proposal-system/api/src/ProposalSystem.Api/Controllers/GeneratedPdfsController.cs
Adam Moussa f051f74fde
Fix security gaps and improve code quality across API and Lambdas (#23)
Security: add system identity claims to InternalApiKeyMiddleware so
Lambda-to-API calls resolve a proper user, inject ICurrentUserService
into GeneratedPdfsController to replace Guid.Empty, and consolidate
CurrentUserService into a single ResolveAsync lookup chain.

Quality: replace four COUNT queries in ProposalService.GetStatsAsync
with a single grouped query, convert all Lambda print() to structured
logging, and add retry helpers for Lambda-to-API HTTP calls.
2026-05-17 13:48:14 -04:00

49 lines
1.5 KiB
C#

using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using Microsoft.EntityFrameworkCore;
using ProposalSystem.Application.Interfaces;
using ProposalSystem.Domain.Entities;
using ProposalSystem.Infrastructure.Data;
namespace ProposalSystem.Api.Controllers;
[ApiController]
[Route("api/generated-pdfs")]
[Authorize]
public class GeneratedPdfsController : ControllerBase
{
private readonly ProposalDbContext _db;
private readonly ICurrentUserService _currentUser;
public GeneratedPdfsController(ProposalDbContext db, ICurrentUserService currentUser)
{
_db = db;
_currentUser = currentUser;
}
[HttpPost]
public async Task<IActionResult> Create([FromBody] CreateGeneratedPdfRequest request, CancellationToken ct)
{
var proposal = await _db.Proposals.FindAsync(new object[] { request.ProposalId }, ct);
if (proposal == null) return NotFound();
await _currentUser.ResolveAsync();
var pdf = new GeneratedPdf
{
Id = Guid.NewGuid(),
ProposalId = request.ProposalId,
Revision = proposal.CurrentRevision,
S3Key = request.S3Key,
GeneratedAt = DateTime.UtcNow,
GeneratedById = _currentUser.UserId,
};
_db.GeneratedPdfs.Add(pdf);
await _db.SaveChangesAsync(ct);
return Created($"/api/generated-pdfs/{pdf.Id}", new { pdf.Id, pdf.S3Key, pdf.Revision });
}
}
public record CreateGeneratedPdfRequest(Guid ProposalId, string S3Key);