Files
govoplan-templates/docs/TEMPLATE_BOUNDARY.md
T

2.6 KiB

Template Module Boundary

govoplan-templates owns reusable render definitions and immutable render evidence. Callers own data selection, approval, delivery, and lifecycle state.

Owned Concepts

  • scoped template definitions and immutable revisions;
  • template type, usage, locale, required-field contracts, output profiles, and page/media hints;
  • safe HTML/text bodies and deterministic token substitution;
  • draft preview and published final rendering;
  • template, input, renderer, and output hashes plus item/page counts and diagnostics; and
  • bounded fallback payloads when no artifact store is available.

The implemented printable types are label, label_sheet, envelope, serial_letter, form_letter, and list_layout. email and generic use the same contract while preserving their explicit usage.

Consumer Boundary

Templates never imports Addresses, Distribution Lists, Campaign, Files, Mail, Reporting, Forms, or Workflow internals. Consumers discover templates.catalog and templates.renderer through Core and submit plain provider-neutral DTOs. The supplied input_snapshot records a stable source reference; Templates does not fetch or silently refresh that source.

Files optionally implements files.artifact_store. A final render can request managed persistence through that contract. If Files is absent, incompatible, or unauthorized, the result carries a warning and remains available through a 5 MiB bounded Templates download. Managed output is not duplicated in the Templates payload column.

Safety And Determinism

  • backend sanitization removes scripts, styles, active embeds, unsafe links, event handlers, and undeclared attributes;
  • substituted values are HTML escaped;
  • output is limited to 5,000 items and 5 MiB;
  • final output requires a published revision and idempotency key;
  • reusing an idempotency key with changed input is rejected;
  • every render pins the immutable definition hash and canonical input hash;
  • final artifacts contain hashes and references, not credentials or plaintext secrets in provenance; and
  • browser/OS printing from deterministic HTML is the baseline. PDF conversion and managed printer delivery belong to future connector adapters.

Recovery

Template definitions, revisions, render evidence, and bounded output are in the shared database and therefore follow platform backup and restore. Managed Files artifacts follow Files recovery. Retiring the module is destructive only after the installer captures a database snapshot; consumers retain pinned hashes and must diagnose the now-unavailable provider.