Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4d570b5e9e | ||
|
|
a6c5bab3a4 | ||
|
|
4175262b8b | ||
|
|
618f10fe89 | ||
|
|
f222be63b2 | ||
|
|
2c97223fb4 | ||
|
|
5b989a7f6c | ||
|
|
08c1ecbf81 | ||
|
|
c1111c605f |
@@ -137,6 +137,13 @@ records the effective Policy decision and ancestor limits. Inherited
|
||||
definitions remain read-only; lower scopes may narrow, but not broaden,
|
||||
execution, reuse, inheritance, or automation permissions.
|
||||
|
||||
Derived definitions report when their source has a newer immutable revision;
|
||||
the source never mutates the child silently. Adopting an update requires the
|
||||
reviewed source revision and hash plus a reason. It appends a new child
|
||||
revision, retains the previous graph and all run evidence, records reviewer
|
||||
and Policy provenance, and returns the child to draft before the changed graph
|
||||
can run or receive automation.
|
||||
|
||||
Complete active flows support explicit user/API starts, administrative
|
||||
backfills, one-time schedules, interval schedules, and exact-match platform
|
||||
events. Trigger deliveries are durable and idempotent. They enqueue the same
|
||||
@@ -147,11 +154,15 @@ the run before source access or output publication.
|
||||
Confidential and restricted events are not accepted through the direct
|
||||
ingress; those require Core's transactional event bridge.
|
||||
|
||||
Reusable subflow nodes pin a template reference, version, graph snapshot, and
|
||||
parameter values. Their single input is bound to an explicitly marked inline
|
||||
source inside the snapshot, parameter substitution is data-only, and nesting
|
||||
is bounded. This keeps completed run definitions reproducible even when the
|
||||
source template changes later.
|
||||
Reusable subflow nodes select a Policy-authorized complete flow or template and
|
||||
an immutable revision. The server resolves the graph instead of accepting a
|
||||
caller-supplied snapshot, records the source hash and Policy decision, and pins
|
||||
closed typed input/output contracts. Their single input is bound to an
|
||||
explicitly marked typed inline source inside the snapshot, parameter
|
||||
substitution is data-only, and cycles across nested references are rejected.
|
||||
Incompatible caller schemas fail validation before execution. This keeps
|
||||
completed run definitions reproducible even when the source definition changes
|
||||
later.
|
||||
|
||||
The executable fixtures in `fixtures/golden` cover monthly structured-file
|
||||
reconciliation, sanctions screening, a HEICO-style current-status export, and
|
||||
@@ -202,3 +213,21 @@ npm run test:structure
|
||||
|
||||
The implementation epic is
|
||||
[`govoplan-dataflow#1`](https://git.add-ideas.de/GovOPlaN/govoplan-dataflow/issues/1).
|
||||
|
||||
## Git-source WebUI package
|
||||
|
||||
The repository root exposes `@govoplan/dataflow-webui` for Git-tagged release
|
||||
dependencies. It mirrors the owning `webui/package.json` version, public
|
||||
TypeScript/CSS exports and peer requirements, with entry paths under
|
||||
`webui/src`. Consumers provide the shared Core/React peers; the facade runs no
|
||||
development or install scripts. The source archive contains `webui/src`, this
|
||||
README and any repository license file. Run module development checks from `webui/`; Python
|
||||
installation remains governed by `pyproject.toml`.
|
||||
|
||||
Das Repository stellt `@govoplan/dataflow-webui` am Wurzelpfad für versionierte
|
||||
Git-Abhängigkeiten bereit. Version, öffentliche TypeScript-/CSS-Exporte und
|
||||
Peer-Anforderungen entsprechen `webui/package.json`; die Einstiegspfade liegen
|
||||
unter `webui/src`. Gemeinsame Core-/React-Peers stellt die einbindende Anwendung
|
||||
bereit. Die Fassade führt keine Entwicklungs- oder Installationsskripte aus.
|
||||
Entwicklungsprüfungen bleiben in `webui/`, die Python-Installation weiterhin in
|
||||
`pyproject.toml` definiert.
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"name": "@govoplan/dataflow-webui",
|
||||
"version": "0.1.25",
|
||||
"private": true,
|
||||
"type": "module",
|
||||
"main": "webui/src/index.ts",
|
||||
"module": "webui/src/index.ts",
|
||||
"types": "webui/src/index.ts",
|
||||
"exports": {
|
||||
".": {
|
||||
"types": "./webui/src/index.ts",
|
||||
"import": "./webui/src/index.ts"
|
||||
},
|
||||
"./styles/dataflow.css": "./webui/src/styles/dataflow.css"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@govoplan/core-webui": "^0.1.46",
|
||||
"@xyflow/react": "^12.11.2",
|
||||
"lucide-react": "^1.23.0",
|
||||
"react": ">=19.2.7 <20",
|
||||
"react-dom": ">=19.2.7 <20",
|
||||
"react-router": ">=8.3.0 <9",
|
||||
"typescript": "^5.7.2"
|
||||
},
|
||||
"peerDependenciesMeta": {
|
||||
"@govoplan/core-webui": {
|
||||
"optional": true
|
||||
}
|
||||
},
|
||||
"files": [
|
||||
"webui/src",
|
||||
"README.md",
|
||||
"LICENSE"
|
||||
]
|
||||
}
|
||||
+2
-2
@@ -4,14 +4,14 @@ build-backend = "setuptools.build_meta"
|
||||
|
||||
[project]
|
||||
name = "govoplan-dataflow"
|
||||
version = "0.1.19"
|
||||
version = "0.1.25"
|
||||
description = "Governed graphical and SQL data pipelines for GovOPlaN."
|
||||
readme = "README.md"
|
||||
requires-python = ">=3.12"
|
||||
license = "AGPL-3.0-or-later"
|
||||
authors = [{ name = "GovOPlaN" }]
|
||||
dependencies = [
|
||||
"govoplan-core>=0.1.18",
|
||||
"govoplan-core>=0.1.46",
|
||||
"sqlglot>=30.14,<31",
|
||||
]
|
||||
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
from __future__ import annotations
|
||||
|
||||
__version__ = "0.1.19"
|
||||
__version__ = "0.1.25"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from dataclasses import dataclass, field
|
||||
import math
|
||||
from typing import Any, Mapping, Protocol, runtime_checkable
|
||||
|
||||
from govoplan_dataflow.backend.batches import TypedBatch
|
||||
@@ -33,8 +34,8 @@ class ExecutionBudget:
|
||||
raise ValueError("Execution output row limit must be positive.")
|
||||
if self.max_batch_bytes < 1:
|
||||
raise ValueError("Execution byte limit must be positive.")
|
||||
if self.max_wall_seconds <= 0:
|
||||
raise ValueError("Execution time limit must be positive.")
|
||||
if not math.isfinite(self.max_wall_seconds) or self.max_wall_seconds <= 0:
|
||||
raise ValueError("Execution time limit must be finite and positive.")
|
||||
if self.max_memory_bytes < 64 * 1024 * 1024:
|
||||
raise ValueError("Execution memory limit must be at least 64 MiB.")
|
||||
if self.max_concurrency < 1:
|
||||
@@ -106,11 +107,19 @@ class BackendExecutionError(RuntimeError):
|
||||
code: str = "backend.execution",
|
||||
node_id: str | None = None,
|
||||
diagnostics: tuple[DataflowDiagnostic, ...] = (),
|
||||
node_diagnostics: tuple[NodePreviewDiagnostic, ...] = (),
|
||||
source_fingerprints: tuple[dict[str, Any], ...] = (),
|
||||
input_row_count: int = 0,
|
||||
node_preview: NodePreviewResult | None = None,
|
||||
) -> None:
|
||||
super().__init__(message)
|
||||
self.code = code
|
||||
self.node_id = node_id
|
||||
self.diagnostics = diagnostics
|
||||
self.node_diagnostics = node_diagnostics
|
||||
self.source_fingerprints = source_fingerprints
|
||||
self.input_row_count = input_row_count
|
||||
self.node_preview = node_preview
|
||||
|
||||
|
||||
@runtime_checkable
|
||||
|
||||
@@ -1,10 +1,25 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from dataclasses import asdict
|
||||
import hashlib
|
||||
import json
|
||||
import math
|
||||
|
||||
from govoplan_core.security.bounded_process import (
|
||||
ProcessBudgetError,
|
||||
ProcessLimits,
|
||||
run_bounded_operation,
|
||||
)
|
||||
from govoplan_core.security.worker_payload import (
|
||||
decode_worker_payload,
|
||||
encode_worker_payload,
|
||||
)
|
||||
from govoplan_dataflow.backend.backends.base import (
|
||||
BackendExecutionError,
|
||||
BackendExecutionRequest,
|
||||
BackendExecutionResult,
|
||||
BackendSource,
|
||||
ExecutionBudget,
|
||||
canonical_result_schema,
|
||||
)
|
||||
from govoplan_dataflow.backend.batches import TypedBatch
|
||||
@@ -14,8 +29,17 @@ from govoplan_dataflow.backend.executor import (
|
||||
ResolvedSource,
|
||||
execute_preview,
|
||||
)
|
||||
from govoplan_dataflow.backend.ir import IrExecutionResult, ir_to_graph
|
||||
from govoplan_dataflow.backend.schemas import GraphNode
|
||||
from govoplan_dataflow.backend.ir import IrExecutionResult, IrSchema, TypedGraphIr, ir_to_graph
|
||||
from govoplan_dataflow.backend.planner import ExecutionPlan
|
||||
from govoplan_dataflow.backend.schemas import (
|
||||
DataflowDiagnostic,
|
||||
GraphNode,
|
||||
NodePreviewDiagnostic,
|
||||
NodePreviewResult,
|
||||
)
|
||||
|
||||
|
||||
_TRANSPORT_BYTES = 32 * 1024 * 1024
|
||||
|
||||
|
||||
class ReferenceExecutionBackend:
|
||||
@@ -32,6 +56,52 @@ class ReferenceExecutionBackend:
|
||||
self,
|
||||
request: BackendExecutionRequest,
|
||||
) -> BackendExecutionResult:
|
||||
_validate_source_batches(request)
|
||||
try:
|
||||
limits = ProcessLimits(
|
||||
wall_seconds=request.budget.max_wall_seconds,
|
||||
cpu_seconds=max(1, math.ceil(request.budget.max_wall_seconds)),
|
||||
memory_bytes=request.budget.max_memory_bytes,
|
||||
input_bytes=_TRANSPORT_BYTES,
|
||||
output_bytes=_TRANSPORT_BYTES,
|
||||
)
|
||||
payload = encode_worker_payload(_request_payload(request), max_bytes=_TRANSPORT_BYTES)
|
||||
response = decode_worker_payload(
|
||||
run_bounded_operation(_execute_reference_worker, payload, limits=limits),
|
||||
max_bytes=_TRANSPORT_BYTES,
|
||||
)
|
||||
except ProcessBudgetError as exc:
|
||||
raise BackendExecutionError(str(exc), code=f"backend.process.{exc.code}") from exc
|
||||
except ValueError as exc:
|
||||
raise BackendExecutionError(
|
||||
"Reference execution exceeds its supported process/transport budget.",
|
||||
code="backend.budget",
|
||||
) from exc
|
||||
if "error" in response:
|
||||
error = response["error"]
|
||||
raise BackendExecutionError(
|
||||
error["message"], code=error["code"], node_id=error["node_id"],
|
||||
diagnostics=tuple(DataflowDiagnostic.model_validate(item) for item in error["diagnostics"]),
|
||||
node_diagnostics=tuple(NodePreviewDiagnostic.model_validate(item) for item in error["node_diagnostics"]),
|
||||
source_fingerprints=error["source_fingerprints"],
|
||||
input_row_count=error["input_row_count"],
|
||||
node_preview=NodePreviewResult.model_validate(error["node_preview"]) if error["node_preview"] else None,
|
||||
)
|
||||
batch = _batch_from_payload(response["batch"])
|
||||
batch.ensure_within(
|
||||
max_rows=request.budget.max_output_rows,
|
||||
max_bytes=request.budget.max_batch_bytes,
|
||||
)
|
||||
return BackendExecutionResult(
|
||||
contract=IrExecutionResult.model_validate(response["contract"]),
|
||||
batch=batch,
|
||||
node_diagnostics=tuple(NodePreviewDiagnostic.model_validate(item) for item in response["node_diagnostics"]),
|
||||
node_preview=NodePreviewResult.model_validate(response["node_preview"]) if response["node_preview"] else None,
|
||||
metadata=response["metadata"],
|
||||
)
|
||||
|
||||
def _execute_in_process(self, request: BackendExecutionRequest) -> BackendExecutionResult:
|
||||
"""Pure reference evaluation, called only inside the disposable worker."""
|
||||
_validate_source_batches(request)
|
||||
try:
|
||||
result = execute_preview(
|
||||
@@ -50,6 +120,10 @@ class ReferenceExecutionBackend:
|
||||
code="backend.reference",
|
||||
node_id=exc.node_id,
|
||||
diagnostics=tuple(exc.diagnostics),
|
||||
node_diagnostics=tuple(exc.node_diagnostics),
|
||||
source_fingerprints=tuple(exc.source_fingerprints),
|
||||
input_row_count=exc.input_row_count,
|
||||
node_preview=exc.node_preview,
|
||||
) from exc
|
||||
observed_batch = TypedBatch.from_rows(result.rows)
|
||||
batch = TypedBatch.from_rows(
|
||||
@@ -97,6 +171,90 @@ class ReferenceExecutionBackend:
|
||||
)
|
||||
|
||||
|
||||
def _batch_payload(batch: TypedBatch) -> dict:
|
||||
return {
|
||||
"schema": batch.schema.model_dump(mode="python"),
|
||||
"columns": dict(batch.columns),
|
||||
"row_count": batch.row_count,
|
||||
"byte_count": batch.byte_count,
|
||||
}
|
||||
|
||||
|
||||
def _batch_from_payload(value: dict) -> TypedBatch:
|
||||
return TypedBatch(
|
||||
schema=IrSchema.model_validate(value["schema"]), columns=value["columns"],
|
||||
row_count=value["row_count"], byte_count=value["byte_count"],
|
||||
)
|
||||
|
||||
|
||||
def _request_payload(request: BackendExecutionRequest) -> dict:
|
||||
plan = request.plan
|
||||
return {
|
||||
"plan": {
|
||||
"graph": plan.graph.model_dump(mode="python"),
|
||||
"ordered_node_ids": plan.ordered_node_ids,
|
||||
"diagnostics": tuple(item.model_dump(mode="python") for item in plan.diagnostics),
|
||||
"generated_sql": plan.generated_sql,
|
||||
"sql_diagnostics": tuple(item.model_dump(mode="python") for item in plan.sql_diagnostics),
|
||||
"semantic_hash": plan.semantic_hash,
|
||||
},
|
||||
"budget": asdict(request.budget),
|
||||
"preview_node_id": request.preview_node_id,
|
||||
"sources": {
|
||||
key: {
|
||||
"node_id": source.node_id, "batch": _batch_payload(source.batch),
|
||||
"source_ref": source.source_ref, "provider": source.provider,
|
||||
"fingerprint": source.fingerprint, "total_rows": source.total_rows,
|
||||
"truncated": source.truncated, "source_name": source.source_name,
|
||||
"kind": source.kind,
|
||||
}
|
||||
for key, source in request.sources.items()
|
||||
},
|
||||
}
|
||||
|
||||
|
||||
def _execute_reference_worker(payload: bytes) -> bytes:
|
||||
"""Data-only worker boundary; no database, provider callback or principal."""
|
||||
value = decode_worker_payload(payload, max_bytes=_TRANSPORT_BYTES)
|
||||
plan = value["plan"]
|
||||
request = BackendExecutionRequest(
|
||||
plan=ExecutionPlan(
|
||||
graph=TypedGraphIr.model_validate(plan["graph"]),
|
||||
ordered_node_ids=plan["ordered_node_ids"],
|
||||
diagnostics=tuple(DataflowDiagnostic.model_validate(item) for item in plan["diagnostics"]),
|
||||
generated_sql=plan["generated_sql"],
|
||||
sql_diagnostics=tuple(DataflowDiagnostic.model_validate(item) for item in plan["sql_diagnostics"]),
|
||||
semantic_hash=plan["semantic_hash"],
|
||||
),
|
||||
budget=ExecutionBudget(**value["budget"]),
|
||||
preview_node_id=value["preview_node_id"],
|
||||
sources={
|
||||
key: BackendSource(**{**source, "batch": _batch_from_payload(source["batch"])})
|
||||
for key, source in value["sources"].items()
|
||||
},
|
||||
)
|
||||
try:
|
||||
result = ReferenceExecutionBackend()._execute_in_process(request)
|
||||
except BackendExecutionError as exc:
|
||||
response = {"error": {
|
||||
"message": str(exc), "code": exc.code, "node_id": exc.node_id,
|
||||
"diagnostics": tuple(item.model_dump(mode="python") for item in exc.diagnostics),
|
||||
"node_diagnostics": tuple(item.model_dump(mode="python") for item in exc.node_diagnostics),
|
||||
"source_fingerprints": exc.source_fingerprints,
|
||||
"input_row_count": exc.input_row_count,
|
||||
"node_preview": exc.node_preview.model_dump(mode="python") if exc.node_preview else None,
|
||||
}}
|
||||
else:
|
||||
response = {
|
||||
"contract": result.contract.model_dump(mode="python"),
|
||||
"batch": _batch_payload(result.batch),
|
||||
"node_diagnostics": tuple(item.model_dump(mode="python") for item in result.node_diagnostics),
|
||||
"node_preview": result.node_preview.model_dump(mode="python") if result.node_preview else None,
|
||||
"metadata": dict(result.metadata),
|
||||
}
|
||||
return encode_worker_payload(response, max_bytes=_TRANSPORT_BYTES)
|
||||
|
||||
|
||||
def _validate_source_batches(request: BackendExecutionRequest) -> None:
|
||||
for source in request.sources.values():
|
||||
try:
|
||||
@@ -139,6 +297,7 @@ def _source_for_node(
|
||||
node: GraphNode,
|
||||
) -> BackendSource | None:
|
||||
candidates = (
|
||||
reference_source_key(node),
|
||||
node.id,
|
||||
str(node.config.get("source_ref") or ""),
|
||||
str(node.config.get("source_name") or ""),
|
||||
@@ -153,4 +312,10 @@ def _source_for_node(
|
||||
)
|
||||
|
||||
|
||||
def reference_source_key(node: GraphNode) -> str:
|
||||
"""Nested graphs may reuse node IDs; bind resolved data to the full config."""
|
||||
content = json.dumps(node.config, sort_keys=True, separators=(",", ":"), default=str)
|
||||
return "reference-config:" + hashlib.sha256(content.encode("utf-8")).hexdigest()
|
||||
|
||||
|
||||
__all__ = ["ReferenceExecutionBackend"]
|
||||
|
||||
@@ -19,6 +19,7 @@ from govoplan_dataflow.backend.operator_registry import (
|
||||
OperatorExecutionContext,
|
||||
OperatorExecutionResult,
|
||||
)
|
||||
from govoplan_dataflow.backend.preview_limits import MAX_RESULT_BYTES
|
||||
from govoplan_dataflow.backend.schemas import (
|
||||
DataflowDiagnostic,
|
||||
GraphNode,
|
||||
@@ -32,7 +33,6 @@ from govoplan_dataflow.backend.subflows import substitute_parameters
|
||||
|
||||
EXECUTOR_VERSION = "dataflow-preview-v2"
|
||||
MAX_EXECUTION_SECONDS = 2.0
|
||||
MAX_RESULT_BYTES = 1_000_000
|
||||
MAX_SOURCE_ROWS = 250
|
||||
MAX_INTERMEDIATE_ROWS = 10_000
|
||||
|
||||
|
||||
@@ -12,6 +12,8 @@ import sqlglot
|
||||
from sqlglot import exp
|
||||
from sqlglot.errors import ParseError
|
||||
|
||||
from govoplan_dataflow.backend.preview_limits import MAX_RESULT_BYTES
|
||||
|
||||
|
||||
ExpressionDataType = Literal[
|
||||
"unknown",
|
||||
@@ -438,6 +440,14 @@ def _evaluate_pad(expression: exp.Expression, row: dict[str, Any]) -> str | None
|
||||
target_length = int(_evaluate(expression.expression, row))
|
||||
if target_length < 0:
|
||||
raise ValueError("Padding length cannot be negative.")
|
||||
# Every character takes at least one serialized byte. Enforce the existing
|
||||
# node budget before padding allocates memory, including when an outer
|
||||
# LENGTH/SUBSTRING would otherwise conceal the oversized intermediate value.
|
||||
# The node's final byte check still accounts for Unicode and JSON overhead.
|
||||
if target_length > MAX_RESULT_BYTES:
|
||||
raise ExpressionError(
|
||||
f"Padding length exceeds the {MAX_RESULT_BYTES:,}-byte preview result limit."
|
||||
)
|
||||
source = str(value)
|
||||
if len(source) >= target_length:
|
||||
return source[:target_length]
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from typing import Iterable
|
||||
|
||||
from govoplan_core.core.modules import DocumentationTopic, localize_documentation_topics as _localize_topics
|
||||
|
||||
|
||||
_TRANSLATIONS = {
|
||||
"dataflow.data-subject-requests": {
|
||||
"title": "Datenschutzanfragen zu Dataflow-Daten",
|
||||
"summary": "Gespeicherte Transformationsdetails minimieren, ohne abgeleitete Datenflüsse als führende Betroffenendaten zu behandeln.",
|
||||
"body": (
|
||||
"Dataflow gleicht exakte mandantenbezogene Pipeline-, Revisions-, Abgleich-, Lauf-, Bereitstellungs-, Trigger- und Zustellkennungen sowie minimierte Konto-, Identitäts- und Mitgliedschaftszuordnungen ab. Ergebnisse enthalten niemals Graphen, SQL, Anfrage- oder Ereignisinhalte, Abgleichkorrekturen, Autorisierungssnapshots, Provenienztexte, Fehler, Quelldetails, Hashwerte, Zugangsdaten oder Ausgabezeilen. Dataflow durchsucht beliebige Transformationsinhalte nicht nach Personen; das führende Eingabemodul muss Betroffenendaten auffinden und berichtigen. Eindeutig bestimmte abgeschlossene Lauf- und Zustelldetails können idempotent minimiert und personenbezogene Automatisierungsbefugnisse deaktiviert und widerrufen werden. Definitionen, Abgleichnachweise, aktive Arbeiten, Bereitstellungen, umfassende Pipeline-Pakete, veröffentlichte Datasource-Ausgaben und institutionelle Zuordnungen benötigen eine autorisierte Prüfung oder Aufbewahrung. Nach der Prüfung sind die Quellen zu berichtigen und Ableitungen in Datasources, Search und Reporting zu aktualisieren."
|
||||
),
|
||||
},
|
||||
"dataflow.module-boundary": {
|
||||
"title": "Modulgrenze von Dataflow",
|
||||
"summary": "Versionierte tabellarische Transformationen grafisch oder mit eingeschränktem SQL bearbeiten.",
|
||||
"body": (
|
||||
"Dataflow verantwortet kanonische Pipeline-Graphen, unveränderliche Revisionen, Validierung, eingeschränkte SQL-Kompilierung, Vorschau- und Laufdiagnosen sowie Herkunftsreferenzen. Datasources verantwortet den gesteuerten Katalog und Materialisierungen, Connectors den externen Abruf und Zugangsdaten, Reporting die analytische Darstellung und Exporte, Workflow die Orchestrierung und menschliche Übergaben und Risk Compliance die Sanktionsprüfung und Richtliniengrenzen. Benutzer-SQL wird in freigegebene Transformationen übersetzt und nie ungeprüft an eine Datenbank weitergereicht. "
|
||||
"Das Öffnen oder Neuladen von Dataflow startet keine Pipeline. Kann der Editor nach einer Entwicklungsaktualisierung nicht geladen werden, sichern Sie ungespeicherte Arbeit vor dem Neuladen des Browsers. Administratoren sollten Fehler beim Laden von Oberflächendateien von Fehlern der Pipeline-API oder Zugriffsfehlern unterscheiden. Entwicklungs- und Browser-Konformitätsserver verwenden getrennte Abhängigkeitscaches; ein älterer Server muss nach dieser Konfigurationsaktualisierung gegebenenfalls neu gestartet werden."
