"created_codes": [item["code"] for item in preview["will_create"]],
"skipped_codes": [item["code"] for item in preview["will_skip"]],
},
commit=True,
)
session.refresh(campaign)
session.refresh(version)
_write_current_version_snapshot_if_available(version)
except Exception:
session.rollback()
raise
return CampaignImportApplyResponse(
campaign=CampaignResponse.model_validate(campaign),
version=CampaignVersionResponse.model_validate(
version,
context=_campaign_response_context(principal),
),
receipt=receipt,
)
def _inspect_import_request(
session: Session,
principal: ApiPrincipal,
*,
package: dict[str, Any],
selected_scopes: list[str] | None,
external_id: str | None,
name: str | None,
) -> CampaignImportInspection:
source = package.get("source")
source = source if isinstance(source, dict) else {}
metadata_payload = package.get("payload")
metadata_payload = metadata_payload if isinstance(metadata_payload, dict) else {}
metadata_scope = metadata_payload.get("metadata")
metadata_scope = metadata_scope if isinstance(metadata_scope, dict) else {}
source_external_id = str(
metadata_scope.get("external_id")
or source.get("campaign_external_id")
or "campaign"
)
destination_external_id = _portable_import_external_id(
session,
tenant_id=principal.tenant_id,
source_external_id=source_external_id,
requested=external_id,
)
destination_name = str(
name
or metadata_scope.get("name")
or source.get("campaign_name")
or "Imported campaign"
).strip()
if not destination_name:
destination_name = "Imported campaign"
inspection = inspect_campaign_portable_package(
package,
selected_scopes=selected_scopes,
external_id=destination_external_id,
name=destination_name,
)
if _campaign_external_id_exists(
session, principal.tenant_id, destination_external_id
):
inspection.preview["compatible"] = False
inspection.preview["errors"].append(
"The destination Campaign ID already exists in this tenant."
)
return CampaignImportInspection(
preview=inspection.preview,
configuration=None,
portable_settings=inspection.portable_settings,
)
return inspection
def _portable_import_external_id(
session: Session,
*,
tenant_id: str,
source_external_id: str,
requested: str | None,
) -> str:
if requested is not None:
candidate = requested.strip()
if not candidate:
raise HTTPException(
status_code=status.HTTP_422_UNPROCESSABLE_CONTENT,
detail="Campaign ID cannot be empty.",
)
return candidate
stem = f"{source_external_id[:238]}-import"
for suffix in ("", *(f"-{number}" for number in range(2, 10_000))):
candidate = f"{stem[:255 - len(suffix)]}{suffix}"
if not _campaign_external_id_exists(session, tenant_id, candidate):
return candidate
raise HTTPException(
status_code=status.HTTP_409_CONFLICT,
detail="No available Campaign import identifier could be generated.",
)
def _campaign_external_id_exists(
session: Session, tenant_id: str, external_id: str
) -> bool:
return (
session.query(Campaign.id)
.filter(
Campaign.tenant_id == tenant_id,
Campaign.external_id == external_id,
)
.first()
is not None
)
def _require_import_scope_permissions(
principal: ApiPrincipal, inspection: CampaignImportInspection
) -> None:
selected = set(inspection.preview.get("selected_scopes") or [])
if "recipients" in selected:
_require_permission(principal, "campaigns:recipient:import")
_require_permission(principal, "campaigns:recipient:write")
def _module_version() -> str:
try:
return metadata.version("govoplan-campaign")
except metadata.PackageNotFoundError:
return "development"
__all__ = [
"export_campaign_package",
"import_campaign_package",
"preview_campaign_import",
"router",
]
@@ -6,6 +6,7 @@ from urllib.parse import quote
from fastapi import APIRouter, Depends, Header, HTTPException, Query, Request, Response, status
from sqlalchemy.orm import Session
from sqlalchemy.orm.exc import StaleDataError
from govoplan_campaign.backend.schemas import (
BuildCampaignRequest,
@@ -23,6 +24,7 @@ from govoplan_campaign.backend.schemas import (
from govoplan_core.auth import ApiPrincipal, has_scope, require_scope
from govoplan_core.audit.logging import audit_from_principal
from govoplan_core.core.object_storage import StorageBackendError
from govoplan_core.core.concurrency import RevisionConflictError
from govoplan_core.core.recovery import (
RecoveryGuaranteeError,
RecoveryMode,
@@ -581,6 +583,10 @@ def set_version_review_state(
for item in payload.issue_decisions
],
user_id=principal.user.id,
merge_progress=payload.merge_progress,
expected_build_token=payload.build_token,
expected_revision=payload.base_revision,
decision_category_key=payload.decision_category_key,
commit=False,
)
audit_from_principal(
@@ -592,9 +598,17 @@ def set_version_review_state(
details={
"campaign_id": campaign_id,
"inspection_complete": payload.inspection_complete,
"merge_progress": payload.merge_progress,
"build_token": payload.build_token,
"base_revision": payload.base_revision,
"result_revision": version.edit_revision,
"reviewed_message_count": len(payload.reviewed_message_keys),
"issue_decision_count": len(payload.issue_decisions),
"issue_decisions": _review_decision_audit_evidence(version),
"issue_decisions": _review_decision_audit_evidence(
version,
job_ids={item.job_id for item in payload.issue_decisions}
if payload.merge_progress and not payload.inspection_complete else None,
),
},
commit=True,
)
@@ -602,6 +616,12 @@ def set_version_review_state(
version,
context=_campaign_response_context(principal),
)
except RevisionConflictError as exc:
session.rollback()
raise HTTPException(status_code=status.HTTP_409_CONFLICT, detail=exc.as_dict()) from exc
except StaleDataError as exc:
session.rollback()
raise HTTPException(status_code=status.HTTP_409_CONFLICT, detail="Review progress changed concurrently. Reload before saving this decision again.") from exc
except LockedCampaignVersionError as exc:
session.rollback()
raise HTTPException(
@@ -1021,13 +1041,18 @@ def _archive_encryption_audit_evidence(value: object) -> dict[str, object]:
def _review_decision_audit_evidence(
version: CampaignVersion,
*,
job_ids: set[str] | None = None,
) -> dict[str, object]:
editor_state = version.editor_state if isinstance(version.editor_state, dict) else {}
review_state = editor_state.get("review_send")
if not isinstance(review_state, dict):
return {}
raw_decisions = review_state.get("issue_decisions")
decisions = [item for item in raw_decisions or [] if isinstance(item, dict)]
decisions = [
item for item in raw_decisions or []
if isinstance(item, dict) and (job_ids is None or str(item.get("job_id")) in job_ids)
]
evidence = [
{
"decision": item.get("decision"),
+136 -4
View File
@@ -16,6 +16,7 @@ from pydantic import (
from govoplan_core.api.v1.schemas import DeltaDeletedItem
from govoplan_campaign.backend.campaign.mail_profile_boundary import (
public_campaign_editor_state,
campaign_review_reference,
validate_campaign_editor_state,
)
from govoplan_campaign.backend.response_security import (
@@ -134,7 +135,13 @@ class CampaignCollaborationListResponse(BaseModel):
CampaignWorkAssigneeType = Literal["account", "group", "organization_function"]
CampaignWorkAssignmentStatus = Literal["open", "in_progress", "completed", "cancelled"]
CampaignWorkAssignmentStatus = Literal[
"open",
"in_progress",
"completed",
"rejected",
"cancelled",
]
CampaignWorkAssigneeResolutionState = Literal[
"resolved",
"unavailable",
@@ -195,7 +202,7 @@ class CampaignWorkAssignmentTransitionRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
expected_revision: int = Field(ge=1)
action: Literal["start", "complete", "cancel"]
action: Literal["accept", "start", "complete", "reject", "cancel"]
reason: str | None = Field(default=None, max_length=500)
@field_validator("reason")
@@ -464,12 +471,22 @@ class CampaignReviewStateRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
inspection_complete: bool = False
reviewed_message_keys: list[str] = Field(default_factory=list)
merge_progress: bool = False
build_token: str | None = Field(default=None, min_length=1, max_length=256)
base_revision: int | None = Field(default=None, ge=1)
decision_category_key: str | None = Field(default=None, min_length=1, max_length=64)
reviewed_message_keys: list[str] = Field(default_factory=list, max_length=100_000)
issue_decisions: list[CampaignReviewDecisionRequest] = Field(
default_factory=list,
max_length=100_000,
)
@model_validator(mode="after")
def require_progress_preconditions(self):
if self.merge_progress and (self.build_token is None or self.base_revision is None):
raise ValueError("Incremental review requires the current build_token and base_revision.")
return self
class CampaignPartialValidationRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
@@ -485,6 +502,7 @@ class CampaignVersionResponse(BaseModel):
campaign_id: str
version_number: int
edit_revision: int = 1
review_build_token: str | None = None
strong_etag: str = ""
schema_version: str
source_filename: str | None = None
@@ -518,10 +536,15 @@ class CampaignVersionResponse(BaseModel):
def remove_unsupported_editor_state(
cls, value: Any, info: ValidationInfo
) -> dict[str, Any]:
return public_campaign_editor_state(
result = public_campaign_editor_state(
value,
include_diagnostics=bool((info.context or {}).get("include_diagnostics")),
)
if isinstance(value, dict) and isinstance(value.get("review_send"), dict) and isinstance(result.get("review_send"), dict):
result["review_send"]["review_build_token"] = campaign_review_reference(
str(info.data.get("id") or ""), value["review_send"].get("build_token")
)
return result
@field_validator("source_filename", mode="before")
@classmethod
@@ -589,6 +612,96 @@ class CampaignCreateResponse(BaseModel):
version: CampaignVersionResponse
CampaignTransferScope = Literal[
"metadata",
"template_config",
"recipients",
"attachments",
"review_state",
"delivery_history",
]
class CampaignExportRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
scopes: list[CampaignTransferScope] = Field(
default_factory=lambda: ["metadata", "template_config"],
min_length=1,
max_length=6,
)
@field_validator("scopes")
@classmethod
def normalize_scopes(
cls, value: list[CampaignTransferScope]
) -> list[CampaignTransferScope]:
return list(dict.fromkeys(value))
class CampaignPortablePackageResponse(BaseModel):
model_config = ConfigDict(extra="forbid")
format: Literal["govoplan.campaign-portable"]
format_version: str
package_id: str
exported_at: str
source: dict[str, Any]
scopes: list[CampaignTransferScope]
manifest: dict[str, Any]
payload: dict[str, Any]
integrity: dict[str, str]
class CampaignImportPreviewRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
package: dict[str, Any]
selected_scopes: list[CampaignTransferScope] | None = Field(
default=None,
max_length=6,
)
external_id: str | None = Field(default=None, min_length=1, max_length=255)
name: str | None = Field(default=None, min_length=1, max_length=255)
@field_validator("selected_scopes")
@classmethod
def normalize_selected_scopes(
cls, value: list[CampaignTransferScope] | None
) -> list[CampaignTransferScope] | None:
return list(dict.fromkeys(value)) if value is not None else None
class CampaignImportApplyRequest(CampaignImportPreviewRequest):
expected_package_sha256: str = Field(min_length=64, max_length=64)
class CampaignTransferPlanItem(BaseModel):
scope: CampaignTransferScope
code: str
summary: str
item_count: int | None = None
class CampaignImportPreviewResponse(BaseModel):
compatible: bool
package_id: str | None = None
package_sha256: str | None = None
format_version: str | None = None
source: dict[str, Any] = Field(default_factory=dict)
available_scopes: list[CampaignTransferScope] = Field(default_factory=list)
selected_scopes: list[CampaignTransferScope] = Field(default_factory=list)
destination: dict[str, Any] = Field(default_factory=dict)
will_create: list[CampaignTransferPlanItem] = Field(default_factory=list)
will_skip: list[CampaignTransferPlanItem] = Field(default_factory=list)
warnings: list[str] = Field(default_factory=list)
errors: list[str] = Field(default_factory=list)
class CampaignImportApplyResponse(CampaignCreateResponse):
receipt: dict[str, Any]
class CampaignListResponse(BaseModel):
campaigns: list[CampaignResponse]
@@ -997,6 +1110,7 @@ class CampaignRetryJobsRequest(BaseModel):
include_permanent: bool = False
force_max_attempts: bool = False
enqueue_celery: bool = True
run_inline: bool = False
dry_run: bool = False
@@ -1006,6 +1120,7 @@ class CampaignSendUnattemptedRequest(BaseModel):
version_id: str | None = None
job_ids: list[str] = Field(default_factory=list)
enqueue_celery: bool = True
run_inline: bool = False
dry_run: bool = False
@@ -1050,6 +1165,21 @@ class CampaignResolveOutcomeRequest(BaseModel):
return self
class CampaignRecoverClaimRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
channel: Literal["smtp", "imap"]
expected_revision: str = Field(pattern=r"^[0-9a-f]{64}$")
note: str = Field(min_length=1, max_length=2000)
@model_validator(mode="after")
def require_evidence(self):
self.note = self.note.strip()
if not self.note:
raise ValueError("Claim recovery requires an evidence note")
return self
class ValidateCampaignRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
@@ -1182,6 +1312,7 @@ class MockCampaignSendRequest(BaseModel):
send: bool = False
include_warnings: bool = True
include_needs_review: bool = False
use_reviewed_build: bool = False
append_sent: bool = True
clear_mailbox: bool = False
check_files: bool = False
@@ -1194,6 +1325,7 @@ class MockCampaignSendResponse(BaseModel):
class AppendSentRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
version_id: str | None = None
enqueue_celery: bool = True
run_inline: bool = False
dry_run: bool = False
+248 -104
View File
@@ -4,7 +4,7 @@ import hashlib
import json
from collections import Counter
from contextlib import nullcontext
from dataclasses import asdict, dataclass
from dataclasses import asdict, dataclass, replace
from datetime import datetime, timezone
from email import policy
from email.parser import BytesParser
@@ -284,6 +284,9 @@ class AppendSentResult:
dry_run: bool = False
folder: str | None = None
message: str | None = None
connection_sequence: int | None = None
session_reused: bool = False
reconnect_count: int = 0
def as_dict(self) -> dict[str, Any]:
return {
@@ -293,6 +296,9 @@ class AppendSentResult:
"dry_run": self.dry_run,
"folder": self.folder,
"message": self.message,
"connection_sequence": self.connection_sequence,
"session_reused": self.session_reused,
"reconnect_count": self.reconnect_count,
}
@@ -1074,6 +1080,32 @@ def send_campaign_now(
# Repeat the hard bound against the post-queue set. This closes the window
# where a concurrent queue operation could otherwise enlarge an immediate
# run between the initial decision and the first provider effect.
_ensure_synchronous_send_count_allowed(len(jobs), policy=synchronous_policy)
return _send_synchronous_job_batch(
session,
campaign=campaign,
version=version,
jobs=jobs,
synchronous_policy=synchronous_policy,
skipped_count=queue_result.skipped_count + queue_result.blocked_count,
use_rate_limit=use_rate_limit,
enqueue_imap_task=enqueue_imap_task,
)
def _send_synchronous_job_batch(
session: Session,
*,
campaign: Campaign,
version: CampaignVersion,
jobs: list[CampaignJob],
synchronous_policy: SynchronousSendPolicy,
skipped_count: int = 0,
use_rate_limit: bool = True,
enqueue_imap_task: bool = False,
) -> SendCampaignNowResult:
"""Shared immutable-job execution for initial delivery and explicit recovery."""
_ensure_synchronous_send_count_allowed(len(jobs), policy=synchronous_policy)
delivery_contexts = _preflight_synchronous_send_batch(
session,
@@ -1095,8 +1127,10 @@ def send_campaign_now(
jobs=jobs,
contexts=delivery_contexts,
)
batch_entered = False
try:
with batch_manager as smtp_batch:
batch_entered = True
# Queue state becomes durable only after local and SMTP
# DNS/connectivity/TLS/auth preflight succeeds.
session.commit()
@@ -1116,6 +1150,8 @@ def send_campaign_now(
sent_count += 1
elif result.status == JobSendStatus.OUTCOME_UNKNOWN.value:
outcome_unknown_count += 1
elif result.status in {JobSendStatus.FAILED_TEMPORARY.value, JobSendStatus.FAILED_PERMANENT.value, "failed"}:
failed_count += 1
else:
skipped_after_queue += 1
except Exception as exc:
@@ -1143,9 +1179,39 @@ def send_campaign_now(
smtp_reconnect_count = int(getattr(smtp_batch, "reconnect_count", 0) or 0)
except (MailProfileError, SmtpConfigurationError, SmtpSendError, OSError) as exc:
session.rollback()
reason_code = str(getattr(exc, "reason_code", "") or "smtp_batch_preflight_failed")
if batch_entered:
# This catch also covers batch teardown. Once entry succeeded it
# must not relabel a later error as a no-effect preflight failure.
raise SendJobError(
"Synchronous delivery was interrupted after SMTP preflight. "
"Messages may already have been sent. Inspect the Campaign report "
"and resolve uncertain outcomes before retrying."
) from exc
if isinstance(exc, MailProfileError):
reason_code = "mail_profile_preflight_failed"
explanation = (
"Campaign delivery preflight was blocked by the selected Mail profile, "
"credential selection, or effective Mail policy. Check the campaign's "
"Mail settings and authorized references"
)
elif isinstance(exc, SmtpConfigurationError):
reason_code = "smtp_configuration_preflight_failed"
explanation = (
"Campaign delivery preflight could not use the selected SMTP configuration. "
"Check its server, credentials, and outbound connection policy"
)
else:
explanations = {
"smtp_authentication_failed": "SMTP authentication failed for the campaign's selected credential",
"smtp_preflight_rejected": "The SMTP server rejected the campaign's connection preflight",
"smtp_connectivity_unavailable": "SMTP preflight could not establish DNS, connectivity, or TLS",
}
reason_code = getattr(exc, "reason_code", None)
if reason_code not in explanations:
reason_code = "smtp_connectivity_unavailable"
explanation = explanations[reason_code]
raise SynchronousSendRejected(
"SMTP batch preflight could not validate DNS, connectivity, TLS, and authentication; no message was sent.",
f"{explanation}; no message was sent.",
reason=reason_code,
eligible_count=len(jobs),
policy=synchronous_policy,
@@ -1158,9 +1224,7 @@ def send_campaign_now(
sent_count=sent_count,
failed_count=failed_count,
outcome_unknown_count=outcome_unknown_count,
skipped_count=queue_result.skipped_count
+ queue_result.blocked_count
+ skipped_after_queue,
skipped_count=skipped_count + skipped_after_queue,
paused_count=paused_count,
batch_state=batch_state,
batch_pause_reason_code=pause_reason_code,
@@ -1518,6 +1582,7 @@ def queue_failed_jobs_for_retry(
include_permanent: bool = False,
force_max_attempts: bool = False,
enqueue_celery: bool = True,
run_inline: bool = False,
dry_run: bool = False,
) -> dict[str, Any]:
"""Queue known failures and incomplete multi-channel deliveries.
@@ -1549,7 +1614,12 @@ def queue_failed_jobs_for_retry(
version=version,
job_ids=job_ids,
):
if job.send_status not in allowed:
if (
job.send_status not in allowed
or job.claim_token is not None
or job.build_status != JobBuildStatus.BUILT.value
or not _single_job_validation_allowed(version, job, include_warnings=True)
):
skipped.append(
{
"job_id": job.id,
@@ -1575,42 +1645,11 @@ def queue_failed_jobs_for_retry(
)
continue
selected.append(job)
if not dry_run:
job.queue_status = JobQueueStatus.QUEUED.value
job.send_status = JobSendStatus.QUEUED.value
job.queued_at = _utcnow()
job.claimed_at = None
job.claim_token = None
job.smtp_started_at = None
job.outcome_unknown_at = None
session.add(job)
if not dry_run:
if selected:
campaign.status = CampaignStatus.QUEUED.value
version.workflow_state = CampaignVersionWorkflowState.QUEUED.value
_set_version_delivery_mode(
version,
_asynchronous_delivery_mode(enqueue_celery),
)
session.add(campaign)
session.add(version)
session.commit()
enqueued = 0
if _should_enqueue_celery(enqueue_celery) and not dry_run:
for job in selected:
_celery_enqueue_send_job(job.id)
enqueued += 1
return {
"campaign_id": campaign.id,
"version_id": version.id,
"action": "retry_failed",
"selected_count": len(selected),
"enqueued_count": enqueued,
"skipped": skipped,
"dry_run": dry_run,
}
return _execute_explicit_delivery_selection(
session, campaign=campaign, version=version, selected=selected,
skipped=skipped, action="retry_failed", enqueue_celery=enqueue_celery,
run_inline=run_inline, dry_run=dry_run,
)
def queue_unattempted_jobs(
@@ -1621,6 +1660,7 @@ def queue_unattempted_jobs(
version_id: str | None = None,
job_ids: list[str] | None = None,
enqueue_celery: bool = True,
run_inline: bool = False,
dry_run: bool = False,
) -> dict[str, Any]:
"""Explicitly queue built jobs that have never started an SMTP attempt."""
@@ -1645,10 +1685,12 @@ def queue_unattempted_jobs(
eligible = (
job.attempt_count == 0
and job.postbox_attempt_count == 0
and job.print_attempt_count == 0
and job.claim_token is None
and job.send_status
in {JobSendStatus.NOT_QUEUED.value, JobSendStatus.CANCELLED.value}
in {JobSendStatus.NOT_QUEUED.value, JobSendStatus.CANCELLED.value, JobSendStatus.QUEUED.value}
and job.build_status == JobBuildStatus.BUILT.value
and job.validation_status in QUEUEABLE_VALIDATION_STATUSES
and _single_job_validation_allowed(version, job, include_warnings=True)
)
if not eligible:
skipped.append(
@@ -1659,41 +1701,86 @@ def queue_unattempted_jobs(
)
continue
selected.append(job)
if not dry_run:
job.queue_status = JobQueueStatus.QUEUED.value
job.send_status = JobSendStatus.QUEUED.value
job.queued_at = _utcnow()
job.claimed_at = None
job.claim_token = None
job.smtp_started_at = None
job.outcome_unknown_at = None
job.last_error = None
session.add(job)
return _execute_explicit_delivery_selection(
session, campaign=campaign, version=version, selected=selected,
skipped=skipped, action="send_unattempted", enqueue_celery=enqueue_celery,
run_inline=run_inline, dry_run=dry_run,
)
def _execute_explicit_delivery_selection(
session: Session, *, campaign: Campaign, version: CampaignVersion,
selected: list[CampaignJob], skipped: list[dict[str, str]], action: str,
enqueue_celery: bool, run_inline: bool, dry_run: bool,
) -> dict[str, Any]:
"""Queue a compare-and-set selection; inline recovery uses normal delivery."""
synchronous_policy = None
remaining_count = 0
if run_inline:
try:
synchronous_policy = effective_synchronous_send_policy(session, tenant_id=campaign.tenant_id)
except CampaignDeliveryPolicyError as exc:
raise QueueingError(f"Invalid synchronous Campaign delivery policy: {exc}") from exc
if synchronous_policy.max_recipient_jobs == 0:
raise QueueingError("Synchronous Campaign delivery is disabled by policy.")
remaining_count = max(0, len(selected) - synchronous_policy.max_recipient_jobs)
selected = selected[:synchronous_policy.max_recipient_jobs]
if not dry_run:
if selected:
campaign.status = CampaignStatus.QUEUED.value
version.workflow_state = CampaignVersionWorkflowState.QUEUED.value
_set_version_delivery_mode(
version,
_asynchronous_delivery_mode(enqueue_celery),
)
session.add(campaign)
session.add(version)
session.commit()
enqueued = 0
if _should_enqueue_celery(enqueue_celery) and not dry_run:
_ensure_campaign_approval_gate(session, tenant_id=campaign.tenant_id, version=version)
claimed_selection = []
for job in selected:
_celery_enqueue_send_job(job.id)
enqueued += 1
return {
"campaign_id": campaign.id,
"version_id": version.id,
"action": "send_unattempted",
"selected_count": len(selected),
"enqueued_count": enqueued,
"skipped": skipped,
"dry_run": dry_run,
# A worker or another operator may have claimed the row after the
# selection query. Never reset that claim or an accepted attempt.
changed = session.query(CampaignJob).filter(
CampaignJob.id == job.id,
CampaignJob.tenant_id == campaign.tenant_id,
CampaignJob.send_status == job.send_status,
CampaignJob.queue_status == job.queue_status,
CampaignJob.attempt_count == job.attempt_count,
CampaignJob.postbox_attempt_count == job.postbox_attempt_count,
CampaignJob.print_attempt_count == job.print_attempt_count,
CampaignJob.claim_token.is_(None),
).update({
CampaignJob.queue_status: JobQueueStatus.QUEUED.value,
CampaignJob.send_status: JobSendStatus.QUEUED.value,
CampaignJob.queued_at: _utcnow(),
CampaignJob.claimed_at: None,
CampaignJob.smtp_started_at: None,
CampaignJob.outcome_unknown_at: None,
}, synchronize_session=False)
if changed:
session.refresh(job)
claimed_selection.append(job)
else:
skipped.append({"job_id": job.id, "reason": "delivery state changed during selection"})
selected = claimed_selection
_persist_campaign_queue(
session, campaign=campaign, version=version, queued=selected,
delivery_mode=DELIVERY_MODE_SYNCHRONOUS if run_inline else _asynchronous_delivery_mode(enqueue_celery),
commit=not run_inline,
)
result = {
"campaign_id": campaign.id, "version_id": version.id, "action": action,
"selected_count": len(selected), "remaining_count": remaining_count,
"enqueued_count": 0, "skipped": skipped, "dry_run": dry_run,
"run_inline": run_inline,
}
if run_inline and not dry_run and selected:
assert synchronous_policy is not None
try:
outcome = _send_synchronous_job_batch(
session, campaign=campaign, version=version, jobs=selected,
synchronous_policy=synchronous_policy, skipped_count=len(skipped),
)
except Exception:
# Local preflight may fail before the batch connection is entered.
# No pending queue edits may leak into a caller's later commit.
session.rollback()
raise
result.update(outcome.as_dict())
elif not dry_run and _should_enqueue_celery(enqueue_celery) and not run_inline:
result["enqueued_count"] = _enqueue_campaign_jobs(selected, enabled=True)
return result
def send_single_campaign_job(
@@ -2731,6 +2818,19 @@ def reconcile_job_outcome(
snapshot = ensure_execution_snapshot(session, version)
now = _utcnow()
attempt = _unfinished_attempt(session, job)
if attempt is None:
attempt = session.query(SendAttempt).filter(
SendAttempt.job_id == job.id,
SendAttempt.status == JobSendStatus.OUTCOME_UNKNOWN.value,
).order_by(SendAttempt.attempt_number.desc()).first()
if decision not in {"smtp_accepted", "not_sent"}:
raise QueueingError("decision must be 'smtp_accepted' or 'not_sent'")
from govoplan_campaign.backend.services.delivery_recovery import reconcile_campaign_delivery_operation
reconcile_campaign_delivery_operation(
session, job=job, channel="smtp", claim_token=getattr(attempt, "claim_token", None),
effect_occurred=decision == "smtp_accepted", note=evidence_note,
)
_claim_unknown_reconciliation(session, job, channel="smtp", next_status="smtp_accepted" if decision == "smtp_accepted" else "failed_temporary")
if decision == "smtp_accepted":
job.send_status = JobSendStatus.SMTP_ACCEPTED.value
job.queue_status = JobQueueStatus.DRAFT.value
@@ -2926,6 +3026,8 @@ def _reconcile_imap_append_outcome(
raise QueueingError(
f"IMAP status {job.imap_status} does not require reconciliation"
)
if decision not in {"imap_appended", "imap_not_appended"}:
raise QueueingError("IMAP decision must be 'imap_appended' or 'imap_not_appended'")
attempt = (
session.query(ImapAppendAttempt)
@@ -2933,6 +3035,12 @@ def _reconcile_imap_append_outcome(
.order_by(ImapAppendAttempt.attempt_number.desc())
.first()
)
from govoplan_campaign.backend.services.delivery_recovery import reconcile_campaign_delivery_operation
reconcile_campaign_delivery_operation(
session, job=job, channel="imap", claim_token=getattr(attempt, "claim_token", None),
effect_occurred=decision == "imap_appended", note=evidence_note,
)
_claim_unknown_reconciliation(session, job, channel="imap", next_status="appended" if decision == "imap_appended" else "failed")
if decision == "imap_appended":
job.imap_status = JobImapStatus.APPENDED.value
attempt_status = "reconciled_imap_appended"
@@ -2971,6 +3079,22 @@ def _reconcile_imap_append_outcome(
}
def _claim_unknown_reconciliation(session: Session, job: CampaignJob, *, channel: str, next_status: str) -> None:
"""Conflicting operators cannot overwrite an already reconciled outcome."""
column = CampaignJob.send_status if channel == "smtp" else CampaignJob.imap_status
claim_column = CampaignJob.claim_token if channel == "smtp" else CampaignJob.imap_claim_token
claim_token = getattr(job, "claim_token" if channel == "smtp" else "imap_claim_token", None)
changed = session.query(CampaignJob).filter(
CampaignJob.id == job.id,
CampaignJob.tenant_id == job.tenant_id,
column == "outcome_unknown",
claim_column == claim_token,
).update({column: next_status}, synchronize_session=False)
if changed != 1:
raise QueueingError("The delivery outcome changed; reload its current evidence before reconciliation.")
session.refresh(job)
def _verify_eml_evidence(job: CampaignJob, payload: bytes) -> None:
if job.eml_size_bytes is not None and len(payload) != job.eml_size_bytes:
raise SendJobError(
@@ -3615,10 +3739,10 @@ def _preflight_send_campaign_job(
message="A delivery outcome is unresolved; reconcile it before any retry.",
)
if job.send_status == JobSendStatus.SENDING.value:
return mark_job_outcome_unknown(
session,
job,
reason="A delivery task resumed while the previous channel attempt was still marked in progress. Automatic redelivery was stopped.",
return SendJobResult(
job_id=job.id, status="already_sending", attempt_number=job.attempt_count,
dry_run=dry_run,
message="Another runtime owns the active delivery. A stopped runtime's claim requires explicit guarded recovery.",
)
if job.send_status == JobSendStatus.CLAIMED.value:
return SendJobResult(
@@ -4983,13 +5107,19 @@ def _perform_imap_append(
)
raise ImapAppendError(reason, outcome_unknown=True) from None
try:
return _record_imap_append_success(
outcome = _record_imap_append_success(
session,
job=claimed.job,
attempt=claimed.attempt,
claim_token=claimed.claim_token,
folder=result.folder,
)
return replace(
outcome,
connection_sequence=getattr(result, "connection_sequence", None),
session_reused=bool(getattr(result, "session_reused", False)),
reconnect_count=int(getattr(result, "reconnect_count", 0) or 0),
)
except Exception:
return _mark_imap_append_outcome_unknown_after_effect(
session,
@@ -5194,6 +5324,7 @@ def enqueue_pending_imap_appends(
*,
tenant_id: str,
campaign_id: str,
version_id: str | None = None,
enqueue_celery: bool = True,
run_inline: bool = False,
dry_run: bool = False,
@@ -5201,11 +5332,13 @@ def enqueue_pending_imap_appends(
campaign = _get_campaign_for_tenant(
session, campaign_id=campaign_id, tenant_id=tenant_id
)
version = _get_version_for_campaign(session, campaign, version_id=version_id)
jobs = (
session.query(CampaignJob)
.filter(
CampaignJob.tenant_id == tenant_id,
CampaignJob.campaign_id == campaign.id,
CampaignJob.campaign_version_id == version.id,
CampaignJob.imap_status.in_(
[JobImapStatus.PENDING.value, JobImapStatus.FAILED.value]
),
@@ -5228,44 +5361,55 @@ def enqueue_pending_imap_appends(
results: list[dict[str, Any]] = []
appended_count = 0
failed_count = 0
outcome_unknown_count = 0
skipped_count = 0
connection_count = 0
reconnect_count = 0
if run_inline or dry_run:
for job in jobs:
try:
result = append_sent_for_job(session, job_id=job.id, dry_run=dry_run)
payload = result.as_dict()
results.append(payload)
if result.status == JobImapStatus.APPENDED.value:
appended_count += 1
elif result.status in {
"skipped",
"not_requested",
"not_sent",
"already_appended",
"dry_run",
}:
skipped_count += 1
except (
Exception
) as exc: # keep processing later jobs and expose per-job details
failed_count += 1
results.append(
{"job_id": job.id, "status": "failed", "message": str(exc)}
)
batch_context = nullcontext() if dry_run else mail_integration().campaign_imap_batch(tenant_id=tenant_id, campaign_id=campaign.id)
with batch_context as batch:
for job in jobs:
try:
result = append_sent_for_job(session, job_id=job.id, dry_run=dry_run)
payload = result.as_dict()
results.append(payload)
if result.status == JobImapStatus.APPENDED.value:
appended_count += 1
elif result.status == JobImapStatus.OUTCOME_UNKNOWN.value:
outcome_unknown_count += 1
elif result.status == JobImapStatus.FAILED.value:
failed_count += 1
else:
skipped_count += 1
except Exception as exc:
# An uncertain append remains frozen by its per-job
# pipeline. The batch never retries the same message.
uncertain = bool(getattr(exc, "outcome_unknown", False))
if uncertain:
outcome_unknown_count += 1
else:
failed_count += 1
results.append({"job_id": job.id, "status": "outcome_unknown" if uncertain else "failed", "message": str(exc)})
connection_count = int(getattr(batch, "connection_count", 0) or 0)
reconnect_count = int(getattr(batch, "reconnect_count", 0) or 0)
elif should_enqueue:
for job in jobs:
_celery_enqueue_append_sent_job(job.id)
return {
"campaign_id": campaign.id,
"version_id": version.id,
"pending_count": len(jobs),
"enqueued_count": len(jobs) if should_enqueue else 0,
"processed_count": len(results) if run_inline and not dry_run else 0,
"appended_count": appended_count,
"failed_count": failed_count,
"outcome_unknown_count": outcome_unknown_count,
"skipped_count": skipped_count,
"dry_run": dry_run,
"run_inline": run_inline,
"imap_connection_count": connection_count,
"imap_reconnect_count": reconnect_count,
"results": results,
}
@@ -0,0 +1,82 @@
"""Small, address-free delivery counters for an explicitly selected version."""
from collections import Counter
from datetime import datetime, timezone
from typing import Any
from sqlalchemy import func
from sqlalchemy.orm import Session
from govoplan_campaign.backend.db.models import CampaignJob, SendAttempt
from govoplan_campaign.backend.sending.jobs import _get_campaign_for_tenant, _get_version_for_campaign
def campaign_delivery_progress(session: Session, *, tenant_id: str, campaign_id: str, version_id: str | None = None) -> dict[str, Any]:
campaign = _get_campaign_for_tenant(session, campaign_id=campaign_id, tenant_id=tenant_id)
version = _get_version_for_campaign(session, campaign, version_id=version_id)
# Aggregate status columns only. Never load recipient/attachment JSON, EML,
# issues, or attempts for a progress poll.
accepted_attempt = session.query(SendAttempt.id).filter(
SendAttempt.job_id == CampaignJob.id,
SendAttempt.status.in_(("smtp_accepted", "smtp_accepted_with_refusals", "reconciled_smtp_accepted")),
).exists()
mail_attempted = session.query(SendAttempt.id).filter(SendAttempt.job_id == CampaignJob.id).exists()
rows = session.query(
CampaignJob.send_status, CampaignJob.queue_status,
CampaignJob.imap_status, CampaignJob.delivery_channel_policy,
CampaignJob.validation_status, accepted_attempt, mail_attempted, func.count(CampaignJob.id),
).filter(
CampaignJob.tenant_id == tenant_id,
CampaignJob.campaign_id == campaign.id,
CampaignJob.campaign_version_id == version.id,
).group_by(
CampaignJob.send_status, CampaignJob.queue_status,
CampaignJob.imap_status, CampaignJob.delivery_channel_policy,
CampaignJob.validation_status, accepted_attempt, mail_attempted,
).all()
smtp = dict.fromkeys(("total", "processed", "accepted", "active", "pending", "failed", "outcome_unknown", "excluded", "paused", "cancelled"), 0)
imap = dict.fromkeys(("total", "processed", "appended", "active", "pending", "failed", "outcome_unknown", "excluded"), 0)
raw = {"send": Counter(), "queue": Counter(), "imap": Counter()}
total = 0
for send, queue, append, channel, validation, mail_accepted, attempted_mail, count in rows:
total += count
raw["send"][send] += count
raw["queue"][queue] += count
raw["imap"][append] += count
# Multi-channel jobs retain their channel policy. Pure Postbox/Print
# jobs and policy-excluded mail are not SMTP work.
fallback_completed = channel in {"mail_then_postbox", "postbox_then_mail", "mail_then_print"} and send in {"delivered", "sent", "postbox_accepted", "print_accepted"}
if channel not in {"mail", "mail_and_postbox", "mail_then_postbox", "postbox_then_mail", "mail_then_print"} or send == "skipped" or validation in {"excluded", "inactive"} or (fallback_completed and not attempted_mail and not mail_accepted):
smtp["excluded"] += count
else:
smtp["total"] += count
if mail_accepted or send == "smtp_accepted" or (channel == "mail" and send in {"sent", "delivered"}):
bucket = "accepted"
elif send in {"claimed", "sending"}:
bucket = "active"
elif send == "outcome_unknown" or (channel != "mail" and send in {"sent", "delivered"}):
bucket = "outcome_unknown"
elif send in {"failed_temporary", "failed_permanent", "partially_accepted", "postbox_accepted", "print_accepted"}:
bucket = "failed"
elif send == "cancelled" or queue == "cancelled":
bucket = "cancelled"
elif queue == "paused":
bucket = "paused"
else:
bucket = "pending"
smtp[bucket] += count
if append in {"not_requested", "skipped"}:
imap["excluded"] += count
else:
imap["total"] += count
bucket = {"appended": "appended", "appending": "active", "failed": "failed", "outcome_unknown": "outcome_unknown"}.get(append, "pending")
imap[bucket] += count
smtp["processed"] = sum(smtp[key] for key in ("accepted", "failed", "outcome_unknown", "cancelled"))
imap["processed"] = sum(imap[key] for key in ("appended", "failed", "outcome_unknown"))
return {
"campaign_id": campaign.id, "version_id": version.id,
"total_jobs": total, "generated_at": datetime.now(timezone.utc).isoformat(),
"smtp": smtp, "imap": imap,
"status_counts": {kind: dict(counts) for kind, counts in raw.items()},
"workflow_state": version.workflow_state,
"delivery_mode": version.delivery_mode,
}
@@ -0,0 +1,234 @@
"""Explicit, fenced recovery of claims left by a proven stopped runtime."""
from datetime import datetime, timezone
import hashlib
import json
from typing import Any
from sqlalchemy.orm import Session
from govoplan_core.core.runtime_coordination import (
DistributedLease, RuntimeNode, acquire_lease, release_lease, process_runtime_identity,
)
from govoplan_core.core.recovery import (
RecoveryOperation, RecoveryStatus, record_recovery_checkpoint,
transition_recovery_operation, verify_recovery_evidence_chain,
)
from govoplan_campaign.backend.db.models import CampaignJob, SendAttempt, ImapAppendAttempt
from govoplan_campaign.backend.sending.jobs import QueueingError, _update_campaign_after_job
class RecoveryStateConflict(QueueingError):
pass
def _utc(value: datetime) -> datetime:
return value.replace(tzinfo=timezone.utc) if value.tzinfo is None else value.astimezone(timezone.utc)
def _key(job: CampaignJob, channel: str) -> str:
return f"campaign:{'delivery' if channel == 'smtp' else 'imap'}:{job.tenant_id}:{job.id}"
def _claim_metadata(job: CampaignJob, channel: str, lease: DistributedLease | None, node: RuntimeNode | None) -> dict[str, Any]:
state = job.send_status if channel == "smtp" else job.imap_status
claim = job.claim_token if channel == "smtp" else job.imap_claim_token
active = state in ({"claimed", "sending"} if channel == "smtp" else {"appending"})
reason = "not_active"
if active:
if lease is None or not claim or not lease.holder_node_id or node is None:
reason = "owner_not_confirmed_stopped"
elif _utc(lease.expires_at) > datetime.now(timezone.utc):
reason = "live_claim"
elif node.incarnation == lease.holder_incarnation and node.state != "stopped":
# Heartbeat age alone is NOT proof that a slow worker is dead.
reason = "owner_not_confirmed_stopped"
else:
reason = "recoverable"
revision = hashlib.sha256(json.dumps({
"job": job.id, "channel": channel, "state": state, "claim": claim,
"attempts": job.attempt_count,
"lease": [lease.id, lease.fencing_token, str(lease.expires_at), lease.holder_node_id, lease.holder_incarnation] if lease else None,
"owner": [node.incarnation, node.state] if node else None,
}, sort_keys=True).encode()).hexdigest()
return {"eligible": reason == "recoverable", "revision": revision, "reason": reason}
def job_recovery_metadata(session: Session, jobs: list[CampaignJob]) -> dict[str, dict[str, Any]]:
"""Two bounded metadata reads per loaded page, not per recipient."""
if not jobs:
return {}
installation_id = process_runtime_identity().installation_id
keys = [_key(job, channel) for job in jobs for channel in ("smtp", "imap")]
leases = session.query(DistributedLease).filter(
DistributedLease.installation_id == installation_id,
DistributedLease.resource_key.in_(keys),
).all()
by_key = {lease.resource_key: lease for lease in leases}
owner_ids = {lease.holder_node_id for lease in leases if lease.holder_node_id}
nodes = session.query(RuntimeNode).filter(
RuntimeNode.installation_id == installation_id,
RuntimeNode.node_id.in_(owner_ids),
).all() if owner_ids else []
by_owner = {node.node_id: node for node in nodes}
result = {}
for job in jobs:
channels = {}
for channel in ("smtp", "imap"):
lease = by_key.get(_key(job, channel))
channels[channel] = _claim_metadata(job, channel, lease, by_owner.get(lease.holder_node_id) if lease else None)
result[job.id] = channels
return result
def recover_stale_delivery_claim(
session: Session, *, tenant_id: str, campaign_id: str, job_id: str,
channel: str, expected_revision: str, note: str,
) -> dict[str, Any]:
"""Freeze an abandoned effect as unknown; NEVER infer that it was not sent."""
if channel not in {"smtp", "imap"} or not note.strip():
raise QueueingError("Claim recovery requires a channel and an evidence note.")
job = session.get(CampaignJob, job_id)
if job is None or job.tenant_id != tenant_id or job.campaign_id != campaign_id:
raise QueueingError("Campaign job not found or not accessible")
identity = process_runtime_identity()
resource_key = _key(job, channel)
# Same lock order as runtime authority: lease, operation, domain row.
lease = session.query(DistributedLease).filter(
DistributedLease.installation_id == identity.installation_id,
DistributedLease.resource_key == resource_key,
).with_for_update().populate_existing().one_or_none()
node = session.query(RuntimeNode).filter(
RuntimeNode.installation_id == identity.installation_id,
RuntimeNode.node_id == lease.holder_node_id,
).with_for_update().populate_existing().one_or_none() if lease and lease.holder_node_id else None
session.refresh(job)
metadata = _claim_metadata(job, channel, lease, node)
if metadata["revision"] != expected_revision:
raise RecoveryStateConflict("Delivery claim changed; reload its current evidence before recovery.")
if not metadata["eligible"]:
raise RecoveryStateConflict("Recovery is blocked until the lease expires and its owning runtime is confirmed stopped or replaced.")
claim_token = job.claim_token if channel == "smtp" else job.imap_claim_token
state = job.send_status if channel == "smtp" else job.imap_status
assert claim_token is not None
claim_sha = hashlib.sha256(claim_token.encode()).hexdigest()
operation_key = f"campaign-{'delivery' if channel == 'smtp' else 'imap'}:{job.id}:{claim_sha[:32]}"
operation = session.query(RecoveryOperation).filter(
RecoveryOperation.installation_id == identity.installation_id,
RecoveryOperation.module_id == "campaigns",
RecoveryOperation.idempotency_key == operation_key,
RecoveryOperation.lease_resource_key == resource_key,
).with_for_update().one_or_none()
if operation is None or operation.status not in {"running", "outcome_unknown"}:
raise RecoveryStateConflict("The original durable delivery evidence cannot be recovered safely.")
authority = acquire_lease(
session, installation_id=identity.installation_id, resource_key=resource_key,
holder_node_id=identity.node_id, holder_incarnation=identity.incarnation,
ttl_seconds=300, metadata={"module_id": "campaigns", "recovery_operation_id": operation.id},
)
if authority is None:
raise RecoveryStateConflict("Another runtime acquired this delivery claim.")
operation.holder_node_id = authority.holder_node_id
operation.holder_incarnation = authority.holder_incarnation
operation.fencing_token = authority.fencing_token
session.add(operation)
session.flush()
evidence = {"job_id": job.id, "channel": channel, "previous_state": state, "evidence_note_sha256": hashlib.sha256(note.strip().encode()).hexdigest(), "claim_sha256": claim_sha}
record_recovery_checkpoint(session, operation, kind="campaign-claim-recovery", summary="An operator fenced a claim owned by a stopped runtime", evidence=evidence, lease_claim=authority)
if operation.status != "outcome_unknown":
transition_recovery_operation(session, operation, status=RecoveryStatus.OUTCOME_UNKNOWN, kind="campaign-claim-outcome-unknown", summary="The abandoned provider effect requires explicit reconciliation", evidence=evidence, failure_summary="The original runtime stopped before recording a final provider result", lease_claim=authority)
if not verify_recovery_evidence_chain(session, operation.id):
raise RecoveryStateConflict("Durable delivery evidence verification failed.")
state_column = CampaignJob.send_status if channel == "smtp" else CampaignJob.imap_status
claim_column = CampaignJob.claim_token if channel == "smtp" else CampaignJob.imap_claim_token
changes = {state_column: "outcome_unknown", claim_column: None, CampaignJob.last_error: note.strip()}
if channel == "smtp":
changes.update({CampaignJob.queue_status: "draft", CampaignJob.outcome_unknown_at: datetime.now(timezone.utc)})
else:
changes[CampaignJob.imap_claimed_at] = None
changed = session.query(CampaignJob).filter(
CampaignJob.id == job.id, state_column == state, claim_column == claim_token,
).update(changes, synchronize_session=False)
if changed != 1:
raise RecoveryStateConflict("The delivery claim changed before recovery could be recorded.")
attempt_model = SendAttempt if channel == "smtp" else ImapAppendAttempt
attempt = session.query(attempt_model).filter(attempt_model.job_id == job.id, attempt_model.claim_token == claim_token).order_by(attempt_model.attempt_number.desc()).first()
if attempt is not None:
attempt.status = "outcome_unknown"
attempt.error_message = note.strip()
if channel == "smtp":
attempt.finished_at = datetime.now(timezone.utc)
session.add(attempt)
release_lease(session, authority)
session.expire(job)
_update_campaign_after_job(session, campaign_id, job.campaign_version_id)
session.flush()
return {"campaign_id": campaign_id, "version_id": job.campaign_version_id, "job_id": job.id, "channel": channel, "send_status": job.send_status, "imap_status": job.imap_status, "note": note.strip(), "reconciliation_required": True}
def reconcile_campaign_delivery_operation(
session: Session, *, job: CampaignJob, channel: str, claim_token: str | None,
effect_occurred: bool, note: str,
) -> None:
"""Resolve only the original Campaign ledger in the caller's audit transaction.
Older jobs without a claim-bound operation remain supported. Mail's nested
provider-effect ledgers are separate evidence and are never rewritten here.
"""
# A compound external-channel operation may include Postbox/Print effects.
# One SMTP decision cannot verify or negate that entire operation.
if not claim_token or (channel == "smtp" and getattr(job, "delivery_channel_policy", "mail") != "mail"):
return
identity = process_runtime_identity()
key = _key(job, channel)
claim_sha = hashlib.sha256(claim_token.encode()).hexdigest()
operation_key = f"campaign-{'delivery' if channel == 'smtp' else 'imap'}:{job.id}:{claim_sha[:32]}"
# Acquire the same lock order as effect execution and claim recovery.
lease = session.query(DistributedLease).filter(
DistributedLease.installation_id == identity.installation_id,
DistributedLease.resource_key == key,
).with_for_update().populate_existing().one_or_none()
operation = session.query(RecoveryOperation).filter(
RecoveryOperation.installation_id == identity.installation_id,
RecoveryOperation.module_id == "campaigns",
RecoveryOperation.idempotency_key == operation_key,
RecoveryOperation.lease_resource_key == key,
RecoveryOperation.resource_type == "campaign_job",
RecoveryOperation.resource_id == job.id,
).with_for_update().populate_existing().one_or_none()
if operation is None:
return
if operation.status in {"succeeded", "recovered"}:
if (operation.status == "succeeded") != effect_occurred:
raise RecoveryStateConflict("The original durable operation already records a different verified outcome.")
return
if operation.status != "outcome_unknown" or lease is None:
raise RecoveryStateConflict("The original durable operation requires guarded claim recovery before reconciliation.")
# Even the same API process must not borrow another active operation's
# lease merely because its runtime identity happens to match.
if lease.holder_node_id is not None:
raise RecoveryStateConflict("The original operation still has a runtime owner; recover its stopped claim before reconciliation.")
authority = acquire_lease(session, installation_id=identity.installation_id, resource_key=key,
holder_node_id=identity.node_id, holder_incarnation=identity.incarnation,
ttl_seconds=300, metadata={"module_id": "campaigns", "recovery_operation_id": operation.id})
if authority is None:
raise RecoveryStateConflict("Another runtime owns the original delivery operation.")
operation.holder_node_id = authority.holder_node_id
operation.holder_incarnation = authority.holder_incarnation
operation.fencing_token = authority.fencing_token
session.add(operation)
session.flush()
evidence = {"verified": True, "checks": {"operator_provider_evidence_recorded": True, "matching_claim_attempt": True},
"job_id": job.id, "channel": channel, "effect_occurred": effect_occurred,
"claim_sha256": claim_sha, "evidence_note_sha256": hashlib.sha256(note.strip().encode()).hexdigest()}
record_recovery_checkpoint(session, operation, kind="campaign-reconciliation-fence", summary="An operator acquired authority for the original Campaign attempt", evidence=evidence, lease_claim=authority)
if effect_occurred:
transition_recovery_operation(session, operation, status=RecoveryStatus.SUCCEEDED,
kind="campaign-reconciled-provider-acceptance", summary="Operator evidence confirms the Campaign effect was accepted", evidence=evidence, lease_claim=authority)
else:
for next_status in (RecoveryStatus.RECOVERY_REQUIRED, RecoveryStatus.RECOVERING, RecoveryStatus.RECOVERED):
transition_recovery_operation(session, operation, status=next_status,
kind=f"campaign-reconciled-absence-{next_status.value}", summary="Operator evidence confirms the Campaign effect did not occur",
evidence=evidence, failure_summary="The original external effect was verified absent" if next_status == RecoveryStatus.RECOVERY_REQUIRED else None, lease_claim=authority)
if not verify_recovery_evidence_chain(session, operation.id):
raise RecoveryStateConflict("Original Campaign recovery evidence verification failed.")
release_lease(session, authority)
+23
View File
@@ -0,0 +1,23 @@
"""Deterministic collision naming shared by message and ZIP construction."""
from pathlib import Path
class FilenameAllocator:
"""Append-only names with the original first-free, casefolded suffix rule."""
def __init__(self) -> None:
self.used: set[str] = set()
self._next: dict[str, int] = {}
def allocate(self, filename: str) -> str:
key = filename.casefold()
candidate = filename
path = Path(filename)
counter = self._next.get(key, 2)
while candidate.casefold() in self.used:
candidate = f"{path.stem} ({counter}){path.suffix}"
counter += 1
self.used.add(candidate.casefold())
self._next[key] = counter
return candidate
@@ -1,11 +1,14 @@
from __future__ import annotations
from govoplan_campaign.backend.services.review_decisions import review_decision_metadata
from govoplan_campaign.backend.services.delivery_recovery import job_recovery_metadata
import json
from collections.abc import Mapping, Sequence
from typing import Literal
from fastapi import HTTPException, Query, status
from sqlalchemy import and_, func, or_
from sqlalchemy import String, and_, cast, func, or_
from sqlalchemy.orm import Session
from govoplan_campaign.backend.schemas import (
@@ -68,11 +71,38 @@ def _job_review_key(job: CampaignJob) -> str:
return str(job.entry_id or job.entry_index)
def _public_recipient_groups(value: object) -> dict[str, list[dict[str, str]]]:
"""Project only frozen recipient display fields, in their authored order.
