mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-10-04 13:42:03 +00:00
BLOCK-01: Add API Gateway JWT authorizer with Cognito, route internal Lambda calls through Function URL to bypass gateway auth BLOCK-02/03: Prevent proposal number race condition with pg_advisory_xact_lock and filter revision numbers from max-number query BLOCK-04: Restrict VendorProposals and GeneratedPdfs to admins/sysadmins BLOCK-05: Sum all vendor costs instead of overwriting with single vendor BLOCK-06: Enable ValidateAudience on JWT, add Auth env vars to API Lambda BLOCK-07: Validate ID token signature in AuthController via OIDC discovery BLOCK-08: Use batchItemFailures in all Lambda SQS handlers BLOCK-09: Increase SQS visibility timeout from 180s to 720s FIX-10: Scope dispatcher queries to own proposals (IDOR fix)
74 lines
2.4 KiB
C#
74 lines
2.4 KiB
C#
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.EntityFrameworkCore;
|
|
using ProposalSystem.Domain.Entities;
|
|
using ProposalSystem.Infrastructure.Data;
|
|
|
|
namespace ProposalSystem.Api.Controllers;
|
|
|
|
[ApiController]
|
|
[Route("api/vendor-proposals")]
|
|
[Authorize(Roles = "admins,sysadmins")]
|
|
public class VendorProposalsController : ControllerBase
|
|
{
|
|
private readonly ProposalDbContext _db;
|
|
|
|
public VendorProposalsController(ProposalDbContext db)
|
|
{
|
|
_db = db;
|
|
}
|
|
|
|
[HttpPut("{id:guid}")]
|
|
public async Task<IActionResult> Update(Guid id, [FromBody] UpdateVendorProposalRequest request, CancellationToken ct)
|
|
{
|
|
var vendor = await _db.VendorProposals.FindAsync(new object[] { id }, ct);
|
|
if (vendor == null) return NotFound();
|
|
|
|
if (request.VendorName != null)
|
|
vendor.VendorName = request.VendorName;
|
|
|
|
if (request.ExtractedData != null)
|
|
vendor.ExtractedData = request.ExtractedData;
|
|
|
|
if (request.TotalVendorCost.HasValue)
|
|
vendor.TotalVendorCost = request.TotalVendorCost.Value;
|
|
|
|
if (request.ProcessingStatus != null && Enum.TryParse<ProcessingStatus>(request.ProcessingStatus, out var status))
|
|
vendor.ProcessingStatus = status;
|
|
|
|
await _db.SaveChangesAsync(ct);
|
|
|
|
var proposal = await _db.Proposals.FindAsync(new object[] { vendor.ProposalId }, ct);
|
|
if (proposal != null)
|
|
{
|
|
proposal.VendorTotalCost = await _db.VendorProposals
|
|
.Where(v => v.ProposalId == vendor.ProposalId)
|
|
.SumAsync(v => v.TotalVendorCost, ct);
|
|
await _db.SaveChangesAsync(ct);
|
|
}
|
|
|
|
return NoContent();
|
|
}
|
|
|
|
[HttpPut("{id:guid}/status")]
|
|
public async Task<IActionResult> UpdateStatus(Guid id, [FromBody] UpdateStatusRequest request, CancellationToken ct)
|
|
{
|
|
var vendor = await _db.VendorProposals.FindAsync(new object[] { id }, ct);
|
|
if (vendor == null) return NotFound();
|
|
|
|
if (Enum.TryParse<ProcessingStatus>(request.ProcessingStatus, out var status))
|
|
vendor.ProcessingStatus = status;
|
|
|
|
await _db.SaveChangesAsync(ct);
|
|
return NoContent();
|
|
}
|
|
}
|
|
|
|
public record UpdateVendorProposalRequest(
|
|
string? VendorName,
|
|
string? ExtractedData,
|
|
decimal? TotalVendorCost,
|
|
string? ProcessingStatus
|
|
);
|
|
|
|
public record UpdateStatusRequest(string ProcessingStatus);
|