|
||||
),
|
||||
},
|
||||
"dataflow.reference.nodes-and-expressions": {
|
||||
"title": "Dataflow-Knoten und Ausdrücke",
|
||||
"summary": "Typisierte Knoteneingaben, Ausdrücke, Schemafortschreibung und begrenzte Zwischenergebnisse verstehen.",
|
||||
"body": (
|
||||
"Jeder Graphknoten definiert typisierte Eingaben, Konfiguration, Ausgabeschema und Validierungsregeln. Quellknoten binden Inline-Inhalte oder gesteuerte Datasource-Referenzen; Verknüpfungs-, Filter-, Transformations-, Qualitäts-, Abgleich-, Teilfluss- und Ausgabeknoten bleiben im kanonischen Graphen ausdrücklich sichtbar. Wiederverwendbare Teilflüsse wählen eine durch Policy erlaubte unveränderliche Fluss- oder Vorlagenrevision. Der Server löst Graph, Quell-Hash, Policy-Entscheidung und geschlossene Ein-/Ausgabeverträge auf und bindet sie; mitgelieferte Graphkopien werden ignoriert, unvereinbare Eingaben und zyklische Referenzen abgelehnt. Abgleichzeilen führen stabile Schlüssel- und Eingabe-Hashes sowie Vorher-/Nachher-Werte. Prüfentscheidungen werden als unveränderliche, mandanteneigene Entscheidungssätze gespeichert; geänderte Eingaben werden ungültig, ohne Fachdaten still umzuschreiben. Ausdrücke führen weder Host- noch Datenbankcode aus. Knoten-Vorschauen sind begrenzt, für die handelnde Person datenschutzgefiltert und werden nicht als Laufergebnis gespeichert. SQL wird in denselben Graphen kompiliert; nicht unterstützte Anweisungen erscheinen als Diagnose. "
|
||||
"Referenz-Vorschauen behalten die bestehende Grenze von 1.000.000 Byte je serialisiertem Knotenergebnis. "
|
||||
"LPAD und RPAD weisen Ziellängen über 1.000.000 Zeichen vor dem Reservieren des Auffüllspeichers zurück. "
|
||||
"Dies gilt auch für übergroße Zwischenergebnisse innerhalb von LENGTH oder SUBSTRING, selbst wenn der endgültige Einzelwert klein wäre. "
|
||||
"Verringern Sie die gewünschte Auffülllänge; der Ausdruck scheitert mit einer Diagnose am betreffenden Knoten, statt Daten abzuschneiden. "
|
||||
"Gewöhnliches Unicode-Auffüllen, NULL-Eingaben und Kürzungen innerhalb der Grenze behalten ihr Verhalten. "
|
||||
"Die abschließende Byteprüfung berücksichtigt weiterhin JSON- und Mehrbyte-Zeichenaufwand. "
|
||||
"Diese Speicherprüfung ersetzt keine Laufzeit- oder Bytegrenzen für andere Ausdrucksoperationen."
|
||||
),
|
||||
},
|
||||
"dataflow.reference.fields-and-consequences": {
|
||||
"title": "Dataflow-Felder und Lebenszyklusfolgen",
|
||||
"summary": "Bedeutung von Geltungsbereich, Revision, Wiederverwendung, Automatisierung, Ausführung, Veröffentlichung, Promotion und Löschung.",
|
||||
"body": (
|
||||
"Der Geltungsbereich bestimmt Eigentum und Policy-Vererbung. Vorlagen können abgeleitet, aber nicht ausgeführt werden; vollständige Flüsse dürfen bei wirksamer Policy geprüft, versioniert, automatisiert und ausgeführt werden. Speichern fügt eine unveränderliche Revision an. Eine bereichsbezogene Kopie bindet Quellrevision und Inhalts-Hash; eine neuere Quelle ändert sie nicht automatisch. Die geprüfte Übernahme benötigt den exakten Quell-Hash und eine Begründung, fügt eine Kopierevision an, protokolliert Policy-Entscheidung und prüfende Person und setzt die Kopie zur erneuten Aktivierung auf Entwurf. Trigger binden Revision und Autorisierungsnachweis und prüfen ihre Befugnis je Zustellung neu. „Läufe zulassen“ ist nur die Zulassungsgrenze der Definition und gewährt niemandem eine Berechtigung. Einmalige Läufe verwenden lokale Mandantenzeit; versäumte Intervalle werden je Richtlinie zu einem Lauf zusammengefasst oder übersprungen, niemals ungeprüft vollständig nachgeholt. Das Parallelitätslimit begrenzt aktive Zustellungen und erhöht keine Worker-Kapazität. Läufe erzeugen dauerhafte Befehls- und Recovery-Nachweise. Veröffentlichung erstellt eine gesteuerte Datasource-Materialisierung; Promotion wählt eine unveränderliche Revision für Staging oder Produktion aus. Abgleichentscheidungen werden mit optimistischer Nebenläufigkeit als neue Revision gespeichert und verändern die geprüfte Fachzeile nicht. Löschen verhindert künftige Nutzung, während Lauf-, Bereitstellungs-, Herkunfts-, Audit- und Recovery-Nachweise ihrer Aufbewahrung folgen."
|
||||
),
|
||||
},
|
||||
"dataflow.execution-and-recovery": {
|
||||
"title": "Dataflow ausführen, veröffentlichen und wiederherstellen",
|
||||
"summary": "Gebundene Läufe, Umgebungsfreigaben, Ausgabeveröffentlichung, Abbruch, Abgleich und Nachweise betreiben.",
|
||||
"body": (
|
||||
"Jeder Lauf ist an eine unveränderliche Revision und einen Idempotenzschlüssel gebunden. Die Warteschlange erfasst handelnde Person, Befugnis, Umgebung, Fortschritt, Abbruch, Ausgabe und Recovery-Zustand. Reine Datenbankläufe werden atomar gespeichert. Die Veröffentlichung in eine gesteuerte Datasource nutzt Vorwärts-Recovery: Ein unbekanntes Anbieterergebnis wird vor einer Wiederholung abgeglichen, damit keine Ausgabe doppelt entsteht. Staging- und Produktionsfreigaben sind ausdrücklich und schreiben keine Revision um. Das Einfrieren einer Veröffentlichung versieht exakt die unveränderliche Ausgabe mit einer dauerhaften Bezeichnung; Daten werden weder kopiert noch von Aufbewahrungs-, Hold- und Zugriffsregeln der Datasource getrennt. Artefaktbasierte und Inline-Ausgaben liefern dieselben stabilen Veröffentlichungs-, Datasource- und Materialisierungsreferenzen. Warnungen und prüfpflichtige Zustände bleiben für Workflow sichtbar. Ein Abbruch ist nach Beginn externer Arbeit nur bestmöglich; der Abschlussnachweis unterscheidet gestoppt, abgeschlossen, fehlgeschlagen und abgleichpflichtig. Vor Annahme eines geplanten, ereignisbasierten oder eingereihten Laufs wird die Modulberechtigung des Mandanten geprüft. Eine Deaktivierung stoppt neue Annahmen und überlässt bereits angenommene Läufe einer ausdrücklichen Betriebsentscheidung. Reporting darf nur einen erfolgreichen veröffentlichten Lauf binden; Dataflow prüft Befugnis und Datasource-Zugriff erneut und liest exakt die protokollierte Materialisierung ohne erneute Parametrisierung oder Ausführung."
|
||||
),
|
||||
},
|
||||
}
|
||||
|
||||
|
||||
def localize_documentation_topics(
|
||||
topics: Iterable[DocumentationTopic],
|
||||
) -> tuple[DocumentationTopic, ...]:
|
||||
return _localize_topics(topics, locale="de", translations=_TRANSLATIONS)
|
||||
@@ -0,0 +1,95 @@
|
||||
"""German translations for public structured documentation metadata."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from typing import Any
|
||||
|
||||
|
||||
GERMAN_STRUCTURED_TRANSLATIONS: dict[str, dict[str, Any]] = {'dataflow.execution-and-recovery': {'consequence_classes': {'cancel_run': 'Stornierung von '
|
||||
'Anfragen; bereits '
|
||||
'anerkannte externe '
|
||||
'Effekte können '
|
||||
'verbleiben.',
|
||||
'promote_revision': 'Macht eine '
|
||||
'unveränderliche '
|
||||
'Revision in '
|
||||
'einer höheren '
|
||||
'Ausführungsumgebung '
|
||||
'geeignet.',
|
||||
'publish_output': 'Erstellt oder '
|
||||
'aktualisiert eine '
|
||||
'geregelte '
|
||||
'Datenquelle und '
|
||||
'fügt eine '
|
||||
'Materialisierung '
|
||||
'hinzu.',
|
||||
'queue_run': 'Erstellt einen '
|
||||
'dauerhaften asynchronen '
|
||||
'Befehls- und '
|
||||
'Autorisierungsnachweis.'}},
|
||||
'dataflow.reference.fields-and-consequences': {'consequence_classes': {'configure_trigger': 'Erstellt '
|
||||
'oder '
|
||||
'ändert '
|
||||
'einen '
|
||||
'Automatisierungsbefehl '
|
||||
'mit '
|
||||
'Revisions- '
|
||||
'und '
|
||||
'Autorisierungsnachweisen.',
|
||||
'delete_pipeline': 'Verhindert '
|
||||
'die '
|
||||
'zukünftige '
|
||||
'Verwendung, '
|
||||
'während '
|
||||
'beibehaltene '
|
||||
'Nachweise '
|
||||
'geregelt '
|
||||
'bleiben.',
|
||||
'derive_copy': 'Erstellt '
|
||||
'eine '
|
||||
'separat '
|
||||
'verwaltete '
|
||||
'Kopie, die '
|
||||
'an die '
|
||||
'Quellrevision '
|
||||
'und den '
|
||||
'Hash '
|
||||
'gebunden '
|
||||
'ist.',
|
||||
'rebase_copy': 'Hängt die '
|
||||
'genaue '
|
||||
'überprüfte '
|
||||
'Quellrevision '
|
||||
'an eine '
|
||||
'Scope-Kopie '
|
||||
'an, '
|
||||
'zeichnet '
|
||||
'die '
|
||||
'Herkunft '
|
||||
'des '
|
||||
'Reviewers '
|
||||
'auf und '
|
||||
'gibt sie '
|
||||
'in den '
|
||||
'Entwurf '
|
||||
'zurück.',
|
||||
'record_decision': 'Fügt '
|
||||
'eine '
|
||||
'vom '
|
||||
'handelnde '
|
||||
'Person '
|
||||
'zugewiesene '
|
||||
'unveränderliche '
|
||||
'Entscheidungsrevision '
|
||||
'gegen '
|
||||
'einen '
|
||||
'genauen '
|
||||
'Eingabe-Hash '
|
||||
'an.',
|
||||
'save_revision': 'Fügt '
|
||||
'eine '
|
||||
'unveränderliche '
|
||||
'Überarbeitung '
|
||||
'der '
|
||||
'Pipelinedefinition '
|
||||
'an.'}}}
|
||||
@@ -121,6 +121,7 @@ def definition_governance_payload(
|
||||
*,
|
||||
principal: ApiPrincipal,
|
||||
registry: object | None,
|
||||
source_update: Mapping[str, object] | None = None,
|
||||
) -> dict[str, object]:
|
||||
actions = {
|
||||
action: definition_decision(
|
||||
@@ -142,6 +143,25 @@ def definition_governance_payload(
|
||||
"derived_from_pipeline_id": pipeline.derived_from_pipeline_id,
|
||||
"derived_from_revision": pipeline.derived_from_revision,
|
||||
"derived_from_hash": pipeline.derived_from_hash,
|
||||
"source_available": bool(
|
||||
source_update and source_update.get("source_available") is True
|
||||
),
|
||||
"source_name": (
|
||||
source_update.get("source_name") if source_update else None
|
||||
),
|
||||
"source_current_revision": (
|
||||
source_update.get("source_current_revision")
|
||||
if source_update
|
||||
else None
|
||||
),
|
||||
"source_current_hash": (
|
||||
source_update.get("source_current_hash")
|
||||
if source_update
|
||||
else None
|
||||
),
|
||||
"update_available": bool(
|
||||
source_update and source_update.get("update_available") is True
|
||||
),
|
||||
"derivation_provenance": dict(pipeline.derivation_provenance),
|
||||
"actions": actions,
|
||||
}
|
||||
|
||||
@@ -1,5 +1,8 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from govoplan_core.core.modules import with_documentation_structured_translations
|
||||
from govoplan_dataflow.backend.german_structured_documentation import GERMAN_STRUCTURED_TRANSLATIONS
|
||||
|
||||
from pathlib import Path
|
||||
|
||||
from govoplan_core.core.module_guards import (
|
||||
@@ -18,6 +21,7 @@ from govoplan_core.core.dataflows import (
|
||||
)
|
||||
from govoplan_core.core.modules import (
|
||||
CapabilityDocumentation,
|
||||
DocumentationCondition,
|
||||
DocumentationTopic,
|
||||
FrontendModule,
|
||||
FrontendRoute,
|
||||
@@ -52,11 +56,14 @@ from govoplan_dataflow.backend.dsar_provider import (
|
||||
DATAFLOW_DSAR_CAPABILITY,
|
||||
DataflowDsarProvider,
|
||||
)
|
||||
from govoplan_dataflow.backend.german_documentation import (
|
||||
localize_documentation_topics,
|
||||
)
|
||||
|
||||
|
||||
MODULE_ID = "dataflow"
|
||||
MODULE_NAME = "Dataflow"
|
||||
MODULE_VERSION = "0.1.19"
|
||||
MODULE_VERSION = "0.1.25"
|
||||
|
||||
READ_SCOPE = "dataflow:pipeline:read"
|
||||
WRITE_SCOPE = "dataflow:pipeline:write"
|
||||
@@ -146,7 +153,119 @@ ROLE_TEMPLATES = (
|
||||
),
|
||||
)
|
||||
|
||||
DOCUMENTATION = (
|
||||
DOCUMENTATION = localize_documentation_topics((
|
||||
DocumentationTopic(
|
||||
id="dataflow.csv-source-fidelity",
|
||||
title="Import CSV without silently changing its values",
|
||||
summary="Choose text preservation or explicit legacy inference before creating a durable datasource.",
|
||||
body=(
|
||||
"The CSV import dialog defaults to Preserve text (no automatic conversion). Field whitespace, decimal digits, large identifiers, boolean-looking text and explicit empty records remain strings. "
|
||||
"Choose Infer types (legacy) only when you want the existing numeric/boolean conversion and empty-row rules. JSON imports are unchanged. Existing API clients omitting csv_value_mode retain legacy_typed behavior. "
|
||||
"The imported datasource is a deliberate durable upload, not a retained preview. Datasources owns its original UTF-8 CSV text, parsed rows, approval evidence, immutable materialization and retention; Core verifies that original input and parsed scalar types/values agree. "
|
||||
"Both original and parsed content are bounded to 5 MB and the table to 10,000 rows. Original-source export is available through the Datasources administrator API only with unrestricted current and historical visibility, never through catalogue metadata. "
|
||||
"Missing older originals cannot be reconstructed. Exact text mode can change the inferred schema to strings; review downstream numeric comparisons and conversions before adopting the new source."
|
||||
),
|
||||
layer="always", documentation_types=("user", "admin"), audience=("user", "module_admin", "operator"), order=8,
|
||||
translations={"de": {
|
||||
"title": "CSV importieren, ohne Werte unbemerkt zu ändern",
|
||||
"summary": "Vor dem dauerhaften Import zwischen Texterhalt und ausdrücklicher bisheriger Typableitung wählen.",
|
||||
"body": (
|
||||
"Der CSV-Import wählt standardmäßig Text erhalten (keine automatische Umwandlung). Leerzeichen in Werten, Dezimalstellen, große Kennungen, boolesch wirkender Text und ausdrücklich leere Datensätze bleiben Zeichenketten. "
|
||||
"Wählen Sie Typen ableiten (bisheriges Verhalten), wenn Sie die bisherige Zahlen-/Wahrheitswertumwandlung und Behandlung leerer Zeilen benötigen. JSON-Importe bleiben unverändert; API-Aufrufe ohne csv_value_mode behalten legacy_typed. "
|
||||
"Der Import ist eine bewusst dauerhafte Datenquelle und keine gespeicherte Vorschau. Datasources verantwortet Originaltext als UTF-8, verarbeitete Zeilen, Freigabenachweis, unveränderliche Materialisierung und Aufbewahrung. Core prüft die Übereinstimmung von Quelltext sowie genauen Typen und Werten. "
|
||||
"Original und verarbeiteter Inhalt sind jeweils auf 5 MB, die Tabelle auf 10.000 Zeilen begrenzt. Das Original kann nur über die Datasources-Administrations-API mit uneingeschränkter aktueller und historischer Sichtbarkeit abgerufen werden, nicht über Katalogmetadaten. "
|
||||
"Fehlende ältere Originale lassen sich nicht rekonstruieren. Der Textmodus kann Spalten zu Zeichenketten machen; prüfen Sie deshalb nachgelagerte Zahlenvergleiche und Umwandlungen vor der Übernahme."
|
||||
),
|
||||
}},
|
||||
),
|
||||
DocumentationTopic(
|
||||
id="dataflow.save-completion",
|
||||
title="Editing while a pipeline save completes",
|
||||
summary="Keep newer local edits separate from the immutable revision accepted by the server.",
|
||||
body=(
|
||||
"You may continue editing a pipeline while Save is pending. The accepted server revision becomes the saved baseline; "
|
||||
"fields changed since submission remain in the local unsaved draft and require another explicit save. Graphs are kept as whole values, "
|
||||
"not merged or reordered node by node. Save-and-leave does not navigate while newer edits remain unsaved. "
|
||||
"A second save uses the revision actually accepted by the first request; duplicate concurrent save submissions are blocked. "
|
||||
"Selecting, replacing or discarding a draft, leaving the page, or changing authentication context prevents an old completion from replacing the current editor. "
|
||||
"Such a request may already have succeeded on the server: reload and review before retrying if the context changed. "
|
||||
"Ordinary session refreshes with the same identity, credentials and permissions keep accepted IDs and revisions; cosmetic profile changes do not interrupt saving. "
|
||||
"If a save was accepted across a real authorization change, further saves in that edit session are blocked until the draft is replaced after review, so a new pipeline is not created twice. "
|
||||
"Revision conflicts retain the local draft and require review; neither the UI nor administrators automatically overwrite a conflicting server revision. "
|
||||
"Current permissions and governance remain server-enforced. No preview rows are persisted by this editor behavior."
|
||||
),
|
||||
layer="always", documentation_types=("user", "admin"), audience=("user", "module_admin", "operator"), order=7,
|
||||
translations={"de": {
|
||||
"title": "Während des Speicherns einer Pipeline weiterarbeiten",
|
||||
"summary": "Neuere lokale Änderungen von der unveränderlichen, serverseitig angenommenen Revision trennen.",
|
||||
"body": (
|
||||
"Während Speichern läuft, können Sie die Pipeline weiter bearbeiten. Die angenommene Serverrevision wird zum gespeicherten Vergleichsstand; "
|
||||
"seit dem Absenden geänderte Felder bleiben im lokalen, ungespeicherten Entwurf und benötigen einen weiteren ausdrücklichen Speichervorgang. "
|
||||
"Graphen bleiben vollständige Werte und werden nicht knotenweise zusammengeführt oder umsortiert. Speichern und Verlassen navigiert nicht, solange neuere Änderungen ungespeichert sind. "
|
||||
"Ein zweiter Speichervorgang verwendet die tatsächlich angenommene Revision des ersten; doppelte gleichzeitige Speicheranfragen werden blockiert. "
|
||||
"Auswahl, Ersetzen oder Verwerfen eines Entwurfs, Verlassen der Seite oder ein geänderter Authentifizierungskontext verhindern, dass ein altes Ergebnis den aktuellen Editor ersetzt. "
|
||||
"Die Anfrage kann auf dem Server bereits erfolgreich gewesen sein: Nach einem Kontextwechsel vor einem erneuten Versuch neu laden und prüfen. "
|
||||
"Gewöhnliche Sitzungsaktualisierungen mit gleicher Identität, gleichen Zugangsdaten und Rechten behalten angenommene IDs und Revisionen; rein optische Profiländerungen unterbrechen das Speichern nicht. "
|
||||
"Wurde ein Speichervorgang während einer tatsächlichen Berechtigungsänderung angenommen, bleiben weitere Speicheranfragen dieser Bearbeitungssitzung bis zum geprüften Ersetzen des Entwurfs gesperrt, damit keine Pipeline doppelt entsteht. "
|
||||
"Bei Revisionskonflikten bleibt der lokale Entwurf erhalten und muss geprüft werden; weder Oberfläche noch Administratoren überschreiben automatisch eine widersprechende Serverrevision. "
|
||||
"Aktuelle Rechte und Governance werden weiterhin serverseitig geprüft. Dieses Editorverhalten speichert keine Vorschauzeilen dauerhaft."
|
||||
),
|
||||
}},
|
||||
),
|
||||
DocumentationTopic(
|
||||
id="dataflow.reference-worker-limits",
|
||||
title="Reference execution process limits",
|
||||
summary="Contain expensive expressions and intermediate allocations without changing datasource authority.",
|
||||
body=(
|
||||
"Reference previews and reference development runs evaluate in a fresh disposable process, including regex and aggregate intermediate allocations. "
|
||||
"The existing row, node and per-result byte checks remain. The process additionally enforces the request's wall-clock and memory budgets "
|
||||
"(default preview: 2 seconds and 256 MiB virtual address space), rounded-up CPU seconds, no regular-file output, and 32 MiB per data-only input/result transport. "
|
||||
"Supported process budgets are at most 600 seconds and 8 GiB; unsupported controls or exceeded limits fail with structured backend.process diagnostics, never inline fallback. "
|
||||
"Datasource authorization and bounded source reads remain in the parent, including nested subflow sources; sessions and credentials are not passed to the child. "
|
||||
"Reference source collection also checks a cumulative 32 MiB typed-data budget before constructing another columnar copy; providers retain their separate per-read limits. "
|
||||
"Completed node diagnostics survive ordinary evaluation errors; a killed worker returns no partial rows or invented node progress. "
|
||||
"GOVOPLAN_ISOLATED_PROCESS_CONCURRENCY limits shared isolated-work admission per API/worker process, default 1; busy capacity is retryable. "
|
||||
"It is not a fleet-wide quota or arbitrary-code sandbox. Cancellation checks before/after reference runs remain; hard wall limits stop an unresponsive expression. "
|
||||
"Staging/production still require the separate DuckDB backend and are not converted to reference execution."
|
||||
),
|
||||
layer="static", documentation_types=("user", "admin"), audience=("user", "module_admin", "operator"), order=6,
|
||||
translations={"de": {
|
||||
"title": "Prozessgrenzen der Referenzausführung",
|
||||
"summary": "Aufwendige Ausdrücke und Zwischenspeicher begrenzen, ohne Datenquellenrechte zu verändern.",
|
||||
"body": (
|
||||
"Referenz-Vorschauen und Referenz-Entwicklungsläufe werten Ausdrücke in einem frischen, kurzlebigen Prozess aus, einschließlich regulärer Ausdrücke und großer Zwischenergebnisse. "
|
||||
"Bestehende Zeilen-, Knoten- und Ergebnis-Bytegrenzen bleiben bestehen. Zusätzlich gelten das Laufzeit- und Speicherbudget der Anfrage "
|
||||
"(Vorschau standardmäßig 2 Sekunden und 256 MiB virtueller Adressraum), aufgerundete CPU-Sekunden, keine regulären Ausgabedateien und je 32 MiB für den reinen Datentransport. "
|
||||
"Prozessbudgets unterstützen höchstens 600 Sekunden und 8 GiB. Fehlende Betriebssystemkontrollen oder überschrittene Grenzen erzeugen strukturierte backend.process-Diagnosen, ohne Ausweichbetrieb im Hauptprozess. "
|
||||
"Datenquellenrechte und begrenzte Quellabrufe werden im Hauptprozess geprüft, auch für verschachtelte Teilflüsse; Sitzungen und Zugangsdaten gelangen nicht in den Kindprozess. "
|
||||
"Referenz-Quellabrufe prüfen außerdem zusammen höchstens 32 MiB typisierte Daten, bevor eine weitere spaltenweise Kopie entsteht; getrennte Abrufgrenzen der Anbieter bleiben bestehen. "
|
||||
"Gewöhnliche Auswertungsfehler behalten bereits abgeschlossene Knotendiagnosen. Ein gestoppter Prozess liefert keine Teilzeilen und keinen erfundenen Knotenfortschritt. "
|
||||
"GOVOPLAN_ISOLATED_PROCESS_CONCURRENCY begrenzt gemeinsam genutzte isolierte Arbeit je API-/Worker-Prozess, standardmäßig 1; bei Auslastung ist ein erneuter Versuch möglich. "
|
||||
"Dies ist weder eine systemweite Quote noch eine Sandbox für beliebigen Code. Abbruchprüfungen vor und nach Referenzläufen bleiben erhalten; harte Laufzeitgrenzen stoppen hängende Ausdrücke. "
|
||||
"Staging und Produktion benötigen weiterhin das gesonderte DuckDB-Backend und wechseln nicht zur Referenzausführung."
|
||||
),
|
||||
}},
|
||||
),
|
||||
DocumentationTopic(
|
||||
id="dataflow.workspace-layout",
|
||||
title="Dataflow workspace actions",
|
||||
summary="Find collection-wide commands in their consistent workspace position.",
|
||||
body="The workspace documentation book sits beside Pipelines; automation and run help sits beside "
|
||||
"the corresponding dialog title, and field help stays with its label. "
|
||||
"Reload and New pipeline use the persistent full-width workspace header at the upper right; Reload sits immediately before creation. Selecting a record, changing filters, or opening an editor does not move these collection-wide commands into the left pane. SQL editing, validation, previews, saving, and execution keep their existing editor scope and bounded safety rules. Existing permissions, disabled-state rules, and unsaved-change guards still apply. Administrators configure authority through the existing permission system; no new permission or automatic operation is introduced.",
|
||||
layer="static",
|
||||
documentation_types=("user", "admin"),
|
||||
audience=("user", "module_admin", "operator"),
|
||||
order=5,
|
||||
translations={"de": {
|
||||
"title": "Datenflüsse: Aktionen im Arbeitsbereich",
|
||||
"summary": "Sammlungsweite Aktionen an ihrer einheitlichen Position im Arbeitsbereich finden.",
|
||||
"body": "Das Dokumentationsbuch des Arbeitsbereichs steht neben Pipelines; Hilfe zu Automatisierung "
|
||||
"und Ausführung steht neben dem jeweiligen Dialogtitel, und Feldhilfe bleibt bei der "
|
||||
"Feldbezeichnung. "
|
||||
"Neu laden und Neue Pipeline stehen oben rechts in der dauerhaft sichtbaren, arbeitsbereichsweiten Leiste; Neu laden steht unmittelbar vor dem Anlegen. Auswahl, Filterwechsel und Bearbeitung verschieben diese sammlungsweiten Aktionen nicht in den linken Bereich. SQL-Bearbeitung, Validierung, Vorschau, Speichern und Ausführung behalten ihren bisherigen Editorbereich und ihre begrenzenden Sicherheitsregeln. Bestehende Berechtigungen, Deaktivierungsregeln und der Schutz ungespeicherter Änderungen gelten weiterhin. Administratoren konfigurieren Rechte im bestehenden Berechtigungssystem; es entstehen weder neue Rechte noch automatische Vorgänge.",
|
||||
}},
|
||||
),
|
||||
DocumentationTopic(
|
||||
id="dataflow.data-subject-requests",
|
||||
title="Dataflow data-subject requests",
|
||||
@@ -179,7 +298,12 @@ DOCUMENTATION = (
|
||||
"and credentials; Reporting owns analytical presentation and exports; "
|
||||
"Workflow owns orchestration and human handoffs; Risk Compliance owns sanctions review "
|
||||
"semantics and policy gates. User SQL is compiled into approved transforms and is never "
|
||||
"passed unchecked to a backing database."