The recipient-aware jobs endpoints enforce recipient-read before loading
these rows. Do not project other arbitrary data from the frozen envelope.
"""
recipients = value if isinstance(value, dict) else {}
groups: dict[str, list[dict[str, str]]] = {}
for group in ("to", "cc", "bcc"):
values = recipients.get(group)
entries = values if isinstance(values, list) else [values]
addresses: list[dict[str, str]] = []
for entry in entries:
if not isinstance(entry, dict) or not isinstance(entry.get("email"), str):
continue
email = entry["email"].strip()
if not email:
continue
address = {"email": email}
if isinstance(entry.get("name"), str) and entry["name"].strip():
address["name"] = entry["name"].strip()
addresses.append(address)
groups[group] = addresses
return groups
def _job_summary_payload(
job: CampaignJob,
*,
reviewed_keys: set[str] | None = None,
calendar_invitation: dict[str, object] | None = None,
recovery: dict[str, object] | None = None,
) -> dict[str, object]:
review_key = _job_review_key(job)
return {
@@ -81,6 +111,8 @@ def _job_summary_payload(
"entry_index": job.entry_index,
"entry_id": job.entry_id,
"recipient_email": job.recipient_email,
"resolved_recipients": _public_recipient_groups(getattr(job, "resolved_recipients", None)),
"recovery": recovery or {},
"subject": job.subject,
"message_id_header": job.message_id_header,
"build_status": job.build_status,
@@ -114,6 +146,7 @@ def _job_summary_payload(
"attachment_count": len(job.resolved_attachments or []),
"review_key": review_key,
"reviewed": review_key in reviewed_keys if reviewed_keys is not None else False,
"review_decision": review_decision_metadata(job),
"matched_file_count": sum(
len(item.get("matches") or [])
for item in (job.resolved_attachments or [])
@@ -128,9 +161,10 @@ def _job_detail_payload(
job: CampaignJob,
*,
calendar_invitation: dict[str, object] | None = None,
recovery: dict[str, object] | None = None,
) -> dict[str, object]:
return {
**_job_summary_payload(job, calendar_invitation=calendar_invitation),
**_job_summary_payload(job, calendar_invitation=calendar_invitation, recovery=recovery),
"message_id_header": job.message_id_header,
"issues": job.issues_snapshot or [],
"attachments": public_campaign_payload(job.resolved_attachments or []),
@@ -561,13 +595,13 @@ def _review_metadata_counts(
bulk_acceptable_count = 0
for entry_id, entry_index, build_status, validation_status in review_rows:
key = str(entry_id or entry_index)
if build_status != "built" or validation_status == "blocked":
if validation_status == "blocked" or (build_status != "built" and validation_status not in {"excluded", "inactive"}):
blocking_count += 1
if validation_status == "needs_review":
required_count += 1
if key in reviewed_keys:
reviewed_required_count += 1
elif validation_status in {"warning", "excluded"}:
elif validation_status == "warning":
bulk_acceptable_count += 1
return {
@@ -636,6 +670,22 @@ CAMPAIGN_JOB_GRID_LIST_FILTERS = {
}
def _campaign_recipient_search_expression(pattern: str):
return or_(
CampaignJob.recipient_email.ilike(pattern, escape="\\"),
CampaignJob.entry_id.ilike(pattern, escape="\\"),
*(
cast(CampaignJob.resolved_recipients[group], String).ilike(pattern, escape="\\")
for group in ("to", "cc", "bcc")
),
)
def _job_page_recovery_metadata(session: Session, jobs: list[CampaignJob]) -> dict[str, dict[str, object]]:
active = [job for job in jobs if job.send_status in {"claimed", "sending"} or job.imap_status == "appending"]
return job_recovery_metadata(session, active) if active else {}
def _campaign_jobs_grid_filter_expressions(
grid_filters: dict[str, str] | None,
) -> list[object]:
@@ -645,10 +695,7 @@ def _campaign_jobs_grid_filter_expressions(
if recipient:
pattern = _contains_pattern(recipient)
expressions.append(
or_(
CampaignJob.recipient_email.ilike(pattern, escape="\\"),
CampaignJob.entry_id.ilike(pattern, escape="\\"),
)
_campaign_recipient_search_expression(pattern)
)
subject = values.get("subject", "").strip()
if subject:
@@ -801,12 +848,11 @@ def _campaign_jobs_query_context(
if imap_status:
filtered.append(CampaignJob.imap_status.in_(imap_status))
if query_text and query_text.strip():
pattern = f"%{query_text.strip()}%"
pattern = _contains_pattern(query_text.strip())
filtered.append(
or_(
CampaignJob.recipient_email.ilike(pattern),
CampaignJob.subject.ilike(pattern),
CampaignJob.entry_id.ilike(pattern),
_campaign_recipient_search_expression(pattern),
CampaignJob.subject.ilike(pattern, escape="\\"),
)
)
filtered.extend(_campaign_jobs_grid_filter_expressions(grid_filters))
@@ -875,12 +921,14 @@ def _campaign_jobs_page_response(
if changed_job_ids is not None:
jobs = [job for job in jobs if job.id in changed_job_ids]
calendar_invitations = _calendar_invitations_for_jobs(session, jobs)
recovery = _job_page_recovery_metadata(session, jobs)
return CampaignJobsResponse(
jobs=[
_job_summary_payload(
job,
reviewed_keys=reviewed_keys,
calendar_invitation=calendar_invitations.get(job.id),
recovery=recovery.get(job.id),
)
for job in jobs
],
@@ -0,0 +1,28 @@
"""Shared, side-effect-free eligibility for individual and grouped review."""
from __future__ import annotations
import hashlib
import json
from typing import Any
def review_decision_metadata(job: Any) -> dict[str, Any]:
issues = [item for item in (job.issues_snapshot or []) if isinstance(item, dict)]
eligible = (
getattr(job, "build_status", "built") == "built"
and job.validation_status == "needs_review"
and not any(str(item.get("behavior") or "").lower() == "block" for item in issues)
)
reviewable = [item for item in issues if str(item.get("behavior") or "").lower() == "ask"]
evidence = reviewable or issues
categories = sorted({
(str(item.get("code") or ""), str(item.get("behavior") or ""), str(item.get("source") or ""))
for item in evidence
})
return {
"eligible": eligible,
"category_key": hashlib.sha256(json.dumps(categories, separators=(",", ":")).encode()).hexdigest() if eligible else "",
"reason_required": eligible and any(str(item.get("source") or "").startswith("attachments") for item in reviewable),
"issue_codes": sorted({str(item.get("code")) for item in evidence if item.get("code")}),
}
@@ -12,6 +12,8 @@ from pathlib import Path
from typing import Iterable
import zlib
from govoplan_campaign.backend.services.filenames import FilenameAllocator
try:
import pyzipper
except ImportError: # pragma: no cover
@@ -24,18 +26,11 @@ ZIP_METHOD_STANDARD = "zip_standard"
def _normalized_members(files: Iterable[Path | ArchiveMember]) -> list[ArchiveMember]:
members: list[ArchiveMember] = []
used_names: set[str] = set()
names = FilenameAllocator()
for item in files:
path, requested_name = item if isinstance(item, tuple) else (item, item.name)
requested = Path(requested_name).name or path.name
stem = Path(requested).stem
suffix = Path(requested).suffix
candidate = requested
counter = 2
while candidate.casefold() in used_names:
candidate = f"{stem} ({counter}){suffix}"
counter += 1
used_names.add(candidate.casefold())
candidate = names.allocate(requested)
members.append((path, candidate))
return members
@@ -0,0 +1,778 @@
from __future__ import annotations
from collections.abc import Mapping
from dataclasses import replace
from datetime import datetime
import hashlib
import json
from fastapi import HTTPException
from sqlalchemy.orm import Session
from govoplan_campaign.backend.db.models import (
Campaign,
CampaignVersion,
CampaignWorkAssignment,
)
from govoplan_campaign.backend.persistence.versions import create_minimal_campaign
from govoplan_campaign.backend.route_support import _get_campaign_for_principal
from govoplan_campaign.backend.routes.assignments import (
_actor_label,
_mirror_assignment_to_tasks,
_notify_assignment,
_record_event,
_require_resolved_assignee,
_resolve_assignee,
)
from govoplan_campaign.backend.schemas import CampaignWorkAssigneeInput
from govoplan_core.audit.logging import audit_from_principal
from govoplan_core.auth import ApiPrincipal, has_scope
from govoplan_core.core.automation import (
ActionDefinition,
ActionExecutionRequest,
ActionExecutionResult,
ActionPreview,
EffectDefinition,
EffectPreview,
ObservedEffect,
)
from govoplan_core.core.campaigns import (
CampaignWorkHandoffInspection,
CampaignWorkHandoffRef,
CampaignWorkHandoffRequest,
)
from govoplan_core.core.notifications import CAPABILITY_NOTIFICATIONS_DISPATCH
from govoplan_core.core.tasks import CAPABILITY_TASK_COMMANDS
from govoplan_core.security.time import utc_now
ACTION_KEY = "campaigns.work.prepare"
ASSIGNMENT_EFFECT = "campaigns.work.assignment_created"
CAMPAIGN_EFFECT = "campaigns.work.campaign_created"
class SqlCampaignWorkOrchestrationProvider:
"""Campaign-owned adapter used through optional Core capabilities only."""
def __init__(self, *, registry: object | None = None) -> None:
self._registry = registry
def action_definitions(self) -> tuple[ActionDefinition, ...]:
return (
ActionDefinition(
action_key=ACTION_KEY,
owner_module="campaigns",
description=(
"Reference or create a Campaign and open one authorization-neutral "
"accountable work hand-off."
),
input_schema_ref="govoplan/campaigns/work-handoff.v1",
required_scopes=(
"campaigns:campaign:read",
"campaigns:campaign:create",
"campaigns:assignment:manage",
),
policy_checks=(
"campaign access is checked independently of assignment",
"the assignee must already have Campaign access",
"the expected Campaign revision must still be current",
),
risk_level="moderate",
reversibility="compensatable",
expected_effect_keys=(ASSIGNMENT_EFFECT, CAMPAIGN_EFFECT),
idempotency_strategy="caller_supplied",
audit_event_types=(
"campaign.assignment.created",
"campaign.created_minimal",
),
preview_required=True,
recovery_mode="atomic",
recovery_verification=(
"resolve the assignment by tenant and orchestration idempotency key",
"verify the exact Campaign version and assignment revisions",
"confirm the assigned principal still has independent Campaign access",
),
),
)
def effect_definitions(self) -> tuple[EffectDefinition, ...]:
return (
EffectDefinition(
effect_key=ASSIGNMENT_EFFECT,
owner_module="campaigns",
operation="created",
description="Create an accountable Campaign work assignment.",
resource_types=("campaign_work_assignment",),
audit_event_types=("campaign.assignment.created",),
compensation_hint="Cancel the open assignment through Campaign work.",
),
EffectDefinition(
effect_key=CAMPAIGN_EFFECT,
owner_module="campaigns",
operation="created",
description="Create a minimal Campaign draft when no campaign is referenced.",
resource_types=("campaign", "campaign_version"),
audit_event_types=("campaign.created_minimal",),
compensation_hint=(
"Delete the untouched draft under the normal Campaign lifecycle policy."
),
),
)
def preview_action(
self,
session: object,
principal: object,
*,
request: ActionExecutionRequest,
) -> ActionPreview:
if request.action_key != ACTION_KEY:
return _blocked_preview("The Campaign work action is not supported.")
try:
sql_session, api_principal = _context(session, principal)
handoff = _request(request)
_preview_handoff(sql_session, api_principal, handoff)
except (HTTPException, TypeError, ValueError) as exc:
return _blocked_preview(_message(exc))
creating = handoff.campaign_id is None
effects = [
EffectPreview(
effect_key=ASSIGNMENT_EFFECT,
summary="Open one revision-bearing Campaign work assignment.",
)
]
if creating:
effects.insert(
0,
EffectPreview(
effect_key=CAMPAIGN_EFFECT,
summary="Create one minimal Campaign draft and initial version.",
),
)
return ActionPreview(
action_key=ACTION_KEY,
allowed=True,
summary=(
"Create a Campaign draft and open accountable work."
if creating
else "Reference the current Campaign revision and open accountable work."
),
risk_level="moderate",
reversibility="compensatable",
effects=tuple(effects),
policy_provenance=(
{
"code": "campaign_assignment_does_not_grant_access",
"assignment_authorization_neutral": True,
"campaign_access_rechecked_on_resume": True,
},
),
preview_ref=f"campaign-work-preview:{_request_hash(handoff)}",
)
def execute_action(
self,
session: object,
principal: object,
*,
request: ActionExecutionRequest,
) -> ActionExecutionResult:
if request.action_key != ACTION_KEY:
raise ValueError("The Campaign work action is not supported.")
sql_session, api_principal = _context(session, principal)
handoff = _request(request)
ref = self.prepare_handoff(
sql_session,
api_principal,
request=handoff,
)
effects = [
ObservedEffect(
effect_key=ASSIGNMENT_EFFECT,
operation="created",
resource_ref=ref.assignment_ref,
summary=(
"Reused the existing idempotent Campaign work assignment."
if ref.replayed
else "Created the Campaign work assignment."
),
metadata={"replayed": ref.replayed},
)
]
if not ref.replayed and handoff.campaign_id is None:
effects.insert(
0,
ObservedEffect(
effect_key=CAMPAIGN_EFFECT,
operation="created",
resource_ref=ref.campaign_ref,
summary="Created the minimal Campaign draft.",
),
)
return ActionExecutionResult(
state="completed",
output=_ref_payload(ref),
observed_effects=tuple(effects),
audit_event_refs=(
str(ref.provenance["audit_event_ref"]),
)
if ref.provenance.get("audit_event_ref")
else (),
)
def prepare_handoff(
self,
session: object,
principal: object,
*,
request: CampaignWorkHandoffRequest,
) -> CampaignWorkHandoffRef:
sql_session, api_principal = _context(session, principal)
if api_principal.tenant_id != request.tenant_id:
raise ValueError("Campaign hand-off tenant does not match the principal")
request_hash = _request_hash(request)
existing = (
sql_session.query(CampaignWorkAssignment)
.filter(
CampaignWorkAssignment.tenant_id == request.tenant_id,
CampaignWorkAssignment.orchestration_idempotency_key
== request.idempotency_key,
)
.one_or_none()
)
if existing is not None:
if existing.orchestration_request_sha256 != request_hash:
raise ValueError(
"Campaign hand-off idempotency key was already used for "
"different input."
)
campaign = _get_campaign_for_principal(
sql_session,
existing.campaign_id,
api_principal,
)
return _handoff_ref(
sql_session,
campaign=campaign,
assignment=existing,
registry=self._registry,
replayed=True,
)
campaign, version, created = _campaign_and_version(
sql_session,
api_principal,
request,
create=True,
)
resolution = _resolve_assignee(
sql_session,
campaign=campaign,
assignee=CampaignWorkAssigneeInput(
type=request.assignee_kind,
id=request.assignee_id,
),
)
_require_resolved_assignee(resolution)
now = utc_now()
assignment = CampaignWorkAssignment(
tenant_id=campaign.tenant_id,
campaign_id=campaign.id,
campaign_version_id=version.id,
reference_kind="campaign_version",
reference_id=version.id,
reference_label=f"Campaign version {version.version_number}",
purpose=request.purpose.strip(),
status="open",
due_at=request.due_at,
assignee_type=request.assignee_kind,
assignee_id=request.assignee_id.strip(),
assignee_label_snapshot=(resolution.label or request.assignee_id)[:500],
assignee_current_label=resolution.label,
assignee_resolution_state=resolution.state,
resolution_provenance={
**resolution.provenance,
"source": "workflow",
"workflow_instance_id": request.workflow_instance_id,
"workflow_step_id": request.workflow_step_id,
"expected_campaign_revision": request.expected_campaign_revision,
},
resolution_checked_at=now,
assigned_by_user_id=api_principal.user.id,
assigned_by_label_snapshot=_actor_label(api_principal),
orchestration_idempotency_key=request.idempotency_key,
orchestration_request_sha256=request_hash,
orchestration_correlation_id=request.correlation_id,
workflow_instance_id=request.workflow_instance_id,
workflow_step_id=request.workflow_step_id,
)
sql_session.add(assignment)
sql_session.flush()
_record_event(
sql_session,
assignment=assignment,
principal=api_principal,
event_kind="assigned",
details={
"source": "workflow",
"workflow_instance_id": request.workflow_instance_id,
"workflow_step_id": request.workflow_step_id,
},
)
if request.mirror_to_tasks:
_mirror_assignment_to_tasks(
sql_session,
campaign=campaign,
assignment=assignment,
principal=api_principal,
)
else:
assignment.task_mirror_status = "skipped"
_notify_assignment(
sql_session,
campaign=campaign,
assignment=assignment,
event_kind="assigned",
)
audit_ref = audit_from_principal(
sql_session,
api_principal,
action="campaign.assignment.created",
object_type="campaign_work_assignment",
object_id=assignment.id,
details={
"campaign_id": campaign.id,
"campaign_version_id": version.id,
"campaign_revision": version.edit_revision,
"resource_revision": assignment.resource_revision,
"source": "workflow",
"workflow_instance_id": request.workflow_instance_id,
"workflow_step_id": request.workflow_step_id,
"assignment_authorization_neutral": True,
"purpose_disclosed": False,
},
correlation_id=request.correlation_id,
causation_id=request.workflow_step_id,
commit=False,
)
if created:
audit_from_principal(
sql_session,
api_principal,
action="campaign.created_minimal",
object_type="campaign",
object_id=campaign.id,
details={
"version_id": version.id,
"external_id": campaign.external_id,
"source": "workflow",
"workflow_instance_id": request.workflow_instance_id,
},
correlation_id=request.correlation_id,
causation_id=request.workflow_step_id,
commit=False,
)
sql_session.flush()
ref = _handoff_ref(
sql_session,
campaign=campaign,
assignment=assignment,
registry=self._registry,
)
return replace(
ref,
provenance={**dict(ref.provenance), "audit_event_ref": audit_ref.id},
)
def inspect_handoff(
self,
session: object,
principal: object,
*,
tenant_id: str,
assignment_id: str,
expected_revision: int | None = None,
) -> CampaignWorkHandoffInspection:
try:
sql_session, api_principal = _context(session, principal)
except TypeError as exc:
return CampaignWorkHandoffInspection(allowed=False, reason=str(exc))
if api_principal.tenant_id != tenant_id:
return CampaignWorkHandoffInspection(
allowed=False,
reason="Campaign hand-off tenant does not match the principal.",
provenance={"code": "campaign_handoff_tenant_mismatch"},
)
assignment = sql_session.get(CampaignWorkAssignment, assignment_id)
if assignment is None or assignment.tenant_id != tenant_id:
return CampaignWorkHandoffInspection(
allowed=False,
reason="Campaign work assignment is unavailable.",
provenance={"code": "campaign_handoff_missing"},
)
try:
_get_campaign_for_principal(
sql_session,
assignment.campaign_id,
api_principal,
)
except HTTPException as exc:
return CampaignWorkHandoffInspection(
allowed=False,
status=assignment.status, # type: ignore[arg-type]
assignment_revision=assignment.resource_revision,
reason=_message(exc),
provenance={
"code": "campaign_handoff_access_revoked",
"campaign_id": assignment.campaign_id,
"assignment_does_not_grant_access": True,
},
)
if (
expected_revision is not None
and assignment.resource_revision != expected_revision
):
return CampaignWorkHandoffInspection(
allowed=False,
status=assignment.status, # type: ignore[arg-type]
assignment_revision=assignment.resource_revision,
action_url=_action_url(assignment),
assignment_ref=_assignment_ref(assignment),
reason="Campaign work assignment revision changed; reload its event.",
provenance={
"code": "campaign_handoff_revision_conflict",
"expected_revision": expected_revision,
"current_revision": assignment.resource_revision,
},
)
return CampaignWorkHandoffInspection(
allowed=True,
status=assignment.status, # type: ignore[arg-type]
assignment_revision=assignment.resource_revision,
action_url=_action_url(assignment),
assignment_ref=_assignment_ref(assignment),
provenance={
"code": "campaign_handoff_access_rechecked",
"campaign_id": assignment.campaign_id,
"assignment_does_not_grant_access": True,
},
)
def _context(
session: object,
principal: object,
) -> tuple[Session, ApiPrincipal]:
if not isinstance(session, Session):
raise TypeError("Campaign work orchestration requires a SQLAlchemy Session.")
if not isinstance(principal, ApiPrincipal):
raise TypeError("Campaign work orchestration requires an API principal.")
return session, principal
def _request(request: ActionExecutionRequest) -> CampaignWorkHandoffRequest:
value = request.input
assignee = value.get("assignee")
if not isinstance(assignee, Mapping):
raise ValueError("Campaign work hand-offs require an assignee object.")
create = value.get("create_campaign")
if create is not None and not isinstance(create, Mapping):
raise ValueError("Campaign creation input must be an object.")
due_at = _date(value.get("due_at"))
return CampaignWorkHandoffRequest(
tenant_id=request.tenant_id,
idempotency_key=request.idempotency_key,
purpose=str(value.get("purpose") or ""),
assignee_kind=str(assignee.get("kind") or ""), # type: ignore[arg-type]
assignee_id=str(assignee.get("id") or ""),
campaign_id=_optional(value.get("campaign_id")),
create_external_id=_optional(create.get("external_id")) if create else None,
create_name=_optional(create.get("name")) if create else None,
create_description=(
_optional(create.get("description")) if create else None
),
expected_campaign_revision=_integer(
value.get("expected_campaign_revision")
),
due_at=due_at,
mirror_to_tasks=bool(value.get("mirror_to_tasks", True)),
correlation_id=request.invocation.correlation_id,
workflow_instance_id=_reference_id(
request.metadata.get("workflow_instance_ref"),
"workflow-instance:",
),
workflow_step_id=_reference_id(
request.metadata.get("workflow_step_ref"),
"workflow-step:",
),
)
def _preview_handoff(
session: Session,
principal: ApiPrincipal,
request: CampaignWorkHandoffRequest,
) -> None:
if principal.tenant_id != request.tenant_id:
raise ValueError("Campaign hand-off tenant does not match the principal")
for scope in (
"campaigns:campaign:read",
"campaigns:campaign:create",
"campaigns:assignment:manage",
):
if not has_scope(principal, scope):
raise ValueError(f"Campaign work hand-off requires {scope}.")
existing = (
session.query(CampaignWorkAssignment)
.filter(
CampaignWorkAssignment.tenant_id == request.tenant_id,
CampaignWorkAssignment.orchestration_idempotency_key
== request.idempotency_key,
)
.one_or_none()
)
if existing is not None:
if existing.orchestration_request_sha256 != _request_hash(request):
raise ValueError(
"Campaign hand-off idempotency key was already used for different input."
)
_get_campaign_for_principal(session, existing.campaign_id, principal)
return
if request.campaign_id is None:
if request.assignee_kind != "account" or (
request.assignee_id != principal.account_id
):
raise ValueError(
"A newly created Campaign can initially be assigned only to its "
"creating account; share it explicitly before assigning other principals."
)
duplicate = (
session.query(Campaign.id)
.filter(
Campaign.tenant_id == request.tenant_id,
Campaign.external_id == request.create_external_id,
)
.first()
)
if duplicate is not None:
raise ValueError("Campaign external ID already exists for this tenant.")
if request.expected_campaign_revision not in {None, 1}:
raise ValueError("A new Campaign starts at revision one.")
return
campaign, _version, _created = _campaign_and_version(
session,
principal,
request,
create=False,
)
resolution = _resolve_assignee(
session,
campaign=campaign,
assignee=CampaignWorkAssigneeInput(
type=request.assignee_kind,
id=request.assignee_id,
),
)
_require_resolved_assignee(resolution)
def _campaign_and_version(
session: Session,
principal: ApiPrincipal,
request: CampaignWorkHandoffRequest,
*,
create: bool,
) -> tuple[Campaign, CampaignVersion, bool]:
if request.campaign_id is None:
if not create:
raise ValueError("Campaign creation is not available during preview.")
campaign, version = create_minimal_campaign(
session,
tenant_id=request.tenant_id,
user_id=principal.user.id,
external_id=str(request.create_external_id),
name=str(request.create_name),
description=request.create_description,
current_flow="create",
current_step="basics",
commit=False,
)
return campaign, version, True
campaign = _get_campaign_for_principal(
session,
request.campaign_id,
principal,
)
version = session.get(CampaignVersion, campaign.current_version_id)
if version is None or version.campaign_id != campaign.id:
raise ValueError("The Campaign current version is unavailable.")
if (
request.expected_campaign_revision is not None
and version.edit_revision != request.expected_campaign_revision
):
raise ValueError(
"Campaign revision changed; reload the Campaign before opening work."
)
return campaign, version, False
def _handoff_ref(
session: Session,
*,
campaign: Campaign,
assignment: CampaignWorkAssignment,
registry: object | None,
replayed: bool = False,
) -> CampaignWorkHandoffRef:
version = session.get(CampaignVersion, assignment.campaign_version_id)
if version is None or version.campaign_id != campaign.id:
raise ValueError("The pinned Campaign hand-off version is unavailable.")
return CampaignWorkHandoffRef(
tenant_id=assignment.tenant_id,
campaign_id=campaign.id,
campaign_version_id=version.id,
campaign_revision=version.edit_revision,
assignment_id=assignment.id,
assignment_revision=assignment.resource_revision,
status=assignment.status, # type: ignore[arg-type]
action_url=_action_url(assignment),
campaign_ref=(
f"campaign:{campaign.id}:version:{version.id}:r{version.edit_revision}"
),
assignment_ref=_assignment_ref(assignment),
replayed=replayed,
optional_capabilities={
"tasks": _has_capability(registry, CAPABILITY_TASK_COMMANDS),
"notifications": _has_capability(
registry,
CAPABILITY_NOTIFICATIONS_DISPATCH,
),
},
provenance={
"assignment_authorization_neutral": True,
"campaign_access_checked": True,
"workflow_instance_id": assignment.workflow_instance_id,
"workflow_step_id": assignment.workflow_step_id,
"correlation_id": assignment.orchestration_correlation_id,
},
)
def _ref_payload(ref: CampaignWorkHandoffRef) -> dict[str, object]:
return {
"campaign_id": ref.campaign_id,
"campaign_version_id": ref.campaign_version_id,
"campaign_revision": ref.campaign_revision,
"assignment_id": ref.assignment_id,
"assignment_revision": ref.assignment_revision,
"status": ref.status,
"action_url": ref.action_url,
"campaign_ref": ref.campaign_ref,
"assignment_ref": ref.assignment_ref,
"event_type": ref.event_type,
"replayed": ref.replayed,
"optional_capabilities": dict(ref.optional_capabilities),
"provenance": dict(ref.provenance),
"outcome": "success",
}
def _request_hash(request: CampaignWorkHandoffRequest) -> str:
payload = {
"tenant_id": request.tenant_id,
"purpose": request.purpose.strip(),
"assignee_kind": request.assignee_kind,
"assignee_id": request.assignee_id.strip(),
"campaign_id": request.campaign_id,
"create_external_id": request.create_external_id,
"create_name": request.create_name,
"create_description": request.create_description,
"expected_campaign_revision": request.expected_campaign_revision,
"due_at": request.due_at.isoformat() if request.due_at else None,
"mirror_to_tasks": request.mirror_to_tasks,
"correlation_id": request.correlation_id,
"workflow_instance_id": request.workflow_instance_id,
"workflow_step_id": request.workflow_step_id,
}
encoded = json.dumps(payload, sort_keys=True, separators=(",", ":"))
return hashlib.sha256(encoded.encode("utf-8")).hexdigest()
def _blocked_preview(reason: str) -> ActionPreview:
return ActionPreview(
action_key=ACTION_KEY,
allowed=False,
summary=reason,
risk_level="moderate",
reversibility="compensatable",
blockers=(reason,),
policy_provenance=(
{
"code": "campaign_work_handoff_blocked",
"reason": reason,
},
),
)
def _message(exc: Exception) -> str:
if isinstance(exc, HTTPException):
detail = exc.detail
if isinstance(detail, Mapping):
return str(detail.get("explanation") or detail.get("code") or detail)
return str(detail)
return str(exc)
def _date(value: object) -> datetime | None:
if value is None or value == "":
return None
if isinstance(value, datetime):
return value
try:
return datetime.fromisoformat(str(value).replace("Z", "+00:00"))
except ValueError as exc:
raise ValueError("Campaign hand-off due date must use ISO 8601.") from exc
def _integer(value: object) -> int | None:
if value is None or value == "":
return None
if isinstance(value, bool):
raise ValueError("Campaign revisions must be integers.")
try:
return int(value)
except (TypeError, ValueError) as exc:
raise ValueError("Campaign revisions must be integers.") from exc
def _optional(value: object) -> str | None:
candidate = str(value or "").strip()
return candidate or None
def _reference_id(value: object, prefix: str) -> str | None:
candidate = str(value or "").strip()
return candidate.removeprefix(prefix) or None if candidate.startswith(prefix) else None
def _assignment_ref(assignment: CampaignWorkAssignment) -> str:
return f"campaign-work-assignment:{assignment.id}:r{assignment.resource_revision}"
def _action_url(assignment: CampaignWorkAssignment) -> str:
return (
f"/campaigns/{assignment.campaign_id}/work"
f"?assignment={assignment.id}"
)
def _has_capability(registry: object | None, name: str) -> bool:
return bool(
registry is not None
and hasattr(registry, "has_capability")
and registry.has_capability(name)
)
__all__ = ["ACTION_KEY", "SqlCampaignWorkOrchestrationProvider"]
@@ -0,0 +1,205 @@
from __future__ import annotations
from govoplan_core.core.campaigns import CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION
from govoplan_core.core.workflows import WorkflowDefinitionContribution
def campaign_workflow_definitions(
*,
module_version: str,
) -> tuple[WorkflowDefinitionContribution, ...]:
"""Return opt-in Campaign workflow templates owned by this module."""
return (
WorkflowDefinitionContribution(
origin_module_id="campaigns",
origin_module_version=module_version,
definition_key="accountable-campaign-work-handoff",
name="Accountable Campaign work hand-off",
description=(
"Create or reference a Campaign, assign bounded work, and wait "
"for its revision-bearing completion, rejection, cancellation, "
"or timeout event."
),
graph=_campaign_work_handoff_graph(),
definition_kind="template",
scope_type="system",
inherit_to_lower_scopes=True,
allow_start=True,
allow_reuse=True,
allow_automation=False,
execution_mode="guided",
activate_on_install=False,
required_capabilities=(CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION,),
required_interfaces=("campaigns.work_orchestration",),
metadata={
"domain": "campaigns.accountable_work",
"state_owner": "campaigns",
"template_requires_configuration": True,
},
policy_metadata={
"assignment_authorization_neutral": True,
"campaign_access_rechecked_on_resume": True,
"navigation_does_not_complete_work": True,
},
),
)
def _campaign_work_handoff_graph() -> dict[str, object]:
return {
"schema_version": 1,
"nodes": [
{
"id": "start",
"type": "workflow.start.manual",
"label": "Campaign work requested",
"position": {"x": 20, "y": 140},
"config": {
"input_schema_ref": "govoplan/campaigns/work-handoff.v1",
},
},
{
"id": "prepare",
"type": "workflow.capability",
"label": "Prepare Campaign work",
"position": {"x": 250, "y": 140},
"config": {
"capability": CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION,
"operation": "campaigns.work.prepare",
"input_mapping": {
"campaign_id": "$input.campaign_id",
"create_campaign": "$input.create_campaign",
"expected_campaign_revision": (
"$input.expected_campaign_revision"
),
"purpose": "$input.purpose",
"assignee": "$input.assignee",
"due_at": "$input.due_at",
"mirror_to_tasks": "$input.mirror_to_tasks",
},
"idempotency_key": "workflow-step",
"failure_policy": "manual",
"view_surface_ids": ["campaigns.page.work"],
},
},
{
"id": "campaign_work",
"type": "workflow.external_handoff",
"label": "Complete Campaign work",
"position": {"x": 510, "y": 140},
"config": {
"provider_capability": (
CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION
),
"event_type": "campaign.work.changed",
"event_filter": {
"payload": {
"assignment_id": (
"$steps.prepare.execution.output.assignment_id"
)
}
},
"outcome_path": "payload.outcome",
"terminal_outcomes": {
"completed": "completed",
"rejected": "rejected",
"cancelled": "cancelled",
},
"observed_outcomes": [
"assigned",
"accepted",
"started",
"reassigned",
],
"external_id": (
"$steps.prepare.execution.output.assignment_id"
),
"expected_revision": (
"$steps.prepare.execution.output.assignment_revision"
),
"action_url": "$steps.prepare.execution.output.action_url",
"immutable_ref": (
"$steps.prepare.execution.output.assignment_ref"
),
"optional_capabilities": (
"$steps.prepare.execution.output.optional_capabilities"
),
"timeout_after": "$input.timeout_after",
"view_surface_ids": ["campaigns.page.work"],
},
},
{
"id": "completed",
"type": "workflow.end.completed",
"label": "Campaign work completed",
"position": {"x": 790, "y": 20},
"config": {"output_mapping": {}},
},
{
"id": "rejected",
"type": "workflow.end.cancelled",
"label": "Campaign work rejected",
"position": {"x": 790, "y": 120},
"config": {"reason": "Campaign work was rejected"},
},
{
"id": "cancelled",
"type": "workflow.end.cancelled",
"label": "Campaign work cancelled",
"position": {"x": 790, "y": 220},
"config": {"reason": "Campaign work was cancelled"},
},
{
"id": "timed_out",
"type": "workflow.end.cancelled",
"label": "Campaign work timed out",
"position": {"x": 790, "y": 320},
"config": {"reason": "Campaign work timed out"},
},
],
"edges": [
{"id": "start-prepare", "source": "start", "target": "prepare"},
{
"id": "prepare-work",
"source": "prepare",
"source_port": "success",
"target": "campaign_work",
},
{
"id": "work-completed",
"source": "campaign_work",
"source_port": "completed",
"target": "completed",
},
{
"id": "work-rejected",
"source": "campaign_work",
"source_port": "rejected",
"target": "rejected",
},
{
"id": "work-cancelled",
"source": "campaign_work",
"source_port": "cancelled",
"target": "cancelled",
},
{
"id": "work-timeout",
"source": "campaign_work",
"source_port": "timed_out",
"target": "timed_out",
},
],
"metadata": {
"notation": "govoplan.workflow.native",
"domain": "campaigns.accountable_work",
"configuration_notes": (
"Provide either campaign_id or create_campaign and explicit null "
"values for unused optional inputs."
),
},
}
__all__ = ["campaign_workflow_definitions"]
+37 -2
View File
@@ -159,9 +159,9 @@ class CampaignAttachmentBuildTests(unittest.TestCase):
cases = {
"block": ("build_failed", "blocked", 0, "block", False),
"ask": ("built", "needs_review", 0, "ask", True),
"drop": ("built", "needs_review", 0, "ask", True),
"drop": ("built", "excluded", 0, "drop", True),
"warn": ("built", "warning", 1, "warn", True),
"continue": ("built", "warning", 1, None, True),
"continue": ("built", "ready", 1, None, True),
}
for behavior, (build_status, validation_status, queueable_count, issue_behavior, has_mime) in cases.items():
with self.subTest(behavior=behavior):
@@ -257,6 +257,41 @@ class CampaignAttachmentBuildTests(unittest.TestCase):
)
self.assertEqual(issue.behavior, "warn")
def test_explicit_optional_empty_rule_is_information_unless_hard_blocked(self) -> None:
for policy, expected in (("warn", "ready"), ("ask", "ready"), ("block", "blocked")):
with self.subTest(policy=policy), tempfile.TemporaryDirectory() as tmp:
root = Path(tmp)
campaign_file = root / "campaign.json"
campaign_file.write_text("{}", encoding="utf-8")
config = self._no_attachment_config(behavior="continue", configure_missing_rule=True)
config.validation_policy.missing_optional_attachment = policy
result = build_campaign_messages(config, campaign_file=campaign_file, output_dir=root / "out", write_eml=True)
message = result.report.messages[0]
self.assertEqual(message.validation_status.value, expected)
issue = next(item for item in message.issues if item.code == "missing_optional_attachment")
self.assertEqual(issue.behavior, "block" if policy == "block" else "continue")
self.assertEqual(issue.severity, "error" if policy == "block" else "info")
self.assertEqual(message.attachments[0].matches, [])
def test_deliberate_rule_drop_is_excluded_but_cannot_override_required_block(self) -> None:
for required, expected in ((False, "excluded"), (True, "blocked")):
with self.subTest(required=required), tempfile.TemporaryDirectory() as tmp:
root = Path(tmp)
campaign_file = root / "campaign.json"
campaign_file.write_text("{}", encoding="utf-8")
config = self._no_attachment_config(behavior="continue", configure_missing_rule=True)
rule = config.attachments.global_[0]
rule.missing_behavior = "drop"
rule.required = required
result = build_campaign_messages(config, campaign_file=campaign_file, output_dir=root / "out", write_eml=True)
message = result.report.messages[0]
self.assertEqual(message.validation_status.value, expected)
self.assertEqual(result.report.queueable_count, 0)
if not required:
self.assertEqual(message.send_status.value, "skipped")
self.assertEqual(message.imap_status.value, "skipped")
self.assertEqual(message.issues[0].behavior, "drop")
def test_missing_pattern_does_not_create_zip_member_or_count_as_attachment(self) -> None:
with tempfile.TemporaryDirectory() as tmp:
root = Path(tmp)
+61
View File
@@ -0,0 +1,61 @@
from __future__ import annotations
import subprocess
import sys
import unittest
from pathlib import Path
_IMPORT_PROGRAM = """
import importlib
import socket
import sys
sys.path.insert(0, sys.argv[1])
def deny_network(*args, **kwargs):
raise AssertionError("Campaign imports must not connect to external services")
class NoNetworkSocket(socket.socket):
connect = deny_network
connect_ex = deny_network
socket.create_connection = deny_network
socket.socket = NoNetworkSocket
importlib.import_module(sys.argv[2])
from govoplan_campaign.backend.campaign import (
CampaignConfig, SemanticIssue, SemanticReport,
load_campaign_config, load_campaign_json, validate_campaign_config,
)
from govoplan_campaign.backend.attachments.resolver import resolve_campaign_attachments
assert all(callable(value) for value in (
CampaignConfig, SemanticIssue, SemanticReport,
load_campaign_config, load_campaign_json, validate_campaign_config,
resolve_campaign_attachments,
))
"""
class CampaignImportOrderTests(unittest.TestCase):
def test_model_validation_and_attachment_entry_points_import_independently(self):
source_root = Path(__file__).resolve().parents[1] / "src"
for first_module in (
"govoplan_campaign.backend.attachments.resolver",
"govoplan_campaign.backend.campaign.validation",
"govoplan_campaign.backend.campaign.entries",
):
with self.subTest(first_module=first_module):
completed = subprocess.run(
[sys.executable, "-I", "-c", _IMPORT_PROGRAM, str(source_root), first_module],
capture_output=True,
text=True,
check=False,
timeout=30,
)
self.assertEqual(0, completed.returncode, completed.stderr or completed.stdout)
if __name__ == "__main__":
unittest.main()
@@ -160,6 +160,42 @@ class CampaignOptimisticConcurrencyTests(unittest.TestCase):
assert current is not None
self.assertEqual(current.raw_json["campaign"]["name"], "First writer")
def test_metadata_save_does_not_erase_recorded_review(self) -> None:
review = {
"build_token": "server-build-token",
"inspection_complete": True,
"reviewed_message_keys": ["recipient-1"],
"issue_decisions": [],
"updated_at": "2026-07-21T00:00:00+00:00",
"updated_by_user_id": "reviewer-1",
}
with self.SessionLocal() as session:
version = session.get(CampaignVersion, "version-1")
assert version is not None
version.editor_state = {
"created_from": "minimal_campaign",
"review_send": review,
}
session.commit()
saved = update_campaign_version(
session,
tenant_id="tenant-1",
campaign_id="campaign-1",
version_id="version-1",
editor_state={"opt_ins": {"inline_guidance": False}},
expected_revision=version.edit_revision,
autosave=True,
)
self.assertEqual(saved.editor_state["review_send"], review)
with self.SessionLocal() as verification:
current = verification.get(CampaignVersion, "version-1")
assert current is not None
self.assertEqual(current.editor_state, {
"opt_ins": {"inline_guidance": False},
"review_send": review,
})
if __name__ == "__main__":
unittest.main()
+528
View File
@@ -0,0 +1,528 @@
from __future__ import annotations
import copy
from types import SimpleNamespace
from unittest.mock import patch
import pytest
from fastapi import HTTPException
from sqlalchemy import Column, String, Table, create_engine
from sqlalchemy.orm import Session, sessionmaker
from govoplan_campaign.backend.campaign.transfers import (
DEFAULT_PORTABLE_CAMPAIGN_SCOPES,
build_campaign_portable_package,
canonical_sha256,
inspect_campaign_portable_package,
)
from govoplan_campaign.backend.db.models import (
Campaign,
CampaignIssue,
CampaignJob,
CampaignShare,
CampaignVersion,
)
from govoplan_campaign.backend.persistence.versions import minimal_campaign_json
from govoplan_campaign.backend.routes.transfers import (
export_campaign_package,
import_campaign_package,
preview_campaign_import,
)
from govoplan_campaign.backend.schemas import (
CampaignExportRequest,
CampaignImportApplyRequest,
CampaignImportPreviewRequest,
CampaignPortablePackageResponse,
)
from govoplan_core.core.change_sequence import ChangeSequenceEntry
from govoplan_core.db.base import Base
def _source() -> tuple[Campaign, CampaignVersion]:
raw_json = minimal_campaign_json(
external_id="monthly-notice",
name="Monthly notice",
description="Portable source",
)
raw_json["fields"] = [
{"name": "case_id", "type": "string"},
{"name": "private_code", "type": "password"},
]
raw_json["global_values"] = {
"office": "Permits",
"private_code": "must-not-leave-the-source",
}
raw_json["server"] = {
"mail_profile_id": "mail-profile-source",
"smtp_server_id": "smtp-source",
"smtp_credential_id": "credential-source",
}
raw_json["template"] = {
"subject": "Case {{case_id}}",
"text": "Hello",
"html": None,
}
raw_json["attachments"]["global"] = [
{"base_dir": ".", "file_filter": "notice.pdf", "required": True}
]
raw_json["entries"]["inline"] = [
{
"id": "recipient-1",
"to": [{"email": "person@example.test"}],
"fields": {
"case_id": "A-1",
"private_code": "recipient-secret",
},
"attachments": [
{"base_dir": ".", "file_filter": "A-1.pdf", "required": True}
],
}
]
campaign = Campaign(
id="campaign-source",
tenant_id="tenant-source",
external_id="monthly-notice",
name="Monthly notice",
description="Portable source",
status="completed",
settings={
"retention_days": 90,
"provider_token": "must-not-export",
},
mail_profile_policy={
"profile_id": "mail-profile-source",
"credential_id": "credential-source",
},
)
version = CampaignVersion(
id="version-source",
campaign_id=campaign.id,
version_number=4,
raw_json=raw_json,
schema_version="1.0",
workflow_state="completed",
validation_summary={"ok": True, "error_count": 0},
build_summary={"built_count": 1},
editor_state={
"review_send": {
"inspection_complete": True,
"reviewed_message_keys": ["message-1"],
"issue_decisions": [
{
"decision": "accept",
"issue_codes": ["attachment_warning"],
"issue_fingerprint": "fingerprint-1",
"message_sha256": "a" * 64,
"reason": "Verified manually",
}
],
}
},
)
return campaign, version
def _job(campaign: Campaign, version: CampaignVersion) -> CampaignJob:
return CampaignJob(
id="job-1",
tenant_id=campaign.tenant_id,
campaign_id=campaign.id,
campaign_version_id=version.id,
entry_index=0,
entry_id="recipient-1",
recipient_email="person@example.test",
message_id_header="<message@example.test>",
eml_sha256="b" * 64,
build_status="built",
validation_status="ready",
queue_status="cancelled",
send_status="smtp_accepted",
postbox_status="not_requested",
print_status="not_requested",
imap_status="appended",
attempt_count=1,
delivery_provenance={"route": "mail", "storage_key": "hidden"},
)
def test_privacy_default_export_is_configuration_only_and_redacts_secrets() -> None:
campaign, version = _source()
package = build_campaign_portable_package(
campaign=campaign,
version=version,
scopes=DEFAULT_PORTABLE_CAMPAIGN_SCOPES,
module_version="0.1.24",
)
assert package["scopes"] == ["metadata", "template_config"]
assert set(package["payload"]) == {"metadata", "template_config"}
assert package["manifest"]["secrets_included"] is False
assert package["manifest"]["redactions"] == {
"deployment_credential_reference": 1,
"password_field_value": 2,
"sensitive_setting": 2,
}
template = package["payload"]["template_config"]
assert "private_code" not in template["configuration"]["global_values"]
assert "smtp_credential_id" not in template["configuration"]["server"]
assert "provider_token" not in template["campaign_settings"]
assert "credential_id" not in template["mail_profile_policy"]
serialized = CampaignPortablePackageResponse.model_validate(package).model_dump(
mode="json"
)
assert inspect_campaign_portable_package(
serialized,
selected_scopes=None,
external_id="serialized-import",
name="Serialized import",
).preview["compatible"] is True
def test_full_export_import_applies_configuration_but_never_replays_evidence() -> None:
campaign, version = _source()
package = build_campaign_portable_package(
campaign=campaign,
version=version,
scopes=(
"metadata",
"template_config",
"recipients",
"attachments",
"review_state",
"delivery_history",
),
jobs=(_job(campaign, version),),
issues=(
CampaignIssue(
id="issue-1",
tenant_id=campaign.tenant_id,
campaign_id=campaign.id,
campaign_version_id=version.id,
severity="warning",
code="attachment_warning",
message="Review attachment",
),
),
module_version="0.1.24",
)
inspection = inspect_campaign_portable_package(
package,
selected_scopes=None,
external_id="monthly-notice-import",
name="Imported monthly notice",
)
assert inspection.preview["compatible"] is True
assert inspection.configuration is not None
assert inspection.configuration["campaign"] == {
"id": "monthly-notice-import",
"name": "Imported monthly notice",
"description": "Portable source",
"mode": "draft",
}
assert inspection.configuration["server"] == {}
assert inspection.configuration["entries"]["inline"][0]["to"] == [
{"email": "person@example.test"}
]
assert inspection.configuration["entries"]["inline"][0]["attachments"][0][
"file_filter"
] == "A-1.pdf"
assert "private_code" not in inspection.configuration["entries"]["inline"][0][
"fields"
]
skipped_codes = {item["code"] for item in inspection.preview["will_skip"]}
assert skipped_codes == {
"deployment_bound_mail_profile",
"operational_evidence_not_replayed",
}
assert package["payload"]["review_state"]["decision_count"] == 1
assert package["payload"]["delivery_history"]["jobs"][0][
"recipient_email"
] == "person@example.test"
assert "storage_key" not in package["payload"]["delivery_history"]["jobs"][0][
"delivery_provenance"
]
def test_import_preview_reports_unselected_recipient_attachment_rules() -> None:
campaign, version = _source()
package = build_campaign_portable_package(
campaign=campaign,
version=version,
scopes=("metadata", "attachments", "recipients"),
module_version="0.1.24",
)
inspection = inspect_campaign_portable_package(
package,
selected_scopes=("metadata", "attachments"),
external_id="attachment-import",
name="Attachment import",
)
assert inspection.preview["compatible"] is True
skipped = {item["code"]: item for item in inspection.preview["will_skip"]}
assert skipped["recipient_scope_required"]["item_count"] == 1
assert skipped["scope_not_selected"]["scope"] == "recipients"
assert inspection.configuration is not None
assert inspection.configuration["entries"]["inline"] == []
def test_import_preview_fails_closed_when_package_is_tampered() -> None:
campaign, version = _source()
package = build_campaign_portable_package(
campaign=campaign,
version=version,
scopes=DEFAULT_PORTABLE_CAMPAIGN_SCOPES,
module_version="0.1.24",
)
tampered = copy.deepcopy(package)
tampered["payload"]["metadata"]["name"] = "Tampered"
inspection = inspect_campaign_portable_package(
tampered,
selected_scopes=None,
external_id="tampered-import",
name="Tampered",
)
assert inspection.preview["compatible"] is False
assert inspection.configuration is None
assert any("integrity checksum" in error for error in inspection.preview["errors"])
def test_import_preview_rejects_unsupported_campaign_schema_even_with_valid_checksum() -> None:
campaign, version = _source()
package = build_campaign_portable_package(
campaign=campaign,
version=version,
scopes=DEFAULT_PORTABLE_CAMPAIGN_SCOPES,
module_version="0.1.24",
)
package["source"]["campaign_schema_version"] = "2.0"
package["integrity"]["package_sha256"] = canonical_package_hash(package)
inspection = inspect_campaign_portable_package(
package,
selected_scopes=None,
external_id="future-import",
name="Future import",
)
assert inspection.preview["compatible"] is False
assert any("schema version" in error for error in inspection.preview["errors"])
def canonical_package_hash(package: dict[str, object]) -> str:
content = copy.deepcopy(package)
content.pop("integrity", None)
return canonical_sha256(content)
class _Principal:
tenant_id = "tenant-1"
api_key = None
def __init__(self, *scopes: str) -> None:
self.user = SimpleNamespace(id="user-1", display_name="Importer")
self.scopes = frozenset(scopes)
def has(self, scope: str) -> bool:
return scope in self.scopes or "tenant:*" in self.scopes
@pytest.fixture()
def route_session() -> Session:
engine = create_engine("sqlite+pysqlite:///:memory:")
access_users = Base.metadata.tables.get("access_users")
if access_users is None:
access_users = Table(
"access_users",
Base.metadata,
Column("id", String(36), primary_key=True),
)
access_groups = Base.metadata.tables.get("access_groups")
if access_groups is None:
access_groups = Table(
"access_groups",
Base.metadata,
Column("id", String(36), primary_key=True),
)
Base.metadata.create_all(
engine,
tables=[
access_users,
access_groups,
Campaign.__table__,
CampaignVersion.__table__,
CampaignShare.__table__,
CampaignJob.__table__,
CampaignIssue.__table__,
ChangeSequenceEntry.__table__,
],
)
session_factory = sessionmaker(bind=engine, class_=Session, expire_on_commit=False)
database = session_factory()
user_values = {"id": "user-1"}
if "tenant_id" in access_users.c:
user_values.update(
tenant_id="tenant-1",
account_id="account-1",
email="user-1@example.test",
)
database.execute(access_users.insert().values(**user_values))
raw_json = minimal_campaign_json(external_id="source", name="Source")
raw_json["entries"]["inline"] = [
{"id": "one", "to": [{"email": "one@example.test"}]}
]
source = Campaign(
id="source-campaign",
tenant_id="tenant-1",
created_by_user_id="user-1",
owner_user_id="user-1",
external_id="source",
name="Source",
status="draft",
current_version_id="source-version",
)
source_version = CampaignVersion(
id="source-version",
campaign_id=source.id,
version_number=1,
raw_json=raw_json,
)
database.add_all((source, source_version))
database.commit()
try:
yield database
finally:
database.close()
engine.dispose()
def test_export_route_enforces_recipient_export_scope(route_session: Session) -> None:
principal = _Principal(
"campaigns:campaign:read",
"campaigns:campaign:export",
"campaigns:recipient:read",
)
with pytest.raises(HTTPException) as denied:
export_campaign_package(
"source-campaign",
"source-version",
CampaignExportRequest(scopes=["metadata", "recipients"]),
session=route_session,
principal=principal,
)
assert denied.value.status_code == 403
assert denied.value.detail == "Missing scope: campaigns:recipient:export"
def test_export_preview_and_apply_routes_keep_matching_provenance(
route_session: Session,
) -> None:
exporter = _Principal(
"campaigns:campaign:read",
"campaigns:campaign:export",
"campaigns:recipient:read",
"campaigns:recipient:export",
)
def commit_audit(active_session: Session, *_args, **_kwargs) -> None:
active_session.commit()
with patch(
"govoplan_campaign.backend.routes.transfers.audit_from_principal",
side_effect=commit_audit,
):
package = export_campaign_package(
"source-campaign",
"source-version",
CampaignExportRequest(scopes=["metadata", "template_config", "recipients"]),
session=route_session,
principal=exporter,
)
limited_importer = _Principal(
"campaigns:campaign:create",
"campaigns:campaign:import",
)
limited_preview = preview_campaign_import(
CampaignImportPreviewRequest(package=package),
session=route_session,
principal=limited_importer,
)
assert limited_preview["compatible"] is True
assert "recipients" in limited_preview["selected_scopes"]
importer = _Principal(
"campaigns:campaign:create",
"campaigns:campaign:import",
"campaigns:recipient:write",
"campaigns:recipient:import",
)
preview = preview_campaign_import(
CampaignImportPreviewRequest(package=package),
session=route_session,
principal=importer,
)
assert preview["compatible"] is True
assert preview["destination"]["external_id"] == "source-import"
def create_import(active_session: Session, **kwargs):
raw_json = kwargs["raw_json"]
destination = Campaign(
id="imported-campaign",
tenant_id="tenant-1",
created_by_user_id="user-1",
owner_user_id="user-1",
external_id=raw_json["campaign"]["id"],
name=raw_json["campaign"]["name"],
status="draft",
current_version_id="imported-version",
)
version = CampaignVersion(
id="imported-version",
campaign_id=destination.id,
version_number=1,
raw_json=raw_json,
)
active_session.add_all((destination, version))
active_session.flush()
return destination, version
with (
patch(
"govoplan_campaign.backend.routes.transfers.create_campaign_version_from_json",
side_effect=create_import,
),
patch(
"govoplan_campaign.backend.routes.transfers.audit_from_principal",
side_effect=commit_audit,
),
patch(
"govoplan_campaign.backend.routes.transfers._write_current_version_snapshot_if_available"
),
):
response = import_campaign_package(
CampaignImportApplyRequest(
package=package,
selected_scopes=preview["selected_scopes"],
external_id=preview["destination"]["external_id"],
name=preview["destination"]["name"],
expected_package_sha256=preview["package_sha256"],
),
session=route_session,
principal=importer,
)
assert response.campaign.external_id == "source-import"
assert response.receipt["package_id"] == package["package_id"]
assert response.receipt["package_sha256"] == package["integrity"]["package_sha256"]
imported = route_session.get(Campaign, "imported-campaign")
assert imported is not None
assert imported.settings["portable_import"]["package_id"] == package["package_id"]
assert route_session.query(CampaignJob).filter_by(campaign_id=imported.id).count() == 0
+261 -2
View File
@@ -32,8 +32,14 @@ from govoplan_campaign.backend.schemas import (
CampaignWorkAssignmentReassignRequest,
CampaignWorkAssignmentTransitionRequest,
)
from govoplan_core.core.access import GroupRef, UserRef
from govoplan_campaign.backend.work_orchestration import (
SqlCampaignWorkOrchestrationProvider,
)
from govoplan_core.auth import ApiPrincipal
from govoplan_core.core.access import GroupRef, PrincipalRef, UserRef
from govoplan_core.core.campaigns import CampaignWorkHandoffRequest
from govoplan_core.core.change_sequence import ChangeSequenceEntry
from govoplan_core.core.events import EventBus, event_bus_context
from govoplan_core.core.organizations import OrganizationFunctionRef
from govoplan_core.core.tasks import WorkItem
from govoplan_core.db.base import Base
@@ -257,6 +263,31 @@ def _assignee() -> _Principal:
)
def _api_principal(user_id: str, account_id: str) -> ApiPrincipal:
return ApiPrincipal(
principal=PrincipalRef(
account_id=account_id,
membership_id=user_id,
tenant_id=TENANT_ID,
scopes=frozenset(
{
"campaigns:campaign:read",
"campaigns:campaign:create",
"campaigns:assignment:read",
"campaigns:assignment:manage",
"campaigns:assignment:complete",
}
),
),
account=SimpleNamespace(id=account_id),
user=SimpleNamespace(
id=user_id,
display_name=f"User {user_id}",
email=f"{user_id}@example.test",
),
)
def _commit_audit(session: Session, *_args, **_kwargs) -> None:
session.commit()
@@ -407,10 +438,189 @@ def test_reassignment_and_deactivation_reconciliation_preserve_history(session:
assert reassigned.assignee_type == "account"
assert result.changed == 1
assert result.assignments[0].assignee_resolution_state == "unavailable"
assert [item.event_kind for item in reversed(history.items)] == ["assigned", "reassigned", "assignee_unavailable"]
assert [item.event_kind for item in reversed(history.items)] == [
"assigned",
"reassigned",
"assignee_unavailable",
]
assert history.items[1].details["assignee_id"] == "group-1"
def test_workflow_provider_is_idempotent_emits_typed_events_and_rechecks_access(
session: Session,
) -> None:
directory = _Directory()
registry = _Registry(_Tasks(), _Notifications())
provider = SqlCampaignWorkOrchestrationProvider(registry=registry)
manager = _api_principal("user-1", "account-1")
assignee = _api_principal("user-2", "account-2")
request = CampaignWorkHandoffRequest(
tenant_id=TENANT_ID,
campaign_id="campaign-1",
expected_campaign_revision=1,
idempotency_key="workflow-handoff-1",
purpose="Review the Campaign evidence",
assignee_kind="account",
assignee_id="account-2",
correlation_id="workflow-correlation-1",
workflow_instance_id="workflow-instance-1",
workflow_step_id="workflow-step-1",
)
bus = EventBus()
events = []
bus.subscribe("campaign.work.changed", events.append)
with (
patch(
"govoplan_campaign.backend.routes.assignments._access_directory",
return_value=directory,
),
patch(
"govoplan_campaign.backend.route_support._access_directory",
return_value=directory,
),
patch(
"govoplan_campaign.backend.routes.assignments.get_registry",
return_value=registry,
),
patch(
"govoplan_campaign.backend.work_orchestration.audit_from_principal",
return_value=SimpleNamespace(id="audit-workflow-1"),
),
patch(
"govoplan_campaign.backend.routes.assignments.audit_from_principal",
side_effect=_commit_audit,
),
event_bus_context(bus),
):
created = provider.prepare_handoff(session, manager, request=request)
session.commit()
replayed = provider.prepare_handoff(session, manager, request=request)
accepted = transition_campaign_work_assignment(
"campaign-1",
created.assignment_id,
CampaignWorkAssignmentTransitionRequest(
expected_revision=1,
action="accept",
),
session,
assignee,
)
completed = transition_campaign_work_assignment(
"campaign-1",
created.assignment_id,
CampaignWorkAssignmentTransitionRequest(
expected_revision=2,
action="complete",
),
session,
assignee,
)
assert created.replayed is False
assert replayed.replayed is True
assert created.assignment_id == replayed.assignment_id
assert created.campaign_ref == "campaign:campaign-1:version:version-1:r1"
assert created.assignment_ref.endswith(":r1")
assert created.optional_capabilities == {"tasks": True, "notifications": True}
assert session.query(CampaignWorkAssignment).filter(
CampaignWorkAssignment.orchestration_idempotency_key
== "workflow-handoff-1"
).count() == 1
assert accepted.status == "in_progress"
assert completed.status == "completed"
assert [event.payload["outcome"] for event in events] == [
"assigned",
"accepted",
"completed",
]
assert [event.payload["assignment_revision"] for event in events] == [1, 2, 3]
assert all(event.correlation_id == "workflow-correlation-1" for event in events)
with patch(
"govoplan_campaign.backend.route_support._access_directory",
return_value=directory,
):
allowed = provider.inspect_handoff(
session,
assignee,
tenant_id=TENANT_ID,
assignment_id=created.assignment_id,
expected_revision=3,
)
share = session.get(CampaignShare, "share-1")
assert share is not None
share.revoked_at = completed.updated_at
session.flush()
revoked = provider.inspect_handoff(
session,
assignee,
tenant_id=TENANT_ID,
assignment_id=created.assignment_id,
expected_revision=3,
)
assert allowed.allowed is True
assert revoked.allowed is False
assert revoked.provenance["code"] == "campaign_handoff_access_revoked"
def test_workflow_provider_can_create_self_assigned_campaign_and_rejects_stale_revision(
session: Session,
) -> None:
directory = _Directory()
registry = _Registry()
provider = SqlCampaignWorkOrchestrationProvider(registry=registry)
manager = _api_principal("user-1", "account-1")
with (
patch(
"govoplan_campaign.backend.routes.assignments._access_directory",
return_value=directory,
),
patch(
"govoplan_campaign.backend.routes.assignments.get_registry",
return_value=registry,
),
patch(
"govoplan_campaign.backend.work_orchestration.audit_from_principal",
return_value=SimpleNamespace(id="audit-workflow-create"),
),
):
created = provider.prepare_handoff(
session,
manager,
request=CampaignWorkHandoffRequest(
tenant_id=TENANT_ID,
create_external_id="workflow-created",
create_name="Workflow-created Campaign",
idempotency_key="workflow-create-1",
purpose="Prepare the Campaign",
assignee_kind="account",
assignee_id="account-1",
workflow_instance_id="workflow-instance-create",
workflow_step_id="workflow-step-create",
),
)
assert session.get(Campaign, created.campaign_id).external_id == "workflow-created"
version = session.get(CampaignVersion, "version-1")
assert version is not None
version.edit_revision = 2
with pytest.raises(ValueError, match="Campaign revision changed"):
provider.prepare_handoff(
session,
manager,
request=CampaignWorkHandoffRequest(
tenant_id=TENANT_ID,
campaign_id="campaign-1",
expected_campaign_revision=1,
idempotency_key="workflow-stale-1",
purpose="Review stale Campaign",
assignee_kind="account",
assignee_id="account-1",
),
)
def test_organization_function_requires_authorized_current_incumbencies(session: Session) -> None:
with (
patch("govoplan_campaign.backend.routes.assignments._access_directory", return_value=_Directory()),
@@ -470,3 +680,52 @@ def test_assignment_migration_is_repeatable_and_creates_history_indexes() -> Non
migration.downgrade()
assert not inspect(connection).has_table("campaign_work_assignment_events")
assert not inspect(connection).has_table("campaign_work_assignments")
def test_workflow_orchestration_migration_is_repeatable() -> None:
assignments = importlib.import_module(
"govoplan_campaign.backend.migrations.versions."
