Invulhulp voor pre-scan, DPIA en IAMA. Samen online of volledig lokaal in je browser, zonder account. https://invulhulpen.rijksapp.nl/
  • TypeScript 80.1%
  • Vue 11.2%
  • Python 3.8%
  • JavaScript 2.2%
  • CSS 1.9%
  • Other 0.8%
Find a file
Robbert Bos 48f4e1c708
fix(pre-scan): laat de gewichten van 1.4.1 en 5.1.2 weer meetellen (#508)
* fix(prescan): let the weights of 1.4.1 and 5.1.2 count again

weightedCountMap looks its keys up verbatim in a plain object, so a key
that does not match the stored answer character for character silently
adds 0. The keys of both questions never matched their option values:
the values carry a 'Categorie betrokkenen: ' / 'Basisregistratie: '
prefix that the keys omit.

Both score keys therefore stayed 0 no matter what was ticked, so the
weights (up to 3 points for children under 16 and other vulnerable
groups) never reached the DPIA threshold of "sum > 4".

Measured against the real calculation store, one filled-in form:
before betrokkenen=0 basisregistratie=0 -> no obligation,
after  betrokkenen=2 basisregistratie=1 -> DPIA verplicht.

Guards the invariant in the content test: every weightedCountMap key
must match an existing option value.

* test(pre-scan): assert the DPIA verdict, not just the score

The weighted answers now run all the way through: risk score mapping,
the sum > 4 criterion and the resulting "DPIA verplicht" level. Without
the fix the scenario yields no obligation at all.

Tightens the changelog entry to match the surrounding style, which keeps
the feature as the subject of the sentence.

---------

Co-authored-by: Ravi Meijer <ravi.meijer@rijksoverheid.nl>
2026-09-07 08:33:25 +02:00
.claude chore(release): v2026.8.25 2026-08-25 12:16:59 +02:00
.claude-plugin feat(plugin): follow the app's CalVer, guarded at release time 2026-08-23 23:11:07 +02:00
.github build(deps): bump github/codeql-action/upload-sarif 2026-09-06 17:51:21 +02:00
apps build(deps): bump the npm-dependencies group across 1 directory with 9 updates 2026-09-06 22:23:03 +02:00
containers build(deps): bump the container-images group across 1 directory with 2 updates 2026-09-06 22:28:00 +02:00
docs fix(deps): unblock CI on the new fast-uri advisories 2026-09-06 22:23:03 +02:00
LICENSES chore: make the repository REUSE compliant 2026-08-24 16:47:52 +02:00
packages/assessment-core fix(pre-scan): laat de gewichten van 1.4.1 en 5.1.2 weer meetellen (#508) 2026-09-07 08:33:25 +02:00
schemas fix: IAMA-antwoorden verdwijnen vanaf stap 2 and tie the client answer-key rule and the sources to the schema 2026-08-25 12:02:11 +02:00
script fix: IAMA-antwoorden verdwijnen vanaf stap 2 and tie the client answer-key rule and the sources to the schema 2026-08-25 12:02:11 +02:00
scripts feat(security): send X-Permitted-Cross-Domain-Policies and pin the baseline 2026-08-25 12:10:13 +02:00
sources fix(pre-scan): laat de gewichten van 1.4.1 en 5.1.2 weer meetellen (#508) 2026-09-07 08:33:25 +02:00
tests/e2e Hernoem Assessment Boekhouding naar Invulhulpen + RVO logo-tagline 2026-06-07 23:29:13 +02:00
.containerignore chore(containers): build the API image without a package manager 2026-08-22 22:37:01 +02:00
.editorconfig Slimme sync bij samenwerken: geen onnodige meldingen (#1) 2026-04-12 19:35:52 +02:00
.gitattributes Restructure into pnpm monorepo with multi-user assessment platform 2026-03-15 16:56:19 +01:00
.gitignore chore: keep artifacts/ out of the repository 2026-08-23 14:50:39 +02:00
.pre-commit-config.yaml chore: pre-commit autoupdate 2026-09-06 22:27:23 +02:00
.prettierrc.json Slimme sync bij samenwerken: geen onnodige meldingen (#1) 2026-04-12 19:35:52 +02:00
CHANGELOG.md fix(pre-scan): laat de gewichten van 1.4.1 en 5.1.2 weer meetellen (#508) 2026-09-07 08:33:25 +02:00
CODE_OF_CONDUCT.md docs: add SUPPORT.md and GOVERNANCE.md, point every contact at one mailbox 2026-08-24 16:01:57 +02:00
CONTRIBUTING.md chore: make the repository REUSE compliant 2026-08-24 16:47:52 +02:00
DCO.md project-setup 2025-03-06 09:57:49 +01:00
eslint.config.ts Restructure into pnpm monorepo with multi-user assessment platform 2026-03-15 16:56:19 +01:00
GOVERNANCE.md ci: keep publiccode.yml on the released version 2026-08-24 16:01:57 +02:00
LICENSE project-setup 2025-03-06 09:57:49 +01:00
package.json feat(security): send X-Permitted-Cross-Domain-Policies and pin the baseline 2026-08-25 12:10:13 +02:00
pnpm-lock.yaml fix(deps): unblock CI on the new fast-uri advisories 2026-09-06 22:23:03 +02:00
pnpm-workspace.yaml fix(deps): unblock CI on the new fast-uri advisories 2026-09-06 22:23:03 +02:00
publiccode.yml chore(release): v2026.8.25 2026-08-25 12:16:59 +02:00
pyproject.toml ci(security): add sectxt guard for generated security.txt 2026-08-22 15:25:59 +02:00
README.md docs: add SUPPORT.md and GOVERNANCE.md, point every contact at one mailbox 2026-08-24 16:01:57 +02:00
REUSE.toml chore: make the repository REUSE compliant 2026-08-24 16:47:52 +02:00
SECURITY.md docs(links): point the stale link targets at where they live now 2026-08-24 12:57:23 +02:00
SUPPORT.md ci: keep publiccode.yml on the released version 2026-08-24 16:01:57 +02:00
uv.lock ci(security): add sectxt guard for generated security.txt 2026-08-22 15:25:59 +02:00