|
||||
"passed unchecked to a backing database. Opening or reloading Dataflow does not "
|
||||
"start a pipeline. If the editor cannot be loaded after a development update, "
|
||||
"preserve unsaved work before reloading the browser. Administrators should "
|
||||
"distinguish frontend asset failures from pipeline API or access errors. "
|
||||
"Development and browser-conformance servers use separate dependency caches; "
|
||||
"an older server may need restarting after this configuration update."
|
||||
),
|
||||
layer="available",
|
||||
documentation_types=("admin", "user"),
|
||||
@@ -197,6 +321,19 @@ DOCUMENTATION = (
|
||||
"audit",
|
||||
),
|
||||
metadata={
|
||||
"kind": "workflow",
|
||||
"route": "/dataflow",
|
||||
"screen": "Dataflow",
|
||||
"prerequisites": [
|
||||
"You may read Dataflow pipeline definitions in the active tenant.",
|
||||
],
|
||||
"steps": [
|
||||
"Open Dataflow and select a pipeline or create an authorized draft.",
|
||||
"Inspect the graph, immutable revision, diagnostics, and declared source references.",
|
||||
"Use preview or run actions only when the effective permissions and Policy allow them.",
|
||||
],
|
||||
"outcome": "The pipeline remains a governed transformation definition with explicit module boundaries and source authority.",
|
||||
"verification": "Confirm the active revision, validation diagnostics, source references, and permitted actions in the Dataflow workspace.",
|
||||
"first_slice": (
|
||||
"Inline and governed datasources, union, join, filter, deduplication, select, "
|
||||
"typed expressions, conversion, quality and reconciliation, reusable subflows, "
|
||||
@@ -218,6 +355,27 @@ DOCUMENTATION = (
|
||||
"dataflow.state.read-only",
|
||||
],
|
||||
},
|
||||
conditions=(
|
||||
DocumentationCondition(
|
||||
required_modules=("dataflow",),
|
||||
required_scopes=(READ_SCOPE,),
|
||||
),
|
||||
),
|
||||
structured_translation_version="1",
|
||||
structured_translations={
|
||||
"de": {
|
||||
"prerequisites": [
|
||||
"Sie dürfen Dataflow-Pipeline-Definitionen im aktiven Mandanten lesen.",
|
||||
],
|
||||
"steps": [
|
||||
"Öffnen Sie Dataflow und wählen Sie eine Pipeline oder legen Sie einen autorisierten Entwurf an.",
|
||||
"Prüfen Sie Graph, unveränderliche Revision, Diagnosen und ausgewiesene Quellreferenzen.",
|
||||
"Verwenden Sie Vorschau- oder Laufaktionen nur, wenn wirksame Berechtigungen und Policy sie erlauben.",
|
||||
],
|
||||
"outcome": "Die Pipeline bleibt eine gesteuerte Transformationsdefinition mit ausdrücklichen Modulgrenzen und Quellenautorität.",
|
||||
"verification": "Prüfen Sie aktive Revision, Validierungsdiagnosen, Quellreferenzen und erlaubte Aktionen im Dataflow-Arbeitsbereich.",
|
||||
}
|
||||
},
|
||||
),
|
||||
DocumentationTopic(
|
||||
id="dataflow.reference.nodes-and-expressions",
|
||||
@@ -227,6 +385,9 @@ DOCUMENTATION = (
|
||||
"Every graph node declares typed inputs, configuration, output schema, and validation rules. "
|
||||
"Source nodes pin inline content or governed Datasource references; combine, filter, transform, "
|
||||
"quality, reconciliation, reusable-subflow, and output nodes remain explicit in the canonical graph. "
|
||||
"Reusable subflows select a Policy-authorized immutable flow or template revision. The server resolves "
|
||||
"and pins its graph, source hash, Policy decision, and closed typed input/output contracts; caller-supplied "
|
||||
"graph snapshots are ignored, incompatible inputs fail validation, and nested reference cycles are rejected. "
|
||||
"Reconciliation rows expose stable key hashes, explicit before/after values, and input hashes. The "
|
||||
"review dialog records accept, reject, correct, or defer decisions in tenant-owned immutable decision "
|
||||
"sets. Their current projection is a fingerprinted Dataflow source; every superseded revision retains "
|
||||
@@ -236,7 +397,14 @@ DOCUMENTATION = (
|
||||
"Expressions use the typed Dataflow expression language and never execute arbitrary host or database "
|
||||
"code. Selecting a node may request a bounded intermediate preview; preview rows are transient, "
|
||||
"privacy-filtered for the actor, and are not retained as run output. SQL editing compiles into the same "
|
||||
"canonical graph, so unsupported statements are diagnostics rather than pass-through SQL."
|
||||
"canonical graph, so unsupported statements are diagnostics rather than pass-through SQL. "
|
||||
"Reference previews retain the existing 1,000,000-byte serialized result limit per node. "
|
||||
"LPAD and RPAD reject target lengths above 1,000,000 characters before allocating padding, "
|
||||
"including oversized intermediate values inside LENGTH or SUBSTRING even if the final scalar would be small. "
|
||||
"Reduce the requested padding length; this fails the expression at its node instead of truncating data. "
|
||||
"Ordinary Unicode padding, null inputs, and in-budget truncation keep their existing behavior; "
|
||||
"the final byte check still accounts for JSON and multibyte character overhead. "
|
||||
"This allocation guard does not replace runtime or byte limits for other expression operations."
|
||||
),
|
||||
layer="available",
|
||||
documentation_types=("admin", "user"),
|
||||
@@ -244,11 +412,15 @@ DOCUMENTATION = (
|
||||
order=76,
|
||||
related_modules=("datasources", "connectors", "policy", "audit"),
|
||||
metadata={
|
||||
"kind": "reference",
|
||||
"help_contexts": [
|
||||
"dataflow.field.node-name",
|
||||
"dataflow.field.source",
|
||||
"dataflow.field.expression",
|
||||
"dataflow.field.schema",
|
||||
"dataflow.field.reusable-input-binding",
|
||||
"dataflow.field.subflow-reference",
|
||||
"dataflow.field.subflow-revision",
|
||||
"dataflow.action.preview-node",
|
||||
"dataflow.action.review-decisions",
|
||||
],
|
||||
@@ -261,7 +433,10 @@ DOCUMENTATION = (
|
||||
body=(
|
||||
"Scope determines ownership and Policy inheritance. Templates can be derived but not run; complete "
|
||||
"flows may be previewed, revisioned, automated, and executed when effective Policy allows it. Saving "
|
||||
"appends an immutable revision. A scoped copy pins its source revision and content hash. Triggers pin "
|
||||
"appends an immutable revision. A scoped copy pins its source revision and content hash. A newer "
|
||||
"source revision is reported without changing the copy. Adopting it requires an exact reviewed source "
|
||||
"hash and a reason, appends an immutable copy revision, records the Policy decision and reviewer, and "
|
||||
"returns the copy to draft so runs and automation cannot use the changed graph before activation. Triggers pin "
|
||||
"the revision and authorization grant, then re-evaluate authority for every delivery. Allow runs is "
|
||||
"the definition-level admission boundary and does not grant a caller permission. A one-time run uses "
|
||||
"the configured tenant-local date and time. The missed-run policy either coalesces elapsed interval "
|
||||
@@ -287,6 +462,7 @@ DOCUMENTATION = (
|
||||
"audit",
|
||||
),
|
||||
metadata={
|
||||
"kind": "reference",
|
||||
"help_contexts": [
|
||||
"dataflow.field.scope",
|
||||
"dataflow.field.definition-kind",
|
||||
@@ -294,8 +470,10 @@ DOCUMENTATION = (
|
||||
"dataflow.field.trigger-run-at",
|
||||
"dataflow.field.trigger-missed-runs",
|
||||
"dataflow.field.trigger-concurrency",
|
||||
"dataflow.field.rebase-reason",
|
||||
"dataflow.action.save",
|
||||
"dataflow.action.derive",
|
||||
"dataflow.action.rebase",
|
||||
"dataflow.action.trigger",
|
||||
"dataflow.action.record-decision",
|
||||
"dataflow.action.delete",
|
||||
@@ -303,6 +481,7 @@ DOCUMENTATION = (
|
||||
"consequence_classes": {
|
||||
"save_revision": "Appends an immutable pipeline definition revision.",
|
||||
"derive_copy": "Creates a separately governed copy pinned to the source revision and hash.",
|
||||
"rebase_copy": "Appends the exact reviewed source revision to a scoped copy, records reviewer provenance, and returns it to draft.",
|
||||
"configure_trigger": "Creates or changes an automation command with revision and authorization evidence.",
|
||||
"record_decision": "Appends an actor-attributed immutable decision revision against an exact input hash.",
|
||||
"delete_pipeline": "Prevents future use while retained evidence remains governed.",
|
||||
@@ -351,7 +530,7 @@ DOCUMENTATION = (
|
||||
},
|
||||
},
|
||||
),
|
||||
)
|
||||
))
|
||||
|
||||
|
||||
def _dataflow_router(context: ModuleContext):
|
||||
@@ -747,6 +926,11 @@ manifest = ModuleManifest(
|
||||
)
|
||||
|
||||
|
||||
manifest = with_documentation_structured_translations(
|
||||
manifest, locale="de", translations=GERMAN_STRUCTURED_TRANSLATIONS
|
||||
)
|
||||
|
||||
|
||||
def get_manifest() -> ModuleManifest:
|
||||
return manifest
|
||||
|
||||
|
||||
@@ -613,14 +613,13 @@ _NODE_TYPES = (
|
||||
type="subflow",
|
||||
category="transform",
|
||||
label="Reusable subflow",
|
||||
description="Run a pinned parameterized template snapshot as one node.",
|
||||
description="Run a Policy-authorized, server-resolved immutable definition revision as one node.",
|
||||
icon="boxes",
|
||||
input_ports=(NodePortDefinition(id="input", label="Input"),),
|
||||
config_fields=(
|
||||
NodeConfigField(id="template_ref", label="Template reference", kind="text", required=True),
|
||||
NodeConfigField(id="template_version", label="Template version", kind="text", required=True),
|
||||
NodeConfigField(id="parameters", label="Parameters", kind="json", required=True),
|
||||
NodeConfigField(id="graph", label="Pinned graph", kind="json", required=True),
|
||||
),
|
||||
default_config={
|
||||
"template_ref": "",
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
"""Shared existing limits for reference-preview results and allocating expressions."""
|
||||
|
||||
MAX_RESULT_BYTES = 1_000_000
|
||||
@@ -32,6 +32,8 @@ from govoplan_core.core.references import (
|
||||
validate_access_scope_reference,
|
||||
)
|
||||
from govoplan_core.core.tabular_sources import (
|
||||
TabularCsvSource,
|
||||
TabularSourceError,
|
||||
parse_tabular_csv,
|
||||
)
|
||||
from govoplan_core.db.session import get_session
|
||||
@@ -68,6 +70,7 @@ from govoplan_dataflow.backend.schemas import (
|
||||
PipelineRunMetricsResponse,
|
||||
PipelineRunResponse,
|
||||
PipelinePromotionRequest,
|
||||
PipelineRebaseRequest,
|
||||
PipelineResponse,
|
||||
PipelineSqlResponse,
|
||||
PipelineUpdateRequest,
|
||||
@@ -109,6 +112,7 @@ from govoplan_dataflow.backend.service import (
|
||||
pipeline_run_response,
|
||||
preview_pipeline,
|
||||
promote_pipeline,
|
||||
rebase_pipeline,
|
||||
render_graph_sql,
|
||||
start_pipeline_run,
|
||||
update_pipeline,
|
||||
@@ -430,6 +434,7 @@ def api_create_source_snapshot(
|
||||
payload.csv_text or "",
|
||||
delimiter=payload.delimiter,
|
||||
max_rows=10_000,
|
||||
value_mode=payload.csv_value_mode,
|
||||
)
|
||||
if payload.format == "csv"
|
||||
else tuple(payload.rows or ())
|
||||
@@ -446,6 +451,11 @@ def api_create_source_snapshot(
|
||||
shape="tabular",
|
||||
rows=rows,
|
||||
provider="dataflow.upload",
|
||||
csv_source=(TabularCsvSource(
|
||||
text=payload.csv_text or "",
|
||||
delimiter=payload.delimiter,
|
||||
value_mode=payload.csv_value_mode,
|
||||
) if payload.format == "csv" else None),
|
||||
provenance={
|
||||
"created_via": "dataflow",
|
||||
"source_format": payload.format,
|
||||
@@ -460,6 +470,8 @@ def api_create_source_snapshot(
|
||||
principal,
|
||||
stage_ref=stage.ref,
|
||||
)
|
||||
except TabularSourceError as exc:
|
||||
raise HTTPException(status_code=status.HTTP_422_UNPROCESSABLE_CONTENT, detail=str(exc)) from exc
|
||||
except DatasourceError as exc:
|
||||
raise _source_http_error(exc) from exc
|
||||
audit_event(
|
||||
@@ -544,6 +556,8 @@ def api_create_pipeline(
|
||||
tenant_id=tenant_id or principal.tenant_id,
|
||||
actor_id=_actor_id(principal),
|
||||
payload=payload,
|
||||
principal=principal,
|
||||
registry=get_registry(),
|
||||
)
|
||||
except (PermissionError, ValueError) as exc:
|
||||
raise _governance_http_error(exc) from exc
|
||||
@@ -842,6 +856,8 @@ def api_update_pipeline(
|
||||
pipeline_id=pipeline_id,
|
||||
actor_id=_actor_id(principal),
|
||||
payload=payload,
|
||||
principal=principal,
|
||||
registry=get_registry(),
|
||||
)
|
||||
except (PermissionError, ValueError) as exc:
|
||||
raise _governance_http_error(exc) from exc
|
||||
@@ -968,6 +984,64 @@ def api_derive_pipeline(
|
||||
return response
|
||||
|
||||
|
||||
@router.post(
|
||||
"/pipelines/{pipeline_id}/rebase",
|
||||
response_model=PipelineResponse,
|
||||
)
|
||||
def api_rebase_pipeline(
|
||||
pipeline_id: str,
|
||||
payload: PipelineRebaseRequest,
|
||||
session: Session = Depends(get_session),
|
||||
principal: ApiPrincipal = Depends(get_api_principal),
|
||||
) -> PipelineResponse:
|
||||
_require_any_scope(principal, WRITE_SCOPE, ADMIN_SCOPE)
|
||||
try:
|
||||
existing = get_pipeline(
|
||||
session,
|
||||
tenant_id=principal.tenant_id,
|
||||
pipeline_id=pipeline_id,
|
||||
)
|
||||
require_definition_action(
|
||||
existing,
|
||||
principal=principal,
|
||||
registry=get_registry(),
|
||||
action="edit",
|
||||
)
|
||||
pipeline = rebase_pipeline(
|
||||
session,
|
||||
tenant_id=principal.tenant_id,
|
||||
pipeline_id=pipeline_id,
|
||||
actor_id=_actor_id(principal),
|
||||
principal=principal,
|
||||
registry=get_registry(),
|
||||
payload=payload,
|
||||
)
|
||||
except PermissionError as exc:
|
||||
raise _governance_http_error(exc) from exc
|
||||
except DataflowError as exc:
|
||||
raise _http_error(exc) from exc
|
||||
audit_event(
|
||||
session,
|
||||
tenant_id=principal.tenant_id,
|
||||
user_id=getattr(principal.user, "id", None),
|
||||
api_key_id=principal.api_key_id,
|
||||
action="dataflow.pipeline.rebased",
|
||||
object_type="dataflow_pipeline",
|
||||
object_id=pipeline.id,
|
||||
details={
|
||||
"child_revision": pipeline.current_revision,
|
||||
"source_pipeline_id": pipeline.derived_from_pipeline_id,
|
||||
"source_revision": pipeline.derived_from_revision,
|
||||
"source_hash": pipeline.derived_from_hash,
|
||||
"status": pipeline.status,
|
||||
"reason": payload.reason.strip(),
|
||||
},
|
||||
)
|
||||
response = _pipeline_response(session, pipeline, principal)
|
||||
session.commit()
|
||||
return response
|
||||
|
||||
|
||||
@router.get(
|
||||
"/pipelines/{pipeline_id}/triggers",
|
||||
response_model=DataflowTriggerListResponse,
|
||||
@@ -1503,10 +1577,22 @@ def api_promote_pipeline(
|
||||
@router.post("/validate", response_model=PipelineValidationResponse)
|
||||
def api_validate_pipeline(
|
||||
payload: PipelineDraftRequest,
|
||||
session: Session = Depends(get_session),
|
||||
principal: ApiPrincipal = Depends(get_api_principal),
|
||||
) -> PipelineValidationResponse:
|
||||
_require_any_scope(principal, READ_SCOPE, WRITE_SCOPE, RUN_SCOPE, ADMIN_SCOPE)
|
||||
return validate_draft(payload)
|
||||
try:
|
||||
return validate_draft(
|
||||
payload,
|
||||
session=session,
|
||||
tenant_id=principal.tenant_id,
|
||||
principal=principal,
|
||||
registry=get_registry(),
|
||||
)
|
||||
except PermissionError as exc:
|
||||
raise _governance_http_error(exc) from exc
|
||||
except DataflowError as exc:
|
||||
raise _http_error(exc) from exc
|
||||
|
||||
|
||||
@router.post("/sql/compile", response_model=PipelineSqlResponse)
|
||||
@@ -1543,6 +1629,8 @@ def api_preview_pipeline(
|
||||
registry=get_registry(),
|
||||
payload=payload,
|
||||
)
|
||||
except PermissionError as exc:
|
||||
raise _governance_http_error(exc) from exc
|
||||
except DataflowError as exc:
|
||||
raise _http_error(exc) from exc
|
||||
if response.pipeline_id:
|
||||
|
||||
@@ -129,7 +129,14 @@ def _propagation_context(
|
||||
def _inline_source(
|
||||
context: SchemaPropagationContext,
|
||||
) -> SchemaPropagationResult:
|
||||
return SchemaPropagationResult(_inline_schema(context.node.config.get("rows")))
|
||||
configured = _configured_schema(
|
||||
context.node.config.get("contract_schema")
|
||||
)
|
||||
return SchemaPropagationResult(
|
||||
configured
|
||||
if configured.columns
|
||||
else _inline_schema(context.node.config.get("rows"))
|
||||
)
|
||||
|
||||
|
||||
def _reference_source(
|
||||
@@ -724,16 +731,57 @@ def _comparison_columns(value: object) -> tuple[list[str], list[str]]:
|
||||
|
||||
|
||||
def _subflow(context: SchemaPropagationContext) -> SchemaPropagationResult:
|
||||
input_schema = _configured_schema(
|
||||
context.node.config.get("input_schema")
|
||||
)
|
||||
output_schema = _configured_schema(
|
||||
context.node.config.get("output_schema")
|
||||
)
|
||||
diagnostics: list[DataflowDiagnostic] = []
|
||||
if input_schema.columns and not context.input_state.open:
|
||||
missing = sorted(input_schema.columns - context.input_state.columns)
|
||||
if missing:
|
||||
diagnostics.append(
|
||||
_error(
|
||||
"subflow.input_contract.missing",
|
||||
"Subflow input is missing required contract columns: "
|
||||
+ ", ".join(missing),
|
||||
node_id=context.node.id,
|
||||
field="input_schema",
|
||||
)
|
||||
)
|
||||
incompatible = sorted(
|
||||
column
|
||||
for column in input_schema.columns & context.input_state.columns
|
||||
if not _compatible_contract_type(
|
||||
context.input_state.type_of(column),
|
||||
input_schema.type_of(column),
|
||||
)
|
||||
)
|
||||
if incompatible:
|
||||
diagnostics.append(
|
||||
_error(
|
||||
"subflow.input_contract.type",
|
||||
"Subflow input has incompatible contract types for: "
|
||||
+ ", ".join(incompatible),
|
||||
node_id=context.node.id,
|
||||
field="input_schema",
|
||||
)
|
||||
)
|
||||
return SchemaPropagationResult(
|
||||
output_schema
|
||||
if output_schema.columns
|
||||
else unknown_schema()
|
||||
else unknown_schema(),
|
||||
tuple(diagnostics),
|
||||
)
|
||||
|
||||
|
||||
def _compatible_contract_type(actual: str, expected: str) -> bool:
|
||||
if "unknown" in {actual, expected} or actual == expected:
|
||||
return True
|
||||
return {actual, expected} <= {"integer", "number"}
|
||||
|
||||
|
||||
def _identity(context: SchemaPropagationContext) -> SchemaPropagationResult:
|
||||
return SchemaPropagationResult(context.input_state)
|
||||
|
||||
|
||||
@@ -122,6 +122,11 @@ class PipelineGovernanceResponse(BaseModel):
|
||||
derived_from_pipeline_id: str | None
|
||||
derived_from_revision: int | None
|
||||
derived_from_hash: str | None
|
||||
source_available: bool = False
|
||||
source_name: str | None = None
|
||||
source_current_revision: int | None = None
|
||||
source_current_hash: str | None = None
|
||||
update_available: bool = False
|
||||
derivation_provenance: dict[str, Any] = Field(default_factory=dict)
|
||||
actions: dict[str, DefinitionActionDecisionResponse]
|
||||
|
||||
@@ -246,7 +251,23 @@ class PipelineDeriveRequest(BaseModel):
|
||||
allow_automation: bool = False
|
||||
|
||||
|
||||
class PipelineRebaseRequest(BaseModel):
|
||||
expected_revision: int = Field(ge=1)
|
||||
source_revision: int = Field(ge=1)
|
||||
source_hash: str = Field(pattern=r"^[0-9a-f]{64}$")
|
||||
reason: str = Field(min_length=3, max_length=4_000)
|
||||
|
||||
@field_validator("reason")
|
||||
@classmethod
|
||||
def validate_reason(cls, value: str) -> str:
|
||||
cleaned = value.strip()
|
||||
if len(cleaned) < 3:
|
||||
raise ValueError("A meaningful rebase review reason is required.")
|
||||
return cleaned
|
||||
|
||||
|
||||
class PipelineDraftRequest(BaseModel):
|
||||
pipeline_id: str | None = Field(default=None, max_length=36)
|
||||
graph: PipelineGraph | None = None
|
||||
sql_text: str | None = Field(default=None, max_length=100_000)
|
||||
source_nodes: list[GraphNode] = Field(default_factory=list, max_length=20)
|
||||
@@ -716,6 +737,7 @@ class TabularSnapshotCreateRequest(BaseModel):
|
||||
format: Literal["json", "csv"] = "json"
|
||||
rows: list[dict[str, Any]] | None = Field(default=None, max_length=10_000)
|
||||
csv_text: str | None = Field(default=None, max_length=5_000_000)
|
||||
csv_value_mode: Literal["legacy_typed", "text"] = "legacy_typed"
|
||||
delimiter: str = Field(default=",", min_length=1, max_length=1)
|
||||
|
||||
@model_validator(mode="after")
|
||||
|
||||
@@ -28,6 +28,7 @@ from govoplan_core.core.datasources import (
|
||||
datasource_publication,
|
||||
)
|
||||
from govoplan_core.db.base import utcnow
|
||||
from govoplan_core.security.worker_payload import WorkerPayloadError, encode_worker_payload
|
||||
from govoplan_dataflow.backend.backends import (
|
||||
BackendExecutionError,
|
||||
BackendSource,
|
||||
@@ -35,6 +36,7 @@ from govoplan_dataflow.backend.backends import (
|
||||
execute_typed_graph,
|
||||
)
|
||||
from govoplan_dataflow.backend.batches import TypedBatch
|
||||
from govoplan_dataflow.backend.backends.reference import reference_source_key
|
||||
from govoplan_dataflow.backend.db.models import (
|
||||
DataflowPipeline,
|
||||
DataflowPipelineDeployment,
|
||||
@@ -48,7 +50,6 @@ from govoplan_dataflow.backend.executor import (
|
||||
PipelineExecutionError,
|
||||
PipelineExecutionResult,
|
||||
ResolvedSource,
|
||||
execute_preview,
|
||||
)
|
||||
from govoplan_dataflow.backend.governance import (
|
||||
definition_governance_payload,
|
||||
@@ -60,6 +61,7 @@ from govoplan_dataflow.backend.graph import (
|
||||
preserve_compatible_graph_layout,
|
||||
validate_graph,
|
||||
)
|
||||
from govoplan_dataflow.backend.ir import graph_to_ir
|
||||
from govoplan_dataflow.backend.schemas import (
|
||||
DataflowDiagnostic,
|
||||
GraphNode,
|
||||
@@ -72,6 +74,7 @@ from govoplan_dataflow.backend.schemas import (
|
||||
PipelinePreviewResponse,
|
||||
PipelineDeploymentResponse,
|
||||
PipelinePromotionRequest,
|
||||
PipelineRebaseRequest,
|
||||
PipelineResponse,
|
||||
PipelineRevisionResponse,
|
||||
PipelineRunResponse,
|
||||
@@ -187,15 +190,177 @@ def get_pipeline_revision(
|
||||
return item
|
||||
|
||||
|
||||
def _resolve_reusable_subflows(
|
||||
session: Session,
|
||||
*,
|
||||
tenant_id: str,
|
||||
graph: PipelineGraph,
|
||||
principal: ApiPrincipal | None,
|
||||
registry: object | None,
|
||||
target_pipeline_id: str | None,
|
||||
ancestry: tuple[str, ...] = (),
|
||||
) -> PipelineGraph:
|
||||
if not any(node.type == "subflow" for node in graph.nodes):
|
||||
return graph
|
||||
if principal is None:
|
||||
raise DataflowConflictError(
|
||||
"Reusable subflows require a tenant principal and current Policy "
|
||||
"decision."
