proposal-system/api/src/ProposalSystem.Api/Controllers/AdminController.cs
Adam Moussa 80e36bfb9a Fix Phase 3 audit findings: polish, operational maturity, and remaining FIX items
Addresses 29 FIX-severity findings and accessibility/code-quality NITs
from the 2026-05-20 audit. Key changes:

- Add confirmation dialogs for Mark as Sent and Create Revision (FIX-17)
- Restrict S3 CORS from wildcard to specific origins (FIX-38)
- Add API Gateway throttling at 100 rps / 50 burst (FIX-39)
- Separate vendor upload from SQS extraction trigger (FIX-04/05)
- Copy TotalBidAmount on proposal revision (FIX-11)
- Add CI paths-ignore and concurrency group (FIX-47)
- Add post-deploy health check (FIX-46)
- Fix N+1 query, Guid.Empty FK, pagination bounds, role sync (FIX-01/02/07/09)
- Fix dashboard OOM, status transitions, audit error handling (FIX-03/06/12)
- Fix frontend date filters, error display, currency formatting (FIX-14/16/18-23)
- Remove AOSS dashboard public access, skip empty AI suggestions (FIX-41/45)
- Add aria-labels, document.title management, deduplicate constants
- Restrict CORS localhost to development, log invalid API key attempts

[skip deploy]
2026-05-20 19:35:13 -04:00

51 lines
1.7 KiB
C#

using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using Microsoft.EntityFrameworkCore;
using ProposalSystem.Application.DTOs;
using ProposalSystem.Domain.Entities;
using ProposalSystem.Infrastructure.Data;
namespace ProposalSystem.Api.Controllers;
[ApiController]
[Route("api/admin")]
[Authorize(Roles = "admins,sysadmins")]
public class AdminController : ControllerBase
{
private readonly ProposalDbContext _db;
public AdminController(ProposalDbContext db)
{
_db = db;
}
[HttpGet("dashboard")]
public async Task<ActionResult<DashboardResponse>> GetDashboard(CancellationToken ct)
{
var pendingCount = await _db.Proposals
.CountAsync(p => p.Status == ProposalStatus.InReview, ct);
var weekStart = DateTime.UtcNow.AddDays(-7);
var approvedThisWeek = await _db.Proposals
.CountAsync(p => p.ApprovedAt >= weekStart, ct);
var approvedCount = await _db.Proposals
.CountAsync(p => p.ApprovedAt.HasValue, ct);
double avgTurnaround = 0;
if (approvedCount > 0)
{
var recentApproved = await _db.Proposals
.Where(p => p.ApprovedAt.HasValue)
.OrderByDescending(p => p.ApprovedAt)
.Take(200)
.Select(p => new { p.ApprovedAt, p.SubmittedAt })
.ToListAsync(ct);
avgTurnaround = recentApproved.Average(p => (p.ApprovedAt!.Value - p.SubmittedAt).TotalHours);
}
var totalProposals = await _db.Proposals.CountAsync(ct);
return Ok(new DashboardResponse(pendingCount, approvedThisWeek, avgTurnaround, totalProposals));
}
}