Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3766e26377 | ||
|
|
6c2b36af0f | ||
|
|
3f75ca8e48 | ||
|
|
a886a9b3de | ||
|
|
fe83290d56 | ||
|
|
c50f699399 | ||
|
|
59b45a0829 | ||
|
|
861abcc573 | ||
|
|
5e995fed88 | ||
|
|
41ca242004 | ||
|
|
85caa8d337 | ||
|
|
64640327ae | ||
|
|
cc7c2a91ee | ||
|
|
7c92565d9d |
@@ -72,6 +72,23 @@ Each WebUI module should be able to announce:
|
||||
The contract references surfaces. It does not permit Core or a product package
|
||||
to import their implementation.
|
||||
|
||||
The first versioned `product_surfaces` slice is now implemented in Core. It
|
||||
binds a stable product identity and entry path to one or more owner routes,
|
||||
View surfaces, presentations, capabilities, search sources, help contexts and
|
||||
documentation topics. It also carries standard unavailable/degraded
|
||||
explanations and migration aliases. Mail and Postbox contribute the first
|
||||
shared identity, `communication.messages`: `/messages` and the migration alias
|
||||
`/inbox` select the first currently authorized, View-visible owner while the
|
||||
underlying `/mail` and `/postbox` deep links, custody and permissions remain
|
||||
unchanged. Alias resolution emits a bounded client telemetry event before the
|
||||
redirect.
|
||||
|
||||
Core's `ProductAvailabilityState` is the shared presentation primitive for
|
||||
authorization, Policy, configuration, disabled, missing-capability, offline and
|
||||
provider-degraded states. Product language is primary; exact module,
|
||||
capability, provider and correlation provenance is available only in an
|
||||
expandable technical section.
|
||||
|
||||
## Navigation Model
|
||||
|
||||
The default shell should prioritize:
|
||||
@@ -132,9 +149,9 @@ first rail slice.
|
||||
|
||||
### Slice 1: inventory and aliases
|
||||
|
||||
- classify every route, navigation item, widget, setting, search object, and
|
||||
- continue classifying every route, navigation item, widget, setting, search object, and
|
||||
help context by product area and object type;
|
||||
- add product aliases without removing existing deep links;
|
||||
- extend the implemented product-surface aliases without removing existing deep links;
|
||||
- flag raw module IDs in ordinary-user labels and errors.
|
||||
|
||||
### Slice 2: work-first shell
|
||||
|
||||
@@ -5,9 +5,9 @@ A migration-owning module must register and document its canonical DSAR provider
|
||||
Every other active module requires a reviewed explanation of why it owns no
|
||||
persistent subject-data store. Adding a migration invalidates that explanation.
|
||||
|
||||
- Active modules: 68
|
||||
- Active modules: 72
|
||||
- Registered and documented DSAR providers: 48
|
||||
- Reviewed no-store rationales: 20
|
||||
- Reviewed no-store rationales: 24
|
||||
- Unexplained coverage gaps: 0
|
||||
|
||||
| Module | Repository | Persistence | Coverage | Rationale |
|
||||
@@ -32,11 +32,14 @@ persistent subject-data store. Adding a migration invalidates that explanation.
|
||||
| `datasources` | `govoplan-datasources` | Migration-owned | Provider | Provider `privacy.dsar.datasources` is registered and documented. |
|
||||
| `decisions` | `govoplan-decisions` | Migration-owned | Provider | Provider `privacy.dsar.decisions` is registered and documented. |
|
||||
| `dist_lists` | `govoplan-dist-lists` | Migration-owned | Provider | Provider `privacy.dsar.dist_lists` is registered and documented. |
|
||||
| `dms` | `govoplan-dms` | No module migration | Reviewed no-store rationale | Stateless integration-preview module: DMS retains no document, person, credential, or provider-response store; Files and Records remain the subject-data owners. Reassess before persisting a target binding, plan, receipt, or diagnostic. |
|
||||
| `docs` | `govoplan-docs` | Migration-owned | Provider | Provider `privacy.dsar.docs` is registered and documented. |
|
||||
| `encryption` | `govoplan-encryption` | Migration-owned | Provider | Provider `privacy.dsar.encryption` is registered and documented. |
|
||||
| `erp` | `govoplan-erp` | No module migration | Reviewed no-store rationale | Stateless integration-contract module: ERP retains no invoice, payable, plan, booking observation, provider response, or credential store; Procurement, Payments, Ledger, Files, and Audit remain the subject-data owners. Reassess before persisting a target binding, plan, receipt, reconciliation decision, or diagnostic. |
|
||||
| `evaluation` | `govoplan-evaluation` | No module migration | Reviewed no-store rationale | Contract-only module: evaluation runs, responses, and scores are not persisted; reassess before adding a migration-owned store. |
|
||||
| `facilities` | `govoplan-facilities` | No module migration | Reviewed no-store rationale | Contract-only module: facility and maintenance persistence are not implemented; reassess before adding a migration-owned store. |
|
||||
| `files` | `govoplan-files` | Migration-owned | Provider | Provider `privacy.dsar.files` is registered and documented. |
|
||||
| `fit_connect` | `govoplan-fit-connect` | No module migration | Reviewed no-store rationale | Stateless transport-contract module: FIT-Connect retains no submission, attachment, receipt, acknowledgement plan, key, provider response, or diagnostic store; the owning Service, Forms, Cases, Files, and Audit workflows remain responsible for subject data. Reassess before persisting any ingress or event-log evidence. |
|
||||
| `forms` | `govoplan-forms` | Migration-owned | Provider | Provider `privacy.dsar.forms` is registered and documented. |
|
||||
| `forms_runtime` | `govoplan-forms-runtime` | Migration-owned | Provider | Provider `privacy.dsar.forms_runtime` is registered and documented. |
|
||||
| `grants` | `govoplan-grants` | No module migration | Reviewed no-store rationale | Contract-only module: grant applications, awards, and monitoring are not persisted; reassess before adding a migration-owned store. |
|
||||
@@ -80,6 +83,7 @@ persistent subject-data store. Adding a migration invalidates that explanation.
|
||||
| `wiki` | `govoplan-wiki` | Migration-owned | Provider | Provider `privacy.dsar.wiki` is registered and documented. |
|
||||
| `workflow` | `govoplan-workflow` | No module migration | Reviewed no-store rationale | Presentation-only module: Workflow edits and projects Workflow Engine state; Workflow Engine owns persistence and DSAR coverage. |
|
||||
| `workflow_engine` | `govoplan-workflow-engine` | Migration-owned | Provider | Provider `privacy.dsar.workflow_engine` is registered and documented. |
|
||||
| `xrechnung` | `govoplan-xrechnung` | No module migration | Reviewed no-store rationale | Stateless validation-contract module: XRechnung persists no invoice, report, diagnostic, or handoff; the invoking Files, Procurement, or Payments workflow remains the subject-data owner. Reassess before adding a validation store. |
|
||||
|
||||
Provider search, export minimization, retention, and erasure behavior remains
|
||||
documented and tested by each owning module. This matrix verifies adoption and
|
||||
|
||||
@@ -4,85 +4,89 @@ build-backend = "setuptools.build_meta"
|
||||
|
||||
[project]
|
||||
name = "govoplan"
|
||||
version = "0.1.34"
|
||||
version = "0.1.40"
|
||||
description = "Developer convenience package for a versioned GovOPlaN composition"
|
||||
readme = "README.md"
|
||||
requires-python = ">=3.12"
|
||||
license = { text = "AGPL-3.0-or-later" }
|
||||
dependencies = [
|
||||
"govoplan-core[server]==0.1.34",
|
||||
"govoplan-tenancy==0.1.18",
|
||||
"govoplan-organizations==0.1.18",
|
||||
"govoplan-identity==0.1.18",
|
||||
"govoplan-idm==0.1.20",
|
||||
"govoplan-access==0.1.19",
|
||||
"govoplan-admin==0.1.18",
|
||||
"govoplan-policy==0.1.20",
|
||||
"govoplan-audit==0.1.19",
|
||||
"govoplan-dashboard==0.1.18",
|
||||
"govoplan-files==0.1.20",
|
||||
"govoplan-mail==0.1.22",
|
||||
"govoplan-campaign==0.1.24",
|
||||
"govoplan-calendar==0.1.18",
|
||||
"govoplan-docs==0.1.20",
|
||||
"govoplan-ops==0.1.19",
|
||||
"govoplan-core[server]==0.1.40",
|
||||
"govoplan-tenancy==0.1.20",
|
||||
"govoplan-organizations==0.1.20",
|
||||
"govoplan-identity==0.1.20",
|
||||
"govoplan-idm==0.1.24",
|
||||
"govoplan-access==0.1.23",
|
||||
"govoplan-admin==0.1.22",
|
||||
"govoplan-policy==0.1.22",
|
||||
"govoplan-audit==0.1.20",
|
||||
"govoplan-dashboard==0.1.20",
|
||||
"govoplan-files==0.1.23",
|
||||
"govoplan-mail==0.1.25",
|
||||
"govoplan-campaign==0.1.27",
|
||||
"govoplan-calendar==0.1.22",
|
||||
"govoplan-docs==0.1.22",
|
||||
"govoplan-ops==0.1.20",
|
||||
]
|
||||
|
||||
[project.optional-dependencies]
|
||||
full = [
|
||||
"govoplan-addresses==0.1.18",
|
||||
"govoplan-approvals==0.1.18",
|
||||
"govoplan-assets==0.1.19",
|
||||
"govoplan-booking==0.1.19",
|
||||
"govoplan-cases==0.1.20",
|
||||
"govoplan-certificates==0.1.19",
|
||||
"govoplan-committee==0.1.18",
|
||||
"govoplan-connectors==0.1.22",
|
||||
"govoplan-consultation==0.1.19",
|
||||
"govoplan-contracts==0.1.19",
|
||||
"govoplan-dataflow==0.1.20",
|
||||
"govoplan-datasources==0.1.20",
|
||||
"govoplan-decisions==0.1.18",
|
||||
"govoplan-dist-lists==0.1.18",
|
||||
"govoplan-encryption==0.1.18",
|
||||
"govoplan-evaluation==0.1.19",
|
||||
"govoplan-facilities==0.1.19",
|
||||
"govoplan-forms==0.1.19",
|
||||
"govoplan-forms-runtime==0.1.18",
|
||||
"govoplan-grants==0.1.19",
|
||||
"govoplan-helpdesk==0.1.20",
|
||||
"govoplan-identity-trust==0.1.18",
|
||||
"govoplan-inspections==0.1.19",
|
||||
"govoplan-learning==0.1.19",
|
||||
"govoplan-mandates==0.1.18",
|
||||
"govoplan-notifications==0.1.18",
|
||||
"govoplan-parties==0.1.18",
|
||||
"govoplan-payments==0.1.20",
|
||||
"govoplan-permits==0.1.19",
|
||||
"govoplan-poll==0.1.19",
|
||||
"govoplan-portal==0.1.19",
|
||||
"govoplan-postbox==0.1.19",
|
||||
"govoplan-procurement==0.1.19",
|
||||
"govoplan-projects==0.1.18",
|
||||
"govoplan-quick-access==0.1.19",
|
||||
"govoplan-records==0.1.19",
|
||||
"govoplan-reporting==0.1.18",
|
||||
"govoplan-resources==0.1.19",
|
||||
"govoplan-addresses==0.1.21",
|
||||
"govoplan-approvals==0.1.20",
|
||||
"govoplan-assets==0.1.20",
|
||||
"govoplan-booking==0.1.20",
|
||||
"govoplan-cases==0.1.22",
|
||||
"govoplan-certificates==0.1.20",
|
||||
"govoplan-committee==0.1.20",
|
||||
"govoplan-connectors==0.1.25",
|
||||
"govoplan-consultation==0.1.20",
|
||||
"govoplan-contracts==0.1.20",
|
||||
"govoplan-dataflow==0.1.23",
|
||||
"govoplan-datasources==0.1.24",
|
||||
"govoplan-decisions==0.1.19",
|
||||
"govoplan-dist-lists==0.1.20",
|
||||
"govoplan-dms==0.1.20",
|
||||
"govoplan-encryption==0.1.19",
|
||||
"govoplan-erp==0.1.20",
|
||||
"govoplan-evaluation==0.1.20",
|
||||
"govoplan-facilities==0.1.20",
|
||||
"govoplan-fit-connect==0.1.20",
|
||||
"govoplan-forms==0.1.22",
|
||||
"govoplan-forms-runtime==0.1.19",
|
||||
"govoplan-grants==0.1.20",
|
||||
"govoplan-helpdesk==0.1.21",
|
||||
"govoplan-identity-trust==0.1.20",
|
||||
"govoplan-inspections==0.1.20",
|
||||
"govoplan-learning==0.1.20",
|
||||
"govoplan-mandates==0.1.19",
|
||||
"govoplan-notifications==0.1.19",
|
||||
"govoplan-parties==0.1.19",
|
||||
"govoplan-payments==0.1.21",
|
||||
"govoplan-permits==0.1.20",
|
||||
"govoplan-poll==0.1.20",
|
||||
"govoplan-portal==0.1.21",
|
||||
"govoplan-postbox==0.1.22",
|
||||
"govoplan-procurement==0.1.20",
|
||||
"govoplan-projects==0.1.19",
|
||||
"govoplan-quick-access==0.1.20",
|
||||
"govoplan-records==0.1.22",
|
||||
"govoplan-reporting==0.1.20",
|
||||
"govoplan-resources==0.1.20",
|
||||
"govoplan-rest==0.1.19",
|
||||
"govoplan-risk-compliance==0.1.18",
|
||||
"govoplan-scheduling==0.1.18",
|
||||
"govoplan-search==0.1.18",
|
||||
"govoplan-services==0.1.18",
|
||||
"govoplan-risk-compliance==0.1.20",
|
||||
"govoplan-scheduling==0.1.21",
|
||||
"govoplan-search==0.1.19",
|
||||
"govoplan-services==0.1.19",
|
||||
"govoplan-soap==0.1.19",
|
||||
"govoplan-tasks==0.1.20",
|
||||
"govoplan-templates==0.1.18",
|
||||
"govoplan-tickets==0.1.20",
|
||||
"govoplan-transparency==0.1.19",
|
||||
"govoplan-views==0.1.19",
|
||||
"govoplan-voting==0.1.18",
|
||||
"govoplan-wiki==0.1.20",
|
||||
"govoplan-workflow==0.1.21",
|
||||
"govoplan-workflow-engine==0.1.19",
|
||||
"govoplan-tasks==0.1.21",
|
||||
"govoplan-templates==0.1.21",
|
||||
"govoplan-tickets==0.1.22",
|
||||
"govoplan-transparency==0.1.20",
|
||||
"govoplan-views==0.1.21",
|
||||
"govoplan-voting==0.1.20",
|
||||
"govoplan-wiki==0.1.22",
|
||||
"govoplan-workflow==0.1.22",
|
||||
"govoplan-workflow-engine==0.1.21",
|
||||
"govoplan-xrechnung==0.1.21",
|
||||
]
|
||||
|
||||
[project.urls]
|
||||
|
||||
@@ -17,6 +17,26 @@ human review handoff, formal outcome, Postbox delivery channel, and Records
|
||||
filing/retention target. Generic permit wording is no longer acceptance
|
||||
evidence for this package.
|
||||
|
||||
The package is now executable rather than metadata-only. Its Access fragments
|
||||
create the bounded resident-permit clerk role, collect only the tenant-local
|
||||
responsibility group key and name, create that group, and bind the role. The
|
||||
Forms-owned fragment carries a digest-bound German-reference application schema
|
||||
and imports it as a tenant-local draft with source provenance. Reapplying the
|
||||
same source digest is a no-op; replacing an unrelated local definition remains
|
||||
blocked unless the reviewed package explicitly selects a new revision. Normal
|
||||
Forms review and publication are still required before the definition can serve
|
||||
new applications. The Workflow Engine-owned fragment materializes and activates
|
||||
the tenant review baseline, resolves the chosen responsibility group into each
|
||||
human handoff, and preserves the evidence, decision, and EUR 30 payment-review
|
||||
steps as a replay-safe contributed definition.
|
||||
|
||||
Services, Cases, Payments, Tasks, and the optional delivery and Records modules
|
||||
already execute the pinned journey through their runtime
|
||||
contracts, but their reusable configuration fragments are not yet claimed by
|
||||
this package. Until those module-owned configuration providers are added, the
|
||||
package preflight deliberately distinguishes the installed runtime composition
|
||||
from the Access, Forms, and Workflow configurations it can currently materialize.
|
||||
|
||||
An installed Forms and Forms Runtime pair adds an alternative governed entry
|
||||
path before case/workflow handoff:
|
||||
|
||||
@@ -76,3 +96,11 @@ and Decision revision filing. Target-environment browser accessibility,
|
||||
production identity and delivery, a named archive profile, and recovery evidence
|
||||
are still required before this product package may claim `reference_ready`
|
||||
maturity.
|
||||
|
||||
The generic package orchestrator stops at the first provider apply or health
|
||||
blocker. Access and Forms may commit in separate provider transactions, so the
|
||||
operator must retain the reviewed pre-apply database snapshot until verification
|
||||
is complete. The Admin result reports no-op, snapshot-required, or partial-apply
|
||||
recovery state and never describes this as atomic cross-module undo. Exported
|
||||
fragments carry source/module/operator/scope provenance; supplied values and
|
||||
credentials are not serialized into that provenance.
