mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 06:03:12 +00:00
fix(dashboard): scope stats to authenticated accounts (SH-336)
This commit is contained in:
parent
4b772c8db3
commit
efd13b6f60
6 changed files with 99 additions and 20 deletions
|
|
@ -1,7 +1,10 @@
|
|||
using System.Security.Claims;
|
||||
using Data.SeaHavenIndustries;
|
||||
using FluentAssertions;
|
||||
using Microsoft.EntityFrameworkCore;
|
||||
using SeaHaven.DataServices.Implementation;
|
||||
using SeaHaven.Services.Exceptions;
|
||||
using SeaHaven.Services.Helpers;
|
||||
using SeaHaven.Services.Implementation;
|
||||
using Xunit;
|
||||
|
||||
|
|
@ -17,33 +20,90 @@ public class DashboardServiceTests
|
|||
return new ApplicationDbContext(options);
|
||||
}
|
||||
|
||||
private static DashboardService NewService(ApplicationDbContext ctx) =>
|
||||
new(new DashboardDataService(ctx));
|
||||
private static DashboardService NewService(ApplicationDbContext ctx)
|
||||
{
|
||||
var resolver = new WorkOrderAccountResolver(
|
||||
new AccountDataService(ctx),
|
||||
new LocationDataService(ctx));
|
||||
return new DashboardService(new DashboardDataService(ctx), resolver);
|
||||
}
|
||||
|
||||
private static WorkOrder Wo(string? status, bool? isTemplate = false, string? assignTo = null) =>
|
||||
new() { Status = status, istemplate = isTemplate, AssignTo = assignTo };
|
||||
private static ClaimsPrincipal AccountUser(int accountId)
|
||||
{
|
||||
var claims = new[]
|
||||
{
|
||||
new Claim(SeaHavenClaimTypes.AccountId, accountId.ToString()),
|
||||
new Claim(ClaimTypes.Role, "Dispatcher")
|
||||
};
|
||||
return new ClaimsPrincipal(new ClaimsIdentity(claims, "test"));
|
||||
}
|
||||
|
||||
private static ClaimsPrincipal OrgWideUser()
|
||||
{
|
||||
var claims = new[]
|
||||
{
|
||||
new Claim(SeaHavenClaimTypes.OrgScope, SeaHavenClaimTypes.OrgScopeAll),
|
||||
new Claim(ClaimTypes.Role, "Admin")
|
||||
};
|
||||
return new ClaimsPrincipal(new ClaimsIdentity(claims, "test"));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task GetStatsAsync_CountsByStatusExcludingTemplates()
|
||||
{
|
||||
using var ctx = NewContext();
|
||||
ctx.workOrders.AddRange(
|
||||
Wo("Open", isTemplate: false),
|
||||
Wo("Open", isTemplate: false, assignTo: "u1"),
|
||||
Wo("In Progress"),
|
||||
Wo("On Hold"),
|
||||
Wo("Done"),
|
||||
Wo("Done"),
|
||||
Wo("Open", isTemplate: true),
|
||||
Wo("Cancelled", isTemplate: false)
|
||||
new WorkOrder { AccountId = 1, Status = "Open", istemplate = false },
|
||||
new WorkOrder { AccountId = 1, Status = "Open", istemplate = false, AssignTo = "u1" },
|
||||
new WorkOrder { AccountId = 1, Status = "In Progress" },
|
||||
new WorkOrder { AccountId = 1, Status = "On Hold" },
|
||||
new WorkOrder { AccountId = 1, Status = "Done" },
|
||||
new WorkOrder { AccountId = 1, Status = "Done" },
|
||||
new WorkOrder { AccountId = 1, Status = "Open", istemplate = true },
|
||||
new WorkOrder { AccountId = 1, Status = "Cancelled" },
|
||||
new WorkOrder { AccountId = 2, Status = "Open" },
|
||||
new WorkOrder { Status = "Open" }
|
||||
);
|
||||
ctx.SaveChanges();
|
||||
|
||||
var stats = await NewService(ctx).GetStatsAsync(CancellationToken.None);
|
||||
var stats = await NewService(ctx).GetStatsAsync(AccountUser(1), CancellationToken.None);
|
||||
|
||||
stats.Total.Should().Be(7);
|
||||
stats.Open.Should().Be(4);
|
||||
stats.NotDispatched.Should().Be(1);
|
||||
stats.Completed.Should().Be(2);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task GetStatsAsync_OrgWideUserSeesAllNonTemplateOrders()
|
||||
{
|
||||
using var ctx = NewContext();
|
||||
ctx.workOrders.AddRange(
|
||||
new WorkOrder { AccountId = 1, Status = "Open" },
|
||||
new WorkOrder { AccountId = 2, Status = "Done" },
|
||||
new WorkOrder { Status = "Open", istemplate = true });
|
||||
ctx.SaveChanges();
|
||||
|
||||
var stats = await NewService(ctx).GetStatsAsync(OrgWideUser(), CancellationToken.None);
|
||||
|
||||
stats.Total.Should().Be(2);
|
||||