"d8e9f0a1b2c3_v0121_campaign_work_assignments"
)
orchestration = importlib.import_module(
"govoplan_campaign.backend.migrations.versions."
"f3c7a9d2e6b1_v0123_campaign_work_orchestration"
)
engine = create_engine("sqlite+pysqlite:///:memory:")
with engine.begin() as connection:
connection.execute(text("CREATE TABLE access_users (id VARCHAR(36) PRIMARY KEY)"))
connection.execute(text("CREATE TABLE campaigns (id VARCHAR(36) PRIMARY KEY)"))
connection.execute(text("CREATE TABLE campaign_versions (id VARCHAR(36) PRIMARY KEY, campaign_id VARCHAR(36) NOT NULL)"))
context = MigrationContext.configure(connection)
with patch.object(assignments, "op", Operations(context)):
assignments.upgrade()
with patch.object(orchestration, "op", Operations(context)):
orchestration.upgrade()
orchestration.upgrade()
inspector = inspect(connection)
columns = {
item["name"]
for item in inspector.get_columns("campaign_work_assignments")
}
indexes = {
item["name"]
for item in inspector.get_indexes("campaign_work_assignments")
}
assert {
"orchestration_idempotency_key",
"orchestration_request_sha256",
"orchestration_correlation_id",
"workflow_instance_id",
"workflow_step_id",
}.issubset(columns)
assert "uq_campaign_work_assignment_orchestration_key" in indexes
with patch.object(orchestration, "op", Operations(context)):
orchestration.downgrade()
assert "workflow_instance_id" not in {
item["name"]
for item in inspect(connection).get_columns(
"campaign_work_assignments"
)
}
+55 -34
View File
@@ -223,8 +223,9 @@ def test_queue_projection_fails_closed_if_no_task_was_published() -> None:
)
@pytest.mark.parametrize("duplicate_mutates", [False, True])
def test_redelivery_orchestration_requires_same_task_and_no_second_smtp_effect(
monkeypatch,
monkeypatch, duplicate_mutates,
) -> None:
first_worker = mock.Mock()
first_worker.received_task_ids.return_value = (TASK_ID,)
@@ -232,22 +233,29 @@ def test_redelivery_orchestration_requires_same_task_and_no_second_smtp_effect(
replacement_worker.received_task_ids.return_value = (TASK_ID,)
workers = iter([first_worker, replacement_worker])
endpoint = _Endpoint()
durable_states = iter(
[
{
"job_count": 1,
"send_status_counts": {"sending": 1},
"attempt_status_counts": {"smtp_in_progress": 1},
"unfinished_attempt_count": 1,
},
{
"job_count": 1,
"send_status_counts": {"outcome_unknown": 1},
"attempt_status_counts": {"outcome_unknown": 1},
"unfinished_attempt_count": 0,
},
]
)
durable_states = [
{
"job_count": 1,
"send_status_counts": {"sending": 1},
"attempt_status_counts": {"smtp_in_progress": 1},
"unfinished_attempt_count": 1,
},
{
"job_count": 1,
"send_status_counts": {"sending": 1},
"attempt_status_counts": {"smtp_in_progress": 1},
"unfinished_attempt_count": 1,
},
{
"job_count": 1,
"send_status_counts": {"outcome_unknown": 1},
"attempt_status_counts": {"outcome_unknown": 1},
"unfinished_attempt_count": 0,
},
]
if duplicate_mutates:
durable_states[1] = durable_states[2]
durable_states = iter(durable_states)
prepared = SimpleNamespace(
campaign_id="campaign-internal",
version_id="version-internal",
@@ -277,24 +285,34 @@ def test_redelivery_orchestration_requires_same_task_and_no_second_smtp_effect(
"_wait_for_broker_drained",
lambda *args, **kwargs: runner.RedisBrokerState(0, 0, 0),
)
recover_claim = mock.Mock(return_value={"explicit_fenced_recovery": True})
evidence = runner.execute_redelivery_scenario(
_Client(),
{"Authorization": "not-retained"},
fixture_path=FIXTURE_PATH,
settings=_settings(),
endpoint=endpoint,
redis_url="redis://127.0.0.1:36379/0",
runtime_root=Path("/not-used"),
snapshot_probe=lambda _version_id: ({}, {}),
audit_probe=lambda _campaign_id, _version_id: {
"campaign.created": 1,
"campaign.validated": 1,
"campaign.messages_built": 1,
"campaign.queued": 1,
},
delivery_probe=lambda _campaign_id, _version_id: next(durable_states),
)
def execute():
return runner.execute_redelivery_scenario(
_Client(),
{"Authorization": "not-retained"},
fixture_path=FIXTURE_PATH,
settings=_settings(),
endpoint=endpoint,
redis_url="redis://127.0.0.1:36379/0",
runtime_root=Path("/not-used"),
snapshot_probe=lambda _version_id: ({}, {}),
audit_probe=lambda _campaign_id, _version_id: {
"campaign.created": 1,
"campaign.validated": 1,
"campaign.messages_built": 1,
"campaign.queued": 1,
},
delivery_probe=lambda _campaign_id, _version_id: next(durable_states),
recover_claim=recover_claim,
)
if duplicate_mutates:
with pytest.raises(runner.AcceptanceError, match="without stopped-runtime proof"):
execute()
recover_claim.assert_not_called()
return
evidence = execute()
assert evidence["broker"] == {
"transport": "redis",
@@ -310,5 +328,8 @@ def test_redelivery_orchestration_requires_same_task_and_no_second_smtp_effect(
assert evidence["recovered_durable_state"]["send_status_counts"] == {
"outcome_unknown": 1
}
assert evidence["redelivered_durable_state"] == evidence["interrupted_durable_state"]
assert evidence["supervision"]["duplicate_task_left_sending_unchanged"] is True
recover_claim.assert_called_once_with("campaign-internal", "version-internal", first_worker.process)
assert TASK_ID not in json.dumps(evidence, sort_keys=True)
assert endpoint.release_count >= 1
+192
View File
@@ -0,0 +1,192 @@
from __future__ import annotations
from types import SimpleNamespace
from unittest.mock import patch
import pytest
from fastapi import FastAPI, HTTPException
from fastapi.testclient import TestClient
from pydantic import ValidationError
from sqlalchemy import create_engine
from sqlalchemy.orm import Session
from govoplan_core.admin.models import SystemSettings
from govoplan_core.auth import ApiPrincipal, get_api_principal
from govoplan_core.db.session import get_session
from govoplan_core.core.access import PrincipalRef
from govoplan_core.core.change_sequence import ChangeSequenceEntry
from govoplan_core.core.configuration_safety import classify_configuration_field, plan_configuration_change
from govoplan_core.tenancy.scope import Tenant
from govoplan_campaign.backend.delivery_policy import SYNCHRONOUS_SEND_MAX_ENV, effective_synchronous_send_policy
from govoplan_campaign.backend.routes import delivery_settings as routes
from govoplan_campaign.backend.router import router as campaign_router
def principal(*scopes, tenant="tenant-a"):
actor = SimpleNamespace(id="admin-1")
return ApiPrincipal(principal=PrincipalRef(account_id=actor.id, membership_id=actor.id, tenant_id=tenant, scopes=frozenset(scopes)), user=actor, account=actor)
@pytest.fixture
def policy(tmp_path, monkeypatch):
monkeypatch.delenv(SYNCHRONOUS_SEND_MAX_ENV, raising=False)
engine = create_engine(f"sqlite+pysqlite:///{tmp_path / 'policy.db'}")
for table in (SystemSettings.__table__, Tenant.__table__, ChangeSequenceEntry.__table__):
table.create(engine)
with Session(engine) as session:
session.add_all([
SystemSettings(id="global", settings={"unrelated": {"enabled": True}}),
Tenant(id="tenant-a", slug="a", name="A", settings={"unrelated": "preserve"}),
Tenant(id="tenant-b", slug="b", name="B", settings={}),
])
session.commit()
with patch.object(routes, "audit_from_principal", autospec=True) as audit:
yield SimpleNamespace(session=session, engine=engine, audit=audit,
admin=principal("system:settings:read", "system:settings:write", "admin:policies:read", "admin:policies:write"))
engine.dispose()
def state(policy, scope="system", actor=None):
return routes.read_delivery_policy(scope, session=policy.session, principal=actor or policy.admin)
def save(policy, value, scope="system", revision=None, actor=None):
payload = routes.DeliveryPolicyUpdate(synchronous_send_max_recipients=value, expected_revision=revision or state(policy, scope)["revision"])
return routes.update_delivery_policy(scope, payload, session=policy.session, principal=actor or policy.admin)
def test_system_admin_can_raise_implicit_default_and_save_is_durable_audited_and_scoped(policy):
before = state(policy)
assert before["effective_max_recipients"] == 25 and before["max_configurable_recipients"] == 500
result = save(policy, 200)
assert result["effective_max_recipients"] == 200 and result["revision"] != before["revision"]
with Session(policy.engine) as fresh:
assert effective_synchronous_send_policy(fresh, tenant_id="tenant-a", environ={}).max_recipient_jobs == 200
system = fresh.get(SystemSettings, "global")
assert system.settings["unrelated"] == {"enabled": True}
history = system.settings["_configuration_control"]["history"]
assert len(history) == 1 and history[0]["key"] == "campaign_delivery_policy.system"
assert history[0]["before"]["synchronous_send_max_recipients"] is None
assert history[0]["after"]["synchronous_send_max_recipients"] == 200
assert history[0]["actor_user_id"] == "admin-1"
assert policy.audit.call_args.kwargs["commit"] is False
assert policy.audit.call_args.kwargs["scope"] == "system"
def test_tenant_can_only_narrow_and_reset_inherits_without_affecting_other_tenant(policy):
save(policy, 200)
with pytest.raises(HTTPException) as failure:
save(policy, 201, "tenant")
assert failure.value.status_code == 422
save(policy, 183, "tenant")
assert effective_synchronous_send_policy(policy.session, tenant_id="tenant-a").max_recipient_jobs == 183
assert effective_synchronous_send_policy(policy.session, tenant_id="tenant-b").max_recipient_jobs == 200
assert policy.session.get(Tenant, "tenant-a").settings["unrelated"] == "preserve"
assert save(policy, None, "tenant")["effective_max_recipients"] == 200
assert save(policy, None)["effective_max_recipients"] == 25
def test_explicit_deployment_ceiling_remains_authoritative_and_zero_disables(policy, monkeypatch):
save(policy, 200)
monkeypatch.setenv(SYNCHRONOUS_SEND_MAX_ENV, "40")
assert state(policy)["effective_max_recipients"] == 40
with pytest.raises(HTTPException) as failure:
save(policy, 41)
assert failure.value.status_code == 422
assert save(policy, None)["effective_max_recipients"] == 40
assert save(policy, 0)["effective_max_recipients"] == 0
assert state(policy, "tenant")["max_configurable_recipients"] == 0
@pytest.mark.parametrize("blank", ["", " ", "\t\n"])
def test_blank_deployment_value_never_turns_default_into_absolute_maximum(policy, monkeypatch, blank):
monkeypatch.setenv(SYNCHRONOUS_SEND_MAX_ENV, blank)
assert state(policy)["effective_max_recipients"] == 25
assert state(policy)["deployment_ceiling_explicit"] is False
save(policy, 200)
assert state(policy)["effective_max_recipients"] == 200
save(policy, 183, "tenant")
assert state(policy, "tenant")["effective_max_recipients"] == 183
def test_stale_parent_own_or_aba_revision_never_overwrites_policy(policy):
initial = state(policy)
tenant = state(policy, "tenant")
save(policy, 200)
for scope, revision in (("system", initial["revision"]), ("tenant", tenant["revision"])):
with pytest.raises(HTTPException) as failure:
save(policy, 10, scope, revision=revision)
assert failure.value.status_code == 409
save(policy, None)
with pytest.raises(HTTPException) as failure:
save(policy, 30, revision=initial["revision"])
assert failure.value.status_code == 409
@pytest.mark.parametrize("scope,scopes,operation", [
("system", ("admin:policies:read", "admin:policies:write"), "read"),
("system", ("admin:policies:write",), "write"),
("tenant", ("system:settings:read", "system:settings:write"), "read"),
("tenant", ("system:settings:write",), "write"),
("system", ("system:settings:read",), "write"),
("tenant", ("admin:policies:read",), "write"),
])
def test_permissions_cannot_cross_scope_or_use_read_permission_to_write(policy, scope, scopes, operation):
actor = principal(*scopes)
with pytest.raises(HTTPException) as failure:
if operation == "read": state(policy, scope, actor=actor)
else: save(policy, 10, scope, actor=actor)
assert failure.value.status_code == 403
assert "_configuration_control" not in policy.session.get(SystemSettings, "global").settings
@pytest.mark.parametrize("value", [True, 1.5, "20", -1, 501])
def test_schema_rejects_coercions_and_unbounded_values(value):
with pytest.raises(ValidationError):
routes.DeliveryPolicyUpdate(synchronous_send_max_recipients=value, expected_revision="a" * 64)
def test_route_rolls_back_configuration_and_history_if_audit_fails(policy):
policy.audit.side_effect = RuntimeError("Audit unavailable")
with pytest.raises(RuntimeError, match="Audit unavailable"):
save(policy, 200)
policy.session.expire_all()
assert policy.session.get(SystemSettings, "global").settings == {"unrelated": {"enabled": True}}
def test_configuration_catalog_supports_only_known_scope_keys_and_scopes():
for scope, permission in (("system", "system:settings:write"), ("tenant", "admin:policies:write")):
key = f"campaign_delivery_policy.{scope}"
field = classify_configuration_field(key)
assert field.owner_module == "campaigns" and field.rollback_history_required
assert plan_configuration_change(key, actor_scopes=(permission,), value={"synchronous_send_max_recipients": 200}).allowed
assert not plan_configuration_change(key, actor_scopes=(), value={"synchronous_send_max_recipients": 200}).allowed
assert classify_configuration_field("campaign_delivery_policy.unknown") is None
def test_registered_http_routes_validate_scope_authorization_payload_and_revision(policy):
app = FastAPI()
app.include_router(campaign_router, prefix="/api/v1")
app.dependency_overrides[get_session] = lambda: policy.session
actor = [policy.admin]
app.dependency_overrides[get_api_principal] = lambda: actor[0]
with TestClient(app) as client:
path = "/api/v1/campaigns/settings/delivery-policy/system"
response = client.get(path)
assert response.status_code == 200
payload = {"synchronous_send_max_recipients": 200, "expected_revision": response.json()["revision"]}
actor[0] = principal("system:settings:read")
assert client.put(path, json=payload).status_code == 403
actor[0] = principal("admin:policies:read", "admin:policies:write")
assert client.get(path).status_code == 403
assert client.put(path, json=payload).status_code == 403
actor[0] = policy.admin
assert client.put(path, json={**payload, "settings": {"unrelated": "overwrite"}}).status_code == 422
assert client.put(path, json={**payload, "synchronous_send_max_recipients": True}).status_code == 422
saved = client.put(path, json=payload)
assert saved.status_code == 200 and saved.json()["effective_max_recipients"] == 200
assert client.put(path, json=payload).status_code == 409
assert client.get("/api/v1/campaigns/settings/delivery-policy/user").status_code == 422
actor[0] = principal()
assert client.get(path).status_code == 403
assert policy.audit.call_args.kwargs["object_type"] == "campaign_delivery_policy"
+6 -3
View File
@@ -464,7 +464,9 @@ def test_static_campaign_handbook_has_unique_ids_help_contexts_and_no_planned_re
"campaign.fields",
"campaign.template",
"campaign.template.content-library",
"campaigns.action.schedule-drafts",
"campaigns.action.schedule-drafts",
"campaigns.action.export-package",
"campaigns.action.import-package",
"campaign.attachments",
"campaign.attachments.reuse-policy",
"campaign.attachments.residual-files",
@@ -484,8 +486,9 @@ def test_static_campaign_handbook_has_unique_ids_help_contexts_and_no_planned_re
"campaign.work",
"campaign.work.create",
"campaign.work.action.start",
"campaign.work.action.complete",
"campaign.work.action.reassign",
"campaign.work.action.complete",
"campaign.work.action.reject",
"campaign.work.action.reassign",
"campaign.work.action.cancel",
"campaign.work.history",
}
+19
View File
@@ -0,0 +1,19 @@
from govoplan_campaign.backend.manifest import get_manifest
def test_static_documentation_has_complete_german_reference_copy() -> None:
for topic in get_manifest().documentation:
german = topic.translations.get("de", {})
assert all(german.get(field, "").strip() for field in ("title", "summary", "body")), topic.id
def test_module_breadcrumb_and_table_layout_contract_is_bilingual_and_non_mutating() -> None:
topic = next(item for item in get_manifest().documentation if item.id == "campaigns.module-navigation-and-table-layout")
assert set(topic.documentation_types) == {"user", "admin"}
assert topic.layer == "available"
for body in (topic.body, topic.translations["de"]["body"]):
for route in ("/campaigns/reports", "/campaigns/queue", "/campaigns/{campaign_id}/report", "/operator"):
assert route in body
assert "Quick Access" in body
assert "report privacy suppression" in topic.body
assert "without module-local negative margins" in topic.body
+48
View File
@@ -6,7 +6,9 @@ import pytest
from pydantic import ValidationError
from govoplan_campaign.backend.campaign.mail_profile_boundary import (
CampaignMailProfileBoundaryError,
campaign_editor_state_for_edit,
campaign_editor_state_with_client_update,
)
from govoplan_campaign.backend.schemas import (
CampaignVersionResponse,
@@ -19,6 +21,7 @@ from govoplan_campaign.backend.schemas import (
[
{"smtp": {"host": "smtp.example.test", "password": "secret"}},
{"transport": {"imap_password": "secret"}},
{"approval_gate": {"request_id": "forged"}},
{
"review_send": {
"build_token": "forged",
@@ -108,3 +111,48 @@ def test_fork_copy_keeps_only_client_owned_bounded_metadata() -> None:
"field_overrides": {"department": False},
}
assert "legacy-secret" not in repr(copied)
def test_client_metadata_update_preserves_only_trusted_server_evidence() -> None:
review = {
"build_token": "server-build-token",
"inspection_complete": True,
"reviewed_message_keys": ["entry-1"],
"issue_decisions": [],
"updated_at": "2026-07-21T00:00:00+00:00",
"updated_by_user_id": "reviewer-1",
}
approval = {
"request_id": "approval-1",
"request_revision": 2,
"subject_version": "version-1",
"subject_digest": "a" * 64,
"requested_at": "2026-07-21T00:00:00+00:00",
"requested_by_user_id": "approver-1",
}
stored = {
"created_from": "minimal_campaign",
"opt_ins": {"inline_guidance": True},
"review_send": review,
"approval_gate": approval,
"credentials": {"password": "legacy-secret"},
}
updated = campaign_editor_state_with_client_update(
stored, {"opt_ins": {"inline_guidance": False}}
)
assert updated == {
"opt_ins": {"inline_guidance": False},
"review_send": review,
"approval_gate": approval,
}
assert updated["review_send"] is not review
assert updated["approval_gate"] is not approval
assert stored["opt_ins"] == {"inline_guidance": True}
assert "legacy-secret" not in repr(updated)
@pytest.mark.parametrize("server_key", ["review_send", "approval_gate"])
def test_client_metadata_update_cannot_replace_server_evidence(server_key: str) -> None:
with pytest.raises(CampaignMailProfileBoundaryError, match="unsupported"):
campaign_editor_state_with_client_update({}, {server_key: {}})
+75
View File
@@ -0,0 +1,75 @@
from pathlib import Path
import random
import unittest
from govoplan_campaign.backend.services.filenames import FilenameAllocator
from govoplan_campaign.backend.services.zip_service import _normalized_members
def legacy_names(names):
used = set()
result = []
for name in names:
path = Path(name)
candidate = name
counter = 2
while candidate.casefold() in used:
candidate = f"{path.stem} ({counter}){path.suffix}"
counter += 1
used.add(candidate.casefold())
result.append(candidate)
return result
class FilenameAllocatorTests(unittest.TestCase):
def test_exact_equivalence_with_colliding_suffixes_case_unicode_and_multiple_dots(
self,
):
choices = [
"report.pdf",
"REPORT.PDF",
"report (2).pdf",
"report (3).pdf",
"report (2) (2).pdf",
".hidden",
"a.tar.gz",
"A.TAR.GZ",
"Straße.txt",
"STRASSE.txt",
"readme",
]
rng = random.Random(42)
for _ in range(30):
names = [rng.choice(choices) for _ in range(200)]
allocator = FilenameAllocator()
self.assertEqual(
legacy_names(names), [allocator.allocate(name) for name in names]
)
def test_zip_and_message_names_preserve_every_input_and_sequence(self):
names = ["a.pdf", "A.pdf", "a (2).pdf", "a.pdf"]
paths = [Path(f"/synthetic/{index}/source") for index in range(len(names))]
members = _normalized_members(list(zip(paths, names)))
self.assertEqual(paths, [path for path, _ in members])
self.assertEqual(legacy_names(names), [name for _, name in members])
self.assertEqual("a.pdf", FilenameAllocator().allocate("a.pdf"))
def test_many_collisions_have_linear_membership_work(self):
class CountingSet(set):
probes = 0
def __contains__(self, item):
self.probes += 1
return super().__contains__(item)
allocator = FilenameAllocator()
allocator.used = CountingSet()
for _ in range(10000):
last = allocator.allocate("report.pdf")
self.assertEqual("report (10000).pdf", last)
self.assertEqual(10000, len(allocator.used))
self.assertEqual(19999, allocator.used.probes)
if __name__ == "__main__":
unittest.main()
+1
View File
@@ -304,6 +304,7 @@ def test_imap_reconciliation_preserves_attempt_and_only_not_appended_is_retryabl
session = MagicMock()
session.get.return_value = job
session.query.return_value.filter.return_value.order_by.return_value.first.return_value = attempt
session.query.return_value.filter.return_value.update.return_value = 1
with (
patch(
+52
View File
@@ -0,0 +1,52 @@
from contextlib import contextmanager
from types import SimpleNamespace
import pytest
from govoplan_campaign.backend.integrations import ImapAppendError, MailCampaignIntegration
def test_older_mail_capability_keeps_single_message_compatibility():
integration = MailCampaignIntegration(SimpleNamespace())
with integration.campaign_imap_batch(tenant_id="tenant", campaign_id="campaign") as state:
assert state is None
def test_optional_batch_forwards_scope_and_cleans_up_when_caller_fails():
calls = []
state = SimpleNamespace(connection_count=0, reconnect_count=0)
@contextmanager
def batch(**kwargs):
calls.append(kwargs)
try:
yield state
finally:
calls.append("closed")
integration = MailCampaignIntegration(SimpleNamespace(campaign_imap_batch=batch))
with pytest.raises(ValueError, match="caller"):
with integration.campaign_imap_batch(tenant_id="tenant", campaign_id="campaign") as actual:
assert actual is state
raise ValueError("caller failure")
assert calls == [{"tenant_id": "tenant", "campaign_id": "campaign"}, "closed"]
def test_optional_batch_translates_unknown_outcome_without_losing_flags():
class ProviderAppendError(RuntimeError):
temporary = False
outcome_unknown = True
@contextmanager
def batch(**kwargs):
raise ProviderAppendError("inspect mailbox")
yield None
integration = MailCampaignIntegration(SimpleNamespace(
campaign_imap_batch=batch, ImapAppendError=ProviderAppendError,
))
with pytest.raises(ImapAppendError) as caught:
with integration.campaign_imap_batch(tenant_id="tenant", campaign_id="campaign"):
pass
assert caught.value.outcome_unknown
assert caught.value.temporary is False
@@ -0,0 +1,245 @@
"""Real database/route checks: a review acceptance is durable before completion."""
from __future__ import annotations
import copy
from types import SimpleNamespace
from unittest.mock import patch
import pytest
from fastapi import HTTPException
from pydantic import ValidationError
from sqlalchemy import Column, String, Table, create_engine, event
from sqlalchemy.orm import Session
from govoplan_campaign.backend.db.models import Campaign, CampaignJob, CampaignVersion
from govoplan_campaign.backend.routes import versions as routes
from govoplan_campaign.backend.schemas import CampaignReviewStateRequest, CampaignVersionDetailResponse
from govoplan_campaign.backend.services.job_queries import _review_metadata, _review_metadata_counts
from govoplan_campaign.backend.services.review_decisions import review_decision_metadata
from govoplan_campaign.backend.sending.jobs import _reviewed_needs_review_keys
from govoplan_core.auth import ApiPrincipal
from govoplan_core.core.access import PrincipalRef
from govoplan_core.core.change_sequence import ChangeSequenceEntry
from govoplan_core.db.base import Base
@pytest.fixture
def review(tmp_path):
engine = create_engine(f"sqlite+pysqlite:///{tmp_path / 'review.db'}")
for name in ("access_users", "access_groups"):
if name not in Base.metadata.tables:
Table(name, Base.metadata, Column("id", String(36), primary_key=True))
Base.metadata.create_all(engine, tables=[
Base.metadata.tables["access_users"], Base.metadata.tables["access_groups"],
ChangeSequenceEntry.__table__, Campaign.__table__, CampaignVersion.__table__, CampaignJob.__table__,
])
with Session(engine) as session:
campaign = Campaign(id="campaign-1", tenant_id="tenant-1", external_id="C1", name="Campaign", current_version_id="version-1")
version = CampaignVersion(id="version-1", campaign_id=campaign.id, version_number=1,
raw_json={"version": "1.0", "campaign": {"id": "C1", "name": "Campaign"}},
build_summary={"build_token": "private-build-1", "built_count": 2}, editor_state={"created_from": "minimal_campaign"})
session.add_all([campaign, version, _job(1), _job(2)])
session.commit()
audits = []
def audit(current_session, _principal, **kwargs):
audits.append(kwargs)
if kwargs.get("commit"):
current_session.commit()
with patch.object(routes, "_get_campaign_for_principal", return_value=campaign), patch.object(routes, "audit_from_principal", side_effect=audit):
yield SimpleNamespace(engine=engine, session=session, version=version, campaign=campaign, audits=audits)
engine.dispose()
def _job(index, *, validation="needs_review", build="built", code="missing_optional_attachment", behavior="ask"):
return CampaignJob(id=f"job-{index}", tenant_id="tenant-1", campaign_id="campaign-1", campaign_version_id="version-1",
entry_index=index, entry_id=f"entry-{index}", validation_status=validation, build_status=build,
eml_sha256=str(index % 10) * 64, issues_snapshot=[{"code": code, "behavior": behavior, "source": "attachments", "details": {"rule_id": f"rule-{index}"}}])
def _principal(actor="reviewer-1"):
return ApiPrincipal(principal=PrincipalRef(account_id=actor, membership_id=actor, tenant_id="tenant-1", scopes=frozenset({"campaigns:campaign:review"})), account=SimpleNamespace(id=actor), user=SimpleNamespace(id=actor))
def _save(review, *, ids=(1,), complete=False, actor="reviewer-1", session=None, **overrides):
payload = {
"inspection_complete": complete, "merge_progress": True,
"build_token": review.version.review_build_token, "base_revision": review.version.edit_revision,
"reviewed_message_keys": [f"entry-{index}" for index in ids],
"issue_decisions": [{"job_id": f"job-{index}", "decision": "accept", "reason": f"Reason {index}"} for index in ids],
**overrides,
}
return routes.set_version_review_state("campaign-1", "version-1", CampaignReviewStateRequest(**payload), session=session or review.session, principal=_principal(actor))
def test_partial_reason_and_reviewed_state_survive_fresh_reload_without_completion(review):
response = _save(review)
review.session.expire_all()
stored = review.session.get(CampaignVersion, "version-1")
state = stored.editor_state["review_send"]
assert state["inspection_complete"] is False
assert state["reviewed_message_keys"] == ["entry-1"]
assert state["issue_decisions"][0]["reason"] == "Reason 1"
assert state["issue_decisions"][0]["actor_user_id"] == "reviewer-1"
assert state["issue_decisions"][0]["message_sha256"] == "1" * 64
assert response.edit_revision == 2
assert response.review_build_token and "private-build-1" not in repr(response)
public_state = response.editor_state["review_send"]
assert public_state["review_build_token"] == response.review_build_token
assert "build_token" not in public_state and "build_token" not in (response.build_summary or {})
metadata, reviewed_keys = _review_metadata(review.session, stored, [CampaignJob.campaign_version_id == stored.id])
assert metadata["reviewed_required_count"] == 1 and reviewed_keys == {"entry-1"}
assert _reviewed_needs_review_keys(stored) == set(), "partial progress never authorizes delivery"
assert review.audits[-1]["action"] == "campaign.message_review_updated"
def test_second_reviewer_and_final_completion_preserve_first_decision_evidence(review):
_save(review)
first = copy.deepcopy(review.version.editor_state["review_send"]["issue_decisions"][0])
_save(review, ids=(2,), actor="reviewer-2")
state = review.version.editor_state["review_send"]
assert state["reviewed_message_keys"] == ["entry-1", "entry-2"]
assert state["issue_decisions"][0] == first
second = copy.deepcopy(state["issue_decisions"][1])
assert review.audits[-1]["details"]["issue_decisions"]["count"] == 1
assert review.audits[-1]["details"]["issue_decisions"] == routes._review_decision_audit_evidence(review.version, job_ids={"job-2"})
_save(review, ids=(), complete=True, actor="reviewer-3")
review.session.expire_all()
state = review.version.editor_state["review_send"]
assert state["inspection_complete"] is True
assert state["issue_decisions"] == [first, second]
assert review.audits[-1]["details"]["issue_decisions"]["count"] == 2
assert _reviewed_needs_review_keys(review.version) == {"entry-1", "entry-2"}
def test_incremental_save_loads_only_selected_job_and_never_materializes_files(review):
review.session.add_all([_job(index, validation="ready", behavior="continue") for index in range(3, 503)])
review.session.commit()
review.session.refresh(review.version)
review.session.refresh(review.campaign)
review.session.expunge_all()
loaded_jobs = []
def loaded(_session, instance):
if isinstance(instance, CampaignJob):
loaded_jobs.append(instance.id)
event.listen(review.session, "loaded_as_persistent", loaded)
try:
with patch("govoplan_campaign.backend.persistence.campaigns.load_version_config", side_effect=AssertionError("Review progress must not rebuild or resolve Files")):
_save(review)
assert loaded_jobs == ["job-1"]
finally:
event.remove(review.session, "loaded_as_persistent", loaded)
@pytest.mark.parametrize("mutation", ["unknown_job", "unknown_key", "missing_reason", "duplicate", "blocked", "hard_issue", "excluded", "category"])
def test_invalid_incremental_acceptance_is_atomic(review, mutation):
options = {}
if mutation == "unknown_job":
options["issue_decisions"] = [{"job_id": "outside-build", "reason": "Not allowed"}]
elif mutation == "unknown_key":
options["reviewed_message_keys"] = ["outside-build"]
elif mutation == "missing_reason":
options["issue_decisions"] = [{"job_id": "job-1", "reason": " "}]
elif mutation == "duplicate":
options["issue_decisions"] = [{"job_id": "job-1", "reason": "A"}, {"job_id": "job-1", "reason": "B"}]
elif mutation == "category":
options["decision_category_key"] = "wrong-category"
else:
job = review.session.get(CampaignJob, "job-1")
if mutation == "hard_issue":
job.issues_snapshot = [{"code": "required", "source": "attachments", "behavior": "block"}]
else:
job.validation_status = mutation
review.session.commit()
original = copy.deepcopy(review.version.editor_state)
with pytest.raises(HTTPException) as error:
_save(review, **options)
assert error.value.status_code == 422
review.session.expire_all()
assert review.version.editor_state == original and review.version.edit_revision == 1
assert review.audits == []
@pytest.mark.parametrize("precondition", ["build", "revision"])
def test_stale_progress_is_conflict_and_preserves_acknowledged_progress(review, precondition):
_save(review)
options = {"build_token": "old-build"} if precondition == "build" else {"base_revision": 1}
with pytest.raises(HTTPException) as error:
_save(review, ids=(2,), **options)
assert error.value.status_code == 409
assert review.version.editor_state["review_send"]["reviewed_message_keys"] == ["entry-1"]
def test_same_category_bulk_is_bound_to_exact_selected_jobs(review):
category = review_decision_metadata(review.session.get(CampaignJob, "job-1"))["category_key"]
result = _save(review, ids=(1, 2), decision_category_key=category)
assert result.editor_state["review_send"]["reviewed_message_keys"] == ["entry-1", "entry-2"]
assert len(result.editor_state["review_send"]["issue_decisions"]) == 2
def test_deliberately_excluded_and_inactive_rows_do_not_block_completion_or_need_bulk_acceptance(review):
review.session.add_all([_job(3, validation="excluded", build="skipped", behavior="drop"), _job(4, validation="inactive", build="skipped", behavior="continue")])
review.session.commit()
_save(review, ids=(1, 2), complete=True)
counts = _review_metadata_counts([(None, 3, "skipped", "excluded"), (None, 4, "skipped", "inactive")], set())
assert counts == {"blocking_count": 0, "required_count": 0, "reviewed_required_count": 0, "bulk_acceptable_count": 0}
assert review.version.editor_state["review_send"]["reviewed_message_keys"] == ["entry-1", "entry-2"]
assert not review_decision_metadata(review.session.get(CampaignJob, "job-3"))["eligible"]
def test_final_review_cannot_override_remaining_hard_blockers(review):
review.session.add(_job(3, validation="blocked", build="build_failed", behavior="block"))
review.session.commit()
_save(review, ids=(1, 2))
with pytest.raises(HTTPException, match="Blocked or failed"):
_save(review, ids=(), complete=True)
assert review.version.editor_state["review_send"]["inspection_complete"] is False
def test_existing_frozen_blocker_is_not_reclassified_from_current_allowed_empty_settings(review):
job = review.session.get(CampaignJob, "job-1")
job.validation_status = "blocked"
job.build_status = "build_failed"
job.issues_snapshot = [{"code": "missing_required_attachment", "source": "attachments", "behavior": "block"}]
review.version.raw_json = {**review.version.raw_json, "attachments": {"missing_behavior": "continue", "send_without_attachments_behavior": "continue"}}
review.session.commit()
evidence = copy.deepcopy(job.issues_snapshot)
with pytest.raises(HTTPException):
_save(review, ids=(1,))
assert job.issues_snapshot == evidence and job.validation_status == "blocked"
def test_concurrent_database_write_is_409_without_losing_other_reviewer(review):
# Keep a genuinely stale ORM identity in a second transaction so the SQL
# version-column check, rather than just the request comparison, must fire.
with Session(review.engine) as stale_session:
stale = stale_session.get(CampaignVersion, "version-1")
assert stale is not None and stale.edit_revision == 1
_save(review, ids=(1,))
with pytest.raises(HTTPException) as error:
_save(review, ids=(2,), session=stale_session, base_revision=1)
assert error.value.status_code == 409
review.session.expire_all()
assert review.version.editor_state["review_send"]["reviewed_message_keys"] == ["entry-1"]
assert len(review.audits) == 1
def test_delivery_final_lock_rejects_incremental_acceptance(review):
review.version.workflow_state = "completed"
review.session.commit()
with pytest.raises(HTTPException) as error:
_save(review)
assert error.value.status_code == 409
assert "review_send" not in review.version.editor_state
def test_owner_denial_rejects_before_persisting_review(review):
with patch.object(routes, "_get_campaign_for_principal", side_effect=HTTPException(status_code=403, detail="Owner access denied")):
with pytest.raises(HTTPException) as error:
_save(review)
assert error.value.status_code == 403
assert "review_send" not in review.version.editor_state and review.audits == []
def test_progress_contract_requires_both_preconditions():
with pytest.raises(ValidationError, match="build_token and base_revision"):
CampaignReviewStateRequest(merge_progress=True, build_token="build-1")
@@ -0,0 +1,317 @@
"""Exercise real version routes/persistence without transport or filesystem effects."""
from __future__ import annotations
import copy
from types import SimpleNamespace
from unittest.mock import Mock, patch
import pytest
from fastapi import HTTPException
from sqlalchemy import Column, String, Table, create_engine
from sqlalchemy.orm import Session
from govoplan_campaign.backend import route_support
from govoplan_campaign.backend.archive_encryption import (
CampaignArchiveEncryptionError,
assert_archive_encryption_allowed,
stamp_legacy_zipcrypto_acknowledgements,
)
from govoplan_campaign.backend.campaign.mail_profile_boundary import (
CampaignMailProfileBoundaryError,
assert_campaign_uses_mail_profile_reference,
)
from govoplan_campaign.backend.db.models import Campaign, CampaignIssue, CampaignVersion
from govoplan_campaign.backend.integrations import MailProfileError
from govoplan_campaign.backend.persistence.campaigns import (
CampaignPersistenceError,
build_campaign_version,
load_campaign_config_from_json,
validate_campaign_version,
)
from govoplan_campaign.backend.schemas import CampaignVersionDetailResponse, CampaignVersionUpdateRequest
from govoplan_core.auth import ApiPrincipal
from govoplan_core.core.access import PrincipalRef
from govoplan_core.core.change_sequence import ChangeSequenceEntry
from govoplan_core.db.base import Base
def _principal(*scopes: str) -> ApiPrincipal:
return ApiPrincipal(
principal=PrincipalRef(
account_id="account-1", membership_id="user-1", tenant_id="tenant-1",
scopes=frozenset(scopes),
),
account=SimpleNamespace(id="account-1"),
user=SimpleNamespace(id="user-1"),
)
def _legacy() -> dict:
return {
"version": "1.0",
"campaign": {"id": "campaign-1", "name": "Campaign", "mode": "send"},
"server": {
"mail_profile_id": "profile-1",
"smtp": {"host": "old.example.test", "password": "stored-secret"},
"imap": None,
"credentials": {},
"inherit_smtp_credentials": True,
},
"recipients": {"from": [{"email": "sender@example.test"}]},
"template": {"subject": "Subject", "text": "Body", "body_mode": "text"},
"entries": {"inline": []},
"attachments": {"zip": {"enabled": True, "archives": [{
"id": "archive-1", "method": "zip_standard", "password_enabled": True,
"password_delivery_channel": "separate_mail",
}]}},
}
@pytest.fixture
def repair():
engine = create_engine("sqlite+pysqlite:///:memory:")
for name in ("access_users", "access_groups"):
if name not in Base.metadata.tables:
Table(name, Base.metadata, Column("id", String(36), primary_key=True))
Base.metadata.create_all(engine, tables=[
Base.metadata.tables["access_users"], Base.metadata.tables["access_groups"],
ChangeSequenceEntry.__table__, Campaign.__table__, CampaignVersion.__table__,
CampaignIssue.__table__,
])
with Session(engine) as session:
campaign = Campaign(
id="campaign-1", tenant_id="tenant-1", external_id="campaign-1",
name="Campaign", current_version_id="draft-1",
)
draft = CampaignVersion(id="draft-1", campaign_id=campaign.id, version_number=2, raw_json=_legacy())
history = CampaignVersion(id="history-1", campaign_id=campaign.id, version_number=1, raw_json=_legacy(), workflow_state="final")
session.add_all((campaign, draft, history))
session.commit()
audits: list[dict] = []
def audit(_session, _principal, **kwargs):
audits.append(kwargs)
if kwargs.get("commit"):
_session.commit()
integration = SimpleNamespace(assert_campaign_mail_policy_allows_json=Mock())
with (
patch.object(route_support, "_get_campaign_for_principal", return_value=campaign),
patch.object(route_support, "audit_from_principal", side_effect=audit),
patch("govoplan_campaign.backend.persistence.versions.mail_integration", return_value=integration),
patch("govoplan_campaign.backend.archive_encryption.get_registry", return_value=None),
):
yield SimpleNamespace(session=session, campaign=campaign, draft=draft, history=history, integration=integration, audits=audits)
engine.dispose()
def _public(repair) -> dict:
return CampaignVersionDetailResponse.model_validate(repair.draft).raw_json
def _save(repair, raw: dict, *, migrate: bool = False, principal=None):
return route_support._update_campaign_version_detail_response(
repair.session, principal or _principal("mail:profile:use"),
repair.campaign.id, repair.draft.id,
CampaignVersionUpdateRequest(
campaign_json=raw, base_revision=repair.draft.edit_revision,
migrate_legacy_mail_settings=migrate,
),
if_match=repair.draft.strong_etag, autosave=True,
audit_action="campaign.version_autosaved",
)
@pytest.mark.parametrize("mail_first", [True, False])
def test_independent_repairs_persist_in_either_order_without_altering_history(repair, mail_first):
original_zip = copy.deepcopy(repair.draft.raw_json["attachments"]["zip"])
original_server = copy.deepcopy(repair.draft.raw_json["server"])
first = _public(repair)
if not mail_first:
first["attachments"]["zip"]["archives"][0]["method"] = "aes"
result = _save(repair, first, migrate=mail_first)
repair.session.expire_all()
assert repair.draft.edit_revision == 2
assert result.mail_profile_migration_required is not mail_first
assert "stored-secret" not in repr(result)
assert repair.draft.build_summary is None
assert repair.draft.execution_snapshot is None
if mail_first:
assert repair.draft.raw_json["attachments"]["zip"] == original_zip
assert repair.draft.raw_json["server"] == {"mail_profile_id": "profile-1"}
# Real validation/build gates still reject the unresolved ZIP policy.
for action in (validate_campaign_version, build_campaign_version):
with patch(
"govoplan_campaign.backend.persistence.campaigns.load_version_config",
return_value=(repair.draft, None, object()),
), pytest.raises(CampaignPersistenceError, match="blocked"):
action(repair.session, tenant_id="tenant-1", version_id=repair.draft.id)
else:
assert repair.draft.raw_json["server"] == original_server
repair.integration.assert_campaign_mail_policy_allows_json.assert_not_called()
# The authoritative config loader still blocks legacy transport.
with pytest.raises(CampaignMailProfileBoundaryError, match="remove campaign-local"):
load_campaign_config_from_json(repair.session, tenant_id="tenant-1", raw_json=repair.draft.raw_json)
second = _public(repair)
if mail_first:
second["attachments"]["zip"]["archives"][0]["method"] = "aes"
result = _save(repair, second, migrate=not mail_first)
repair.session.expire_all()
assert repair.draft.edit_revision == 3
assert not result.mail_profile_migration_required
assert_campaign_uses_mail_profile_reference(repair.draft.raw_json)
assert_archive_encryption_allowed(repair.session, repair.campaign, repair.draft.raw_json)
assert repair.history.raw_json == _legacy()
assert len(repair.audits) == 2
assert repair.audits[0]["details"]["legacy_mail_settings_preserved"] is not mail_first
assert repair.audits[0]["details"]["legacy_mail_settings_migrated"] is mail_first
assert not any(item["details"]["legacy_zipcrypto_acknowledgements"] for item in repair.audits)
def test_zip_repair_does_not_require_use_of_unchanged_revoked_mail_profile(repair):
repair.integration.assert_campaign_mail_policy_allows_json.side_effect = MailProfileError("Profile revoked")
raw = _public(repair)
raw["attachments"]["zip"]["archives"][0]["method"] = "aes"
result = _save(repair, raw, principal=_principal())
assert result.mail_profile_migration_required
repair.integration.assert_campaign_mail_policy_allows_json.assert_not_called()
with pytest.raises(HTTPException) as denied:
_save(repair, _public(repair), migrate=True, principal=_principal())
assert denied.value.status_code == 403
assert "mail:profile:use" in denied.value.detail
with pytest.raises(HTTPException, match="Profile revoked"):
_save(repair, _public(repair), migrate=True)
assert repair.draft.mail_profile_migration_required
def test_archive_repair_is_saveable_after_mail_migration_and_a_stricter_credential_policy(repair):
_save(repair, _public(repair), migrate=True)
repair.integration.assert_campaign_mail_policy_allows_json.reset_mock()
repair.integration.assert_campaign_mail_policy_allows_json.side_effect = MailProfileError(
"SMTP credential policy requires an explicit credential selection"
)
raw = _public(repair)
raw["attachments"]["zip"]["archives"][0]["method"] = "aes"
result = _save(repair, raw, principal=_principal())
assert not result.mail_profile_migration_required
assert result.raw_json["server"] == {"mail_profile_id": "profile-1"}
assert result.raw_json["attachments"]["zip"]["archives"][0]["method"] == "aes"
repair.integration.assert_campaign_mail_policy_allows_json.assert_not_called()
changed_mail = _public(repair)
changed_mail["server"]["smtp_server_id"] = "smtp-1"
with pytest.raises(HTTPException) as missing_permission:
_save(repair, changed_mail, principal=_principal())
assert missing_permission.value.status_code == 403
with pytest.raises(HTTPException, match="explicit credential selection"):
_save(repair, changed_mail)
assert repair.draft.raw_json["server"] == {"mail_profile_id": "profile-1"}
@pytest.mark.parametrize("mutation", ["new_profile", "remove_profile", "credential", "inline", "echo_inline"])
def test_archive_save_cannot_modify_or_introduce_mail_transport_without_migration(repair, mutation):
raw = _public(repair)
raw["attachments"]["zip"]["archives"][0]["method"] = "aes"
if mutation == "new_profile":
raw["server"]["mail_profile_id"] = "other-profile"
elif mutation == "remove_profile":
raw["server"] = {}
elif mutation == "credential":
raw["server"].update(smtp_server_id="smtp-1", smtp_credential_id="credential-1")
elif mutation == "inline":
raw["server"]["smtp"] = {"password": "injected-secret"}
else:
raw["server"] = copy.deepcopy(repair.draft.raw_json["server"])
with pytest.raises(HTTPException):
_save(repair, raw)
assert repair.draft.raw_json == _legacy()
assert repair.draft.edit_revision == 1
@pytest.mark.parametrize("mutation", ["acknowledgement", "reason", "actor", "method", "channel", "typed_boolean"])
def test_mail_migration_cannot_grandfather_modified_zip_settings(repair, mutation):
raw = _public(repair)
archive = raw["attachments"]["zip"]["archives"][0]
if mutation == "typed_boolean":
archive["password_enabled"] = 1 # Python True == 1 is not exact JSON equality.
