Skip to content

Registry submission

Submission is separate from approval. Approval never auto-submits, and submission stays disabled without explicit configuration.

POST /api/biobadamex/drafts/:id/submit requires session, research access, ownership, approved state, resolved required fields, BIOBADAMEX_REGISTRY_SUBMIT_ENABLED=1, comorbidity confirmation when needed, and a valid map-versioned payload.

Admins may audit-read another clinician’s draft but cannot submit it. Unowned drafts are not submittable.

The API enqueues draft id, approved record, and map version. Registry submit uses batch size one per worker but no specific retry policy. Multiple app instances need extra coordination to guarantee one global external session.

For each job, the service validates configuration, loads the worker bundle, creates a disposable Tenki microVM, injects payload and credentials through process environment, runs Playwright, parses structured JSON, and disposes the microVM.

  1. Log in.
  2. Fill and save crdA.
  3. Read assigned idpac.
  4. Visit and save crdB, crdC, crdD, and crdE.
  5. Open summary.
  6. Require text for the same idpac.

idpac and summary are fatal checks. Many individual fields are best effort: missing controls or unmatched options are logged and skipped. succeeded confirms patient and summary, not field-by-field parity.

The control map is versioned. Selector changes require a version bump and revalidation. Known gaps include unmapped controls, radio ambiguities, BASDAI ambiguity, biologic brands awaiting validation, and uncovered detail/date fields. Do not describe it as total form coverage.

crdE accepts role-aware episodes. Only previous enters prior treatments. The worker rejects unknown role with identified drug, brand-substance conflict, duplicate control overwrite, and unmapped drugs.

  • Success persists idpac, submittedAt, submitted state, and audit.
  • Form rejection persists submitError, audits, and does not repeat the same submission.
  • Infrastructure failure throws, but the queue has no specific registry-submit retry policy.
  • Current read-back confirms summary, not each field.
  • Bounded read contracts exist but are not mounted in this commit’s submit flow.
  • The endpoint drops the job id and uses no per-draft singleton. Two requests before the first outcome can enqueue two external mutations.
  • If crdA assigns an idpac and a later page fails, the failed result may carry it in memory, but persistence stores only submitError. Retry can repeat identity creation.
  • summaryUrl is not persisted.
  • Infrastructure failure before structured result leaves the draft approved without submitError; the UI has no durable queued/running state.