PAR Assessments

Status: Beta License: EUPL v1.2

Webapplicatie voor het uitvoeren van Pre-scan-, DPIA- en IAMA-assessments, volgens het Rijksmodel DPIA en het IAMA (Impact Assessment Mensenrechten en Algoritmes) van de Nederlandse overheid. Gebouwd met het RVO component library.

Kenmerken

  • Pre-scan, DPIA en IAMA invullen in de browser als losstaande applicatie
  • Samenwerken aan Pre-scans, DPIA's en IAMA's via Invulhulpen:
    • Samenwerken aan assessments met meerdere gebruikers
    • Projectbeheer met rollen (eigenaar, bewerker, kijker)
    • Voortgang opslaan en later hervatten
    • PDF-export van ingevulde assessments

Architectuur

pnpm monorepo:

Package Omschrijving
packages/assessment-core Gedeelde assessment-engine: formulierweergave, navigatie, validatie, PDF-export
apps/boekhouding-frontend Vue 3 SPA — projectbeheer, samenwerken, Keycloak-login
apps/boekhouding-backend Fastify REST API — PostgreSQL, JWT-authenticatie
apps/standalone-form Standalone formulier — draait zonder backend, exporteert als single HTML
sources/ YAML-bronbestanden voor Pre-scan-, DPIA- en IAMA-assessments

Technologie

  • Frontend: Vue 3 (Composition API), TypeScript, Vite, Pinia
  • Backend: Fastify 5, Drizzle ORM, PostgreSQL 17
  • Auth: Keycloak (OIDC), JWT-verificatie via jose
  • Styling: RVO Design System
  • Standalone: Vite single-file build — alles (HTML, CSS, JS) in één bestand
  • PDF: pdfmake

