mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-10-01 04:43:13 +00:00
BLOCK-01: Add API Gateway JWT authorizer with Cognito, route internal Lambda calls through Function URL to bypass gateway auth BLOCK-02/03: Prevent proposal number race condition with pg_advisory_xact_lock and filter revision numbers from max-number query BLOCK-04: Restrict VendorProposals and GeneratedPdfs to admins/sysadmins BLOCK-05: Sum all vendor costs instead of overwriting with single vendor BLOCK-06: Enable ValidateAudience on JWT, add Auth env vars to API Lambda BLOCK-07: Validate ID token signature in AuthController via OIDC discovery BLOCK-08: Use batchItemFailures in all Lambda SQS handlers BLOCK-09: Increase SQS visibility timeout from 180s to 720s FIX-10: Scope dispatcher queries to own proposals (IDOR fix)
44 lines
1.4 KiB
C#
44 lines
1.4 KiB
C#
using Microsoft.EntityFrameworkCore;
|
|
using ProposalSystem.Application.Interfaces;
|
|
using ProposalSystem.Infrastructure.Data;
|
|
|
|
namespace ProposalSystem.Infrastructure.Services;
|
|
|
|
public class ProposalNumberGenerator : IProposalNumberGenerator
|
|
{
|
|
private readonly ProposalDbContext _db;
|
|
|
|
public ProposalNumberGenerator(ProposalDbContext db)
|
|
{
|
|
_db = db;
|
|
}
|
|
|
|
public async Task<string> GenerateAsync(CancellationToken ct = default)
|
|
{
|
|
var year = DateTime.UtcNow.Year;
|
|
var prefix = $"SHI-{year}-";
|
|
|
|
// Advisory lock prevents concurrent number generation within the same transaction
|
|
await _db.Database.ExecuteSqlRawAsync(
|
|
"SELECT pg_advisory_xact_lock(hashtext('proposal_number_gen'))", ct);
|
|
|
|
var lastNumber = await _db.Proposals
|
|
.Where(p => p.ProposalNumber.StartsWith(prefix))
|
|
.Where(p => !p.ProposalNumber.Contains("-R"))
|
|
.OrderByDescending(p => p.ProposalNumber)
|
|
.Select(p => p.ProposalNumber)
|
|
.FirstOrDefaultAsync(ct);
|
|
|
|
int nextSequence = 1;
|
|
if (lastNumber != null)
|
|
{
|
|
var sequencePart = lastNumber[prefix.Length..];
|
|
if (int.TryParse(sequencePart, out var current))
|
|
{
|
|
nextSequence = current + 1;
|
|
}
|
|
}
|
|
|
|
return $"{prefix}{nextSequence:D4}";
|
|
}
|
|
}
|