elif mutation == "method":
archive["method"] = "unknown"
elif mutation == "channel":
archive["method"] = "aes"
archive["password_delivery_channel"] = "same_mail"
else:
archive[{
"acknowledgement": "legacy_zipcrypto_acknowledged",
"reason": "legacy_zipcrypto_reason",
"actor": "legacy_zipcrypto_acknowledged_by",
}[mutation]] = True if mutation == "acknowledgement" else "forged evidence"
with pytest.raises(HTTPException):
_save(repair, raw, migrate=True)
assert repair.draft.raw_json == _legacy()
assert repair.draft.edit_revision == 1
def test_unchanged_zip_is_not_restamped_even_after_legacy_permission_revocation(repair):
raw = _public(repair)
archive = raw["attachments"]["zip"]["archives"][0]
archive.update(
legacy_zipcrypto_acknowledged=True,
legacy_zipcrypto_reason="Existing recipient compatibility requirement",
legacy_zipcrypto_acknowledged_by="original-actor",
legacy_zipcrypto_acknowledged_at="2026-08-01T10:00:00+00:00",
)
repair.draft.raw_json = {**copy.deepcopy(repair.draft.raw_json), "attachments": copy.deepcopy(raw["attachments"])}
repair.session.commit()
result = _save(repair, raw, migrate=True, principal=_principal("mail:profile:use"))
assert result.raw_json["attachments"]["zip"]["archives"][0] == archive
assert repair.audits[-1]["details"]["legacy_zipcrypto_acknowledgements"] == []
with pytest.raises(CampaignArchiveEncryptionError, match="blocked"):
assert_archive_encryption_allowed(repair.session, repair.campaign, repair.draft.raw_json)
with patch(
"govoplan_campaign.backend.archive_encryption.effective_archive_encryption_policy",
return_value=SimpleNamespace(
available=True, allowed_password_encryption_methods={"aes", "zip_standard"},
allowed_password_delivery_channels={"separate_mail"}, reason="Policy allows legacy",
),
), pytest.raises(CampaignArchiveEncryptionError, match="Missing scope"):
assert_archive_encryption_allowed(
repair.session, repair.campaign, repair.draft.raw_json,
principal=_principal("mail:profile:use"),
)
def test_unchanged_missing_zip_remains_noop_without_policy_lookup(repair):
with patch("govoplan_campaign.backend.archive_encryption.effective_archive_encryption_policy") as policy:
candidate, evidence = stamp_legacy_zipcrypto_acknowledgements(
repair.session, repair.campaign, {}, {"template": {"text": "New"}}, principal=_principal(),
)
assert candidate == {"template": {"text": "New"}}
assert evidence == []
policy.assert_not_called()
@pytest.mark.parametrize("target", ["individual", "global"])
def test_recipient_address_order_round_trips_through_the_real_save_route(repair, target):
addresses = [
{"name": "Zulu", "email": "zulu@example.test"},
{"name": "Alpha", "email": "alpha@example.test"},
{"name": "Beta", "email": "beta@example.test"},
]
raw = _public(repair)
if target == "individual":
raw["entries"]["inline"] = [{"id": "entry-1", "to": addresses}]
else:
raw["recipients"]["to"] = addresses
result = _save(repair, raw, principal=_principal("campaigns:recipient:write"))
repair.session.expire_all()
persisted = repair.session.get(CampaignVersion, "draft-1")
assert persisted is not None
if target == "individual":
assert persisted.raw_json["entries"]["inline"][0]["to"] == addresses
assert result.raw_json["entries"]["inline"][0]["to"] == addresses
else:
assert persisted.raw_json["recipients"]["to"] == addresses
assert result.raw_json["recipients"]["to"] == addresses
assert persisted.mail_profile_migration_required
assert persisted.edit_revision == 2
+54
View File
@@ -1,6 +1,8 @@
from __future__ import annotations
import unittest
from types import SimpleNamespace
from unittest.mock import patch
from fastapi import HTTPException
from sqlalchemy import create_engine
@@ -12,6 +14,8 @@ from govoplan_campaign.backend.services.job_queries import (
_campaign_jobs_grid_filter_expressions,
_campaign_jobs_ordering,
_campaign_jobs_page_response,
_campaign_jobs_query_context,
_public_recipient_groups,
)
from govoplan_core.core.change_sequence import ChangeSequenceEntry
from govoplan_core.db.base import Base
@@ -119,6 +123,56 @@ class CampaignJobListQueryTests(unittest.TestCase):
self.assertEqual(raised.exception.status_code, 422)
def test_recipient_projection_preserves_each_group_order_without_extra_fields(self) -> None:
recipients = {"to": [{"email": "second@example.test", "name": "Second", "secret": "never-project"},
{"email": "first@example.test"}],
"cc": [{"email": "copy@example.test"}], "bcc": [{"email": "blind@example.test"}],
"from": {"email": "sender@example.test"}, "private": "never-project"}
result = _public_recipient_groups(recipients)
self.assertEqual(list(result), ["to", "cc", "bcc"])
self.assertEqual([value["email"] for value in result["to"]], ["second@example.test", "first@example.test"])
self.assertNotIn("never-project", str(result))
def test_each_frozen_recipient_group_is_searchable_before_pagination(self) -> None:
row = self.session.get(CampaignJob, "job-0")
row.resolved_recipients = {"to": [{"email": "second-to@example.test"}],
"cc": [{"email": "copy@example.test"}], "bcc": [{"email": "blind@example.test"}]}
self.session.commit()
for recipient in ("second-to", "copy@", "blind@"):
with self.subTest(recipient=recipient):
filters = _campaign_jobs_grid_filter_expressions({"recipient": recipient})
page = _campaign_jobs_page_response(self.session, campaign_id="campaign-1", version_id="version-1",
base_filters=[CampaignJob.tenant_id == "tenant-1"], filtered=filters,
reviewed_keys=set(), review_metadata={}, page=1, page_size=1, grid_filters={"recipient": recipient})
self.assertEqual(page.total, 1)
self.assertEqual(page.jobs[0]["id"], "job-0")
self.assertEqual(page.jobs[0]["resolved_recipients"]["bcc"], [{"email": "blind@example.test"}])
def test_free_search_also_matches_additional_recipients_and_keeps_tenant_scope(self) -> None:
row = self.session.get(CampaignJob, "job-0")
row.resolved_recipients = {"bcc": [{"email": "additional@example.test"}]}
other = self.session.get(CampaignJob, "job-1")
other.tenant_id = "other-tenant"
other.resolved_recipients = row.resolved_recipients
self.session.commit()
principal = SimpleNamespace(tenant_id="tenant-1", has=lambda scope: scope == "campaigns:recipient:read")
with patch("govoplan_campaign.backend.services.job_queries._get_campaign_for_principal"), \
patch("govoplan_campaign.backend.services.job_queries._get_campaign_for_tenant", return_value=SimpleNamespace(id="campaign-1")), \
patch("govoplan_campaign.backend.services.job_queries._review_metadata", return_value=({}, set())):
_, _, filters, _, _ = _campaign_jobs_query_context(self.session, principal, campaign_id="campaign-1", version_id=None,
send_status=None, validation_status=None, imap_status=None, query_text="additional@example.test")
self.assertEqual([job.id for job in self.session.query(CampaignJob).filter(*filters)], ["job-0"])
def test_recipient_read_is_required_before_additional_addresses_are_queried(self) -> None:
principal = SimpleNamespace(tenant_id="tenant-1", has=lambda _scope: False)
with patch("govoplan_campaign.backend.services.job_queries._get_campaign_for_principal"), \
patch("govoplan_campaign.backend.services.job_queries._get_campaign_for_tenant") as lookup:
with self.assertRaises(HTTPException) as raised:
_campaign_jobs_query_context(self.session, principal, campaign_id="campaign-1", version_id=None,
send_status=None, validation_status=None, imap_status=None, query_text="blind@example.test")
self.assertEqual(raised.exception.status_code, 403)
lookup.assert_not_called()
def test_skipped_transport_filters_and_counts_remain_separate(self) -> None:
base_filters = [CampaignJob.tenant_id == "tenant-1", CampaignJob.campaign_id == "campaign-1"]
grid_filters = {"send": 'list:["skipped"]', "imap": 'list:["skipped"]'}
+135 -3
View File
@@ -1,10 +1,12 @@
from __future__ import annotations
from types import SimpleNamespace
from unittest.mock import call, patch
from unittest.mock import Mock, call, patch
import pytest
from fastapi import HTTPException
from sqlalchemy import Column, String, Table, create_engine
from sqlalchemy.orm import Session
from govoplan_campaign.backend import route_support
from govoplan_campaign.backend.routes import attachments as attachment_routes
@@ -17,11 +19,14 @@ from govoplan_campaign.backend.campaign.mail_profile_boundary import (
campaign_mail_profile_id,
)
from govoplan_campaign.backend.campaign.models import DeliveryConfig
from govoplan_campaign.backend.db.models import Campaign, CampaignIssue, CampaignVersion
from govoplan_campaign.backend.persistence.campaigns import CampaignPersistenceError, load_campaign_config_from_json
from govoplan_campaign.backend.persistence.versions import update_campaign_version
from govoplan_campaign.backend.integrations import MailCampaignIntegration
from govoplan_campaign.backend.persistence.versions import _updated_runtime_json, update_campaign_version
from govoplan_campaign.backend.integrations import MailCampaignIntegration, MailProfileError
from govoplan_campaign.backend.sending.execution import ExecutionSnapshotError, create_execution_snapshot, ensure_execution_snapshot
from govoplan_campaign.backend.schemas import CampaignVersionUpdateRequest
from govoplan_core.core.change_sequence import ChangeSequenceEntry
from govoplan_core.db.base import Base
def _campaign_json(server: dict[str, object] | None = None) -> dict[str, object]:
@@ -237,6 +242,133 @@ def test_editing_a_legacy_record_requires_an_explicit_profile_migration() -> Non
assert legacy_raw["server"]["smtp"]["password"] == "secret" # type: ignore[index]
def test_explicit_legacy_migration_accepts_an_unchanged_authorized_profile_reference() -> None:
legacy = _campaign_json({
"mail_profile_id": "profile-1",
"smtp": {"host": "smtp.example.test", "password": "legacy-secret"},
"imap": None,
"credentials": {},
"inherit_smtp_credentials": True,
"inherit_imap_credentials": True,
})
submitted = _campaign_json({"mail_profile_id": "profile-1"})
integration = SimpleNamespace(assert_campaign_mail_policy_allows_json=Mock())
session = object()
with patch("govoplan_campaign.backend.persistence.versions.mail_integration", return_value=integration):
result = _updated_runtime_json(
session, # type: ignore[arg-type]
tenant_id="tenant-1",
campaign=SimpleNamespace(id="campaign-1"),
version=SimpleNamespace(raw_json=legacy),
raw_json=submitted,
source_base_path=None,
migrate_legacy_mail_settings=True,
)
assert result == submitted
assert result is not submitted
assert campaign_mail_profile_boundary_violations(result) == ()
assert "legacy-secret" not in repr(result)
assert legacy["server"]["smtp"]["password"] == "legacy-secret" # type: ignore[index]
integration.assert_campaign_mail_policy_allows_json.assert_called_once_with(
session, tenant_id="tenant-1", raw_json=result, campaign_id="campaign-1"
)
def test_explicit_legacy_migration_requires_a_profile_and_preserves_mail_authorization() -> None:
legacy = _campaign_json({"smtp": {"password": "legacy-secret"}})
integration = SimpleNamespace(assert_campaign_mail_policy_allows_json=Mock(
side_effect=MailProfileError("Mail profile is not authorized for this campaign")
))
with patch("govoplan_campaign.backend.persistence.versions.mail_integration", return_value=integration):
for submitted, expected_error in (
(_campaign_json(), CampaignPersistenceError),
(_campaign_json({"mail_profile_id": "unauthorized-profile"}), MailProfileError),
(_campaign_json({"mail_profile_id": "profile-1", "smtp": {}}), CampaignMailProfileBoundaryError),
):
with pytest.raises(expected_error):
_updated_runtime_json(
object(), # type: ignore[arg-type]
tenant_id="tenant-1",
campaign=SimpleNamespace(id="campaign-1"),
version=SimpleNamespace(raw_json=legacy),
raw_json=submitted,
source_base_path=None,
migrate_legacy_mail_settings=True,
)
assert integration.assert_campaign_mail_policy_allows_json.call_count == 1
assert legacy["server"]["smtp"]["password"] == "legacy-secret" # type: ignore[index]
def test_persisted_legacy_draft_can_migrate_then_save_other_content_without_changing_history() -> None:
engine = create_engine("sqlite+pysqlite:///:memory:")
for table_name in ("access_users", "access_groups"):
if table_name not in Base.metadata.tables:
Table(table_name, Base.metadata, Column("id", String(36), primary_key=True))
Base.metadata.create_all(engine, tables=[
Base.metadata.tables["access_users"],
Base.metadata.tables["access_groups"],
ChangeSequenceEntry.__table__,
Campaign.__table__,
CampaignVersion.__table__,
CampaignIssue.__table__,
])
legacy = _campaign_json({
"mail_profile_id": "profile-1",
"smtp": {"host": "old.example.test", "password": "historical-secret"},
"imap": None,
"credentials": {},
"inherit_smtp_credentials": True,
"inherit_imap_credentials": True,
})
integration = SimpleNamespace(assert_campaign_mail_policy_allows_json=Mock())
try:
with Session(engine) as session, patch(
"govoplan_campaign.backend.persistence.versions.mail_integration", return_value=integration
):
campaign = Campaign(id="campaign-1", tenant_id="tenant-1", external_id="campaign-1", name="Campaign", current_version_id="draft-1")
historical = CampaignVersion(id="history-1", campaign_id=campaign.id, version_number=1, raw_json=legacy, workflow_state="final")
draft = CampaignVersion(id="draft-1", campaign_id=campaign.id, version_number=2, raw_json=legacy, editor_state={"created_from": "minimal_campaign"})
session.add_all((campaign, historical, draft))
session.commit()
original_revision = draft.edit_revision
assert draft.mail_profile_migration_required
migrated = update_campaign_version(
session,
tenant_id="tenant-1", campaign_id=campaign.id, version_id=draft.id,
raw_json=_campaign_json({"mail_profile_id": "profile-1"}),
editor_state={"created_from": "minimal_campaign"},
expected_revision=original_revision,
migrate_legacy_mail_settings=True,
autosave=True,
)
session.expire_all()
persisted = session.get(CampaignVersion, migrated.id)
assert persisted is not None
assert not persisted.mail_profile_migration_required
assert persisted.raw_json["server"] == {"mail_profile_id": "profile-1"}
assert persisted.edit_revision > original_revision
assert persisted.autosaved_at is not None
assert "historical-secret" not in repr(persisted.raw_json)
assert session.get(CampaignVersion, historical.id).raw_json == legacy
edited = _campaign_json({"mail_profile_id": "profile-1"})
edited["template"]["subject"] = "Edited after migration" # type: ignore[index]
updated = update_campaign_version(
session,
tenant_id="tenant-1", campaign_id=campaign.id, version_id=persisted.id,
raw_json=edited,
expected_revision=persisted.edit_revision,
)
session.expire_all()
assert session.get(CampaignVersion, updated.id).raw_json["template"]["subject"] == "Edited after migration"
assert session.get(CampaignVersion, historical.id).raw_json == legacy
assert integration.assert_campaign_mail_policy_allows_json.call_count == 1
finally:
engine.dispose()
def test_fork_inherited_profile_requires_mail_profile_use_scope() -> None:
principal = SimpleNamespace(
tenant_id="tenant-1",
+142
View File
@@ -0,0 +1,142 @@
"""Mock accepted exceptions using real frozen jobs/EML, never new live effects."""
from __future__ import annotations
import copy
import hashlib
from email import policy
from email.message import EmailMessage
from types import SimpleNamespace
from unittest.mock import Mock, patch
import pytest
from test_incremental_review_persistence import review, _save
from govoplan_campaign.backend.campaign.models import DeliveryConfig
from govoplan_campaign.backend.db.models import CampaignJob
from govoplan_campaign.backend.dev import mock_campaign
from govoplan_campaign.backend.persistence.campaigns import CampaignPersistenceError
from govoplan_campaign.backend.sending.execution import ExecutionSnapshotError, create_execution_snapshot
@pytest.fixture
def frozen(review, tmp_path):
review.version.raw_json = {**review.version.raw_json, "server": {"mail_profile_id": "profile-1"}}
jobs = review.session.query(CampaignJob).order_by(CampaignJob.entry_index).all()
for job in jobs:
job.subject = f"Frozen subject {job.entry_index}"
job.resolved_recipients = {"from": {"email": "sender@example.test"}, "to": [{"email": f"recipient-{job.entry_index}@example.test"}]}
job.issues_snapshot = [{**item, "severity": "warning", "message": "Explicit attachment exception"} for item in job.issues_snapshot]
message = EmailMessage()
message["From"] = "sender@example.test"
message["To"] = f"recipient-{job.entry_index}@example.test"
message["Subject"] = job.subject
message["Date"] = "Mon, 07 Sep 2026 09:00:00 +0200"
message["Message-ID"] = f"<frozen-{job.entry_index}@example.test>"
message.set_content(f"Frozen reviewed body {job.entry_index}")
payload = message.as_bytes(policy=policy.SMTP)
path = tmp_path / f"message-{job.entry_index}.eml"
path.write_bytes(payload)
job.eml_local_path = str(path)
job.eml_size_bytes = len(payload)
job.eml_sha256 = hashlib.sha256(payload).hexdigest()
job.message_id_header = str(message["Message-ID"])
review.session.flush()
payload, digest = create_execution_snapshot(review.version, mail_profile_id="profile-1",
smtp_transport_revision="smtp-1", imap_transport_revision="imap-1", delivery=DeliveryConfig(),
jobs=jobs, build_summary=review.version.build_summary)
review.version.execution_snapshot = payload
review.version.execution_snapshot_hash = digest
review.session.commit()
_save(review, ids=(1, 2), complete=True)
mailbox = Mock()
mailbox.consume_fail_next_smtp.return_value = False
mailbox.consume_fail_next_imap.return_value = False
mailbox.get_failures.return_value = {}
mailbox.record_smtp_delivery.return_value = SimpleNamespace(id="mock-1")
mailbox.record_imap_append.return_value = SimpleNamespace(id="mock-imap-1")
mailbox.list_records.return_value = []
with (
patch.object(mock_campaign, "_mock_mailbox", return_value=mailbox),
patch("govoplan_campaign.backend.sending.execution.files_integration", return_value=SimpleNamespace(available=False)),
patch("govoplan_campaign.backend.sending.execution.assert_archive_encryption_allowed", return_value=SimpleNamespace(policy_hash="archive-policy")),
patch("govoplan_campaign.backend.sending.execution.profile_delivery_summary", return_value={"smtp_transport_revision": "smtp-1", "imap_transport_revision": "imap-1"}) as transport,
):
yield SimpleNamespace(**vars(review), jobs=jobs, mailbox=mailbox, transport=transport)
def _run(frozen, **options):
return mock_campaign.run_mock_campaign_send(frozen.session, tenant_id="tenant-1", campaign_id="campaign-1", version_id="version-1",
use_reviewed_build=True, include_needs_review=False, send=True, **options)
def test_mock_reuses_reviewed_frozen_bytes_and_decisions_without_reasking_or_mutating_campaign(frozen):
original = copy.deepcopy(frozen.version.editor_state)
revision = frozen.version.edit_revision
with patch.object(mock_campaign, "_build_mock_campaign_run", side_effect=AssertionError("Do not rebuild reviewed messages")):
result = _run(frozen)
assert result["send"]["sent_count"] == 2 and result["send"]["skipped_count"] == 0
assert result["use_reviewed_build"] is True and result["build"]["review_satisfied"] is True
assert [step["status"] for step in result["steps"]] == ["ok", "ok", "ok", "ok"]
assert frozen.mailbox.record_smtp_delivery.call_count == 2
captured = frozen.mailbox.record_smtp_delivery.call_args_list[0].args[0]
assert str(captured["Message-ID"]) == "<frozen-1@example.test>"
assert "Frozen reviewed body 1" in captured.get_content()
frozen.session.expire_all()
assert frozen.version.editor_state == original and frozen.version.edit_revision == revision
assert all(job.send_status == "not_queued" for job in frozen.jobs)
@pytest.mark.parametrize("mutation", ["partial", "build", "issue", "reason_evidence", "configuration", "snapshot", "bytes", "transport", "imap"])
def test_invalid_frozen_review_stops_before_mock_capture_or_mailbox_clear(frozen, mutation):
if mutation == "partial":
state = copy.deepcopy(frozen.version.editor_state)
state["review_send"]["inspection_complete"] = False
frozen.version.editor_state = state
elif mutation == "build":
frozen.version.build_summary = {"build_token": "different-build", "built_count": 2}
elif mutation == "issue":
frozen.jobs[1].issues_snapshot = [{"code": "new-hard-block", "source": "attachments", "behavior": "block", "severity": "error", "message": "Missing required attachment"}]
elif mutation == "reason_evidence":
state = copy.deepcopy(frozen.version.editor_state)
state["review_send"]["issue_decisions"][0]["issue_fingerprint"] = "f" * 64
frozen.version.editor_state = state
elif mutation == "configuration":
frozen.version.raw_json = {**frozen.version.raw_json, "template": {"subject": "Unreviewed changed subject"}}
elif mutation == "snapshot":
frozen.version.execution_snapshot = None
elif mutation == "bytes":
from pathlib import Path
Path(frozen.jobs[1].eml_local_path).write_bytes(b"changed bytes")
else:
frozen.transport.return_value = {"smtp_transport_revision": "changed" if mutation == "transport" else "smtp-1", "imap_transport_revision": "changed" if mutation == "imap" else "imap-1"}
frozen.session.flush()
with pytest.raises((mock_campaign.MockCampaignSendError, ExecutionSnapshotError, CampaignPersistenceError)):
_run(frozen, clear_mailbox=True)
frozen.mailbox.record_smtp_delivery.assert_not_called()
frozen.mailbox.record_imap_append.assert_not_called()
frozen.mailbox.clear_records.assert_not_called()
def test_policy_dropped_frozen_message_stays_skipped_even_with_ask_evidence(frozen):
excluded = frozen.jobs[1]
excluded.validation_status = "excluded"
excluded.send_status = "skipped"
excluded.imap_status = "skipped"
payload, digest = create_execution_snapshot(frozen.version, mail_profile_id="profile-1", smtp_transport_revision="smtp-1",
imap_transport_revision="imap-1", delivery=DeliveryConfig(), jobs=frozen.jobs, build_summary=frozen.version.build_summary)
frozen.version.execution_snapshot = payload
frozen.version.execution_snapshot_hash = digest
state = copy.deepcopy(frozen.version.editor_state)
state["review_send"]["reviewed_message_keys"] = ["entry-1"]
state["review_send"]["issue_decisions"] = state["review_send"]["issue_decisions"][:1]
frozen.version.editor_state = state
frozen.session.commit()
result = _run(frozen)
assert result["send"]["sent_count"] == 1 and result["send"]["skipped_count"] == 1
assert frozen.mailbox.record_smtp_delivery.call_count == 1
def test_default_authoring_mock_still_uses_transient_preview(frozen):
with patch.object(mock_campaign, "_build_mock_campaign_run", side_effect=RuntimeError("authoring preview path")):
with pytest.raises(RuntimeError, match="authoring preview path"):
mock_campaign.run_mock_campaign_send(frozen.session, tenant_id="tenant-1", campaign_id="campaign-1", send=False)
+13 -1
View File
@@ -8,11 +8,13 @@ from govoplan_campaign.backend.routes.assignments import router as assignments_r
from govoplan_campaign.backend.routes.campaigns import router as campaigns_router
from govoplan_campaign.backend.routes.collaboration import router as collaboration_router
from govoplan_campaign.backend.routes.delivery import router as delivery_router
from govoplan_campaign.backend.routes.delivery_settings import router as delivery_settings_router
from govoplan_campaign.backend.routes.jobs import router as jobs_router
from govoplan_campaign.backend.routes.operations import router as operations_router
from govoplan_campaign.backend.routes.reports import router as reports_router
from govoplan_campaign.backend.routes.schedules import router as schedules_router
from govoplan_campaign.backend.routes.sharing import router as sharing_router
from govoplan_campaign.backend.routes.transfers import router as transfers_router
from govoplan_campaign.backend.routes.versions import router as versions_router
@@ -26,7 +28,9 @@ def _operation_keys(candidate_router) -> list[tuple[str, str]]:
def test_campaign_router_composes_every_workflow_operation_once() -> None:
workflow_routers = (
delivery_settings_router,
operations_router,
transfers_router,
campaigns_router,
assignments_router,
collaboration_router,
@@ -46,17 +50,25 @@ def test_campaign_router_composes_every_workflow_operation_once() -> None:
actual = _operation_keys(router)
assert actual == expected
assert len(actual) == 93
assert len(actual) == 100
assert not [operation for operation, count in Counter(actual).items() if count > 1]
def test_key_routes_are_owned_by_their_focused_router() -> None:
expectations = (
(delivery_settings_router, ("GET", "/campaigns/settings/delivery-policy/{scope}")),
(delivery_settings_router, ("PUT", "/campaigns/settings/delivery-policy/{scope}")),
(delivery_router, ("GET", "/campaigns/{campaign_id}/delivery-progress")),
(delivery_router, ("POST", "/campaigns/{campaign_id}/jobs/{job_id}/recover-claim")),
(
operations_router,
("POST", "/campaigns/operations/artifacts/reconcile"),
),
(campaigns_router, ("GET", "/campaigns/{campaign_id}/workspace")),
(
transfers_router,
("POST", "/campaign-transfers/imports/preview"),
),
(collaboration_router, ("POST", "/campaigns/{campaign_id}/collaboration")),
(assignments_router, ("POST", "/campaigns/{campaign_id}/assignments")),
(versions_router, ("POST", "/campaigns/versions/{version_id}/build")),
+4
View File
@@ -49,6 +49,8 @@ def test_send_now_omits_provider_and_recipient_text_from_response_and_audit() ->
"source": "deployment_default",
"deployment_max_recipient_jobs": 25,
"tenant_max_recipient_jobs": None,
"system_max_recipient_jobs": 200,
"deployment_ceiling_explicit": False,
"provider_diagnostic": "provider-secret-policy",
},
results=[
@@ -107,6 +109,8 @@ def test_send_now_omits_provider_and_recipient_text_from_response_and_audit() ->
"source": "deployment_default",
"deployment_max_recipient_jobs": 25,
"tenant_max_recipient_jobs": None,
"system_max_recipient_jobs": 200,
"deployment_ceiling_explicit": False,
}
audit_details = audit.call_args.kwargs["details"]
+67 -1
View File
@@ -8,6 +8,7 @@ import pytest
from fastapi import HTTPException
from govoplan_campaign.backend import router as campaign_api
from govoplan_core.tenancy.scope import Tenant
from govoplan_campaign.backend.routes import delivery as router
from govoplan_campaign.backend.delivery_policy import (
CampaignDeliveryPolicyError,
@@ -20,8 +21,14 @@ from govoplan_campaign.backend.db.models import (
JobSendStatus,
JobValidationStatus,
)
from govoplan_campaign.backend.integrations import (
MailProfileError,
SmtpConfigurationError,
SmtpSendError,
)
from govoplan_campaign.backend.sending.jobs import (
QueueCampaignResult,
SendJobError,
SynchronousSendRejected,
_ensure_synchronous_send_count_allowed,
_pause_jobs_after_systemic_smtp_failure,
@@ -39,7 +46,7 @@ class _PolicySession:
self.tenant = SimpleNamespace(settings=settings or {})
def get(self, _model, _id):
return self.tenant
return self.tenant if _model is Tenant else None
def _version() -> SimpleNamespace:
@@ -218,6 +225,65 @@ def test_post_queue_growth_is_rejected_before_batch_or_provider_preflight() -> N
batch_preflight.assert_not_called()
@pytest.mark.parametrize(
("error", "reason", "message", "fails_on_exit"),
[
(MailProfileError("private credential detail"), "mail_profile_preflight_failed", "credential selection", False),
(SmtpConfigurationError("private credential detail"), "smtp_configuration_preflight_failed", "SMTP configuration", False),
(SmtpSendError("private credential detail", reason_code="smtp_authentication_failed"), "smtp_authentication_failed", "SMTP authentication failed", False),
(SmtpSendError("private credential detail", reason_code="smtp_preflight_rejected"), "smtp_preflight_rejected", "server rejected", False),
(SmtpSendError("private credential detail", reason_code="private provider code"), "smtp_connectivity_unavailable", "connectivity", False),
(OSError("private credential detail"), "smtp_connectivity_unavailable", "connectivity", False),
(OSError("private credential detail"), None, "Messages may already have been sent", True),
],
)
def test_smtp_preflight_errors_distinguish_policy_configuration_and_connection_without_secrets(
error: Exception, reason: str | None, message: str, fails_on_exit: bool,
) -> None:
session = Mock()
campaign = SimpleNamespace(id="campaign-1")
job = _job("one", queue_status="queued", send_status="queued")
policy = effective_synchronous_send_policy(_PolicySession(), tenant_id="tenant-1", environ={})
@contextmanager
def rejected_connection():
if fails_on_exit:
yield SimpleNamespace(connection_count=1, reconnect_count=0)
raise error
with (
patch("govoplan_campaign.backend.sending.jobs._get_campaign_for_tenant", return_value=campaign),
patch("govoplan_campaign.backend.sending.jobs._get_current_version", return_value=_version()),
patch("govoplan_campaign.backend.sending.jobs._ensure_version_validated_and_locked"),
patch("govoplan_campaign.backend.sending.jobs._ensure_campaign_execution_snapshot"),
patch("govoplan_campaign.backend.sending.jobs.effective_synchronous_send_policy", return_value=policy),
patch("govoplan_campaign.backend.sending.jobs._campaign_jobs_for_queue", return_value=[job]),
patch("govoplan_campaign.backend.sending.jobs.queue_campaign_jobs") as queue,
patch("govoplan_campaign.backend.sending.jobs._campaign_jobs_for_version", return_value=[job]),
patch("govoplan_campaign.backend.sending.jobs._preflight_synchronous_send_batch", return_value={"one": Mock()}),
patch("govoplan_campaign.backend.sending.jobs._synchronous_smtp_batch_manager", return_value=rejected_connection()),
patch("govoplan_campaign.backend.sending.jobs._deliver_job_with_recovery", return_value=SimpleNamespace(status="smtp_accepted", as_dict=lambda: {"status": "smtp_accepted"})) as deliver,
pytest.raises(SendJobError if fails_on_exit else SynchronousSendRejected) as rejected,
):
send_campaign_now(session, tenant_id="tenant-1", campaign_id=campaign.id)
assert message in str(rejected.value)
assert "private" not in str(rejected.value)
assert queue.call_args.kwargs["commit_queue"] is False
session.rollback.assert_called_once_with()
if fails_on_exit:
assert "no message was sent" not in str(rejected.value)
session.commit.assert_called_once_with()
deliver.assert_called_once()
else:
assert rejected.value.reason == reason
assert "no message was sent" in str(rejected.value)
assert "private" not in str(rejected.value.audit_details())
assert rejected.value.eligible_count == 1
session.commit.assert_not_called()
deliver.assert_not_called()
@pytest.mark.parametrize(
("workers_available", "expected_mode", "expected_enqueued"),
((False, "database_queue", 0), (True, "worker_queue", 1)),
+183
View File
@@ -0,0 +1,183 @@
"""Disposable SQLite and in-process HTTP only; never run Docker or a mail provider."""
from __future__ import annotations
import sqlite3
from types import SimpleNamespace
from unittest.mock import Mock
import pytest
from fastapi import FastAPI
from fastapi.testclient import TestClient
from sqlalchemy import create_engine
from sqlalchemy.orm import sessionmaker
from govoplan_campaign.backend.db.models import Campaign, CampaignVersion, SendAttempt
from govoplan_campaign.backend.routes import delivery as routes
from govoplan_campaign.backend.sending import jobs
from govoplan_core.auth import ApiPrincipal, get_api_principal
from govoplan_core.core.access import PrincipalRef
from govoplan_core.core.recovery import RecoveryOperation, verify_recovery_evidence_chain
from govoplan_core.db.session import get_session
from test_mail_testbed_acceptance import runner, _settings, _Response, FIXTURE_PATH
from test_workerless_recovery import recovery, _stale_claim # noqa: F401
@pytest.fixture
def fixture_claim(recovery, tmp_path, monkeypatch):
root = tmp_path / "govoplan-campaign-greenmail-regression"
root.mkdir()
database_file = root / "acceptance.db"
with recovery.engine.connect() as source, sqlite3.connect(database_file) as target:
source.connection.driver_connection.backup(target)
engine = create_engine(f"sqlite:///{database_file}")
factory = sessionmaker(engine)
session = factory()
fixture = SimpleNamespace(
session=session, factory=factory, engine=engine, root=root,
campaign=session.get(Campaign, "campaign"), version=session.get(CampaignVersion, "version"),
snapshot=recovery.snapshot, provider=recovery.provider,
)
monkeypatch.setattr(jobs, "get_database", lambda: SimpleNamespace(SessionLocal=factory))
job, lease, node, operation_id = _stale_claim(fixture, expired=False, owner="active")
node.metadata_ = {"acceptance_worker_pid": 12345}
session.commit()
fixture.job, fixture.lease, fixture.node, fixture.operation_id = job, lease, node, operation_id
fixture.process = SimpleNamespace(pid=12345, returncode=-9, poll=lambda: -9)
monkeypatch.setenv("APP_ENV", "test")
monkeypatch.setenv("DATABASE_URL", f"sqlite:///{database_file}")
monkeypatch.setattr(runner.tempfile, "gettempdir", lambda: str(tmp_path))
yield fixture
session.close()
engine.dispose()
def _recover(fixture, client):
return runner.recover_stopped_fixture_claim(
client, {}, database=SimpleNamespace(engine=fixture.engine, SessionLocal=fixture.factory),
runtime_root=fixture.root, campaign_id="campaign", version_id="version", stopped_process=fixture.process,
)
def test_fixture_proof_calls_actual_fenced_http_action_without_replaying_smtp(fixture_claim, monkeypatch):
fixture = fixture_claim
app = FastAPI()
app.include_router(routes.router, prefix="/api/v1")
actor = SimpleNamespace(id="operator")
scopes = frozenset({"campaigns:campaign:reconcile", "campaigns:recipient:read"})
app.dependency_overrides[get_api_principal] = lambda: ApiPrincipal(
principal=PrincipalRef(account_id="operator", membership_id="operator", tenant_id="tenant", scopes=scopes),
user=actor, account=actor,
)
def session_dependency():
with fixture.factory() as session:
yield session
app.dependency_overrides[get_session] = session_dependency
monkeypatch.setattr(routes, "_get_campaign_for_principal", lambda session, *_args, **_kwargs: session.get(Campaign, "campaign"))
monkeypatch.setattr(routes, "audit_from_principal", lambda session, *_args, **_kwargs: session.commit())
with TestClient(app) as client:
evidence = _recover(fixture, client)
assert evidence == {"stopped_process_verified": True, "fixture_lease_expired": True, "explicit_fenced_recovery": True}
fixture.session.expire_all()
assert fixture.job.send_status == "outcome_unknown"
assert fixture.job.claim_token is None
assert fixture.session.query(SendAttempt).one().status == "outcome_unknown"
assert fixture.session.query(SendAttempt).one().finished_at is not None
assert fixture.session.get(RecoveryOperation, fixture.operation_id).status == "outcome_unknown"
assert verify_recovery_evidence_chain(fixture.session, fixture.operation_id)
assert fixture.lease.fencing_token > 1
fixture.provider.send_campaign_email_bytes.assert_not_called()
@pytest.mark.parametrize("unsafe", ["production", "foreign_database", "live_process", "wrong_pid", "different_incarnation"])
def test_fixture_claim_proof_rejects_unsafe_target_or_process_without_state_changes(fixture_claim, monkeypatch, unsafe):
fixture = fixture_claim
if unsafe == "production":
monkeypatch.setenv("APP_ENV", "production")
elif unsafe == "foreign_database":
monkeypatch.setenv("DATABASE_URL", "sqlite:////tmp/a-different-database.db")
elif unsafe == "live_process":
fixture.process = SimpleNamespace(pid=12345, returncode=None, poll=lambda: None)
elif unsafe == "wrong_pid":
fixture.process = SimpleNamespace(pid=22222, returncode=-9, poll=lambda: -9)
else:
fixture.node.incarnation = "new-worker-incarnation"
fixture.session.commit()
original_expiry = fixture.lease.expires_at
client = Mock()
with pytest.raises(runner.AcceptanceError):
_recover(fixture, client)
client.post.assert_not_called()
fixture.session.expire_all()
assert fixture.job.send_status == "sending"
assert fixture.job.claim_token == "stale-token"
assert fixture.node.state == "active"
assert fixture.lease.expires_at == original_expiry
assert fixture.session.get(RecoveryOperation, fixture.operation_id).status == "running"
@pytest.mark.parametrize("duplicate_mutates", [False, True])
def test_process_restart_requires_unchanged_claim_before_explicit_recovery(monkeypatch, duplicate_mutates):
interrupted = {"job_count": 1, "send_status_counts": {"sending": 1}, "attempt_status_counts": {"smtp_in_progress": 1}, "unfinished_attempt_count": 1}
recovered = {"job_count": 1, "send_status_counts": {"outcome_unknown": 1}, "attempt_status_counts": {"outcome_unknown": 1}, "unfinished_attempt_count": 0}
states = iter([interrupted, recovered if duplicate_mutates else interrupted, recovered])
first, second = Mock(), Mock()
first.poll.return_value = -9
workers = iter([first, second])
prepared = SimpleNamespace(campaign_id="campaign", version_id="version", public_evidence=lambda: {})
monkeypatch.setattr(runner, "prepare_campaign_scenario", lambda *_args, **_kwargs: prepared)
monkeypatch.setattr(runner, "_start_campaign_worker_task", lambda *_args: next(workers))
monkeypatch.setattr(runner, "_terminate_worker_process", lambda *_args: None)
monkeypatch.setattr(runner, "_wait_for_worker_process", lambda *_args, **_kwargs: None)
client = Mock()
client.post.return_value = _Response(200, {
"queued_count": 1, "skipped_count": 0, "blocked_count": 0, "enqueued_count": 0,
"delivery_mode": "database_queue", "worker_queue_available": False, "dry_run": False,
})
client.get.return_value = _Response(200, {"cards": {}, "status_counts": {"send": {"outcome_unknown": 1}, "imap": {}}})
endpoint = Mock()
endpoint.wait_for_data.return_value = True
endpoint.evidence.return_value = {"connection_count": 1, "accepted_rcpt_commands": 1, "refused_rcpt_commands": 0, "data_transactions": 1}
recover_claim = Mock(return_value={"explicit_fenced_recovery": True})
arguments = dict(
fixture_path=FIXTURE_PATH, profile_id="profile", settings=_settings(), endpoint=endpoint,
snapshot_probe=lambda _: ({}, {}), audit_probe=lambda *_: {"campaign.created": 1, "campaign.validated": 1, "campaign.messages_built": 1, "campaign.queued": 1},
delivery_probe=lambda *_: next(states), worker_job_probe=lambda _: "job", recover_claim=recover_claim,
)
if duplicate_mutates:
with pytest.raises(runner.AcceptanceError, match="without stopped-runtime proof"):
runner.execute_worker_interruption_scenario(client, {}, **arguments)
recover_claim.assert_not_called()
else:
evidence = runner.execute_worker_interruption_scenario(client, {}, **arguments)
assert evidence["interrupted_durable_state"] == evidence["restarted_durable_state"] == interrupted
assert evidence["recovered_durable_state"] == recovered
recover_claim.assert_called_once_with("campaign", "version", first)
def test_direct_task_bootstrap_registers_unique_fixture_owner_and_accepts_read_only_duplicate(monkeypatch):
import os
import sys
from unittest.mock import MagicMock
from govoplan_core import celery_app, db
from govoplan_core.core import runtime_coordination
identity = SimpleNamespace(node_id="fixture-owner")
bind = Mock(return_value=identity)
register = Mock()
session = MagicMock()
database = SimpleNamespace(SessionLocal=MagicMock())
database.SessionLocal.return_value.__enter__.return_value = session
task = SimpleNamespace(run=Mock(return_value={"status": "already_sending"}))
monkeypatch.setattr(celery_app, "_worker_runtime_identity", bind)
monkeypatch.setattr(celery_app, "send_email", task)
monkeypatch.setattr(runtime_coordination, "register_runtime_node", register)
monkeypatch.setattr(db.session, "get_database", lambda: database)
monkeypatch.setattr(sys, "argv", ["fixture-worker", "fixture-job"])
exec(compile(runner.WORKER_TASK_CODE, "<isolated-worker-test>", "exec"), {})
assert bind.call_args.args[0].hostname == f"campaign-acceptance-{os.getpid()}"
register.assert_called_once_with(session, identity, metadata={"acceptance_worker_pid": os.getpid()})
session.commit.assert_called_once()
task.run.assert_called_once_with("fixture-job")
+505
View File
@@ -0,0 +1,505 @@
"""Workerless recovery operates the real job/attempt ledger, never resend actions."""
