Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00
|
|
|
using System.Net;
|
|
|
|
|
using System.Text.Json;
|
|
|
|
|
using FluentValidation;
|
|
|
|
|
using Microsoft.AspNetCore.Mvc;
|
|
|
|
|
|
|
|
|
|
namespace ProposalSystem.Api.Middleware;
|
|
|
|
|
|
|
|
|
|
public class GlobalExceptionHandler : IMiddleware
|
|
|
|
|
{
|
|
|
|
|
private readonly ILogger<GlobalExceptionHandler> _logger;
|
|
|
|
|
|
|
|
|
|
public GlobalExceptionHandler(ILogger<GlobalExceptionHandler> logger)
|
|
|
|
|
{
|
|
|
|
|
_logger = logger;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public async Task InvokeAsync(HttpContext context, RequestDelegate next)
|
|
|
|
|
{
|
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
await next(context);
|
|
|
|
|
}
|
|
|
|
|
catch (Exception ex)
|
|
|
|
|
{
|
|
|
|
|
await HandleExceptionAsync(context, ex);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private async Task HandleExceptionAsync(HttpContext context, Exception exception)
|
|
|
|
|
{
|
|
|
|
|
var (statusCode, problemDetails) = exception switch
|
|
|
|
|
{
|
|
|
|
|
ValidationException validationEx => (
|
|
|
|
|
HttpStatusCode.BadRequest,
|
|
|
|
|
new ProblemDetails
|
|
|
|
|
{
|
|
|
|
|
Status = 400,
|
|
|
|
|
Title = "Validation Error",
|
|
|
|
|
Detail = string.Join("; ", validationEx.Errors.Select(e => e.ErrorMessage)),
|
|
|
|
|
}
|
|
|
|
|
),
|
|
|
|
|
KeyNotFoundException => (
|
|
|
|
|
HttpStatusCode.NotFound,
|
|
|
|
|
new ProblemDetails
|
|
|
|
|
{
|
|
|
|
|
Status = 404,
|
|
|
|
|
Title = "Not Found",
|
|
|
|
|
Detail = exception.Message,
|
|
|
|
|
}
|
|
|
|
|
),
|
|
|
|
|
UnauthorizedAccessException => (
|
|
|
|
|
HttpStatusCode.Unauthorized,
|
|
|
|
|
new ProblemDetails
|
|
|
|
|
{
|
|
|
|
|
Status = 401,
|
|
|
|
|
Title = "Unauthorized",
|
|
|
|
|
Detail = "Authentication required",
|
|
|
|
|
}
|
|
|
|
|
),
|
|
|
|
|
InvalidOperationException => (
|
Phase 3 audit fixes: FIX-01–47, accessibility NITs, code quality NITs [skip deploy]
## Summary
Implements Phase 3 of the AUDIT-2026-05-20 findings:
- 29 FIX-severity items across API, web, infra, and lambdas
- 7 accessibility NITs (aria-labels, document titles)
- 4 code quality NITs (deduplication, constants extraction)
Key changes:
- API: N+1 fix, pagination clamping, idempotent transitions, upload confirm endpoint, revision TotalBidAmount carry-forward
- Web: confirmation dialogs, currency formatting, error states, date range filters, document titles
- Infra: S3 CORS lockdown, API Gateway throttling, AOSS network policy fix, CI concurrency
- Lambdas: skip empty suggestions, remove status side-effect
- Scripts: post-deploy health check
## Test plan
- [x] tsc --noEmit (web + infra)
- [x] dotnet build (api)
- [x] ruff check + format (lambdas)
- [x] Cross-review via orchestrator (no blockers)
[skip deploy]
2026-05-20 19:38:36 -04:00
|
|
|
HttpStatusCode.BadRequest,
|
Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00
|
|
|
new ProblemDetails
|
|
|
|
|
{
|
Phase 3 audit fixes: FIX-01–47, accessibility NITs, code quality NITs [skip deploy]
## Summary
Implements Phase 3 of the AUDIT-2026-05-20 findings:
- 29 FIX-severity items across API, web, infra, and lambdas
- 7 accessibility NITs (aria-labels, document titles)
- 4 code quality NITs (deduplication, constants extraction)
Key changes:
- API: N+1 fix, pagination clamping, idempotent transitions, upload confirm endpoint, revision TotalBidAmount carry-forward
- Web: confirmation dialogs, currency formatting, error states, date range filters, document titles
- Infra: S3 CORS lockdown, API Gateway throttling, AOSS network policy fix, CI concurrency
- Lambdas: skip empty suggestions, remove status side-effect
- Scripts: post-deploy health check
## Test plan
- [x] tsc --noEmit (web + infra)
- [x] dotnet build (api)
- [x] ruff check + format (lambdas)
- [x] Cross-review via orchestrator (no blockers)
[skip deploy]
2026-05-20 19:38:36 -04:00
|
|
|
Status = 400,
|
Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00
|
|
|
Title = "Invalid Operation",
|
|
|
|
|
Detail = exception.Message,
|
|
|
|
|
}
|
|
|
|
|
),
|
|
|
|
|
_ => (
|
|
|
|
|
HttpStatusCode.InternalServerError,
|
|
|
|
|
new ProblemDetails
|
|
|
|
|
{
|
|
|
|
|
Status = 500,
|
|
|
|
|
Title = "Internal Server Error",
|
|
|
|
|
Detail = "An unexpected error occurred",
|
|
|
|
|
}
|
|
|
|
|
),
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
if (statusCode == HttpStatusCode.InternalServerError)
|
|
|
|
|
{
|
|
|
|
|
_logger.LogError(exception, "Unhandled exception");
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
context.Response.StatusCode = (int)statusCode;
|
|
|
|
|
context.Response.ContentType = "application/problem+json";
|
|
|
|
|
|
|
|
|
|
await context.Response.WriteAsync(
|
|
|
|
|
JsonSerializer.Serialize(problemDetails, new JsonSerializerOptions
|
|
|
|
|
{
|
|
|
|
|
PropertyNamingPolicy = JsonNamingPolicy.CamelCase,
|
|
|
|
|
}));
|
|
|
|
|
}
|
|
|
|
|
}
|