Build document attachment collector for activities
epic-bufdir-reporting-export-processing-services-task-008 — Implement the BufdirAttachmentBundler's collection phase that queries the database for all document attachments linked to activities within the export scope. Retrieve signed URLs from Supabase Storage for each attachment, validate file availability, and build a manifest of documents to include in the export bundle.
Acceptance Criteria
Technical Requirements
Execution Context
Tier 1 - 540 tasks
Can start after Tier 0 completes
Implementation Notes
Model the collection phase as a dedicated method `collectAttachmentManifest(String organisationId, String reportPeriodId)` on the `BufdirAttachmentBundler` class. Use a Supabase join query on the attachments table filtered by `organisation_id` and a subquery of activity IDs within the report period — avoid multiple round-trips. Batch signed URL creation using `supabase.storage.from(bucket).createSignedUrls(paths, expiresIn)` which accepts a list — this avoids N+1 calls. For availability validation, use `Future.wait` with a pool pattern (e.g.
`package:async`'s `Pool`) capped at 10 concurrent requests. Define `BufdirAttachmentManifestEntry` as an immutable Dart class with `copyWith`. Log warnings via a structured logger, not `print()`. Store the manifest as a `List
Ensure the method is `async` and returns `Future>` — never void.
Testing Requirements
Unit tests (flutter_test with Mockito or mocktail) must cover: (1) happy path — mock Supabase returning 3 attachments for 2 activities, assert manifest has 3 entries with correct field values; (2) unavailable file — one attachment returns 404 on availability check, assert it is excluded and a warning is emitted; (3) empty scope — no activities in period, assert empty manifest returned without exception; (4) RLS boundary — query executed with wrong org context returns empty result, assert no crash; (5) partial failure — 2 of 5 signed URL generations fail, assert 3 entries in manifest with 2 warnings logged. Integration tests against a Supabase test project should cover the full collection cycle with real Storage objects. Test coverage for BufdirAttachmentBundler collection phase must be at least 90%.
NHF contacts can belong to up to five local chapters simultaneously. If the deduplication logic in the activity query service incorrectly attributes cross-chapter activities, organisations will either under-report or over-report to Bufdir, which could trigger grant clawback or compliance investigations.
Mitigation & Contingency
Mitigation: Implement deduplication using the existing multi-chapter membership service as the source of truth for chapter affiliation. Write test fixtures covering all known multi-chapter edge cases and validate outputs against manually prepared reference exports from NHF.
Contingency: If deduplication cannot be made deterministic for complex hierarchies before release, gate the export behind an org-level feature flag and require NHF to validate a preview export against their manual Excel before enabling in production.
Server-side Dart libraries for Excel generation are less mature than equivalents in Node.js or Python. The chosen library may lack support for Bufdir-required formatting features (merged cells, data validation, specific date formats), requiring significant workaround effort or a library switch mid-implementation.
Mitigation & Contingency
Mitigation: Evaluate the top two Dart xlsx libraries (excel, spreadsheet_decoder) against a Bufdir template sample file before committing. Identify all required formatting features and verify library support in a spike.
Contingency: If no Dart library meets requirements, implement the Excel generation as a Supabase Edge Function in TypeScript using the well-supported ExcelJS library, exposing it to the Dart backend via an internal RPC call.
The attachment bundler must retrieve documents from Supabase Storage that were uploaded by the document attachments feature. If storage paths, RLS policies, or signed URL expiry have not been standardised across features, the bundler may fail to retrieve attachments at export time.
Mitigation & Contingency
Mitigation: Audit the document attachments feature's storage schema and RLS policies before implementing the bundler. Agree on a stable internal service-account access pattern for cross-feature storage reads.
Contingency: If cross-feature storage access cannot be made reliable, implement the bundler to include only attachments that can be retrieved successfully and produce a manifest listing any attachments that could not be bundled, rather than failing the entire export.