Aan de slag

Vereisten

  • Volledige stack: Podman of Docker
  • Standalone formulier: Node.js 22+ en pnpm (via corepack enable)

Volledige stack

Start PostgreSQL, Keycloak en de applicatie met één commando. Wil je alleen een formulier invullen zonder backend? Zie Standalone formulier.

podman compose -f containers/compose.dev.yaml up -d
pnpm db:seed  # testdata laden (idempotent)
Service URL
Frontend http://localhost:5174
Backend API http://localhost:3000
Standalone formulier http://localhost:5175
Keycloak admin http://localhost:8080 (admin / admin)

Testgebruikers: sam@example.com / welkom123, noor@example.com / welkom123

De seed maakt drie projecten aan (een pre-scan met antwoorden, een DPIA met versiegeschiedenis, en een leeg project) gekoppeld aan de testgebruikers. Database-migraties draaien automatisch bij het starten van de backend container.

Standalone formulier

Voor ontwikkeling zonder backend (vereist Node.js 22+ en pnpm):

corepack enable
pnpm install
pnpm dev

Bouwen

pnpm build:standalone   # Standalone HTML-bestand
pnpm build:backend      # Backend
pnpm build:frontend     # Frontend

Commando's

Commando Omschrijving
pnpm dev Start standalone formulier
pnpm dev:backend Start backend (vereist PostgreSQL)
pnpm dev:frontend Start frontend
pnpm db:generate Genereer database-migraties
pnpm db:migrate Voer migraties uit
pnpm db:seed Vul database met testdata (idempotent)
pnpm lint Lint de code

Assessment-bronbestanden

De sources/ directory bevat de assessment-definities in YAML:

Bestand Omschrijving
prescan.yaml Pre-scan DPIA-definitie
dpia.yaml Volledige DPIA-definitie
iama.yaml IAMA-definitie
begrippenkader_dpia.yaml Begrippenlijst met tooltips
begrippenkader_iama.yaml Begrippenlijst IAMA / Algoritmekader

YAML verwerken

Vereist uv (Python package manager).

# Valideer en genereer JSON voor standalone formulier
uv run script/run_all.py \
  --schema schemas/assessment-definition.v1.schema.json \
  --source sources/dpia.yaml \
  --begrippen-yaml sources/begrippenkader_dpia.yaml \
  --output-json form-app/src/assets/DPIA.json \
  --output-md docs/questions/questions_DPIA.md

Domeinkennis-plugin (AI-assistent)

Voor ontwikkelaars en redacteuren die in de editor (Claude Code / Cursor) aan déze repo werken is er een Claude-plugin met domeinkennis over de assessment-definities: schema's, begrippenkaders, RVO-styling en een validatie-agent. Het is een hulpmiddel bij het bouwen en onderhouden van de definities en applicatie — niet een invul-assistent voor eindgebruikers die een pre-scan, DPIA of IAMA uitvoeren.

Installeren:

/plugin marketplace add MinBZK/par-dpia-form
/plugin install assessments@assessment-tools

Zie het ontwerp en de verantwoording van de marketplace en plugin.

Standaarden en compliance

Invulhulpen conformeert aan de volgende overheidsstandaarden:

Standaard Status
NL GOV API Design Rules URI-versioning (/api/v1/), application/problem+json, security headers, API-Version header
WCAG 2.2 AA Gedeeltelijk — actieve verbetering, zie toegankelijkheidsverklaring
BIO2 JWT audience-validatie, rate limiting, input-validatie, security headers
AVG / GDPR Dataminimalisatie, RBAC, auditlog, privacyverklaring
EUPL-1.2 Open source licentie conform open-tenzij beleid

Privacy en gegevensverwerking

Zie docs/gegevensverwerking.md voor een overzicht van verwerkte persoonsgegevens, rechtsgrond en bewaartermijnen.

Documentatie

Bijdragen en hulp