|
||||
)
|
||||
resolved_nodes: list[GraphNode] = []
|
||||
for node in graph.nodes:
|
||||
if node.type != "subflow":
|
||||
resolved_nodes.append(node)
|
||||
continue
|
||||
source_id = _pipeline_id_from_ref(node.config.get("template_ref"))
|
||||
if source_id == target_pipeline_id:
|
||||
raise DataflowConflictError(
|
||||
"A pipeline cannot reference itself as a reusable subflow."
|
||||
)
|
||||
source = get_pipeline(
|
||||
session,
|
||||
tenant_id=tenant_id,
|
||||
pipeline_id=source_id,
|
||||
)
|
||||
reuse_decision = require_definition_action(
|
||||
source,
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
action="reuse",
|
||||
)
|
||||
source_revision_number = _subflow_revision(
|
||||
node.config.get("template_version")
|
||||
)
|
||||
source_revision = get_pipeline_revision(
|
||||
session,
|
||||
pipeline=source,
|
||||
revision=source_revision_number,
|
||||
)
|
||||
reference_key = f"{source.id}:{source_revision.revision}"
|
||||
if reference_key in ancestry:
|
||||
raise DataflowConflictError(
|
||||
"Reusable subflow references contain a cycle at "
|
||||
f"pipeline:{source.id} revision {source_revision.revision}."
|
||||
)
|
||||
nested = _resolve_reusable_subflows(
|
||||
session,
|
||||
tenant_id=tenant_id,
|
||||
graph=PipelineGraph.model_validate(source_revision.graph),
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
target_pipeline_id=target_pipeline_id,
|
||||
ancestry=(*ancestry, reference_key),
|
||||
)
|
||||
input_nodes = [
|
||||
item
|
||||
for item in nested.nodes
|
||||
if item.type == "source.inline"
|
||||
and item.config.get("input_binding") is True
|
||||
]
|
||||
if len(input_nodes) != 1:
|
||||
raise DataflowConflictError(
|
||||
"A referenced reusable definition must declare exactly one "
|
||||
"inline template input binding."
|
||||
)
|
||||
typed = graph_to_ir(nested)
|
||||
typed_by_id = {item.id: item for item in typed.nodes}
|
||||
output_nodes = [item for item in nested.nodes if item.type == "output"]
|
||||
if len(output_nodes) != 1:
|
||||
raise DataflowConflictError(
|
||||
"A referenced reusable definition must have exactly one "
|
||||
"typed output."
|
||||
)
|
||||
input_contract = _typed_contract(
|
||||
typed_by_id[input_nodes[0].id].output_schema,
|
||||
label="input",
|
||||
)
|
||||
output_contract = _typed_contract(
|
||||
typed_by_id[output_nodes[0].id].output_schema,
|
||||
label="output",
|
||||
)
|
||||
config = {
|
||||
**node.config,
|
||||
"template_ref": f"pipeline:{source.id}",
|
||||
"template_version": str(source_revision.revision),
|
||||
"template_hash": source_revision.content_hash,
|
||||
"graph": canonical_graph_payload(nested),
|
||||
"input_schema": input_contract,
|
||||
"output_schema": output_contract,
|
||||
"reference_provenance": {
|
||||
"source_scope": {
|
||||
"scope_type": source.scope_type,
|
||||
"scope_id": source.scope_id,
|
||||
},
|
||||
"source_definition_kind": source.definition_kind,
|
||||
"policy_decision": reuse_decision.to_dict(),
|
||||
},
|
||||
}
|
||||
resolved_nodes.append(
|
||||
node.model_copy(update={"config": config}, deep=True)
|
||||
)
|
||||
return graph.model_copy(update={"nodes": resolved_nodes}, deep=True)
|
||||
|
||||
|
||||
def _pipeline_id_from_ref(value: object) -> str:
|
||||
text = str(value or "").strip()
|
||||
if not text.startswith("pipeline:") or len(text) <= len("pipeline:"):
|
||||
raise DataflowConflictError(
|
||||
"Reusable subflows require a canonical pipeline reference."
|
||||
)
|
||||
return text.removeprefix("pipeline:")
|
||||
|
||||
|
||||
def _subflow_revision(value: object) -> int:
|
||||
try:
|
||||
revision = int(str(value).strip())
|
||||
except (TypeError, ValueError) as exc:
|
||||
raise DataflowConflictError(
|
||||
"Reusable subflows require a valid immutable source revision."
|
||||
) from exc
|
||||
if revision < 1:
|
||||
raise DataflowConflictError(
|
||||
"Reusable subflow revisions must be positive."
|
||||
)
|
||||
return revision
|
||||
|
||||
|
||||
def _typed_contract(schema: object, *, label: str) -> list[dict[str, object]]:
|
||||
fields = tuple(getattr(schema, "fields", ()))
|
||||
if not fields or any(getattr(item, "type", "unknown") == "unknown" for item in fields):
|
||||
raise DataflowConflictError(
|
||||
f"The reusable definition needs a closed typed {label} contract. "
|
||||
"Provide representative typed rows at its template input."
|
||||
)
|
||||
return [
|
||||
{
|
||||
"name": str(item.name),
|
||||
"type": str(item.type),
|
||||
"nullable": bool(item.nullable),
|
||||
}
|
||||
for item in fields
|
||||
]
|
||||
|
||||
|
||||
def create_pipeline(
|
||||
session: Session,
|
||||
*,
|
||||
tenant_id: str,
|
||||
actor_id: str | None,
|
||||
payload: PipelineCreateRequest,
|
||||
principal: ApiPrincipal | None = None,
|
||||
registry: object | None = None,
|
||||
) -> DataflowPipeline:
|
||||
definition = normalize_definition(
|
||||
pipeline_id = new_uuid()
|
||||
graph = _resolve_reusable_subflows(
|
||||
session,
|
||||
tenant_id=tenant_id,
|
||||
graph=payload.graph,
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
target_pipeline_id=pipeline_id,
|
||||
)
|
||||
definition = normalize_definition(
|
||||
graph=graph,
|
||||
sql_text=payload.sql_text,
|
||||
editor_mode=payload.editor_mode,
|
||||
)
|
||||
@@ -209,6 +374,7 @@ def create_pipeline(
|
||||
else payload.scope_id
|
||||
)
|
||||
pipeline = DataflowPipeline(
|
||||
id=pipeline_id,
|
||||
tenant_id=stored_tenant_id,
|
||||
scope_type=payload.scope_type,
|
||||
scope_id=scope_id,
|
||||
@@ -248,6 +414,8 @@ def update_pipeline(
|
||||
pipeline_id: str,
|
||||
actor_id: str | None,
|
||||
payload: PipelineUpdateRequest,
|
||||
principal: ApiPrincipal | None = None,
|
||||
registry: object | None = None,
|
||||
) -> DataflowPipeline:
|
||||
pipeline = get_pipeline(session, tenant_id=tenant_id, pipeline_id=pipeline_id)
|
||||
if payload.expected_revision != pipeline.current_revision:
|
||||
@@ -270,8 +438,16 @@ def update_pipeline(
|
||||
raise DataflowConflictError(
|
||||
"Definition kind is immutable; derive a flow or template instead."
|
||||
)
|
||||
definition = normalize_definition(
|
||||
graph = _resolve_reusable_subflows(
|
||||
session,
|
||||
tenant_id=tenant_id,
|
||||
graph=payload.graph,
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
target_pipeline_id=pipeline.id,
|
||||
)
|
||||
definition = normalize_definition(
|
||||
graph=graph,
|
||||
sql_text=payload.sql_text,
|
||||
editor_mode=payload.editor_mode,
|
||||
)
|
||||
@@ -417,6 +593,195 @@ def derive_pipeline(
|
||||
return pipeline
|
||||
|
||||
|
||||
def pipeline_source_update_status(
|
||||
session: Session,
|
||||
*,
|
||||
tenant_id: str,
|
||||
pipeline: DataflowPipeline,
|
||||
) -> dict[str, object]:
|
||||
source_id = pipeline.derived_from_pipeline_id
|
||||
if not source_id:
|
||||
return {
|
||||
"source_available": False,
|
||||
"source_name": None,
|
||||
"source_current_revision": None,
|
||||
"source_current_hash": None,
|
||||
"update_available": False,
|
||||
}
|
||||
source = session.scalar(
|
||||
select(DataflowPipeline).where(
|
||||
DataflowPipeline.id == source_id,
|
||||
or_(
|
||||
DataflowPipeline.tenant_id == tenant_id,
|
||||
DataflowPipeline.tenant_id.is_(None),
|
||||
),
|
||||
DataflowPipeline.deleted_at.is_(None),
|
||||
)
|
||||
)
|
||||
if source is None:
|
||||
return {
|
||||
"source_available": False,
|
||||
"source_name": None,
|
||||
"source_current_revision": None,
|
||||
"source_current_hash": None,
|
||||
"update_available": False,
|
||||
}
|
||||
revision = get_pipeline_revision(session, pipeline=source)
|
||||
return {
|
||||
"source_available": True,
|
||||
"source_name": source.name,
|
||||
"source_current_revision": revision.revision,
|
||||
"source_current_hash": revision.content_hash,
|
||||
"update_available": (
|
||||
revision.revision != pipeline.derived_from_revision
|
||||
or revision.content_hash != pipeline.derived_from_hash
|
||||
),
|
||||
}
|
||||
|
||||
|
||||
def rebase_pipeline(
|
||||
session: Session,
|
||||
*,
|
||||
tenant_id: str,
|
||||
pipeline_id: str,
|
||||
actor_id: str | None,
|
||||
principal: ApiPrincipal,
|
||||
registry: object | None,
|
||||
payload: PipelineRebaseRequest,
|
||||
) -> DataflowPipeline:
|
||||
pipeline = get_pipeline(
|
||||
session,
|
||||
tenant_id=tenant_id,
|
||||
pipeline_id=pipeline_id,
|
||||
)
|
||||
if payload.expected_revision != pipeline.current_revision:
|
||||
raise DataflowConflictError(
|
||||
"Derived pipeline changed on the server; expected revision "
|
||||
f"{payload.expected_revision}, current revision is "
|
||||
f"{pipeline.current_revision}."
|
||||
)
|
||||
source_id = pipeline.derived_from_pipeline_id
|
||||
if not source_id:
|
||||
raise DataflowConflictError(
|
||||
"Only a pipeline derived from another definition can adopt a "
|
||||
"source update."
|
||||
)
|
||||
source = get_pipeline(
|
||||
session,
|
||||
tenant_id=tenant_id,
|
||||
pipeline_id=source_id,
|
||||
)
|
||||
reuse_decision = require_definition_action(
|
||||
source,
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
action="derive",
|
||||
)
|
||||
source_revision = get_pipeline_revision(
|
||||
session,
|
||||
pipeline=source,
|
||||
revision=payload.source_revision,
|
||||
)
|
||||
if source_revision.content_hash != payload.source_hash:
|
||||
raise DataflowConflictError(
|
||||
"The reviewed source hash no longer matches the requested "
|
||||
"revision; reload before adopting the update."
|
||||
)
|
||||
if (
|
||||
pipeline.derived_from_revision is not None
|
||||
and source_revision.revision <= pipeline.derived_from_revision
|
||||
):
|
||||
raise DataflowConflictError(
|
||||
"A source update must use a revision newer than the currently "
|
||||
"pinned revision."
|
||||
)
|
||||
|
||||
previous_child_revision = pipeline.current_revision
|
||||
previous_child = get_pipeline_revision(session, pipeline=pipeline)
|
||||
previous_source_revision = pipeline.derived_from_revision
|
||||
previous_source_hash = pipeline.derived_from_hash
|
||||
source_limits = _effective_governance_limits(
|
||||
source,
|
||||
decision_details=reuse_decision.details,
|
||||
)
|
||||
effective_limits = {
|
||||
"inherit_to_lower_scopes": (
|
||||
pipeline.inherit_to_lower_scopes
|
||||
and source_limits["inherit_to_lower_scopes"]
|
||||
),
|
||||
"allow_run": pipeline.allow_run and source_limits["allow_run"],
|
||||
"allow_reuse": pipeline.allow_reuse and source_limits["allow_reuse"],
|
||||
"allow_automation": (
|
||||
pipeline.allow_automation and source_limits["allow_automation"]
|
||||
),
|
||||
}
|
||||
next_child_revision = previous_child_revision + 1
|
||||
rebased_at = utcnow()
|
||||
history_value = pipeline.derivation_provenance.get("rebase_history", [])
|
||||
history = list(history_value) if isinstance(history_value, list) else []
|
||||
history.append(
|
||||
{
|
||||
"child_revision_before": previous_child_revision,
|
||||
"child_hash_before": previous_child.content_hash,
|
||||
"child_revision_after": next_child_revision,
|
||||
"source_revision_before": previous_source_revision,
|
||||
"source_hash_before": previous_source_hash,
|
||||
"source_revision_after": source_revision.revision,
|
||||
"source_hash_after": source_revision.content_hash,
|
||||
"policy_decision": reuse_decision.to_dict(),
|
||||
"reason": payload.reason.strip(),
|
||||
"rebased_by": actor_id,
|
||||
"rebased_at": rebased_at.isoformat(),
|
||||
}
|
||||
)
|
||||
provenance = dict(pipeline.derivation_provenance)
|
||||
provenance.update(
|
||||
{
|
||||
"source_ref": f"pipeline:{source.id}",
|
||||
"source_scope": {
|
||||
"scope_type": source.scope_type,
|
||||
"scope_id": source.scope_id,
|
||||
},
|
||||
"source_definition_kind": source.definition_kind,
|
||||
"source_revision": source_revision.revision,
|
||||
"source_hash": source_revision.content_hash,
|
||||
"source_effective_limits": effective_limits,
|
||||
"policy_decision": reuse_decision.to_dict(),
|
||||
"last_rebased_by": actor_id,
|
||||
"last_rebased_at": rebased_at.isoformat(),
|
||||
"last_rebase_reason": payload.reason.strip(),
|
||||
"rebase_history": history,
|
||||
}
|
||||
)
|
||||
|
||||
pipeline.current_revision = next_child_revision
|
||||
pipeline.status = "draft"
|
||||
pipeline.inherit_to_lower_scopes = effective_limits[
|
||||
"inherit_to_lower_scopes"
|
||||
]
|
||||
pipeline.allow_run = effective_limits["allow_run"]
|
||||
pipeline.allow_reuse = effective_limits["allow_reuse"]
|
||||
pipeline.allow_automation = effective_limits["allow_automation"]
|
||||
pipeline.derived_from_revision = source_revision.revision
|
||||
pipeline.derived_from_hash = source_revision.content_hash
|
||||
pipeline.derivation_provenance = provenance
|
||||
pipeline.updated_by = actor_id
|
||||
pipeline.revisions.append(
|
||||
DataflowPipelineRevision(
|
||||
tenant_id=pipeline.tenant_id,
|
||||
revision=next_child_revision,
|
||||
schema_version=source_revision.schema_version,
|
||||
graph=json.loads(json.dumps(source_revision.graph)),
|
||||
sql_text=source_revision.sql_text,
|
||||
editor_mode=source_revision.editor_mode,
|
||||
content_hash=source_revision.content_hash,
|
||||
created_by=actor_id,
|
||||
)
|
||||
)
|
||||
session.flush()
|
||||
return pipeline
|
||||
|
||||
|
||||
def delete_pipeline(
|
||||
session: Session,
|
||||
*,
|
||||
@@ -455,11 +820,36 @@ def pipeline_response(
|
||||
pipeline,
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
source_update=pipeline_source_update_status(
|
||||
session,
|
||||
tenant_id=principal.tenant_id,
|
||||
pipeline=pipeline,
|
||||
),
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
def validate_draft(payload: PipelineDraftRequest) -> PipelineValidationResponse:
|
||||
def validate_draft(
|
||||
payload: PipelineDraftRequest,
|
||||
*,
|
||||
session: Session | None = None,
|
||||
tenant_id: str | None = None,
|
||||
principal: ApiPrincipal | None = None,
|
||||
registry: object | None = None,
|
||||
) -> PipelineValidationResponse:
|
||||
if payload.graph is not None and session is not None and tenant_id is not None:
|
||||
payload = payload.model_copy(
|
||||
update={
|
||||
"graph": _resolve_reusable_subflows(
|
||||
session,
|
||||
tenant_id=tenant_id,
|
||||
graph=payload.graph,
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
target_pipeline_id=payload.pipeline_id,
|
||||
)
|
||||
}
|
||||
)
|
||||
if payload.sql_text and payload.sql_text.strip():
|
||||
try:
|
||||
graph, sql_text, diagnostics = compile_sql(
|
||||
@@ -598,7 +988,13 @@ def preview_pipeline(
|
||||
sql_text=payload.sql_text,
|
||||
source_nodes=payload.source_nodes,
|
||||
)
|
||||
validated = validate_draft(draft)
|
||||
validated = validate_draft(
|
||||
draft,
|
||||
session=session,
|
||||
tenant_id=tenant_id,
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
)
|
||||
if not validated.valid or validated.graph is None:
|
||||
return PipelinePreviewResponse(
|
||||
run_id=None,
|
||||
@@ -727,20 +1123,11 @@ def _execute_pipeline_preview(
|
||||
principal=principal,
|
||||
registry=registry,
|
||||
)
|
||||
if backend == "reference":
|
||||
return (
|
||||
execute_preview(
|
||||
graph,
|
||||
row_limit=row_limit,
|
||||
source_resolver=source_resolver,
|
||||
preview_node_id=preview_node_id,
|
||||
),
|
||||
EXECUTOR_VERSION,
|
||||
)
|
||||
sources = _typed_backend_sources(
|
||||
graph,
|
||||
source_resolver=source_resolver,
|
||||
source_limit=max(MAX_SOURCE_ROWS, row_limit),
|
||||
source_limit=MAX_SOURCE_ROWS if backend == "reference" else max(MAX_SOURCE_ROWS, row_limit),
|
||||
include_subflows=backend == "reference",
|
||||
)
|
||||
try:
|
||||
result = execute_typed_graph(
|
||||
@@ -754,8 +1141,14 @@ def _execute_pipeline_preview(
|
||||
raise PipelineExecutionError(
|
||||
str(exc),
|
||||
node_id=exc.node_id,
|
||||
diagnostics=tuple(exc.diagnostics),
|
||||
retryable=exc.code == "backend.capacity",
|
||||
diagnostics=(*exc.diagnostics, DataflowDiagnostic(
|
||||
severity="error", code=exc.code, message=str(exc), node_id=exc.node_id,
|
||||
)),
|
||||
node_diagnostics=exc.node_diagnostics,
|
||||
source_fingerprints=exc.source_fingerprints,
|
||||
input_row_count=exc.input_row_count,
|
||||
node_preview=exc.node_preview,
|
||||
retryable=exc.code in {"backend.capacity", "backend.process.busy"},
|
||||
) from exc
|
||||
columns = [
|
||||
PreviewColumn(
|
||||
@@ -832,13 +1225,51 @@ def _typed_backend_sources(
|
||||
*,
|
||||
source_resolver,
|
||||
source_limit: int = MAX_SOURCE_ROWS,
|
||||
include_subflows: bool = False,
|
||||
_depth: int = 0,
|
||||
_remaining_source_bytes: list[int] | None = None,
|
||||
) -> dict[str, BackendSource]:
|
||||
if _depth > 5:
|
||||
raise PipelineExecutionError("Subflows are limited to five nested levels.")
|
||||
if _remaining_source_bytes is None:
|
||||
_remaining_source_bytes = [32 * 1024 * 1024]
|
||||
sources: dict[str, BackendSource] = {}
|
||||
for node in graph.nodes:
|
||||
if include_subflows and node.type == "subflow":
|
||||
from govoplan_dataflow.backend.subflows import substitute_parameters
|
||||
|
||||
parameters = node.config.get("parameters")
|
||||
nested = PipelineGraph.model_validate(substitute_parameters(
|
||||
node.config.get("graph"), parameters if isinstance(parameters, dict) else {},
|
||||
))
|
||||
sources.update(_typed_backend_sources(
|
||||
nested, source_resolver=source_resolver, source_limit=source_limit,
|
||||
include_subflows=True, _depth=_depth + 1,
|
||||
_remaining_source_bytes=_remaining_source_bytes,
|
||||
))
|
||||
if node.type != "source.reference":
|
||||
continue
|
||||
if include_subflows and _remaining_source_bytes[0] <= 0:
|
||||
raise PipelineExecutionError(
|
||||
"Combined source data exceeds the 32 MiB transfer budget.", node_id=node.id,
|
||||
)
|
||||
resolved = source_resolver(node, source_limit)
|
||||
sources[node.id] = BackendSource(
|
||||
if include_subflows:
|
||||
try:
