proposal-system/api/src/ProposalSystem.Api/Controllers/GeneratedPdfsController.cs
Adam Moussa 8d73e66a17 fix(api): API-M2, M5, M7, M9, M10, M12, M13 — Medium audit findings
- API-M2: Add comment for fail-loud auth config guard (already implemented)
- API-M5: Add FluentValidation validators for VendorProposal, GeneratedPdf,
  and SimilarReference DTOs; move request records to Application DTOs
- API-M7: Add AsNoTracking() to all read-only queries in ProposalService,
  LineItemService, AdminController, UsersController, FilesController
- API-M9: Log stderr from dev PDF generation instead of returning to client
- API-M10: Return generic "Authentication service unavailable" in auth
  callbacks instead of leaking Cognito/DevMode configuration state
- API-M12: Enrich audit logging with before/after values for status changes,
  proposal edits, and line item operations using structured JSON
- API-M13: Log previous role alongside new role on user role changes in
  both UsersController and Cognito-synced role updates in AuthController
2026-05-27 18:18:44 -04:00

62 lines
2 KiB
C#

using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using Microsoft.EntityFrameworkCore;
using ProposalSystem.Application.DTOs;
using ProposalSystem.Application.Interfaces;
using ProposalSystem.Domain.Entities;
using ProposalSystem.Infrastructure.Data;
namespace ProposalSystem.Api.Controllers;
[ApiController]
[Route("api/generated-pdfs")]
[Authorize]
public class GeneratedPdfsController : ControllerBase
{
private readonly ProposalDbContext _db;
private readonly ICurrentUserService _currentUser;
public GeneratedPdfsController(ProposalDbContext db, ICurrentUserService currentUser)
{
_db = db;
_currentUser = currentUser;
}
[HttpPost]
[Authorize(Roles = "admins,sysadmins")]
public async Task<IActionResult> Create([FromBody] CreateGeneratedPdfRequest request, CancellationToken ct)
{
var proposal = await _db.Proposals.FindAsync(new object[] { request.ProposalId }, ct);
if (proposal == null) return NotFound();
// Fix: API-M4 — verify dispatcher ownership before allowing PDF creation
if (!AuthorizeProposalAccess(proposal))
return Forbid();
await _currentUser.ResolveAsync();
var pdf = new GeneratedPdf
{
Id = Guid.NewGuid(),
ProposalId = request.ProposalId,
Revision = proposal.CurrentRevision,
S3Key = request.S3Key,
GeneratedAt = DateTime.UtcNow,
GeneratedById = _currentUser.UserId,
};
_db.GeneratedPdfs.Add(pdf);
await _db.SaveChangesAsync(ct);
return Created($"/api/generated-pdfs/{pdf.Id}", new { pdf.Id, pdf.S3Key, pdf.Revision });
}
// Fix: API-M4 — dispatchers can only access PDFs for proposals they submitted
private bool AuthorizeProposalAccess(Proposal proposal)
{
if (_currentUser.Role != UserRole.Dispatcher)
return true;
return proposal.SubmittedById == _currentUser.UserId;
}
}