|
||||
|
||||
@@ -8,36 +8,366 @@
|
||||
"category": "institutional-governance",
|
||||
"license": "AGPL-3.0-or-later",
|
||||
"required_modules": [
|
||||
{"module_id": "access"},
|
||||
{"module_id": "audit"},
|
||||
{"module_id": "cases"},
|
||||
{"module_id": "decisions"},
|
||||
{"module_id": "forms"},
|
||||
{"module_id": "forms_runtime"},
|
||||
{"module_id": "mandates"},
|
||||
{"module_id": "parties"},
|
||||
{"module_id": "payments"},
|
||||
{"module_id": "policy"},
|
||||
{"module_id": "portal"},
|
||||
{"module_id": "services"}
|
||||
{"module_id": "services"},
|
||||
{"module_id": "tasks"},
|
||||
{"module_id": "workflow_engine"}
|
||||
],
|
||||
"required_capabilities": [
|
||||
"access.configuration",
|
||||
"cases.party_context",
|
||||
"cases.service_intake",
|
||||
"decisions.registry",
|
||||
"forms.configuration",
|
||||
"forms.definitions",
|
||||
"mandates.resolver",
|
||||
"parties.resolver",
|
||||
"payments.requests",
|
||||
"portal.service_directory",
|
||||
"services.availability",
|
||||
"services.definitions"
|
||||
"services.definitions",
|
||||
"workflow.configuration"
|
||||
],
|
||||
"optional_modules": [
|
||||
{"module_id": "approvals"},
|
||||
{"module_id": "committee"},
|
||||
{"module_id": "files"},
|
||||
{"module_id": "forms"},
|
||||
{"module_id": "forms_runtime"},
|
||||
{"module_id": "postbox"},
|
||||
{"module_id": "records"},
|
||||
{"module_id": "search"},
|
||||
{"module_id": "tasks"},
|
||||
{"module_id": "workflow_engine"}
|
||||
{"module_id": "search"}
|
||||
],
|
||||
"data_requirements": [
|
||||
{
|
||||
"key": "responsible_group_slug",
|
||||
"label": "Responsible permit group key",
|
||||
"data_type": "string",
|
||||
"required": true,
|
||||
"secret": false,
|
||||
"description": "Tenant-local stable key for the group that reviews resident parking permit applications."
|
||||
},
|
||||
{
|
||||
"key": "responsible_group_name",
|
||||
"label": "Responsible permit group name",
|
||||
"data_type": "string",
|
||||
"required": true,
|
||||
"secret": false,
|
||||
"description": "Human-readable tenant-local name shown for the responsible permit group."
|
||||
}
|
||||
],
|
||||
"fragments": [
|
||||
{
|
||||
"module_id": "access",
|
||||
"fragment_type": "roles",
|
||||
"fragment_id": "resident-parking-permit-clerk",
|
||||
"payload": {
|
||||
"items": [
|
||||
{
|
||||
"slug": "resident-parking-permit-clerk",
|
||||
"name": "Resident parking permit clerk",
|
||||
"description": "Reviews resident parking permit submissions, workflow handoffs, cases, decisions, and payment evidence.",
|
||||
"permissions": [
|
||||
"cases:case:read",
|
||||
"cases:case:create",
|
||||
"cases:case:update",
|
||||
"decisions:decision:read",
|
||||
"decisions:decision:write",
|
||||
"forms:definition:read",
|
||||
"forms_runtime:workspace:read",
|
||||
"forms_runtime:workspace:write",
|
||||
"payments:payment:read",
|
||||
"payments:payment:write",
|
||||
"tasks:item:read",
|
||||
"tasks:item:write",
|
||||
"workflow:definition:read",
|
||||
"workflow:instance:read",
|
||||
"workflow:instance:start",
|
||||
"workflow:instance:transition"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"module_id": "access",
|
||||
"fragment_type": "groups",
|
||||
"fragment_id": "resident-parking-permit-responsibility",
|
||||
"payload": {
|
||||
"items": [
|
||||
{
|
||||
"slug": {"$data": "responsible_group_slug"},
|
||||
"name": {"$data": "responsible_group_name"},
|
||||
"description": "Tenant-local responsibility group for the resident parking permit reference journey."
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"module_id": "access",
|
||||
"fragment_type": "group_role_assignments",
|
||||
"fragment_id": "resident-parking-permit-clerk-assignment",
|
||||
"payload": {
|
||||
"items": [
|
||||
{
|
||||
"group": {"$data": "responsible_group_slug"},
|
||||
"role": "resident-parking-permit-clerk"
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"module_id": "forms",
|
||||
"fragment_type": "definition",
|
||||
"fragment_id": "resident-parking-permit-application",
|
||||
"payload": {
|
||||
"on_conflict": "new_revision",
|
||||
"change_reason": "Install the reviewed resident parking permit reference form.",
|
||||
"fragment": {
|
||||
"kind": "govoplan.forms.definition",
|
||||
"contract_version": "0.1.0",
|
||||
"definition": {
|
||||
"reference": {
|
||||
"kind": "form",
|
||||
"owner_module": "forms",
|
||||
"object_id": "resident-parking-permit-application",
|
||||
"tenant_id": "reference-package",
|
||||
"version": "3",
|
||||
"valid_at": null,
|
||||
"label": null
|
||||
},
|
||||
"key": "resident-parking-permit-application",
|
||||
"temporal": {
|
||||
"revision": "3",
|
||||
"valid_from": null,
|
||||
"valid_to": null,
|
||||
"recorded_at": "2026-08-22T00:00:00+00:00",
|
||||
"superseded_at": null,
|
||||
"change_reason": "Reference package revision."
|
||||
},
|
||||
"title": "Resident parking permit",
|
||||
"description": "Apply for a resident parking permit through a digital or assisted channel.",
|
||||
"fields": [
|
||||
{
|
||||
"key": "applicant_name",
|
||||
"label": "Name",
|
||||
"value_type": "text",
|
||||
"required": true,
|
||||
"help_text": null,
|
||||
"options": [],
|
||||
"constraints": {"min_length": 2, "max_length": 200},
|
||||
"default_value": null
|
||||
},
|
||||
{
|
||||
"key": "applicant_email",
|
||||
"label": "Email",
|
||||
"value_type": "text",
|
||||
"required": true,
|
||||
"help_text": null,
|
||||
"options": [],
|
||||
"constraints": {"format": "email"},
|
||||
"default_value": null
|
||||
},
|
||||
{
|
||||
"key": "residence_address",
|
||||
"label": "Primary residence",
|
||||
"value_type": "text",
|
||||
"required": true,
|
||||
"help_text": null,
|
||||
"options": [],
|
||||
"constraints": {"max_length": 500},
|
||||
"default_value": null
|
||||
},
|
||||
{
|
||||
"key": "licence_plate",
|
||||
"label": "Licence plate",
|
||||
"value_type": "text",
|
||||
"required": true,
|
||||
"help_text": null,
|
||||
"options": [],
|
||||
"constraints": {"max_length": 20},
|
||||
"default_value": null
|
||||
}
|
||||
],
|
||||
"publication_state": "published",
|
||||
"allow_drafts": true,
|
||||
"max_attachments": 4,
|
||||
"signature_requirement": "none",
|
||||
"policy_refs": [
|
||||
"law:resident-parking-permit",
|
||||
"records:resident-parking-permit"
|
||||
],
|
||||
"handoff_kinds": ["case", "workflow"],
|
||||
"metadata": {},
|
||||
"pages": [
|
||||
{
|
||||
"key": "application",
|
||||
"title": "Application",
|
||||
"description": null,
|
||||
"sections": [
|
||||
{
|
||||
"key": "applicant-and-vehicle",
|
||||
"title": "Applicant and vehicle",
|
||||
"description": null,
|
||||
"field_keys": [
|
||||
"applicant_name",
|
||||
"applicant_email",
|
||||
"residence_address",
|
||||
"licence_plate"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"localizations": [
|
||||
{
|
||||
"locale": "de",
|
||||
"title": "Anwohnerparkausweis beantragen",
|
||||
"description": "Einen Anwohnerparkausweis digital oder mit Unterstützung beantragen.",
|
||||
"field_labels": {
|
||||
"applicant_name": "Name",
|
||||
"applicant_email": "E-Mail-Adresse",
|
||||
"residence_address": "Hauptwohnsitz",
|
||||
"licence_plate": "Kennzeichen"
|
||||
},
|
||||
"field_help_texts": {},
|
||||
"option_labels": {},
|
||||
"page_titles": {"application": "Antrag"},
|
||||
"section_titles": {
|
||||
"applicant-and-vehicle": "Antragstellende Person und Fahrzeug"
|
||||
}
|
||||
}
|
||||
],
|
||||
"fallback_locale": "de"
|
||||
},
|
||||
"definition_sha256": "7dc108002d532c07e5e7f3b14029a9d4deb3836ebb65d97fb6b51166a70e0ed4",
|
||||
"provenance": {
|
||||
"owner_module": "forms",
|
||||
"tenant_id": "reference-package",
|
||||
"form_id": "resident-parking-permit-application",
|
||||
"revision": "3",
|
||||
"exported_at": "2026-08-22T12:00:00+00:00",
|
||||
"exported_by": "GovOPlaN reference package"
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
{
|
||||
"module_id": "workflow_engine",
|
||||
"fragment_type": "workflow_definitions",
|
||||
"fragment_id": "resident-parking-permit-workflow",
|
||||
"payload": {
|
||||
"schema_version": 1,
|
||||
"origin_module_id": "configuration_package.service_to_decision",
|
||||
"origin_module_version": "0.1.0",
|
||||
"items": [
|
||||
{
|
||||
"definition_key": "resident-parking-permit-review",
|
||||
"name": "Resident parking permit review",
|
||||
"description": "Review evidence, record the formal decision, and verify payment evidence for the resident parking permit reference journey.",
|
||||
"scope_type": "tenant",
|
||||
"allow_start": true,
|
||||
"allow_reuse": true,
|
||||
"allow_automation": false,
|
||||
"execution_mode": "guided",
|
||||
"activate_on_install": true,
|
||||
"graph": {
|
||||
"schema_version": 1,
|
||||
"nodes": [
|
||||
{
|
||||
"id": "start",
|
||||
"type": "workflow.start.manual",
|
||||
"label": "Application received",
|
||||
"config": {"input_schema_ref": "form:resident-parking-permit-application"}
|
||||
},
|
||||
{
|
||||
"id": "review-evidence",
|
||||
"type": "workflow.review",
|
||||
"label": "Review application evidence",
|
||||
"config": {
|
||||
"title": "Review resident parking permit evidence",
|
||||
"reviewer": {
|
||||
"kind": "group",
|
||||
"id": {"$data": "responsible_group_slug"},
|
||||
"label": {"$data": "responsible_group_name"}
|
||||
},
|
||||
"due_after": "P14D",
|
||||
"required_evidence": [
|
||||
"identity",
|
||||
"primary_residence",
|
||||
"vehicle_registration"
|
||||
],
|
||||
"view_surface_ids": []
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "record-decision",
|
||||
"type": "workflow.activity",
|
||||
"label": "Record formal decision",
|
||||
"config": {
|
||||
"title": "Record the resident parking permit decision",
|
||||
"instructions": "Record the operative result, reasoning, legal basis, remedy, and exact evidence references through the Decisions capability.",
|
||||
"assignee": {
|
||||
"kind": "group",
|
||||
"id": {"$data": "responsible_group_slug"},
|
||||
"label": {"$data": "responsible_group_name"}
|
||||
},
|
||||
"due_after": "P7D",
|
||||
"view_surface_ids": []
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "verify-payment",
|
||||
"type": "workflow.activity",
|
||||
"label": "Verify payment evidence",
|
||||
"config": {
|
||||
"title": "Verify the resident parking permit fee",
|
||||
"instructions": "Verify the EUR 30.00 obligation, immutable receipt evidence, currency, amount, and transaction reference before completion.",
|
||||
"assignee": {
|
||||
"kind": "group",
|
||||
"id": {"$data": "responsible_group_slug"},
|
||||
"label": {"$data": "responsible_group_name"}
|
||||
},
|
||||
"due_after": "P14D",
|
||||
"view_surface_ids": []
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "completed",
|
||||
"type": "workflow.end.completed",
|
||||
"label": "Permit journey complete",
|
||||
"config": {"output_mapping": {}}
|
||||
}
|
||||
],
|
||||
"edges": [
|
||||
{"id": "start-review", "source": "start", "target": "review-evidence"},
|
||||
{"id": "review-decision", "source": "review-evidence", "source_port": "approved", "target": "record-decision"},
|
||||
{"id": "decision-payment", "source": "record-decision", "target": "verify-payment"},
|
||||
{"id": "payment-completed", "source": "verify-payment", "target": "completed"}
|
||||
],
|
||||
"metadata": {
|
||||
"reference_journey": "resident-parking-permit",
|
||||
"locale": "de-DE",
|
||||
"payment_amount_minor": 3000,
|
||||
"payment_currency": "EUR"
|
||||
}
|
||||
},
|
||||
"metadata": {
|
||||
"reference_package": "product.service-to-decision",
|
||||
"form_id": "resident-parking-permit-application"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
],
|
||||
"evidence": [
|
||||
{
|
||||
|
||||
+15
-15
@@ -1,18 +1,18 @@
|
||||
# Whole-product release install from immutable, independently versioned module tags.
|
||||
# Only add a module after its referenced tag has been published.
|
||||
../govoplan-core[server]
|
||||
govoplan-tenancy @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-tenancy.git@v0.1.18
|
||||
govoplan-organizations @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-organizations.git@v0.1.18
|
||||
govoplan-identity @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-identity.git@v0.1.18
|
||||
govoplan-idm @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-idm.git@v0.1.20
|
||||
govoplan-access @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-access.git@v0.1.19
|
||||
govoplan-admin @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-admin.git@v0.1.18
|
||||
govoplan-policy @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-policy.git@v0.1.20
|
||||
govoplan-audit @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-audit.git@v0.1.19
|
||||
govoplan-dashboard @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-dashboard.git@v0.1.18
|
||||
govoplan-files @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-files.git@v0.1.20
|
||||
govoplan-mail @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-mail.git@v0.1.22
|
||||
govoplan-campaign @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-campaign.git@v0.1.24
|
||||
govoplan-calendar @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-calendar.git@v0.1.18
|
||||
govoplan-docs @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-docs.git@v0.1.20
|
||||
govoplan-ops @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-ops.git@v0.1.19
|
||||
govoplan-tenancy @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-tenancy.git@v0.1.20
|
||||
govoplan-organizations @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-organizations.git@v0.1.20
|
||||
govoplan-identity @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-identity.git@v0.1.20
|
||||
govoplan-idm @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-idm.git@v0.1.24
|
||||
govoplan-access @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-access.git@v0.1.23
|
||||
govoplan-admin @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-admin.git@v0.1.22
|
||||
govoplan-policy @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-policy.git@v0.1.22
|
||||
govoplan-audit @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-audit.git@v0.1.20
|
||||
govoplan-dashboard @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-dashboard.git@v0.1.20
|
||||
govoplan-files @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-files.git@v0.1.23
|
||||
govoplan-mail @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-mail.git@v0.1.25
|
||||
govoplan-campaign @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-campaign.git@v0.1.27
|
||||
govoplan-calendar @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-calendar.git@v0.1.22
|
||||
govoplan-docs @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-docs.git@v0.1.22
|
||||
govoplan-ops @ git+ssh://git@git.add-ideas.de/GovOPlaN/govoplan-ops.git@v0.1.20
|
||||
|
||||
@@ -5,9 +5,17 @@ import json
|
||||
from pathlib import Path
|
||||
import unittest
|
||||
|
||||
from sqlalchemy import create_engine
|
||||
from sqlalchemy.orm import Session
|
||||
|
||||
from govoplan_core.core.configuration_packages import (
|
||||
ConfigurationApplyResult,
|
||||
ConfigurationExportResult,
|
||||
ConfigurationPackageManifest,
|
||||
ConfigurationPlanItem,
|
||||
ConfigurationPreflightContext,
|
||||
ConfigurationPreflightResult,
|
||||
ConfigurationProviderDescription,
|
||||
configuration_package_claim_issues,
|
||||
dry_run_configuration_package,
|
||||
)
|
||||
@@ -54,10 +62,19 @@ class ConfigurationPackageArtifactTests(unittest.TestCase):
|
||||
f"Missing repository for {requirement.module_id}",
|
||||
)
|
||||
|
||||
provider_module_ids = tuple(
|
||||
sorted({fragment.module_id for fragment in manifest.fragments})
|
||||
)
|
||||
providers = tuple(_ArtifactProvider(module_id) for module_id in provider_module_ids)
|
||||
supplied_data = {
|
||||
str(item["key"]): _sample_value(item)
|
||||
for item in manifest.data_requirements
|
||||
}
|
||||
result = dry_run_configuration_package(
|
||||
manifest,
|
||||
(),
|
||||
providers,
|
||||
ConfigurationPreflightContext(
|
||||
supplied_data=supplied_data,
|
||||
installed_modules={
|
||||
item.module_id: item.version or "workspace"
|
||||
for item in manifest.required_modules
|
||||
@@ -74,6 +91,155 @@ class ConfigurationPackageArtifactTests(unittest.TestCase):
|
||||
self.assertIn("product.governed-data-assurance", package_ids)
|
||||
self.assertIn("product.service-to-decision", package_ids)
|
||||
|
||||
def test_service_to_decision_package_imports_its_form_as_an_idempotent_local_draft(self) -> None:
|
||||
from govoplan_forms.backend.configuration_provider import (
|
||||
_apply_definition,
|
||||
_preflight_definition,
|
||||
)
|
||||
from govoplan_forms.backend.db.models import FormDefinitionRevision
|
||||
from govoplan_forms.backend.service import get_form_definition
|
||||
|
||||
package = ConfigurationPackageManifest.from_mapping(json.loads(
|
||||
(PACKAGE_ROOT / "product/service-to-decision/package.json").read_text(
|
||||
encoding="utf-8"
|
||||
)
|
||||
))
|
||||
fragment = next(
|
||||
item
|
||||
for item in package.fragments
|
||||
if item.module_id == "forms" and item.fragment_type == "definition"
|
||||
)
|
||||
context = ConfigurationPreflightContext(
|
||||
tenant_id="tenant-reference-test",
|
||||
operator_user_id="operator-1",
|
||||
operator_scopes=frozenset({"system:governance:write"}),
|
||||
)
|
||||
engine = create_engine("sqlite+pysqlite:///:memory:")
|
||||
FormDefinitionRevision.__table__.create(engine)
|
||||
session = Session(engine)
|
||||
try:
|
||||
preflight = _preflight_definition(session, fragment, context)
|
||||
applied = _apply_definition(session, fragment, context)
|
||||
session.commit()
|
||||
replay = _apply_definition(session, fragment, context)
|
||||
imported = get_form_definition(
|
||||
session,
|
||||
type("Principal", (), {"tenant_id": "tenant-reference-test"})(),
|
||||
form_id="resident-parking-permit-application",
|
||||
)
|
||||
finally:
|
||||
session.close()
|
||||
engine.dispose()
|
||||
|
||||
self.assertFalse(any(item.severity == "blocker" for item in preflight.diagnostics))
|
||||
self.assertEqual("create", preflight.plan[0].action)
|
||||
self.assertEqual(1, len(applied.created_refs))
|
||||
self.assertEqual({}, replay.created_refs)
|
||||
self.assertIsNotNone(imported)
|
||||
assert imported is not None
|
||||
self.assertEqual("tenant-reference-test", imported.reference.tenant_id)
|
||||
self.assertEqual("draft", imported.publication_state)
|
||||
self.assertEqual("de", imported.fallback_locale)
|
||||
|
||||
def test_service_to_decision_package_materializes_its_tenant_workflow_idempotently(self) -> None:
|
||||
from govoplan_core.core.configuration_packages import _resolve_fragment_data_references
|
||||
from govoplan_workflow_engine.backend.configuration_provider import (
|
||||
apply_workflow_definitions,
|
||||
preflight_workflow_definitions,
|
||||
)
|
||||
from govoplan_workflow_engine.backend.db.models import (
|
||||
WorkflowDefinition,
|
||||
WorkflowDefinitionRevision,
|
||||
)
|
||||
|
||||
package = ConfigurationPackageManifest.from_mapping(json.loads(
|
||||
(PACKAGE_ROOT / "product/service-to-decision/package.json").read_text(
|
||||
encoding="utf-8"
|
||||
)
|
||||
))
|
||||
fragment = next(
|
||||
item
|
||||
for item in package.fragments
|
||||
if item.module_id == "workflow_engine"
|
||||
)
|
||||
context = ConfigurationPreflightContext(
|
||||
tenant_id="tenant-reference-test",
|
||||
supplied_data={
|
||||
"responsible_group_slug": "traffic-permits",
|
||||
"responsible_group_name": "Traffic permits",
|
||||
},
|
||||
)
|
||||
resolved = _resolve_fragment_data_references(
|
||||
fragment,
|
||||
context.supplied_data,
|
||||
)
|
||||
engine = create_engine("sqlite+pysqlite:///:memory:")
|
||||
WorkflowDefinition.__table__.create(engine)
|
||||
WorkflowDefinitionRevision.__table__.create(engine)
|
||||
session = Session(engine)
|
||||
try:
|
||||
preflight = preflight_workflow_definitions(session, resolved, context)
|
||||
applied = apply_workflow_definitions(
|
||||
session,
|
||||
resolved,
|
||||
context,
|
||||
registry=None,
|
||||
)
|
||||
replay = apply_workflow_definitions(
|
||||
session,
|
||||
resolved,
|
||||
context,
|
||||
registry=None,
|
||||
)
|
||||
session.commit()
|
||||
finally:
|
||||
session.close()
|
||||
engine.dispose()
|
||||
|
||||
self.assertFalse(any(item.severity == "blocker" for item in preflight.diagnostics))
|
||||
self.assertEqual("create", preflight.plan[0].action)
|
||||
self.assertIn("resident-parking-permit-review", applied.created_refs)
|
||||
self.assertEqual({}, replay.created_refs)
|
||||
self.assertEqual({}, replay.updated_refs)
|
||||
|
||||
|
||||
class _ArtifactProvider:
|
||||
def __init__(self, module_id: str) -> None:
|
||||
self.module_id = module_id
|
||||
|
||||
def describe(self) -> ConfigurationProviderDescription:
|
||||
return ConfigurationProviderDescription(module_id=self.module_id)
|
||||
|
||||
def preflight(self, fragment, context) -> ConfigurationPreflightResult:
|
||||
del context
|
||||
return ConfigurationPreflightResult(plan=(ConfigurationPlanItem(
|
||||
action="create",
|
||||
module_id=fragment.module_id,
|
||||
fragment_type=fragment.fragment_type,
|
||||
fragment_id=fragment.fragment_id,
|
||||
),))
|
||||
|
||||
def apply(self, fragment, supplied_data, context) -> ConfigurationApplyResult:
|
||||
del fragment, supplied_data, context
|
||||
return ConfigurationApplyResult()
|
||||
|
||||
def export(self, selection, context) -> ConfigurationExportResult:
|
||||
del selection, context
|
||||
return ConfigurationExportResult()
|
||||
|
||||
def health(self, import_result, context):
|
||||
del import_result, context
|
||||
return ()
|
||||
|
||||
|
||||
def _sample_value(requirement: dict[str, object]) -> object:
|
||||
data_type = str(requirement.get("data_type") or requirement.get("type") or "string")
|
||||
if data_type == "boolean":
|
||||
return False
|
||||
if data_type in {"integer", "number"}:
|
||||
return 1
|
||||
return f"fixture-{requirement['key']}"
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
|
||||
@@ -70,7 +70,7 @@ class PackageRegistryReleaseTests(unittest.TestCase):
|
||||
by_name = {item["name"]: item for item in selected}
|
||||
self.assertIn("govoplan-core", by_name)
|
||||
self.assertIn("govoplan-records", by_name)
|
||||
self.assertEqual("0.1.20", by_name["govoplan-tasks"]["version"])
|
||||
self.assertEqual("0.1.21", by_name["govoplan-tasks"]["version"])
|
||||
|
||||
payload = PACKAGE_SET.generate_package_set(
|
||||
core_version=core_version,
|
||||
|
||||
@@ -22,11 +22,16 @@ class PackageSetDispatchTests(unittest.TestCase):
|
||||
def test_meta_package_resolves_to_exact_tagged_repository_targets(self) -> None:
|
||||
targets = MODULE.package_targets()
|
||||
|
||||
self.assertEqual(66, len(targets))
|
||||
self.assertEqual(66, len({target.distribution for target in targets}))
|
||||
self.assertEqual(73, len(targets))
|
||||
self.assertEqual(73, len({target.distribution for target in targets}))
|
||||
by_name = {target.distribution: target for target in targets}
|
||||
self.assertEqual("v0.1.14", by_name["govoplan-core"].tag)
|
||||
self.assertEqual("v0.1.8", by_name["govoplan-access"].tag)
|
||||
self.assertEqual("v0.1.38", by_name["govoplan-core"].tag)
|
||||
self.assertEqual("v0.1.22", by_name["govoplan-access"].tag)
|
||||
self.assertEqual("v0.1.20", by_name["govoplan-dms"].tag)
|
||||
self.assertEqual("v0.1.20", by_name["govoplan-erp"].tag)
|
||||
self.assertEqual("v0.1.20", by_name["govoplan-fit-connect"].tag)
|
||||
self.assertEqual("v0.1.23", by_name["govoplan-idm"].tag)
|
||||
self.assertEqual("v0.1.21", by_name["govoplan-xrechnung"].tag)
|
||||
self.assertTrue(by_name["govoplan-core"].tag_exists)
|
||||
self.assertTrue(by_name["govoplan-access"].has_webui)
|
||||
self.assertEqual(
|
||||
|
||||
@@ -169,6 +169,69 @@ class PlatformInterfaceInventoryTests(unittest.TestCase):
|
||||
),
|
||||
)
|
||||
|
||||
def test_high_risk_help_baseline_is_validated(self) -> None:
