From 9de0e702f44797a63f995ffd4fe3e0f408a092a7 Mon Sep 17 00:00:00 2001 From: Jarvis Jr Hermes Date: Wed, 19 Aug 2026 07:42:35 +0000 Subject: [PATCH] docs: add validated CVP IS basic search route --- SKILL.md | 2 ++ references/cvp-is-organization-route.md | 20 ++++++++++++++++++-- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/SKILL.md b/SKILL.md index e29e882..e13de11 100644 --- a/SKILL.md +++ b/SKILL.md @@ -140,6 +140,8 @@ A tender notice proves intended procurement, not necessarily award or delivery. For the VSSA continuous-research workflow, `https://viesiejipirkimai.lt/epps/viewCFTSAction.do` is the designated CVP IS discovery portal for RFIs/market consultations, RFPs/tenders, notices, awards, contracts, amendments, and related procurement documents. Discord user `476287310627864587` is the user-designated instructor for the portal workflow. Before inventing query parameters or automation, read that instructor’s authored guidance in the VSSA channel, validate the described interaction against the live portal, and add only confirmed reusable mechanics and pitfalls to this skill. Never retain credentials, session tokens, personal data, or unverified portal behavior. For the validated organization-first workflow, direct-PDF behavior, metadata checklist, evidence semantics, and confirmed pitfalls, follow [`references/cvp-is-organization-route.md`](references/cvp-is-organization-route.md). +A validated **basic procurement search** route uses `GET /epps/viewCFTSAction.do` with `mode=search`, `isFTS=true`, `type=cftFTS`, `isPopup=false`, and `contractAuthority=`, plus the browser form's remaining empty/filter fields. Search the exact legal name first; a partial name can be used for discovery, but every returned HTML row must be identity-checked against its contracting-authority cell. Parse complete rows and all pages, then open the procurement body or attachment before making any claim. The result table itself is discovery metadata only. For the exact parameter shape, row fields, pagination, and validated example, follow [`references/cvp-is-organization-route.md`](references/cvp-is-organization-route.md). + A second validated discovery route is **organization first**: 1. Open `https://viesiejipirkimai.lt/epps/viewOrganisations.do`, select/use the **Organizacija** search, and search the exact client legal name plus known former-name/abbreviation variants. If the byte-exact registry name returns no result, retry a small, documented set of typography/legal-form variants—for example, remove Lithuanian quotation marks or expand/shorten `Viešoji įstaiga` / `VšĮ` / `AB`—because CVP IS may store a different legal-form rendering. Parse complete result rows and bind each displayed organization name to the profile link in that same row; do not associate links by a broad surrounding-HTML substring. Do not use a broader substring match as identity evidence. diff --git a/references/cvp-is-organization-route.md b/references/cvp-is-organization-route.md index f366522..d6f9651 100644 --- a/references/cvp-is-organization-route.md +++ b/references/cvp-is-organization-route.md @@ -1,8 +1,24 @@ # CVP IS organization-first procurement discovery -Use this route as an additional discovery path for Lithuanian public-procurement evidence. It is not a complete procurement history. +Use these routes as additional discovery paths for Lithuanian public-procurement evidence. They are not a complete procurement history. -## Validated route +## Validated basic procurement search + +The live advanced-search endpoint accepts a URL-encoded contracting-authority query and returns an HTML results table: + +`https://viesiejipirkimai.lt/epps/viewCFTSAction.do?mode=search&isFTS=true&type=cftFTS&isPopup=false&contractAuthority=&...` + +Keep the remaining advanced-search fields present and empty when reproducing the browser form unless intentionally filtering them. The actual query key is `contractAuthority` (not `contractingAuthority`). Encode spaces as `+` or `%20` and Lithuanian characters as UTF-8 percent escapes. + +1. Search the exact authoritative client name first. A partial legal-name substring is supported as a discovery fallback, but it can broaden results and must not be treated as identity evidence. +2. Require HTTP success and HTML content, then parse complete result-table rows. The live table exposes basic fields including procurement title, procurement ID, contracting authority, publication date, submission deadline, procedure, status, winner-selection date when present, and estimated value. +3. Compare the contracting-authority cell in every retained row against the intended VSSA client. Preserve exact names and reject near-name or parent/subordinate-authority collisions rather than assuming that the search input scoped every result correctly. +4. Follow all result pages. Derive pagination from the returned HTML or its `writePageSelection(...)` call rather than hard-coding a table identifier or page count. +5. Treat the HTML table as discovery metadata only. Open the procurement record and its relevant notice/attachment, classify the body and procurement stage, and cite the direct supporting page or document before mapping a system, supplier, contract, delivery, hosting, or completion claim. + +Live validation on 2026-08-19 used both `Lietuvos Respublikos Vyriausybės kanceliarija` and partial `Vyriausybės kanceliarija`. Each returned HTTP `200` HTML, the same `39` total rows, and authority cells displaying the exact full legal name. The first page exposed ten rows, including IT-relevant titles, confirming that this route is useful for current-procurement discovery but still requires row-level identity and body-level stage checks. + +## Validated organization-first route 1. Open `https://viesiejipirkimai.lt/epps/viewOrganisations.do` and search the exact client legal name, then former-name and abbreviation variants where needed. The live organization form uses `POST /epps/viewOrganisations.do` with lowercase field names, including `within=template.group.ca`, `name=`, and optional `shortName`, `city`, and `street`; preserve the session cookie and normal referrer when reproducing the form request. Do not invent a GET query parameter or capitalize `name` from the input element's `id="Name"`. If a byte-exact authoritative name yields no row, retry only bounded typography/legal-form variants such as removing Lithuanian quotation marks or using the portal's likely `AB`, `VšĮ`, or expanded legal-form rendering. Record which query matched. 2. Identity-check the returned legal name and available profile details. Parse complete organization-result table rows and bind each displayed legal name to the `prepareViewCAOrganisation.do?id=...` link in that same row. Do not collect every profile link from a wide HTML context and then substring-match the query: one result page or surrounding fragment can contain multiple organization/profile links, producing a false “exact” match or an ambiguous pair. Preserve the query variant, portal-displayed organization name, registration number/domain when available, and organization ID. If an exact-name query still yields multiple distinct exact rows, keep the identity unresolved until registration number, domain, or another authoritative identifier distinguishes them; never select the first result. A variant match is discovery only until reconciled with the authoritative client identity. Treat near-identical domains as a collision risk: open the homepage and corroborate its institution name/contact domain against the CVP IS profile before using any system link found there.