elsa-core/specs/013-user-tasks/contracts/forms-contract.md
Sipke Schoorstra ffff359756
feat(user-tasks): add identity-neutral workflow-bound human tasks (#7955)
Adds durable, identity-neutral, workflow-bound human tasks, and reconciles the
REST surface with the approved Studio contract.

- Flat summary/detail DTOs, a global capability descriptor, and workflow context
  captured at activation.
- Scope is part of the list authorization predicate; manager decisions require
  manage:user-tasks; a denied command answers 404 so it cannot prove a task exists.
- Guest sessions are task-scoped, action-allowlisted, and revoked when the task
  closes. Invitations resolve by token hash through the repository, wait in a
  Data Protection encrypted outbox, and are rate limited per caller.
- Masked form values are disclosed only through an audited reveal command.
- Store-specific concurrency failures are translated into a single
  UserTaskRevisionConflictException, so a concurrent edit returns the documented
  revision-conflict result behind any provider instead of a 500.

EF Core (SQLite, SQL Server, PostgreSQL, MySQL, Oracle) and VNext persistence,
hosted due/reconciliation/delivery workers, docs, and 49 tests.

Note: this branch also carries two commits inherited from its branch point that
are not part of User Tasks and are squashed in here — the revert-version
allocation change from #7917 (WorkflowDefinitionPublisher.RevertVersionAsync now
allocates from the last version rather than the latest) and an NU1903 package
pin. Merged deliberately rather than rebased out.
2026-08-25 00:09:06 +02:00

1.1 KiB

Forms Contract

FormReference contains provider, id, and an optional version selector. The replaceable IUserTaskFormProvider resolves a reference during activation, returns a version-pinned render descriptor, and validates/normalizes completion data.

  • A selector such as latest is resolved once and stored as a concrete version on the task.
  • Resolution failure creates a blocking manager-only health issue; it never silently substitutes a different form.
  • Repair retries the original reference. V1 provides no live editing or repinning of an open task.
  • Workers receive only the provider-neutral render descriptor after assignment. Studio delegates rendering to a registered renderer and shows an unsupported-provider state otherwise.
  • Submitted data is bounded to 256 KiB by default, validated by the same provider and pinned version, normalized, then stored and supplied to the workflow result.
  • A task without a form accepts no arbitrary data; completion consists only of a configured action.
  • Form data is protected, excluded from search and audit payloads, and retained/purged with the task.
  • V1 has no native form builder or draft protocol.