mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-10-05 22:22:00 +00:00
BLOCK-01: Add API Gateway JWT authorizer with Cognito, route internal Lambda calls through Function URL to bypass gateway auth BLOCK-02/03: Prevent proposal number race condition with pg_advisory_xact_lock and filter revision numbers from max-number query BLOCK-04: Restrict VendorProposals and GeneratedPdfs to admins/sysadmins BLOCK-05: Sum all vendor costs instead of overwriting with single vendor BLOCK-06: Enable ValidateAudience on JWT, add Auth env vars to API Lambda BLOCK-07: Validate ID token signature in AuthController via OIDC discovery BLOCK-08: Use batchItemFailures in all Lambda SQS handlers BLOCK-09: Increase SQS visibility timeout from 180s to 720s FIX-10: Scope dispatcher queries to own proposals (IDOR fix)
49 lines
1.5 KiB
C#
49 lines
1.5 KiB
C#
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.EntityFrameworkCore;
|
|
using ProposalSystem.Application.Interfaces;
|
|
using ProposalSystem.Domain.Entities;
|
|
using ProposalSystem.Infrastructure.Data;
|
|
|
|
namespace ProposalSystem.Api.Controllers;
|
|
|
|
[ApiController]
|
|
[Route("api/generated-pdfs")]
|
|
[Authorize(Roles = "admins,sysadmins")]
|
|
public class GeneratedPdfsController : ControllerBase
|
|
{
|
|
private readonly ProposalDbContext _db;
|
|
private readonly ICurrentUserService _currentUser;
|
|
|
|
public GeneratedPdfsController(ProposalDbContext db, ICurrentUserService currentUser)
|
|
{
|
|
_db = db;
|
|
_currentUser = currentUser;
|
|
}
|
|
|
|
[HttpPost]
|
|
public async Task<IActionResult> Create([FromBody] CreateGeneratedPdfRequest request, CancellationToken ct)
|
|
{
|
|
var proposal = await _db.Proposals.FindAsync(new object[] { request.ProposalId }, ct);
|
|
if (proposal == null) return NotFound();
|
|
|
|
await _currentUser.ResolveAsync();
|
|
|
|
var pdf = new GeneratedPdf
|
|
{
|
|
Id = Guid.NewGuid(),
|
|
ProposalId = request.ProposalId,
|
|
Revision = proposal.CurrentRevision,
|
|
S3Key = request.S3Key,
|
|
GeneratedAt = DateTime.UtcNow,
|
|
GeneratedById = _currentUser.UserId,
|
|
};
|
|
|
|
_db.GeneratedPdfs.Add(pdf);
|
|
await _db.SaveChangesAsync(ct);
|
|
|
|
return Created($"/api/generated-pdfs/{pdf.Id}", new { pdf.Id, pdf.S3Key, pdf.Revision });
|
|
}
|
|
}
|
|
|
|
public record CreateGeneratedPdfRequest(Guid ProposalId, string S3Key);
|