from contextlib import nullcontext
from dataclasses import dataclass, field
from datetime import datetime, timedelta, timezone
from types import SimpleNamespace
from unittest.mock import Mock, patch
import pytest
from fastapi import FastAPI, HTTPException
from fastapi.testclient import TestClient
from sqlalchemy import Column, String, Table, create_engine, event
from sqlalchemy.orm import Session, sessionmaker
from govoplan_campaign.backend.db.models import (
Campaign, CampaignVersion, CampaignJob, SendAttempt, ImapAppendAttempt,
PostboxDeliveryAttempt, PrintOutputAttempt, CampaignMessageAction,
)
from govoplan_campaign.backend.delivery_policy import SynchronousSendPolicy
from govoplan_campaign.backend.integrations import MailProfileError, SmtpSendError, ImapAppendError
from govoplan_campaign.backend.routes import delivery as routes
from govoplan_campaign.backend.schemas import CampaignRetryJobsRequest, CampaignSendUnattemptedRequest, CampaignRecoverClaimRequest
from govoplan_campaign.backend.services.delivery_progress import campaign_delivery_progress
from govoplan_campaign.backend.services.delivery_recovery import job_recovery_metadata, recover_stale_delivery_claim, RecoveryStateConflict
from govoplan_campaign.backend.sending import jobs
from govoplan_core.core.change_sequence import ChangeSequenceEntry
from govoplan_core.core.recovery import RecoveryOperation, RecoveryCheckpoint, verify_recovery_evidence_chain
from govoplan_core.core.runtime_coordination import DistributedLease, RuntimeNode, process_runtime_identity
from govoplan_core.db.base import Base
from govoplan_core.db.session import get_session
from govoplan_core.auth import get_api_principal, ApiPrincipal
from govoplan_core.core.access import PrincipalRef
@dataclass
class _SmtpResult:
accepted_count: int = 1
refused_recipients: dict = field(default_factory=dict)
envelope_recipients: list = field(default_factory=lambda: ["recipient@example.test"])
@pytest.fixture
def recovery(tmp_path, monkeypatch):
engine = create_engine(f"sqlite+pysqlite:///{tmp_path / 'recovery.db'}")
for name in ("access_users", "access_groups"):
if name not in Base.metadata.tables:
Table(name, Base.metadata, Column("id", String(36), primary_key=True))
Base.metadata.create_all(engine, tables=[Base.metadata.tables[name] for name in ("access_users", "access_groups")] + [
model.__table__ for model in (ChangeSequenceEntry, Campaign, CampaignVersion, CampaignJob,
SendAttempt, ImapAppendAttempt, PostboxDeliveryAttempt, PrintOutputAttempt, CampaignMessageAction,
DistributedLease, RuntimeNode, RecoveryOperation, RecoveryCheckpoint)
])
factory = sessionmaker(engine)
session = factory()
campaign = Campaign(id="campaign", tenant_id="tenant", external_id="C", name="Recovery", current_version_id="version")
version = CampaignVersion(id="version", campaign_id="campaign", version_number=1, raw_json={},
locked_at=datetime.now(timezone.utc), validation_summary={"ok": True},
build_summary={"build_token": "build"}, execution_snapshot_hash="f" * 64,
editor_state={"review_send": {"build_token": "build", "inspection_complete": True, "reviewed_message_keys": ["reviewed"]}})
session.add_all([campaign, version])
session.commit()
snapshot = SimpleNamespace(
mail_profile_id="profile", smtp_server_id="smtp", smtp_credential_id="credential",
smtp_transport_revision="smtp-revision", imap_transport_revision="imap-revision", uses_mail=True,
delivery=SimpleNamespace(retry=SimpleNamespace(max_attempts=3),
rate_limit=SimpleNamespace(messages_per_minute=60), imap_append_sent=SimpleNamespace(enabled=True)),
)
provider = Mock()
provider.wait_for_rate_limit.return_value = None
provider.send_campaign_email_bytes.return_value = _SmtpResult()
provider.campaign_imap_batch.side_effect = lambda **_: nullcontext(SimpleNamespace(connection_count=1, reconnect_count=0))
monkeypatch.setattr(jobs, "get_database", lambda: SimpleNamespace(SessionLocal=factory))
monkeypatch.setattr(jobs, "ensure_execution_snapshot", lambda *_args, **_kw: snapshot)
monkeypatch.setattr(jobs, "_ensure_campaign_approval_gate", Mock())
monkeypatch.setattr(jobs, "_emit_campaign_status_notification", Mock())
monkeypatch.setattr(jobs, "_mark_accepted_job_artifacts", Mock())
monkeypatch.setattr(jobs, "mail_integration", lambda: provider)
monkeypatch.setattr(jobs, "_celery_enabled", lambda: False)
monkeypatch.setattr(jobs, "effective_synchronous_send_policy", lambda *_args, **_kw: SynchronousSendPolicy(2, "system", 500, system_max_recipient_jobs=2))
monkeypatch.setattr(jobs, "_synchronous_smtp_batch_manager", lambda *_args, **_kw: nullcontext(SimpleNamespace(connection_count=1, reconnect_count=0)))
monkeypatch.setattr(jobs, "_send_job_delivery_context", lambda _session, job: SimpleNamespace(
version=version, snapshot=snapshot, message_bytes=b"immutable message",
envelope_from="sender@example.test", envelope_recipients=["recipient@example.test"],
))
monkeypatch.setattr(jobs, "profile_delivery_summary", lambda *_: {"smtp_transport_revision": "smtp-revision"})
yield SimpleNamespace(session=session, factory=factory, engine=engine, campaign=campaign, version=version, provider=provider, snapshot=snapshot)
session.close()
engine.dispose()
def _add(recovery, name, *, status="not_queued", attempt=0, **kwargs):
job = CampaignJob(id=name, tenant_id="tenant", campaign_id="campaign", campaign_version_id="version",
entry_index=recovery.session.query(CampaignJob).count() + 1, entry_id=name,
build_status="built", validation_status="ready", send_status=status,
queue_status="draft", attempt_count=attempt, eml_sha256="e" * 64,
eml_local_path="unused-exact-message.eml",
resolved_recipients={"from": {"email": "sender@example.test"}, "to": [{"email": "recipient@example.test"}]})
for key, value in kwargs.items():
setattr(job, key, value)
recovery.session.add(job)
recovery.session.commit()
return job
def _retry(recovery, **kw):
return jobs.queue_failed_jobs_for_retry(recovery.session, tenant_id="tenant", campaign_id="campaign", version_id="version", enqueue_celery=False, run_inline=True, **kw)
def _continue(recovery, **kw):
return jobs.queue_unattempted_jobs(recovery.session, tenant_id="tenant", campaign_id="campaign", version_id="version", enqueue_celery=False, run_inline=True, **kw)
def test_inline_retry_records_canonical_acceptance_and_never_creates_resend_action(recovery):
failed = _add(recovery, "failed", status="failed_temporary", attempt=1)
recovery.session.add(SendAttempt(job_id=failed.id, attempt_number=1, status="failed_temporary", finished_at=datetime.now(timezone.utc)))
recovery.session.commit()
result = _retry(recovery)
assert result["sent_count"] == result["attempted_count"] == 1
with recovery.factory() as check:
current = check.get(CampaignJob, failed.id)
assert current.send_status == "smtp_accepted" and current.attempt_count == 2 and current.imap_status == "pending"
assert [a.status for a in check.query(SendAttempt).order_by(SendAttempt.attempt_number)] == ["failed_temporary", "smtp_accepted"]
assert check.query(CampaignMessageAction).count() == 0
ledger = check.query(RecoveryOperation).one()
assert ledger.status == "succeeded" and verify_recovery_evidence_chain(check, ledger.id)
second = _retry(recovery)
assert second["selected_count"] == 0 and recovery.provider.send_campaign_email_bytes.call_count == 1
def test_continue_is_bounded_and_skips_accepted_excluded_unknown_and_active(recovery):
for name in ("one", "two", "three"):
_add(recovery, name)
_add(recovery, "accepted", status="smtp_accepted", attempt=1)
_add(recovery, "excluded", status="skipped", validation_status="excluded")
_add(recovery, "unknown", status="outcome_unknown", attempt=1)
_add(recovery, "active", status="sending", attempt=1, claim_token="live")
_add(recovery, "claimed", status="claimed", claim_token="live-before-smtp")
first = _continue(recovery)
assert first["selected_count"] == first["sent_count"] == 2 and first["remaining_count"] == 1
assert recovery.session.get(CampaignJob, "three").send_status == "not_queued"
second = _continue(recovery)
assert second["sent_count"] == 1 and second["remaining_count"] == 0
assert recovery.provider.send_campaign_email_bytes.call_count == 3
assert recovery.session.get(CampaignJob, "active").send_status == "sending"
assert recovery.session.get(CampaignJob, "claimed").send_status == "claimed"
assert recovery.session.get(CampaignJob, "unknown").send_status == "outcome_unknown"
def test_continue_drains_queued_unattempted_remainder_but_never_repeats_prior_print_effect(recovery):
_add(recovery, "queued", status="queued", queue_status="queued")
_add(recovery, "printed", status="queued", queue_status="queued", print_attempt_count=1)
result = _continue(recovery)
assert result["sent_count"] == 1
assert recovery.session.get(CampaignJob, "queued").send_status == "smtp_accepted"
assert recovery.session.get(CampaignJob, "printed").send_status == "queued"
assert recovery.provider.send_campaign_email_bytes.call_count == 1
def test_unattempted_review_exception_requires_completed_same_build_review(recovery):
_add(recovery, "reviewed", validation_status="needs_review")
_add(recovery, "not-reviewed", validation_status="needs_review")
result = _continue(recovery)
assert result["selected_count"] == 1 and result["sent_count"] == 1
assert recovery.session.get(CampaignJob, "not-reviewed").send_status == "not_queued"
@pytest.mark.parametrize("reason", ["max_attempts", "permanent", "blocked", "approval", "limit_zero"])
def test_recovery_preserves_delivery_gates(recovery, monkeypatch, reason):
job = _add(recovery, "candidate", status="failed_temporary", attempt=1)
if reason == "max_attempts":
job.attempt_count = 3
elif reason == "permanent":
job.send_status = "failed_permanent"
elif reason == "blocked":
job.validation_status = "blocked"
elif reason == "approval":
monkeypatch.setattr(jobs, "_ensure_campaign_approval_gate", Mock(side_effect=jobs.QueueingError("Approval missing")))
else:
monkeypatch.setattr(jobs, "effective_synchronous_send_policy", lambda *_args, **_kw: SynchronousSendPolicy(0, "system", 500))
recovery.session.commit()
if reason in {"approval", "limit_zero"}:
with pytest.raises(jobs.QueueingError):
_retry(recovery)
else:
assert _retry(recovery)["selected_count"] == 0
assert recovery.provider.send_campaign_email_bytes.call_count == 0
def test_preflight_failure_rolls_back_queue_changes_without_provider_effect(recovery, monkeypatch):
job = _add(recovery, "failed", status="failed_temporary", attempt=1)
class Refuse:
def __enter__(self):
raise MailProfileError("Revoked profile selection")
def __exit__(self, *_):
return False
monkeypatch.setattr(jobs, "_synchronous_smtp_batch_manager", lambda *_args, **_kw: Refuse())
with pytest.raises(jobs.SynchronousSendRejected):
_retry(recovery)
recovery.session.expire_all()
assert job.send_status == "failed_temporary" and job.attempt_count == 1
recovery.provider.send_campaign_email_bytes.assert_not_called()
def test_repeated_worker_task_does_not_mutate_a_live_smtp_claim(recovery):
job = _add(recovery, "live", status="sending", attempt=1, claim_token="live", queue_status="sending")
result = jobs.send_campaign_job(recovery.session, job_id=job.id)
assert result.status == "already_sending"
recovery.session.expire_all()
assert job.send_status == "sending" and job.claim_token == "live"
recovery.provider.send_campaign_email_bytes.assert_not_called()
def test_progress_counts_include_active_and_partition_each_channel_without_loading_jobs(recovery):
_add(recovery, "accepted", status="smtp_accepted", imap_status="appended")
_add(recovery, "imap-active", status="smtp_accepted", imap_status="appending")
_add(recovery, "sending", status="sending", queue_status="sending", imap_status="pending")
_add(recovery, "claimed", status="claimed", imap_status="pending")
_add(recovery, "pending", imap_status="pending")
_add(recovery, "failed", status="failed_temporary", imap_status="failed")
_add(recovery, "unknown", status="outcome_unknown", imap_status="outcome_unknown")
_add(recovery, "paused", status="queued", queue_status="paused", imap_status="pending")
_add(recovery, "cancelled", status="cancelled", imap_status="skipped")
_add(recovery, "excluded", status="skipped", validation_status="excluded", imap_status="skipped")
recovery.session.expunge_all()
loaded = []
event.listen(recovery.session, "loaded_as_persistent", lambda _session, row: loaded.append(row))
progress = campaign_delivery_progress(recovery.session, tenant_id="tenant", campaign_id="campaign")
assert progress["total_jobs"] == 10
assert progress["smtp"] == dict(total=9, processed=5, accepted=2, active=2, pending=1, failed=1, outcome_unknown=1, excluded=1, paused=1, cancelled=1)
assert progress["imap"] == dict(total=8, processed=3, appended=1, active=1, pending=4, failed=1, outcome_unknown=1, excluded=2)
assert not any(isinstance(row, CampaignJob) for row in loaded)
assert progress["status_counts"]["send"]["claimed"] == 1
assert "recipient@example.test" not in repr(progress)
def test_progress_scopes_version_and_preserves_partial_multichannel_smtp_acceptance(recovery):
job = _add(recovery, "partial", status="partially_accepted", delivery_channel_policy="mail_and_postbox")
recovery.session.add(SendAttempt(job_id=job.id, attempt_number=1, status="smtp_accepted"))
recovery.session.add(CampaignVersion(id="old", campaign_id="campaign", version_number=2, raw_json={}))
recovery.session.commit()
result = campaign_delivery_progress(recovery.session, tenant_id="tenant", campaign_id="campaign", version_id="version")
assert result["smtp"]["accepted"] == 1 and result["smtp"]["failed"] == 0
assert campaign_delivery_progress(recovery.session, tenant_id="tenant", campaign_id="campaign", version_id="old")["total_jobs"] == 0
with pytest.raises(jobs.QueueingError):
campaign_delivery_progress(recovery.session, tenant_id="other", campaign_id="campaign")
def test_append_processes_only_selected_version_and_uses_one_lazy_batch(recovery, monkeypatch):
first = _add(recovery, "current", status="smtp_accepted", imap_status="pending")
recovery.session.add(CampaignVersion(id="old", campaign_id="campaign", version_number=2, raw_json={}))
recovery.session.commit()
old = _add(recovery, "old-job", status="smtp_accepted", imap_status="pending", campaign_version_id="old")
appended = []
def append(session, *, job_id, dry_run):
appended.append(job_id)
return jobs.AppendSentResult(job_id=job_id, status="appended", attempt_number=1)
monkeypatch.setattr(jobs, "append_sent_for_job", append)
result = jobs.enqueue_pending_imap_appends(recovery.session, tenant_id="tenant", campaign_id="campaign", enqueue_celery=False, run_inline=True)
assert appended == [first.id] and result["version_id"] == "version" and result["imap_connection_count"] == 1
jobs.enqueue_pending_imap_appends(recovery.session, tenant_id="tenant", campaign_id="campaign", version_id="old", enqueue_celery=False, run_inline=True)
assert appended == [first.id, old.id]
@pytest.mark.parametrize("outcome", ["failed", "outcome_unknown", "raised_unknown"])
def test_inline_imap_summary_keeps_failed_and_unknown_results_distinct(recovery, monkeypatch, outcome):
job = _add(recovery, "imap", status="smtp_accepted", imap_status="pending")
def append(*_args, **_kwargs):
if outcome == "raised_unknown":
raise ImapAppendError("Provider response lost", outcome_unknown=True)
return jobs.AppendSentResult(job_id=job.id, status=outcome, attempt_number=1)
monkeypatch.setattr(jobs, "append_sent_for_job", append)
result = jobs.enqueue_pending_imap_appends(recovery.session, tenant_id="tenant", campaign_id="campaign", run_inline=True)
assert result["appended_count"] == 0 and result["processed_count"] == 1
assert result["outcome_unknown_count"] == int(outcome != "failed")
assert result["failed_count"] == int(outcome == "failed")
assert result["results"][0]["status"] == ("outcome_unknown" if outcome == "raised_unknown" else outcome)
def _stale_claim(recovery, *, channel="smtp", expired=True, owner="stopped", policy="mail"):
job = _add(recovery, "stale", status="sending" if channel == "smtp" else "smtp_accepted", queue_status="sending" if channel == "smtp" else "draft",
attempt=1, claim_token="stale-token" if channel == "smtp" else None,
imap_status="appending" if channel == "imap" else "pending", imap_claim_token="stale-token" if channel == "imap" else None,
delivery_channel_policy=policy)
identity = process_runtime_identity()
context = SimpleNamespace(version=recovery.version, snapshot=recovery.snapshot, folder="Sent")
begin = jobs._begin_job_delivery_recovery if channel == "smtp" else jobs._begin_imap_append_recovery
started = begin(job=job, context=context, claim_token="stale-token")
recovery.session.expire_all()
lease = recovery.session.query(DistributedLease).one()
lease.holder_node_id = "old-process"
lease.holder_incarnation = "old-incarnation"
lease.expires_at = datetime.now(timezone.utc) + timedelta(minutes=-1 if expired else 10)
node = RuntimeNode(installation_id=identity.installation_id, node_id="old-process",
incarnation="replacement" if owner == "replaced" else "old-incarnation", role="worker", software_version="test", composition_hash="c" * 64,
state="stopped" if owner == "stopped" else "active")
recovery.session.add(node)
attempt = SendAttempt(job_id=job.id, attempt_number=1, status="smtp_in_progress", claim_token="stale-token") if channel == "smtp" else ImapAppendAttempt(job_id=job.id, attempt_number=1, status="appending", claim_token="stale-token")
recovery.session.add(attempt)
recovery.session.commit()
return job, lease, node, started.operation_id
@pytest.mark.parametrize("channel", ["smtp", "imap"])
@pytest.mark.parametrize("owner", ["stopped", "replaced"])
def test_stale_claim_recovery_is_fenced_unknown_then_explicit_evidence_reconciliation(recovery, channel, owner):
job, lease, node, operation_id = _stale_claim(recovery, channel=channel, owner=owner)
metadata = job_recovery_metadata(recovery.session, [job])[job.id][channel]
assert metadata["eligible"] is True
result = recover_stale_delivery_claim(recovery.session, tenant_id="tenant", campaign_id="campaign", job_id=job.id,
channel=channel, expected_revision=metadata["revision"], note="Verified original worker process stopped; inspect provider evidence next.")
recovery.session.commit()
assert result["reconciliation_required"] is True
assert (job.send_status if channel == "smtp" else job.imap_status) == "outcome_unknown"
assert recovery.session.get(RecoveryOperation, operation_id).status == "outcome_unknown"
assert verify_recovery_evidence_chain(recovery.session, operation_id)
assert _retry(recovery)["selected_count"] == 0
decision = "not_sent" if channel == "smtp" else "imap_not_appended"
jobs.reconcile_job_outcome(recovery.session, tenant_id="tenant", campaign_id="campaign", job_id=job.id, decision=decision, note="Provider logs and target mailbox confirm the effect did not occur.")
assert (job.send_status if channel == "smtp" else job.imap_status) == ("failed_temporary" if channel == "smtp" else "failed")
assert recovery.session.get(RecoveryOperation, operation_id).status == "recovered"
assert verify_recovery_evidence_chain(recovery.session, operation_id)
original_attempt = recovery.session.query(SendAttempt if channel == "smtp" else ImapAppendAttempt).filter_by(job_id=job.id).one()
assert original_attempt.status == ("reconciled_not_sent" if channel == "smtp" else "reconciled_imap_not_appended")
assert "Provider logs" in original_attempt.error_message
recovery.provider.send_campaign_email_bytes.assert_not_called()
@pytest.mark.parametrize("case", ["live_lease", "active_owner", "changed_revision", "wrong_tenant", "missing_ledger"])
def test_claim_recovery_rejects_live_ambiguous_changed_or_unauthorized_state(recovery, case):
job, lease, node, operation_id = _stale_claim(recovery, expired=case != "live_lease", owner="active" if case == "active_owner" else "stopped")
metadata = job_recovery_metadata(recovery.session, [job])[job.id]["smtp"]
if case == "missing_ledger":
recovery.session.get(RecoveryOperation, operation_id).idempotency_key = "another-operation"
recovery.session.commit()
with pytest.raises(jobs.QueueingError):
recover_stale_delivery_claim(recovery.session, tenant_id="other" if case == "wrong_tenant" else "tenant", campaign_id="campaign", job_id=job.id, channel="smtp", expected_revision="f" * 64 if case == "changed_revision" else metadata["revision"], note="Evidence")
recovery.session.rollback()
assert job.send_status == "sending" and job.claim_token == "stale-token"
recovery.provider.send_campaign_email_bytes.assert_not_called()
class _Principal:
tenant_id = "tenant"
user = SimpleNamespace(id="operator")
def __init__(self, *scopes):
self.scopes = set(scopes)
def has(self, scope):
return scope in self.scopes
@pytest.mark.parametrize("kind", ["retry", "unattempted"])
@pytest.mark.parametrize("missing", ["send", "recipient"])
def test_inline_recovery_requires_send_and_recipient_permission(recovery, kind, missing):
principal = _Principal(*({"campaigns:campaign:send", "campaigns:recipient:read"} - {"campaigns:campaign:send" if missing == "send" else "campaigns:recipient:read"}))
endpoint = routes.retry_campaign_jobs if kind == "retry" else routes.send_unattempted_campaign_jobs
schema = CampaignRetryJobsRequest if kind == "retry" else CampaignSendUnattemptedRequest
with patch.object(routes, "_get_campaign_for_principal", return_value=recovery.campaign):
with pytest.raises(HTTPException) as error:
endpoint("campaign", schema(version_id="version", run_inline=True), session=recovery.session, principal=principal)
assert error.value.status_code == 403
recovery.provider.send_campaign_email_bytes.assert_not_called()
def test_claim_recovery_and_audit_are_atomic(recovery):
job, lease, node, operation_id = _stale_claim(recovery)
metadata = job_recovery_metadata(recovery.session, [job])[job.id]["smtp"]
original_fence = lease.fencing_token
principal = _Principal("campaigns:recipient:read", "campaigns:campaign:reconcile")
with patch.object(routes, "_get_campaign_for_principal", return_value=recovery.campaign), patch.object(routes, "audit_from_principal", autospec=True, side_effect=RuntimeError("Audit unavailable")):
with pytest.raises(RuntimeError, match="Audit unavailable"):
routes.recover_campaign_job_claim("campaign", job.id, CampaignRecoverClaimRequest(channel="smtp", expected_revision=metadata["revision"], note="Stopped process verified"), session=recovery.session, principal=principal)
with recovery.factory() as check:
assert check.get(CampaignJob, job.id).send_status == "sending"
assert check.get(CampaignJob, job.id).claim_token == "stale-token"
assert check.get(RecoveryOperation, operation_id).status == "running"
assert check.get(DistributedLease, lease.id).fencing_token == original_fence
assert verify_recovery_evidence_chain(check, operation_id)
def test_existing_worker_queue_path_remains_supported(recovery, monkeypatch):
job = _add(recovery, "retry", status="failed_temporary", attempt=1)
enqueue = Mock()
monkeypatch.setattr(jobs, "_celery_enabled", lambda: True)
monkeypatch.setattr(jobs, "_celery_enqueue_send_job", enqueue)
result = jobs.queue_failed_jobs_for_retry(recovery.session, tenant_id="tenant", campaign_id="campaign", enqueue_celery=True)
assert result["enqueued_count"] == 1 and result["run_inline"] is False
enqueue.assert_called_once_with(job.id)
assert job.send_status == "queued" and job.attempt_count == 1
recovery.provider.send_campaign_email_bytes.assert_not_called()
def test_retry_dry_run_and_foreign_ids_never_change_selected_state(recovery):
job = _add(recovery, "retry", status="failed_temporary", attempt=1)
assert _retry(recovery, dry_run=True)["selected_count"] == 1
assert job.send_status == "failed_temporary" and job.attempt_count == 1
assert _retry(recovery, job_ids=["foreign-job"])["selected_count"] == 0
recovery.provider.send_campaign_email_bytes.assert_not_called()
def test_recovery_public_response_never_returns_provider_diagnostics():
projected = routes._public_recovery_result({"run_inline": True, "campaign_id": "campaign", "version_id": "version",
"selected_count": 1, "remaining_count": 0, "sent_count": 0, "failed_count": 1,
"results": [{"job_id": "job", "status": "failed", "message": "Provider rejected hidden@example.test"}]})
assert projected["selected_count"] == 1
assert projected["results"] == [{"job_id": "job", "status": "failed"}]
assert "hidden@example.test" not in repr(projected)
@pytest.mark.parametrize("result_status", ["failed_temporary", "failed_permanent", "outcome_unknown"])
def test_inline_summary_counts_returned_failures_and_unknown_separately(recovery, monkeypatch, result_status):
job = _add(recovery, "candidate", status="failed_temporary", attempt=1)
monkeypatch.setattr(jobs, "_deliver_job_with_recovery", lambda *_args, **_kw: jobs.SendJobResult(job_id=job.id, status=result_status, attempt_number=2))
result = _retry(recovery)
assert result["failed_count"] == int(result_status != "outcome_unknown")
assert result["outcome_unknown_count"] == int(result_status == "outcome_unknown")
assert result["skipped_count"] == 0
@pytest.mark.parametrize("path,scope,method,payload", [
("delivery-progress?version_id=version", "campaigns:campaign:read", "get", None),
("jobs/retry", "campaigns:campaign:retry", "post", {"version_id": "version", "dry_run": True}),
("jobs/send-unattempted", "campaigns:campaign:queue", "post", {"version_id": "version", "dry_run": True}),
("jobs/job/recover-claim", "campaigns:campaign:reconcile", "post", {"channel": "smtp", "expected_revision": "f" * 64, "note": "Evidence"}),
])
def test_http_scope_dependencies_reject_missing_route_permission(recovery, path, scope, method, payload):
app = FastAPI()
app.include_router(routes.router, prefix="/api/v1")
scopes = {"campaigns:campaign:send", "campaigns:recipient:read"}
actor = SimpleNamespace(id="operator")
app.dependency_overrides[get_api_principal] = lambda: ApiPrincipal(principal=PrincipalRef(account_id="operator", membership_id="operator", tenant_id="tenant", scopes=frozenset(scopes)), user=actor, account=actor)
app.dependency_overrides[get_session] = lambda: recovery.session
with TestClient(app) as client:
response = client.request(method, f"/api/v1/campaigns/campaign/{path}", **({"json": payload} if payload else {}))
assert response.status_code == 403
recovery.provider.send_campaign_email_bytes.assert_not_called()
@pytest.mark.parametrize("channel", ["smtp", "imap"])
def test_accepted_reconciliation_updates_only_matching_original_campaign_operation(recovery, channel):
job, lease, node, operation_id = _stale_claim(recovery, channel=channel)
meta = job_recovery_metadata(recovery.session, [job])[job.id][channel]
recover_stale_delivery_claim(recovery.session, tenant_id="tenant", campaign_id="campaign", job_id=job.id, channel=channel, expected_revision=meta["revision"], note="Stopped process verified")
recovery.session.commit()
jobs.reconcile_job_outcome(recovery.session, tenant_id="tenant", campaign_id="campaign", job_id=job.id,
decision="smtp_accepted" if channel == "smtp" else "imap_appended", note="Provider log confirms the exact Message-ID was accepted")
with recovery.factory() as check:
assert check.get(RecoveryOperation, operation_id).status == "succeeded"
assert verify_recovery_evidence_chain(check, operation_id)
assert check.query(RecoveryOperation).count() == 1
assert (check.get(CampaignJob, job.id).send_status if channel == "smtp" else check.get(CampaignJob, job.id).imap_status) == ("smtp_accepted" if channel == "smtp" else "appended")
recovery.provider.send_campaign_email_bytes.assert_not_called()
@pytest.mark.parametrize("channel", ["smtp", "imap"])
def test_reconciliation_audit_failure_rolls_back_campaign_attempt_and_core_operation(recovery, channel):
job, lease, node, operation_id = _stale_claim(recovery, channel=channel)
meta = job_recovery_metadata(recovery.session, [job])[job.id][channel]
recover_stale_delivery_claim(recovery.session, tenant_id="tenant", campaign_id="campaign", job_id=job.id, channel=channel, expected_revision=meta["revision"], note="Stopped process verified")
recovery.session.commit()
from govoplan_campaign.backend.schemas import CampaignResolveOutcomeRequest
with patch.object(routes, "_get_campaign_for_principal", return_value=recovery.campaign), patch.object(routes, "audit_from_principal", autospec=True, side_effect=RuntimeError("Audit unavailable")):
with pytest.raises(RuntimeError, match="Audit unavailable"):
routes.resolve_campaign_job_outcome("campaign", job.id, CampaignResolveOutcomeRequest(decision="not_sent" if channel == "smtp" else "imap_not_appended", note="Verified effect absent"), session=recovery.session, principal=_Principal("campaigns:recipient:read"))
with recovery.factory() as check:
assert check.get(RecoveryOperation, operation_id).status == "outcome_unknown"
assert (check.get(CampaignJob, job.id).send_status if channel == "smtp" else check.get(CampaignJob, job.id).imap_status) == "outcome_unknown"
assert check.query(SendAttempt if channel == "smtp" else ImapAppendAttempt).filter_by(job_id=job.id).one().status == "outcome_unknown"
@pytest.mark.parametrize("channel_policy", ["mail_then_postbox", "postbox_then_mail", "mail_then_print", "mail_and_postbox"])
def test_mixed_delivered_status_without_smtp_attempt_evidence_never_claims_mail_acceptance(recovery, channel_policy):
_add(recovery, "mixed", status="delivered", delivery_channel_policy=channel_policy)
result = campaign_delivery_progress(recovery.session, tenant_id="tenant", campaign_id="campaign")
assert result["smtp"]["accepted"] == 0
if channel_policy == "mail_and_postbox":
assert result["smtp"]["outcome_unknown"] == 1
else:
assert result["smtp"]["excluded"] == 1
def test_concurrent_legacy_reconciliation_cannot_overwrite_already_accepted_state(recovery):
job = _add(recovery, "legacy", status="outcome_unknown", attempt=1)
# Keep an old ORM projection, then commit another operator's decision.
with recovery.factory() as concurrent:
current = concurrent.get(CampaignJob, job.id)
current.send_status = "smtp_accepted"
concurrent.commit()
assert job.send_status == "outcome_unknown"
with pytest.raises(jobs.QueueingError, match="changed"):
jobs.reconcile_job_outcome(recovery.session, tenant_id="tenant", campaign_id="campaign", job_id=job.id, decision="not_sent", note="Stale operator evidence")
recovery.session.rollback()
assert job.send_status == "smtp_accepted"
def test_one_smtp_decision_never_resolves_compound_postbox_operation(recovery):
job, lease, node, operation_id = _stale_claim(recovery, policy="mail_and_postbox")
meta = job_recovery_metadata(recovery.session, [job])[job.id]["smtp"]
recover_stale_delivery_claim(recovery.session, tenant_id="tenant", campaign_id="campaign", job_id=job.id, channel="smtp", expected_revision=meta["revision"], note="Original process stopped")
recovery.session.commit()
jobs.reconcile_job_outcome(recovery.session, tenant_id="tenant", campaign_id="campaign", job_id=job.id,
decision="smtp_accepted", note="SMTP acceptance verified; Postbox remains separately unresolved")
assert job.send_status == "smtp_accepted"
assert recovery.session.get(RecoveryOperation, operation_id).status == "outcome_unknown"
assert verify_recovery_evidence_chain(recovery.session, operation_id)
+42
View File
@@ -0,0 +1,42 @@
from __future__ import annotations
from govoplan_campaign.backend.manifest import get_manifest
from govoplan_campaign.backend.workflow_definitions import (
campaign_workflow_definitions,
)
from govoplan_core.core.campaigns import CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION
def test_campaign_work_handoff_is_an_opt_in_reusable_template() -> None:
contribution = campaign_workflow_definitions(module_version="0.1.23")[0]
assert contribution.origin_module_id == "campaigns"
assert contribution.definition_kind == "template"
assert contribution.activate_on_install is False
assert contribution.allow_reuse is True
assert contribution.required_capabilities == (
CAPABILITY_CAMPAIGNS_WORK_ORCHESTRATION,
)
assert contribution.policy_metadata["assignment_authorization_neutral"] is True
nodes = {
str(node["id"]): node
for node in contribution.graph["nodes"] # type: ignore[index]
}
prepare = nodes["prepare"]
handoff = nodes["campaign_work"]
assert prepare["config"]["operation"] == "campaigns.work.prepare" # type: ignore[index]
assert handoff["type"] == "workflow.external_handoff"
assert handoff["config"]["event_type"] == "campaign.work.changed" # type: ignore[index]
assert handoff["config"]["terminal_outcomes"] == { # type: ignore[index]
"completed": "completed",
"rejected": "rejected",
"cancelled": "cancelled",
}
def test_manifest_contributes_the_current_campaign_work_template() -> None:
manifest = get_manifest()
assert len(manifest.workflow_definitions) == 1
assert manifest.workflow_definitions[0].origin_module_version == manifest.version
+3 -3
View File
@@ -1,6 +1,6 @@
{
"name": "@govoplan/campaign-webui",
"version": "0.1.21",
"version": "0.1.29",
"private": true,
"type": "module",
"main": "src/index.ts",
@@ -17,7 +17,7 @@
"read-excel-file": "9.2.0"
},
"peerDependencies": {
"@govoplan/core-webui": "^0.1.18",
"@govoplan/core-webui": "^0.1.45",
"lucide-react": "^1.23.0",
"react": ">=19.2.7 <20",
"react-dom": ">=19.2.7 <20",
@@ -30,7 +30,7 @@
"test:recipient-search": "node tests/recipient-search-ui-structure.test.mjs",
"test:report-grid": "rm -rf .report-grid-test-build && mkdir -p .report-grid-test-build && printf '{\"type\":\"commonjs\"}\\n' > .report-grid-test-build/package.json && tsc -p tsconfig.report-grid-tests.json && node .report-grid-test-build/tests/report-grid-query.test.js",
"test:review-preview-ui": "rm -rf .review-preview-test-build && mkdir -p .review-preview-test-build && printf '{\"type\":\"commonjs\"}\\n' > .review-preview-test-build/package.json && tsc -p tsconfig.review-preview-tests.json && node .review-preview-test-build/tests/review-preview-ui.test.js && node tests/delivery-mode-ui-structure.test.mjs",
"test:review-workflow": "node --experimental-strip-types --test tests/review-workflow-guidance.test.ts && node tests/review-workflow-guidance-ui-structure.test.mjs",
"test:review-workflow": "node --experimental-strip-types --test tests/review-workflow-guidance.test.ts tests/bulk-message-review.test.ts tests/built-message-state.test.ts tests/validation-issue-groups.test.ts && node tests/review-workflow-guidance-ui-structure.test.mjs",
"test:operator-queue": "node --experimental-strip-types --test tests/operator-queue-model.test.ts && node tests/operator-queue-ui-structure.test.mjs",
"test:aggregate-report": "tsc -p tsconfig.aggregate-report-tests.json && node tests/aggregate-report-ui-structure.test.mjs",
"test:wizards": "node tests/wizard-directory-ui-structure.test.mjs",
+135 -12
View File
@@ -5,6 +5,7 @@ import {
type ReferenceOptionProvider
} from "@govoplan/core-webui";
import { campaignJobsQueryParams, type CampaignJobsQueryParameters } from "../features/campaigns/utils/jobListQuery";
import { campaignVersionUpdateForRequest } from "../features/campaigns/utils/editorState";
export {
fetchResourceAccessExplanation,
fetchResourceAccessExplanationSubjects
@@ -82,7 +83,7 @@ export type CampaignCollaborationCreate = {
};
export type CampaignWorkAssigneeType = "account" | "group" | "organization_function";
export type CampaignWorkAssignmentStatus = "open" | "in_progress" | "completed" | "cancelled";
export type CampaignWorkAssignmentStatus = "open" | "in_progress" | "completed" | "rejected" | "cancelled";
export type CampaignWorkAssignmentResolutionState = "resolved" | "unavailable" | "provider_unavailable";
export type CampaignWorkAssignment = {
@@ -234,6 +235,52 @@ export type CampaignCopyOptions = {
include_mail_profile: boolean;
};
export type CampaignTransferScope =
| "metadata"
| "template_config"
| "recipients"
| "attachments"
| "review_state"
| "delivery_history";
export type CampaignPortablePackage = {
format: "govoplan.campaign-portable";
format_version: string;
package_id: string;
exported_at: string;
source: Record<string, unknown>;
scopes: CampaignTransferScope[];
manifest: Record<string, unknown>;
payload: Record<string, unknown>;
integrity: { algorithm: string; package_sha256: string };
};
export type CampaignTransferPlanItem = {
scope: CampaignTransferScope;
code: string;
summary: string;
item_count?: number | null;
};
export type CampaignImportPreview = {
compatible: boolean;
package_id?: string | null;
package_sha256?: string | null;
format_version?: string | null;
source: Record<string, unknown>;
available_scopes: CampaignTransferScope[];
selected_scopes: CampaignTransferScope[];
destination: { external_id?: string; name?: string; status?: string };
will_create: CampaignTransferPlanItem[];
will_skip: CampaignTransferPlanItem[];
warnings: string[];
errors: string[];
};
export type CampaignImportApplyResponse = CampaignCreateResponse & {
receipt: Record<string, unknown>;
};
export type CampaignScheduleOccurrence = {
id: string;
schedule_id: string;
@@ -294,6 +341,7 @@ export type CampaignScheduleCreate = {
};
export type CampaignVersionDetail = CampaignVersionListItem & {
review_build_token?: string | null;
raw_json: Record<string, unknown>;
campaign_json?: Record<string, unknown>;
mail_profile_migration_required?: boolean;
@@ -890,6 +938,7 @@ export type CampaignSendNowPayload = {
};
export type CampaignAppendSentPayload = {
version_id?: string;
dry_run?: boolean;
enqueue_celery?: boolean;
run_inline?: boolean;
@@ -971,6 +1020,7 @@ export type CampaignAttachmentLinkMatchesResponse = {
};
export type CampaignMockSendPayload = {
use_reviewed_build?: boolean;
version_id?: string | null;
send?: boolean;
include_warnings?: boolean;
@@ -981,6 +1031,10 @@ export type CampaignMockSendPayload = {
};
export type CampaignReviewStatePayload = {
merge_progress?: boolean;
build_token?: string | null;
base_revision?: number | null;
decision_category_key?: string | null;
inspection_complete: boolean;
reviewed_message_keys: string[];
issue_decisions: Array<{
@@ -1339,6 +1393,49 @@ options: CampaignCopyOptions)
});
}
export async function exportCampaignPackage(
settings: ApiSettings,
campaignId: string,
versionId: string,
scopes: CampaignTransferScope[])
: Promise<CampaignPortablePackage> {
return apiFetch<CampaignPortablePackage>(settings, `/api/v1/campaigns/${campaignId}/versions/${versionId}/exports`, {
method: "POST",
body: JSON.stringify({ scopes })
});
}
export async function previewCampaignImport(
settings: ApiSettings,
payload: {
package: Record<string, unknown>;
selected_scopes?: CampaignTransferScope[] | null;
external_id?: string;
name?: string;
})
: Promise<CampaignImportPreview> {
return apiFetch<CampaignImportPreview>(settings, "/api/v1/campaign-transfers/imports/preview", {
method: "POST",
body: JSON.stringify(payload)
});
}
export async function importCampaignPackage(
settings: ApiSettings,
payload: {
package: Record<string, unknown>;
selected_scopes: CampaignTransferScope[];
external_id?: string;
name?: string;
expected_package_sha256: string;
})
: Promise<CampaignImportApplyResponse> {
return apiFetch<CampaignImportApplyResponse>(settings, "/api/v1/campaign-transfers/imports", {
method: "POST",
body: JSON.stringify(payload)
});
}
export async function listCampaignSchedules(
settings: ApiSettings,
campaignId: string)
@@ -1428,7 +1525,8 @@ options: CampaignWorkspaceQuery = {})
export async function getCampaignWorkspaceDelta(
settings: ApiSettings,
campaignId: string,
options: CampaignWorkspaceQuery = {})
options: CampaignWorkspaceQuery = {},
requestOptions?: Pick<RequestInit, "cache" | "signal">)
: Promise<CampaignWorkspaceDeltaResponse> {
const params = new URLSearchParams();
if (options.versionId) params.set("version_id", options.versionId);
@@ -1438,7 +1536,7 @@ options: CampaignWorkspaceQuery = {})
if (options.since) params.set("since", options.since);
if (options.limit) params.set("limit", String(options.limit));
const suffix = params.size > 0 ? `?${params.toString()}` : "";
return apiFetch<CampaignWorkspaceDeltaResponse>(settings, `/api/v1/campaigns/${campaignId}/workspace/delta${suffix}`);
return apiFetch<CampaignWorkspaceDeltaResponse>(settings, `/api/v1/campaigns/${campaignId}/workspace/delta${suffix}`, requestOptions);
}
export async function listCampaignVersions(
@@ -1453,7 +1551,9 @@ settings: ApiSettings,
campaignId: string,
versionId: string)
: Promise<CampaignVersionDetail> {
return apiFetch<CampaignVersionDetail>(settings, `/api/v1/campaigns/${campaignId}/versions/${versionId}`);
// Conflict reconciliation and discard/reload require the current revision,
// never an older coalesced or short-lived cached read.
return apiFetch<CampaignVersionDetail>(settings, `/api/v1/campaigns/${campaignId}/versions/${versionId}`, { cache: "no-store" });
}
export async function unlockCampaignVersionValidation(
@@ -1506,7 +1606,7 @@ ifMatch: string)
return apiFetch<CampaignVersionDetail>(settings, `/api/v1/campaigns/${campaignId}/versions/${versionId}`, {
method: "PUT",
headers: { "If-Match": ifMatch },
body: JSON.stringify(payload)
body: JSON.stringify(campaignVersionUpdateForRequest(payload))
});
}
@@ -1518,7 +1618,7 @@ payload: CampaignVersionUpdatePayload = {})
: Promise<CampaignCreateResponse> {
return apiFetch<CampaignCreateResponse>(settings, `/api/v1/campaigns/${campaignId}/versions/${versionId}/fork`, {
method: "POST",
body: JSON.stringify(payload)
body: JSON.stringify(campaignVersionUpdateForRequest(payload))
});
}
@@ -1532,7 +1632,7 @@ ifMatch: string)
return apiFetch<CampaignVersionDetail>(settings, `/api/v1/campaigns/${campaignId}/versions/${versionId}/autosave`, {
method: "POST",
headers: { "If-Match": ifMatch },
body: JSON.stringify(payload)
body: JSON.stringify(campaignVersionUpdateForRequest(payload))
});
}
@@ -1630,24 +1730,46 @@ versionId?: string)
return apiFetch<CampaignSummary>(settings, `/api/v1/campaigns/${campaignId}/summary${suffix}`);
}
export type CampaignDeliveryProgress = {
delivery_mode?: string | null;
workflow_state?: string;
campaign_id: string;
version_id: string;
generated_at: string;
total_jobs: number;
smtp: { total: number; processed: number; accepted: number; active: number; pending: number; failed: number; outcome_unknown: number; excluded: number; paused: number; cancelled: number };
imap: { total: number; processed: number; appended: number; active: number; pending: number; failed: number; outcome_unknown: number; excluded: number };
status_counts: { send: Record<string, number>; queue: Record<string, number>; imap: Record<string, number> };
};
export async function getCampaignDeliveryProgress(
settings: ApiSettings, campaignId: string, versionId: string, signal?: AbortSignal
): Promise<CampaignDeliveryProgress> {
return apiFetch<CampaignDeliveryProgress>(settings,
`/api/v1/campaigns/${campaignId}/delivery-progress?version_id=${encodeURIComponent(versionId)}`,
{ cache: "no-store", signal });
}
export async function getCampaignJobs(
settings: ApiSettings,
campaignId: string,
options: CampaignJobsQuery = {})
options: CampaignJobsQuery = {},
init?: Pick<RequestInit, "cache" | "signal">)
: Promise<CampaignJobsResponse> {
const params = campaignJobsQueryParams(options);
const suffix = params.size > 0 ? `?${params.toString()}` : "";
return apiFetch<CampaignJobsResponse>(settings, `/api/v1/campaigns/${campaignId}/jobs${suffix}`);
return apiFetch<CampaignJobsResponse>(settings, `/api/v1/campaigns/${campaignId}/jobs${suffix}`, init);
}
export async function getCampaignJobsDelta(
settings: ApiSettings,
campaignId: string,
options: CampaignJobsQuery & {since?: string | null;limit?: number;} = {})
options: CampaignJobsQuery & {since?: string | null;limit?: number;} = {},
init?: Pick<RequestInit, "cache" | "signal">)
: Promise<CampaignJobsDeltaResponse> {
const params = campaignJobsQueryParams(options);
const suffix = params.size > 0 ? `?${params.toString()}` : "";
return apiFetch<CampaignJobsDeltaResponse>(settings, `/api/v1/campaigns/${campaignId}/jobs/delta${suffix}`);
return apiFetch<CampaignJobsDeltaResponse>(settings, `/api/v1/campaigns/${campaignId}/jobs/delta${suffix}`, init);
}
export async function getCampaignJobDetail(
@@ -1852,6 +1974,7 @@ payload: CampaignAppendSentPayload = {})
return apiFetch<Record<string, unknown>>(settings, `/api/v1/campaigns/${campaignId}/append-sent`, {
method: "POST",
body: JSON.stringify({
version_id: payload.version_id,
dry_run: payload.dry_run ?? false,
enqueue_celery: payload.enqueue_celery ?? true,
run_inline: payload.run_inline ?? false
@@ -1976,7 +2099,7 @@ export async function transitionCampaignWorkAssignment(
settings: ApiSettings,
campaignId: string,
assignment: Pick<CampaignWorkAssignment, "id" | "resource_revision">,
action: "start" | "complete" | "cancel"
action: "accept" | "start" | "complete" | "reject" | "cancel"
): Promise<CampaignWorkAssignment> {
return apiFetch<CampaignWorkAssignment>(
settings,
+24
View File
@@ -0,0 +1,24 @@
import { apiFetch, type ApiSettings } from "@govoplan/core-webui";
export type CampaignDeliveryPolicyScope = "system" | "tenant";
export type CampaignDeliveryPolicy = {
scope: CampaignDeliveryPolicyScope;
synchronous_send_max_recipients: number | null;
revision: string;
max_configurable_recipients: number;
effective_max_recipients: number;
inherited_max_recipients: number;
absolute_max_recipients: number;
deployment_ceiling_explicit: boolean;
deployment_max_recipients: number;
};
export function getCampaignDeliveryPolicy(settings: ApiSettings, scope: CampaignDeliveryPolicyScope, signal?: AbortSignal) {
return apiFetch<CampaignDeliveryPolicy>(settings, `/api/v1/campaigns/settings/delivery-policy/${scope}`, { cache: "no-store", signal });
}
export function saveCampaignDeliveryPolicy(settings: ApiSettings, scope: CampaignDeliveryPolicyScope, value: number | null, revision: string) {
return apiFetch<CampaignDeliveryPolicy>(settings, `/api/v1/campaigns/settings/delivery-policy/${scope}`, {
method: "PUT", body: JSON.stringify({ synchronous_send_max_recipients: value, expected_revision: revision })
});
}
+37
View File
@@ -0,0 +1,37 @@
import { apiFetch, type ApiSettings } from "@govoplan/core-webui";
export type CampaignRecoveryChannel = "smtp" | "imap";
export type CampaignInlineRecoveryAction = "retry" | "send-unattempted";
export type CampaignInlineRecoveryResult = {
selected_count: number;
remaining_count?: number;
attempted_count?: number;
sent_count?: number;
failed_count?: number;
outcome_unknown_count?: number;
enqueued_count?: number;
run_inline?: boolean;
};
export async function runCampaignInlineRecovery(settings: ApiSettings, campaignId: string, action: CampaignInlineRecoveryAction, payload: {
version_id: string;
job_ids: string[];
include_permanent?: boolean;
}): Promise<CampaignInlineRecoveryResult> {
const response = await apiFetch<{ result: CampaignInlineRecoveryResult }>(settings,
`/api/v1/campaigns/${encodeURIComponent(campaignId)}/jobs/${action}`, {
method: "POST",
body: JSON.stringify({ ...payload, run_inline: true, enqueue_celery: false })
});
return response.result;
}
export async function recoverCampaignJobClaim(settings: ApiSettings, campaignId: string, jobId: string, payload: {
channel: CampaignRecoveryChannel;
expected_revision: string;
note: string;
}): Promise<void> {
await apiFetch(settings, `/api/v1/campaigns/${encodeURIComponent(campaignId)}/jobs/${encodeURIComponent(jobId)}/recover-claim`, {
method: "POST", body: JSON.stringify(payload)
});
}
+12 -6
View File
@@ -72,8 +72,10 @@ export async function testMailProfileSmtp(
serverId?: string | null,
credentialId?: string | null,
campaignId?: string | null
): Promise<MailConnectionTestResponse> {
return runProfileAction<MailConnectionTestResponse>(settings, profileId, "smtp", serverId, credentialId, campaignId);
): Promise<MailConnectionTestResponse & { protocol: "smtp" }> {
const result = await runProfileAction<MailConnectionTestResponse>(settings, profileId, "smtp", serverId, credentialId, campaignId);
if (result.protocol !== "smtp") throw new Error("Unexpected protocol in SMTP test response.");
return { ...result, protocol: result.protocol };
}
export async function testMailProfileImap(
@@ -82,8 +84,10 @@ export async function testMailProfileImap(
serverId?: string | null,
credentialId?: string | null,
campaignId?: string | null
): Promise<MailConnectionTestResponse> {
return runProfileAction<MailConnectionTestResponse>(settings, profileId, "imap", serverId, credentialId, campaignId);
): Promise<MailConnectionTestResponse & { protocol: "imap" }> {
const result = await runProfileAction<MailConnectionTestResponse>(settings, profileId, "imap", serverId, credentialId, campaignId);
if (result.protocol !== "imap") throw new Error("Unexpected protocol in IMAP test response.");
return { ...result, protocol: result.protocol };
}
export async function listMailProfileImapFolders(
@@ -92,8 +96,10 @@ export async function listMailProfileImapFolders(
serverId?: string | null,
credentialId?: string | null,
campaignId?: string | null
): Promise<MailImapFolderListResponse> {
return runProfileAction<MailImapFolderListResponse>(settings, profileId, "folders", serverId, credentialId, campaignId);
): Promise<MailImapFolderListResponse & { protocol: "imap" }> {
const result = await runProfileAction<MailImapFolderListResponse>(settings, profileId, "folders", serverId, credentialId, campaignId);
if (result.protocol !== "imap") throw new Error("Unexpected protocol in IMAP folder response.");
return { ...result, protocol: result.protocol };
}
export async function getMockMailboxMessage(settings: ApiSettings, id: string): Promise<MockMailboxMessageResponse> {
@@ -0,0 +1,119 @@
import { useEffect, useRef, useState } from "react";
import {
AdminPageLayout, Card, DescriptionItem, DescriptionList, FormField, PageActionBar,
ToggleSwitch, adminErrorMessage, usePlatformLanguage, useUnsavedDraftGuard, type ApiSettings
} from "@govoplan/core-webui";
import { getCampaignDeliveryPolicy, saveCampaignDeliveryPolicy, type CampaignDeliveryPolicy, type CampaignDeliveryPolicyScope } from "../../api/deliveryPolicy";
// This optional administration screen owns its bilingual copy and loads lazily.
const labels = {
en: {
system: "System Campaign delivery", tenant: "Tenant Campaign delivery", title: "Interactive delivery limit",
description: "Set the recipient-job limit for one Send now request. This is not a campaign-size limit; background workers process larger campaigns separately.",
inherit: "Inherit the parent or default limit", limit: "Maximum recipient jobs per Send now request", help: "0 disables Send now. Larger values hold requests open longer and may reach proxy timeouts; Mail provider rate limits still apply. Saving policy never sends messages or changes existing reviews.",
effective: "Saved effective limit", parent: "Inherited limit", maximum: "Maximum allowed here", deployment: "Explicit deployment ceiling", absent: "Not set; the absolute safety maximum is 500.",
saved: "Campaign delivery policy saved.", invalid: "Enter a whole number within the permitted range.", readOnly: "You may inspect this policy but do not have permission to change it.",
reload: "Reload saved delivery policy", save: "Save", discard: "Discard", ceiling: "Tenant settings can only narrow system policy. An explicit deployment ceiling cannot be raised in this screen."
},
de: {
system: "Systemweiter Campaign-Versand", tenant: "Mandantenweiter Campaign-Versand", title: "Grenze für interaktiven Versand",
description: "Legen Sie die Empfängerauftragsgrenze für eine Anfrage „Jetzt senden“ fest. Sie begrenzt nicht die Kampagnengröße; Hintergrund-Worker verarbeiten größere Kampagnen getrennt.",
inherit: "Übergeordnete Grenze oder Standard erben", limit: "Maximale Empfängeraufträge je Anfrage „Jetzt senden“", help: "0 deaktiviert „Jetzt senden“. Höhere Werte halten Anfragen länger offen und können Proxy-Zeitlimits erreichen; Mail-Anbieterraten gelten weiterhin. Speichern versendet keine Nachrichten und ändert keine bestehenden Prüfungen.",
effective: "Gespeicherte wirksame Grenze", parent: "Geerbte Grenze", maximum: "Hier maximal zulässig", deployment: "Ausdrückliche Bereitstellungsgrenze", absent: "Nicht gesetzt; die absolute Sicherheitsgrenze beträgt 500.",
saved: "Campaign-Versandrichtlinie gespeichert.", invalid: "Geben Sie eine ganze Zahl im zulässigen Bereich ein.", readOnly: "Sie dürfen diese Richtlinie ansehen, besitzen aber keine Änderungsberechtigung.",
reload: "Gespeicherte Versandrichtlinie neu laden", save: "Speichern", discard: "Verwerfen", ceiling: "Mandanteneinstellungen dürfen die Systemrichtlinie nur einschränken. Eine ausdrücklich gesetzte Bereitstellungsgrenze lässt sich hier nicht erhöhen."
