Commit graph

45 commits

Author SHA1 Message Date
Alexandre Brandizzi
9bad363930 fix(work-orders): cancelling from the board cancels the pending uplift
The board and slide-over cancel a work order through the lifecycle status
patch, which set Canceled without touching uplifts, so a pending uplift
stayed in the approval queue. A patch to Canceled now withdraws pending
uplifts in the same save, each with its own uplift_cancel audit entry, and
runs under the per-work-order gate uplift create uses.
2026-09-25 18:37:56 -03:00
Alexandre Brandizzi
207bf59208 fix(media): name HEIC in the unsupported-type message and keep ticket keys out of comments
The rejection message now lists every type the media allowlist accepts, and a
test fails if the message and the allowlist drift apart.
2026-09-25 02:58:15 -03:00
Alexandre Brandizzi
3e3f0f383d fix(media): serialize SH-116 media counts under the work-order lock and serve HEIC as image/heic
The 10-photo / 3-video cap was a check-then-insert with no lock on both
upload surfaces, so two overlapping uploads could both take the last slot.
The board media upload and the vendor portal upload now run count, insert
and save inside ExecuteWorkOrderMutationAsync. GetMediaContent maps .heic
to image/heic.
2026-09-24 22:56:21 -03:00
Alexandre Brandizzi
a8414cd4fa style(tests): format vendor quota test initializers 2026-09-24 21:29:51 -03:00
Alexandre Brandizzi
e15de6e90b fix(media): enforce the per-work-order photo/video limit across both surfaces
The 10-photo / 3-video limit only counted dispatcher attachments, so vendor
portal uploads could push a work order past it (and vice versa). Count the
work order's current vendor documents alongside its attachments on both the
dispatcher media endpoint and the vendor portal. A new completion version
does not count the version it replaces.
2026-09-24 21:27:01 -03:00
Alexandre Brandizzi
dc251c42d4 fix(media): apply SH-116 media contract and lift the 1 MB proxy body cap
The Elastic Beanstalk nginx proxy kept its 1 MB default body limit, so every
media upload over ~1 MB got an nginx 413 before reaching the API. Ship a
.platform nginx override (120M) in the bundle and assert it in the bundle
contract.

Apply the client-confirmed contract: photos up to 10 MB (JPEG/PNG/HEIC),
videos up to 100 MB (MP4/MOV), at most 10 photos and 3 videos per work order,
with stable generic rejection messages. The request ceiling (110 MB) sits
between the per-kind caps and the proxy so oversize files get the generic
message. The vendor portal accepts the same photo/video types and caps.
2026-09-24 20:52:44 -03:00
Alexandre Brandizzi
46eed22707 fix(work-orders): accept mobile media whose declared MIME is foreign (SH-381)
Mobile browsers attach an unreliable Content-Type to a picked file: empty or
application/octet-stream when the OS cannot classify it, and sometimes a
foreign-but-plausible type for a supported container (video/3gpp for an .mp4,
video/x-quicktime for a .mov). The media allowlist already resolved empty and
octet-stream types from the extension, but a concrete foreign type was rejected
outright, so a real .MP4/.MOV picked on a phone passed the client dialog and was
refused by the API.

Any declared type that is not itself on the allowlist now falls back to the
extension. The extension pairing and magic-byte signature still decide, so the
accepted set of files is unchanged; an allowlisted declared type stays
authoritative and must still match its own extension.
2026-09-18 16:33:24 -03:00
Alexandre Brandizzi
776c8be5cb
fix(work-orders): resolve undetermined media MIME from the extension (SH-370) (#122)
The media allowlist refused any upload whose multipart part had an empty or
application/octet-stream Content-Type before looking at the extension or the
bytes. Browsers take that header from File.type, which mobile browsers leave
empty when the OS cannot classify a picked file, while the client-side gate
already accepts such files on extension alone. A real JPG/MP4/MOV could pass
the dialog and still be refused by the API.

