Alexandre Brandizzi
e0e45d5ed3
feat(uplifts): expose approval queue contract fields (SH-208)
2026-09-16 22:32:23 -03:00
Alexandre Brandizzi
3cb1e3e3f3
feat(uplifts): add approval queue read contract (SH-207)
2026-09-16 20:03:35 -03:00
Alexandre Brandizzi
3047c2ba59
Merge branch 'dev' into feat/ab/sh-278-vendor-area
2026-09-16 17:00:27 -03:00
Alexandre Brandizzi
4b772c8db3
fix(work-orders): keep SH placeholder WO numbers and block downgrades ( #123 )
...
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
SH-320: the WO number normalizer stripped every non-digit, so a manually
entered SH placeholder (e.g. SH00001) was saved as 00000000001 on both
create and patch. Keep the SH prefix, and reject replacing a saved real
APM number with an SH placeholder.
2026-09-16 15:01:10 -03:00
Alexandre Brandizzi
776c8be5cb
fix(work-orders): resolve undetermined media MIME from the extension (SH-370) ( #122 )
...
The media allowlist refused any upload whose multipart part had an empty or
application/octet-stream Content-Type before looking at the extension or the
bytes. Browsers take that header from File.type, which mobile browsers leave
empty when the OS cannot classify a picked file, while the client-side gate
already accepts such files on extension alone. A real JPG/MP4/MOV could pass
the dialog and still be refused by the API.
Only an undetermined type now falls back to the extension. The resolved type
still goes through the SH-171 document/category rule, the extension pairing,
and the magic-byte signature check, so an octet-stream .pdf stays refused for
Completion, Before and After, and a declared type is never overridden.
2026-09-16 14:53:58 -03:00
Alexandre Brandizzi
caba84ea08
fix(work-orders): reject forged automatic lifecycle statuses on board patch (SH-357, SH-358) ( #120 )
...
Incomplete and Scheduled are derived by the server. A direct lifecycleStatus
PATCH may only restate the status derivation already produced; any other
request to move a work order into an automatic state returns the stable
AutomaticLifecycleStatus validation error and leaves status and audit untouched.
2026-09-16 14:41:23 -03:00
Alexandre Brandizzi
8515676f4d
feat(vendors): add admin-assigned vendor company Area
...
Seed an organization-wide Area catalogue (East, Central, West, California)
with stable ids, add a nullable AreaId to VendorCompany, allow only Admins
to change it through the roster endpoints, expose areas facet metadata and
an areas[n] company-directory filter with the __unassigned__ sentinel.
2026-09-16 11:34:45 -03:00
Alexandre Brandizzi
4872fe5ba1
feat(locations): manage ordered site contacts
2026-09-15 19:03:54 -03:00
Alexandre Brandizzi
802b7a414e
SH-338: filter unscheduled work orders before pagination ( #116 )
...
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
* fix(work-orders): filter unscheduled search server-side
* fix(work-orders): preserve unscheduled status scope
2026-09-15 16:46:40 -03:00
Alexandre Brandizzi
1a6edd255a
feat(locations): filter sites by state ( #117 )
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
2026-09-15 16:32:30 -03:00
Alexandre Brandizzi
67089c2135
SH-281: group vendor directory by company ( #115 )
...
* feat(vendors): group directory by company
* style(vendors): format company directory query
* fix(vendors): preserve technician list contract
2026-09-15 16:02:44 -03:00
Arthur Bassi
073d4df963
Merge branch 'dev' into feat/SH-191-completion-freeze
2026-09-14 09:47:22 -03:00
Arthur Bassi
deeb29b512
fix(work-orders): allow Complete without a linked site
...
Snapshot whatever Site/Vendor/POC data exists instead of gating completion on Locations.
2026-09-10 17:56:00 -03:00
Arthur Bassi
e0139d4601
feat(work-orders): capture Site/Vendor/POC snapshot on Completed
...
Freeze effective live values on first Completed transition and project them on GET.
2026-09-10 15:46:25 -03:00
Alexandre Brandizzi
af6faf77e3
Merge branch 'dev' into fix/SH-337-completion-doc-allowlist
2026-09-10 14:38:06 -03:00
Arthur Bassi
1e37fb486c
Merge remote-tracking branch 'origin/dev' into feat/SH-186-status-auto-derivation
2026-09-09 17:34:00 -03:00
Arthur Bassi
3454125d2d
fix(work-orders): address document review feedback
2026-09-09 17:09:26 -03:00
Arthur Bassi
cd34a23e78
Merge remote-tracking branch 'origin/dev' into feat/SH-186-status-auto-derivation
2026-09-09 10:24:15 -03:00
Arthur Bassi
8b4aec300f
feat(work-orders): re-derive lifecycle when board status is patched
...
Scheduled still requires a concrete date, and Incomplete/Pending with a date must promote even when only lifecycleStatus is sent.
2026-09-09 10:23:22 -03:00
Alexandre Brandizzi
7e4db749d0
fix(work-orders): enforce a file allowlist on completion-doc upload (SH-337)
...
The completion-document endpoint persisted whatever file it received: the
only checks were non-null, non-empty, and a 30 MB request limit. Its sibling
media endpoint has enforced a MIME allowlist, MIME-to-extension pairing, and
a magic-byte signature check since SH-116.
Validate before the file reaches storage, so a rejected upload leaves nothing
behind. An undetermined content type is accepted only alongside a .pdf name
and a %PDF- signature, because the browser leaves File.type empty when the OS
cannot classify the file and the completion-doc dialog already allows that.
2026-09-08 21:24:10 -03:00
Arthur Bassi
a0fdd19934
fix(work-orders): accept image/jpg MIME and expose board MediaCount ( #107 )
...
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-09-09 00:10:52 +00:00
Arthur Bassi
f3f9ac1b58
feat(work-orders): derive lifecycle on board create and schedule PATCH
2026-09-08 16:23:13 -03:00
Arthur Bassi
ae9122243d
feat(work-orders): run schedule status side-effects on board field mutations
2026-09-08 16:22:11 -03:00
Arthur Bassi
e12b3ea54b
feat(work-orders): apply schedule lifecycle promote and demote
2026-09-08 16:21:14 -03:00
Arthur Bassi
335390f746
feat(work-orders): derive Scheduled from date without assignee
2026-09-08 16:19:50 -03:00
Arthur Bassi
b4f2c8b763
feat(work-orders): authorize WO media content reads
2026-09-08 11:19:41 -03:00
Arthur Bassi
bb651bb547
feat(work-orders): add file storage OpenRead port
2026-09-08 11:08:26 -03:00
Arthur Bassi
47022c7761
feat(work-orders): allow Extra Docs PDF/DOC by category
2026-09-08 11:02:40 -03:00
Arthur Bassi
9a0d3fb74c
fix(work-orders): copy persisted severity onto GET detail
...
EOF
2026-09-07 12:02:23 -03:00
Arthur Bassi
7a0b91bcd6
feat(work-orders): persist board severity on create, patch, and search
2026-09-07 11:46:13 -03:00
Arthur Bassi
b7df5ef629
feat(work-orders): persist board create lifecycleStatus from the client
2026-09-03 13:36:22 -03:00
Arthur Bassi
f15dde8b30
Merge branch 'fix/sh-296-vendor-invalid-dispatch' of https://github.com/Sea-Haven-Industries/shoc-backend into fix/sh-296-vendor-invalid-dispatch
2026-09-01 09:43:14 -03:00
Arthur Bassi
03c069d10d
fix(work-orders): detach shared dispatch on vendor fork
...
Keep same-vendor saves idempotent and drop stale DispatchWorkOrders so listing and uplift follow the new primary.
2026-09-01 09:42:41 -03:00
Arthur Bassi
af27186527
Merge branch 'dev' into fix/sh-296-vendor-invalid-dispatch
2026-09-01 09:35:00 -03:00
Arthur Bassi
ca0404272e
fix(work-orders): accept linked primary dispatch on vendor board patch
...
Vendor PATCH treated a GET-echoed id as foreign when belong-check used only WorkOrderId.
2026-08-31 15:48:33 -03:00
Arthur Bassi
dcb757b404
fix(work-orders): persist empty apptTime as null scheduled instants
...
EOF
2026-08-31 10:49:54 -03:00
Alexandre Brandizzi
31a4af7da3
fix: omit unmapped sites from work order options ( #89 )
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
2026-08-26 16:39:25 -04:00
Arthur Bassi
0f2e0dacc7
fix(locations): authorize location owner on every board update
...
Reject account-scoped updates of foreign or orphan locations even when accountId is omitted, matching fail-closed tenant scope.
2026-08-26 14:38:34 -03:00
Arthur Bassi
2718fdd294
fix(locations): gate account assignment by scope and active accounts
...
Reject soft-deleted accounts and stop account-scoped callers from assigning or stealing locations across tenants.
2026-08-26 14:16:59 -03:00
Arthur Bassi
2be36d4eac
feat(locations): persist accountId on create and update
...
Allow location CRUD to stamp Locations.AccountId after account existence checks so board create can resolve tenant scope.
2026-08-26 14:03:12 -03:00
Arthur Bassi
2e56ec7678
fix(work-orders): keep location account server-owned and forward create cancellation
...
Stop client writes from changing Locations.AccountId, make the SH-221 migration discoverable, and thread the board-create CancellationToken through lookup and persistence.
2026-08-26 10:00:02 -03:00
Arthur Bassi
61923b2a7d
feat(work-orders): stamp board create account from location
...
Org-wide create no longer depends on customer name. POST /workorders/board requires locationId and stamps WorkOrder.AccountId from Location.AccountId.
2026-08-26 09:12:48 -03:00
Alexandre Brandizzi
5857f8483a
fix(vendors): complete directory contact fallbacks ( #86 )
...
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
* fix(vendors): complete directory contact fallbacks
* fix(vendors): normalize location labels
* fix(vendors): keep company location authoritative
2026-08-25 19:33:47 -04:00
Arthur Bassi
14b85c64a8
Merge branch 'dev' into feat/sh-117-aveta-required
2026-08-25 17:19:30 -03:00
Arthur Bassi
7c7c6bc525
feat(work-orders): persist Aveta Extra Docs media category
...
Round-trip category 5 on media POST/PATCH/GET and project hasAvetaDocument so pending vs attached survives reopen.
2026-08-25 15:10:45 -03:00
Arthur Bassi
04958e6121
fix(work-orders): keep GET /board to scheduled-in-week rows only (SH-165)
2026-08-24 18:29:18 -03:00
Arthur Bassi
15315edf08
feat(work-orders): persist avetaRequired on board create, patch, and search
...
Expose avetaRequired and originalDate on list rows so the frontend can round-trip the Aveta checkbox and Reschedule hover.
2026-08-24 15:14:31 -03:00
Arthur Bassi
4b8a08fb10
fix(work-orders): block comment creation on canceled work orders
2026-08-24 09:59:13 -03:00
Arthur Bassi
f47264ec4d
feat(work-orders): allow selective mutations on completed work orders
...
Permit flagColor, comments, and Extra media after completion while keeping Canceled fully locked.
2026-08-24 09:31:30 -03:00
Alexandre Brandizzi
518d856334
fix(vendors): enforce notes length limit
2026-08-20 18:17:48 -03:00