}
};
export default function CampaignDeliveryPolicyPanel({ settings, scope, canWrite }: {
settings: ApiSettings; scope: CampaignDeliveryPolicyScope; canWrite: boolean;
}) {
const { language } = usePlatformLanguage();
const text = labels[language.startsWith("de") ? "de" : "en"];
const [saved, setSaved] = useState<CampaignDeliveryPolicy | null>(null);
const [draft, setDraft] = useState("");
const [inherit, setInherit] = useState(true);
const [loading, setLoading] = useState(true);
const [saving, setSaving] = useState(false);
const [error, setError] = useState("");
const [success, setSuccess] = useState("");
const generation = useRef(0);
const request = useRef<AbortController | null>(null);
const inFlight = useRef<Promise<boolean> | null>(null);
const dirty = Boolean(saved && (inherit !== (saved.synchronous_send_max_recipients === null) || (!inherit && draft !== String(saved.synchronous_send_max_recipients))));
const valid = inherit || (/^\d+$/.test(draft) && Number(draft) <= (saved?.max_configurable_recipients ?? 0));
function adopt(state: CampaignDeliveryPolicy) {
setSaved(state); setInherit(state.synchronous_send_max_recipients === null);
setDraft(String(state.synchronous_send_max_recipients ?? state.inherited_max_recipients));
}
async function reload() {
request.current?.abort();
const controller = new AbortController(); request.current = controller;
const current = ++generation.current;
setLoading(true); setError(""); setSuccess("");
try {
const response = await getCampaignDeliveryPolicy(settings, scope, controller.signal);
if (current === generation.current) adopt(response);
} catch (cause) {
if (current === generation.current && !controller.signal.aborted) setError(adminErrorMessage(cause));
} finally { if (current === generation.current) setLoading(false); }
}
useEffect(() => {
setSaved(null);
setSaving(false); inFlight.current = null;
void reload();
return () => { ++generation.current; request.current?.abort(); };
}, [scope, settings.apiBaseUrl, settings.apiKey, settings.accessToken]);
function discard() { if (saved && !inFlight.current) { adopt(saved); setError(""); setSuccess(""); } }
function save(): Promise<boolean> {
if (inFlight.current) return inFlight.current;
if (!dirty) return Promise.resolve(true);
if (!saved || !canWrite || !valid || loading) return Promise.resolve(false);
const current = generation.current;
setSaving(true); setError(""); setSuccess("");
const operation = (async () => {
try {
const response = await saveCampaignDeliveryPolicy(settings, scope, inherit ? null : Number(draft), saved.revision);
if (current !== generation.current) return false;
adopt(response); setSuccess(text.saved); return true;
} catch (cause) {
if (current === generation.current) setError(adminErrorMessage(cause));
return false;
} finally {
if (current === generation.current) { inFlight.current = null; setSaving(false); }
}
})();
inFlight.current = operation;
return operation;
}
useUnsavedDraftGuard({ dirty, onSave: save, onDiscard: discard });
const disabled = !canWrite || saving || loading;
return <AdminPageLayout archetype="editor" title={text[scope]} description={text.description}
loading={loading && !saved} error={error} success={success}
interfaceId={`campaigns.admin.${scope}-delivery`} helpModuleId="campaigns" helpTopicId="campaigns.admin.delivery-policy"
actions={<PageActionBar variant="editor" state={saving ? "saving" : !valid ? "invalid" : error && dirty ? "save-failed" : dirty ? "dirty" : "clean"}
refreshable reloadAction={{ onReload: () => void reload(), label: text.reload, loading, disabled: saving }}
saveAction={{ label: text.save, onClick: () => void save(), disabled: !canWrite || !saved || loading }}
discardAction={{ label: text.discard, onClick: discard, disabled: saving }} />}>
{saved && <Card title={text.title}>
{!canWrite && <p>{text.readOnly}</p>}
<ToggleSwitch label={text.inherit} checked={inherit} disabled={disabled} onChange={setInherit} />
<FormField label={text.limit} help={text.help}>
<input type="number" min={0} max={saved.max_configurable_recipients} step={1} value={draft}
aria-invalid={!valid} disabled={disabled || inherit} onChange={(event) => setDraft(event.target.value)} />
</FormField>
{!valid && <p role="alert">{text.invalid}</p>}
<p>{text.ceiling}</p>
<DescriptionList>
<DescriptionItem term={text.effective}>{saved.effective_max_recipients}</DescriptionItem>
<DescriptionItem term={text.parent}>{saved.inherited_max_recipients}</DescriptionItem>
<DescriptionItem term={text.maximum}>{saved.max_configurable_recipients}</DescriptionItem>
<DescriptionItem term={text.deployment}>{saved.deployment_ceiling_explicit ? saved.deployment_max_recipients : text.absent}</DescriptionItem>
</DescriptionList>
</Card>}
</AdminPageLayout>;
}
@@ -3,10 +3,7 @@ import { useEffect, useMemo, useState } from "react";
import { Pencil } from "lucide-react";
import { useGuardedNavigate, usePlatformModuleInstalled, usePlatformUiCapability, type FilesFileExplorerUiCapability, type FilesFileSpace } from "@govoplan/core-webui";
import type { ApiSettings, AuthInfo } from "../../types";
import {
getCampaignArchiveEncryptionPolicy,
type CampaignArchiveEncryptionPolicy
} from "../../api/campaigns";
import type { CampaignArchiveEncryptionPolicy } from "../../api/campaigns";
import { Button } from "@govoplan/core-webui";
import { Card } from "@govoplan/core-webui";
import { PageActionBar, PageLayout } from "@govoplan/core-webui";
@@ -14,6 +11,7 @@ import { LoadingFrame } from "@govoplan/core-webui";
import { MetricCard } from "@govoplan/core-webui";
import { FormField } from "@govoplan/core-webui";
import LockedVersionNotice from "./components/LockedVersionNotice";
import LegacyMailMigrationNotice from "./components/LegacyMailMigrationNotice";
import VersionLine from "./components/VersionLine";
import { ToggleSwitch } from "@govoplan/core-webui";
import { DismissibleAlert } from "@govoplan/core-webui";
@@ -21,7 +19,7 @@ import { ConfirmDialog } from "@govoplan/core-webui";
import { DataGrid, DataGridEmptyAction, DataGridRowActions, type DataGridColumn } from "@govoplan/core-webui";
import { useCampaignWorkspaceData } from "./hooks/useCampaignWorkspaceData";
import { useCampaignDraftEditor } from "./hooks/useCampaignDraftEditor";
import { asArray, asRecord, isAuditLockedVersion } from "./utils/campaignView";
import { asArray, asRecord, getCampaignJson, isAuditLockedVersion } from "./utils/campaignView";
import { updateNested } from "./utils/draftEditor";
import { AttachmentRulesDataGrid } from "./components/AttachmentRulesOverlay";
import TemplateExpressionEditorDialog from "./components/TemplateExpressionEditorDialog";
@@ -29,21 +27,11 @@ import { countIndividualAttachmentRules, countIndividualAttachmentRulesForBasePa
import { hasScope, insertAfter, moveArrayItem, i18nMessage } from "@govoplan/core-webui";
import { getDraftFields, humanizeFieldName } from "./utils/fieldDefinitions";
import { buildTemplatePreviewContext, recipientAddressTemplateFieldOptions } from "./utils/templatePlaceholders";
import CampaignArchiveEncryptionPolicyNotice, { UNAVAILABLE_ARCHIVE_POLICY } from "./components/CampaignArchiveEncryptionPolicyNotice";
type PathChooserState = {index: number;};
type IndividualDisableState = {index: number;usageCount: number;};
const UNAVAILABLE_ARCHIVE_POLICY: CampaignArchiveEncryptionPolicy = {
available: false,
allowed_password_encryption_methods: ["aes"],
allowed_password_delivery_channels: ["separate_mail", "sms", "letter", "phone", "in_person"],
policy_hash: "",
source_path: [],
reason: "Archive-encryption policy is loading. Legacy ZipCrypto remains blocked.",
diagnostics: [],
legacy_label: "Legacy ZipCrypto — Windows-compatible, weak encryption"
};
export default function AttachmentsDataPage({ settings, auth, campaignId }: {settings: ApiSettings;auth: AuthInfo;campaignId: string;}) {
const navigate = useGuardedNavigate();
const filesModuleInstalled = usePlatformModuleInstalled("files");
@@ -59,7 +47,7 @@ export default function AttachmentsDataPage({ settings, auth, campaignId }: {set
const [archivePolicy, setArchivePolicy] = useState<CampaignArchiveEncryptionPolicy>(UNAVAILABLE_ARCHIVE_POLICY);
const version = data.currentVersion;
const locked = isAuditLockedVersion(version, data.campaign?.current_version_id);
const { draft, setDraft, displayDraft, dirty, saveState, localError, patch, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
const { draft, setDraft, displayDraft, dirty, saving, saveState, localError, patch, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
settings,
campaignId,
version,
@@ -94,7 +82,10 @@ export default function AttachmentsDataPage({ settings, auth, campaignId }: {set
!archive.legacy_zipcrypto_acknowledged || archive.legacy_zipcrypto_reason.trim().length < 10
)
);
const canSave = dirty && !locked && Boolean(draft) && !zipArchiveNameValidation.message && !legacyConfigurationInvalid;
const zipChanged = JSON.stringify(attachments.zip ?? null) !== JSON.stringify(asRecord(getCampaignJson(version).attachments).zip ?? null);
// An unchanged ZIP policy must not lock unrelated source/rule corrections.
// The backend rechecks changed ZIP settings and all actual archive use.
const canSave = dirty && !locked && Boolean(draft) && (!zipChanged || !zipArchiveNameValidation.message && !legacyConfigurationInvalid);
const globalSummary = useMemo(() => summarizeAttachmentRules(globalRules), [globalRules]);
const individualRulesCount = useMemo(() => countIndividualAttachmentRules(displayDraft.entries), [displayDraft.entries]);
const attachmentPreviewEntry = useMemo(
@@ -118,22 +109,6 @@ export default function AttachmentsDataPage({ settings, auth, campaignId }: {set
return () => {cancelled = true;};
}, [listManagedFileSpaces, settings.apiBaseUrl, settings.apiKey, settings.accessToken]);
useEffect(() => {
let cancelled = false;
setArchivePolicy(UNAVAILABLE_ARCHIVE_POLICY);
void getCampaignArchiveEncryptionPolicy(settings, campaignId)
.then((policy) => { if (!cancelled) setArchivePolicy(policy); })
.catch((cause) => {
if (!cancelled) {
setArchivePolicy({
...UNAVAILABLE_ARCHIVE_POLICY,
reason: cause instanceof Error ? cause.message : String(cause)
});
}
});
return () => { cancelled = true; };
}, [campaignId, settings.accessToken, settings.apiBaseUrl, settings.apiKey]);
function patchBasePaths(paths: AttachmentBasePath[]) {
if (locked) return;
const normalized = ensureAttachmentBasePaths(paths);
@@ -321,16 +296,17 @@ export default function AttachmentsDataPage({ settings, auth, campaignId }: {set
mode="workspace"
title="i18n:govoplan-campaign.attachments.6771ade6"
description={<VersionLine version={version} versions={data.versions} status={saveState} />}
headerLoading={loading}
headerLoading={loading || saving}
error={error}
actions={<PageActionBar
variant="editor"
state={loading ? "saving" : dirty ? "dirty" : "clean"}
state={loading || saving ? "saving" : dirty ? "dirty" : "clean"}
contextActions={filesModuleInstalled ? <Button onClick={() => navigate("/files")}>i18n:govoplan-campaign.manage_files.90a419f7</Button> : undefined}
discardAction={{ label: "i18n:govoplan-campaign.discard.36fff63c", onClick: () => void discardDraft() }}
saveAction={{ label: "i18n:govoplan-campaign.save.efc007a3", onClick: () => saveDraft("manual"), disabled: !canSave && dirty, disabledReason: !canSave && dirty ? "Resolve the current editor blocker before saving." : undefined }}
/>}
notices={(localError || locked) ? <>
notices={(localError || locked || version?.mail_profile_migration_required) ? <>
{version?.mail_profile_migration_required && <LegacyMailMigrationNotice campaignId={campaignId} versionId={version.id} />}
{localError && <DismissibleAlert tone="danger" resetKey={localError} floating>{localError}</DismissibleAlert>}
{locked && <LockedVersionNotice settings={settings} campaignId={campaignId} version={version} currentVersionId={data.campaign?.current_version_id} reload={reload} message="i18n:govoplan-campaign.this_page_is_read_only_for_the_selected_version.dacf5743" />}
</> : undefined}
@@ -346,11 +322,12 @@ export default function AttachmentsDataPage({ settings, auth, campaignId }: {set
</MetricGrid>
<Card id="campaign-attachment-sources" tabIndex={-1} title="i18n:govoplan-campaign.attachment_sources.8ef0a6ce">
{filesModuleInstalled && !managedFilesAvailable && <DismissibleAlert tone="warning" dismissible={false}>i18n:govoplan-campaign.file_chooser_unavailable</DismissibleAlert>}
<div className="admin-table-surface attachment-sources-table-surface">
<DataGrid
id={`campaign-${campaignId}-attachment-sources`}
rows={basePaths}
columns={attachmentSourceColumns({ locked, basePaths, fileSpaces, managedFilesAvailable, patchBasePath, setIndividualEligibility, addBasePath, moveBasePath, removeBasePath, setPathChooser })}
columns={attachmentSourceColumns({ locked, basePaths, fileSpaces, managedFilesAvailable, filesModuleInstalled, patchBasePath, setIndividualEligibility, addBasePath, moveBasePath, removeBasePath, setPathChooser })}
getRowKey={(basePath) => basePath.id}
emptyText="i18n:govoplan-campaign.no_attachment_sources_configured.48664606"
emptyAction={<DataGridEmptyAction onAdd={() => addBasePath(-1)} disabled={locked} label="i18n:govoplan-campaign.add_first_attachment_source.cefa7882" />}
@@ -425,11 +402,7 @@ export default function AttachmentsDataPage({ settings, auth, campaignId }: {set
</Card>
<Card title="i18n:govoplan-campaign.zip_attachments.6b58ed68" collapsible>
<DismissibleAlert tone={legacyZipCryptoAllowed ? "warning" : "info"} dismissible={false} compact>
<strong>{archivePolicy.legacy_label}</strong>: {archivePolicy.reason}
{archivePolicy.source_path.length > 0 && <> Source: {archivePolicy.source_path.map((step) => step.label).join(" → ")}.</>}
{!canUseLegacyZipCrypto && <> Your account does not have the dedicated legacy-encryption permission.</>}
</DismissibleAlert>
<CampaignArchiveEncryptionPolicyNotice settings={settings} auth={auth} campaignId={campaignId} onPolicyChange={setArchivePolicy} />
<div className="attachment-zip-master-toggle">
<ToggleSwitch
label="i18n:govoplan-campaign.enable_zip_attachments.6077075b"
@@ -471,8 +444,10 @@ export default function AttachmentsDataPage({ settings, auth, campaignId }: {set
}
</Card>
<Card id="campaign-global-attachments" tabIndex={-1} title="i18n:govoplan-campaign.global_attachments.492bd841" collapsible>
<AttachmentRulesDataGrid
<Card id="campaign-global-attachments" tabIndex={-1} title="i18n:govoplan-campaign.global_attachments.492bd841" bodyLayout="table" collapsible>
{/* The loading draft has no ZIP columns yet. Do not let that
temporary signature overwrite the user's saved table layout. */}
{version && draft && <AttachmentRulesDataGrid
id={`campaign-${campaignId}-global-attachments`}
rules={globalRules}
disabled={locked}
@@ -481,9 +456,9 @@ export default function AttachmentsDataPage({ settings, auth, campaignId }: {set
settings={settings}
campaignId={campaignId}
zipConfig={zipConfig}
filesModuleInstalled={managedFilesAvailable}
filesModuleInstalled={filesModuleInstalled}
previewContext={attachmentPreviewContext}
onChange={(rules) => patch(["attachments", "global"], rules)} />
onChange={(rules) => patch(["attachments", "global"], rules)} />}
</Card>
@@ -615,6 +590,8 @@ function zipArchiveColumns({ disabled, archives, invalidNameIndexes, onEditName,
value={archive.method}
disabled={disabled}
aria-label="Archive password encryption"
data-help-context-id="campaign.archive-encryption"
data-help-module-id="campaigns"
onChange={(event) => {
const method = event.target.value === "zip_standard" ? "zip_standard" : "aes";
patchArchive(index, method === "zip_standard" ? {
@@ -640,6 +617,8 @@ function zipArchiveColumns({ disabled, archives, invalidNameIndexes, onEditName,
value={archive.password_delivery_channel}
disabled={disabled || !archive.password_enabled}
aria-label="Separate password-delivery channel"
data-help-context-id="campaign.archive-encryption"
data-help-module-id="campaigns"
onChange={(event) => patchArchive(index, { password_delivery_channel: event.target.value as AttachmentZipArchive["password_delivery_channel"] })}>
{(["separate_mail", "sms", "letter", "phone", "in_person"] as const).map((channel) =>
<option key={channel} value={channel} disabled={!allowedDeliveryChannels.includes(channel)}>{passwordDeliveryChannelLabel(channel)}</option>
@@ -653,6 +632,8 @@ function zipArchiveColumns({ disabled, archives, invalidNameIndexes, onEditName,
<div className="campaign-legacy-zipcrypto-acknowledgement">
<ToggleSwitch
label="I acknowledge that ZipCrypto encryption is weak"
helpContextId="campaign.archive-encryption"
helpModuleId="campaigns"
checked={archive.legacy_zipcrypto_acknowledged}
disabled={disabled || !legacyAllowed || !canUseLegacy}
onChange={(checked) => patchArchive(index, { legacy_zipcrypto_acknowledged: checked })} />
@@ -663,6 +644,8 @@ function zipArchiveColumns({ disabled, archives, invalidNameIndexes, onEditName,
maxLength={1000}
placeholder="Operational reason (at least 10 characters)"
aria-label="Reason for weak legacy encryption"
data-help-context-id="campaign.archive-encryption"
data-help-module-id="campaigns"
onChange={(event) => patchArchive(index, { legacy_zipcrypto_reason: event.target.value })} />
</div> : <span>Not required for AES</span>,
value: (archive) => archive.legacy_zipcrypto_reason
@@ -798,6 +781,7 @@ type AttachmentSourceColumnContext = {
basePaths: AttachmentBasePath[];
fileSpaces: FilesFileSpace[];
managedFilesAvailable: boolean;
filesModuleInstalled: boolean;
patchBasePath: (index: number, patch: Partial<AttachmentBasePath>) => void;
setIndividualEligibility: (index: number, checked: boolean) => void;
addBasePath: (afterIndex?: number) => void;
@@ -806,7 +790,7 @@ type AttachmentSourceColumnContext = {
setPathChooser: (state: PathChooserState | null) => void;
};
function attachmentSourceColumns({ locked, basePaths, fileSpaces, managedFilesAvailable, patchBasePath, setIndividualEligibility, addBasePath, moveBasePath, removeBasePath, setPathChooser }: AttachmentSourceColumnContext): DataGridColumn<AttachmentBasePath>[] {
function attachmentSourceColumns({ locked, basePaths, fileSpaces, managedFilesAvailable, filesModuleInstalled, patchBasePath, setIndividualEligibility, addBasePath, moveBasePath, removeBasePath, setPathChooser }: AttachmentSourceColumnContext): DataGridColumn<AttachmentBasePath>[] {
return [
{ id: "name", header: "i18n:govoplan-campaign.name.709a2322", width: 220, resizable: true, sortable: true, filterable: true, sticky: "start", render: (basePath, index) => <input value={basePath.name} disabled={locked} placeholder="i18n:govoplan-campaign.campaign_files.96e7004b" onChange={(event) => patchBasePath(index, { name: event.target.value })} />, value: (basePath) => basePath.name },
{
@@ -822,9 +806,9 @@ function attachmentSourceColumns({ locked, basePaths, fileSpaces, managedFilesAv
<input
className="chooser-display-input"
value={managedFilesAvailable ? formatAttachmentSourcePath(basePath, fileSpaces) : basePath.path}
disabled={locked}
disabled={locked || filesModuleInstalled && !managedFilesAvailable}
readOnly={managedFilesAvailable}
tabIndex={managedFilesAvailable ? -1 : undefined}
tabIndex={0}
placeholder="i18n:govoplan-campaign.attachments_placeholder"
onChange={(event) => {
if (!managedFilesAvailable) patchBasePath(index, { path: event.target.value, source: "" });
@@ -24,7 +24,13 @@ export default function CampaignAuditPage({ settings, campaignId }: {settings: A
reloadAction={{ onReload: () => void reload({ force: true }), loading }}
/>}
>
<Card title="i18n:govoplan-campaign.recent_audit_events.7ec32b1d">
<Card title="i18n:govoplan-campaign.recent_audit_events.7ec32b1d" titleHelp={<DocumentationHelpLink
reference={{
topicId: "campaigns.reference.composition-assurance",
documentationType: "user"
}}
label="Open Campaign assurance documentation"
/>}>
<ActionBlockerHint
tone="info"
reason={{
@@ -39,13 +45,6 @@ export default function CampaignAuditPage({ settings, campaignId }: {settings: A
documentationType: "admin"
}}
/>
<DocumentationHelpLink
reference={{
topicId: "campaigns.reference.composition-assurance",
documentationType: "user"
}}
label="Open Campaign assurance documentation"
/>
</Card>
</PageLayout>);
@@ -5,6 +5,7 @@ import { PageActionBar, PageLayout } from "@govoplan/core-webui";
import { Card } from "@govoplan/core-webui";
import { LoadingFrame } from "@govoplan/core-webui";
import LockedVersionNotice from "./components/LockedVersionNotice";
import LegacyMailMigrationNotice from "./components/LegacyMailMigrationNotice";
import VersionLine from "./components/VersionLine";
import { ToggleSwitch } from "@govoplan/core-webui";
import { useCampaignWorkspaceData } from "./hooks/useCampaignWorkspaceData";
@@ -22,7 +23,7 @@ export default function CampaignFieldsPage({ settings, campaignId }: {settings:
const version = data.currentVersion;
const locked = isAuditLockedVersion(version, data.campaign?.current_version_id);
const { draft, setDraft, displayDraft, dirty, saveState, setSaveState, localError, setLocalError, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
const { draft, setDraft, displayDraft, dirty, saving, saveState, setSaveState, localError, setLocalError, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
settings,
campaignId,
version,
@@ -155,15 +156,16 @@ export default function CampaignFieldsPage({ settings, campaignId }: {settings:
mode="workspace"
title="i18n:govoplan-campaign.fields.e8b68527"
description={<VersionLine version={version} versions={data.versions} status={saveState} />}
headerLoading={loading}
headerLoading={loading || saving}
error={error}
actions={<PageActionBar
variant="editor"
state={loading ? "saving" : dirty ? "dirty" : "clean"}
state={loading || saving ? "saving" : dirty ? "dirty" : "clean"}
discardAction={{ label: "i18n:govoplan-campaign.discard.36fff63c", onClick: () => void discardDraft() }}
saveAction={{ label: "i18n:govoplan-campaign.save.efc007a3", onClick: saveFields, disabled: !canSave && dirty, disabledReason: !canSave && dirty ? "Resolve the current field-definition blocker before saving." : undefined }}
/>}
notices={(localError || fieldNameWarning || locked) ? <>
notices={(localError || fieldNameWarning || locked || version?.mail_profile_migration_required) ? <>
{version?.mail_profile_migration_required && <LegacyMailMigrationNotice campaignId={campaignId} versionId={version.id} />}
{localError && <DismissibleAlert tone="danger" resetKey={localError} floating>{localError}</DismissibleAlert>}
{fieldNameWarning && <DismissibleAlert tone="warning" resetKey={fieldNameWarning} floating>{fieldNameWarning}</DismissibleAlert>}
{locked && <LockedVersionNotice settings={settings} campaignId={campaignId} version={version} currentVersionId={data.campaign?.current_version_id} reload={reload} message="i18n:govoplan-campaign.this_page_is_read_only_for_the_selected_version.dacf5743" />}
@@ -1,18 +1,28 @@
import { useEffect, useState } from "react";
import { ExternalLink } from "lucide-react";
import { ExternalLink, Upload } from "lucide-react";
import { formatDateTime as formatPlatformDateTime, formatDateTimeFromDate, mergeDeltaRows } from "@govoplan/core-webui";
import { Link } from "react-router";
import type { ApiSettings } from "../../types";
import type { ApiSettings, AuthInfo } from "../../types";
import { Card } from "@govoplan/core-webui";
import { Button } from "@govoplan/core-webui";
import { Dialog } from "@govoplan/core-webui";
import { FormField } from "@govoplan/core-webui";
import { StatusBadge } from "@govoplan/core-webui";
import { LoadingFrame } from "@govoplan/core-webui";
import { PageActionBar, PageLayout, TableActionGroup, i18nMessage, useGuardedNavigate } from "@govoplan/core-webui";
import { DismissibleAlert, PageActionBar, PageLayout, TableActionGroup, ToggleSwitch, hasScope, i18nMessage, useGuardedNavigate } from "@govoplan/core-webui";
import { DataGrid, type DataGridColumn } from "@govoplan/core-webui";
import { createNewCampaign, listCampaignsDelta, type CampaignDeltaResponse } from "../../api/campaigns";
import {
createNewCampaign,
importCampaignPackage,
listCampaignsDelta,
previewCampaignImport,
type CampaignDeltaResponse,
type CampaignImportPreview,
type CampaignTransferScope
} from "../../api/campaigns";
import type { CampaignListItem } from "../../types";
export default function CampaignListPage({ settings }: {settings: ApiSettings;}) {
export default function CampaignListPage({ settings, auth }: {settings: ApiSettings;auth: AuthInfo;}) {
const navigate = useGuardedNavigate();
const [campaigns, setCampaigns] = useState<CampaignListItem[]>([]);
const [error, setError] = useState<string>("");
@@ -20,6 +30,16 @@ export default function CampaignListPage({ settings }: {settings: ApiSettings;})
const [creating, setCreating] = useState(false);
const [lastLoadedAt, setLastLoadedAt] = useState<string>("");
const [campaignDeltaWatermark, setCampaignDeltaWatermark] = useState<string | null>(null);
const [importOpen, setImportOpen] = useState(false);
const [importPackage, setImportPackage] = useState<Record<string, unknown> | null>(null);
const [importPreview, setImportPreview] = useState<CampaignImportPreview | null>(null);
const [importScopes, setImportScopes] = useState<CampaignTransferScope[]>([]);
const [importIdentity, setImportIdentity] = useState({ external_id: "", name: "" });
const [importPreviewStale, setImportPreviewStale] = useState(false);
const [importBusy, setImportBusy] = useState(false);
const [importError, setImportError] = useState("");
const canImport = hasScope(auth, "campaigns:campaign:import") && hasScope(auth, "campaigns:campaign:create");
const canImportRecipients = hasScope(auth, "campaigns:recipient:import") && hasScope(auth, "campaigns:recipient:write");
async function load(forcedSince: string | null | undefined = campaignDeltaWatermark) {
setLoading(true);
@@ -60,6 +80,101 @@ export default function CampaignListPage({ settings }: {settings: ApiSettings;})
}
}
function openImport() {
setImportPackage(null);
setImportPreview(null);
setImportScopes([]);
setImportIdentity({ external_id: "", name: "" });
setImportPreviewStale(false);
setImportError("");
setImportOpen(true);
}
async function readImportFile(file: File | undefined) {
if (!file) return;
setImportBusy(true);
setImportError("");
try {
if (file.size > 25 * 1024 * 1024) throw new Error("Campaign packages larger than 25 MB must be reviewed and imported through a governed integration.");
const parsed: unknown = JSON.parse(await file.text());
if (!parsed || typeof parsed !== "object" || Array.isArray(parsed)) throw new Error("Select a JSON object exported as a portable Campaign package.");
const packageData = parsed as Record<string, unknown>;
const preview = await previewCampaignImport(settings, { package: packageData });
const allowedScopes = preview.selected_scopes.filter((scope) => scope !== "recipients" || canImportRecipients);
setImportPackage(packageData);
setImportPreview(preview);
setImportScopes(allowedScopes);
setImportIdentity({
external_id: preview.destination.external_id ?? "",
name: preview.destination.name ?? ""
});
setImportPreviewStale(allowedScopes.length !== preview.selected_scopes.length);
} catch (err) {
setImportPackage(null);
setImportPreview(null);
setImportError(err instanceof Error ? err.message : String(err));
} finally {
setImportBusy(false);
}
}
function patchImportIdentity(key: "external_id" | "name", value: string) {
setImportIdentity((current) => ({ ...current, [key]: value }));
setImportPreviewStale(true);
}
function toggleImportScope(scope: CampaignTransferScope, checked: boolean) {
setImportScopes((current) => checked
? [...current, scope].filter((item, index, rows) => rows.indexOf(item) === index)
: current.filter((item) => item !== scope));
setImportPreviewStale(true);
}
async function refreshImportPreview() {
if (!importPackage || importBusy || importScopes.length === 0) return;
setImportBusy(true);
setImportError("");
try {
const preview = await previewCampaignImport(settings, {
package: importPackage,
selected_scopes: importScopes,
external_id: importIdentity.external_id.trim() || undefined,
name: importIdentity.name.trim() || undefined
});
setImportPreview(preview);
setImportIdentity({
external_id: preview.destination.external_id ?? importIdentity.external_id,
name: preview.destination.name ?? importIdentity.name
});
setImportPreviewStale(false);
} catch (err) {
setImportError(err instanceof Error ? err.message : String(err));
} finally {
setImportBusy(false);
}
}
async function applyImport() {
if (!importPackage || !importPreview?.compatible || !importPreview.package_sha256 || importPreviewStale || importBusy) return;
setImportBusy(true);
setImportError("");
try {
const created = await importCampaignPackage(settings, {
package: importPackage,
selected_scopes: importScopes,
external_id: importIdentity.external_id.trim() || undefined,
name: importIdentity.name.trim() || undefined,
expected_package_sha256: importPreview.package_sha256
});
setImportOpen(false);
navigate(`/campaigns/${created.campaign.id}`);
} catch (err) {
setImportError(err instanceof Error ? err.message : String(err));
} finally {
setImportBusy(false);
}
}
useEffect(() => {
setCampaignDeltaWatermark(null);
load(null);
@@ -141,7 +256,7 @@ export default function CampaignListPage({ settings }: {settings: ApiSettings;})
}];
return (
return (<>
<PageLayout
archetype="collection"
mode="workspace"
@@ -154,9 +269,15 @@ export default function CampaignListPage({ settings }: {settings: ApiSettings;})
variant="collection"
refreshable
reloadAction={{ onReload: () => void load(null), loading }}
createAction={<Button variant="primary" onClick={create} disabled={creating}>
{creating ? "i18n:govoplan-campaign.creating.94d7d8ee" : "i18n:govoplan-campaign.new_campaign.aaf9a8a4"}
createAction={<>
{canImport && <Button onClick={openImport} disabled={creating || importBusy}>
<Upload size={16} aria-hidden="true" />
Import package
</Button>}
<Button variant="primary" onClick={create} disabled={creating}>
{creating ? "i18n:govoplan-campaign.creating.94d7d8ee" : "i18n:govoplan-campaign.new_campaign.aaf9a8a4"}
</Button>
</>}
/>}
>
@@ -185,7 +306,75 @@ export default function CampaignListPage({ settings }: {settings: ApiSettings;})
}
</LoadingFrame>
</Card>
</PageLayout>);
</PageLayout>
<Dialog
open={importOpen}
title="Import portable Campaign package"
className="campaign-copy-dialog campaign-import-dialog"
helpContextId="campaigns.action.import-package"
closeDisabled={importBusy}
onClose={() => setImportOpen(false)}
footer={<>
<Button onClick={() => setImportOpen(false)} disabled={importBusy}>Cancel</Button>
{importPackage && <Button onClick={() => void refreshImportPreview()} disabled={importBusy || importScopes.length === 0 || !importPreviewStale}>
{importBusy ? "Checking..." : "Refresh preview"}
</Button>}
<Button
variant="primary"
onClick={() => void applyImport()}
disabled={importBusy || importPreviewStale || !importPreview?.compatible || !importPreview.package_sha256}>
{importBusy ? "Importing..." : "Create draft"}
</Button>
</>}>
<div className="campaign-copy-form">
<DismissibleAlert tone="info" resetKey="campaign-portable-import-safety">
Import always creates a new draft. Historical review, approval, and delivery evidence is shown in the preview but never replayed as live state.
</DismissibleAlert>
<FormField label="Portable Campaign package" help="Select a .govoplan-campaign.json file. Packages are integrity-checked before any draft is created.">
<input type="file" accept="application/json,.json,.govoplan-campaign.json" disabled={importBusy} onChange={(event) => void readImportFile(event.target.files?.[0])} />
</FormField>
{importError && <div className="inline-alert is-error" role="alert">{importError}</div>}
{importPreview && <>
<div className="campaign-copy-identity">
<FormField label="Campaign name">
<input value={importIdentity.name} disabled={importBusy} onChange={(event) => patchImportIdentity("name", event.target.value)} />
</FormField>
<FormField label="Campaign ID">
<input value={importIdentity.external_id} disabled={importBusy} onChange={(event) => patchImportIdentity("external_id", event.target.value)} />
</FormField>
</div>
<div className="campaign-copy-options">
{importPreview.available_scopes.map((scope) => <div className="campaign-copy-option" key={scope}>
<div>
<strong>{transferScopeLabel(scope)}</strong>
<small>{transferScopeDescription(scope)}</small>
</div>
<ToggleSwitch
label={`Import ${transferScopeLabel(scope)}`}
checked={importScopes.includes(scope)}
disabled={importBusy || scope === "recipients" && !canImportRecipients}
onChange={(checked) => toggleImportScope(scope, checked)} />
</div>)}
</div>
{importPreviewStale && <p className="muted small-note">Identity or scope choices changed. Refresh the preview before importing.</p>}
{!importPreview.compatible && <div className="inline-alert is-error" role="alert">
<strong>This package cannot be imported.</strong>
<ul>{importPreview.errors.map((item) => <li key={item}>{item}</li>)}</ul>
</div>}
{importPreview.warnings.length > 0 && <div className="inline-alert is-warning">
<strong>Review before import</strong>
<ul>{importPreview.warnings.map((item) => <li key={item}>{item}</li>)}</ul>
</div>}
<div className="campaign-import-plan">
<ImportPlan title="Will create" items={importPreview.will_create} />
<ImportPlan title="Will skip" items={importPreview.will_skip} />
</div>
<p className="muted mono-small">Package {importPreview.package_id ?? "unknown"} · SHA-256 {importPreview.package_sha256 ?? "unavailable"}</p>
</>}
</div>
</Dialog>
</>);
}
@@ -194,6 +383,40 @@ function shortId(value: string): string {
return `${value.slice(0, 12)}${value.slice(-6)}`;
}
function ImportPlan({ title, items }: {title: string;items: CampaignImportPreview["will_create"];}) {
return <div>
<h3>{title}</h3>
{items.length === 0
? <p className="muted">Nothing.</p>
: <ul>{items.map((item) => <li key={`${item.scope}:${item.code}`}>
<strong>{transferScopeLabel(item.scope)}</strong>: {item.summary}
{typeof item.item_count === "number" ? ` (${item.item_count})` : ""}
</li>)}</ul>}
</div>;
}
function transferScopeLabel(scope: CampaignTransferScope): string {
return ({
metadata: "Metadata",
template_config: "Template and configuration",
recipients: "Recipients",
attachments: "Attachments",
review_state: "Review state",
delivery_history: "Delivery history"
} satisfies Record<CampaignTransferScope, string>)[scope];
}
function transferScopeDescription(scope: CampaignTransferScope): string {
return ({
metadata: "Identity and source description for the new draft.",
template_config: "Portable fields, templates, policies, and delivery settings.",
recipients: "Campaign-local recipient rows and import provenance.",
attachments: "Attachment rules and references; never file content.",
review_state: "Historical evidence retained in the package, never replayed.",
delivery_history: "Historical outcomes retained in the package, never replayed."
} satisfies Record<CampaignTransferScope, string>)[scope];
}
function formatDateTime(value?: string): string {
return formatPlatformDateTime(value);
}
@@ -77,7 +77,7 @@ export default function CampaignModulePage({
? <OperatorQueuePage settings={settings} auth={auth} />
: active === "reports"
? <AggregateReportsPage settings={settings} />
: <CampaignListPage settings={settings} />}
: <CampaignListPage settings={settings} auth={auth} />}
</WorkspaceLayout>
);
}
@@ -1,6 +1,6 @@
import { MetricGrid } from "@govoplan/core-webui";
import { useEffect, useMemo, useState } from "react";
import { Archive, CalendarClock, Copy, ExternalLink, LockKeyhole, LockOpen, Pause, Play, Trash2 } from "lucide-react";
import { Archive, CalendarClock, Copy, Download, ExternalLink, LockKeyhole, LockOpen, Pause, Play, Trash2 } from "lucide-react";
import { Link } from "react-router";
import type { ApiSettings, AuthInfo } from "../../types";
import { FormGrid, Button } from "@govoplan/core-webui";
@@ -21,6 +21,7 @@ import {
copyCampaign,
createCampaignSchedule,
deleteCampaign,
exportCampaignPackage,
getCampaignLifecyclePolicy,
lockCampaignVersionPermanently,
lockCampaignVersionTemporarily,
@@ -32,6 +33,7 @@ import {
type CampaignScheduleCreate,
type CampaignLifecyclePolicy,
type CampaignCopyOptions,
type CampaignTransferScope,
type CampaignVersionDetail,
type CampaignVersionListItem } from
"../../api/campaigns";
@@ -49,6 +51,7 @@ import {
summaryValue } from
"./utils/campaignView";
import { buildUndefinedPlaceholders, extractTemplatePlaceholders, recipientAddressTemplateFieldOptions } from "./utils/templatePlaceholders";
import { downloadJson, safeFileStem } from "./utils/draftEditor";
const campaignModeOptions = ["draft", "test", "send"];
type LockAction = "temporary" | "unlock" | "permanent";
@@ -68,6 +71,7 @@ const defaultCopyOptions: CampaignCopyOptions = {
include_policies: true,
include_mail_profile: true
};
const defaultExportScopes: CampaignTransferScope[] = ["metadata", "template_config"];
function defaultScheduleDraft(): CampaignScheduleCreate {
const start = new Date(Date.now() + 60 * 60 * 1000);
@@ -104,6 +108,9 @@ export default function CampaignOverviewPage({ settings, auth, campaignId }: {se
const [pendingLifecycleAction, setPendingLifecycleAction] = useState<PendingLifecycleAction>(null);
const [copyOptions, setCopyOptions] = useState<CampaignCopyOptions>(defaultCopyOptions);
const [lifecycleBusy, setLifecycleBusy] = useState(false);
const [exportDialogOpen, setExportDialogOpen] = useState(false);
const [exportScopes, setExportScopes] = useState<CampaignTransferScope[]>(defaultExportScopes);
const [exportBusy, setExportBusy] = useState(false);
const [message, setMessage] = useState("");
const [schedules, setSchedules] = useState<CampaignSchedule[]>([]);
const [scheduleDialogOpen, setScheduleDialogOpen] = useState(false);
@@ -113,11 +120,15 @@ export default function CampaignOverviewPage({ settings, auth, campaignId }: {se
const canArchive = Boolean(campaign) && campaign?.status !== "archived" && hasScope(auth, "campaigns:campaign:archive");
const canDelete = Boolean(campaign) && campaign?.status === "draft" && hasScope(auth, "campaigns:campaign:delete");
const canCopy = Boolean(data.currentVersion) && hasScope(auth, "campaigns:campaign:copy");
const canExport = Boolean(data.currentVersion) && hasScope(auth, "campaigns:campaign:export");
const canSchedule = Boolean(data.currentVersion) && hasScope(auth, "campaigns:campaign:schedule") && hasScope(auth, "campaigns:campaign:copy");
const canAutonomousSchedule = canSchedule
&& hasScope(auth, "campaigns:campaign:queue")
&& hasScope(auth, "campaigns:campaign:send")
&& hasScope(auth, "mail:profile:use");
const canExportRecipients = hasScope(auth, "campaigns:recipient:read") && hasScope(auth, "campaigns:recipient:export");
const canExportReview = hasScope(auth, "campaigns:report:read");
const canExportDelivery = canExportRecipients && hasScope(auth, "campaigns:report:export");
function openSection(section: string, fragment = "") {
const params = new URLSearchParams();
@@ -352,6 +363,36 @@ export default function CampaignOverviewPage({ settings, auth, campaignId }: {se
}
}
function toggleExportScope(scope: CampaignTransferScope, checked: boolean) {
setExportScopes((current) => checked
? [...current, scope].filter((item, index, rows) => rows.indexOf(item) === index)
: current.filter((item) => item !== scope));
}
async function exportPortablePackage() {
if (!campaign || !data.currentVersion || exportBusy || exportScopes.length === 0) return;
setExportBusy(true);
setError("");
try {
const portablePackage = await exportCampaignPackage(
settings,
campaign.id,
data.currentVersion.id,
exportScopes
);
downloadJson(
`${safeFileStem(campaign.external_id || campaign.name)}-v${data.currentVersion.version_number ?? 1}.govoplan-campaign.json`,
portablePackage
);
setExportDialogOpen(false);
setMessage("Portable Campaign package downloaded. Keep recipient or delivery packages in an approved location.");
} catch (err) {
setError(err instanceof Error ? err.message : String(err));
} finally {
setExportBusy(false);
}
}
return (
<PageLayout
archetype="editor"
@@ -364,7 +405,16 @@ export default function CampaignOverviewPage({ settings, auth, campaignId }: {se
actions={<PageActionBar
variant="editor"
state={savingIdentity ? "saving" : identityDirty ? "dirty" : "clean"}
refreshable
reloadAction={{ onReload: () => void reload(), loading }}
primaryActions={<>
{canExport && <Button
onClick={() => setExportDialogOpen(true)}
disabled={loading || savingIdentity || identityDirty || exportBusy}
disabledReason={identityDirty ? "Save or discard overview changes before exporting." : undefined}>
<Download size={16} aria-hidden="true" />
Export package
</Button>}
{canCopy && data.currentVersion && <Button
onClick={() => void prepareLifecycleAction("copy_campaign", data.currentVersion ?? undefined)}
disabled={loading || savingIdentity || lockBusy || lifecycleBusy || identityDirty}
@@ -383,6 +433,8 @@ export default function CampaignOverviewPage({ settings, auth, campaignId }: {se
destructiveActions={<>
{canDelete && <Button
variant="danger"
helpContextId="campaign.overview"
helpModuleId="campaigns"
onClick={() => void prepareLifecycleAction("delete_campaign")}
disabled={loading || savingIdentity || lockBusy || lifecycleBusy || identityDirty}
disabledReason={identityDirty ? "Save or discard overview changes before deleting." : undefined}>
@@ -580,6 +632,34 @@ export default function CampaignOverviewPage({ settings, auth, campaignId }: {se
</div>
</Dialog>
<Dialog
open={exportDialogOpen}
title="Export portable Campaign package"
className="campaign-copy-dialog"
helpContextId="campaigns.action.export-package"
closeDisabled={exportBusy}
onClose={() => setExportDialogOpen(false)}
footer={<>
<Button onClick={() => setExportDialogOpen(false)} disabled={exportBusy}>Cancel</Button>
<Button variant="primary" onClick={() => void exportPortablePackage()} disabled={exportBusy || exportScopes.length === 0}>
{exportBusy ? "Preparing package..." : "Download package"}
</Button>
</>}>
<div className="campaign-copy-form">
<p className="muted small-note">
Configuration-only is the privacy-safe default. The package contains JSON and attachment references, never file content, credentials, or transport secrets.
</p>
<div className="campaign-copy-options">
<CopyOption label="Metadata" detail="Campaign identity, description, and source status." checked={exportScopes.includes("metadata")} onChange={(checked) => toggleExportScope("metadata", checked)} />
<CopyOption label="Template and configuration" detail="Fields, template, validation and delivery settings. Deployment-bound Mail credentials are excluded." checked={exportScopes.includes("template_config")} onChange={(checked) => toggleExportScope("template_config", checked)} />
<CopyOption label="Recipients" detail="Recipient rows and import provenance. This can contain personal data and needs recipient-export authority." checked={exportScopes.includes("recipients")} disabled={!canExportRecipients} onChange={(checked) => toggleExportScope("recipients", checked)} />
<CopyOption label="Attachments" detail="Global and per-recipient attachment rules. File bytes are not embedded." checked={exportScopes.includes("attachments")} onChange={(checked) => toggleExportScope("attachments", checked)} />
<CopyOption label="Review state" detail="Aggregate validation, build, issue, and review evidence. Imports retain provenance but never replay approval state." checked={exportScopes.includes("review_state")} disabled={!canExportReview} onChange={(checked) => toggleExportScope("review_state", checked)} />
<CopyOption label="Delivery history" detail="Recipient-level delivery outcomes and safe provenance. Imports never recreate sent state." checked={exportScopes.includes("delivery_history")} disabled={!canExportDelivery} onChange={(checked) => toggleExportScope("delivery_history", checked)} />
</div>
</div>
</Dialog>
<Dialog
open={scheduleDialogOpen}
title="Schedule campaign"
@@ -1,7 +1,7 @@
import { DescriptionList } from "@govoplan/core-webui";
import { useCallback, useEffect, useMemo, useRef, useState } from "react";
import { Check, RotateCcw, Search, X } from "lucide-react";
import type { ApiSettings } from "../../types";
import type { ApiSettings, AuthInfo } from "../../types";
import {
downloadCampaignJobsCsv,
emailCampaignReport,
@@ -9,7 +9,6 @@ import {
getCampaignJobs,
resolveCampaignJobOutcome,
retryCampaignJobs,
sendCampaignJob,
sendUnattemptedCampaignJobs,
type CampaignJobDetailResponse,
type CampaignJobsResponse,
@@ -17,15 +16,19 @@ import {
"../../api/campaigns";
import { ContentGrid, Card } from "@govoplan/core-webui";
import { Button } from "@govoplan/core-webui";
import { ConfirmDialog } from "@govoplan/core-webui";
import { DataGrid, type DataGridColumn, type DataGridListOption, type DataGridQueryState } from "@govoplan/core-webui";
import { Dialog } from "@govoplan/core-webui";
import { DismissibleAlert } from "@govoplan/core-webui";
import { FormField } from "@govoplan/core-webui";
import { PageActionBar, PageLayout } from "@govoplan/core-webui";
import { StatusBadge } from "@govoplan/core-webui";
import VersionLine from "./components/VersionLine";
import { LoadingFrame, TableActionGroup, ToggleSwitch, i18nMessage } from "@govoplan/core-webui";
import { LoadingFrame, TableActionGroup, ToggleSwitch, hasScope, i18nMessage } from "@govoplan/core-webui";
import { recoverCampaignJobClaim, runCampaignInlineRecovery, type CampaignInlineRecoveryAction } from "../../api/deliveryRecovery";
import ReportRecipients, { reportRecipientSearchText } from "./reporting/ReportRecipients";
import ReportRecoveryDialog from "./reporting/ReportRecoveryDialog";
import { reportClaimRecovery, reportRecoveryHints, reportRetryableFailure, reportUnattempted, type ReportReconciliation } from "./reporting/reportRecovery";
import CampaignDeliveryProgressDialog from "./review/CampaignDeliveryProgressDialog";
import { SEND_STATUS_OPTIONS, IMAP_STATUS_OPTIONS, deliveryStatusLabel } from "./utils/deliveryStatusOptions";
import { useCampaignWorkspaceData } from "./hooks/useCampaignWorkspaceData";
import { asRecord, formatDateTime, humanize } from "./utils/campaignView";
import { emptyCampaignJobsResponse } from "./utils/jobDeltas";
@@ -38,24 +41,6 @@ import {
type ReportGridShortcutId
} from "./utils/reportGridShortcuts";
const SEND_STATUS_OPTIONS: DataGridListOption[] = [
"not_queued",
"skipped",
"queued",
"claimed",
"sending",
"smtp_accepted",
"postbox_accepted",
"print_accepted",
"delivered",
"partially_accepted",
"sent",
"outcome_unknown",
"failed_temporary",
"failed_permanent",
"cancelled"].
map((value) => ({ value, label: deliveryStatusLabel(value) ?? humanize(value) }));
const PRINT_STATUS_OPTIONS: DataGridListOption[] = [
"not_requested",
"ready",
@@ -77,16 +62,6 @@ const POSTBOX_STATUS_OPTIONS: DataGridListOption[] = [
"skipped"].
map((value) => ({ value, label: deliveryStatusLabel(value) ?? humanize(value) }));
const IMAP_STATUS_OPTIONS: DataGridListOption[] = [
"not_requested",
"pending",
"appending",
"appended",
"outcome_unknown",
"failed",
"skipped"].
map((value) => ({ value, label: deliveryStatusLabel(value) ?? humanize(value) }));
const VALIDATION_STATUS_OPTIONS: DataGridListOption[] = [
"ready",
"warning",
@@ -106,17 +81,25 @@ map((value) => ({ value, label: humanize(value) }));
const JOB_GRID_QUERY_DELAY_MS = 300;
type ReconcileRequest = {jobId: string;decision: "smtp_accepted" | "not_sent";} | null;
export default function CampaignReportPage({ settings, campaignId }: {settings: ApiSettings;campaignId: string;}) {
export default function CampaignReportPage({ settings, auth, campaignId }: {settings: ApiSettings;auth: AuthInfo;campaignId: string;}) {
const { data, loading, error, reload } = useCampaignWorkspaceData(settings, campaignId, { includeSummary: true });
const version = data.currentVersion;
const cards = data.summary?.cards;
const sendCounts = data.summary?.status_counts?.send ?? {};
const imapCounts = data.summary?.status_counts?.imap ?? {};
const delivery = asRecord(data.summary?.delivery);
const postboxReceipts = asRecord(data.summary?.postbox_receipts);
const retention = data.summary?.retention;
const rateLimit = asRecord(delivery.rate_limit);
const imapPolicy = asRecord(delivery.imap_append_sent);
const canRetry = hasScope(auth, "campaigns:campaign:retry");
const canSend = hasScope(auth, "campaigns:campaign:send");
const canQueue = hasScope(auth, "campaigns:campaign:queue");
const canReconcile = hasScope(auth, "campaigns:campaign:reconcile");
const workersAvailable = delivery.background_workers_enabled === true || delivery.celery_enabled === true;
const reportContext = JSON.stringify([campaignId, version?.id, settings.apiBaseUrl, settings.apiKey, settings.accessToken, auth.tenant.id, auth.user.id]);
const reportContextRef = useRef(reportContext);
reportContextRef.current = reportContext;
const [jobs, setJobs] = useState<CampaignJobsResponse>(() => emptyCampaignJobsResponse());
const jobsRequestRef = useRef(0);
@@ -140,7 +123,18 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
const [emailRecipients, setEmailRecipients] = useState("");
const [attachCsv, setAttachCsv] = useState(true);
const [attachJson, setAttachJson] = useState(false);
const [reconcile, setReconcile] = useState<ReconcileRequest>(null);
const [reconcile, setReconcile] = useState<ReportReconciliation | null>(null);
const pendingAction = useRef(false);
const [progress, setProgress] = useState<{ versionId: string; requestState: "running" | "finished" | "interrupted"; requestError?: string } | null>(null);
useEffect(() => {
++jobsRequestRef.current;
setJobs(emptyCampaignJobsResponse());
setDetail(null); setReconcile(null); setProgress(null);
setActionError(""); setActionMessage(""); setBusyAction("");
pendingAction.current = false;
setPage(1);
}, [reportContext]);
useEffect(() => {
const handle = window.setTimeout(() => {
@@ -172,6 +166,8 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
const deliveryOutcomeShortcuts: { label: string; value: string | number; shortcutId: ReportGridShortcutId }[] = [
{ label: "i18n:govoplan-campaign.jobs_total.98da65bc", value: cards?.jobs_total ?? "—", shortcutId: "all" },
{ label: "i18n:govoplan-campaign.smtp_accepted.e3aa7603", value: cards?.smtp_accepted ?? cards?.sent ?? 0, shortcutId: "smtp_accepted" },
{ label: "i18n:govoplan-campaign.delivery_status_sending", value: (sendCounts.claimed ?? 0) + (sendCounts.sending ?? 0), shortcutId: "smtp_active" },
{ label: "i18n:govoplan-campaign.delivery_status_queued", value: sendCounts.queued ?? 0, shortcutId: "smtp_queued" },
{ label: "Postbox accepted", value: cards?.postbox_accepted ?? 0, shortcutId: "postbox_accepted" },
{ label: "Print accepted", value: cards?.print_accepted ?? 0, shortcutId: "print_accepted" },
{ label: "i18n:govoplan-campaign.failed.09fef5d8", value: cards?.failed ?? 0, shortcutId: "failed" },
@@ -181,13 +177,16 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
{ label: "i18n:govoplan-campaign.cancelled.a1bf92ef", value: cards?.cancelled ?? 0, shortcutId: "cancelled" }
];
const imapOutcomeShortcuts: { label: string; value: string | number; shortcutId: ReportGridShortcutId }[] = [
{ label: "i18n:govoplan-campaign.delivery_status_pending", value: imapCounts.pending ?? 0, shortcutId: "imap_pending" },
{ label: "i18n:govoplan-campaign.delivery_status_appending", value: imapCounts.appending ?? 0, shortcutId: "imap_active" },
{ label: "i18n:govoplan-campaign.delivery_status_outcome_unknown", value: imapCounts.outcome_unknown ?? 0, shortcutId: "imap_unknown" },
{ label: "i18n:govoplan-campaign.imap_appended.56017ea3", value: cards?.imap_appended ?? 0, shortcutId: "imap_appended" },
{ label: "i18n:govoplan-campaign.imap_failed.50dbca55", value: cards?.imap_failed ?? 0, shortcutId: "imap_failed" },
{ label: "i18n:govoplan-campaign.imap_skipped.5a97b542", value: cards?.imap_skipped ?? jobs.counts.imap?.skipped ?? 0, shortcutId: "imap_skipped" }
];
const loadJobs = useCallback(async () => {
if (!campaignId) return;
if (!campaignId || !version?.id) return;
const requestId = ++jobsRequestRef.current;
setJobsLoading(true);
setActionError("");
@@ -200,16 +199,16 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
sortBy: campaignJobSortColumn(appliedJobGridQuery.sort?.columnId),
sortDirection: appliedJobGridQuery.sort?.direction ?? "asc",
filters: appliedJobGridQuery.filters
});
if (requestId !== jobsRequestRef.current) return;
}, { cache: "no-store" });
if (requestId !== jobsRequestRef.current || reportContext !== reportContextRef.current) return;
setJobs(response);
if (response.pages > 0 && page > response.pages) setPage(response.pages);
} catch (err) {
if (requestId === jobsRequestRef.current) setActionError(err instanceof Error ? err.message : String(err));
if (requestId === jobsRequestRef.current && reportContext === reportContextRef.current) setActionError(err instanceof Error ? err.message : String(err));
} finally {
if (requestId === jobsRequestRef.current) setJobsLoading(false);
if (requestId === jobsRequestRef.current && reportContext === reportContextRef.current) setJobsLoading(false);
}
}, [settings, campaignId, version?.id, page, pageSize, appliedQuery, appliedJobGridQuery]);
}, [settings, campaignId, version?.id, page, pageSize, appliedQuery, appliedJobGridQuery, reportContext]);
useEffect(() => {
void loadJobs();
@@ -220,7 +219,8 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
}
async function runExplicitAction(action: "retry" | "unattempted") {
if (!version || busyAction) return;
if (!version || busyAction || pendingAction.current || !workersAvailable || (action === "retry" ? !canRetry : !canQueue)) return;
pendingAction.current = true;
setBusyAction(action);
setActionError("");
setActionMessage("");
@@ -228,94 +228,74 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
const response = action === "retry" ?
await retryCampaignJobs(settings, campaignId, { version_id: version.id, enqueue_celery: true }) :
await sendUnattemptedCampaignJobs(settings, campaignId, { version_id: version.id, enqueue_celery: true });
if (reportContext !== reportContextRef.current) return;
const result = asRecord(response.result ?? response);
setActionMessage(`${humanize(String(result.action ?? action))}: ${String(result.selected_count ?? 0)} job(s) selected, ${String(result.enqueued_count ?? 0)} enqueued.`);
await reloadAll();
} catch (err) {
setActionError(err instanceof Error ? err.message : String(err));
if (reportContext === reportContextRef.current) setActionError(err instanceof Error ? err.message : String(err));
} finally {
setBusyAction("");
if (reportContext === reportContextRef.current) { pendingAction.current = false; setBusyAction(""); }
}
}
const failedRowsOnPage = useMemo(
() => jobs.jobs.filter((row) => retryableFailedStatus(String(row.send_status ?? "")) && String(row.id ?? "")),
() => jobs.jobs.filter((row) => reportRetryableFailure(row) && String(row.id ?? "")),
[jobs.jobs]
);
const unattemptedRowsOnPage = useMemo(() => jobs.jobs.filter(row => reportUnattempted(row) && String(row.id ?? "")), [jobs.jobs]);
async function retryFailedSynchronously(rows: Record<string, unknown>[]) {
if (!version || busyAction || rows.length === 0) return;
setBusyAction(rows.length === 1 ? `retry-sync:${String(rows[0].id ?? "")}` : "retry-sync-page");
async function runInlineRecovery(action: CampaignInlineRecoveryAction, rows: Record<string, unknown>[]) {
if (!version || busyAction || pendingAction.current || !canSend || (action === "retry" ? !canRetry : !canQueue) || rows.length === 0) return;
const jobIds = [...new Set(rows.map(row => String(row.id ?? "")).filter(Boolean))];
if (!jobIds.length) return;
pendingAction.current = true;
setBusyAction(`inline:${action}`);
setActionError("");
setActionMessage("");
let attempted = 0;
let accepted = 0;
let skipped = 0;
const failures: string[] = [];
const versionId = version.id;
setProgress({ versionId, requestState: "running" });
try {
for (const row of rows) {
const jobId = String(row.id ?? "");
if (!jobId) {
skipped += 1;
continue;
}
const sendStatus = String(row.send_status ?? "");
const queueResponse = await retryCampaignJobs(settings, campaignId, {
version_id: version.id,
job_ids: [jobId],
include_permanent: sendStatus === "failed_permanent",
enqueue_celery: false
});
const queueResult = asRecord(queueResponse.result ?? queueResponse);
if (Number(queueResult.selected_count ?? 0) < 1) {
skipped += 1;
const skippedRows = Array.isArray(queueResult.skipped) ? queueResult.skipped.map(asRecord) : [];
const reason = String(skippedRows[0]?.reason ?? "not selected for retry");
failures.push(`${shortJobId(jobId)}: ${reason}`);
continue;
}
attempted += 1;
try {
const sendResponse = await sendCampaignJob(settings, campaignId, jobId, {
kind: "single_resend",
idempotency_key: crypto.randomUUID(),
reason: "Operator requested synchronous resend from the campaign report.",
include_warnings: true,
use_rate_limit: true,
enqueue_imap_task: false
});
const sendResult = asRecord(asRecord(sendResponse.result ?? sendResponse).result);
const status = String(sendResult.status ?? "submitted");
if (["smtp_accepted", "postbox_accepted", "print_accepted", "delivered", "partially_accepted", "already_accepted"].includes(status)) accepted += 1;
else failures.push(`${shortJobId(jobId)}: ${humanize(status)}`);
} catch (err) {
failures.push(`${shortJobId(jobId)}: ${err instanceof Error ? err.message : String(err)}`);
}
}
const failed = failures.length;
setActionMessage(`Synchronous retry finished: ${attempted} attempted, ${accepted} accepted, ${failed} failed, ${skipped} skipped.`);
if (failures.length > 0) setActionError(failures.slice(0, 5).join("\n"));
await reloadAll();
const result = await runCampaignInlineRecovery(settings, campaignId, action, {
version_id: versionId, job_ids: jobIds,
...(action === "retry" ? { include_permanent: rows.some(row => row.send_status === "failed_permanent") } : {})
});
if (reportContext !== reportContextRef.current) return;
setProgress({ versionId, requestState: "finished" });
setActionMessage(i18nMessage("i18n:govoplan-campaign.report_inline_result", {
value0: result.attempted_count ?? 0, value1: result.sent_count ?? 0,
value2: result.failed_count ?? 0, value3: result.outcome_unknown_count ?? 0, value4: result.remaining_count ?? 0
}));
try { await reloadAll(); }
catch { if (reportContext === reportContextRef.current) setActionError("i18n:govoplan-campaign.report_acknowledged_refresh_failed"); }
} catch (cause) {
if (reportContext !== reportContextRef.current) return;
const message = cause instanceof Error ? cause.message : String(cause);
setActionError(message);
setProgress({ versionId, requestState: "interrupted", requestError: message });
} finally {
setBusyAction("");
if (reportContext === reportContextRef.current) { pendingAction.current = false; setBusyAction(""); }
}
}
async function reconcileOutcome() {
if (!reconcile || busyAction) return;
async function reconcileOutcome(note: string) {
if (!reconcile || busyAction || pendingAction.current || !canReconcile || !note.trim()) return;
pendingAction.current = true;
setBusyAction("reconcile");
setActionError("");
try {
await resolveCampaignJobOutcome(settings, campaignId, reconcile.jobId, reconcile.decision);
setActionMessage(reconcile.decision === "smtp_accepted" ?