|
||||
with tempfile.TemporaryDirectory() as directory:
|
||||
path = Path(directory) / "help-baseline.json"
|
||||
path.write_text(
|
||||
json.dumps(
|
||||
{
|
||||
"schema_version": 1,
|
||||
"maximum_missing_exact_help": 3,
|
||||
}
|
||||
),
|
||||
encoding="utf-8",
|
||||
)
|
||||
|
||||
self.assertEqual(
|
||||
3,
|
||||
inventory._load_high_risk_help_baseline(path)[
|
||||
"maximum_missing_exact_help"
|
||||
],
|
||||
)
|
||||
path.write_text(
|
||||
json.dumps(
|
||||
{
|
||||
"schema_version": 1,
|
||||
"maximum_missing_exact_help": -1,
|
||||
}
|
||||
),
|
||||
encoding="utf-8",
|
||||
)
|
||||
with self.assertRaisesRegex(ValueError, "non-negative integer"):
|
||||
inventory._load_high_risk_help_baseline(path)
|
||||
|
||||
def test_declaration_strict_mode_rejects_high_risk_help_regression(
|
||||
self,
|
||||
) -> None:
|
||||
result = {
|
||||
"translation_health": {"missing_catalog_entries": []},
|
||||
"api": {
|
||||
"unclassified_endpoints": [],
|
||||
"stale_endpoint_declarations": [],
|
||||
},
|
||||
"declaration_health": {},
|
||||
"help_health": {
|
||||
"invalid_risk_annotations": [],
|
||||
"unresolved_exact_high_risk_help": [],
|
||||
"high_risk_help_without_german": [],
|
||||
"missing_exact_high_risk_help": [{"id": "example.delete"}],
|
||||
"baseline_maximum_missing": 0,
|
||||
"baseline_regression": True,
|
||||
},
|
||||
}
|
||||
|
||||
self.assertEqual(
|
||||
[
|
||||
"1 high-risk controls lack exact F1 help; baseline permits at most 0"
|
||||
],
|
||||
inventory._strict_failures(
|
||||
result,
|
||||
check_translations=False,
|
||||
check_endpoints=False,
|
||||
check_declarations=True,
|
||||
),
|
||||
)
|
||||
|
||||
def test_fastapi_route_scanner_includes_router_prefix(self) -> None:
|
||||
tree = ast.parse(
|
||||
"""
|
||||
|
||||
@@ -4,8 +4,11 @@
|
||||
"certificates": "Contract-only module: certificate issuance and revocation persistence are not implemented; reassess before adding a migration-owned store.",
|
||||
"consultation": "Contract-only module: consultation submissions and evaluation persistence are not implemented; reassess before adding a migration-owned store.",
|
||||
"contracts": "Contract-only module: contract, amendment, and obligation persistence are not implemented; reassess before adding a migration-owned store.",
|
||||
"dms": "Stateless integration-preview module: DMS retains no document, person, credential, or provider-response store; Files and Records remain the subject-data owners. Reassess before persisting a target binding, plan, receipt, or diagnostic.",
|
||||
"erp": "Stateless integration-contract module: ERP retains no invoice, payable, plan, booking observation, provider response, or credential store; Procurement, Payments, Ledger, Files, and Audit remain the subject-data owners. Reassess before persisting a target binding, plan, receipt, reconciliation decision, or diagnostic.",
|
||||
"evaluation": "Contract-only module: evaluation runs, responses, and scores are not persisted; reassess before adding a migration-owned store.",
|
||||
"facilities": "Contract-only module: facility and maintenance persistence are not implemented; reassess before adding a migration-owned store.",
|
||||
"fit_connect": "Stateless transport-contract module: FIT-Connect retains no submission, attachment, receipt, acknowledgement plan, key, provider response, or diagnostic store; the owning Service, Forms, Cases, Files, and Audit workflows remain responsible for subject data. Reassess before persisting any ingress or event-log evidence.",
|
||||
"grants": "Contract-only module: grant applications, awards, and monitoring are not persisted; reassess before adding a migration-owned store.",
|
||||
"inspections": "Contract-only module: inspections, findings, and measures are not persisted; reassess before adding a migration-owned store.",
|
||||
"learning": "Contract-only module: learning offers, enrollment, and completion are not persisted; reassess before adding a migration-owned store.",
|
||||
@@ -18,5 +21,6 @@
|
||||
"soap": "Transport-only module: SOAP binds explicitly published operations and owns no domain or subject-data store.",
|
||||
"tenancy": "Orchestration module: tenant lifecycle and settings use Core-owned storage; Access covers account and membership subject data.",
|
||||
"transparency": "Contract-only module: requests, disclosure reviews, and publications are not persisted; reassess before adding a migration-owned store.",
|
||||
"workflow": "Presentation-only module: Workflow edits and projects Workflow Engine state; Workflow Engine owns persistence and DSAR coverage."
|
||||
"workflow": "Presentation-only module: Workflow edits and projects Workflow Engine state; Workflow Engine owns persistence and DSAR coverage.",
|
||||
"xrechnung": "Stateless validation-contract module: XRechnung persists no invoice, report, diagnostic, or handoff; the invoking Files, Procurement, or Payments workflow remains the subject-data owner. Reassess before adding a validation store."
|
||||
}
|
||||
|
||||
@@ -63,6 +63,28 @@ const helpAttributes = new Set([
|
||||
"helperText",
|
||||
"helpText"
|
||||
]);
|
||||
const exactHelpAttributes = new Set([
|
||||
"data-help-context-id",
|
||||
"helpContextId"
|
||||
]);
|
||||
const helpRiskAttributes = new Set([
|
||||
"data-help-risk",
|
||||
"helpRisk"
|
||||
]);
|
||||
const reviewedHelpRiskAttributes = new Set([
|
||||
"data-help-risk-reviewed",
|
||||
"helpRiskReviewed"
|
||||
]);
|
||||
const supportedHelpRisks = new Set([
|
||||
"authority",
|
||||
"credential",
|
||||
"disclosure",
|
||||
"encryption",
|
||||
"external-effect",
|
||||
"irreversible",
|
||||
"policy",
|
||||
"retention"
|
||||
]);
|
||||
const actionComponentPattern = /(?:Action|Button|Link)$/;
|
||||
const contributionTypes = new Map([
|
||||
["AdminSectionsUiCapability", "admin_section"],
|
||||
@@ -200,20 +222,43 @@ function inspectSource(repository, sourceRoot, sourcePath) {
|
||||
const parentAttributes = parentFormField
|
||||
? jsxAttributes(parentFormField)
|
||||
: new Map();
|
||||
const scopedAncestorAttributes = nearestScopedHelpAttributes(node);
|
||||
const label =
|
||||
attributes.get("label") ??
|
||||
attributes.get("aria-label") ??
|
||||
parentAttributes.get("label") ??
|
||||
null;
|
||||
const help = firstAttribute(attributes, helpAttributes) ??
|
||||
firstAttribute(parentAttributes, helpAttributes);
|
||||
firstAttribute(parentAttributes, helpAttributes) ??
|
||||
firstAttribute(scopedAncestorAttributes, helpAttributes);
|
||||
const hasHelp = hasAnyAttribute(attributes, helpAttributes) ||
|
||||
hasAnyAttribute(parentAttributes, helpAttributes);
|
||||
hasAnyAttribute(parentAttributes, helpAttributes) ||
|
||||
hasAnyAttribute(scopedAncestorAttributes, helpAttributes);
|
||||
const hasExactHelp = hasAnyAttribute(attributes, exactHelpAttributes) ||
|
||||
hasAnyAttribute(parentAttributes, exactHelpAttributes) ||
|
||||
hasAnyAttribute(scopedAncestorAttributes, exactHelpAttributes);
|
||||
const helpContextId = firstAttribute(attributes, exactHelpAttributes) ??
|
||||
firstAttribute(parentAttributes, exactHelpAttributes) ??
|
||||
firstAttribute(scopedAncestorAttributes, exactHelpAttributes);
|
||||
const explicitId = firstAttribute(
|
||||
attributes,
|
||||
new Set(["interfaceId", "data-interface-id", "id", "name", "field"])
|
||||
);
|
||||
const context = nearestNamedContext(node);
|
||||
const risk = helpRiskFor({
|
||||
component,
|
||||
context,
|
||||
file: relativeFile,
|
||||
label,
|
||||
explicitId,
|
||||
name: attributes.get("name") ?? attributes.get("id") ?? attributes.get("field") ?? null,
|
||||
explicitRisk: firstAttribute(attributes, helpRiskAttributes) ??
|
||||
firstAttribute(parentAttributes, helpRiskAttributes) ??
|
||||
firstAttribute(scopedAncestorAttributes, helpRiskAttributes)
|
||||
});
|
||||
const riskReviewed = firstAttribute(attributes, reviewedHelpRiskAttributes) ??
|
||||
firstAttribute(parentAttributes, reviewedHelpRiskAttributes) ??
