Registry submission
Submission is separate from approval. Approval never auto-submits, and submission stays disabled without explicit configuration.
Preconditions
Section titled “Preconditions”POST /api/biobadamex/drafts/:id/submit requires session, research access, ownership, approved state, resolved required fields, BIOBADAMEX_REGISTRY_SUBMIT_ENABLED=1, comorbidity confirmation when needed, and a valid map-versioned payload.
Admins may audit-read another clinician’s draft but cannot submit it. Unowned drafts are not submittable.
The API enqueues draft id, approved record, and map version. Registry submit uses batch size one per worker but no specific retry policy. Multiple app instances need extra coordination to guarantee one global external session.
Sandbox
Section titled “Sandbox”For each job, the service validates configuration, loads the worker bundle, creates a disposable Tenki microVM, injects payload and credentials through process environment, runs Playwright, parses structured JSON, and disposes the microVM.
External flow
Section titled “External flow”- Log in.
- Fill and save
crdA. - Read assigned
idpac. - Visit and save
crdB,crdC,crdD, andcrdE. - Open summary.
- Require text for the same
idpac.
idpac and summary are fatal checks. Many individual fields are best effort: missing controls or unmatched options are logged and skipped. succeeded confirms patient and summary, not field-by-field parity.
External map
Section titled “External map”The control map is versioned. Selector changes require a version bump and revalidation. Known gaps include unmapped controls, radio ambiguities, BASDAI ambiguity, biologic brands awaiting validation, and uncovered detail/date fields. Do not describe it as total form coverage.
Biologic treatments
Section titled “Biologic treatments”crdE accepts role-aware episodes. Only previous enters prior treatments. The worker rejects unknown role with identified drug, brand-substance conflict, duplicate control overwrite, and unmapped drugs.
Outcomes
Section titled “Outcomes”- Success persists
idpac,submittedAt,submittedstate, and audit. - Form rejection persists
submitError, audits, and does not repeat the same submission. - Infrastructure failure throws, but the queue has no specific registry-submit retry policy.
- Current read-back confirms summary, not each field.
- Bounded read contracts exist but are not mounted in this commit’s submit flow.
Idempotency and state risks
Section titled “Idempotency and state risks”- The endpoint drops the job id and uses no per-draft singleton. Two requests before the first outcome can enqueue two external mutations.
- If
crdAassigns anidpacand a later page fails, the failed result may carry it in memory, but persistence stores onlysubmitError. Retry can repeat identity creation. summaryUrlis not persisted.- Infrastructure failure before structured result leaves the draft
approvedwithoutsubmitError; the UI has no durablequeued/runningstate.