49 lines
2.6 KiB
Markdown
49 lines
2.6 KiB
Markdown
# govoplan-portal
|
|
|
|
<!-- govoplan-repository-type:start -->
|
|
**Repository type:** module (domain).
|
|
<!-- govoplan-repository-type:end -->
|
|
|
|
The service-directory route, state, blocker, and accessibility mapping is
|
|
recorded in
|
|
[`docs/INTERFACE_PATTERN_MIGRATION.md`](docs/INTERFACE_PATTERN_MIGRATION.md).
|
|
|
|
Portal owns service discovery, presentation, and channel entry. Its
|
|
`portal.service_directory` capability projects provider-owned, versioned
|
|
service definitions into available, explainably unavailable, or undiscoverable
|
|
entries. It does not persist the institutional service promise or import Cases,
|
|
Forms, Workflow, Access, or Policy tables.
|
|
|
|
The capability works in a reduced composition without a Services provider by
|
|
returning an empty directory. When a provider is present, provider-level access
|
|
filtering remains authoritative and Portal adds only presentation-oriented
|
|
availability checks for publication, effective time, audience, module, and
|
|
capability requirements.
|
|
|
|
The tenant-scoped `/api/v1/portal/services` endpoint and `/portal` WebUI expose
|
|
the projection. Audience visibility is derived from trusted principal and
|
|
active function-assignment state on the server.
|
|
|
|
`POST /api/v1/portal/services/{service_id}/launch` re-fetches and re-evaluates
|
|
the exact Service revision before any effect. URL entries return a validated
|
|
redirect. Case, form, and workflow bindings delegate through the optional
|
|
`cases.service_launcher`, `forms_runtime.service_launcher`, and
|
|
`workflow_engine.service_launcher` contracts; each is tenant-bound and
|
|
replay-safe. A missing owner launcher makes the entry explainably unavailable.
|
|
Form launch resolves an exact published `<form-id>/<revision>` and returns the
|
|
owner's Form-instance route rather than persisting values in Portal.
|
|
|
|
The public `/portal/status/:trackingId` surface presents the bounded
|
|
`application_status.projection` owned by Forms Runtime. It supports the
|
|
configured authenticated, short-lived email-link, and permanent-link modes,
|
|
while Portal owns only the accessible presentation and reload/request actions.
|
|
|
|
Portal deliberately does not publish a DSAR provider because it persists no
|
|
service-directory, launch, Postbox, application-status, applicant, or session
|
|
records. Services owns definitions, each launch target owns its effects,
|
|
Postbox owns mailbox data, and Forms Runtime owns status grants and submission
|
|
data. Core and the deployment operator remain responsible for request/security
|
|
logs. This reviewed boundary avoids duplicate or contradictory privacy exports.
|
|
|
|
See [docs/SERVICE_DIRECTORY_CONCEPT.md](docs/SERVICE_DIRECTORY_CONCEPT.md).
|