|
||||
firstAttribute(scopedAncestorAttributes, reviewedHelpRiskAttributes);
|
||||
const stableId = sourceIdentity(
|
||||
"field",
|
||||
node,
|
||||
@@ -237,7 +282,14 @@ function inspectSource(repository, sourceRoot, sourcePath) {
|
||||
help: help ?? null,
|
||||
helpId: hasHelp ? `${stableId}.help` : null,
|
||||
helpDynamic: hasHelp && help === null,
|
||||
helpCandidate: !hasHelp
|
||||
helpCandidate: !hasHelp,
|
||||
helpExact: hasExactHelp,
|
||||
helpContextId,
|
||||
helpContextDynamic: hasExactHelp && helpContextId === null,
|
||||
helpRisk: risk.value,
|
||||
helpRiskSource: risk.source,
|
||||
helpRiskReviewed: riskReviewed,
|
||||
highRiskHelpMissing: risk.value !== null && !hasExactHelp && riskReviewed !== "standard"
|
||||
});
|
||||
|
||||
}
|
||||
@@ -261,6 +313,19 @@ function inspectSource(repository, sourceRoot, sourcePath) {
|
||||
new Set(["interfaceId", "data-interface-id", "id", "name"])
|
||||
);
|
||||
const context = nearestNamedContext(node);
|
||||
const hasHelp = hasAnyAttribute(attributes, helpAttributes);
|
||||
const hasExactHelp = hasAnyAttribute(attributes, exactHelpAttributes);
|
||||
const helpContextId = firstAttribute(attributes, exactHelpAttributes);
|
||||
const risk = helpRiskFor({
|
||||
component,
|
||||
context,
|
||||
file: relativeFile,
|
||||
label,
|
||||
explicitId,
|
||||
name: attributes.get("name") ?? attributes.get("id") ?? null,
|
||||
explicitRisk: firstAttribute(attributes, helpRiskAttributes)
|
||||
});
|
||||
const riskReviewed = firstAttribute(attributes, reviewedHelpRiskAttributes);
|
||||
result.actions.push({
|
||||
...locate(node),
|
||||
id: sourceIdentity(
|
||||
@@ -273,7 +338,15 @@ function inspectSource(repository, sourceRoot, sourcePath) {
|
||||
idSource: explicitId === null ? "source_anchor" : "explicit",
|
||||
context,
|
||||
component,
|
||||
label
|
||||
label,
|
||||
helpExact: hasExactHelp,
|
||||
helpContextId,
|
||||
helpContextDynamic: hasExactHelp && helpContextId === null,
|
||||
helpDynamic: hasHelp && firstAttribute(attributes, helpAttributes) === null,
|
||||
helpRisk: risk.value,
|
||||
helpRiskSource: risk.source,
|
||||
helpRiskReviewed: riskReviewed,
|
||||
highRiskHelpMissing: risk.value !== null && !hasExactHelp && riskReviewed !== "standard"
|
||||
});
|
||||
}
|
||||
|
||||
@@ -354,6 +427,26 @@ function inspectSource(repository, sourceRoot, sourcePath) {
|
||||
return null;
|
||||
}
|
||||
|
||||
function nearestScopedHelpAttributes(node) {
|
||||
let current = node.parent;
|
||||
while (current) {
|
||||
if (ts.isJsxElement(current)) {
|
||||
const attributes = jsxAttributes(current.openingElement);
|
||||
if (attributes.get("data-help-scope") === "field") return attributes;
|
||||
}
|
||||
if (
|
||||
ts.isFunctionDeclaration(current) ||
|
||||
ts.isMethodDeclaration(current) ||
|
||||
ts.isArrowFunction(current) ||
|
||||
ts.isFunctionExpression(current)
|
||||
) {
|
||||
return new Map();
|
||||
}
|
||||
current = current.parent;
|
||||
}
|
||||
return new Map();
|
||||
}
|
||||
|
||||
function jsxAttributes(node) {
|
||||
const mapped = new Map();
|
||||
for (const attribute of node.attributes.properties) {
|
||||
@@ -579,6 +672,34 @@ function hasAnyAttribute(attributes, names) {
|
||||
return false;
|
||||
}
|
||||
|
||||
function helpRiskFor({ component, context, file, label, explicitId, name, explicitRisk }) {
|
||||
if (typeof explicitRisk === "string") {
|
||||
return supportedHelpRisks.has(explicitRisk)
|
||||
? { value: explicitRisk, source: "explicit" }
|
||||
: { value: null, source: "invalid_explicit" };
|
||||
}
|
||||
const value = [component, context, file, label, explicitId, name]
|
||||
.filter((item) => typeof item === "string")
|
||||
.join(" ")
|
||||
.toLowerCase()
|
||||
.replace(/^i18n:/g, "")
|
||||
.replace(/[._-]+/g, " ");
|
||||
const patterns = [
|
||||
["irreversible", /\b(delete|destroy|erase|purge|dispose|disposition|revoke|withdraw|shred)\b/],
|
||||
["credential", /\b(credential|password|secret|token|api key|private key)\b/],
|
||||
["retention", /\b(retention|legal hold|archive lifecycle)\b/],
|
||||
["encryption", /\b(encrypt|encryption|decrypt|decryption|signing key|signature key)\b/],
|
||||
["disclosure", /\b(disclose|disclosure|publish|share externally|public export)\b/],
|
||||
["external-effect", /\b(send|deliver|transfer|refund|payment execution|webhook execution)\b/],
|
||||
["authority", /\b(grant permission|role assignment|approve|reject|formal decision|mandate)\b/],
|
||||
["policy", /\b(policy apply|policy override|enforcement mode)\b/]
|
||||
];
|
||||
for (const [risk, pattern] of patterns) {
|
||||
if (pattern.test(value)) return { value: risk, source: "inferred" };
|
||||
}
|
||||
return { value: null, source: null };
|
||||
}
|
||||
|
||||
function slug(value) {
|
||||
const normalized = value
|
||||
.toLowerCase()
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
{
|
||||
"schema_version": 1,
|
||||
"maximum_missing_exact_help": 0,
|
||||
"rationale": "The source-derived high-risk queue for Core issue #284 is fully resolved. Strict declarations reject any new high-risk control without an exact, manifest-declared, German-complete F1 context."
|
||||
}
|
||||
@@ -31,6 +31,9 @@ ENDPOINT_SURFACE_CATEGORIES = {
|
||||
DEFAULT_ENDPOINT_DECLARATIONS = (
|
||||
META_ROOT / "tools" / "inventory" / "endpoint-surface-declarations.json"
|
||||
)
|
||||
DEFAULT_HIGH_RISK_HELP_BASELINE = (
|
||||
META_ROOT / "tools" / "inventory" / "high-risk-help-baseline.json"
|
||||
)
|
||||
REQUIRED_LOCALES = ("de", "en")
|
||||
REFERENCE_LOCALE = "de"
|
||||
|
||||
@@ -75,6 +78,12 @@ def main() -> int:
|
||||
default=DEFAULT_ENDPOINT_DECLARATIONS,
|
||||
help="Versioned endpoint-surface declaration registry.",
|
||||
)
|
||||
parser.add_argument(
|
||||
"--high-risk-help-baseline",
|
||||
type=Path,
|
||||
default=DEFAULT_HIGH_RISK_HELP_BASELINE,
|
||||
help="Versioned upper bound for high-risk controls without exact F1 help.",
|
||||
)
|
||||
args = parser.parse_args()
|
||||
|
||||
catalog = json.loads((META_ROOT / "repositories.json").read_text(encoding="utf-8"))
|
||||
@@ -85,11 +94,15 @@ def main() -> int:
|
||||
endpoint_declarations = _load_endpoint_declarations(
|
||||
args.endpoint_declarations.resolve()
|
||||
)
|
||||
high_risk_help_baseline = _load_high_risk_help_baseline(
|
||||
args.high_risk_help_baseline.resolve()
|
||||
)
|
||||
inventory = _assemble_inventory(
|
||||
webui=webui,
|
||||
backend_endpoints=backend_endpoints,
|
||||
manifests=manifests,
|
||||
endpoint_declarations=endpoint_declarations,
|
||||
high_risk_help_baseline=high_risk_help_baseline,
|
||||
runtime_snapshot=(
|
||||
_load_runtime_snapshot(args.runtime_snapshot.resolve())
|
||||
if args.runtime_snapshot is not None
|
||||
@@ -164,6 +177,28 @@ def _strict_failures(
|
||||
f"{len(declaration_health['stale_runtime_routes'])} runtime route "
|
||||
"declarations have no WebUI implementation"
|
||||
)
|
||||
help_health = inventory.get("help_health", {})
|
||||
if check_declarations and help_health.get("invalid_risk_annotations"):
|
||||
failures.append(
|
||||
f"{len(help_health['invalid_risk_annotations'])} controls use an "
|
||||
"unsupported contextual-help risk class"
|
||||
)
|
||||
if check_declarations and help_health.get("baseline_regression"):
|
||||
failures.append(
|
||||
f"{len(help_health['missing_exact_high_risk_help'])} high-risk "
|
||||
"controls lack exact F1 help; baseline permits at most "
|
||||
f"{help_health['baseline_maximum_missing']}"
|
||||
)
|
||||
if check_declarations and help_health.get("unresolved_exact_high_risk_help"):
|
||||
failures.append(
|
||||
f"{len(help_health['unresolved_exact_high_risk_help'])} high-risk "
|
||||
"controls reference no manifest DocumentationTopic help context"
|
||||
)
|
||||
if check_declarations and help_health.get("high_risk_help_without_german"):
|
||||
failures.append(
|
||||
f"{len(help_health['high_risk_help_without_german'])} high-risk "
|
||||
"controls resolve to documentation without complete German content"
|
||||
)
|
||||
runtime_comparison = inventory.get("runtime_comparison")
|
||||
if (
|
||||
check_declarations
|
||||
@@ -355,6 +390,29 @@ def _extract_manifests(
|
||||
}
|
||||
for permission in manifest.permissions
|
||||
],
|
||||
"documentation": [
|
||||
{
|
||||
"id": topic.id,
|
||||
"help_contexts": sorted(
|
||||
{
|
||||
str(context)
|
||||
for context in topic.metadata.get(
|
||||
"help_contexts", ()
|
||||
)
|
||||
if isinstance(context, str) and context.strip()
|
||||
}
|
||||
),
|
||||
"german_complete": (
|
||||
isinstance(topic.translations.get("de"), dict)
|
||||
and all(
|
||||
