proposal-system/api/src/ProposalSystem.Api/Controllers/FilesController.cs
Adam Moussa ceefae2850
Implement Phases 2-5: Frontend, AI/RAG, PDF Generation (#22)
* Fix NuGet versions and add InitialCreate EF Core migration

- Update AWSSDK.SQS and AWSSDK.SecretsManager to 3.7.500.0 (actual available versions)
- Update AWSSDK.Extensions.NETCore.Setup to 3.7.400
- Generate InitialCreate migration for PostgreSQL (all 8 entities)
- Build verified: 0 errors, 0 warnings

* Implement Dispatcher Frontend (Phase 2)

React 19 + MUI v7 + TypeScript + Vite SPA matching SHOC patterns:
Redux Toolkit (auth/ui slices), TanStack React Query, axios interceptors,
react-toastify, Cognito OAuth PKCE login flow, paginated proposal list,
new proposal form with customer autocomplete and vendor PDF upload,
read-only proposal detail with status stepper timeline.

* Add AuthController for Cognito code exchange and .env.example

Backend endpoint POST /api/auth/callback exchanges the OAuth
authorization code with Cognito's token endpoint, auto-provisions
the user in the DB, and returns the access token to the frontend.

* Implement Admin Frontend Experience (Phase 3)

Three-panel admin workspace: left reference panel (submission details,
vendor data), center editor (refined scope, inline line item table with
reorder/add/remove/pricing), right similar proposals panel (KB results
with pull-to-editor). Admin dashboard with stats cards and proposal
queue table. Approval flow with confirmation dialog, mark-as-sent,
and create-revision actions. Role-based sidebar navigation.

* Implement backend dev mode, internal API auth, and service layer enhancements

- Add dev-login endpoint with local JWT signing for local development
- Add InternalApiKeyMiddleware with timing-safe comparison for Lambda-to-API auth
- Add DevS3Service and NoOpJobPublisher for running without AWS services
- Implement CurrentUserService cascading user resolution (ID → sub → email → create)
- Add async ResolveAsync() to avoid synchronous DB calls in request pipeline
- Add /proposals/stats endpoint for efficient server-side status counts
- Guard status transitions: only allow Draft → InReview via update endpoint
- Add vendor proposals, generated PDFs, and similar proposals controllers
- Add ISimilarProposalService and SimilarProposalService
- Add [Authorize] to AddSimilarReference endpoint

* Implement Lambda functions for PDF processing, suggestions, and library ingest

- pdf-extract: Parse vendor PDFs with pdfplumber, fallback to Claude multimodal
- pdf-generate: Generate branded proposal PDFs with reportlab Platypus
- library-ingest: Format approved proposals as markdown and sync to Bedrock KB
- suggestions: Query KB for similar proposals, generate line items via Claude
- All Lambdas use internal API key auth and cold-start secret caching
- Fix pdf_path unbound variable in pdf-extract error handling

* Add Bedrock Knowledge Base, OpenSearch Serverless, and SQS message filtering

- Provision OpenSearch Serverless collection for vector search
- Create Bedrock Knowledge Base with Titan embedding model
- Configure S3 data source with fixed-size chunking (512 tokens, 20% overlap)
- Add suggestions Lambda with SQS event source filtering
- Scope bedrock:InvokeModel IAM to specific model ARN patterns
- Add internal API key secret in Secrets Manager
- Add log retention (2 months) to all Lambda functions
- Add docker-compose.yml for local PostgreSQL

* Apply SHOC design system styling across frontend

- Rewrite theme with SHOC palette (#0c4f6f primary, Nunito font, 4px radius)
- Add global CSS with Google Fonts import for Nunito
- Redesign Topbar with avatar initials, role subtitle, gradient header
- Redesign Sidebar with 220px width, section headers, active state border
- Restyle LoginPage with SHOC branded card and dev-mode role selector
- Update AdminDashboard KPI cards to centered SHOC style
- Add devLogin API method for local development auth flow

* Fix frontend navigation bugs, differentiate Dashboard from Proposals list

- Fix double nav selection by adding isNavActive() with ALL_NAV_PATHS set
- Fix /admin/users routing to placeholder instead of redirect to /
- Fix ProposalDetailPage Back button navigating to / instead of /proposals
- Differentiate Dashboard (KPI cards + recent 5) from ProposalListPage (full paginated table)
- Dashboard now uses dedicated /proposals/stats endpoint for accurate counts
- Fix adminApi.getPdf dead code (axios rejects before status check)
- Wire up PDF generation button in AdminWorkspace
- Adjust layout: 220px drawer, 10px content padding, 64px toolbar height

* Add appsettings.Development.json to gitignore

Prevent dev-only signing keys and connection strings from being committed.

* Fix CI failures: unused Python imports and CDK synth asset path

CDK synth job needs the .NET API published first so the Lambda asset
path exists. Python lint had 3 unused imports in pdf-generate.

