A table with filters made the user do the work. Rare disease triage is a different task:
which few variants could explain *this* patient's phenotype, and why. The app now answers
that, and lets a reviewer act on the answer.
Domain
- a case is a proband: a VCF plus the HPO terms observed in the patient (samples -> cases)
- HPO's gene-to-phenotype annotations are loaded as reference data (scripts/load-hpo.py)
- each candidate can be shortlisted or dismissed with a reason and a note
Ranking (app/services/triage.py, 21 tests)
- weighted sum of phenotype match, rarity, consequence severity and the model's score,
with every component shown next to the candidate
- rarity and consequence filter; phenotype only ranks, because a real diagnosis can sit in
a gene nobody has annotated yet and filtering on it would hide exactly that case
- ClinVar is deliberately not an input: it appears beside the result as independent
confirmation, so nothing ranks highly merely because ClinVar already said pathogenic
UI
- the funnel is the headline: variants called -> rare -> coding candidates -> phenotype-matched
- ranked candidates with evidence chips, not a grid of everything; filters are demoted
- a variant panel showing the score breakdown, the matched HPO terms, the raw VEP record and
links out to Ensembl/gnomAD/ClinVar, with the decision controls
- a printable case report: phenotype, funnel, shortlisted variants with reasons, provenance
API: /cases with phenotypes, /cases/{id}/candidates (funnel + ranked + weights),
/variants/{id}, /variants/{id}/decision, /cases/{id}/report, /phenotypes for the picker.
Scoring moved under the case and now answers 503 with the reason when no model registry is
reachable, instead of a 500.
Verified end to end on a simulated proband (scripts/make-demo-case.sh: real GIAB HG002
background + one real ClinVar 2-star pathogenic NF2 variant). 13 variants called -> 1 coding
candidate, and the planted variant ranks first at 0.80 on phenotype 1.00, rarity 1.00 and
consequence 1.00, with ClinVar agreeing afterwards.
Tests: api 75, ml 18, loader 16, web 27; ruff, mypy, svelte-check, terraform validate, both
kustomize overlays and the Nextflow stub run all clean.
52 lines
1.8 KiB
Python
52 lines
1.8 KiB
Python
import pytest
|
|
from httpx import AsyncClient
|
|
from pydantic import ValidationError
|
|
|
|
from app.schemas import CaseCreate
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"uri",
|
|
[
|
|
"gs://bucket/dir/sample.vcf.gz",
|
|
"gs://my.bucket-1/a/b.bcf",
|
|
"gs://bucket/x.vcf",
|
|
"/data/example.vcf.gz",
|
|
"/data/giab/hg002.chr22.vcf.bgz",
|
|
],
|
|
)
|
|
def test_vcf_uri_accepts_gcs_objects_and_files_under_the_data_root(uri: str) -> None:
|
|
assert CaseCreate(name="s", vcf_uri=uri).vcf_uri == uri
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"uri",
|
|
[
|
|
"-c/tmp/evil.config", # would be parsed as a Nextflow option
|
|
"--outdir=/etc",
|
|
"/etc/passwd", # outside the data root
|
|
"/data/../etc/shadow.vcf", # traversal out of it
|
|
"data/example.vcf.gz", # relative: depends on the API's working directory
|
|
"gs://bucket/notes.txt", # not a VCF/BCF
|
|
"https://example.com/x.vcf.gz",
|
|
"gs:///x.vcf.gz",
|
|
"/data/x.vcf.gz\n--foo", # control characters
|
|
"",
|
|
],
|
|
)
|
|
def test_vcf_uri_rejects_everything_else(uri: str) -> None:
|
|
with pytest.raises(ValidationError):
|
|
CaseCreate(name="s", vcf_uri=uri)
|
|
|
|
|
|
async def test_bad_vcf_uri_is_422_at_the_api(client: AsyncClient) -> None:
|
|
r = await client.post("/api/cases", json={"name": "s", "vcf_uri": "/etc/passwd"})
|
|
assert r.status_code == 422
|
|
|
|
|
|
async def test_cors_allows_only_configured_origins(client: AsyncClient) -> None:
|
|
allowed = await client.get("/health", headers={"Origin": "http://localhost:5173"})
|
|
assert allowed.headers.get("access-control-allow-origin") == "http://localhost:5173"
|
|
other = await client.get("/health", headers={"Origin": "https://evil.example"})
|
|
assert "access-control-allow-origin" not in other.headers
|