isinstance(topic.translations["de"].get(field), str)
|
||||
and topic.translations["de"][field].strip()
|
||||
for field in ("title", "summary", "body")
|
||||
)
|
||||
),
|
||||
}
|
||||
for topic in manifest.documentation
|
||||
],
|
||||
"architecture": (
|
||||
manifest.architecture.to_dict()
|
||||
if manifest.architecture is not None
|
||||
@@ -400,6 +458,7 @@ def _assemble_inventory(
|
||||
backend_endpoints: list[dict[str, Any]],
|
||||
manifests: list[dict[str, Any]],
|
||||
endpoint_declarations: dict[tuple[str, str, str], dict[str, Any]],
|
||||
high_risk_help_baseline: dict[str, Any] | None = None,
|
||||
runtime_snapshot: dict[str, Any] | None = None,
|
||||
) -> dict[str, Any]:
|
||||
frontend_refs = webui["frontendApiReferences"]
|
||||
@@ -471,8 +530,47 @@ def _assemble_inventory(
|
||||
if any(key not in catalog_keys.get(locale, set()) for locale in expected_locales)
|
||||
]
|
||||
fields = webui["fields"]
|
||||
actions = webui.get("actions", [])
|
||||
help_candidates = [field for field in fields if field["helpCandidate"]]
|
||||
dynamic_help = [field for field in fields if field.get("helpDynamic")]
|
||||
controls = [*fields, *actions]
|
||||
high_risk_controls = [item for item in controls if item.get("helpRisk")]
|
||||
missing_exact_high_risk_help = [
|
||||
item for item in controls if item.get("highRiskHelpMissing")
|
||||
]
|
||||
invalid_risk_annotations = [
|
||||
item
|
||||
for item in controls
|
||||
if item.get("helpRiskSource") == "invalid_explicit"
|
||||
]
|
||||
documentation_contexts = {
|
||||
context: {
|
||||
"module_id": manifest["id"],
|
||||
"topic_id": topic["id"],
|
||||
"german_complete": topic["german_complete"],
|
||||
}
|
||||
for manifest in manifests
|
||||
for topic in manifest.get("documentation", [])
|
||||
for context in topic.get("help_contexts", [])
|
||||
}
|
||||
unresolved_exact_high_risk_help = [
|
||||
item
|
||||
for item in high_risk_controls
|
||||
if item.get("helpExact")
|
||||
and not item.get("helpContextDynamic")
|
||||
and item.get("helpContextId") not in documentation_contexts
|
||||
]
|
||||
high_risk_help_without_german = [
|
||||
item
|
||||
for item in high_risk_controls
|
||||
if item.get("helpContextId") in documentation_contexts
|
||||
and not documentation_contexts[item["helpContextId"]]["german_complete"]
|
||||
]
|
||||
baseline_maximum_missing = (
|
||||
high_risk_help_baseline["maximum_missing_exact_help"]
|
||||
if high_risk_help_baseline is not None
|
||||
else None
|
||||
)
|
||||
governance_adoption = Counter(
|
||||
dimension["adoption"]
|
||||
for manifest in manifests
|
||||
@@ -499,10 +597,34 @@ def _assemble_inventory(
|
||||
"modules": manifests,
|
||||
"interface_declarations": source_declarations,
|
||||
"declaration_health": declaration_health,
|
||||
"help_health": {
|
||||
"supported_risk_classes": sorted(
|
||||
{
|
||||
str(item["helpRisk"])
|
||||
for item in high_risk_controls
|
||||
if item.get("helpRisk")
|
||||
}
|
||||
),
|
||||
"high_risk_controls": high_risk_controls,
|
||||
"missing_exact_high_risk_help": missing_exact_high_risk_help,
|
||||
"invalid_risk_annotations": invalid_risk_annotations,
|
||||
"unresolved_exact_high_risk_help": unresolved_exact_high_risk_help,
|
||||
"high_risk_help_without_german": high_risk_help_without_german,
|
||||
"dynamic_owner_context_controls": [
|
||||
item
|
||||
for item in high_risk_controls
|
||||
if item.get("helpContextDynamic")
|
||||
],
|
||||
"baseline_maximum_missing": baseline_maximum_missing,
|
||||
"baseline_regression": (
|
||||
baseline_maximum_missing is not None
|
||||
and len(missing_exact_high_risk_help) > baseline_maximum_missing
|
||||
),
|
||||
},
|
||||
"runtime_comparison": runtime_comparison,
|
||||
"ui": {
|
||||
"fields": fields,
|
||||
"actions": webui.get("actions", []),
|
||||
"actions": actions,
|
||||
"labels": webui["labels"],
|
||||
"visible_text": webui["visibleText"],
|
||||
"routes": webui["routes"],
|
||||
@@ -554,7 +676,19 @@ def _assemble_inventory(
|
||||
"ui_fields_with_resolvable_f1_context": len(fields),
|
||||
"help_review_candidates": len(help_candidates),
|
||||
"dynamic_help_references": len(dynamic_help),
|
||||
"ui_actions": len(webui.get("actions", [])),
|
||||
"ui_actions": len(actions),
|
||||
"high_risk_controls": len(high_risk_controls),
|
||||
"high_risk_controls_with_exact_help": (
|
||||
len(high_risk_controls) - len(missing_exact_high_risk_help)
|
||||
),
|
||||
"high_risk_controls_missing_exact_help": len(
|
||||
missing_exact_high_risk_help
|
||||
),
|
||||
"invalid_help_risk_annotations": len(invalid_risk_annotations),
|
||||
"unresolved_exact_high_risk_help": len(
|
||||
unresolved_exact_high_risk_help
|
||||
),
|
||||
"high_risk_help_without_german": len(high_risk_help_without_german),
|
||||
"interface_declarations": len(source_declarations),
|
||||
"duplicate_interface_ids": len(declaration_health["duplicate_ids"]),
|
||||
"undeclared_source_surfaces": len(
|
||||
@@ -885,6 +1019,10 @@ def _render_markdown(inventory: dict[str, Any]) -> str:
|
||||
for item in inventory["api"]["unreferenced_by_static_webui_scan"]
|
||||
)
|
||||
classification_counts = inventory["api"]["classification_counts"]
|
||||
high_risk_by_repository = Counter(
|
||||
item["repository"]
|
||||
for item in inventory["help_health"]["missing_exact_high_risk_help"]
|
||||
)
|
||||
lines = [
|
||||
"# GovOPlaN Platform Interface Inventory",
|
||||
"",
|
||||
@@ -900,6 +1038,12 @@ def _render_markdown(inventory: dict[str, Any]) -> str:
|
||||
f"- Fields with a resolvable F1 context: {summary['ui_fields_with_resolvable_f1_context']}",
|
||||
f"- Fields with dynamic help references: {summary['dynamic_help_references']}",
|
||||
f"- Help review candidates: {summary['help_review_candidates']}",
|
||||
f"- High-risk controls: {summary['high_risk_controls']}",
|
||||
f"- High-risk controls with exact F1 help: {summary['high_risk_controls_with_exact_help']}",
|
||||
f"- High-risk controls missing exact F1 help: {summary['high_risk_controls_missing_exact_help']}",
|
||||
f"- Invalid help-risk annotations: {summary['invalid_help_risk_annotations']}",
|
||||
f"- High-risk exact contexts missing a manifest topic: {summary['unresolved_exact_high_risk_help']}",
|
||||
f"- High-risk contexts without complete German topic content: {summary['high_risk_help_without_german']}",
|
||||
f"- Stable interface declarations: {summary['interface_declarations']}",
|
||||
f"- Duplicate interface IDs: {summary['duplicate_interface_ids']}",
|
||||
f"- WebUI surfaces missing runtime declarations: {summary['undeclared_source_surfaces']}",
|
||||
@@ -930,6 +1074,23 @@ def _render_markdown(inventory: dict[str, Any]) -> str:
|
||||
f"| `{repository}` | {count} |"
|
||||
for repository, count in sorted(help_by_repository.items())
|
||||
)
|
||||
lines.extend(
|
||||
[
|
||||
"",
|
||||
"## High-risk Contextual-help Debt",
|
||||
"",
|
||||
"Inferred or explicitly classified high-risk controls require an exact",
|
||||
"F1 context. `data-help-risk-reviewed=\"standard\"` records a reviewed",
|
||||
"false positive. The versioned baseline makes this queue non-regressing.",
|
||||
"",
|
||||
"| Repository | Missing exact contexts |",
|
||||
"| --- | ---: |",
|
||||
]
|
||||
)
|
||||
lines.extend(
|
||||
f"| `{repository}` | {count} |"
|
||||
for repository, count in sorted(high_risk_by_repository.items())
|
||||
)
|
||||
lines.extend(
|
||||
[
|
||||
"",
|
||||
@@ -1005,6 +1166,29 @@ def endpoint_key(endpoint: dict[str, Any]) -> tuple[str, str, str]:
|
||||
)
|
||||
|
||||
|
||||
def _load_high_risk_help_baseline(path: Path) -> dict[str, Any]:
|
||||
try:
|
||||
payload = json.loads(path.read_text(encoding="utf-8"))
|
||||
except FileNotFoundError as exc:
|
||||
raise ValueError(
|
||||
f"High-risk contextual-help baseline does not exist: {path}"
|
||||
) from exc
|
||||
except json.JSONDecodeError as exc:
|
||||
raise ValueError(
|
||||
f"High-risk contextual-help baseline is invalid JSON: {exc}"
|
||||
) from exc
|
||||
if not isinstance(payload, dict) or payload.get("schema_version") != 1:
|
||||
raise ValueError(
|
||||
"High-risk contextual-help baseline must use schema_version 1."
|
||||
)
|
||||
maximum = payload.get("maximum_missing_exact_help")
|
||||
if not isinstance(maximum, int) or isinstance(maximum, bool) or maximum < 0:
|
||||
raise ValueError(
|
||||
"High-risk contextual-help baseline maximum must be a non-negative integer."
|
||||
)
|
||||
return payload
|
||||
|
||||
|
||||
def _load_endpoint_declarations(
|
||||
path: Path,
|
||||
) -> dict[tuple[str, str, str], dict[str, Any]]:
|
||||
|
||||
Reference in New Issue
Block a user