"i18n:govoplan-campaign.the_job_was_recorded_as_smtp_accepted_and_is_pro.12ee72b6" :
"i18n:govoplan-campaign.the_job_was_recorded_as_not_sent_it_is_now_an_ex.2cea8409");
if (reconcile.kind === "claim") {
await recoverCampaignJobClaim(settings, campaignId, reconcile.jobId, { channel: reconcile.channel, expected_revision: reconcile.revision, note });
} else {
await resolveCampaignJobOutcome(settings, campaignId, reconcile.jobId, reconcile.decision, note);
}
if (reportContext !== reportContextRef.current) return;
setActionMessage(reconcile.kind === "claim" ? "i18n:govoplan-campaign.report_claim_recovered" : "i18n:govoplan-campaign.report_evidence_recorded");
setReconcile(null);
await reloadAll();
} catch (err) {
setActionError(err instanceof Error ? err.message : String(err));
try { await reloadAll(); }
catch { if (reportContext === reportContextRef.current) setActionError("i18n:govoplan-campaign.report_acknowledged_refresh_failed"); }
} finally {
setBusyAction("");
if (reportContext === reportContextRef.current) { pendingAction.current = false; setBusyAction(""); }
}
}
@@ -323,11 +303,12 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
setBusyAction("detail");
setActionError("");
try {
setDetail(await getCampaignJobDetail(settings, campaignId, jobId));
const response = await getCampaignJobDetail(settings, campaignId, jobId);
if (reportContext === reportContextRef.current) setDetail(response);
} catch (err) {
setActionError(err instanceof Error ? err.message : String(err));
if (reportContext === reportContextRef.current) setActionError(err instanceof Error ? err.message : String(err));
} finally {
setBusyAction("");
if (reportContext === reportContextRef.current) setBusyAction("");
}
}
@@ -376,13 +357,8 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
resizable: true,
sortable: true,
filterable: true,
render: (row) =>
<div className="recipient-outcome-cell">
<strong>{String(row.recipient_email ?? "—")}</strong>
<span>{String(row.entry_id ?? i18nMessage("i18n:govoplan-campaign.entry_value.b7706ee4", { value0: Number(row.entry_index ?? 0) || 1 }))}</span>
</div>,
value: (row) => String(row.recipient_email ?? "—")
render: (row) => <ReportRecipients row={row} />,
value: reportRecipientSearchText
},
{ id: "subject", header: "i18n:govoplan-campaign.subject.8d183dbd", width: "minmax(260px, 1fr)", maxWidth: 640, resizable: true, sortable: true, filterable: true, value: (row) => String(row.subject ?? "—") },
{ id: "validation", header: "i18n:govoplan-campaign.validation.dd74d182", width: 145, sortable: true, filterable: true, columnType: "from-list", list: { options: VALIDATION_STATUS_OPTIONS, display: "pill" }, render: (row) => <StatusBadge status={String(row.validation_status ?? "unknown")} />, value: (row) => String(row.validation_status ?? "unknown") },
@@ -422,7 +398,8 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
width: "minmax(220px, 1fr)",
maxWidth: 720,
resizable: true,
render: (row) => <span className={row.last_error ? "recipient-outcome-error" : "muted"} title={String(row.last_error ?? "")}>{String(row.last_error ?? "—")}</span>,
render: (row) => <div className="recipient-outcome-cell"><span className={row.last_error ? "recipient-outcome-error" : "muted"} title={String(row.last_error ?? "")}>{String(row.last_error ?? "—")}</span>
{reportRecoveryHints(row).map(hint => <span key={hint}>{hint}</span>)}</div>,
value: (row) => String(row.last_error ?? "—")
},
{ id: "updated", header: "i18n:govoplan-campaign.updated.f2f8570d", width: 165, sortable: true, value: (row) => formatDateTime(String(row.updated_at ?? row.sent_at ?? row.queued_at ?? "")) },
@@ -434,16 +411,23 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
render: (row) => {
const id = String(row.id ?? "");
const status = String(row.send_status ?? "");
const smtpClaim = reportClaimRecovery(row, "smtp");
const imapClaim = reportClaimRecovery(row, "imap");
return <TableActionGroup actions={[
{ id: "details", label: "i18n:govoplan-campaign.details.dc3decbb", icon: <Search aria-hidden="true" />, disabled: !id || busyAction === "detail", onClick: () => void openJob(id) },
{ id: "retry", label: busyAction === `retry-sync:${id}` ? "Sending..." : "Retry now", icon: <RotateCcw aria-hidden="true" />, applicable: retryableFailedStatus(status), disabled: !id || Boolean(busyAction), onClick: () => void retryFailedSynchronously([row]) },
{ id: "accepted", label: "i18n:govoplan-campaign.accepted.61a0572c", icon: <Check aria-hidden="true" />, applicable: status === "outcome_unknown", onClick: () => setReconcile({ jobId: id, decision: "smtp_accepted" }) },
{ id: "not-sent", label: "i18n:govoplan-campaign.not_sent.587c501e", icon: <X aria-hidden="true" />, variant: "danger", applicable: status === "outcome_unknown", onClick: () => setReconcile({ jobId: id, decision: "not_sent" }) }
{ id: "retry", label: "i18n:govoplan-campaign.report_retry_now", icon: <RotateCcw aria-hidden="true" />, applicable: reportRetryableFailure(row), disabled: !id || !canRetry || !canSend || Boolean(busyAction), onClick: () => void runInlineRecovery("retry", [row]) },
{ id: "unattempted", label: "i18n:govoplan-campaign.report_send_unattempted_now", icon: <RotateCcw aria-hidden="true" />, applicable: reportUnattempted(row), disabled: !id || !canQueue || !canSend || Boolean(busyAction), onClick: () => void runInlineRecovery("send-unattempted", [row]) },
{ id: "accepted", label: "i18n:govoplan-campaign.accepted.61a0572c", icon: <Check aria-hidden="true" />, applicable: status === "outcome_unknown", disabled: !canReconcile || Boolean(busyAction), onClick: () => setReconcile({ kind: "outcome", jobId: id, decision: "smtp_accepted" }) },
{ id: "not-sent", label: "i18n:govoplan-campaign.not_sent.587c501e", icon: <X aria-hidden="true" />, variant: "danger", applicable: status === "outcome_unknown", disabled: !canReconcile || Boolean(busyAction), onClick: () => setReconcile({ kind: "outcome", jobId: id, decision: "not_sent" }) },
{ id: "recover-smtp", label: "i18n:govoplan-campaign.report_recover_smtp_claim", icon: <RotateCcw aria-hidden="true" />, applicable: smtpClaim.eligible, disabled: !canReconcile || Boolean(busyAction), onClick: () => setReconcile({ kind: "claim", jobId: id, channel: "smtp", revision: smtpClaim.revision }) },
{ id: "recover-imap", label: "i18n:govoplan-campaign.report_recover_imap_claim", icon: <RotateCcw aria-hidden="true" />, applicable: imapClaim.eligible, disabled: !canReconcile || Boolean(busyAction), onClick: () => setReconcile({ kind: "claim", jobId: id, channel: "imap", revision: imapClaim.revision }) },
{ id: "imap-appended", label: "i18n:govoplan-campaign.report_record_imap_appended", icon: <Check aria-hidden="true" />, applicable: row.imap_status === "outcome_unknown", disabled: !canReconcile || Boolean(busyAction), onClick: () => setReconcile({ kind: "outcome", jobId: id, decision: "imap_appended" }) },
{ id: "imap-not-appended", label: "i18n:govoplan-campaign.report_record_imap_not_appended", icon: <X aria-hidden="true" />, variant: "danger", applicable: row.imap_status === "outcome_unknown", disabled: !canReconcile || Boolean(busyAction), onClick: () => setReconcile({ kind: "outcome", jobId: id, decision: "imap_not_appended" }) }
]} />;
}
}],
[busyAction, retryFailedSynchronously]);
[busyAction, canRetry, canSend, canQueue, canReconcile, runInlineRecovery]);
return (
<PageLayout
@@ -457,7 +441,7 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
actions={<PageActionBar
variant="detail"
refreshable
reloadAction={{ onReload: () => void reloadAll(), loading: loading || jobsLoading }}
reloadAction={{ onReload: () => void reloadAll(), loading: loading || jobsLoading, disabled: Boolean(busyAction) }}
primaryActions={<>
<Button onClick={() => void exportCsv()} disabled={busyAction === "csv"}>i18n:govoplan-campaign.download_csv.eaa216ad</Button>
<Button onClick={() => setEmailOpen(true)}>i18n:govoplan-campaign.email_report.ee3e7091</Button>
@@ -533,12 +517,17 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
<Card title="i18n:govoplan-campaign.explicit_delivery_actions.b35e72a4">
<p className="muted">i18n:govoplan-campaign.these_actions_never_include_smtp_accepted_or_unr.449d0a80</p>
<div className="button-row compact-actions">
<Button onClick={() => void runExplicitAction("retry")} disabled={!version || Boolean(busyAction)}>i18n:govoplan-campaign.retry_temporary_failures.e65cfd13</Button>
<Button onClick={() => void retryFailedSynchronously(failedRowsOnPage)} disabled={!version || Boolean(busyAction) || failedRowsOnPage.length === 0}>
{busyAction === "retry-sync-page" ? "Sending failed jobs..." : `Retry failed on this page now (${failedRowsOnPage.length})`}
<Button onClick={() => void runExplicitAction("retry")} disabled={!version || !canRetry || !workersAvailable || Boolean(busyAction)}>i18n:govoplan-campaign.report_queue_retry_workers</Button>
<Button onClick={() => void runInlineRecovery("retry", failedRowsOnPage)} disabled={!version || !canRetry || !canSend || Boolean(busyAction) || failedRowsOnPage.length === 0}>
{i18nMessage("i18n:govoplan-campaign.report_retry_page_now", { value0: failedRowsOnPage.length })}
</Button>
<Button helpContextId="campaign.report" helpModuleId="campaigns" onClick={() => void runExplicitAction("unattempted")} disabled={!version || !canQueue || !workersAvailable || Boolean(busyAction)}>i18n:govoplan-campaign.report_queue_unattempted_workers</Button>
<Button onClick={() => void runInlineRecovery("send-unattempted", unattemptedRowsOnPage)} disabled={!version || !canQueue || !canSend || Boolean(busyAction) || unattemptedRowsOnPage.length === 0}>
{i18nMessage("i18n:govoplan-campaign.report_send_page_now", { value0: unattemptedRowsOnPage.length })}
</Button>
<Button onClick={() => void runExplicitAction("unattempted")} disabled={!version || Boolean(busyAction)}>i18n:govoplan-campaign.send_unattempted_jobs.db7acc9f</Button>
</div>
{!workersAvailable && <p className="muted">i18n:govoplan-campaign.report_workers_unavailable</p>}
<p className="muted">i18n:govoplan-campaign.report_inline_scope_help</p>
</Card>
</ContentGrid>
@@ -591,7 +580,7 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
footer={
<div className="button-row">
<Button onClick={() => setEmailOpen(false)} disabled={busyAction === "email"}>i18n:govoplan-campaign.cancel.77dfd213</Button>
<Button variant="primary" onClick={() => void sendReportEmail()} disabled={!emailRecipients.trim() || busyAction === "email"}>i18n:govoplan-campaign.send_report.a5b32af9</Button>
<Button variant="primary" helpContextId="campaign.report" helpModuleId="campaigns" onClick={() => void sendReportEmail()} disabled={!emailRecipients.trim() || busyAction === "email"}>i18n:govoplan-campaign.send_report.a5b32af9</Button>
</div>
}>
@@ -612,7 +601,7 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
{detail &&
<div className="stacked-sections">
<DescriptionList variant="inline">
<div><dt>i18n:govoplan-campaign.recipient.90343260</dt><dd>{String(detail.job.recipient_email ?? "—")}</dd></div>
<div><dt>i18n:govoplan-campaign.recipients.78cbf8eb</dt><dd><ReportRecipients row={detail.job} /></dd></div>
<div><dt>i18n:govoplan-campaign.subject.8d183dbd</dt><dd>{String(detail.job.subject ?? "—")}</dd></div>
<div><dt>i18n:govoplan-campaign.message_id.465056ba</dt><dd>{String(detail.job.message_id_header ?? "—")}</dd></div>
<div><dt>i18n:govoplan-campaign.smtp_state.ff372566</dt><dd><StatusBadge status={String(detail.job.send_status ?? "unknown")} label={deliveryStatusLabel(String(detail.job.send_status ?? "unknown"))} /></dd></div>
@@ -640,17 +629,11 @@ export default function CampaignReportPage({ settings, campaignId }: {settings:
}
</Dialog>
<ConfirmDialog
open={Boolean(reconcile)}
title={reconcile?.decision === "smtp_accepted" ? "i18n:govoplan-campaign.record_smtp_acceptance.c40f8c9d" : "i18n:govoplan-campaign.record_message_as_not_sent.42e4faf8"}
message={reconcile?.decision === "smtp_accepted" ?
"i18n:govoplan-campaign.use_this_only_after_checking_the_smtp_server_or_.6f4396e1" :
"i18n:govoplan-campaign.use_this_only_when_you_have_evidence_that_smtp_d.aa48f4ad"}
confirmLabel={reconcile?.decision === "smtp_accepted" ? "i18n:govoplan-campaign.record_accepted.023d6747" : "i18n:govoplan-campaign.record_not_sent.b376b4ed"}
tone={reconcile?.decision === "smtp_accepted" ? "default" : "danger"}
busy={busyAction === "reconcile"}
onConfirm={() => void reconcileOutcome()}
onCancel={() => setReconcile(null)} />
{reconcile && <ReportRecoveryDialog key={`${reconcile.jobId}-${reconcile.kind}-${reconcile.kind === "claim" ? reconcile.channel : reconcile.decision}`}
request={reconcile} onConfirm={reconcileOutcome} onClose={() => setReconcile(null)} />}
{progress && <CampaignDeliveryProgressDialog settings={settings} campaignId={campaignId} versionId={progress.versionId}
kind="smtp" requestState={progress.requestState} requestError={progress.requestError}
onClose={() => { if (!pendingAction.current) setProgress(null); }} />}
</PageLayout>);
@@ -1049,10 +1032,6 @@ function initialReportGridFilters(): Record<string, string | string[]> {
return result;
}
function deliveryStatusLabel(status: string): string | undefined {
return status === "skipped" ? "i18n:govoplan-campaign.skipped.5a000ad7" : undefined;
}
function calendarRsvpStatus(row: Record<string, unknown>): string {
const invitation = asRecord(row.calendar_invitation);
return String(invitation.rsvp_status || "—");
@@ -1086,11 +1065,3 @@ function campaignJobSortColumn(value?: string): CampaignJobSortColumn {
}
return "number";
}
function retryableFailedStatus(status: string): boolean {
return status === "failed_temporary" || status === "failed_permanent" || status === "partially_accepted";
}
function shortJobId(jobId: string): string {
return jobId.length > 12 ? `${jobId.slice(0, 12)}...` : jobId;
}
@@ -1,5 +1,6 @@
import { useCallback, useEffect, useMemo, useState } from "react";
import { CheckCircle2, History, Play, Plus, RefreshCw, UserRoundCog } from "lucide-react";
import { useSearchParams } from "react-router";
import {
Button,
Card,
@@ -59,6 +60,8 @@ export default function CampaignWorkPage({
campaignId: string;
}) {
const workspace = useCampaignWorkspaceData(settings, campaignId);
const [searchParams] = useSearchParams();
const requestedAssignmentId = searchParams.get("assignment");
const [assignments, setAssignments] = useState<CampaignWorkAssignment[]>([]);
const [nextCursor, setNextCursor] = useState<string | null>(null);
const [hasMore, setHasMore] = useState(false);
@@ -71,6 +74,7 @@ export default function CampaignWorkPage({
const [createOpen, setCreateOpen] = useState(false);
const [reassigning, setReassigning] = useState<CampaignWorkAssignment | null>(null);
const [cancelling, setCancelling] = useState<CampaignWorkAssignment | null>(null);
const [rejecting, setRejecting] = useState<CampaignWorkAssignment | null>(null);
const [historyFor, setHistoryFor] = useState<CampaignWorkAssignment | null>(null);
const [history, setHistory] = useState<CampaignWorkAssignmentEvent[]>([]);
const [historyCursor, setHistoryCursor] = useState<string | null>(null);
@@ -102,6 +106,13 @@ export default function CampaignWorkPage({
void loadAssignments();
}, [loadAssignments]);
useEffect(() => {
if (!requestedAssignmentId || loading) return;
document
.getElementById(`campaign-assignment-${requestedAssignmentId}`)
?.focus({ preventScroll: false });
}, [assignments, loading, requestedAssignmentId]);
function replaceAssignment(updated: CampaignWorkAssignment) {
setAssignments((current) => current.map((item) => item.id === updated.id ? updated : item));
}
@@ -175,7 +186,7 @@ export default function CampaignWorkPage({
}
}
async function transition(assignment: CampaignWorkAssignment, action: "start" | "complete" | "cancel") {
async function transition(assignment: CampaignWorkAssignment, action: "accept" | "start" | "complete" | "reject" | "cancel") {
if (busyId) return;
setBusyId(assignment.id);
setError("");
@@ -183,7 +194,15 @@ export default function CampaignWorkPage({
const updated = await transitionCampaignWorkAssignment(settings, campaignId, assignment, action);
replaceAssignment(updated);
setCancelling(null);
setMessage(`Work ${action === "start" ? "started" : action === "complete" ? "completed" : "cancelled"}.`);
setRejecting(null);
const resultLabel = {
accept: "accepted",
start: "started",
complete: "completed",
reject: "rejected",
cancel: "cancelled"
}[action];
setMessage(`Work ${resultLabel}.`);
} catch (err) {
setError(errorText(err));
} finally {
@@ -285,7 +304,12 @@ export default function CampaignWorkPage({
) : (
<ol className="campaign-work-list" aria-label="Campaign work assignments">
{assignments.map((assignment) => (
<li key={assignment.id} className="campaign-work-item">
<li
key={assignment.id}
id={`campaign-assignment-${assignment.id}`}
className={`campaign-work-item${assignment.id === requestedAssignmentId ? " is-focused" : ""}`}
tabIndex={-1}
>
<article>
<header className="campaign-work-item-header">
<div>
@@ -319,8 +343,8 @@ export default function CampaignWorkPage({
<History size={16} aria-hidden="true" /> History
</Button>
{canComplete && assignment.status === "open" ? (
<Button onClick={() => void transition(assignment, "start")} disabled={Boolean(busyId)} helpContextId="campaign.work.action.start" helpModuleId="campaign">
<Play size={16} aria-hidden="true" /> Start
<Button onClick={() => void transition(assignment, "accept")} disabled={Boolean(busyId)} helpContextId="campaign.work.action.start" helpModuleId="campaign">
<Play size={16} aria-hidden="true" /> Accept
</Button>
) : null}
{canComplete && (assignment.status === "open" || assignment.status === "in_progress") ? (
@@ -333,6 +357,13 @@ export default function CampaignWorkPage({
<UserRoundCog size={16} aria-hidden="true" /> Reassign
</Button>
) : null}
{canComplete && (assignment.status === "open" || assignment.status === "in_progress") ? (
<span className="campaign-work-destructive-action">
<Button variant="danger" helpContextId="campaign.work.action.reject" helpModuleId="campaigns" onClick={() => setRejecting(assignment)} disabled={Boolean(busyId)}>
Reject work
</Button>
</span>
) : null}
{canManage && (assignment.status === "open" || assignment.status === "in_progress") ? (
<span className="campaign-work-destructive-action">
<Button variant="danger" onClick={() => setCancelling(assignment)} disabled={Boolean(busyId)} helpContextId="campaign.work.action.cancel" helpModuleId="campaign">
@@ -391,6 +422,17 @@ export default function CampaignWorkPage({
{historyHasMore ? <Button onClick={() => void loadOlderHistory()} disabled={historyLoading}>Load older history</Button> : null}
</Dialog>
<ConfirmDialog
open={Boolean(rejecting)}
title="Reject assigned work?"
message="The work will close as rejected, separately from cancellation. Its purpose, assignee and transition history remain durable evidence."
confirmLabel="Reject work"
tone="danger"
busy={Boolean(busyId)}
onCancel={() => setRejecting(null)}
onConfirm={() => rejecting ? void transition(rejecting, "reject") : undefined}
/>
<ConfirmDialog
open={Boolean(cancelling)}
title="Cancel assigned work?"
@@ -116,7 +116,7 @@ function CampaignWorkspaceInner({ settings, auth }: { settings: ApiSettings; aut
<Route path="policy" element={<Navigate to="../policies" replace />} />
<Route path="review" element={<ReviewSendPage settings={settings} auth={auth} campaignId={campaignId || ""} />} />
<Route path="send" element={<Navigate to="../review" replace />} />
<Route path="report" element={<CampaignReportPage settings={settings} campaignId={campaignId || ""} />} />
<Route path="report" element={<CampaignReportPage settings={settings} auth={auth} campaignId={campaignId || ""} />} />
<Route path="activity" element={hasScope(auth, "campaigns:discussion:read") ? <CampaignCollaborationPage settings={settings} auth={auth} campaignId={campaignId || ""} /> : <Navigate to="../" replace />} />
<Route path="work" element={hasScope(auth, "campaigns:assignment:read") ? <CampaignWorkPage settings={settings} auth={auth} campaignId={campaignId || ""} /> : <Navigate to="../" replace />} />
<Route path="reports" element={<Navigate to="../report" replace />} />
@@ -15,7 +15,9 @@ import { LoadingFrame } from "@govoplan/core-webui";
import { PolicyRow } from "@govoplan/core-webui";
import { PolicyTable } from "@govoplan/core-webui";
import LockedVersionNotice from "./components/LockedVersionNotice";
import LegacyMailMigrationNotice from "./components/LegacyMailMigrationNotice";
import CampaignAccessCard from "./components/CampaignAccessCard";
import CampaignArchiveEncryptionPolicyNotice from "./components/CampaignArchiveEncryptionPolicyNotice";
import VersionLine from "./components/VersionLine";
import { ToggleSwitch } from "@govoplan/core-webui";
import { hasScope } from "@govoplan/core-webui";
@@ -63,7 +65,7 @@ export default function GlobalSettingsPage({ settings, auth, campaignId, view =
const version = data.currentVersion;
const locked = isAuditLockedVersion(version, data.campaign?.current_version_id);
const { draft, displayDraft, dirty, saveState, localError, patch, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
const { draft, displayDraft, dirty, saving, saveState, localError, patch, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
settings,
campaignId,
version,
@@ -183,21 +185,23 @@ export default function GlobalSettingsPage({ settings, auth, campaignId, view =
mode="workspace"
title={pageTitle}
description={<VersionLine version={version} versions={data.versions} status={saveState} />}
headerLoading={loading}
headerLoading={loading || saving}
error={error}
actions={<PageActionBar
variant="editor"
state={loading ? "saving" : dirty ? "dirty" : "clean"}
state={loading || saving ? "saving" : dirty ? "dirty" : "clean"}
discardAction={{ label: "i18n:govoplan-campaign.discard.36fff63c", onClick: () => void discardDraft() }}
saveAction={{ label: "i18n:govoplan-campaign.save.efc007a3", onClick: () => saveDraft("manual"), disabled: (locked || !draft) && dirty, disabledReason: locked && dirty ? "This campaign version is locked." : !draft && dirty ? "The campaign draft is not available." : undefined }}
/>}
notices={(localError || locked) ? <>
notices={(localError || locked || version?.mail_profile_migration_required) ? <>
{version?.mail_profile_migration_required && <LegacyMailMigrationNotice campaignId={campaignId} versionId={version.id} />}
{localError && <DismissibleAlert tone="danger" resetKey={localError} floating>{localError}</DismissibleAlert>}
{locked && <LockedVersionNotice settings={settings} campaignId={campaignId} version={version} currentVersionId={data.campaign?.current_version_id} reload={reload} message="i18n:govoplan-campaign.this_page_is_read_only_for_the_selected_version.dacf5743" />}
</> : undefined}
>
<LoadingFrame loading={loading || !draft} label="i18n:govoplan-campaign.loading_campaign_draft.1cf47e50">
<CampaignArchiveEncryptionPolicyNotice settings={settings} auth={auth} campaignId={campaignId} />
{isPolicyView ?
<>
{canReadRetentionPolicy &&
@@ -379,6 +383,8 @@ export default function GlobalSettingsPage({ settings, auth, campaignId, view =
<FormGrid columns={2} collapseAt="wide" className="">
<ToggleSwitch
label="Send individualized invitations"
helpContextId="campaign.global-settings"
helpModuleId="campaigns"
checked={getBool(calendarInvitation, "enabled")}
disabled={locked || !calendarCatalog.available || !mailModuleInstalled}
onChange={(checked) => patch(["delivery", "calendar_invitation", "enabled"], checked)}
@@ -1,5 +1,5 @@
import { MetricGrid } from "@govoplan/core-webui";
import { useEffect, useState } from "react";
import { useEffect, useRef, useState } from "react";
import { FormGrid,
Button,
Card,
@@ -33,10 +33,11 @@ import {
import { useCampaignWorkspaceData } from "./hooks/useCampaignWorkspaceData";
import { useCampaignDraftEditor } from "./hooks/useCampaignDraftEditor";
import LockedVersionNotice from "./components/LockedVersionNotice";
import LegacyMailMigrationNotice from "./components/LegacyMailMigrationNotice";
import VersionLine from "./components/VersionLine";
import { asRecord, isAuditLockedVersion } from "./utils/campaignView";
import { getBool, getText } from "./utils/draftEditor";
import { campaignMailProfileReferenceOnly } from "./utils/mailProfileReference";
import { campaignMailProfileListOptions, campaignMailProfileReferenceOnly } from "./utils/mailProfileReference";
type MailSettingsView = "settings" | "policy";
@@ -63,6 +64,8 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
const [mailProfiles, setMailProfiles] = useState<MailServerProfile[]>([]);
const [policyProfiles, setPolicyProfiles] = useState<MailServerProfile[]>([]);
const [profilesLoading, setProfilesLoading] = useState(false);
const profileLoadGeneration = useRef(0);
const [migrationSaving, setMigrationSaving] = useState(false);
const [profileError, setProfileError] = useState("");
const [mailActionState, setMailActionState] = useState<"smtp" | "imap" | "folders" | null>(null);
const [smtpTestResult, setSmtpTestResult] = useState<MailServerConnectionTestResult | null>(null);
@@ -81,7 +84,7 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
const version = data.currentVersion;
const locked = isAuditLockedVersion(version, data.campaign?.current_version_id);
const migrationRequired = version?.mail_profile_migration_required === true;
const { draft, displayDraft, dirty, saveState, localError, setLocalError, patch, discardDraft, saveDraft } = useCampaignDraftEditor({
const { draft, displayDraft, dirty, saving, saveState, localError, setLocalError, patch, discardDraft, saveDraft } = useCampaignDraftEditor({
settings,
campaignId,
version,
@@ -104,30 +107,28 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
const selectedProfile = mailProfiles.find((profile) => profile.id === selectedProfileId) ?? null;
const smtpServers = (selectedProfile?.servers ?? []).filter((item) => item.protocol === "smtp" && item.is_active);
const imapServers = (selectedProfile?.servers ?? []).filter((item) => item.protocol === "imap" && item.is_active);
const selectedSmtpServer = smtpServers.find((item) => item.id === getText(server, "smtp_server_id"))
?? smtpServers.find((item) => item.is_default)
?? smtpServers[0]
?? null;
const selectedImapServer = imapServers.find((item) => item.id === getText(server, "imap_server_id"))
?? imapServers.find((item) => item.is_default)
?? imapServers[0]
?? null;
const smtpServerId = getText(server, "smtp_server_id");
const imapServerId = getText(server, "imap_server_id");
const selectedSmtpServer = (smtpServerId
? smtpServers.find((item) => item.id === smtpServerId)
: smtpServers.find((item) => item.is_default) ?? smtpServers[0]) ?? null;
const selectedImapServer = (imapServerId
? imapServers.find((item) => item.id === imapServerId)
: imapServers.find((item) => item.is_default) ?? imapServers[0]) ?? null;
const selectedSmtpCredential = selectedSmtpServer?.credentials.find((item) => item.id === getText(server, "smtp_credential_id"))
?? selectedSmtpServer?.credentials.find((item) => item.is_default)
?? selectedSmtpServer?.credentials[0]
?? null;
const selectedImapCredential = selectedImapServer?.credentials.find((item) => item.id === getText(server, "imap_credential_id"))
?? selectedImapServer?.credentials.find((item) => item.is_default)
?? selectedImapServer?.credentials[0]
?? null;
const delivery = asRecord(displayDraft.delivery);
const imapAppend = asRecord(delivery.imap_append_sent);
const imapAppendEnabled = getBool(imapAppend, "enabled");
const selectedProfileHasImap = Boolean(selectedImapServer);
const selectedProfileUnavailable = Boolean(selectedProfileId && !profilesLoading && !selectedProfile);
const canSave = dirty && !locked && Boolean(draft) && (!migrationRequired || Boolean(selectedProfileId));
const canMigrate = migrationRequired && !locked && !saving && Boolean(draft) && Boolean(selectedProfile) && !profilesLoading;
const canSave = dirty && !locked && !saving && !migrationSaving && Boolean(draft) && (!migrationRequired || canMigrate);
useEffect(() => {
profileLoadGeneration.current += 1;
if (!mailModuleInstalled) {
setMailProfiles([]);
setPolicyProfiles([]);
@@ -135,25 +136,41 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
return;
}
void refreshMailProfiles();
}, [settings.apiBaseUrl, settings.apiKey, settings.accessToken, campaignId, mailModuleInstalled]);
return () => {
profileLoadGeneration.current += 1;
};
}, [settings.apiBaseUrl, settings.apiKey, settings.accessToken, campaignId, mailModuleInstalled, view]);
async function refreshMailProfiles() {
if (!mailModuleInstalled) return;
const generation = ++profileLoadGeneration.current;
setProfilesLoading(true);
setProfileError("");
try {
const [allowedProfiles, visibleProfiles] = await Promise.all([
listMailServerProfiles(settings, false, campaignId),
listMailServerProfiles(settings, true)
]);
setMailProfiles(allowedProfiles);
setPolicyProfiles(visibleProfiles);
const options = campaignMailProfileListOptions(view, campaignId);
const profiles = await listMailServerProfiles(settings, options.includeInactive, options.campaignId);
if (generation !== profileLoadGeneration.current) return;
if (isPolicyView) setPolicyProfiles(profiles);
else setMailProfiles(profiles);
} catch (err) {
setMailProfiles([]);
setPolicyProfiles([]);
if (generation !== profileLoadGeneration.current) return;
if (isPolicyView) setPolicyProfiles([]);
else setMailProfiles([]);
setProfileError(err instanceof Error ? err.message : String(err));
} finally {
setProfilesLoading(false);
if (generation === profileLoadGeneration.current) setProfilesLoading(false);
}
}
async function migrateMailProfile() {
if (!canMigrate || migrationSaving) return;
setMigrationSaving(true);
try {
// Explicit consent is needed even when the existing public profile
// reference is unchanged, so this action deliberately works on a clean draft.
await saveDraft("manual");
} finally {
setMigrationSaving(false);
}
}
@@ -190,10 +207,10 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
?? null;
patch(["server"], mailReference(
selectedProfile.id,
protocol === "smtp" ? selected?.id : selectedSmtpServer?.id,
protocol === "smtp" ? credential?.id : selectedSmtpCredential?.id,
protocol === "imap" ? selected?.id : selectedImapServer?.id,
protocol === "imap" ? credential?.id : selectedImapCredential?.id
protocol === "smtp" ? selected?.id : getText(server, "smtp_server_id"),
protocol === "smtp" ? credential?.id : getText(server, "smtp_credential_id"),
protocol === "imap" ? selected?.id : getText(server, "imap_server_id"),
protocol === "imap" ? credential?.id : getText(server, "imap_credential_id")
));
if (protocol === "smtp") setSmtpTestResult(null);
else {
@@ -206,10 +223,10 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
if (!selectedProfile || locked) return;
patch(["server"], mailReference(
selectedProfile.id,
selectedSmtpServer?.id,
protocol === "smtp" ? credentialId : selectedSmtpCredential?.id,
selectedImapServer?.id,
protocol === "imap" ? credentialId : selectedImapCredential?.id
protocol === "smtp" ? selectedSmtpServer?.id : getText(server, "smtp_server_id"),
protocol === "smtp" ? credentialId : getText(server, "smtp_credential_id"),
protocol === "imap" ? selectedImapServer?.id : getText(server, "imap_server_id"),
protocol === "imap" ? credentialId : getText(server, "imap_credential_id")
));
if (protocol === "smtp") setSmtpTestResult(null);
else {
@@ -282,7 +299,7 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
settings,
selectedProfileId,
selectedSmtpServer?.id,
selectedSmtpCredential?.id,
getText(server, "smtp_credential_id") || undefined,
campaignId
));
} else {
@@ -290,7 +307,7 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
settings,
selectedProfileId,
selectedImapServer?.id,
selectedImapCredential?.id,
getText(server, "imap_credential_id") || undefined,
campaignId
));
}
@@ -312,7 +329,7 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
settings,
selectedProfileId,
selectedImapServer?.id,
selectedImapCredential?.id,
getText(server, "imap_credential_id") || undefined,
campaignId
));
} catch (err) {
@@ -333,7 +350,7 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
mode="workspace"
title={isPolicyView ? "i18n:govoplan-campaign.mail_policy.3eb5d32a" : "i18n:govoplan-campaign.mail_settings.19e07f55"}
description={<VersionLine version={version} versions={data.versions} status={saveState} />}
headerLoading={loading}
headerLoading={loading || migrationSaving || saving}
error={error}
actions={isPolicyView ? (
<PageActionBar
@@ -344,7 +361,7 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
) : (
<PageActionBar
variant="editor"
state={loading ? "saving" : dirty ? "dirty" : "clean"}
state={loading || migrationSaving || saving ? "saving" : dirty ? "dirty" : "clean"}
discardAction={{ label: "i18n:govoplan-campaign.discard.36fff63c", onClick: () => void discardDraft() }}
saveAction={{ label: "i18n:govoplan-campaign.save.efc007a3", onClick: () => void saveDraft("manual"), disabled: !canSave && dirty, disabledReason: !canSave && dirty ? "Resolve the current mail-settings blocker before saving." : undefined }}
/>
@@ -359,9 +376,16 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
<>
{!mailModuleInstalled && <DismissibleAlert tone="warning" dismissible={false}>i18n:govoplan-campaign.install_and_enable_the_mail_module_to_select_a_d.01c75fc4</DismissibleAlert>}
{migrationRequired && <DismissibleAlert tone="warning" dismissible={false}>
i18n:govoplan-campaign.this_version_contains_legacy_campaign_local_mail.44c7a6fd
</DismissibleAlert>}
{migrationRequired && <LegacyMailMigrationNotice
campaignId={campaignId}
versionId={version?.id}
showSettingsLink={isPolicyView}
onMigrate={!isPolicyView && !locked ? () => void migrateMailProfile() : undefined}
canMigrate={canMigrate}
busy={migrationSaving}
/>}
{profileError && <DismissibleAlert tone="warning" resetKey={profileError} dismissible={false}>{profileError}</DismissibleAlert>}
{isPolicyView && mailModuleInstalled && MailProfilePolicyEditor && <MailProfilePolicyEditor
settings={settings}
@@ -383,45 +407,51 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
title="i18n:govoplan-campaign.reusable_mail_profile.f9c9aab1"
actions={<div className="button-row compact-actions">
<Button onClick={() => void refreshMailProfiles()} disabled={profilesLoading}>{profilesLoading ? "i18n:govoplan-campaign.loading.33ce4174" : "i18n:govoplan-campaign.reload_profiles.0fe100d1"}</Button>
<Button variant="primary" onClick={openCredentialDialog} disabled={locked || profilesLoading || !selectedProfile || !selectedSmtpServer && !selectedImapServer}>Add campaign credential</Button>
<Button variant="primary" helpContextId="campaign.server-settings" helpModuleId="campaigns" onClick={openCredentialDialog} disabled={locked || profilesLoading || !selectedProfile || !selectedSmtpServer && !selectedImapServer}>Add campaign credential</Button>
</div>}>
<p className="muted small-note">The campaign stores stable references to the envelope, selected servers, and credentials.</p>
<FormGrid columns={2} collapseAt="wide" className="">
<FormField label="i18n:govoplan-campaign.profile.ff4fc027">
<select value={selectedProfileId} disabled={locked || profilesLoading} onChange={(event) => selectMailProfile(event.target.value)}>
<option value="">i18n:govoplan-campaign.select_a_mail_profile.76480af0</option>
{selectedProfileId && !selectedProfile && <option value={selectedProfileId}>i18n:govoplan-campaign.unavailable_selected_profile</option>}
{mailProfiles.map((profile) => <option key={profile.id} value={profile.id}>{profile.name} ({profileScopeLabel(profile)})</option>)}
</select>
</FormField>
<FormField label="SMTP server">
<select value={selectedSmtpServer?.id ?? ""} disabled={locked || profilesLoading || !selectedProfile} onChange={(event) => selectServer("smtp", event.target.value)}>
<option value="">No SMTP server</option>
<select value={smtpServerId} disabled={locked || profilesLoading || !selectedProfile} onChange={(event) => selectServer("smtp", event.target.value)}>
<option value="">i18n:govoplan-campaign.inherit_mail_server</option>
{smtpServerId && !selectedSmtpServer && <option value={smtpServerId}>i18n:govoplan-campaign.unavailable_selected_server</option>}
{smtpServers.map((item) => <option key={item.id} value={item.id}>{item.name} ({serverEndpointLabel(item.config)})</option>)}
</select>
</FormField>
<FormField label="SMTP credential">
<select value={selectedSmtpCredential?.id ?? ""} disabled={locked || profilesLoading || !selectedSmtpServer} onChange={(event) => selectCredential("smtp", event.target.value)}>
<option value="">No credential</option>
<FormField label="SMTP credential" helpContextId="campaign.server-settings" helpModuleId="campaigns">
<select data-help-context-id="campaign.server-settings" data-help-module-id="campaigns" value={getText(server, "smtp_credential_id")} disabled={locked || profilesLoading || !selectedSmtpServer} onChange={(event) => selectCredential("smtp", event.target.value)}>
<option value="">i18n:govoplan-campaign.inherit_mail_credential_when_allowed</option>
{getText(server, "smtp_credential_id") && !selectedSmtpServer?.credentials.some((item) => item.is_active && item.id === getText(server, "smtp_credential_id")) && <option value={getText(server, "smtp_credential_id")}>i18n:govoplan-campaign.unavailable_selected_credential</option>}
{selectedSmtpServer?.credentials.filter((item) => item.is_active).map((item) =>
<option key={item.id} value={item.id}>{credentialLabel(item)}</option>
)}
</select>
</FormField>
<FormField label="IMAP server">
<select value={selectedImapServer?.id ?? ""} disabled={locked || profilesLoading || !selectedProfile} onChange={(event) => selectServer("imap", event.target.value)}>
<option value="">No IMAP server</option>
<select value={imapServerId} disabled={locked || profilesLoading || !selectedProfile} onChange={(event) => selectServer("imap", event.target.value)}>
<option value="">i18n:govoplan-campaign.inherit_mail_server</option>
{imapServerId && !selectedImapServer && <option value={imapServerId}>i18n:govoplan-campaign.unavailable_selected_server</option>}
{imapServers.map((item) => <option key={item.id} value={item.id}>{item.name} ({serverEndpointLabel(item.config)})</option>)}
</select>
</FormField>
<FormField label="IMAP credential">
<select value={selectedImapCredential?.id ?? ""} disabled={locked || profilesLoading || !selectedImapServer} onChange={(event) => selectCredential("imap", event.target.value)}>
<option value="">No credential</option>
<FormField label="IMAP credential" helpContextId="campaign.server-settings" helpModuleId="campaigns">
<select data-help-context-id="campaign.server-settings" data-help-module-id="campaigns" value={getText(server, "imap_credential_id")} disabled={locked || profilesLoading || !selectedImapServer} onChange={(event) => selectCredential("imap", event.target.value)}>
<option value="">i18n:govoplan-campaign.inherit_mail_credential_when_allowed</option>
{getText(server, "imap_credential_id") && !selectedImapServer?.credentials.some((item) => item.is_active && item.id === getText(server, "imap_credential_id")) && <option value={getText(server, "imap_credential_id")}>i18n:govoplan-campaign.unavailable_selected_credential</option>}
{selectedImapServer?.credentials.filter((item) => item.is_active).map((item) =>
<option key={item.id} value={item.id}>{credentialLabel(item)}</option>
)}
</select>
</FormField>
</FormGrid>
<p className="muted small-note">i18n:govoplan-campaign.explicit_mail_credential_help</p>
{selectedProfileUnavailable && <DismissibleAlert tone="warning" dismissible={false}>i18n:govoplan-campaign.the_referenced_mail_profile_is_inactive_unavaila.abeebe26</DismissibleAlert>}
{selectedProfile && <MetricGrid spacing="inset">
<MetricCard label="i18n:govoplan-campaign.profile.ff4fc027" value={selectedProfile.name} />
@@ -435,7 +465,6 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
</div>
{smtpTestResult && <DismissibleAlert tone={smtpTestResult.ok ? "success" : "danger"} resetKey={`${smtpTestResult.protocol}:${smtpTestResult.message}`} floating>{smtpTestResult.message}</DismissibleAlert>}
{imapTestResult && <DismissibleAlert tone={imapTestResult.ok ? "success" : "danger"} resetKey={`${imapTestResult.protocol}:${imapTestResult.message}`} floating>{imapTestResult.message}</DismissibleAlert>}
{profileError && <DismissibleAlert tone="warning" resetKey={profileError} floating>{profileError}</DismissibleAlert>}
</Card>}
<Dialog variant="administration" size="wide"
@@ -476,8 +505,8 @@ export default function MailSettingsPage({ settings, campaignId, view = "setting
<FormField label="Username">
<input value={credentialDraft.username} disabled={credentialSaving} onChange={(event) => setCredentialDraft({ ...credentialDraft, username: event.target.value })} />
</FormField>
<FormField label="Password">
<PasswordField value={credentialDraft.password} onValueChange={(password) => setCredentialDraft({ ...credentialDraft, password })} disabled={credentialSaving} generator autoComplete="new-password" />
<FormField label="Password" helpContextId="campaign.server-settings" helpModuleId="campaigns">
<PasswordField helpContextId="campaign.server-settings" helpModuleId="campaigns" value={credentialDraft.password} onValueChange={(password) => setCredentialDraft({ ...credentialDraft, password })} disabled={credentialSaving} generator autoComplete="new-password" />
</FormField>
</FormGrid>
<FormGrid columns={2} collapseAt="standard" className="">
@@ -541,8 +570,8 @@ function mailReference(
}
function serverEndpointLabel(config: MailServerEndpoint["config"]): string {
const host = typeof config.host === "string" && config.host ? config.host : "No host";
return config.port ? `${host}:${config.port}` : host;
const host = "host" in config && typeof config.host === "string" && config.host ? config.host : "No host";
return "port" in config && config.port ? `${host}:${config.port}` : host;
}
function credentialLabel(credential: MailCredentialEnvelope): string {
@@ -5,7 +5,6 @@ import {
getCampaignPostboxCatalog,
listCampaignRecipientAddressSources,
listCampaignRecipientDistributionLists,
snapshotCampaignRecipientAddressSource,
type CampaignDistributionListExpansion,
type CampaignDistributionListSource,
type CampaignPostboxCatalog,
@@ -41,7 +40,7 @@ import {
createAddressSourceImportProvenance
} from "./utils/addressSourceImport";
import { addressesFromValue, type MailboxAddress } from "@govoplan/core-webui";
import { i18nMessage, insertAfter, moveArrayItem, useGuardedNavigate, usePlatformLanguage } from "@govoplan/core-webui";
import { i18nMessage, insertAfter, moveArrayItem, usePlatformLanguage } from "@govoplan/core-webui";
import AddressSourceImportDialog from "./recipients/AddressSourceImportDialog";
import DistributionListImportDialog from "./recipients/DistributionListImportDialog";
import {
@@ -53,15 +52,10 @@ import {
AddressHeaderControl,
HeaderAddressEditorDialog,
RecipientAddressEditorDialog,
entryWithAddressList,
entryWithAddressValues,
formatAddressCollectionForClipboard,
getAddressColumn,
getEntryAddresses,
headerAddressValues,
hiddenRecipientAddressMatch,
recipientAddressFilterValue,
recipientAddressOverlayColumns,
recipientAddressSummary,
recipientHeaderRows,
type AddressFieldKey,
type EntryAddressColumn,
@@ -110,7 +104,7 @@ export default function RecipientDataPage({ settings, campaignId }: {settings: A
const version = data.currentVersion;
const locked = isAuditLockedVersion(version, data.campaign?.current_version_id);
const { draft, setDraft, displayDraft, dirty, saveState, localError, patch, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
const { draft, setDraft, displayDraft, dirty, saving, saveState, localError, patch, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
settings,
campaignId,
version,
@@ -293,17 +287,7 @@ export default function RecipientDataPage({ settings, campaignId }: {settings: A
values: HeaderAddressValues,
merges: EntryAddressMergeValues
) {
updateEntry(index, (entry) => {
let nextEntry = entry;
for (const column of recipientAddressOverlayColumns) {
if (!(column.key in values)) continue;
nextEntry = entryWithAddressList(nextEntry, column.key, values[column.key] ?? []);
if (!column.mergeKey || !(column.mergeKey in merges)) continue;
nextEntry = { ...nextEntry, [column.mergeKey]: Boolean(merges[column.mergeKey]) };
delete nextEntry[column.mergeKey.replace("merge_", "combine_")];
}
return nextEntry;
});
updateEntry(index, (entry) => entryWithAddressValues(entry, values, merges));
setRecipientAddressEditorIndex(null);
}
@@ -417,6 +401,7 @@ export default function RecipientDataPage({ settings, campaignId }: {settings: A
campaignId={campaignId}
title="i18n:govoplan-campaign.sender_recipients.922c6d24"
loading={loading}
saving={saving}
version={version}
versions={data.versions}
saveState={saveState}
@@ -573,7 +558,9 @@ export default function RecipientDataPage({ settings, campaignId }: {settings: A
</div>
</DismissibleAlert>
}
{!source.type &&
{/* Mount with the real draft's delivery/attachment/field columns;
an empty loading signature would erase personal column widths. */}
{version && draft && !source.type &&
<div className="admin-table-surface recipient-profiles-table-surface">
<DataGrid
id={`campaign-${campaignId}-recipient-profiles`}
File diff suppressed because it is too large Load Diff
@@ -21,6 +21,7 @@ import { LoadingFrame } from "@govoplan/core-webui";
import { DismissibleAlert, SegmentedControl, ToggleSwitch, i18nMessage } from "@govoplan/core-webui";
import { WysiwygEditor, type WysiwygEditorHandle } from "@govoplan/core-webui/wysiwyg";
import LockedVersionNotice from "./components/LockedVersionNotice";
import LegacyMailMigrationNotice from "./components/LegacyMailMigrationNotice";
import VersionLine from "./components/VersionLine";
import CampaignMessagePreviewOverlay, { type CampaignMessagePreviewAttachment } from "./components/MessagePreviewOverlay";
import { TemplateFieldChipList, UndefinedPlaceholderDecisionDialog, UndefinedPlaceholderList } from "./components/TemplatePlaceholderControls";
@@ -79,7 +80,7 @@ export default function TemplateDataPage({ settings, campaignId }: {settings: Ap
const version = data.currentVersion;
const locked = isAuditLockedVersion(version, data.campaign?.current_version_id);
const { draft, setDraft, displayDraft, dirty, saveState, localError, patch, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
const { draft, setDraft, displayDraft, dirty, saving, saveState, localError, patch, markDirty, discardDraft, saveDraft } = useCampaignDraftEditor({
settings,
campaignId,
version,
@@ -478,17 +479,18 @@ export default function TemplateDataPage({ settings, campaignId }: {settings: Ap
mode="workspace"
title="i18n:govoplan-campaign.template.3ec1ae06"
description={<VersionLine version={version} versions={data.versions} status={saveState} />}
headerLoading={loading}
headerLoading={loading || saving}
error={error}
success={contentLibraryNotice}
actions={<PageActionBar
variant="editor"
state={loading ? "saving" : dirty ? "dirty" : "clean"}
state={loading || saving ? "saving" : dirty ? "dirty" : "clean"}
contextActions={<Button onClick={() => window.location.assign("/templates")}>i18n:govoplan-campaign.manage_templates.23688071</Button>}
discardAction={{ label: "i18n:govoplan-campaign.discard.36fff63c", onClick: () => void discardDraft() }}
saveAction={{ label: "i18n:govoplan-campaign.save.efc007a3", onClick: () => saveDraft("manual"), disabled: (locked || !draft) && dirty, disabledReason: locked && dirty ? "This campaign version is locked." : !draft && dirty ? "The campaign draft is not available." : undefined }}
/>}
notices={(localError || locked) ? <>
notices={(localError || locked || version?.mail_profile_migration_required) ? <>
{version?.mail_profile_migration_required && <LegacyMailMigrationNotice campaignId={campaignId} versionId={version.id} />}
{localError && <DismissibleAlert tone="danger" resetKey={localError} floating>{localError}</DismissibleAlert>}
{locked && <LockedVersionNotice settings={settings} campaignId={campaignId} version={version} currentVersionId={data.campaign?.current_version_id} reload={reload} message="i18n:govoplan-campaign.this_page_is_read_only_for_the_selected_version.dacf5743" />}
</> : undefined}
@@ -2,7 +2,7 @@ import { useMemo, useState } from "react";
import { createPortal } from "react-dom";
import type { ApiSettings } from "../../../types";
import { Button } from "@govoplan/core-webui";
import { Dialog } from "@govoplan/core-webui";
import { Dialog, DismissibleAlert } from "@govoplan/core-webui";
import { usePlatformUiCapability, type FilesFileExplorerUiCapability, type FilesManagedAttachmentSelection } from "@govoplan/core-webui";
import { DataGrid, DataGridEmptyAction, DataGridRowActions, type DataGridColumn } from "@govoplan/core-webui";
import { ToggleSwitch } from "@govoplan/core-webui";
@@ -161,6 +161,7 @@ export function AttachmentRulesDataGrid({
onChange
}: AttachmentRulesTableProps) {
const [fileChooser, setFileChooser] = useState<FileChooserState | null>(null);
const [chooserError, setChooserError] = useState("");
const filesFileExplorer = usePlatformUiCapability<FilesFileExplorerUiCapability>("files.fileExplorer");
const ManagedFileChooser = filesModuleInstalled ? filesFileExplorer?.ManagedFileChooser : null;
const managedFilesAvailable = Boolean(ManagedFileChooser);
@@ -187,7 +188,12 @@ export function AttachmentRulesDataGrid({
}
function openFileChooser(ruleIndex: number) {
if (!managedFilesAvailable) return;
if (disabled) return;
setChooserError("");
if (!managedFilesAvailable) {
setChooserError("i18n:govoplan-campaign.file_chooser_unavailable");
return;
}
if (onOpenFileChooser) {
onOpenFileChooser(ruleIndex);
return;
@@ -200,7 +206,10 @@ export function AttachmentRulesDataGrid({
basePaths.find((item) => item.path === currentPath) ?? (
!explicitlyReferenced ? basePaths[0] : undefined) ??