Only an undetermined type now falls back to the extension. The resolved type
still goes through the SH-171 document/category rule, the extension pairing,
and the magic-byte signature check, so an octet-stream .pdf stays refused for
Completion, Before and After, and a declared type is never overridden.
2026-09-16 14:53:58 -03:00
Alexandre Brandizzi
6212949fff test(work-orders): scope the media-allowlist guard to photo categories
Updating this branch onto dev turned MediaRules_StillRejectPdf red, and the
test was the thing that had gone stale, not the rule. SH-171 added documents
to the SH-116 media allowlist for Extra and Aveta in 3454125 — a deliberate
widening with its own review — so asserting that media rejects a PDF outright
now contradicts shipped behaviour.

What this branch actually needs guarded is that the completion-doc allowlist
stopped there. Assert it per category instead: Completion, the category
SH-337 touches, plus Before and After, must all still refuse a PDF.
2026-09-10 14:46:54 -03:00
Alexandre Brandizzi
af6faf77e3
Merge branch 'dev' into fix/SH-337-completion-doc-allowlist 2026-09-10 14:38:06 -03:00
Arthur Bassi
3454125d2d fix(work-orders): address document review feedback 2026-09-09 17:09:26 -03:00
Alexandre Brandizzi
7e4db749d0 fix(work-orders): enforce a file allowlist on completion-doc upload (SH-337)
The completion-document endpoint persisted whatever file it received: the
only checks were non-null, non-empty, and a 30 MB request limit. Its sibling
media endpoint has enforced a MIME allowlist, MIME-to-extension pairing, and
a magic-byte signature check since SH-116.

