2026-05-20 17:23:55 -04:00
|
|
|
using System.Text.Json;
|
Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00
|
|
|
using ProposalSystem.Application.Interfaces;
|
|
|
|
|
using ProposalSystem.Domain.Entities;
|
|
|
|
|
using ProposalSystem.Infrastructure.Data;
|
|
|
|
|
|
|
|
|
|
namespace ProposalSystem.Infrastructure.Services;
|
|
|
|
|
|
|
|
|
|
public class AuditService : IAuditService
|
|
|
|
|
{
|
|
|
|
|
private readonly ProposalDbContext _db;
|
|
|
|
|
private readonly ICurrentUserService _currentUser;
|
|
|
|
|
|
|
|
|
|
public AuditService(ProposalDbContext db, ICurrentUserService currentUser)
|
|
|
|
|
{
|
|
|
|
|
_db = db;
|
|
|
|
|
_currentUser = currentUser;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public async Task LogAsync(AuditAction action, Guid? proposalId, string? details = null, CancellationToken ct = default)
|
2026-07-14 01:18:30 -04:00
|
|
|
{
|
|
|
|
|
Stage(action, proposalId, details);
|
|
|
|
|
await _db.SaveChangesAsync(ct);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public void Stage(AuditAction action, Guid? proposalId, string? details = null)
|
|
|
|
|
{
|
|
|
|
|
_db.AuditLogs.Add(BuildEntry(action, proposalId, details));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private AuditLog BuildEntry(AuditAction action, Guid? proposalId, string? details)
|
Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00
|
|
|
{
|
fix(api): API-M2, M5, M7, M9, M10, M12, M13 — Medium audit findings
- API-M2: Add comment for fail-loud auth config guard (already implemented)
- API-M5: Add FluentValidation validators for VendorProposal, GeneratedPdf,
and SimilarReference DTOs; move request records to Application DTOs
- API-M7: Add AsNoTracking() to all read-only queries in ProposalService,
LineItemService, AdminController, UsersController, FilesController
- API-M9: Log stderr from dev PDF generation instead of returning to client
- API-M10: Return generic "Authentication service unavailable" in auth
callbacks instead of leaking Cognito/DevMode configuration state
- API-M12: Enrich audit logging with before/after values for status changes,
proposal edits, and line item operations using structured JSON
- API-M13: Log previous role alongside new role on user role changes in
both UsersController and Cognito-synced role updates in AuthController
2026-05-27 18:06:04 -04:00
|
|
|
// Fix: API-M12 — accept pre-serialized JSON from callers that provide structured audit data.
|
|
|
|
|
// If the details string is already valid JSON (starts with '{'), use it directly;
|
|
|
|
|
// otherwise, wrap plain text in a JSON envelope for consistency.
|
|
|
|
|
string? jsonDetails = null;
|
|
|
|
|
if (details != null)
|
|
|
|
|
{
|
|
|
|
|
var trimmed = details.TrimStart();
|
|
|
|
|
if (trimmed.StartsWith('{') || trimmed.StartsWith('['))
|
|
|
|
|
jsonDetails = details;
|
|
|
|
|
else
|
|
|
|
|
jsonDetails = JsonSerializer.Serialize(new { message = details });
|
|
|
|
|
}
|
2026-05-20 17:23:55 -04:00
|
|
|
|
2026-07-14 01:18:30 -04:00
|
|
|
return new AuditLog
|
Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00
|
|
|
{
|
|
|
|
|
Id = Guid.NewGuid(),
|
|
|
|
|
ProposalId = proposalId,
|
|
|
|
|
UserId = _currentUser.UserId,
|
|
|
|
|
Action = action,
|
2026-05-20 17:23:55 -04:00
|
|
|
Details = jsonDetails,
|
Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00
|
|
|
Timestamp = DateTime.UtcNow,
|
|
|
|
|
IpAddress = _currentUser.IpAddress,
|
|
|
|
|
};
|
|
|
|
|
}
|
|
|
|
|
}
|