* Apply ruff formatting to all Lambda Python files
2026-05-17 13:06:23 -04:00

138 lines
4.7 KiB
C#

using System.Text.Json;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using Microsoft.EntityFrameworkCore;
using ProposalSystem.Application.DTOs;
using ProposalSystem.Application.Interfaces;
using ProposalSystem.Domain.Entities;
using ProposalSystem.Infrastructure.Data;
namespace ProposalSystem.Api.Controllers;
[ApiController]
[Route("api/proposals/{proposalId:guid}")]
[Authorize]
public class FilesController : ControllerBase
{
private readonly ProposalDbContext _db;
private readonly IS3Service _s3;
private readonly IJobPublisher _jobPublisher;
private readonly IAuditService _audit;
private readonly IConfiguration _config;
public FilesController(
ProposalDbContext db,
IS3Service s3,
IJobPublisher jobPublisher,
IAuditService audit,
IConfiguration config)
{
_db = db;
_s3 = s3;
_jobPublisher = jobPublisher;
_audit = audit;
_config = config;
}
[HttpPost("attachments")]
public async Task<ActionResult<PresignedUploadResponse>> UploadAttachment(
Guid proposalId,
[FromQuery] string fileName,
CancellationToken ct)
{
var proposal = await _db.Proposals.FindAsync(new object[] { proposalId }, ct);
if (proposal == null) return NotFound();
var extension = Path.GetExtension(fileName).ToLowerInvariant();
if (extension != ".pdf")
return BadRequest(new { error = "Only PDF files are accepted" });
var s3Key = $"vendors/{proposalId}/{Guid.NewGuid()}{extension}";
var bucket = _config["UPLOADS_BUCKET"]!;
var url = await _s3.GeneratePresignedUploadUrlAsync(bucket, s3Key, "application/pdf");
var vendorProposal = new VendorProposal
{
Id = Guid.NewGuid(),
ProposalId = proposalId,
FileName = fileName,
S3Key = s3Key,
UploadedAt = DateTime.UtcNow,
ProcessingStatus = ProcessingStatus.Pending,
};
_db.VendorProposals.Add(vendorProposal);
await _db.SaveChangesAsync(ct);
await _jobPublisher.PublishAsync("pdf-extract", new { proposalId, s3Key, vendorProposalId = vendorProposal.Id }, ct);
return Ok(new PresignedUploadResponse(url, s3Key, DateTime.UtcNow.AddMinutes(15)));
}
[HttpGet("pdf")]
[Authorize(Roles = "admins,sysadmins")]
public async Task<ActionResult<PdfDownloadResponse>> GetPdf(Guid proposalId, CancellationToken ct)
{
var pdf = await _db.GeneratedPdfs
.Where(p => p.ProposalId == proposalId)
.OrderByDescending(p => p.Revision)
.FirstOrDefaultAsync(ct);
if (pdf == null)
{
await _jobPublisher.PublishAsync("pdf-generate", new { proposalId }, ct);
return Accepted(new { message = "PDF generation queued" });
}
var bucket = _config["GENERATED_BUCKET"]!;
var url = await _s3.GeneratePresignedDownloadUrlAsync(bucket, pdf.S3Key, 60);
await _audit.LogAsync(AuditAction.Download, proposalId, $"Downloaded rev {pdf.Revision}", ct);
return Ok(new PdfDownloadResponse(url, DateTime.UtcNow.AddMinutes(60)));
}
[HttpGet("pdf/{revision:int}")]
[Authorize(Roles = "admins,sysadmins")]
public async Task<ActionResult<PdfDownloadResponse>> GetPdfRevision(
Guid proposalId,
int revision,
CancellationToken ct)
{
var pdf = await _db.GeneratedPdfs
.FirstOrDefaultAsync(p => p.ProposalId == proposalId && p.Revision == revision, ct);
if (pdf == null) return NotFound();
var bucket = _config["GENERATED_BUCKET"]!;
var url = await _s3.GeneratePresignedDownloadUrlAsync(bucket, pdf.S3Key, 60);
await _audit.LogAsync(AuditAction.Download, proposalId, $"Downloaded rev {revision}", ct);
return Ok(new PdfDownloadResponse(url, DateTime.UtcNow.AddMinutes(60)));
}
[HttpGet("vendors")]
[Authorize(Roles = "admins,sysadmins")]
public async Task<ActionResult<IReadOnlyList<VendorProposalResponse>>> GetVendors(
Guid proposalId,
CancellationToken ct)
{
var entities = await _db.VendorProposals
.Where(v => v.ProposalId == proposalId)
.OrderByDescending(v => v.UploadedAt)
.ToListAsync(ct);
var vendors = entities.Select(v => new VendorProposalResponse(
v.Id,
v.VendorName,
v.FileName,
v.TotalVendorCost,
v.ProcessingStatus.ToString(),
string.IsNullOrEmpty(v.ExtractedData) ? null : JsonSerializer.Deserialize<object>(v.ExtractedData)
)).ToList();
return Ok(vendors);
}
}