Validate before the file reaches storage, so a rejected upload leaves nothing
behind. An undetermined content type is accepted only alongside a .pdf name
and a %PDF- signature, because the browser leaves File.type empty when the OS
cannot classify the file and the completion-doc dialog already allows that.
2026-09-08 21:24:10 -03:00
Arthur Bassi
a0fdd19934
fix(work-orders): accept image/jpg MIME and expose board MediaCount (#107)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-09-09 00:10:52 +00:00
Arthur Bassi
b4f2c8b763 feat(work-orders): authorize WO media content reads 2026-09-08 11:19:41 -03:00
Arthur Bassi
47022c7761 feat(work-orders): allow Extra Docs PDF/DOC by category 2026-09-08 11:02:40 -03:00
Arthur Bassi
9a0d3fb74c fix(work-orders): copy persisted severity onto GET detail
EOF
2026-09-07 12:02:23 -03:00
Arthur Bassi
7c7c6bc525 feat(work-orders): persist Aveta Extra Docs media category
Round-trip category 5 on media POST/PATCH/GET and project hasAvetaDocument so pending vs attached survives reopen.
2026-08-25 15:10:45 -03:00
Arthur Bassi
f47264ec4d feat(work-orders): allow selective mutations on completed work orders
Permit flagColor, comments, and Extra media after completion while keeping Canceled fully locked.
2026-08-24 09:31:30 -03:00
Arthur Bassi
743841d93e fix(work-orders): map primary dispatch status on detail (SH-183) 2026-08-20 13:41:42 -03:00
arthur.bassi
2222d04fcb Merge remote-tracking branch 'origin/dev' into feature/sh-218-additional-contacts 2026-08-18 20:52:34 -03:00
Alexandre Brandizzi
5386d6129d
Merge branch 'dev' into feature/sh-196-wo-uplifts 2026-08-18 17:46:38 -03:00
Arthur Bassi
92a3b3f045 chore(work-orders): merge origin/dev into SH-218 additional contacts
Keep IsAddOn create tests from dev alongside additional-contacts coverage.
2026-08-18 11:53:26 -03:00
arthur.bassi
aeface594a fix(work-orders): serialize uplift create and atomic cancel (SH-196) 2026-08-18 10:20:05 -03:00
Arthur Bassi
3609365939 fix(work-orders): map additionalContacts on detail GET (SH-218)
Copy contacts into MapInfo so slide-over round-trips create/PATCH, and require name plus phone on retained entries while dropping blank placeholders.
2026-08-18 10:03:12 -03:00
Arthur Bassi
c9a80f5c79 fix(work-orders): restore SH-185 Schedule On Past Due and assert IsAddOn audit
Past Due follows ScheduledDate so Due Date alone cannot set or clear it. Auto-schedule and reschedule tests now expect the third IsAddOn audit field.
2026-08-17 10:36:03 -03:00
Arthur Bassi
05dd262e80 fix(work-orders): derive Past Due from DueDate instead of ScheduledDate
Past Due must track the deadline (Due Date), not Schedule On. Keep dueDate and scheduledDate PATCH mutations independent so rescheduling alone does not clear Past Due.
2026-08-13 13:28:25 -03:00
Arthur Bassi
29dec00790 fix(work-orders): keep pendingUpliftCount on detail and exclude deleted dispatches
Map board PendingUpliftCount through WorkOrderDetailService.MapInfo and ignore soft-deleted dispatches in the aggregate so SH-188 gating is authoritative for board/search/detail.
2026-08-12 11:50:56 -03:00
Arthur Bassi
3c090e2757 fix(work-orders): scope comments and completion-doc by account [SH-221]
Close the remaining SH-221 bypass: board/legacy comments and completion-doc now enforce server-derived account scope, authorize before blob storage, and cover cross-account regressions.
2026-08-11 14:52:02 -03:00
Arthur Bassi
1edcf479ae fix(work-orders): apply account scope across create and reads [SH-221]
Stamp WorkOrder.AccountId on all create paths and filter board/list/search/detail by server-derived account claims so scoped callers cannot cross accounts.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 10:45:37 -03:00
Arthur Bassi
ea2dedf579 !fix(work-orders): fail-closed media account scope with org_scope claim [SH-221] 2026-08-06 10:26:04 -03:00
Arthur Bassi
fdc315d8fe !feat(work-orders): enforce media account scope and AddMedia freshness [SH-221] 2026-08-06 09:47:34 -03:00
Arthur Bassi
e572786b1c ~docs(work-orders): demote ADR 0001 to Proposed pending CODEOWNERS [SH-116] 2026-08-05 09:57:14 -03:00
Arthur Bassi
8ff4ab1742 fix(work-orders): document single-org media scope (ADR 0001)
Clarify SH-116 tenant scope as board-aligned ApplyBaseScope + claims, and add out-of-org-scope GET/mutation tests for deleted/template/missing WOs.
2026-08-04 16:07:26 -03:00
Arthur Bassi
6b18327d6b fix(work-orders): authorize GET media and forward cancellation
Enforce claims-derived read scope on media list and thread CancellationToken through detail data reads so HTTP cancel stops EF work.
2026-08-04 14:14:37 -03:00
Arthur Bassi
680012d88b fix(work-orders): enforce media role scope and relational concurrency
Derive staff vs technician scope from claims (Assigned for User), map
DbUpdateConcurrencyException to a stable 409, and add SQLite competing-write
tests for categorize-vs-categorize and categorize-vs-delete.
2026-08-04 11:08:18 -03:00
Arthur Bassi
899da0eb4f fix(work-orders): enforce media auth and base scope on mutations
Require an authenticated ClaimsPrincipal at service entry and filter
tracked work orders with board base scope so deleted/template rows
surface as NotFound without disclosure.
2026-08-04 11:08:18 -03:00
Arthur Bassi
2ec85d1193 fix(work-orders): harden media upload contract for review blockers
Enforce MIME/extension/magic-byte validation, auth and workOrderVersion concurrency, audit on category changes, and validate-before-store with blob compensate.
2026-08-04 11:08:18 -03:00
Alexandre Brandizzi
d073a503d1 feat(work-orders): board completedDate + media categorize contract
Expose completedDate on PATCH /workorders/{id}/board so CompDoc can leave legacy EditWorkorder. Allow optional media category on upload, PATCH category afterward, and enforce JPG/PNG/MP4/MOV allowlist (SH-116).
2026-08-04 11:08:18 -03:00
Arthur Bassi
8f492c0faf
feat(work-orders): allow comment edit and resolve author audit display names (#24)
* feat(work-orders): enrich board search overdue filters and 0-based paging

* fix(work-orders): align stacked services with CI build

* fix(tests): pass userDataService in comment service unit test

* fix(work-orders): use dedicated overdue query flag

Stop treating WorkOrderType.Other as an overdue sentinel. Board and advanced search now accept overdue=true while types=Other filters real Other rows; combining both uses OR.

