feat: wire persistence into the web layer (check → archive → dossier)
This is the piece that turns a Pre-Publish-Prüfung into an actual
archived, provable record instead of a one-off form response.
extract.Client.Extract now returns Result{Facts, RawJSON} instead of
just Facts — RawJSON is the model's exact, unmodified JSON, which is
what belongs in extraction.payload (the audit trail), not a re-encoded
view through our own Facts struct. extract.ParsePayload reconstructs
Facts from a stored payload later, reusing the same parsing/validation
path Extract uses (including the enum guard), so a previously-saved
extraction can be read back exactly as it would have been the first
time.
internal/dossier.BuildContent no longer requires AssetHash: most checks
right now are caption-only (no image/video upload wired yet), and
inventing a placeholder hash for a nonexistent asset would itself be an
integrity problem in an evidence tool. Content shows "kein Asset
hinterlegt" instead.
internal/web gains a narrow Store interface (mirroring the Extractor
pattern — only the methods these handlers use, not the full
*store.Store) so its test suite stays network/DB-free via an in-memory
fake:
- POST /pruefen persists submission + extraction + findings and marks
the submission "checked". A needsClarification result persists the
extraction (there's something worth keeping) but no findings and no
status change, and the template omits the archive option entirely.
- POST /veroeffentlichen re-derives Facts from the stored payload, hashes
the canonical submission+facts+findings metadata, gets an RFC-3161
timestamp, generates the PDF dossier to disk, and persists the
evidence_package row before marking the submission "published".
- GET /dossier/{id} serves the generated PDF.
Tested end-to-end offline: a fake Timestamper builds a real, structurally
valid self-signed RFC-3161 response so the full check→archive→download
flow runs against an in-memory store, verifying the downloaded bytes are
an actual PDF and the dossier file lands on disk — without hitting a
real database, TSA, or the Claude API.
cmd/deklarix/main.go now wires store.Store, evidence.NewHTTPTimestamper
(TSA_URL, default FreeTSA), and DOSSIER_DIR (default "dossiers") into
web.NewServer alongside the extractor and rule set.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -9,6 +9,15 @@ PORT=8080
|
||||
# /usr/share/deklarix/rules installiert (siehe scripts/build.sh).
|
||||
RULES_DIR=/usr/share/deklarix/rules
|
||||
|
||||
# Wo erzeugte Nachweis-Dossiers (PDF) abgelegt werden. Wird beim
|
||||
# Archivieren eines Beitrags automatisch angelegt.
|
||||
DOSSIER_DIR=/var/lib/deklarix/dossiers
|
||||
|
||||
# RFC-3161-Zeitstempeldienst. Leer = FreeTSA.org (frei, aber NICHT
|
||||
# eIDAS-qualifiziert — siehe CLAUDE.md, Offene Punkte). Vor echtem
|
||||
# Kundeneinsatz auf einen eIDAS-qualifizierten Dienst umstellen.
|
||||
#TSA_URL=https://freetsa.org/tsr
|
||||
|
||||
# Pflicht — der Dienst startet nicht ohne gültige DATABASE_URL und
|
||||
# ANTHROPIC_API_KEY. Beide auskommentiert lassen, bis echte Werte
|
||||
# eingetragen sind: postinst prüft genau diese beiden Zeilen, um den
|
||||
|
||||
Reference in New Issue
Block a user