proposal-system/api/src/ProposalSystem.Application/DTOs/FileDtos.cs
Adam Moussa 8d73e66a17 fix(api): API-M2, M5, M7, M9, M10, M12, M13 — Medium audit findings
- API-M2: Add comment for fail-loud auth config guard (already implemented)
- API-M5: Add FluentValidation validators for VendorProposal, GeneratedPdf,
  and SimilarReference DTOs; move request records to Application DTOs
- API-M7: Add AsNoTracking() to all read-only queries in ProposalService,
  LineItemService, AdminController, UsersController, FilesController
- API-M9: Log stderr from dev PDF generation instead of returning to client
- API-M10: Return generic "Authentication service unavailable" in auth
  callbacks instead of leaking Cognito/DevMode configuration state
- API-M12: Enrich audit logging with before/after values for status changes,
  proposal edits, and line item operations using structured JSON
- API-M13: Log previous role alongside new role on user role changes in
  both UsersController and Cognito-synced role updates in AuthController
2026-05-27 18:18:44 -04:00

39 lines
910 B
C#

namespace ProposalSystem.Application.DTOs;
public record PresignedUploadResponse(
string UploadUrl,
string S3Key,
DateTime ExpiresAt,
Guid VendorProposalId
);
public record PdfDownloadResponse(
string DownloadUrl,
DateTime ExpiresAt
);
public record PdfVersionResponse(
int Revision,
DateTime GeneratedAt
);
public record VendorProposalResponse(
Guid Id,
string VendorName,
string FileName,
decimal TotalVendorCost,
string ProcessingStatus,
object? ExtractedData
);
// Fix: API-M5 — moved request DTOs here from controllers so validators can reference them
public record UpdateVendorProposalRequest(
string? VendorName,
string? ExtractedData,
decimal? TotalVendorCost,
string? ProcessingStatus
);
public record UpdateStatusRequest(string ProcessingStatus);
public record CreateGeneratedPdfRequest(Guid ProposalId, string S3Key);