stats.Open.Should().Be(1);
|
||||
stats.Completed.Should().Be(1);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task GetStatsAsync_MissingScopeFailsClosed()
|
||||
{
|
||||
using var ctx = NewContext();
|
||||
var user = new ClaimsPrincipal(new ClaimsIdentity(new[]
|
||||
{
|
||||
new Claim(ClaimTypes.Role, "Dispatcher")
|
||||
}, "test"));
|
||||
|
||||
var act = () => NewService(ctx).GetStatsAsync(user, CancellationToken.None);
|
||||
|
||||
var exception = await act.Should().ThrowAsync<WorkOrderBoardValidationException>();
|
||||
|
||||
exception.Which.Code.Should().Be("Forbidden");
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -19,7 +19,7 @@ namespace Api.SeaHavenIndustries.Controllers
|
|||
[HttpGet("Stats")]
|
||||
public async Task<IActionResult> GetStats(CancellationToken cancellationToken)
|
||||
{
|
||||
var stats = await _dashboardService.GetStatsAsync(cancellationToken);
|
||||
var stats = await _dashboardService.GetStatsAsync(User, cancellationToken);
|
||||
|
||||
return Ok(new
|
||||
{
|
||||
|
|
|
|||
|
|
@ -13,9 +13,15 @@ namespace SeaHaven.DataServices.Implementation
|
|||
_context = context;
|
||||
}
|
||||
|
||||
public async Task<DashboardCounts> GetWorkOrderCountsAsync(CancellationToken cancellationToken)
|
||||
public async Task<DashboardCounts> GetWorkOrderCountsAsync(
|
||||
int? accountId,
|
||||
CancellationToken cancellationToken)
|
||||
{
|
||||
var query = _context.workOrders.Where(w => w.istemplate != true);
|
||||
if (accountId is int scopedAccountId)
|
||||
{
|
||||
query = query.Where(w => w.AccountId == scopedAccountId);
|
||||
}
|
||||
|
||||
var total = await query.CountAsync(cancellationToken);
|
||||
var open = await query.CountAsync(w => w.Status == "Open" || w.Status == "In Progress" || w.Status == "On Hold", cancellationToken);
|
||||
|
|
|
|||
|
|
@ -2,7 +2,9 @@ namespace SeaHaven.DataServices.Interfaces
|
|||
{
|
||||
public interface IDashboardDataService
|
||||
{
|
||||
Task<DashboardCounts> GetWorkOrderCountsAsync(CancellationToken cancellationToken);
|
||||
Task<DashboardCounts> GetWorkOrderCountsAsync(
|
||||
int? accountId,
|
||||
CancellationToken cancellationToken);
|
||||
}
|
||||
|
||||
public class DashboardCounts
|
||||
|
|
|
|||
|
|
@ -1,3 +1,4 @@
|
|||
using System.Security.Claims;
|
||||
using SeaHaven.DataServices.Interfaces;
|
||||
using SeaHaven.Services.DTOs;
|
||||
using SeaHaven.Services.Interfaces;
|
||||
|
|
@ -7,15 +8,22 @@ namespace SeaHaven.Services.Implementation
|
|||
public class DashboardService : IDashboardService
|
||||
{
|
||||
private readonly IDashboardDataService _dataService;
|
||||
private readonly IWorkOrderAccountResolver _accountResolver;
|
||||
|
||||
public DashboardService(IDashboardDataService dataService)
|
||||
public DashboardService(
|
||||
IDashboardDataService dataService,
|
||||
IWorkOrderAccountResolver accountResolver)
|
||||
{
|
||||
_dataService = dataService;
|
||||
_accountResolver = accountResolver;
|
||||
}
|
||||
|
||||
public async Task<DashboardStatsDTO> GetStatsAsync(CancellationToken cancellationToken)
|
||||
public async Task<DashboardStatsDTO> GetStatsAsync(
|
||||
ClaimsPrincipal user,
|
||||
CancellationToken cancellationToken)
|
||||
{
|
||||
var counts = await _dataService.GetWorkOrderCountsAsync(cancellationToken);
|
||||
var accountId = _accountResolver.ResolveAccountFilter(user);
|
||||
var counts = await _dataService.GetWorkOrderCountsAsync(accountId, cancellationToken);
|
||||
|
||||
return new DashboardStatsDTO
|
||||
{
|
||||
|
|
|
|||
|
|
@ -1,9 +1,12 @@
|
|||
using System.Security.Claims;
|
||||
using SeaHaven.Services.DTOs;
|
||||
|
||||
namespace SeaHaven.Services.Interfaces
|
||||
{
|
||||
public interface IDashboardService
|
||||
{
|
||||
Task<DashboardStatsDTO> GetStatsAsync(CancellationToken cancellationToken);
|
||||
Task<DashboardStatsDTO> GetStatsAsync(
|
||||
ClaimsPrincipal user,
|
||||
CancellationToken cancellationToken);
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue