The Document(...) helper object initializer was under-indented, failing the G3 dotnet format changed-file gate in the architecture and deployable-bundle checks. Reindented to satisfy dotnet format --verify-no-changes.
The approvals queue frontend needs four list-contract additions the read
contract PRs do not carry yet: workOrderClosed so the Approved tab can
disable Revoke on terminal work orders (mirroring the SH-196 revoke
guard), attachmentCount from non-deleted UpliftEvidence documents so the
+N chip renders, decidedByName for the Approved By column, and the
queue-wide pendingExposureTotal for the header total.
SH-320: the WO number normalizer stripped every non-digit, so a manually
entered SH placeholder (e.g. SH00001) was saved as 00000000001 on both
create and patch. Keep the SH prefix, and reject replacing a saved real
APM number with an SH placeholder.
The media allowlist refused any upload whose multipart part had an empty or
application/octet-stream Content-Type before looking at the extension or the
bytes. Browsers take that header from File.type, which mobile browsers leave
empty when the OS cannot classify a picked file, while the client-side gate
already accepts such files on extension alone. A real JPG/MP4/MOV could pass
the dialog and still be refused by the API.
Only an undetermined type now falls back to the extension. The resolved type
still goes through the SH-171 document/category rule, the extension pairing,
and the magic-byte signature check, so an octet-stream .pdf stays refused for
Completion, Before and After, and a declared type is never overridden.
Incomplete and Scheduled are derived by the server. A direct lifecycleStatus
PATCH may only restate the status derivation already produced; any other
request to move a work order into an automatic state returns the stable
AutomaticLifecycleStatus validation error and leaves status and audit untouched.
Seed an organization-wide Area catalogue (East, Central, West, California)
with stable ids, add a nullable AreaId to VendorCompany, allow only Admins
to change it through the roster endpoints, expose areas facet metadata and
an areas[n] company-directory filter with the __unassigned__ sentinel.
Updating this branch onto dev turned MediaRules_StillRejectPdf red, and the
test was the thing that had gone stale, not the rule. SH-171 added documents
to the SH-116 media allowlist for Extra and Aveta in 3454125 — a deliberate
widening with its own review — so asserting that media rejects a PDF outright
now contradicts shipped behaviour.
What this branch actually needs guarded is that the completion-doc allowlist
stopped there. Assert it per category instead: Completion, the category
SH-337 touches, plus Before and After, must all still refuse a PDF.
The dev Terraform rollback verify was the one gate the previous commit
missed, and it is the copy that actually ran on 34293894914. It still
decided on the first Ready poll: previous version correctly restored,
health not yet converged, reported as a failed rollback.
Split the version and health conditions the same way the other three
gates now do — a Ready poll on the wrong version fails immediately and
names the version that came up, while the correct version with unsettled
health keeps polling inside the unchanged 80 x 15s budget. Timeout now
reports the last observed status, version and health.
Elastic Beanstalk reports Ready as soon as a rollout finishes, before
enhanced health has converged. Both verification gates decided on the first
Ready poll, so a release whose version had activated correctly was failed on
a health value that had not settled yet — and then rolled back.
The failure message compounded it: run 34293894914 printed 'Environment
became Ready without activating expected version a0fdd199...' when the
active version was exactly a0fdd199... The discriminator was health, not
version, which sends whoever reads the log after the wrong problem.
Separate the two conditions, keep polling while the correct version is
active but health has not settled, and report the last observed state on
timeout. An environment that stays unhealthy for the full window still
fails; this does not widen what counts as a good deploy.
The completion-document endpoint persisted whatever file it received: the
only checks were non-null, non-empty, and a 30 MB request limit. Its sibling
media endpoint has enforced a MIME allowlist, MIME-to-extension pairing, and
a magic-byte signature check since SH-116.
Validate before the file reaches storage, so a rejected upload leaves nothing
behind. An undetermined content type is accepted only alongside a .pdf name
and a %PDF- signature, because the browser leaves File.type empty when the OS
cannot classify the file and the completion-doc dialog already allows that.