null;
if (!basePath) return;
if (!basePath) {
setChooserError("i18n:govoplan-campaign.choose_available_attachment_source");
return;
}
setFileChooser({ ruleIndex, basePath });
}
@@ -220,10 +229,11 @@ export function AttachmentRulesDataGrid({
return (
<>
{(chooserError || filesModuleInstalled && !managedFilesAvailable) && <DismissibleAlert tone="warning" dismissible={false}>{chooserError || "i18n:govoplan-campaign.file_chooser_unavailable"}</DismissibleAlert>}
<DataGrid
id={id}
rows={rules}
columns={attachmentRuleColumns({ disabled, rules, basePaths, zipConfig, filesModuleInstalled: managedFilesAvailable, activeChooserRuleIndex: activeChooserRuleIndex ?? fileChooser?.ruleIndex ?? null, patchRule, addRule, moveRule, openFileChooser, removeRule })}
columns={attachmentRuleColumns({ disabled, rules, basePaths, zipConfig, filesModuleInstalled, activeChooserRuleIndex: activeChooserRuleIndex ?? fileChooser?.ruleIndex ?? null, patchRule, addRule, moveRule, openFileChooser, removeRule })}
getRowKey={(rule, index) => String(rule.id ?? index)}
emptyText={basePaths.length === 0 ? "i18n:govoplan-campaign.no_attachment_source_is_enabled_for_individual_a.818a2820" : emptyText}
emptyAction={<DataGridEmptyAction onAdd={() => addRule(-1)} disabled={disabled || basePaths.length === 0} label="i18n:govoplan-campaign.add_first_attachment.025fbf31" />}
@@ -242,7 +252,7 @@ export function AttachmentRulesDataGrid({
initialPattern={getText(rules[fileChooser.ruleIndex], "file_filter")}
rememberKey={`${id}:${String(rules[fileChooser.ruleIndex]?.id ?? fileChooser.ruleIndex)}`}
previewContext={previewContext}
renderPatternPreview={(pattern, context) => renderTemplatePreviewText(pattern, context, false)}
renderPatternPreview={(pattern, context) => renderTemplatePreviewText(pattern, context ?? {}, false)}
onClose={() => setFileChooser(null)}
onSelectAttachment={selectAttachment} />
@@ -316,7 +326,7 @@ function attachmentRuleColumns({ disabled, rules, basePaths, zipConfig, filesMod
value={getText(rule, "file_filter")}
disabled={disabled || basePaths.length === 0}
readOnly={filesModuleInstalled}
tabIndex={filesModuleInstalled ? -1 : undefined}
tabIndex={0}
placeholder={filesModuleInstalled ? "i18n:govoplan-campaign.choose_a_managed_file_or_pattern.96bb3bfb" : "file.pdf or **/*.pdf"}
onChange={(event) => {
if (!filesModuleInstalled) patchRule(index, { file_filter: event.target.value });
@@ -429,7 +429,7 @@ export default function CampaignAccessCard({
return (
<>
<Card title="i18n:govoplan-campaign.ownership_and_sharing.867283c0" actions={<div className="button-row compact-actions">{canProposeOwnership ? <Button onClick={openOwnerDialog}><ArrowRightLeft size={16} aria-hidden="true" /> Transfer ownership</Button> : null}{canRequestOwnership ? <Button onClick={openRequestDialog}><ArrowRightLeft size={16} aria-hidden="true" /> Request ownership</Button> : null}<Button onClick={() => setShareOpen(true)} disabled={available !== true}>i18n:govoplan-campaign.share.09ca55ca</Button><Button onClick={() => void openAccessExplanation()} disabled={!canExplainResourceAccess}><KeyRound size={16} aria-hidden="true" /> i18n:govoplan-campaign.explain_access.4d5fac37</Button></div>}>
<Card title="i18n:govoplan-campaign.ownership_and_sharing.867283c0" actions={<div className="button-row compact-actions">{canProposeOwnership ? <Button helpContextId="campaign.overview" helpModuleId="campaigns" onClick={openOwnerDialog}><ArrowRightLeft size={16} aria-hidden="true" /> Transfer ownership</Button> : null}{canRequestOwnership ? <Button onClick={openRequestDialog}><ArrowRightLeft size={16} aria-hidden="true" /> Request ownership</Button> : null}<Button onClick={() => setShareOpen(true)} disabled={available !== true}>i18n:govoplan-campaign.share.09ca55ca</Button><Button onClick={() => void openAccessExplanation()} disabled={!canExplainResourceAccess}><KeyRound size={16} aria-hidden="true" /> i18n:govoplan-campaign.explain_access.4d5fac37</Button></div>}>
<p><strong>i18n:govoplan-campaign.owner.719379ae</strong> {ownerLabel}</p>
<p className="muted small-note">Ownership changes require acceptance by the new owner. They never transfer private encryption keys. A completed transfer clears owner-scoped mail profile selection and requires revalidation.</p>
{ownershipTransfers.length > 0 ? (
@@ -489,7 +489,7 @@ export default function CampaignAccessCard({
)}
</Card>
<Dialog open={ownerOpen} className="campaign-access-dialog" title="Transfer campaign ownership" onClose={() => !busy && closeOwnerDialog()} footer={<><Button onClick={closeOwnerDialog} disabled={busy}>i18n:govoplan-campaign.cancel.77dfd213</Button><Button variant="primary" onClick={() => void saveOwner()} disabled={busy || !ownerId || ownerType === currentOwnerType && ownerId === currentOwnerId}>Propose transfer</Button></>}>
<Dialog open={ownerOpen} className="campaign-access-dialog" title="Transfer campaign ownership" helpContextId="campaign.overview" helpModuleId="campaigns" onClose={() => !busy && closeOwnerDialog()} footer={<><Button onClick={closeOwnerDialog} disabled={busy}>i18n:govoplan-campaign.cancel.77dfd213</Button><Button variant="primary" helpContextId="campaign.overview" helpModuleId="campaigns" onClick={() => void saveOwner()} disabled={busy || !ownerId || ownerType === currentOwnerType && ownerId === currentOwnerId}>Propose transfer</Button></>}>
<FormField label="i18n:govoplan-campaign.owner_type.6b86eacc"><select value={ownerType} onChange={(event) => {const next = event.target.value as TargetType;setOwnerType(next);setOwnerId("");}}><option value="user">i18n:govoplan-campaign.user.9f8a2389</option><option value="group">i18n:govoplan-campaign.group.171a0606</option></select></FormField>
<FormField label="i18n:govoplan-campaign.owner.89ff3122">
<ReferenceSelect
@@ -0,0 +1,82 @@
import { useEffect, useState } from "react";
import {
Button,
DismissibleAlert,
hasScope,
useGuardedNavigate,
usePlatformModuleInstalled
} from "@govoplan/core-webui";
import type { ApiSettings, AuthInfo } from "../../../types";
import {
getCampaignArchiveEncryptionPolicy,
type CampaignArchiveEncryptionPolicy
} from "../../../api/campaigns";
export const UNAVAILABLE_ARCHIVE_POLICY: CampaignArchiveEncryptionPolicy = {
available: false,
allowed_password_encryption_methods: ["aes"],
allowed_password_delivery_channels: ["separate_mail", "sms", "letter", "phone", "in_person"],
policy_hash: "",
source_path: [],
reason: "Archive-encryption policy is loading. Legacy ZipCrypto remains blocked.",
diagnostics: [],
legacy_label: "Legacy ZipCrypto — Windows-compatible, weak encryption"
};
export default function CampaignArchiveEncryptionPolicyNotice({
settings,
auth,
campaignId,
onPolicyChange
}: {
settings: ApiSettings;
auth: AuthInfo;
campaignId: string;
onPolicyChange?: (policy: CampaignArchiveEncryptionPolicy) => void;
}) {
const navigate = useGuardedNavigate();
const policyInstalled = usePlatformModuleInstalled("policy");
const [policy, setPolicy] = useState(UNAVAILABLE_ARCHIVE_POLICY);
const [loading, setLoading] = useState(true);
const [refresh, setRefresh] = useState(0);
const allowed = policy.available && policy.allowed_password_encryption_methods.includes("zip_standard");
const canReadPolicy = policyInstalled && hasScope(auth, "admin:policies:read");
const canUseLegacy = hasScope(auth, "campaigns:archive:use_legacy_zipcrypto");
useEffect(() => {
let cancelled = false;
setLoading(true);
setPolicy(UNAVAILABLE_ARCHIVE_POLICY);
void getCampaignArchiveEncryptionPolicy(settings, campaignId)
.then((loaded) => { if (!cancelled) setPolicy(loaded); })
.catch((cause) => {
if (!cancelled) setPolicy({
...UNAVAILABLE_ARCHIVE_POLICY,
reason: cause instanceof Error ? cause.message : String(cause)
});
})
.finally(() => { if (!cancelled) setLoading(false); });
return () => { cancelled = true; };
}, [campaignId, refresh, settings.accessToken, settings.apiBaseUrl, settings.apiKey]);
useEffect(() => { onPolicyChange?.(policy); }, [onPolicyChange, policy]);
return <DismissibleAlert tone={allowed ? "warning" : "info"} dismissible={false} compact>
<strong>{policy.legacy_label}</strong>: {policy.reason}
{policy.source_path.length > 0 && <p>{policy.source_path.map((step) => step.label).join(" → ")}</p>}
<p>i18n:govoplan-campaign.archive_policy_enable_guidance</p>
{!canUseLegacy && <p>i18n:govoplan-campaign.archive_policy_permission_missing</p>}
{!policyInstalled && <p>i18n:govoplan-campaign.archive_policy_module_missing</p>}
{canReadPolicy && <Button
helpContextId="campaign.archive-encryption"
helpModuleId="campaigns"
onClick={() => navigate("/admin?section=system-campaign-archive-encryption")}
>i18n:govoplan-campaign.archive_policy_open_system</Button>}
{canReadPolicy && <Button
onClick={() => navigate("/admin?section=tenant-campaign-archive-encryption")}
>i18n:govoplan-campaign.archive_policy_open_tenant</Button>}
<Button disabled={loading} onClick={() => setRefresh((value) => value + 1)}>
i18n:govoplan-campaign.archive_policy_reload
</Button>
</DismissibleAlert>;
}
@@ -3,6 +3,7 @@ import { DismissibleAlert, PageActionBar, PageLayout } from "@govoplan/core-webu
import type { ApiSettings } from "../../../types";
import type { CampaignVersionDetail, CampaignVersionListItem } from "../../../api/campaigns";
import LockedVersionNotice from "./LockedVersionNotice";
import LegacyMailMigrationNotice from "./LegacyMailMigrationNotice";
import VersionLine from "./VersionLine";
type CampaignDraftPageScaffoldProps = {
@@ -10,6 +11,7 @@ type CampaignDraftPageScaffoldProps = {
campaignId: string;
title: string;
loading: boolean;
saving?: boolean;
version: CampaignVersionDetail | null;
versions: CampaignVersionListItem[];
saveState: string;
@@ -30,6 +32,7 @@ export default function CampaignDraftPageScaffold({
campaignId,
title,
loading,
saving = false,
version,
versions,
saveState,
@@ -54,12 +57,13 @@ export default function CampaignDraftPageScaffold({
error={error || ""}
actions={<PageActionBar
variant="editor"
state={loading ? "saving" : dirty ? "dirty" : "clean"}
state={loading || saving ? "saving" : dirty ? "dirty" : "clean"}
discardAction={{ label: "i18n:govoplan-campaign.discard.36fff63c", onClick: onReload }}
saveAction={{ label: "i18n:govoplan-campaign.save.efc007a3", onClick: onSave, disabled: (locked || !draft) && dirty, disabledReason: locked && dirty ? "This campaign version is locked." : !draft && dirty ? "The campaign draft is not available." : undefined }}
/>}
notices={(localError || locked) ?
notices={(localError || locked || version?.mail_profile_migration_required) ?
<>
{version?.mail_profile_migration_required && <LegacyMailMigrationNotice campaignId={campaignId} versionId={version.id} />}
{localError && <DismissibleAlert tone="danger" resetKey={localError} floating>{localError}</DismissibleAlert>}
{locked && <LockedVersionNotice settings={settings} campaignId={campaignId} version={version} currentVersionId={currentVersionId} reload={onReload} message="i18n:govoplan-campaign.this_page_is_read_only_for_the_selected_version.dacf5743" />}
</> : undefined}
@@ -0,0 +1,37 @@
import { Button, DismissibleAlert, useGuardedNavigate } from "@govoplan/core-webui";
type LegacyMailMigrationNoticeProps = {
campaignId: string;
versionId?: string;
showSettingsLink?: boolean;
onMigrate?: () => void;
canMigrate?: boolean;
busy?: boolean;
};
export default function LegacyMailMigrationNotice({
campaignId,
versionId,
showSettingsLink = true,
onMigrate,
canMigrate = false,
busy = false
}: LegacyMailMigrationNoticeProps) {
const navigate = useGuardedNavigate();
const query = versionId ? `?version=${encodeURIComponent(versionId)}` : "";
return (
<DismissibleAlert tone="warning" dismissible={false}>
<p>i18n:govoplan-campaign.legacy_mail_migration_required</p>
<div className="button-row compact-actions">
{showSettingsLink && <Button
onClick={() => navigate(`/campaigns/${encodeURIComponent(campaignId)}/mail-settings${query}`)}
disabled={busy}
>i18n:govoplan-campaign.open_mail_settings</Button>}
{onMigrate && <Button variant="primary" onClick={onMigrate} disabled={!canMigrate || busy}>
{busy ? "i18n:govoplan-campaign.migrating_mail_profile" : "i18n:govoplan-campaign.migrate_selected_mail_profile"}
</Button>}
</div>
</DismissibleAlert>
);
}
@@ -38,6 +38,7 @@ export type CampaignMessagePreviewOverlayProps = {
navigation?: CampaignMessagePreviewNavigation;
actions?: ReactNode;
closeLabel?: string;
closeDisabled?: boolean;
onClose: () => void;
};
@@ -56,6 +57,7 @@ export default function CampaignMessagePreviewOverlay({
navigation,
actions,
closeLabel = "i18n:govoplan-campaign.close.bbfa773e",
closeDisabled = false,
onClose
}: CampaignMessagePreviewOverlayProps) {
const shownSubject = subject?.trim() || "i18n:govoplan-campaign.no_subject.7b4e8035";
@@ -67,7 +69,7 @@ export default function CampaignMessagePreviewOverlay({
const dialogPanel = contentRef.current?.closest<HTMLElement>("[data-dialog-stack-state]");
if (dialogPanel?.dataset.dialogStackState !== "topmost") return;
if (isEditableTarget(event.target)) return;
if (!navigation) return;
if (!navigation || closeDisabled) return;
if (event.key === "ArrowLeft") {
event.preventDefault();
if (navigation.index > 0) navigation.onPrevious();
@@ -85,7 +87,7 @@ export default function CampaignMessagePreviewOverlay({
window.addEventListener("keydown", handleKeyDown);
return () => window.removeEventListener("keydown", handleKeyDown);
}, [navigation]);
}, [navigation, closeDisabled]);
return (
<Dialog
@@ -93,6 +95,7 @@ export default function CampaignMessagePreviewOverlay({
title={title}
onClose={onClose}
closeLabel={closeLabel}
closeDisabled={closeDisabled}
closeOnBackdrop={false}
backdropClassName="overlay-backdrop message-preview-backdrop"
className="modal-panel template-preview-modal message-preview-modal"
@@ -101,7 +104,7 @@ export default function CampaignMessagePreviewOverlay({
footerClassName="modal-footer"
footer={<>
{actions && <div className="button-row compact-actions">{actions}</div>}
<Button variant="primary" onClick={onClose}>{closeLabel}</Button>
<Button variant="primary" onClick={onClose} disabled={closeDisabled}>{closeLabel}</Button>
</>}
>
<div ref={contentRef} className="message-preview-content">
@@ -113,11 +116,11 @@ export default function CampaignMessagePreviewOverlay({
</div>
{navigation &&
<div className="button-row compact-actions template-preview-nav" aria-label="i18n:govoplan-campaign.preview_message_navigation.d28a8dc0">
<button type="button" className="version-arrow" onClick={navigation.onFirst} disabled={navigation.index <= 0} title="i18n:govoplan-campaign.first_message.ffc124fd" aria-label="i18n:govoplan-campaign.first_message.ffc124fd"><ArrowBigLeftDash aria-hidden="true" /></button>
<button type="button" className="version-arrow" onClick={navigation.onPrevious} disabled={navigation.index <= 0} title="i18n:govoplan-campaign.previous_message.93261bd8" aria-label="i18n:govoplan-campaign.previous_message.93261bd8"><ArrowBigLeft aria-hidden="true" /></button>
<button type="button" className="version-arrow" onClick={navigation.onFirst} disabled={closeDisabled || navigation.index <= 0} title="i18n:govoplan-campaign.first_message.ffc124fd" aria-label="i18n:govoplan-campaign.first_message.ffc124fd"><ArrowBigLeftDash aria-hidden="true" /></button>
<button type="button" className="version-arrow" onClick={navigation.onPrevious} disabled={closeDisabled || navigation.index <= 0} title="i18n:govoplan-campaign.previous_message.93261bd8" aria-label="i18n:govoplan-campaign.previous_message.93261bd8"><ArrowBigLeft aria-hidden="true" /></button>
<span className="template-preview-count">{navigation.index + 1} / {navigation.total}</span>
<button type="button" className="version-arrow" onClick={navigation.onNext} disabled={navigation.index >= navigation.total - 1} title="i18n:govoplan-campaign.next_message.e3960a5d" aria-label="i18n:govoplan-campaign.next_message.e3960a5d"><ArrowBigRight aria-hidden="true" /></button>
<button type="button" className="version-arrow" onClick={navigation.onLast} disabled={navigation.index >= navigation.total - 1} title="i18n:govoplan-campaign.last_message.83741110" aria-label="i18n:govoplan-campaign.last_message.83741110"><ArrowBigRightDash aria-hidden="true" /></button>
<button type="button" className="version-arrow" onClick={navigation.onNext} disabled={closeDisabled || navigation.index >= navigation.total - 1} title="i18n:govoplan-campaign.next_message.e3960a5d" aria-label="i18n:govoplan-campaign.next_message.e3960a5d"><ArrowBigRight aria-hidden="true" /></button>
<button type="button" className="version-arrow" onClick={navigation.onLast} disabled={closeDisabled || navigation.index >= navigation.total - 1} title="i18n:govoplan-campaign.last_message.83741110" aria-label="i18n:govoplan-campaign.last_message.83741110"><ArrowBigRightDash aria-hidden="true" /></button>
</div>
}
</ActionToolbar>
@@ -1,4 +1,4 @@
import { useCallback, useEffect, useMemo, useRef, useState } from "react";
import { useCallback, useEffect, useMemo, useRef, useState, type SetStateAction } from "react";
import {
revisionConflictFromError,
threeWayMerge,
@@ -13,6 +13,8 @@ import {
} from "../../../api/campaigns";
import { formatDateTime, getCampaignJson } from "../utils/campaignView";
import { ensureCampaignDraft, updateNested } from "../utils/draftEditor";
import { clientCampaignEditorState } from "../utils/editorState";
import { campaignMailReferencesUnchanged } from "../utils/mailProfileReference";
import { useRegisterCampaignUnsavedChanges } from "../context/UnsavedChangesContext";
type StepValue = string | (() => string | null | undefined);
@@ -93,6 +95,16 @@ export function useCampaignDraftEditor({
const baseDraftRef = useRef<Record<string, unknown> | null>(null);
const baseRevisionRef = useRef<number | null>(null);
const baseEtagRef = useRef<string | null>(null);
const loadedVersionIdRef = useRef<string | null>(null);
const contextKey = JSON.stringify([campaignId, settings.apiBaseUrl, settings.apiKey, settings.accessToken]);
const contextRef = useRef(contextKey);
const loadedContextRef = useRef(contextKey);
contextRef.current = contextKey;
const draftRef = useRef<Record<string, unknown> | null>(null);
const dirtyRef = useRef(false);
const editSequenceRef = useRef(0);
const saveInFlightRef = useRef<Promise<boolean> | null>(null);
const discardGenerationRef = useRef(0);
const resolveConcurrencyConflict = useConcurrencyConflictResolver();
useEffect(() => {
@@ -102,13 +114,37 @@ export function useCampaignDraftEditor({
onLoadedRef.current = onLoaded;
}, [loadedLabel, transformLoadedDraft, transformDraftBeforeSave, onLoaded]);
const [draft, setDraft] = useState<Record<string, unknown> | null>(null);
const [dirty, setDirty] = useState(false);
const [draft, setDraftState] = useState<Record<string, unknown> | null>(null);
const [dirty, setDirtyState] = useState(false);
const [saving, setSaving] = useState(false);
const [saveState, setSaveState] = useState("i18n:govoplan-campaign.loaded.6db90a0a");
const [localError, setLocalError] = useState("");
const setDraft = useCallback((update: SetStateAction<Record<string, unknown> | null>) => {
const next = typeof update === "function" ? update(draftRef.current) : update;
if (next === draftRef.current) return;
draftRef.current = next;
editSequenceRef.current += 1;
setDraftState(next);
}, []);
const setDirty = useCallback((update: SetStateAction<boolean>) => {
dirtyRef.current = typeof update === "function" ? update(dirtyRef.current) : update;
setDirtyState(dirtyRef.current);
}, []);
useEffect(() => {
if (!version) return;
if (!version) {
if (loadedContextRef.current !== contextKey) {
draftRef.current = null;
setDraftState(null);
setDirty(false);
loadedVersionIdRef.current = null;
}
return;
}
if (loadedContextRef.current === contextKey && loadedVersionIdRef.current === version.id && (
dirtyRef.current || saveInFlightRef.current || version.edit_revision < (baseRevisionRef.current ?? 0)
)) return;
const initialDraft = ensureCampaignDraft(version);
const loadedDraft = transformLoadedDraftRef.current?.(version, initialDraft) ?? initialDraft;
baseDraftRef.current = (
@@ -116,32 +152,51 @@ export function useCampaignDraftEditor({
);
baseRevisionRef.current = version.edit_revision;
baseEtagRef.current = version.strong_etag;
setDraft(loadedDraft);
loadedVersionIdRef.current = version.id;
loadedContextRef.current = contextKey;
draftRef.current = loadedDraft;
setDraftState(loadedDraft);
setDirty(false);
setLocalError("");
setSaveState(loadedLabelRef.current(version));
onLoadedRef.current?.(version, loadedDraft);
}, [version]);
}, [contextKey, version, setDirty]);
const markDirty = useCallback(() => {
editSequenceRef.current += 1;
setDirty(true);
setLocalError("");
}, []);
}, [setDirty]);
const patch = useCallback((path: string[], value: unknown) => {
if (locked) return;
setDraft((current) => updateNested(current ?? {}, path, value));
markDirty();
}, [locked, markDirty]);
}, [locked, markDirty, setDraft]);
const saveDraft = useCallback(async (_mode: "auto" | "manual" = "manual"): Promise<boolean> => {
if (!draft || !version || locked) return false;
const saveDraft = useCallback((_mode: "auto" | "manual" = "manual"): Promise<boolean> => {
if (saveInFlightRef.current) return saveInFlightRef.current;
const submittedDraft = draftRef.current;
if (!submittedDraft || !version || locked) return Promise.resolve(false);
discardGenerationRef.current += 1;
const submittedSequence = editSequenceRef.current;
const submittedVersionId = version.id;
const stillCurrent = () => loadedVersionIdRef.current === submittedVersionId && contextRef.current === contextKey;
setSaving(true);
setSaveState("i18n:govoplan-campaign.saving.56a2285c");
setError("");
setLocalError("");
const operation = (async () => {
try {
const draftToSave = transformDraftBeforeSaveRef.current?.(draft) ?? draft;
const draftToSave = transformDraftBeforeSaveRef.current?.(submittedDraft) ?? submittedDraft;
const additionalPayload = extraPayload?.() ?? {};
if (version.mail_profile_migration_required && !additionalPayload.migrate_legacy_mail_settings
&& !campaignMailReferencesUnchanged(baseDraftRef.current ?? getCampaignJson(version), draftToSave)) {
// Unchanged Mail references allow independent content/archive repairs;
// the server retains legacy transport without migrating it. Changing
// the reference still needs the explicit audited Mail settings action.
throw new Error("i18n:govoplan-campaign.legacy_mail_migration_required");
}
let mutation = campaignVersionMutation(
version,
draftToSave,
@@ -181,6 +236,7 @@ export function useCampaignDraftEditor({
campaignId,
version.id
);
if (!stillCurrent()) return false;
const latestLoaded = transformLoadedDraftRef.current?.(
latest,
ensureCampaignDraft(latest)
@@ -211,10 +267,20 @@ export function useCampaignDraftEditor({
resourceLabel: `Campaign version ${latest.version_number}`,
merge
});
if (resolution.action === "cancel") return false;
if (!stillCurrent()) return false;
if (resolution.action === "cancel") {
setSaveState("i18n:govoplan-campaign.save_cancelled");
return false;
}
if (resolution.action === "reload") {
draftRef.current = latestLoaded;
setDraftState(latestLoaded);
baseDraftRef.current = latestDraft;
baseRevisionRef.current = latest.edit_revision;
baseEtagRef.current = latest.strong_etag;
setDirty(false);
await reload({ force: true });
setSaveState(loadedLabelRef.current(latest));
onLoadedRef.current?.(latest, latestLoaded);
return false;
}
mutation = resolution.value;
@@ -231,35 +297,83 @@ export function useCampaignDraftEditor({
"The campaign changed repeatedly while it was being saved. Reload and try again."
);
}
setDraft(getCampaignJson(saved));
baseDraftRef.current = getCampaignJson(saved);
baseRevisionRef.current = saved.edit_revision;
baseEtagRef.current = saved.strong_etag;
setDirty(false);
setSaveState(`Saved ${formatDateTime(saved.autosaved_at ?? saved.updated_at)}`);
onSaved?.(saved);
await reload();
return true;
if (!stillCurrent()) return false;
const savedInitial = ensureCampaignDraft(saved);
const savedDraft = transformLoadedDraftRef.current?.(saved, savedInitial) ?? savedInitial;
const newerEdits = editSequenceRef.current !== submittedSequence;
if (!newerEdits) {
draftRef.current = savedDraft;
setDraftState(savedDraft);
baseDraftRef.current = transformDraftBeforeSaveRef.current?.(savedDraft) ?? savedDraft;
baseRevisionRef.current = saved.edit_revision;
baseEtagRef.current = saved.strong_etag;
setDirty(false);
}
// A late local edit keeps its original merge base and revision. The next
// explicit save reconciles against the acknowledged server revision,
// rather than silently overwriting concurrent changes merged into it.
if (newerEdits) setDirty(true);
setSaveState(newerEdits ? "i18n:govoplan-campaign.saved_newer_changes_pending"
: `Saved ${formatDateTime(saved.autosaved_at ?? saved.updated_at)}`);
try {
if (!newerEdits) {
onSaved?.(saved);
await reload();
}
} catch {
// The POST acknowledgement is authoritative. A failed refresh or
// observer must not report a committed mutation as a failed save.
setError("i18n:govoplan-campaign.saved_refresh_failed");
}
return !newerEdits && !dirtyRef.current;
} catch (err) {
const text = err instanceof Error ? err.message : String(err);
setLocalError(text);
setSaveState("i18n:govoplan-campaign.save_failed.0a444467");
if (stillCurrent()) {
setLocalError(text);
setSaveState("i18n:govoplan-campaign.save_failed.0a444467");
}
return false;
}
}, [campaignId, currentFlow, currentStep, draft, extraPayload, isComplete, locked, onSaved, reload, resolveConcurrencyConflict, setError, settings, version, workflowState]);
})();
const pending = operation.finally(() => {
saveInFlightRef.current = null;
setSaving(false);
});
saveInFlightRef.current = pending;
return pending;
}, [campaignId, contextKey, currentFlow, currentStep, extraPayload, isComplete, locked, onSaved, reload, resolveConcurrencyConflict, setDirty, setError, settings, version, workflowState]);
const discardDraft = useCallback(async () => {
if (version) {
const initialDraft = ensureCampaignDraft(version);
const loadedDraft = transformLoadedDraftRef.current?.(version, initialDraft) ?? initialDraft;
setDraft(loadedDraft);
if (saveInFlightRef.current || !version) return;
const generation = ++discardGenerationRef.current;
const sequence = editSequenceRef.current;
const stillCurrent = () => generation === discardGenerationRef.current
&& loadedVersionIdRef.current === version.id && contextRef.current === contextKey;
try {
// Do not discard local work until a fresh version was actually read.
const latest = await getCampaignVersion(settings, campaignId, version.id);
if (!stillCurrent()) return;
if (sequence !== editSequenceRef.current || saveInFlightRef.current
|| latest.edit_revision < (baseRevisionRef.current ?? 0)) {
setLocalError("i18n:govoplan-campaign.discard_superseded");
return;
}
const initialDraft = ensureCampaignDraft(latest);
const loadedDraft = transformLoadedDraftRef.current?.(latest, initialDraft) ?? initialDraft;
draftRef.current = loadedDraft;
setDraftState(loadedDraft);
baseDraftRef.current = transformDraftBeforeSaveRef.current?.(loadedDraft) ?? loadedDraft;
baseRevisionRef.current = latest.edit_revision;
baseEtagRef.current = latest.strong_etag;
setDirty(false);
setLocalError("");
setSaveState(loadedLabelRef.current(version));
onLoadedRef.current?.(version, loadedDraft);
setSaveState(loadedLabelRef.current(latest));
onLoadedRef.current?.(latest, loadedDraft);
await reload({ force: true });
} catch (err) {
if (stillCurrent()) setLocalError(err instanceof Error ? err.message : String(err));
}
await reload({ force: true });
}, [reload, version]);
}, [campaignId, contextKey, reload, setDirty, settings, version]);
const unsavedRegistration = useMemo(() => dirty && !locked ? {
title: unsavedTitle,
@@ -275,6 +389,7 @@ export function useCampaignDraftEditor({
setDraft,
displayDraft: draft ?? ensureCampaignDraft(null),
dirty,
saving,
setDirty,
saveState,
setSaveState,
@@ -298,7 +413,7 @@ function campaignVersionMutation(
current_step: overrides.current_step ?? version.current_step ?? null,
workflow_state: overrides.workflow_state ?? version.workflow_state ?? null,
is_complete: overrides.is_complete ?? version.is_complete ?? false,
editor_state: overrides.editor_state ?? version.editor_state ?? {},
editor_state: clientCampaignEditorState(overrides.editor_state ?? version.editor_state),
source_filename: overrides.source_filename ?? version.source_filename ?? null,
source_base_path: overrides.source_base_path ?? version.source_base_path ?? null,
migrate_legacy_mail_settings: (
@@ -0,0 +1,73 @@
import { useRef, useState } from "react";
import { ApiError } from "@govoplan/core-webui";
import { getCampaignVersion, updateCampaignReviewState, type CampaignReviewStatePayload, type CampaignVersionDetail } from "../../../api/campaigns";
import type { ApiSettings } from "../../../types";
import { storedMessageReviewState } from "../review/builtMessageQuery";
type ReviewProgressDelta = Pick<CampaignReviewStatePayload, "reviewed_message_keys" | "issue_decisions" | "decision_category_key"> & {
inspection_complete?: boolean;
};
/** A decision ACK is durable progress, not a full workspace reload or rebuild. */
export function useCampaignReviewProgress(settings: ApiSettings, campaignId: string, version: CampaignVersionDetail | null) {
const buildToken = storedMessageReviewState(version).buildToken;
const key = JSON.stringify([settings.apiBaseUrl, settings.apiKey, settings.accessToken, campaignId, version?.id, buildToken]);
const currentKey = useRef(key);
currentKey.current = key;
const latest = useRef({ key, version });
if (latest.current.key !== key || (version && version.edit_revision > (latest.current.version?.edit_revision ?? -1))) {
latest.current = { key, version };
}
const [, renderAcknowledgement] = useState(0);
const [saving, setSaving] = useState(false);
const pending = useRef(false);
const effectiveVersion = storedMessageReviewState(latest.current.version).buildToken === buildToken ? latest.current.version : version;
async function recordProgress(delta: ReviewProgressDelta): Promise<CampaignVersionDetail> {
const base = latest.current.version;
if (pending.current) throw new Error("i18n:govoplan-campaign.review_save_pending");
if (!base || !buildToken || storedMessageReviewState(base).buildToken !== buildToken) {
throw new Error("i18n:govoplan-campaign.review_build_changed");
}
pending.current = true;
setSaving(true);
try {
const saved = await updateCampaignReviewState(settings, campaignId, base.id, {
...delta,
inspection_complete: delta.inspection_complete === true,
merge_progress: true,
build_token: buildToken,
base_revision: base.edit_revision
});
if (currentKey.current !== key) throw new Error("i18n:govoplan-campaign.review_build_changed");
const current = latest.current.version;
if (current && storedMessageReviewState(current).buildToken !== buildToken) {
throw new Error("i18n:govoplan-campaign.review_build_changed");
}
// A workspace refresh can observe a newer same-build revision while
// this request is still in flight. Never replace it with an older ACK.
const acknowledged = current && current.edit_revision > saved.edit_revision ? current : saved;
latest.current = { key, version: acknowledged };
renderAcknowledgement(value => value + 1);
return acknowledged;
} catch (error) {
if (error instanceof ApiError && error.status === 409) {
// Refresh only authoritative revision/evidence. Never automatically
// replay an approval, or reconcile it onto another frozen build.
try {
const fresh = await getCampaignVersion(settings, campaignId, base.id);
if (currentKey.current === key && fresh.edit_revision >= (latest.current.version?.edit_revision ?? -1)) {
latest.current = { key, version: fresh };
renderAcknowledgement(value => value + 1);
}
} catch { /* Keep the submitted note and original conflict visible. */ }
}
throw error;
} finally {
pending.current = false;
setSaving(false);
}
}
return { reviewVersion: effectiveVersion, recordProgress, saving, buildToken };
}
@@ -33,10 +33,12 @@ export function useCampaignWorkspaceData(
} = options;
const [searchParams] = useSearchParams();
const selectedVersionId = searchParams.get("version");
const [data, setData] = useState<CampaignWorkspaceData>(initialData);
const [data, setData] = useState<{ queryKey: string; value: CampaignWorkspaceData } | null>(null);
const [loading, setLoading] = useState(false);
const [error, setError] = useState("");
const dataRef = useRef<CampaignWorkspaceData>(initialData);
const dataRef = useRef<{ queryKey: string; value: CampaignWorkspaceData } | null>(null);
const requestGeneration = useRef(0);
const requestAbort = useRef<AbortController | null>(null);
const { getDeltaWatermark, setDeltaWatermark, resetDeltaWatermark } = useDeltaWatermarks();
const queryKey = useMemo(
() => JSON.stringify({
@@ -51,9 +53,18 @@ export function useCampaignWorkspaceData(
}),
[campaignId, selectedVersionId, includeCurrentVersion, includeSummary, includeVersions, settings.apiBaseUrl, settings.apiKey, settings.accessToken]
);
const activeQueryKey = useRef(queryKey);
activeQueryKey.current = queryKey;
const reload = useCallback(async (options?: {force?: boolean;}) => {
if (!campaignId) return;
if (!campaignId || activeQueryKey.current !== queryKey) return;
const generation = ++requestGeneration.current;
requestAbort.current?.abort();
const controller = new AbortController();
requestAbort.current = controller;
const isCurrentRequest = () => (
!controller.signal.aborted && activeQueryKey.current === queryKey && requestGeneration.current === generation
);
const force = options?.force === true;
setLoading(true);
setError("");
@@ -61,7 +72,8 @@ export function useCampaignWorkspaceData(
const shouldLoadVersions = includeCurrentVersion || includeVersions;
if (force) resetDeltaWatermark(queryKey);
let nextWatermark = force ? null : getDeltaWatermark(queryKey);
let merged: CampaignWorkspaceData = force ? initialData : dataRef.current;
let merged = !force && dataRef.current?.queryKey === queryKey
? dataRef.current.value : initialData;
let hasMore = false;
do {
const response = await getCampaignWorkspaceDelta(settings, campaignId, {
@@ -70,35 +82,48 @@ export function useCampaignWorkspaceData(
includeSummary,
includeVersions: shouldLoadVersions,
since: nextWatermark,
});
}, { cache: "no-store", signal: controller.signal });
// Do not apply an old campaign/version/auth response or request another
// page after a newer reload or navigation has superseded this request.
if (!isCurrentRequest()) return;
merged = mergeWorkspaceDelta(merged, response);
nextWatermark = response.watermark ?? null;
hasMore = response.has_more;
} while (hasMore);
setDeltaWatermark(queryKey, nextWatermark);
dataRef.current = merged;
setData(merged);
dataRef.current = { queryKey, value: merged };
setData(dataRef.current);
} catch (err) {
dataRef.current = initialData;
setData(initialData);
if (!isCurrentRequest()) return;
// A failed refresh does not undo an authoritative save or erase the last
// usable same-query workspace. Retry from a full response next time.
resetDeltaWatermark(queryKey);
setError(err instanceof Error ? err.message : String(err));
} finally {
setLoading(false);
if (isCurrentRequest()) {
requestAbort.current = null;
setLoading(false);
}
}
}, [settings, campaignId, includeCurrentVersion, includeSummary, includeVersions, selectedVersionId, queryKey, getDeltaWatermark, setDeltaWatermark, resetDeltaWatermark]);
useEffect(() => {
resetDeltaWatermark(queryKey);
dataRef.current = initialData;
setData(initialData);
dataRef.current = null;
setData(null);
setError("");
}, [queryKey, resetDeltaWatermark]);
useEffect(() => {
reload();
void reload();
return () => {
requestGeneration.current += 1;
requestAbort.current?.abort();
requestAbort.current = null;
};
}, [reload]);
return { data, loading, error, reload, setError };
return { data: data?.queryKey === queryKey ? data.value : initialData, loading, error, reload, setError };
}
function mergeWorkspaceDelta(current: CampaignWorkspaceData, response: CampaignWorkspaceDeltaResponse): CampaignWorkspaceData {
@@ -464,7 +464,7 @@ function mergeAddressGroups(
nextValues[group.key] = dedupeAddresses([
...(nextValues[group.key] ?? []),
...group.addresses.map(cloneMailboxAddress)
]);
], { preserveOrder: true });
}
return nextValues;
}
@@ -489,7 +489,7 @@ function prepareAddressValues(
}
addresses.push({ name, email });
}
prepared[column.key] = column.allowMultiple ? dedupeAddresses(addresses) : addresses.slice(0, 1);
prepared[column.key] = column.allowMultiple ? dedupeAddresses(addresses, { preserveOrder: true }) : addresses.slice(0, 1);
}
return { values: prepared, error: "" };
}
@@ -521,6 +521,20 @@ export function entryWithAddressList(entry: Record<string, unknown>, key: Addres
return nextEntry;
}
export function entryWithAddressValues(
entry: Record<string, unknown>, values: HeaderAddressValues, merges: EntryAddressMergeValues
): Record<string, unknown> {
let next = entry;
for (const column of recipientAddressOverlayColumns) {
if (!(column.key in values)) continue;
next = entryWithAddressList(next, column.key, values[column.key] ?? []);
if (!column.mergeKey || !(column.mergeKey in merges)) continue;
next = { ...next, [column.mergeKey]: Boolean(merges[column.mergeKey]) };
delete next[column.mergeKey.replace("merge_", "combine_")];
}
return next;
}
export function headerAddressValues(columns: EntryAddressColumn[], recipientsSection: Record<string, unknown>): HeaderAddressValues {
return Object.fromEntries(columns.map((column) => [
column.key,
@@ -580,7 +594,7 @@ function parsePastedAddressGroups(targetKey: AddressFieldKey, text: string): Arr
const addressText = prefixed?.text ?? token;
const address = parseMailboxAddressText(addressText);
if (!address?.email) continue;
grouped.set(key, dedupeAddresses([...(grouped.get(key) ?? []), address]));
grouped.set(key, dedupeAddresses([...(grouped.get(key) ?? []), address], { preserveOrder: true }));
}
return [...grouped.entries()].map(([key, addresses]) => ({ key, addresses }));
}
@@ -23,7 +23,6 @@ import {
import { getDraftFields } from "../utils/fieldDefinitions";
import { asRecord } from "../utils/campaignView";
import {
getEntryAddresses,
hiddenRecipientAddressMatch,
recipientAddressFilterValue,
recipientAddressSummary
@@ -74,7 +73,7 @@ export function recipientProfileColumns({ settings, campaignId, draft, locked, f
id: "recipients",
header: "Recipient(s)",
width: "minmax(320px, 1.4fr)",
maxWidth: 640,
preferredMaxWidth: 640,
resizable: true,
filterable: true,
render: (entry, index) => {
@@ -114,7 +113,7 @@ export function recipientProfileColumns({ settings, campaignId, draft, locked, f
id: "delivery",
header: "Delivery",
width: "minmax(260px, 0.9fr)",
maxWidth: 480,
preferredMaxWidth: 480,
resizable: true,
filterable: true,
render: (entry, index) => {
@@ -151,7 +150,7 @@ export function recipientProfileColumns({ settings, campaignId, draft, locked, f
Postboxes ({targets.length})
</Button>
)}
{printTarget.target && (
{Boolean(printTarget.target) && (
<span className="muted small-note" title={String(printTarget.target)}>
{printTarget.channel === "internal_mail" ? "Internal mail" : "Postal"}: {String(printTarget.target)}
</span>
@@ -185,13 +184,13 @@ export function recipientProfileColumns({ settings, campaignId, draft, locked, f
},
value: (entry) => normalizeAttachmentRules(entry.attachments).map((rule) => `${rule.label ?? ""} ${rule.file_filter ?? ""}`).join(", ")
}] : []),
} satisfies DataGridColumn<Record<string, unknown>>] : []),
...fieldDefinitions.filter((field) => field.can_override !== false).map((field): DataGridColumn<Record<string, unknown>> => ({
id: `field-${field.name}`,
header: field.label || field.name,
width: 190,
minWidth: 160,
maxWidth: 360,
preferredMaxWidth: 360,
resizable: true,
sortable: true,
filterable: true,
@@ -0,0 +1,35 @@
import { addressesFromValue, i18nMessage } from "@govoplan/core-webui";
import { asRecord } from "../utils/campaignView";
const groups = [
{ id: "to", label: "i18n:govoplan-campaign.report_recipients_to" },
{ id: "cc", label: "i18n:govoplan-campaign.report_recipients_cc" },
{ id: "bcc", label: "i18n:govoplan-campaign.report_recipients_bcc" }
] as const;
export function reportRecipientGroups(row: Record<string, unknown>) {
const resolved = asRecord(row.resolved_recipients);
const result = groups.map(group => ({ ...group, addresses: addressesFromValue(resolved[group.id]) }));
if (result.every(group => group.addresses.length === 0) && typeof row.recipient_email === "string" && row.recipient_email.trim()) {
result[0].addresses = [{ email: row.recipient_email.trim() }];
}
return result.filter(group => group.addresses.length > 0);
}
export function reportRecipientSearchText(row: Record<string, unknown>): string {
return reportRecipientGroups(row).flatMap(group => group.addresses.map(address => `${address.name ?? ""} ${address.email}`)).join(" ");
}
export default function ReportRecipients({ row }: { row: Record<string, unknown> }) {
const values = reportRecipientGroups(row);
if (!values.length) return <span></span>;
return <div className="recipient-outcome-cell campaign-report-recipient-cell">
{values.map(group => <div key={group.id}>
<strong>{group.label}: </strong>
{group.addresses.map((address, index) => <span key={`${address.email}-${index}`}>
{index > 0 ? "; " : ""}{address.name ? `${address.name} <${address.email}>` : address.email}
</span>)}
</div>)}
<span>{String(row.entry_id ?? i18nMessage("i18n:govoplan-campaign.entry_value.b7706ee4", { value0: Number(row.entry_index ?? 0) || 1 }))}</span>
</div>;
}
@@ -0,0 +1,42 @@
import { useRef, useState } from "react";
import { Button, Dialog, DismissibleAlert, FormField } from "@govoplan/core-webui";
import type { ReportReconciliation } from "./reportRecovery";
export default function ReportRecoveryDialog({ request, onConfirm, onClose }: {
request: ReportReconciliation;
onConfirm: (note: string) => Promise<void>;
onClose: () => void;
}) {
const [note, setNote] = useState("");
const [error, setError] = useState("");
const [saving, setSaving] = useState(false);
const pending = useRef(false);
const claim = request.kind === "claim";
const accepted = request.kind === "outcome" && ["smtp_accepted", "imap_appended"].includes(request.decision);
const confirmLabel = claim ? "i18n:govoplan-campaign.report_recover_claim_confirm"
: request.decision === "imap_appended" ? "i18n:govoplan-campaign.report_record_imap_appended"
: request.decision === "imap_not_appended" ? "i18n:govoplan-campaign.report_record_imap_not_appended"
: accepted ? "i18n:govoplan-campaign.report_record_accepted" : "i18n:govoplan-campaign.report_record_not_sent";
async function confirm() {
if (pending.current || !note.trim()) return;
pending.current = true; setSaving(true); setError("");
try { await onConfirm(note.trim()); }
catch (cause) { setError(cause instanceof Error ? cause.message : String(cause)); }
finally { pending.current = false; setSaving(false); }
}
function close() { if (!pending.current) onClose(); }
return <Dialog open portal size="small" title={claim ? "i18n:govoplan-campaign.report_recover_claim_title" : "i18n:govoplan-campaign.report_reconcile_title"}
closeDisabled={saving} onClose={close}
footer={<>
<Button onClick={close} disabled={saving}>i18n:govoplan-campaign.cancel.77dfd213</Button>
<Button variant={accepted ? "primary" : "danger"} onClick={() => void confirm()} disabled={saving || !note.trim()}>
{saving ? "i18n:govoplan-campaign.report_recording_evidence" : confirmLabel}
</Button>
</>}>
<p>{claim ? "i18n:govoplan-campaign.report_recover_claim_help" : accepted ? "i18n:govoplan-campaign.report_accepted_evidence_help" : "i18n:govoplan-campaign.report_not_sent_evidence_help"}</p>
{error && <DismissibleAlert tone="danger" resetKey={error}>{error}</DismissibleAlert>}
<FormField label="i18n:govoplan-campaign.report_evidence_note">
<textarea value={note} onChange={event => setNote(event.target.value)} maxLength={2000} rows={4} required disabled={saving} />
</FormField>
</Dialog>;
}

Some files were not shown because too many files have changed in this diff Show More