|
||||
# Check before constructing another columnar copy. The provider
|
||||
# still owns bounds on its individual authorized read; do not keep
|
||||
# accumulating individually valid batches before the worker gate.
|
||||
encoded_size = len(encode_worker_payload(
|
||||
tuple(dict(row) for row in resolved.rows), max_bytes=_remaining_source_bytes[0],
|
||||
))
|
||||
except WorkerPayloadError as exc:
|
||||
raise PipelineExecutionError(
|
||||
"Combined source data exceeds the 32 MiB transfer budget or contains unsupported values.",
|
||||
node_id=node.id,
|
||||
) from exc
|
||||
_remaining_source_bytes[0] -= encoded_size
|
||||
key = reference_source_key(node) if include_subflows else node.id
|
||||
sources[key] = BackendSource(
|
||||
node_id=node.id,
|
||||
batch=TypedBatch.from_rows(resolved.rows),
|
||||
source_ref=resolved.source_ref,
|
||||
@@ -2290,11 +2721,13 @@ __all__ = [
|
||||
"list_pipelines",
|
||||
"normalize_definition",
|
||||
"pipeline_response",
|
||||
"pipeline_source_update_status",
|
||||
"pipeline_deployment_response",
|
||||
"pipeline_run_descriptor",
|
||||
"pipeline_run_request",
|
||||
"pipeline_run_response",
|
||||
"promote_pipeline",
|
||||
"rebase_pipeline",
|
||||
"preview_pipeline",
|
||||
"render_graph_sql",
|
||||
"start_pipeline_run",
|
||||
|
||||
Executable
+121
@@ -0,0 +1,121 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from types import SimpleNamespace
|
||||
import unittest
|
||||
from unittest.mock import Mock, patch
|
||||
|
||||
from fastapi import HTTPException
|
||||
from pydantic import ValidationError
|
||||
|
||||
from govoplan_core.auth import ApiPrincipal
|
||||
from govoplan_core.core.access import PrincipalRef
|
||||
from govoplan_dataflow.backend.router import WRITE_SCOPE, api_create_source_snapshot
|
||||
from govoplan_dataflow.backend.schemas import TabularSnapshotCreateRequest
|
||||
|
||||
|
||||
class CsvStagingRouteTests(unittest.TestCase):
|
||||
def setUp(self) -> None:
|
||||
self.principal = ApiPrincipal(
|
||||
principal=PrincipalRef(
|
||||
account_id="account",
|
||||
membership_id="membership",
|
||||
tenant_id="tenant",
|
||||
scopes=frozenset({WRITE_SCOPE}),
|
||||
),
|
||||
user=object(),
|
||||
account=object(),
|
||||
)
|
||||
self.session = Mock()
|
||||
self.writer = Mock()
|
||||
self.writer.create_stage.return_value = SimpleNamespace(ref="stage:one")
|
||||
self.writer.promote_stage.return_value = (
|
||||
SimpleNamespace(
|
||||
ref="datasource:one",
|
||||
provider="dataflow.upload",
|
||||
source_name="upload",
|
||||
row_count=1,
|
||||
fingerprint="f" * 64,
|
||||
),
|
||||
SimpleNamespace(ref="materialization:one"),
|
||||
)
|
||||
for name, options in (
|
||||
("get_registry", {"return_value": object()}),
|
||||
("datasource_lifecycle", {"return_value": self.writer}),
|
||||
("audit_event", {}),
|
||||
("_source_response", {"side_effect": lambda value: value}),
|
||||
):
|
||||
active = patch(f"govoplan_dataflow.backend.router.{name}", **options)
|
||||
active.start()
|
||||
self.addCleanup(active.stop)
|
||||
|
||||
def test_csv_stage_receives_exact_original_and_selected_parser_mode(self) -> None:
|
||||
text = 'value\r\n" 001 "\r\n'
|
||||
for mode, expected in (("text", " 001 "), ("legacy_typed", "001")):
|
||||
with self.subTest(mode=mode):
|
||||
api_create_source_snapshot(
|
||||
TabularSnapshotCreateRequest(
|
||||
name="Upload",
|
||||
source_name="upload",
|
||||
format="csv",
|
||||
csv_text=text,
|
||||
csv_value_mode=mode,
|
||||
),
|
||||
session=self.session,
|
||||
principal=self.principal,
|
||||
)
|
||||
stage = self.writer.create_stage.call_args.kwargs["stage"]
|
||||
self.assertEqual(({"value": expected},), stage.rows)
|
||||
self.assertEqual(text, stage.csv_source.text)
|
||||
self.assertEqual(mode, stage.csv_source.value_mode)
|
||||
self.assertEqual("core.csv.v1", stage.csv_source.parser_profile)
|
||||
self.assertNotIn("text", stage.metadata)
|
||||
self.assertEqual(2, self.writer.promote_stage.call_count)
|
||||
self.assertEqual(2, self.session.commit.call_count)
|
||||
|
||||
def test_json_stage_does_not_invent_csv_evidence(self) -> None:
|
||||
api_create_source_snapshot(
|
||||
TabularSnapshotCreateRequest(
|
||||
name="Upload", source_name="upload", rows=[{"value": "001"}]
|
||||
),
|
||||
session=self.session,
|
||||
principal=self.principal,
|
||||
)
|
||||
stage = self.writer.create_stage.call_args.kwargs["stage"]
|
||||
self.assertIsNone(stage.csv_source)
|
||||
self.assertEqual(({"value": "001"},), stage.rows)
|
||||
|
||||
def test_malformed_text_csv_is_422_before_any_durable_write(self) -> None:
|
||||
with self.assertRaises(HTTPException) as raised:
|
||||
api_create_source_snapshot(
|
||||
TabularSnapshotCreateRequest(
|
||||
name="Upload",
|
||||
source_name="upload",
|
||||
format="csv",
|
||||
csv_text="a,b\nonly-one\n",
|
||||
csv_value_mode="text",
|
||||
),
|
||||
session=self.session,
|
||||
principal=self.principal,
|
||||
)
|
||||
self.assertEqual(422, raised.exception.status_code)
|
||||
self.writer.create_stage.assert_not_called()
|
||||
self.writer.promote_stage.assert_not_called()
|
||||
self.session.commit.assert_not_called()
|
||||
|
||||
def test_invalid_unicode_is_rejected_by_request_schema_before_any_durable_write(
|
||||
self,
|
||||
) -> None:
|
||||
with self.assertRaises(ValidationError):
|
||||
api_create_source_snapshot(
|
||||
TabularSnapshotCreateRequest(
|
||||
name="Upload",
|
||||
source_name="upload",
|
||||
format="csv",
|
||||
csv_text="value\nprivate-\ud800\n",
|
||||
),
|
||||
session=self.session,
|
||||
principal=self.principal,
|
||||
)
|
||||
self.writer.create_stage.assert_not_called()
|
||||
self.writer.promote_stage.assert_not_called()
|
||||
self.session.commit.assert_not_called()
|
||||
@@ -0,0 +1,19 @@
|
||||
from govoplan_dataflow.backend.manifest import get_manifest
|
||||
|
||||
|
||||
def test_static_documentation_has_complete_german_reference_copy() -> None:
|
||||
for topic in get_manifest().documentation:
|
||||
german = topic.translations.get("de", {})
|
||||
assert all(german.get(field, "").strip() for field in ("title", "summary", "body")), topic.id
|
||||
|
||||
|
||||
def test_documentation_exposes_conditioned_workflow_and_reference() -> None:
|
||||
topics = {topic.id: topic for topic in get_manifest().documentation}
|
||||
workflow = topics["dataflow.module-boundary"]
|
||||
assert workflow.metadata.get("kind") == "workflow"
|
||||
assert any(condition.required_scopes for condition in workflow.conditions)
|
||||
assert workflow.structured_translations.get("de")
|
||||
|
||||
reference = topics["dataflow.reference.fields-and-consequences"]
|
||||
assert reference.metadata.get("kind") == "reference"
|
||||
assert reference.metadata.get("consequence_classes")
|
||||
@@ -67,12 +67,13 @@ class DataflowInterfaceDocumentationContractTests(unittest.TestCase):
|
||||
|
||||
for component in (
|
||||
"ActionBlockerHint",
|
||||
"DocumentationHelpLink",
|
||||
"titleHelp={<DocumentationHelpLink reference={DATAFLOW_DOCUMENTATION} />}",
|
||||
"useUnsavedDraftGuard",
|
||||
"ConfirmDialog",
|
||||
):
|
||||
self.assertIn(component, page)
|
||||
self.assertIn("DATAFLOW_NODE_DOCUMENTATION", inspector)
|
||||
self.assertNotIn("helpAction=", page)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
|
||||
@@ -0,0 +1,165 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import unittest
|
||||
|
||||
from govoplan_dataflow.backend.executor import (
|
||||
MAX_RESULT_BYTES,
|
||||
PipelineExecutionError,
|
||||
execute_preview,
|
||||
)
|
||||
from govoplan_dataflow.backend.expressions import ExpressionError, evaluate_expression
|
||||
from govoplan_dataflow.backend.manifest import get_manifest
|
||||
from govoplan_dataflow.backend.schemas import (
|
||||
GraphEdge,
|
||||
GraphNode,
|
||||
GraphPosition,
|
||||
PipelineGraph,
|
||||
)
|
||||
|
||||
|
||||
class _UnreadableFill:
|
||||
def __str__(self) -> str:
|
||||
raise AssertionError(
|
||||
"Oversized padding must be rejected before reading or multiplying its fill."
|
||||
)
|
||||
|
||||
|
||||
def _expression_graph(expression: str, *, result_type: str = "string") -> PipelineGraph:
|
||||
return PipelineGraph(
|
||||
nodes=[
|
||||
GraphNode(
|
||||
id="source",
|
||||
type="source.inline",
|
||||
label="Source",
|
||||
position=GraphPosition(x=0, y=0),
|
||||
config={"source_name": "fixture", "rows": [{"value": "x"}]},
|
||||
),
|
||||
GraphNode(
|
||||
id="padding",
|
||||
type="expression",
|
||||
label="Padding",
|
||||
position=GraphPosition(x=200, y=0),
|
||||
config={
|
||||
"target_column": "padded",
|
||||
"expression": expression,
|
||||
"result_type": result_type,
|
||||
},
|
||||
),
|
||||
GraphNode(
|
||||
id="output",
|
||||
type="output",
|
||||
label="Output",
|
||||
position=GraphPosition(x=400, y=0),
|
||||
config={},
|
||||
),
|
||||
],
|
||||
edges=[
|
||||
GraphEdge(id="source-padding", source="source", target="padding"),
|
||||
GraphEdge(id="padding-output", source="padding", target="output"),
|
||||
],
|
||||
)
|
||||
|
||||
|
||||
class PaddingBudgetTests(unittest.TestCase):
|
||||
def test_oversized_padding_is_rejected_before_fill_evaluation_or_allocation(
|
||||
self,
|
||||
) -> None:
|
||||
for operation in ("lpad", "rpad"):
|
||||
for length in (MAX_RESULT_BYTES + 1, 10**100):
|
||||
with self.subTest(operation=operation, length=length):
|
||||
with self.assertRaisesRegex(
|
||||
ExpressionError, "Padding length.*1,000,000"
|
||||
):
|
||||
evaluate_expression(
|
||||
f"{operation}('x', {length}, fill)",
|
||||
{"fill": _UnreadableFill()},
|
||||
)
|
||||
|
||||
def test_budget_cannot_be_bypassed_by_hiding_large_padding_in_a_small_scalar(
|
||||
self,
|
||||
) -> None:
|
||||
for wrapper in ("length({})", "substring({}, 1, 1)"):
|
||||
with self.subTest(wrapper=wrapper):
|
||||
expression = wrapper.format(f"lpad('x', {MAX_RESULT_BYTES + 1}, fill)")
|
||||
with self.assertRaises(ExpressionError):
|
||||
evaluate_expression(expression, {"fill": _UnreadableFill()})
|
||||
|
||||
def test_existing_boundary_and_ordinary_padding_are_preserved(self) -> None:
|
||||
self.assertEqual(1_000_000, MAX_RESULT_BYTES)
|
||||
for operation in ("lpad", "rpad"):
|
||||
with self.subTest(operation=operation):
|
||||
value = evaluate_expression(
|
||||
f"{operation}('x', {MAX_RESULT_BYTES}, '0')", {}
|
||||
)
|
||||
self.assertEqual(MAX_RESULT_BYTES, len(value))
|
||||
self.assertEqual(1, value.count("x"))
|
||||
self.assertEqual(
|
||||
"abc", evaluate_expression(f"{operation}('abcdef', 3, '')", {})
|
||||
)
|
||||
self.assertEqual(
|
||||
"", evaluate_expression(f"{operation}('abcdef', 0, '')", {})
|
||||
)
|
||||
self.assertEqual(
|
||||
"abc", evaluate_expression(f"{operation}('abc', 3, '')", {})
|
||||
)
|
||||
|
||||
def test_null_negative_and_empty_fill_semantics_are_unchanged(self) -> None:
|
||||
for operation in ("lpad", "rpad"):
|
||||
with self.subTest(operation=operation):
|
||||
self.assertIsNone(
|
||||
evaluate_expression(f"{operation}(NULL, {10**100}, '')", {})
|
||||
)
|
||||
self.assertIsNone(evaluate_expression(f"{operation}(NULL, -1, '')", {}))
|
||||
with self.assertRaisesRegex(ValueError, "cannot be negative"):
|
||||
evaluate_expression(f"{operation}('x', -1, '0')", {})
|
||||
with self.assertRaisesRegex(ValueError, "fill text cannot be empty"):
|
||||
evaluate_expression(f"{operation}('x', 2, '')", {})
|
||||
|
||||
def test_multibyte_fill_and_truncation_preserve_character_semantics(self) -> None:
|
||||
self.assertEqual("ö🙂öÄ", evaluate_expression("lpad('Ä', 4, 'ö🙂')", {}))
|
||||
self.assertEqual("Äö🙂ö", evaluate_expression("rpad('Ä', 4, 'ö🙂')", {}))
|
||||
self.assertEqual("🙂ä", evaluate_expression("lpad('🙂ä中', 2, '0')", {}))
|
||||
result = execute_preview(
|
||||
_expression_graph("rpad(value, 4, 'ö🙂')"), row_limit=10
|
||||
)
|
||||
self.assertEqual("xö🙂ö", result.rows[0]["padded"])
|
||||
|
||||
def test_preview_reports_padding_guard_at_owning_node_and_retains_final_byte_limit(
|
||||
self,
|
||||
) -> None:
|
||||
with self.assertRaisesRegex(PipelineExecutionError, "Padding length") as raised:
|
||||
execute_preview(
|
||||
_expression_graph(
|
||||
f"length(lpad(value, {MAX_RESULT_BYTES + 1}, '0'))",
|
||||
result_type="integer",
|
||||
),
|
||||
row_limit=10,
|
||||
)
|
||||
self.assertEqual("padding", raised.exception.node_id)
|
||||
# Non-ASCII characters need several serialized bytes. The preallocation
|
||||
# character bound supplements, and never replaces, the node byte bound.
|
||||
with self.assertRaisesRegex(
|
||||
PipelineExecutionError, "one-megabyte result limit"
|
||||
) as raised:
|
||||
execute_preview(_expression_graph("rpad(value, 200000, 'ö')"), row_limit=10)
|
||||
self.assertEqual("padding", raised.exception.node_id)
|
||||
|
||||
def test_user_and_operator_documentation_explains_intermediate_padding_limit_in_both_languages(
|
||||
self,
|
||||
) -> None:
|
||||
topic = next(
|
||||
topic
|
||||
for topic in get_manifest().documentation
|
||||
if topic.id == "dataflow.reference.nodes-and-expressions"
|
||||
)
|
||||
self.assertIn("user", topic.documentation_types)
|
||||
self.assertIn("admin", topic.documentation_types)
|
||||
for text in (topic.body, topic.translations["de"]["body"]):
|
||||
self.assertIn("LPAD", text)
|
||||
self.assertIn("RPAD", text)
|
||||
self.assertIn("LENGTH", text)
|
||||
self.assertIn("SUBSTRING", text)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
@@ -0,0 +1,117 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from datetime import date, datetime, timezone
|
||||
from decimal import Decimal
|
||||
import time
|
||||
import unittest
|
||||
from unittest.mock import patch
|
||||
|
||||
from govoplan_core.security.bounded_process import ProcessBudgetError
|
||||
from govoplan_dataflow.backend.backends import (
|
||||
BackendExecutionError, BackendSource, ExecutionBudget, execute_typed_graph,
|
||||
)
|
||||
from govoplan_dataflow.backend.backends.reference import ReferenceExecutionBackend
|
||||
from govoplan_dataflow.backend.batches import TypedBatch
|
||||
from govoplan_dataflow.backend.executor import PipelineExecutionError, ResolvedSource
|
||||
from govoplan_dataflow.backend.manifest import get_manifest
|
||||
from govoplan_dataflow.backend.schemas import GraphEdge, GraphNode, GraphPosition, PipelineGraph
|
||||
from govoplan_dataflow.backend.service import _execute_pipeline_preview, _typed_backend_sources
|
||||
|
||||
|
||||
def graph_for(expression: str = "value", rows: list | None = None) -> PipelineGraph:
|
||||
nodes = [
|
||||
GraphNode(id="source", type="source.inline", label="Source", position=GraphPosition(x=0, y=0),
|
||||
config={"source_name": "records", "rows": rows or [{"value": "normal"}]}),
|
||||
GraphNode(id="expression", type="expression", label="Expression", position=GraphPosition(x=100, y=0),
|
||||
config={"target_column": "result", "expression": expression, "result_type": "unknown"}),
|
||||
GraphNode(id="output", type="output", label="Output", position=GraphPosition(x=200, y=0), config={}),
|
||||
]
|
||||
return PipelineGraph(nodes=nodes, edges=[
|
||||
GraphEdge(id="first", source="source", target="expression"),
|
||||
GraphEdge(id="second", source="expression", target="output"),
|
||||
])
|
||||
|
||||
|
||||
class ReferenceProcessTests(unittest.TestCase):
|
||||
def test_non_finite_deadlines_are_rejected_before_registry_wait(self) -> None:
|
||||
for value in (float("nan"), float("inf")):
|
||||
with self.subTest(value=value), self.assertRaisesRegex(ValueError, "finite"):
|
||||
ExecutionBudget(max_wall_seconds=value)
|
||||
|
||||
def test_real_child_not_parent_helper_and_typed_result_preserved(self) -> None:
|
||||
row = {"value": Decimal("1.20"), "date": date(2026, 9, 8),
|
||||
"when": datetime(2026, 9, 8, tzinfo=timezone.utc), "binary": b"\x00\xff"}
|
||||
graph = graph_for()
|
||||
graph.nodes[0] = graph.nodes[0].model_copy(update={"type": "source.reference", "config": {
|
||||
"source_ref": "datasource:fixture", "source_name": "records",
|
||||
}})
|
||||
source = BackendSource(node_id="source", batch=TypedBatch.from_rows([row]),
|
||||
source_ref="datasource:fixture", provider="test", fingerprint="pinned", total_rows=1)
|
||||
with patch.object(ReferenceExecutionBackend, "_execute_in_process", side_effect=AssertionError("parent evaluation")):
|
||||
result = execute_typed_graph(graph, backend="reference", sources={"source": source})
|
||||
self.assertEqual(result.rows, [{**row, "result": Decimal("1.20")}])
|
||||
self.assertEqual(result.contract.lineage.source_fingerprints[0]["fingerprint"], "pinned")
|
||||
|
||||
def test_real_pathological_regex_is_stopped_with_structured_failure(self) -> None:
|
||||
graph = graph_for("regexp_full_match(value, '(a+)+$')", [{"value": "a" * 100 + "!"}])
|
||||
started = time.monotonic()
|
||||
with self.assertRaises(BackendExecutionError) as caught:
|
||||
execute_typed_graph(graph, backend="reference", budget=ExecutionBudget(max_wall_seconds=2))
|
||||
self.assertIn(caught.exception.code, {"backend.process.timeout", "backend.process.cpu_limit"})
|
||||
self.assertLess(time.monotonic() - started, 4)
|
||||
|
||||
def test_aggregate_padding_allocation_is_contained_by_child_memory_limit(self) -> None:
|
||||
graph = graph_for("lpad(value, 900000, '0')", [{"value": "x"} for _ in range(250)])
|
||||
with self.assertRaises(BackendExecutionError) as caught:
|
||||
execute_typed_graph(graph, backend="reference", budget=ExecutionBudget(
|
||||
max_wall_seconds=5, max_memory_bytes=128 * 1024 * 1024,
|
||||
))
|
||||
self.assertEqual(caught.exception.code, "backend.process.memory_limit")
|
||||
|
||||
def test_busy_preview_is_retryable_and_never_evaluates_inline(self) -> None:
|
||||
with patch("govoplan_dataflow.backend.backends.reference.run_bounded_operation", side_effect=ProcessBudgetError("busy")):
|
||||
with self.assertRaises(PipelineExecutionError) as caught:
|
||||
_execute_pipeline_preview(graph_for(), session=None, principal=None, registry=None,
|
||||
backend="reference", row_limit=10, preview_node_id=None)
|
||||
self.assertTrue(caught.exception.retryable)
|
||||
self.assertEqual(caught.exception.diagnostics[-1].code, "backend.process.busy")
|
||||
|
||||
def test_nested_source_ids_do_not_alias_different_authorized_data(self) -> None:
|
||||
outer = graph_for()
|
||||
inner = graph_for()
|
||||
for graph, ref in ((outer, "datasource:outer"), (inner, "datasource:inner")):
|
||||
graph.nodes[0] = graph.nodes[0].model_copy(update={"type": "source.reference", "config": {
|
||||
"source_ref": ref, "source_name": "records",
|
||||
}})
|
||||
outer.nodes[1] = outer.nodes[1].model_copy(update={"type": "subflow", "config": {
|
||||
"graph": inner.model_dump(mode="python"), "parameters": {},
|
||||
}})
|
||||
def resolve(node, limit):
|
||||
return ResolvedSource(rows=({"value": node.config["source_ref"]},),
|
||||
source_ref=node.config["source_ref"], provider="test",
|
||||
fingerprint=node.config["source_ref"], total_rows=1)
|
||||
sources = _typed_backend_sources(outer, source_resolver=resolve, include_subflows=True)
|
||||
self.assertEqual({source.source_ref for source in sources.values()}, {"datasource:outer", "datasource:inner"})
|
||||
self.assertEqual(len(sources), 2)
|
||||
|
||||
def test_static_worker_documentation_is_bilingual(self) -> None:
|
||||
topic = next(item for item in get_manifest().documentation if item.id == "dataflow.reference-worker-limits")
|
||||
for body in (topic.body, topic.translations["de"]["body"]):
|
||||
self.assertIn("GOVOPLAN_ISOLATED_PROCESS_CONCURRENCY", body)
|
||||
self.assertIn("32 MiB", body)
|
||||
self.assertEqual(set(topic.documentation_types), {"user", "admin"})
|
||||
|
||||
def test_cumulative_source_budget_stops_before_reading_further_sources(self) -> None:
|
||||
graph = graph_for()
|
||||
graph.nodes = [graph.nodes[0].model_copy(update={
|
||||
"id": f"source-{index}", "type": "source.reference", "config": {"source_ref": f"fixture:{index}"},
|
||||
}) for index in range(3)]
|
||||
calls = []
|
||||
def resolve(node, limit):
|
||||
calls.append(node.id)
|
||||
return ResolvedSource(rows=({"value": "x" * 100},), source_ref=node.config["source_ref"],
|
||||
provider="test", fingerprint="fixed", total_rows=1)
|
||||
with self.assertRaisesRegex(PipelineExecutionError, "Combined source data"):
|
||||
_typed_backend_sources(graph, source_resolver=resolve, include_subflows=True,
|
||||
_remaining_source_bytes=[200])
|
||||
self.assertEqual(calls, ["source-0", "source-1"])
|
||||
@@ -0,0 +1,194 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import hashlib
|
||||
import json
|
||||
import os
|
||||
from types import SimpleNamespace
|
||||
import unittest
|
||||
from unittest.mock import Mock, patch
|
||||
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from govoplan_core.auth import ApiPrincipal
|
||||
from govoplan_core.core.access import PrincipalRef
|
||||
from govoplan_core.core.datasources import (
|
||||
CAPABILITY_DATASOURCE_CATALOGUE,
|
||||
DatasourceAccessError,
|
||||
DatasourceCatalogueProvider,
|
||||
DatasourceDescriptor,
|
||||
DatasourceReadRequest,
|
||||
DatasourceReadResult,
|
||||
)
|
||||
from govoplan_core.security.bounded_process import run_bounded_operation
|
||||
from govoplan_dataflow.backend.backends.reference import ReferenceExecutionBackend
|
||||
from govoplan_dataflow.backend.executor import EXECUTOR_VERSION, PipelineExecutionError
|
||||
from govoplan_dataflow.backend.graph import validate_graph
|
||||
from govoplan_dataflow.backend.schemas import GraphEdge, GraphNode, GraphPosition, PipelineGraph
|
||||
from govoplan_dataflow.backend.service import _execute_pipeline_preview
|
||||
|
||||
|
||||
OUTER_ROWS = ({"id": "outer", "amount": 15}, {"id": "outer-low", "amount": 5})
|
||||
INNER_ROWS = ({"id": "inner", "amount": 25}, {"id": "inner-low", "amount": 2})
|
||||
|
||||
|
||||
def node(node_id: str, node_type: str, config: dict) -> GraphNode:
|
||||
return GraphNode(
|
||||
id=node_id, type=node_type, label=node_id,
|
||||
position=GraphPosition(x=0, y=0), config=config,
|
||||
)
|
||||
|
||||
|
||||
def nested_source_graph() -> PipelineGraph:
|
||||
# Both external sources deliberately share their node ID and logical name.
|
||||
# The pinned subflow still has exactly one distinct inline input binding.
|
||||
nested = PipelineGraph(
|
||||
nodes=[
|
||||
node("input", "source.inline", {
|
||||
"source_name": "bound_input", "rows": [], "input_binding": True,
|
||||
}),
|
||||
node("shared", "source.reference", {
|
||||
"source_name": "records", "source_ref": {"$parameter": "source_ref"},
|
||||
"expected_fingerprint": "inner-pinned", "consistency": "frozen",
|
||||
}),
|
||||
node("union", "combine.union", {"mode": "all"}),
|
||||
node("minimum", "filter.expression", {"expression": "amount >= ${minimum}"}),
|
||||
node("output", "output", {}),
|
||||
],
|
||||
edges=[
|
||||
GraphEdge(id="input-union", source="input", target="union"),
|
||||
GraphEdge(id="shared-union", source="shared", target="union"),
|
||||
GraphEdge(id="union-minimum", source="union", target="minimum"),
|
||||
GraphEdge(id="minimum-output", source="minimum", target="output"),
|
||||
],
|
||||
)
|
||||
return PipelineGraph(
|
||||
nodes=[
|
||||
node("shared", "source.reference", {
|
||||
"source_name": "records", "source_ref": "datasource:outer",
|
||||
"expected_fingerprint": "outer-pinned", "consistency": "current",
|
||||
}),
|
||||
node("nested", "subflow", {
|
||||
"template_ref": "fixture-nested-source", "template_version": "1",
|
||||
"parameters": {"source_ref": "datasource:inner", "minimum": 10},
|
||||
"graph": nested.model_dump(mode="python"),
|
||||
}),
|
||||
node("output", "output", {}),
|
||||
],
|
||||
edges=[
|
||||
GraphEdge(id="shared-nested", source="shared", target="nested"),
|
||||
GraphEdge(id="nested-output", source="nested", target="output"),
|
||||
],
|
||||
)
|
||||
|
||||
|
||||
class ReferenceSubflowProcessTests(unittest.TestCase):
|
||||
def setUp(self) -> None:
|
||||
self.graph = nested_source_graph()
|
||||
self.assertEqual([], [item.model_dump() for item in validate_graph(self.graph) if item.severity == "error"])
|
||||
self.session = Mock(spec=Session)
|
||||
self.principal = ApiPrincipal(
|
||||
principal=PrincipalRef(
|
||||
account_id="fixture-account", membership_id="fixture-membership",
|
||||
tenant_id="fixture-tenant", scopes=frozenset(),
|
||||
),
|
||||
account=object(), user=object(),
|
||||
)
|
||||
self.provider = Mock(spec=DatasourceCatalogueProvider)
|
||||
self.provider.read_datasource.side_effect = self.read_source
|
||||
self.registry = SimpleNamespace(
|
||||
has_capability=lambda name: name == CAPABILITY_DATASOURCE_CATALOGUE,
|
||||
capability=lambda name: self.provider if name == CAPABILITY_DATASOURCE_CATALOGUE else None,
|
||||
)
|
||||
self.reads: list[tuple[int, DatasourceReadRequest]] = []
|
||||
self.denied = False
|
||||
|
||||
def read_source(self, session, principal, *, request: DatasourceReadRequest) -> DatasourceReadResult:
|
||||
self.assertIs(session, self.session)
|
||||
self.assertIs(principal, self.principal)
|
||||
self.reads.append((os.getpid(), request))
|
||||
if request.datasource_ref == "datasource:inner" and self.denied:
|
||||
raise DatasourceAccessError("Current principal cannot read datasource:inner.")
