feat(core-dsr): handlers, dsrRouter, integration tests

Add four protocol-agnostic handlers (export, delete, rectify, restrict)
returning normalized { status, body, headers } responses, and a tRPC
dsrRouter via createDsrRouter(binding) following the factory pattern.

Auth checks: requireAuthenticated middleware gates all four procedures;
cascade-hard delete additionally requires admin role. Integration tests
assert happy-path response shapes, UNAUTHORIZED/FORBIDDEN error codes,
and error passthrough from the DSR service layer.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-05-19 20:34:51 +00:00
parent 6f56a04335
commit 46e575a5a6
13 changed files with 588 additions and 4 deletions

View File

@@ -0,0 +1,20 @@
import type { IDataDelete } from "../data-delete.interface";
import type { DeletionMode, DeletionCertificate } from "../dsr-types";
import type { HandlerResponse } from "./handler-types";
export type DeleteHandlerInput = {
subjectId: string;
mode: DeletionMode;
};
export function createDeleteHandler(dataDelete: IDataDelete) {
return async (
input: DeleteHandlerInput,
): Promise<HandlerResponse<DeletionCertificate>> => {
const cert = await dataDelete.deleteSubjectData(
input.subjectId,
input.mode,
);
return { status: 200, body: cert };
};
}

View File

@@ -0,0 +1,24 @@
import type { IDataExport } from "../data-export.interface";
import type { DsrFormat, UserDataBundle } from "../dsr-types";
import type { HandlerResponse } from "./handler-types";
export type ExportHandlerInput = {
subjectId: string;
format: DsrFormat;
};
export function createExportHandler(dataExport: IDataExport) {
return async (
input: ExportHandlerInput,
): Promise<HandlerResponse<UserDataBundle>> => {
const bundle = await dataExport.exportSubjectData(
input.subjectId,
input.format,
);
const headers: Record<string, string> =
input.format === "json-ld"
? { "Content-Type": "application/ld+json" }
: { "Content-Type": "application/json" };
return { status: 200, body: bundle, headers };
};
}

View File

@@ -0,0 +1,5 @@
export type HandlerResponse<T = unknown> = {
status: number;
body: T;
headers?: Record<string, string>;
};

View File

@@ -0,0 +1,23 @@
import type { IDataRectify } from "../data-rectify.interface";
import type { HandlerResponse } from "./handler-types";
export type RectifyHandlerInput = {
subjectId: string;
collection: string;
field: string;
value: unknown;
};
export function createRectifyHandler(dataRectify: IDataRectify) {
return async (
input: RectifyHandlerInput,
): Promise<HandlerResponse<{ ok: true }>> => {
await dataRectify.updateSubjectField(
input.subjectId,
input.collection,
input.field,
input.value,
);
return { status: 200, body: { ok: true as const } };
};
}

View File

@@ -0,0 +1,18 @@
import type { IProcessingRestriction } from "../processing-restriction.interface";
import type { HandlerResponse } from "./handler-types";
export type RestrictHandlerInput = {
subjectId: string;
granted: boolean;
};
export function createRestrictHandler(
processingRestriction: IProcessingRestriction,
) {
return async (
input: RestrictHandlerInput,
): Promise<HandlerResponse<{ ok: true }>> => {
await processingRestriction.setRestriction(input.subjectId, input.granted);
return { status: 200, body: { ok: true as const } };
};
}