* feat(work-orders): allow comment edit and resolve author audit display names

Add PATCH comment for author/Admin, return authorName, and resolve
AssignTo audit values to user display names.

* fix(work-orders): enforce author-only comment edits per SH-122

Remove the undocumented Admin override so only the original comment author can edit, matching the ticket acceptance criteria.

---------

Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-07-24 21:28:44 +00:00
Arthur Bassi
620a36af54
feat(work-orders): enrich board search overdue filters and 0-based paging (#23)
* feat(work-orders): enrich board search overdue filters and 0-based paging

* fix(work-orders): align stacked services with CI build

* fix(tests): pass userDataService in comment service unit test

* fix(work-orders): use dedicated overdue query flag

Stop treating WorkOrderType.Other as an overdue sentinel. Board and advanced search now accept overdue=true while types=Other filters real Other rows; combining both uses OR.

* test(work-orders): cover overdue date/status boundary and Other type-filter

Lock the PR #23 overdue regression boundary through the public advanced
search service. Prove overdue filtering is driven by past-due date plus
non-terminal status, not by the WorkOrderType.Other sentinel:
- Other + future/not-completed excluded from overdue
- past-due + Scheduled included; past-due + Completed/Canceled excluded
- types=[PM, Other] keeps real Other rows and does not pull past-due rows
- assert 0-based paging (Page=0) is preserved alongside overdue/type filters

---------

Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-07-24 21:12:03 +00:00
Alexandre Brandizzi
7d245eb717
refactor: enforce backend boundaries and optimize dispatch (#30)
* refactor(api): enforce service and data-service boundaries

* refactor(api): complete feature service boundaries

* refactor(identity): enforce service and data boundaries

* refactor(vendors): enforce service and data boundaries

* refactor(workorders): enforce service and data boundaries

* refactor(backend): enforce architecture and optimize dispatch

* style(backend): format changed architecture files

* fix(architecture): address backend review follow-ups

* fix(backend): sanitize exception disclosure in changed API endpoints

Replace raw exception-message disclosure (ex.Message) returned to API
callers with a stable sanitized public message plus correlated structured
internal logging, across the endpoints changed in this PR.

- Add SanitizedErrors helper: logs the original exception at Error with a
  generated correlation id and returns a stable public message referencing
  it so support can trace without exposing internals.
- Inject ILogger<T> into the 14 changed controllers and route every
  ex.Message/dbex.Message disclosure through the helper, preserving status
  codes, response shapes, and business data (e.g. OpenWorkOrders).
- Leave FluentValidation (vex.Errors) and existing fixed-message catches
  untouched; out-of-scope controllers (Account/Contact/Employee/Asset/
  PMSchedule) are unchanged.
- Add focused tests proving internal exception text is not returned and
  that Error logging carrying the original exception is invoked.

* fix(architecture): abstract job run state access

* style: format board update service

* test: use collection assertion idiom
2026-07-24 17:35:34 -03:00
Arthur Bassi
c722d37a8f fix(work-orders): align stacked services with CI build 2026-07-17 13:38:55 -03:00
Arthur Bassi
f8511ce732 test(work-orders): cover Phase 6 slide-over and completion doc flows 2026-07-13 13:13:09 -03:00
Arthur Bassi
d040832b87 feat(work-orders): isolate phase 2 inline edit with optimistic concurrency
Deliver PATCH board field updates and drop phases 3-7 code from the branch while keeping phase 0/1 dependencies required to build and test.
2026-07-07 11:26:13 -03:00
Arthur Bassi
4f697f257a wip: work orders phases 1-7 (isolated from phase 0 foundation) 2026-06-30 10:09:48 -03:00