|
||||
rows, fingerprint = {
|
||||
"datasource:outer": (OUTER_ROWS, "outer-pinned"),
|
||||
"datasource:inner": (INNER_ROWS, "inner-pinned"),
|
||||
}[request.datasource_ref]
|
||||
self.assertEqual(fingerprint, request.expected_fingerprint)
|
||||
return DatasourceReadResult(
|
||||
datasource=DatasourceDescriptor(
|
||||
ref=request.datasource_ref, source_name="records", name="Fixture source",
|
||||
kind="custom", mode="static", shape="tabular",
|
||||
fingerprint=fingerprint, provider="fixture-catalogue",
|
||||
),
|
||||
rows=rows, total_rows=len(rows), truncated=False,
|
||||
)
|
||||
|
||||
def preview(self, *, row_limit: int = 10):
|
||||
return _execute_pipeline_preview(
|
||||
self.graph, session=self.session, principal=self.principal,
|
||||
registry=self.registry, backend="reference", row_limit=row_limit,
|
||||
preview_node_id="nested",
|
||||
)
|
||||
|
||||
def test_nested_parameterized_sources_execute_in_real_child_without_id_aliasing(self) -> None:
|
||||
with (
|
||||
patch.object(ReferenceExecutionBackend, "_execute_in_process", side_effect=AssertionError("parent evaluation")),
|
||||
patch("govoplan_dataflow.backend.backends.reference.run_bounded_operation", wraps=run_bounded_operation) as worker,
|
||||
):
|
||||
result, version = self.preview()
|
||||
worker.assert_called_once()
|
||||
self.assertEqual(EXECUTOR_VERSION, version)
|
||||
self.assertEqual([OUTER_ROWS[0], INNER_ROWS[0]], result.rows)
|
||||
self.assertEqual(2, result.total_rows)
|
||||
self.assertFalse(result.truncated)
|
||||
self.assertEqual(2, result.input_row_count) # Root input count, not the nested binding again.
|
||||
self.assertIsNotNone(result.node_preview)
|
||||
self.assertEqual("nested", result.node_preview.node_id)
|
||||
self.assertEqual(result.rows, result.node_preview.rows)
|
||||
self.assertEqual(2, result.node_preview.total_rows)
|
||||
self.assertEqual(
|
||||
[("shared", "succeeded", 0, 2), ("nested", "succeeded", 2, 2), ("output", "succeeded", 2, 2)],
|
||||
[(item.node_id, item.status, item.input_rows, item.output_rows) for item in result.node_diagnostics],
|
||||
)
|
||||
binding_hash = hashlib.sha256(json.dumps(list(OUTER_ROWS), sort_keys=True, separators=(",", ":")).encode()).hexdigest()
|
||||
self.assertEqual([
|
||||
{"node_id": "shared", "source_ref": "datasource:outer", "source_name": "records", "kind": "datasource", "provider": "fixture-catalogue", "fingerprint": "outer-pinned", "row_count": 2, "preview_rows": 2, "truncated": False},
|
||||
{"node_id": "input", "source_name": "bound_input", "kind": "inline", "fingerprint": binding_hash, "row_count": 2, "subflow_node_id": "nested"},
|
||||
{"node_id": "shared", "source_ref": "datasource:inner", "source_name": "records", "kind": "datasource", "provider": "fixture-catalogue", "fingerprint": "inner-pinned", "row_count": 2, "preview_rows": 2, "truncated": False, "subflow_node_id": "nested"},
|
||||
], result.source_fingerprints)
|
||||
self.assertEqual(
|
||||
[("datasource:outer", "current", "outer-pinned"), ("datasource:inner", "frozen", "inner-pinned")],
|
||||
[(request.datasource_ref, request.consistency, request.expected_fingerprint) for _, request in self.reads],
|
||||
)
|
||||
self.assertTrue(all(pid == os.getpid() for pid, _ in self.reads))
|
||||
self.assertTrue(all(request.limit <= 500 and request.offset == 0 for _, request in self.reads))
|
||||
self.assertEqual([], self.session.mock_calls)
|
||||
|
||||
def test_nested_result_and_node_preview_keep_full_totals_when_output_is_bounded(self) -> None:
|
||||
result, _ = self.preview(row_limit=1)
|
||||
self.assertEqual([OUTER_ROWS[0]], result.rows)
|
||||
self.assertEqual(2, result.total_rows)
|
||||
self.assertTrue(result.truncated)
|
||||
self.assertEqual([OUTER_ROWS[0]], result.node_preview.rows)
|
||||
self.assertEqual(2, result.node_preview.total_rows)
|
||||
self.assertTrue(result.node_preview.truncated)
|
||||
self.assertEqual({"outer-pinned", "inner-pinned"}, {
|
||||
item["fingerprint"] for item in result.source_fingerprints if item["kind"] == "datasource"
|
||||
})
|
||||
self.assertEqual([], self.session.mock_calls)
|
||||
|
||||
def test_denied_nested_datasource_stops_before_worker_or_persistence(self) -> None:
|
||||
self.denied = True
|
||||
with (
|
||||
patch("govoplan_dataflow.backend.service.execute_typed_graph") as execute,
|
||||
patch("govoplan_dataflow.backend.backends.reference.run_bounded_operation") as worker,
|
||||
self.assertRaises(PipelineExecutionError) as caught,
|
||||
):
|
||||
self.preview()
|
||||
execute.assert_not_called()
|
||||
worker.assert_not_called()
|
||||
self.assertEqual("shared", caught.exception.node_id)
|
||||
self.assertEqual("Current principal cannot read datasource:inner.", str(caught.exception))
|
||||
self.assertFalse(caught.exception.retryable)
|
||||
self.assertIsInstance(caught.exception.__cause__, DatasourceAccessError)
|
||||
self.assertEqual(["datasource:outer", "datasource:inner"], [request.datasource_ref for _, request in self.reads])
|
||||
self.assertEqual([], self.session.mock_calls)
|
||||
+351
-2
@@ -25,12 +25,16 @@ from govoplan_dataflow.backend.schemas import (
|
||||
DataflowTriggerSchedule,
|
||||
PipelineCreateRequest,
|
||||
PipelineDeriveRequest,
|
||||
PipelineRebaseRequest,
|
||||
PipelineUpdateRequest,
|
||||
)
|
||||
from govoplan_dataflow.backend.service import (
|
||||
DataflowConflictError,
|
||||
DataflowValidationError,
|
||||
create_pipeline,
|
||||
derive_pipeline,
|
||||
pipeline_response,
|
||||
rebase_pipeline,
|
||||
start_pipeline_run,
|
||||
update_pipeline,
|
||||
)
|
||||
@@ -46,10 +50,87 @@ POLICY_CAPABILITY = "policy.definitionGovernance"
|
||||
AUTOMATION_CAPABILITY = "auth.automationPrincipalProvider"
|
||||
|
||||
|
||||
def sample_graph():
|
||||
def sample_graph(*, minimum: int = 10):
|
||||
from test_service import sample_graph as build_graph
|
||||
|
||||
return build_graph()
|
||||
return build_graph(minimum=minimum)
|
||||
|
||||
|
||||
def reusable_graph(*, minimum: int = 10):
|
||||
graph = sample_graph(minimum=minimum)
|
||||
return graph.model_copy(
|
||||
update={
|
||||
"nodes": [
|
||||
(
|
||||
node.model_copy(
|
||||
update={
|
||||
"config": {
|
||||
**node.config,
|
||||
"input_binding": True,
|
||||
}
|
||||
},
|
||||
deep=True,
|
||||
)
|
||||
if node.id == "source"
|
||||
else node
|
||||
)
|
||||
for node in graph.nodes
|
||||
]
|
||||
},
|
||||
deep=True,
|
||||
)
|
||||
|
||||
|
||||
def referencing_graph(
|
||||
source_ref: str,
|
||||
source_revision: int,
|
||||
*,
|
||||
omit_amount: bool = False,
|
||||
input_binding: bool = False,
|
||||
):
|
||||
graph = sample_graph()
|
||||
return graph.model_copy(
|
||||
update={
|
||||
"nodes": [
|
||||
(
|
||||
node.model_copy(
|
||||
update={
|
||||
"config": {
|
||||
**node.config,
|
||||
"rows": (
|
||||
[{"id": 1}]
|
||||
if omit_amount
|
||||
else node.config["rows"]
|
||||
),
|
||||
"input_binding": input_binding,
|
||||
}
|
||||
},
|
||||
deep=True,
|
||||
)
|
||||
if node.id == "source"
|
||||
else node.model_copy(
|
||||
update={
|
||||
"type": "subflow",
|
||||
"label": "Governed reusable flow",
|
||||
"config": {
|
||||
"template_ref": source_ref,
|
||||
"template_version": str(source_revision),
|
||||
"parameters": {},
|
||||
"graph": sample_graph(
|
||||
minimum=999
|
||||
).model_dump(mode="json"),
|
||||
},
|
||||
},
|
||||
deep=True,
|
||||
)
|
||||
if node.id == "filter"
|
||||
else node
|
||||
)
|
||||
for node in graph.nodes
|
||||
]
|
||||
},
|
||||
deep=True,
|
||||
)
|
||||
|
||||
|
||||
def principal() -> ApiPrincipal:
|
||||
@@ -482,6 +563,152 @@ class DataflowTriggerTests(unittest.TestCase):
|
||||
),
|
||||
)
|
||||
|
||||
def test_reusable_reference_is_policy_resolved_with_typed_contracts(
|
||||
self,
|
||||
) -> None:
|
||||
template = create_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
actor_id="template-author",
|
||||
payload=PipelineCreateRequest(
|
||||
name="Typed reusable filter",
|
||||
graph=reusable_graph(minimum=10),
|
||||
definition_kind="template",
|
||||
allow_reuse=True,
|
||||
),
|
||||
)
|
||||
consumer = create_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
actor_id="account-1",
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
payload=PipelineCreateRequest(
|
||||
name="Resolved consumer",
|
||||
graph=referencing_graph(f"pipeline:{template.id}", 1),
|
||||
),
|
||||
)
|
||||
self.session.commit()
|
||||
|
||||
stored = consumer.revisions[0].graph
|
||||
subflow = next(
|
||||
node for node in stored["nodes"] if node["id"] == "filter"
|
||||
)
|
||||
self.assertEqual(template.revisions[0].content_hash, subflow["config"]["template_hash"])
|
||||
self.assertEqual(
|
||||
10,
|
||||
next(
|
||||
node
|
||||
for node in subflow["config"]["graph"]["nodes"]
|
||||
if node["id"] == "filter"
|
||||
)["config"]["value"],
|
||||
)
|
||||
self.assertEqual(
|
||||
{"id", "amount"},
|
||||
{
|
||||
field["name"]
|
||||
for field in subflow["config"]["input_schema"]
|
||||
},
|
||||
)
|
||||
self.assertEqual(
|
||||
{"id", "amount"},
|
||||
{
|
||||
field["name"]
|
||||
for field in subflow["config"]["output_schema"]
|
||||
},
|
||||
)
|
||||
self.assertTrue(
|
||||
subflow["config"]["reference_provenance"][
|
||||
"policy_decision"
|
||||
]["allowed"]
|
||||
)
|
||||
|
||||
with self.assertRaises(DataflowValidationError):
|
||||
create_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
actor_id="account-1",
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
payload=PipelineCreateRequest(
|
||||
name="Incompatible consumer",
|
||||
graph=referencing_graph(
|
||||
f"pipeline:{template.id}",
|
||||
1,
|
||||
omit_amount=True,
|
||||
),
|
||||
),
|
||||
)
|
||||
|
||||
def test_reusable_reference_cycles_are_rejected_across_revisions(
|
||||
self,
|
||||
) -> None:
|
||||
left = create_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
actor_id="account-1",
|
||||
payload=PipelineCreateRequest(
|
||||
name="Left template",
|
||||
graph=reusable_graph(),
|
||||
definition_kind="template",
|
||||
allow_reuse=True,
|
||||
),
|
||||
)
|
||||
right = create_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
actor_id="account-1",
|
||||
payload=PipelineCreateRequest(
|
||||
name="Right template",
|
||||
graph=reusable_graph(),
|
||||
definition_kind="template",
|
||||
allow_reuse=True,
|
||||
),
|
||||
)
|
||||
self.session.flush()
|
||||
update_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
pipeline_id=left.id,
|
||||
actor_id="account-1",
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
payload=PipelineUpdateRequest(
|
||||
name=left.name,
|
||||
graph=referencing_graph(
|
||||
f"pipeline:{right.id}",
|
||||
1,
|
||||
input_binding=True,
|
||||
),
|
||||
status="draft",
|
||||
expected_revision=1,
|
||||
definition_kind="template",
|
||||
allow_reuse=True,
|
||||
),
|
||||
)
|
||||
|
||||
with self.assertRaisesRegex(DataflowConflictError, "cannot reference itself"):
|
||||
update_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
pipeline_id=right.id,
|
||||
actor_id="account-1",
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
payload=PipelineUpdateRequest(
|
||||
name=right.name,
|
||||
graph=referencing_graph(
|
||||
f"pipeline:{left.id}",
|
||||
2,
|
||||
input_binding=True,
|
||||
),
|
||||
status="draft",
|
||||
expected_revision=1,
|
||||
definition_kind="template",
|
||||
allow_reuse=True,
|
||||
),
|
||||
)
|
||||
|
||||
def test_derived_limits_cannot_be_broadened_transitively(self) -> None:
|
||||
template = create_pipeline(
|
||||
self.session,
|
||||
@@ -549,6 +776,128 @@ class DataflowTriggerTests(unittest.TestCase):
|
||||
self.assertFalse(grandchild.allow_automation)
|
||||
self.assertFalse(grandchild.inherit_to_lower_scopes)
|
||||
|
||||
def test_source_update_is_detected_and_rebased_as_reviewed_revision(
|
||||
self,
|
||||
) -> None:
|
||||
template = create_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
actor_id="account-1",
|
||||
payload=PipelineCreateRequest(
|
||||
name="Reusable import",
|
||||
graph=sample_graph(),
|
||||
definition_kind="template",
|
||||
allow_reuse=True,
|
||||
allow_automation=True,
|
||||
),
|
||||
)
|
||||
derived = derive_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
actor_id="account-1",
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
source_pipeline_id=template.id,
|
||||
payload=PipelineDeriveRequest(
|
||||
name="Tenant import",
|
||||
allow_run=True,
|
||||
allow_automation=True,
|
||||
),
|
||||
)
|
||||
self.session.commit()
|
||||
|
||||
before = pipeline_response(
|
||||
self.session,
|
||||
derived,
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
)
|
||||
self.assertTrue(before.governance.source_available)
|
||||
self.assertFalse(before.governance.update_available)
|
||||
original_child_hash = derived.revisions[0].content_hash
|
||||
|
||||
update_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
pipeline_id=template.id,
|
||||
actor_id="template-author",
|
||||
payload=PipelineUpdateRequest(
|
||||
name=template.name,
|
||||
graph=sample_graph(minimum=20),
|
||||
status="draft",
|
||||
expected_revision=1,
|
||||
definition_kind="template",
|
||||
allow_reuse=True,
|
||||
allow_automation=True,
|
||||
),
|
||||
)
|
||||
self.session.commit()
|
||||
source_hash = template.revisions[-1].content_hash
|
||||
|
||||
available = pipeline_response(
|
||||
self.session,
|
||||
derived,
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
)
|
||||
self.assertTrue(available.governance.update_available)
|
||||
self.assertEqual(2, available.governance.source_current_revision)
|
||||
self.assertEqual(source_hash, available.governance.source_current_hash)
|
||||
self.assertEqual(original_child_hash, derived.revisions[0].content_hash)
|
||||
|
||||
with self.assertRaisesRegex(DataflowConflictError, "source hash"):
|
||||
rebase_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
pipeline_id=derived.id,
|
||||
actor_id="reviewer-1",
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
payload=PipelineRebaseRequest(
|
||||
expected_revision=1,
|
||||
source_revision=2,
|
||||
source_hash="0" * 64,
|
||||
reason="Reviewed the changed filter threshold.",
|
||||
),
|
||||
)
|
||||
|
||||
rebased = rebase_pipeline(
|
||||
self.session,
|
||||
tenant_id="tenant-1",
|
||||
pipeline_id=derived.id,
|
||||
actor_id="reviewer-1",
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
payload=PipelineRebaseRequest(
|
||||
expected_revision=1,
|
||||
source_revision=2,
|
||||
source_hash=source_hash,
|
||||
reason="Reviewed the changed filter threshold.",
|
||||
),
|
||||
)
|
||||
self.session.commit()
|
||||
|
||||
self.assertEqual(2, rebased.current_revision)
|
||||
self.assertEqual("draft", rebased.status)
|
||||
self.assertEqual(2, rebased.derived_from_revision)
|
||||
self.assertEqual(source_hash, rebased.derived_from_hash)
|
||||
self.assertEqual(source_hash, rebased.revisions[-1].content_hash)
|
||||
self.assertEqual(original_child_hash, rebased.revisions[0].content_hash)
|
||||
history = rebased.derivation_provenance["rebase_history"]
|
||||
self.assertEqual(1, len(history))
|
||||
self.assertEqual("reviewer-1", history[0]["rebased_by"])
|
||||
self.assertEqual(
|
||||
"Reviewed the changed filter threshold.",
|
||||
history[0]["reason"],
|
||||
)
|
||||
current = pipeline_response(
|
||||
self.session,
|
||||
rebased,
|
||||
principal=self.actor,
|
||||
registry=self.registry,
|
||||
)
|
||||
self.assertFalse(current.governance.update_available)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
|
||||
+4
-3
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@govoplan/dataflow-webui",
|
||||
"version": "0.1.19",
|
||||
"version": "0.1.25",
|
||||
"private": true,
|
||||
"type": "module",
|
||||
"main": "src/index.ts",
|
||||
@@ -15,10 +15,11 @@
|
||||
},
|
||||
"scripts": {
|
||||
"typecheck": "tsc --noEmit",
|
||||
"test:structure": "node scripts/test-dataflow-page-structure.mjs"
|
||||
"test:structure": "node scripts/test-dataflow-page-structure.mjs",
|
||||
"test:save-completion": "node --test scripts/test-save-completion.mjs"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@govoplan/core-webui": "^0.1.18",
|
||||
"@govoplan/core-webui": "^0.1.46",
|
||||
"@xyflow/react": "^12.11.2",
|
||||
"lucide-react": "^1.23.0",
|
||||
"react": ">=19.2.7 <20",
|
||||
|
||||
Executable
+200
@@ -0,0 +1,200 @@
|
||||
import assert from "node:assert/strict";
|
||||
import { readFileSync } from "node:fs";
|
||||
import { createRequire } from "node:module";
|
||||
import test from "node:test";
|
||||
import vm from "node:vm";
|
||||
|
||||
const require = createRequire(new URL("../../../govoplan-core/webui/package.json", import.meta.url));
|
||||
const { transformSync } = require("esbuild");
|
||||
const page = readFileSync(new URL("../src/features/dataflow/DataflowPage.tsx", import.meta.url), "utf8");
|
||||
function loadTs(path) {
|
||||
const context = vm.createContext({ module: { exports: {} }, require: () => ({}), structuredClone });
|
||||
context.exports = context.module.exports;
|
||||
vm.runInContext(transformSync(readFileSync(new URL(path, import.meta.url), "utf8"), { loader: "ts", format: "cjs" }).code, context);
|
||||
return context.module.exports;
|
||||
}
|
||||
const { reconcilePipelineSave } = loadTs("../src/features/dataflow/saveCompletion.ts");
|
||||
const { draftFingerprint, pipelinePayload } = loadTs("../src/features/dataflow/model.ts");
|
||||
const { authAuthorityKey } = loadTs("../../../govoplan-core/webui/src/api/authAuthority.ts");
|
||||
const start = page.indexOf(" const saveDraft = useCallback(async (): Promise<boolean> => {");
|
||||
const end = page.indexOf(" }, [canEdit, draft, settings, authorityKey, authorityGeneration]);", start);
|
||||
assert.ok(start >= 0 && end > start, "exercise the actual page save closure");
|
||||
const code = transformSync(page.slice(start, end) + " }, []);\nmodule.exports = saveDraft;", { loader: "ts" }).code;
|
||||
const base = () => ({
|
||||
id: "pipeline-1", currentRevision: 1, name: "Pipeline", description: "Submitted", status: "draft",
|
||||
graph: { nodes: [{ id: "a", config: { rows: [{ id: "001", value: " text " }] } }, { id: "b" }], edges: [{ id: "a-b" }] },
|
||||
sqlText: "", editorMode: "graph", scopeType: "tenant", scopeId: "tenant-1", definitionKind: "flow",
|
||||
inheritToLowerScopes: false, allowRun: true, allowReuse: true, allowAutomation: false, governance: { actions: {} }
|
||||
});
|
||||
function harness(draft = base()) {
|
||||
const calls = [];
|
||||
const responses = [];
|
||||
const context = vm.createContext({
|
||||
module: { exports: {} }, useCallback: (value) => value, structuredClone,
|
||||
draft, canEdit: true, settings: {}, saveInFlight: { current: false },
|
||||
draftSession: { current: { generation: 1, value: draft } },
|
||||
authorityKey: "authority-A", saveContext: { current: "authority-A" }, unresolvedSaveGeneration: { current: null },
|
||||
authorityGeneration: 0, saveAuthorityEpoch: { current: { key: "authority-A", revision: 0 } },
|
||||
reconcilePipelineSave, draftFingerprint, pipelinePayload, draftFromPipeline: (value) => value,
|
||||
updateDataflowPipeline: (_settings, id, payload) => new Promise((resolve, reject) => { calls.push({ id, payload }); responses.push({ resolve, reject }); }),
|
||||
createDataflowPipeline: (_settings, payload) => new Promise((resolve, reject) => { calls.push({ payload }); responses.push({ resolve, reject }); }),
|
||||
setDraftValue: (value) => { context.draft = value; },
|
||||
setSavedDraft: (value) => { context.baseline = value; },
|
||||
setSaving: (value) => { context.saving = value; },
|
||||
setError: (value) => { context.error = value; },
|
||||
setSuccess: () => {}, setPipelines: () => {}, setSelectedNodeId: () => {}, setDiagnostics: () => {}, apiErrorMessage: String
|
||||
});
|
||||
vm.runInContext(code, context);
|
||||
return { context, calls, responses, save: context.module.exports };
|
||||
}
|
||||
function accepted(draft, revision = 2) {
|
||||
return { ...structuredClone(draft), currentRevision: revision, current_revision: revision, governance: { actions: { edit: { allowed: true } } } };
|
||||
}
|
||||
|
||||
test("edits made during an accepted save survive and navigation remains blocked until saved", async () => {
|
||||
const h = harness();
|
||||
const submitted = h.context.draft;
|
||||
const pending = h.save();
|
||||
const newerGraph = { ...submitted.graph, nodes: [...submitted.graph.nodes].reverse(), custom: { preserve: ["001", null, ""] } };
|
||||
h.context.draftSession.current.value = { ...submitted, description: "Typed during save", graph: newerGraph };
|
||||
h.responses[0].resolve(accepted(submitted));
|
||||
assert.equal(await pending, false);
|
||||
assert.equal(h.context.draft.description, "Typed during save");
|
||||
assert.equal(h.context.draft.graph, newerGraph, "graph remains atomic, including order and unknown data");
|
||||
assert.equal(h.context.baseline.description, "Submitted");
|
||||
assert.equal(h.context.draft.currentRevision, 2);
|
||||
assert.notEqual(draftFingerprint(h.context.draft), draftFingerprint(h.context.baseline));
|
||||
const second = h.save();
|
||||
assert.equal(h.calls[1].payload.expected_revision, 2, "next save uses the accepted revision, not the stale submitted one");
|
||||
assert.deepEqual(h.calls[1].payload.graph, newerGraph);
|
||||
h.responses[1].resolve(accepted(h.context.draft, 3));
|
||||
assert.equal(await second, true);
|
||||
assert.equal(draftFingerprint(h.context.draft), draftFingerprint(h.context.baseline));
|
||||
});
|
||||
|
||||
test("unchanged submitted fields accept canonical response and new identities without a duplicate create", async () => {
|
||||
const h = harness({ ...base(), id: null, currentRevision: null });
|
||||
const pending = h.save();
|
||||
assert.equal(await h.save(), false);
|
||||
assert.equal(h.calls.length, 1);
|
||||
const response = { ...accepted(h.context.draft), id: "created", name: "Server canonical name" };
|
||||
h.responses[0].resolve(response);
|
||||
assert.equal(await pending, true);
|
||||
assert.equal(h.context.draft.id, "created");
|
||||
assert.equal(h.context.draft.name, "Server canonical name");
|
||||
});
|
||||
|
||||
test("replacement draft, authority change and unmount cannot receive an old save completion", async () => {
|
||||
for (const change of ["replacement", "authority", "unmount"]) {
|
||||
const h = harness();
|
||||
const pending = h.save();
|
||||
if (change === "authority") h.context.saveContext.current = "authority-B";
|
||||
else h.context.draftSession.current.generation += 1;
|
||||
h.responses[0].resolve(accepted(h.context.draft));
|
||||
assert.equal(await pending, false);
|
||||
assert.equal(h.context.baseline, undefined);
|
||||
assert.equal(h.context.draft.currentRevision, 1);
|
||||
}
|
||||
});
|
||||
|
||||
test("harmless session/profile object refresh preserves an accepted new identity and revision", async () => {
|
||||
const h = harness({ ...base(), id: null, currentRevision: null });
|
||||
const settings = { apiBaseUrl: "/api", apiKey: "", accessToken: "" };
|
||||
const auth = {
|
||||
user: { id: "member", account_id: "account", email: "person@example.test", display_name: "Before" },
|
||||
tenant: { id: "tenant" }, scopes: ["dataflow:pipeline:write"], roles: [], groups: []
|
||||
};
|
||||
h.context.authorityKey = authAuthorityKey(auth, settings);
|
||||
h.context.saveContext.current = h.context.authorityKey;
|
||||
const pending = h.save();
|
||||
h.context.saveContext.current = authAuthorityKey({ ...structuredClone(auth), user: { ...auth.user, display_name: "After", preferred_language: "de" } }, { ...settings });
|
||||
h.responses[0].resolve({ ...accepted(h.context.draft), id: "accepted-created-id" });
|
||||
assert.equal(await pending, true);
|
||||
assert.equal(h.context.draft.id, "accepted-created-id");
|
||||
const next = h.save();
|
||||
assert.equal(h.calls[1].id, "accepted-created-id", "retry updates the accepted identity, never creates another pipeline");
|
||||
assert.equal(h.calls[1].payload.expected_revision, 2);
|
||||
h.responses[1].resolve(accepted(h.context.draft, 3));
|
||||
assert.equal(await next, true);
|
||||
});
|
||||
|
||||
test("an accepted save across a real authority change cannot be blindly retried as a duplicate create", async () => {
|
||||
const h = harness({ ...base(), id: null, currentRevision: null });
|
||||
const pending = h.save();
|
||||
h.context.saveContext.current = "authority-B";
|
||||
h.responses[0].resolve({ ...accepted(h.context.draft), id: "accepted-under-A" });
|
||||
assert.equal(await pending, false);
|
||||
h.context.authorityKey = "authority-B";
|
||||
assert.equal(await h.save(), false);
|
||||
assert.equal(h.calls.length, 1);
|
||||
assert.match(h.context.error, /Reload and review/);
|
||||
});
|
||||
|
||||
test("returning to authority A after B does not revive a stale A save completion", async () => {
|
||||
const h = harness();
|
||||
const pending = h.save();
|
||||
h.context.saveAuthorityEpoch.current = { key: "authority-A", revision: 2 };
|
||||
h.responses[0].resolve(accepted(h.context.draft));
|
||||
assert.equal(await pending, false);
|
||||
assert.equal(h.context.baseline, undefined);
|
||||
});
|
||||
|
||||
test("conflict preserves both local draft and prior revision, allowing an explicit reviewed retry", async () => {
|
||||
const h = harness();
|
||||
const original = h.context.draft;
|
||||
const pending = h.save();
|
||||
h.responses[0].reject(new Error("revision conflict"));
|
||||
assert.equal(await pending, false);
|
||||
assert.equal(h.context.draft, original);
|
||||
assert.equal(h.context.baseline, undefined);
|
||||
assert.match(h.context.error, /revision conflict/);
|
||||
assert.equal(h.context.saveInFlight.current, false);
|
||||
});
|
||||
|
||||
test("the submitted baseline is frozen even if a nested local editor mutates a shared object", async () => {
|
||||
const h = harness();
|
||||
const serverAccepted = accepted(h.context.draft);
|
||||
const pending = h.save();
|
||||
h.context.draft.graph.nodes.reverse();
|
||||
h.responses[0].resolve(serverAccepted);
|
||||
assert.equal(await pending, false);
|
||||
assert.equal(h.context.draft.graph.nodes[0].id, "b");
|
||||
assert.equal(h.context.baseline.graph.nodes[0].id, "a");
|
||||
assert.equal(h.calls[0].payload.graph.nodes[0].id, "a", "submission data is not aliased to later editor mutations");
|
||||
});
|
||||
|
||||
test("CSV imports explicitly preserve text by default; JSON payload stays independent", () => {
|
||||
assert.match(page, /\[csvValueMode, setCsvValueMode\] = useState<"text" \| "legacy_typed">\("text"\)/);
|
||||
assert.match(page, /\? \{ format, rows \}\s*: \{ format, csv_text: csvText, delimiter, csv_value_mode: csvValueMode \}/);
|
||||
assert.match(page, /setCsvValueMode\("text"\)/);
|
||||
});
|
||||
|
||||
test("source dialog sends exact CSV content and selected mode without changing JSON rows", async () => {
|
||||
const dialog = page.slice(page.indexOf("function SourceSnapshotDialog("));
|
||||
const start = dialog.indexOf(" const create = async (): Promise<boolean> => {");
|
||||
const end = dialog.indexOf("\n };", start);
|
||||
assert.ok(start >= 0 && end > start);
|
||||
const code = transformSync(dialog.slice(start, end) + "\n}; module.exports = create;", { loader: "ts" }).code;
|
||||
const csvText = 'code,value\r\n001," text "\r\n';
|
||||
for (const format of ["csv", "json"]) {
|
||||
for (const csvValueMode of ["text", "legacy_typed"]) {
|
||||
let payload;
|
||||
const context = vm.createContext({
|
||||
module: { exports: {} }, settings: {}, format, csvValueMode, csvText, delimiter: ",",
|
||||
name: "Fixture", sourceName: "fixture", description: "", rowsText: '[{"code":"001","value":" text "}]',
|
||||
isRecord: (value) => Boolean(value) && typeof value === "object" && !Array.isArray(value),
|
||||
createDataflowSourceSnapshot: async (_settings, value) => { payload = value; return {}; },
|
||||
onCreated: () => {}, setBusy: () => {}, setError: () => {}, apiErrorMessage: String
|
||||
});
|
||||
vm.runInContext(code, context);
|
||||
assert.equal(await context.module.exports(), true);
|
||||
if (format === "csv") {
|
||||
assert.equal(payload.csv_value_mode, csvValueMode);
|
||||
assert.equal(payload.csv_text, csvText);
|
||||
} else {
|
||||
assert.equal("csv_value_mode" in payload, false);
|
||||
assert.equal(JSON.stringify(payload.rows), '[{"code":"001","value":" text "}]');
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
@@ -95,6 +95,11 @@ export type PipelineGovernance = {
|
||||
derived_from_pipeline_id?: string | null;
|
||||
derived_from_revision?: number | null;
|
||||
derived_from_hash?: string | null;
|
||||
source_available: boolean;
|
||||
source_name?: string | null;
|
||||
source_current_revision?: number | null;
|
||||
source_current_hash?: string | null;
|
||||
update_available: boolean;
|
||||
derivation_provenance: Record<string, unknown>;
|
||||
actions: Record<string, DefinitionActionDecision>;
|
||||
};
|
||||
@@ -387,6 +392,7 @@ export function createDataflowSourceSnapshot(
|
||||
format: "csv";
|
||||
csv_text: string;
|
||||
delimiter: string;
|
||||
csv_value_mode?: "text" | "legacy_typed";
|
||||
}
|
||||
)
|
||||
): Promise<TabularSource> {
|
||||
@@ -505,6 +511,23 @@ export function deriveDataflowPipeline(
|
||||
);
|
||||
}
|
||||
|
||||
export function rebaseDataflowPipeline(
|
||||
settings: ApiSettings,
|
||||
pipelineId: string,
|
||||
payload: {
|
||||
expected_revision: number;
|
||||
source_revision: number;
|
||||
source_hash: string;
|
||||
reason: string;
|
||||
}
|
||||
): Promise<Pipeline> {
|
||||
return apiFetch(
|
||||
settings,
|
||||
`/api/v1/dataflow/pipelines/${encodeURIComponent(pipelineId)}/rebase`,
|
||||
{ method: "POST", body: JSON.stringify(payload) }
|
||||
);
|
||||
}
|
||||
|
||||
export function dataflowScopeReferenceProvider(
|
||||
settings: ApiSettings,
|
||||
scopeType: "user" | "group"
|
||||
@@ -564,7 +587,7 @@ export function deleteDataflowTrigger(
|
||||
|
||||
export function validateDataflowPipeline(
|
||||
settings: ApiSettings,
|
||||
payload: { graph?: PipelineGraph; sql_text?: string; source_nodes?: PipelineGraphNode[] }
|
||||
payload: { pipeline_id?: string | null; graph?: PipelineGraph; sql_text?: string; source_nodes?: PipelineGraphNode[] }
|
||||
): Promise<PipelineValidation> {
|
||||
return apiFetch<PipelineValidation>(settings, "/api/v1/dataflow/validate", {
|
||||
method: "POST",
|
||||
|
||||
@@ -13,6 +13,7 @@ import {
|
||||
Code2,
|
||||
CopyPlus,
|
||||
DatabaseZap,
|
||||
GitCompareArrows,
|
||||
ListChecks,
|
||||
Network,
|
||||
Play,
|
||||
@@ -55,6 +56,7 @@ import { DialogSection, ActionToolbar,
|
||||
WorkspaceFrame,
|
||||
WorkspaceLayout,
|
||||
hasScope,
|
||||
authAuthorityKey,
|
||||
isApiError,
|
||||
useUnsavedChanges,
|
||||
useUnsavedDraftGuard,
|
||||
@@ -84,6 +86,7 @@ import {
|
||||
listDataflowTriggers,
|
||||
previewDataflowPipeline,
|
||||
promoteDataflowPipeline,
|
||||
rebaseDataflowPipeline,
|
||||
recordDataflowDecision,
|
||||
runDataflowPipeline,
|
||||
renderDataflowSql,
|
||||
@@ -127,6 +130,8 @@ import {
|
||||
DATAFLOW_RUN_DOCUMENTATION
|
||||
} from "./interfacePatterns";
|
||||
|
||||
import { reconcilePipelineSave } from "./saveCompletion";
|
||||
|
||||
type ResultTab = "preview" | "diagnostics";
|
||||
type SnapshotFormat = "json" | "csv";
|
||||
|
||||
@@ -141,7 +146,29 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
[location.search]
|
||||
);
|
||||
const [pipelines, setPipelines] = useState<Pipeline[]>([]);
|
||||
const [draft, setDraft] = useState<PipelineDraft | null>(null);
|
||||
const [draft, setDraftValue] = useState<PipelineDraft | null>(null);
|
||||
const draftSession = useRef<{ generation: number; value: PipelineDraft | null }>({ generation: 0, value: null });
|
||||
const saveInFlight = useRef(false);
|
||||
const authorityKey = authAuthorityKey(auth, settings);
|
||||
const saveAuthorityEpoch = useRef({ key: authorityKey, revision: 0 });
|
||||
if (saveAuthorityEpoch.current.key !== authorityKey) {
|
||||
saveAuthorityEpoch.current = { key: authorityKey, revision: saveAuthorityEpoch.current.revision + 1 };
|
||||
}
|
||||
const authorityGeneration = saveAuthorityEpoch.current.revision;
|
||||
const saveContext = useRef(authorityKey);
|
||||
saveContext.current = authorityKey;
|
||||
const unresolvedSaveGeneration = useRef<number | null>(null);
|
||||
useEffect(() => {
|
||||
saveContext.current = authorityKey;
|
||||
return () => { if (saveContext.current === authorityKey) saveContext.current = ""; };
|
||||
}, [authorityKey]);
|
||||
// Replacement (selection, reload, discard, derive) is a different edit session,
|
||||
// even when both unsaved drafts have a null identifier.
|
||||
const setDraft = useCallback((next: PipelineDraft | null) => {
|
||||
draftSession.current = { generation: draftSession.current.generation + 1, value: next };
|
||||
setDraftValue(next);
|
||||
}, []);
|
||||
useEffect(() => () => { draftSession.current.generation += 1; }, []);
|
||||
const [savedDraft, setSavedDraft] = useState<PipelineDraft | null>(null);
|
||||
const [selectedNodeId, setSelectedNodeId] = useState<string | null>(null);
|
||||
const [search, setSearch] = useState("");
|
||||
@@ -161,6 +188,7 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
const [runOpen, setRunOpen] = useState(false);
|
||||
const [definitionSettingsOpen, setDefinitionSettingsOpen] = useState(false);
|
||||
const [deriveOpen, setDeriveOpen] = useState(false);
|
||||
const [rebaseOpen, setRebaseOpen] = useState(false);
|
||||
const [triggersOpen, setTriggersOpen] = useState(false);
|
||||
const [decisionReviewOpen, setDecisionReviewOpen] = useState(false);
|
||||
const [nodeLibrary, setNodeLibrary] = useState<NodeTypeDefinition[]>(FALLBACK_NODE_LIBRARY);
|
||||
@@ -183,6 +211,14 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
&& canWrite
|
||||
&& draft.governance?.actions.derive?.allowed
|
||||
);
|
||||
const canRebase = Boolean(
|
||||
draft?.id
|
||||
&& draft.governance?.update_available
|
||||
&& draft.governance.source_current_revision
|
||||
&& draft.governance.source_current_hash
|
||||
&& canEdit
|
||||
&& !dirty
|
||||
);
|
||||
const canStartSavedRun = Boolean(
|
||||
draft?.id
|
||||
&& draft.definitionKind === "flow"
|
||||
@@ -311,15 +347,27 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
}, [savedDraft]);
|
||||
|
||||
const saveDraft = useCallback(async (): Promise<boolean> => {
|
||||
if (saveInFlight.current) return false;
|
||||
if (authorityKey !== saveContext.current || authorityGeneration !== saveAuthorityEpoch.current.revision) return false;
|
||||
if (unresolvedSaveGeneration.current === draftSession.current.generation) {
|
||||
setError("A prior save completed after authorization changed. Reload and review the server revision before saving again.");
|
||||
return false;
|
||||
}
|
||||
if (!draft || !canEdit || !draft.name.trim()) {
|
||||
setError(!draft?.name.trim() ? "Pipeline name is required." : "You cannot save this pipeline.");
|
||||
return false;
|
||||
}
|
||||
saveInFlight.current = true;
|
||||
const generation = draftSession.current.generation;
|
||||
const context = authorityKey;
|
||||
const isCurrent = () => generation === draftSession.current.generation
|
||||
&& context === saveContext.current && authorityGeneration === saveAuthorityEpoch.current.revision;
|
||||
setSaving(true);
|
||||
setError("");
|
||||
setSuccess("");
|
||||
try {
|
||||
const payload = pipelinePayload(draft);
|
||||
const submitted = structuredClone(draft);
|
||||
const payload = pipelinePayload(submitted);
|
||||
const saved = draft.id && draft.currentRevision
|
||||
? await updateDataflowPipeline(settings, draft.id, {
|
||||
...payload,
|
||||
@@ -327,22 +375,32 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
})
|
||||
: await createDataflowPipeline(settings, payload);
|
||||
const next = draftFromPipeline(saved);
|
||||
setDraft(next);
|
||||
if (!isCurrent() || !draftSession.current.value) {
|
||||
if (generation === draftSession.current.generation) unresolvedSaveGeneration.current = generation;
|
||||
return false;
|
||||
}
|
||||
const reconciled = reconcilePipelineSave(submitted, draftSession.current.value, next);
|
||||
draftSession.current.value = reconciled;
|
||||
setDraftValue(reconciled);
|
||||
setSavedDraft(structuredClone(next));
|
||||
setPipelines((current) => [saved, ...current.filter((item) => item.id !== saved.id)]);
|
||||
setSelectedNodeId((current) => current && next.graph.nodes.some((node) => node.id === current)
|
||||
setSelectedNodeId((current) => current && reconciled.graph.nodes.some((node) => node.id === current)
|
||||
? current
|
||||
: next.graph.nodes[0]?.id ?? null);
|
||||
: reconciled.graph.nodes[0]?.id ?? null);
|
||||
setDiagnostics([]);
|
||||
setSuccess(`Saved revision ${saved.current_revision}.`);
|
||||
return true;
|
||||
const fullySaved = draftFingerprint(reconciled) === draftFingerprint(next);
|
||||
setSuccess(fullySaved ? `Saved revision ${saved.current_revision}.`
|
||||
: "The submitted revision was saved. Newer edits remain unsaved.");
|
||||
// A navigation guard may proceed only if ALL current edits were accepted.
|
||||
return fullySaved;
|
||||
} catch (saveError) {
|
||||
setError(apiErrorMessage(saveError));
|
||||
if (isCurrent()) setError(apiErrorMessage(saveError));
|
||||
return false;
|
||||
} finally {
|
||||
saveInFlight.current = false;
|
||||
setSaving(false);
|
||||
}
|
||||
}, [canEdit, draft, settings]);
|
||||
}, [canEdit, draft, settings, authorityKey, authorityGeneration]);
|
||||
|
||||
useUnsavedDraftGuard({
|
||||
dirty,
|
||||
@@ -391,7 +449,12 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
};
|
||||
|
||||
const updateDraft = (patch: Partial<PipelineDraft>) => {
|
||||
setDraft((current) => current ? { ...current, ...patch } : current);
|
||||
const current = draftSession.current.value;
|
||||
if (current) {
|
||||
const next = { ...current, ...patch };
|
||||
draftSession.current.value = next;
|
||||
setDraftValue(next);
|
||||
}
|
||||
setSuccess("");
|
||||
};
|
||||
|
||||
@@ -411,10 +474,15 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
setSuccess("");
|
||||
try {
|
||||
const response = await validateDataflowPipeline(settings, draft.editorMode === "sql"
|
||||
? { graph: draft.graph, sql_text: draft.sqlText, source_nodes: sourceNodes(draft.graph) }
|
||||
: { graph: draft.graph });
|
||||
? { pipeline_id: draft.id, graph: draft.graph, sql_text: draft.sqlText, source_nodes: sourceNodes(draft.graph) }
|
||||
: { pipeline_id: draft.id, graph: draft.graph });
|
||||
setDiagnostics(response.diagnostics);
|
||||
if (response.valid) setSuccess("Pipeline definition is valid.");
|
||||
if (response.valid) {
|
||||
if (response.graph && draft.editorMode === "graph") {
|
||||
updateDraft({ graph: response.graph });
|
||||
}
|
||||
setSuccess("Pipeline definition is valid.");
|
||||
}
|
||||
setResultOpen(true);
|
||||
setResultTab("diagnostics");
|
||||
} catch (validationError) {
|
||||
@@ -599,6 +667,22 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
|
||||
return (
|
||||
<WorkspaceFrame as="main" height="viewport" surface="plain" className="dataflow-page" label="Dataflow workspace">
|
||||
<WorkspaceActionBar
|
||||
title="Pipelines"
|
||||
titleHelp={<DocumentationHelpLink reference={DATAFLOW_DOCUMENTATION} />}
|
||||
scope="workspace"
|
||||
variant="collection"
|
||||
refreshable
|
||||
reloadAction={{ onReload: () => void loadPipelines(draft?.id), loading, label: "Refresh pipelines" }}
|
||||
createAction={<IconButton
|
||||
label="New pipeline"
|
||||
icon={<Plus size={17} />}
|
||||
variant="primary"
|
||||
onClick={createNew}
|
||||
disabled={!canWrite}
|
||||
disabledReason={!canWrite ? DATAFLOW_I18N.writeReason : undefined}
|
||||
/>}
|
||||
/>
|
||||
<WorkspaceLayout
|
||||
variant="split"
|
||||
primarySize="compact"
|
||||
@@ -609,21 +693,6 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
contentLabel="Pipeline editor"
|
||||
contentClassName="dataflow-workspace"
|
||||
primary={<>
|
||||
<WorkspaceActionBar
|
||||
scope="collection-pane"
|
||||
variant="collection"
|
||||
refreshable
|
||||
reloadAction={{ onReload: () => void loadPipelines(draft?.id), loading, label: "Refresh pipelines" }}
|
||||
contextActions={<strong>Pipelines</strong>}
|
||||
createAction={<IconButton
|
||||
label="New pipeline"
|
||||
icon={<Plus size={17} />}
|
||||
variant="primary"
|
||||
onClick={createNew}
|
||||
disabled={!canWrite}
|
||||
disabledReason={!canWrite ? DATAFLOW_I18N.writeReason : undefined}
|
||||
/>}
|
||||
/>
|
||||
<FilterBar surface="panel">
|
||||
<input
|
||||
type="search"
|
||||
@@ -691,7 +760,6 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
<option value="archived">Archived</option>
|
||||
</select>
|
||||
</div>}
|
||||
helpAction={<DocumentationHelpLink reference={DATAFLOW_DOCUMENTATION} />}
|
||||
primaryActions={<div className="dataflow-command-bar">
|
||||
<SegmentedControl<EditorMode>
|
||||
ariaLabel="Pipeline editor mode"
|
||||
@@ -766,6 +834,26 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
}
|
||||
/>
|
||||
) : null}
|
||||
{draft.governance?.derived_from_pipeline_id ? (
|
||||
<IconButton
|
||||
label="Review source update"
|
||||
icon={<GitCompareArrows size={16} />}
|
||||
variant="ghost"
|
||||
onClick={() => setRebaseOpen(true)}
|
||||
disabled={!canRebase}
|
||||
disabledReason={
|
||||
dirty
|
||||
? DATAFLOW_I18N.saveFirst
|
||||
: !canEdit
|
||||
? editBlockedReason
|
||||
: !draft.governance.source_available
|
||||
? "The source definition is no longer available."
|
||||
: !draft.governance.update_available
|
||||
? "This copy already pins the current source revision."
|
||||
: undefined
|
||||
}
|
||||
/>
|
||||
) : null}
|
||||
{draft.id ? (
|
||||
<IconButton
|
||||
label="Automation triggers"
|
||||
@@ -780,6 +868,8 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
destructiveActions={draft.id ? (
|
||||
<IconButton
|
||||
label="Delete pipeline"
|
||||
helpContextId="dataflow.action.delete"
|
||||
helpModuleId="dataflow"
|
||||
icon={<Trash2 size={16} />}
|
||||
variant="danger"
|
||||
onClick={() => setDeleteOpen(true)}
|
||||
@@ -899,6 +989,10 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
<NodeInspector
|
||||
node={selectedNode}
|
||||
nodeLibrary={nodeLibrary}
|
||||
reusablePipelines={pipelines.filter((pipeline) => (
|
||||
pipeline.id !== draft.id
|
||||
&& pipeline.governance.actions.reuse?.allowed
|
||||
))}
|
||||
sources={sources}
|
||||
sourceCatalogueAvailable={sourceCatalogueAvailable}
|
||||
readOnly={!canEdit}
|
||||
@@ -1060,6 +1154,32 @@ export default function DataflowPage({ settings, auth }: { settings: ApiSettings
|
||||
setSuccess("Created a pinned scoped copy.");
|
||||
}}
|
||||
/>
|
||||
<RebasePipelineDialog
|
||||
open={rebaseOpen}
|
||||
settings={settings}
|
||||
pipeline={draft?.id && draft.currentRevision && draft.governance ? {
|
||||
id: draft.id,
|
||||
name: draft.name,
|
||||
currentRevision: draft.currentRevision,
|
||||
governance: draft.governance
|
||||
} : null}
|
||||
onClose={() => setRebaseOpen(false)}
|
||||
onRebased={(pipeline) => {
|
||||
const next = draftFromPipeline(pipeline);
|
||||
setPipelines((current) => [
|
||||
pipeline,
|
||||
...current.filter((item) => item.id !== pipeline.id)
|
||||
]);
|
||||
setDraft(next);
|
||||
setSavedDraft(structuredClone(next));
|
||||
setSelectedNodeId(next.graph.nodes[0]?.id ?? null);
|
||||
setRebaseOpen(false);
|
||||
setPreview(null);
|
||||
setDiagnostics([]);
|
||||
setNodeDiagnostics([]);
|
||||
setSuccess(`Adopted source revision ${pipeline.governance.derived_from_revision} as draft revision ${pipeline.current_revision}.`);
|
||||
}}
|
||||
/>
|
||||
<DataflowTriggersDialog
|
||||
open={triggersOpen}
|
||||
settings={settings}
|
||||
@@ -1231,6 +1351,20 @@ function DefinitionSettingsDialog({
|
||||
{draft.governance.derived_from_revision}
|
||||
</span>
|
||||
<code>{draft.governance.derived_from_hash}</code>
|
||||
{!draft.governance.source_available ? (
|
||||
<StatusBadge status="warning" label="Source unavailable" />
|
||||
) : draft.governance.update_available ? (
|
||||
<>
|
||||
<StatusBadge status="warning" label="Source update available" />
|
||||
<span>
|
||||
{draft.governance.source_name ?? "Source definition"}
|
||||
{" · revision "}
|
||||
{draft.governance.source_current_revision}
|
||||
</span>
|
||||
</>
|
||||
) : (
|
||||
<StatusBadge status="success" label="Source revision current" />
|
||||
)}
|
||||
</ContentSection>
|
||||
) : null}
|
||||
{provenance.length ? (
|
||||
@@ -1430,6 +1564,153 @@ function DerivePipelineDialog({
|
||||
);
|
||||
}
|
||||
|
||||
function RebasePipelineDialog({
|
||||
open,
|
||||
settings,
|
||||
pipeline,
|
||||
onClose,
|
||||
onRebased
|
||||
}: {
|
||||
open: boolean;
|
||||
settings: ApiSettings;
|
||||
pipeline: {
|
||||
id: string;
|
||||
name: string;
|
||||
currentRevision: number;
|
||||
governance: Pipeline["governance"];
|
||||
} | null;
|
||||
onClose: () => void;
|
||||
onRebased: (pipeline: Pipeline) => void;
|
||||
}) {
|
||||
const { requestDiscard } = useUnsavedChanges();
|
||||
const [reason, setReason] = useState("");
|
||||
const [busy, setBusy] = useState(false);
|
||||
const [error, setError] = useState("");
|
||||
const governance = pipeline?.governance;
|
||||
const sourceRevision = governance?.source_current_revision ?? null;
|
||||
const sourceHash = governance?.source_current_hash ?? null;
|
||||
const dirty = Boolean(open && reason);
|
||||
|
||||
useEffect(() => {
|
||||
if (!open) return;
|
||||
setReason("");
|
||||
setError("");
|
||||
}, [open, pipeline?.id, sourceRevision]);
|
||||
|
||||
const resetDraft = () => {
|
||||
setReason("");
|
||||
setError("");
|
||||
};
|
||||
|
||||
const rebase = async (): Promise<boolean> => {
|
||||
if (
|
||||
!pipeline
|
||||
|| !sourceRevision
|
||||
|| !sourceHash
|
||||
|| !reason.trim()
|
||||
|| !governance?.update_available
|
||||
) return false;
|
||||
setBusy(true);
|
||||
setError("");
|
||||
try {
|
||||
onRebased(await rebaseDataflowPipeline(settings, pipeline.id, {
|
||||
expected_revision: pipeline.currentRevision,
|
||||
source_revision: sourceRevision,
|
||||
source_hash: sourceHash,
|
||||
reason: reason.trim()
|
||||
}));
|
||||
return true;
|
||||
} catch (rebaseError) {
|
||||
setError(apiErrorMessage(rebaseError));
|
||||
return false;
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
};
|
||||
|
||||
useUnsavedDraftGuard({
|
||||
dirty,
|
||||
title: "Unapplied source update",
|
||||
message: "Apply the reviewed source update or discard the review reason before leaving.",
|
||||
onSave: rebase,
|
||||
onDiscard: resetDraft
|
||||
});
|
||||
|
||||
const close = () => {
|
||||
if (busy) return;
|
||||
if (dirty) requestDiscard(onClose);
|
||||
else onClose();
|
||||
};
|
||||
|
||||
return (
|
||||
<Dialog
|
||||
open={open}
|
||||
title="Review source update"
|
||||
className="dataflow-definition-dialog"
|
||||
closeDisabled={busy}
|
||||
onClose={close}
|
||||
footer={(
|
||||
<>
|
||||
<Button onClick={close} disabled={busy}>Cancel</Button>
|
||||
<Button
|
||||
variant="primary"
|
||||
onClick={() => void rebase()}
|
||||
disabled={
|
||||
busy
|
||||
|| !pipeline
|
||||
|| !sourceRevision
|
||||
|| !sourceHash
|
||||
|| !reason.trim()
|
||||
|| !governance?.update_available
|
||||
}
|
||||
>
|
||||
<GitCompareArrows size={16} /> Adopt source revision
|
||||
</Button>
|
||||
</>
|
||||
)}
|
||||
>
|
||||
<div className="dataflow-definition-fields">
|
||||
{error ? <DismissibleAlert tone="danger" resetKey={error}>{error}</DismissibleAlert> : null}
|
||||
<ContentSection spacing="none" surface="subtle" density="compact" layout="stack">
|
||||
<strong>{governance?.source_name ?? "Source definition"}</strong>
|
||||
<span>
|
||||
Pinned revision {governance?.derived_from_revision ?? "—"}
|
||||
{" → source revision "}
|
||||
{sourceRevision ?? "—"}
|
||||
</span>
|
||||
{sourceHash ? <code>{sourceHash}</code> : null}
|
||||
</ContentSection>
|
||||
<DismissibleAlert
|
||||
tone="warning"
|
||||
resetKey={`${pipeline?.id ?? "none"}:${sourceRevision ?? "none"}`}
|
||||
>
|
||||
Adopting the update replaces the copy's current graph with the exact
|
||||
reviewed source revision and returns the copy to draft. Existing
|
||||
revisions, run evidence and rebase provenance remain immutable.
|
||||
</DismissibleAlert>
|
||||
<FormField
|
||||
label="Review reason"
|
||||
help="Record what was reviewed and why this source revision is appropriate for the scoped copy."
|
||||
interfaceId="dataflow.field.rebase-reason"
|
||||
helpContextId="dataflow.field.rebase-reason"
|
||||
helpModuleId="dataflow"
|
||||
helpTopicId="dataflow.reference.fields-and-consequences"
|
||||
documentation={DATAFLOW_FIELDS_DOCUMENTATION}
|
||||
>
|
||||
<textarea
|
||||
value={reason}
|
||||
onChange={(event) => setReason(event.target.value)}
|
||||
rows={4}
|
||||
maxLength={4000}
|
||||
disabled={busy}
|
||||
required
|
||||
/>
|
||||
</FormField>
|
||||
</div>
|
||||
</Dialog>
|
||||
);
|
||||
}
|
||||
|
||||
function DataflowTriggersDialog({
|
||||
open,
|
||||
settings,
|
||||
@@ -1672,6 +1953,7 @@ function DataflowTriggersDialog({
|
||||
<Dialog
|
||||
open={open}
|
||||
title={`Automation · ${pipeline?.name ?? "pipeline"}`}
|
||||
titleHelp={<DocumentationHelpLink reference={DATAFLOW_FIELDS_DOCUMENTATION} />}
|
||||
className="dataflow-triggers-dialog"
|
||||
closeDisabled={busy}
|
||||
onClose={close}
|
||||
@@ -1728,7 +2010,6 @@ function DataflowTriggersDialog({
|
||||
{!busy && !triggers.length ? <small>No triggers configured</small> : null}
|
||||
</div>
|
||||
<div className="dataflow-trigger-form">
|
||||
<DocumentationHelpLink reference={DATAFLOW_FIELDS_DOCUMENTATION} />
|
||||
{error ? <DismissibleAlert tone="danger" resetKey={error}>{error}</DismissibleAlert> : null}
|
||||
<FormField label="Name" documentation={DATAFLOW_FIELDS_DOCUMENTATION}>
|
||||
<input disabled={!editable} value={name} onChange={(event) => setName(event.target.value)} />
|
||||
@@ -1812,6 +2093,8 @@ function DataflowTriggersDialog({
|
||||
{selected.last_error ? <small className="is-error">{selected.last_error}</small> : null}
|
||||
<Button
|
||||
variant="danger"
|
||||
helpContextId="dataflow.action.delete"
|
||||
helpModuleId="dataflow"
|
||||
onClick={() => requestNavigation(() => setDeleteCandidate(selected))}
|
||||
disabled={busy || !editable}
|
||||
disabledReason={busy ? DATAFLOW_I18N.working : !editable ? DATAFLOW_I18N.writeReason : undefined}
|
||||
@@ -2030,6 +2313,7 @@ function RunPipelineDialog({
|
||||
<Dialog
|
||||
open={open}
|
||||
title={`Run ${pipeline?.name ?? "pipeline"}`}
|
||||
titleHelp={<DocumentationHelpLink reference={DATAFLOW_RUN_DOCUMENTATION} />}
|
||||
className="dataflow-run-dialog"
|
||||
onClose={() => {
|
||||
if (!busy) {
|
||||
@@ -2066,7 +2350,6 @@ function RunPipelineDialog({
|
||||
</DismissibleAlert>
|
||||
) : null}
|
||||
<div className="dataflow-run-controls">
|
||||
<DocumentationHelpLink reference={DATAFLOW_RUN_DOCUMENTATION} />
|
||||
<SegmentedControl<RunMode>
|
||||
ariaLabel="Run output"
|
||||
options={[
|
||||
@@ -2287,6 +2570,7 @@ function SourceSnapshotDialog({
|
||||
const [rowsText, setRowsText] = useState("[]");
|
||||
const [csvText, setCsvText] = useState("");
|
||||
const [delimiter, setDelimiter] = useState(",");
|
||||
const [csvValueMode, setCsvValueMode] = useState<"text" | "legacy_typed">("text");
|
||||
const [fileInputKey, setFileInputKey] = useState(0);
|
||||
const [busy, setBusy] = useState(false);
|
||||
const [error, setError] = useState("");
|
||||
@@ -2300,6 +2584,7 @@ function SourceSnapshotDialog({
|
||||
|| rowsText !== "[]"
|
||||
|| csvText !== ""
|
||||
|| delimiter !== ","
|
||||
|| csvValueMode !== "text"
|
||||
)
|
||||
);
|
||||
|
||||
@@ -2311,6 +2596,7 @@ function SourceSnapshotDialog({
|
||||
setRowsText("[]");
|
||||
setCsvText("");
|
||||
setDelimiter(",");
|
||||
setCsvValueMode("text");
|
||||
setFileInputKey((current) => current + 1);
|
||||
setError("");
|
||||
};
|
||||
@@ -2346,7 +2632,7 @@ function SourceSnapshotDialog({
|
||||
description: description.trim() || null,
|
||||
...(format === "json"
|
||||
? { format, rows }
|
||||
: { format, csv_text: csvText, delimiter })
|
||||
: { format, csv_text: csvText, delimiter, csv_value_mode: csvValueMode })
|
||||
});
|
||||
onCreated(source);
|
||||
return true;
|
||||
@@ -2451,6 +2737,16 @@ function SourceSnapshotDialog({
|
||||
<option value="|">Pipe</option>
|
||||
</select>
|
||||
</FormField>
|
||||
<FormField label="CSV values" documentation={DATAFLOW_FIELDS_DOCUMENTATION}>
|
||||
<select
|
||||
value={csvValueMode}
|
||||
onChange={(event) => setCsvValueMode(event.target.value as "text" | "legacy_typed")}
|
||||
disabled={busy}
|
||||
>
|
||||
<option value="text">Preserve text (no automatic conversion)</option>
|
||||
<option value="legacy_typed">Infer types (legacy)</option>
|
||||
</select>
|
||||
</FormField>
|
||||
<FormField label="CSV data" documentation={DATAFLOW_FIELDS_DOCUMENTATION}>
|
||||
<textarea
|
||||
className="dataflow-json-editor"
|
||||
|
||||
@@ -9,6 +9,7 @@ import {
|
||||
} from "@govoplan/core-webui";
|
||||
import type {
|
||||
NodeTypeDefinition,
|
||||
Pipeline,
|
||||
PipelineGraphNode,
|
||||
TabularSource
|
||||
} from "../../api/dataflow";
|
||||
@@ -28,6 +29,7 @@ function NodeFormField({ documentation, ...props }: NodeFormFieldProps) {
|
||||
type NodeInspectorProps = {
|
||||
node: PipelineGraphNode | null;
|
||||
nodeLibrary: NodeTypeDefinition[];
|
||||
reusablePipelines: Pipeline[];
|
||||
sources: TabularSource[];
|
||||
sourceCatalogueAvailable: boolean;
|
||||
readOnly: boolean;
|
||||
@@ -41,6 +43,7 @@ type NodeInspectorProps = {
|
||||
export default function NodeInspector({
|
||||
node,
|
||||
nodeLibrary,
|
||||
reusablePipelines,
|
||||
sources,
|
||||
sourceCatalogueAvailable,
|
||||
readOnly,
|
||||
@@ -57,7 +60,6 @@ export default function NodeInspector({
|
||||
const [rankSortText, setRankSortText] = useState("");
|
||||
const [rulesText, setRulesText] = useState("");
|
||||
const [parametersText, setParametersText] = useState("");
|
||||
const [subflowGraphText, setSubflowGraphText] = useState("");
|
||||
const [localError, setLocalError] = useState("");
|
||||
|
||||
useEffect(() => {
|
||||
@@ -68,7 +70,6 @@ export default function NodeInspector({
|
||||
setRankSortText(node ? sortFieldsToText(node.config.order_by) : "");
|
||||
setRulesText(node ? JSON.stringify(node.config.rules ?? [], null, 2) : "");
|
||||
setParametersText(node ? JSON.stringify(node.config.parameters ?? {}, null, 2) : "");
|
||||
setSubflowGraphText(node ? JSON.stringify(node.config.graph ?? {}, null, 2) : "");
|
||||
setLocalError("");
|
||||
}, [node?.id]);
|
||||
|
||||
@@ -84,6 +85,9 @@ export default function NodeInspector({
|
||||
}
|
||||
|
||||
const definition = nodeLibrary.find((item) => item.type === node.type);
|
||||
const selectedReusable = reusablePipelines.find(
|
||||
(item) => `pipeline:${item.id}` === textValue(node.config.template_ref)
|
||||
);
|
||||
const updateConfig = (patch: Record<string, unknown>) => {
|
||||
onChange({ ...node, config: { ...node.config, ...patch } });
|
||||
};
|
||||
@@ -178,6 +182,8 @@ export default function NodeInspector({
|
||||
/>
|
||||
<IconButton
|
||||
label="Delete node"
|
||||
helpContextId="dataflow.action.delete"
|
||||
helpModuleId="dataflow"
|
||||
icon={<Trash2 size={16} />}
|
||||
variant="danger"
|
||||
onClick={() => onDelete(node.id)}
|
||||
@@ -263,16 +269,33 @@ export default function NodeInspector({
|
||||
</>
|
||||
) : null}
|
||||
{node.type === "source.inline" ? (
|
||||
<NodeFormField label="Rows">
|
||||
<textarea
|
||||
className="dataflow-json-editor"
|
||||
value={rowsText}
|
||||
onChange={(event) => setRowsText(event.target.value)}
|
||||
onBlur={commitRows}
|
||||
spellCheck={false}
|
||||
disabled={readOnly}
|
||||
/>
|
||||
</NodeFormField>
|
||||
<>
|
||||
<NodeFormField label="Rows">
|
||||
<textarea
|
||||
className="dataflow-json-editor"
|
||||
value={rowsText}
|
||||
onChange={(event) => setRowsText(event.target.value)}
|
||||
onBlur={commitRows}
|
||||
spellCheck={false}
|
||||
disabled={readOnly}
|
||||
/>
|
||||
</NodeFormField>
|
||||
<NodeFormField
|
||||
label="Reusable input binding"
|
||||
help="A reusable definition must mark exactly one typed inline source as the rows supplied by its caller."
|
||||
interfaceId="dataflow.field.reusable-input-binding"
|
||||
helpContextId="dataflow.field.reusable-input-binding"
|
||||
helpModuleId="dataflow"
|
||||
helpTopicId="dataflow.reference.nodes-and-expressions"
|
||||
>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={node.config.input_binding === true}
|
||||
onChange={(event) => updateConfig({ input_binding: event.target.checked })}
|
||||
disabled={readOnly}
|
||||
/>
|
||||
</NodeFormField>
|
||||
</>
|
||||
) : null}
|
||||
{node.type === "filter" ? (
|
||||
<>
|
||||
@@ -783,19 +806,62 @@ export default function NodeInspector({
|
||||
) : null}
|
||||
{node.type === "subflow" ? (
|
||||
<>
|
||||
<NodeFormField label="Template reference">
|
||||
<input
|
||||
<NodeFormField
|
||||
label="Reusable definition"
|
||||
interfaceId="dataflow.field.subflow-reference"
|
||||
helpContextId="dataflow.field.subflow-reference"
|
||||
helpModuleId="dataflow"
|
||||
helpTopicId="dataflow.reference.nodes-and-expressions"
|
||||
>
|
||||
<select
|
||||
value={textValue(node.config.template_ref)}
|
||||
onChange={(event) => updateConfig({ template_ref: event.target.value })}
|
||||
onChange={(event) => {
|
||||
const selected = reusablePipelines.find(
|
||||
(item) => `pipeline:${item.id}` === event.target.value
|
||||
);
|
||||
updateConfig({
|
||||
template_ref: event.target.value,
|
||||
template_version: selected ? String(selected.current_revision) : "",
|
||||
template_hash: "",
|
||||
graph: { schema_version: 1, nodes: [], edges: [] },
|
||||
input_schema: [],
|
||||
output_schema: []
|
||||
});
|
||||
}}
|
||||
disabled={readOnly}
|
||||
/>
|
||||
>
|
||||
<option value="">Choose a reusable definition</option>
|
||||
{reusablePipelines.map((pipeline) => (
|
||||
<option key={pipeline.id} value={`pipeline:${pipeline.id}`}>
|
||||
{pipeline.name} · revision {pipeline.current_revision}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
</NodeFormField>
|
||||
<NodeFormField label="Template version">
|
||||
<input
|
||||
<NodeFormField
|
||||
label="Template version"
|
||||
interfaceId="dataflow.field.subflow-revision"
|
||||
helpContextId="dataflow.field.subflow-revision"
|
||||
helpModuleId="dataflow"
|
||||
helpTopicId="dataflow.reference.nodes-and-expressions"
|
||||
>
|
||||
<select
|
||||
value={textValue(node.config.template_version)}
|
||||
onChange={(event) => updateConfig({ template_version: event.target.value })}
|
||||
disabled={readOnly}
|
||||
/>
|
||||
>
|
||||
{textValue(node.config.template_version)
|
||||
&& textValue(node.config.template_version) !== String(selectedReusable?.current_revision ?? "") ? (
|
||||
<option value={textValue(node.config.template_version)}>
|
||||
Pinned revision {textValue(node.config.template_version)}
|
||||
</option>
|
||||
) : null}
|
||||
{selectedReusable ? (
|
||||
<option value={String(selectedReusable.current_revision)}>
|
||||
Current revision {selectedReusable.current_revision}
|
||||
</option>
|
||||
) : null}
|
||||
</select>
|
||||
</NodeFormField>
|
||||
<NodeFormField label="Parameters">
|
||||
<textarea
|
||||
@@ -807,16 +873,13 @@ export default function NodeInspector({
|
||||
disabled={readOnly}
|
||||
/>
|
||||
</NodeFormField>
|
||||
<NodeFormField label="Pinned graph">
|
||||
<textarea
|
||||
className="dataflow-json-editor"
|
||||
value={subflowGraphText}
|
||||
onChange={(event) => setSubflowGraphText(event.target.value)}
|
||||
onBlur={() => commitJsonConfig("graph", subflowGraphText, "object")}
|
||||
spellCheck={false}
|
||||
disabled={readOnly}
|
||||
/>
|
||||
</NodeFormField>
|
||||
{Array.isArray(node.config.input_schema) && Array.isArray(node.config.output_schema) ? (
|
||||
<NodeFormField label="Pinned contracts">
|
||||
<code>
|
||||
{node.config.input_schema.length} input · {node.config.output_schema.length} output fields
|
||||
</code>
|
||||
</NodeFormField>
|
||||
) : null}
|
||||
</>
|
||||
) : null}
|
||||
</div>
|
||||
|
||||
@@ -272,7 +272,7 @@ export const FALLBACK_NODE_LIBRARY: NodeTypeDefinition[] = [
|
||||
"transform",
|
||||
"Transform",
|
||||
"Reusable subflow",
|
||||
"Run a pinned parameterized template snapshot.",
|
||||
"Run a Policy-authorized, server-resolved immutable definition revision.",
|
||||
"boxes",
|
||||
input,
|
||||
output,
|
||||
|
||||
+18
@@ -0,0 +1,18 @@
|
||||
import type { PipelineDraft } from "./model";
|
||||
|
||||
/** Reconcile one accepted save, never structurally merge/reorder graph data.
|
||||
* Fields edited since submission stay local; identity, revision and authority
|
||||
* always come from the accepted server response.
|
||||
*/
|
||||
export function reconcilePipelineSave(
|
||||
submitted: PipelineDraft, current: PipelineDraft, accepted: PipelineDraft
|
||||
): PipelineDraft {
|
||||
const result = { ...current, ...accepted };
|
||||
for (const key of Object.keys(submitted) as Array<keyof PipelineDraft>) {
|
||||
if (key === "id" || key === "currentRevision" || key === "governance") continue;
|
||||
if (JSON.stringify(current[key]) !== JSON.stringify(submitted[key])) {
|
||||
Object.assign(result, { [key]: current[key] });
|
||||
}
|
||||
}
|
||||
return result;
|
||||
}
|
||||
@@ -1,6 +1,11 @@
|
||||
import type { PlatformTranslations } from "@govoplan/core-webui";
|
||||
|
||||
const en = {
|
||||
"A prior save completed after authorization changed. Reload and review the server revision before saving again.": "A prior save completed after authorization changed. Reload and review the server revision before saving again.",
|
||||
"The submitted revision was saved. Newer edits remain unsaved.": "The submitted revision was saved. Newer edits remain unsaved.",
|
||||
"CSV values": "CSV values",
|
||||
"Preserve text (no automatic conversion)": "Preserve text (no automatic conversion)",
|
||||
"Infer types (legacy)": "Infer types (legacy)",
|
||||
"i18n:govoplan-dataflow.dataflow": "Dataflow",
|
||||
"i18n:govoplan-dataflow.library": "Pipeline library",
|
||||
"i18n:govoplan-dataflow.graph": "Graph editor",
|
||||
@@ -56,6 +61,25 @@ const en = {
|
||||
"New pipeline": "New pipeline",
|
||||
"Definition settings": "Definition settings",
|
||||
"Reuse as scoped copy": "Reuse as scoped copy",
|
||||
"Review source update": "Review source update",
|
||||
"Adopt source revision": "Adopt source revision",
|
||||
"Source unavailable": "Source unavailable",
|
||||
"Source update available": "Source update available",
|
||||
"Source definition": "Source definition",
|
||||
"Source revision current": "Source revision current",
|
||||
"Unapplied source update": "Unapplied source update",
|
||||
"Apply the reviewed source update or discard the review reason before leaving.": "Apply the reviewed source update or discard the review reason before leaving.",
|
||||
"The source definition is no longer available.": "The source definition is no longer available.",
|
||||
"This copy already pins the current source revision.": "This copy already pins the current source revision.",
|
||||
"Adopting the update replaces the copy's current graph with the exact reviewed source revision and returns the copy to draft. Existing revisions, run evidence and rebase provenance remain immutable.": "Adopting the update replaces the copy's current graph with the exact reviewed source revision and returns the copy to draft. Existing revisions, run evidence and rebase provenance remain immutable.",
|
||||
"Review reason": "Review reason",
|
||||
"Record what was reviewed and why this source revision is appropriate for the scoped copy.": "Record what was reviewed and why this source revision is appropriate for the scoped copy.",
|
||||
"Reusable input binding": "Reusable input binding",
|
||||
"A reusable definition must mark exactly one typed inline source as the rows supplied by its caller.": "A reusable definition must mark exactly one typed inline source as the rows supplied by its caller.",
|
||||
"Reusable definition": "Reusable definition",
|
||||
"Choose a reusable definition": "Choose a reusable definition",
|
||||
"Template version": "Template version",
|
||||
"Pinned contracts": "Pinned contracts",
|
||||
"Automation triggers": "Automation triggers",
|
||||
"Discard changes": "Discard changes",
|
||||
"Delete pipeline": "Delete pipeline",
|
||||
@@ -81,6 +105,11 @@ const en = {
|
||||
} as const;
|
||||
|
||||
const de: Record<keyof typeof en, string> = {
|
||||
"A prior save completed after authorization changed. Reload and review the server revision before saving again.": "Ein vorheriger Speichervorgang wurde nach einer Berechtigungsänderung abgeschlossen. Vor erneutem Speichern neu laden und die Serverrevision prüfen.",
|
||||
"The submitted revision was saved. Newer edits remain unsaved.": "Die übermittelte Revision wurde gespeichert. Neuere Änderungen sind noch ungespeichert.",
|
||||
"CSV values": "CSV-Werte",
|
||||
"Preserve text (no automatic conversion)": "Text erhalten (keine automatische Umwandlung)",
|
||||
"Infer types (legacy)": "Typen ableiten (bisheriges Verhalten)",
|
||||
"i18n:govoplan-dataflow.dataflow": "Datenfluss",
|
||||
"i18n:govoplan-dataflow.library": "Datenflussbibliothek",
|
||||
"i18n:govoplan-dataflow.graph": "Graph-Editor",
|
||||
@@ -136,6 +165,25 @@ const de: Record<keyof typeof en, string> = {
|
||||
"New pipeline": "Neuer Datenfluss",
|
||||
"Definition settings": "Definitionseinstellungen",
|
||||
"Reuse as scoped copy": "Als eingegrenzte Kopie verwenden",
|
||||
"Review source update": "Aktualisierung der Quelle prüfen",
|
||||
"Adopt source revision": "Quellrevision übernehmen",
|
||||
"Source unavailable": "Quelle nicht verfügbar",
|
||||
"Source update available": "Aktualisierung der Quelle verfügbar",
|
||||
"Source definition": "Quelldefinition",
|
||||
"Source revision current": "Quellrevision aktuell",
|
||||
"Unapplied source update": "Nicht übernommene Quellenaktualisierung",
|
||||
"Apply the reviewed source update or discard the review reason before leaving.": "Übernehmen Sie die geprüfte Quellenaktualisierung oder verwerfen Sie die Prüfbegründung, bevor Sie den Dialog verlassen.",
|
||||
"The source definition is no longer available.": "Die Quelldefinition ist nicht mehr verfügbar.",
|
||||
"This copy already pins the current source revision.": "Diese Kopie ist bereits an die aktuelle Quellrevision gebunden.",
|
||||
"Adopting the update replaces the copy's current graph with the exact reviewed source revision and returns the copy to draft. Existing revisions, run evidence and rebase provenance remain immutable.": "Die Übernahme ersetzt den aktuellen Graphen der Kopie durch die exakt geprüfte Quellrevision und setzt die Kopie auf Entwurf zurück. Bestehende Revisionen, Ausführungsnachweise und die Herkunft der Übernahme bleiben unveränderlich.",
|
||||
"Review reason": "Prüfbegründung",
|
||||
"Record what was reviewed and why this source revision is appropriate for the scoped copy.": "Dokumentieren Sie, was geprüft wurde und warum diese Quellrevision für die eingegrenzte Kopie geeignet ist.",
|
||||
"Reusable input binding": "Wiederverwendbare Eingabebindung",
|
||||
"A reusable definition must mark exactly one typed inline source as the rows supplied by its caller.": "Eine wiederverwendbare Definition muss genau eine typisierte Inline-Quelle als die vom Aufrufer gelieferten Zeilen kennzeichnen.",
|
||||
"Reusable definition": "Wiederverwendbare Definition",
|
||||
"Choose a reusable definition": "Wiederverwendbare Definition auswählen",
|
||||
"Template version": "Vorlagenversion",
|
||||
"Pinned contracts": "Gebundene Verträge",
|
||||
"Automation triggers": "Automatisierungsauslöser",
|
||||
"Discard changes": "Änderungen verwerfen",
|
||||
"Delete pipeline": "Datenfluss löschen",
|
||||
|
||||
Reference in New Issue
Block a user