Commit graph

78 commits

Author SHA1 Message Date
Alexandre Brandizzi
35adef5808 fix(workorders): persist explicit technician assignment 2026-09-29 17:58:52 -03:00
Alexandre Brandizzi
9198c5cd5d Merge remote-tracking branch 'origin/main' into fix/ab/sh-403-reset-code-hardening 2026-09-25 17:52:04 -03:00
Alexandre Brandizzi
e09ef061d1 Merge remote-tracking branch 'origin/main' into feat/ab/sh-385-invite-registration
# Conflicts:
#	Api.SeaHavenIndustries/Controllers/TeamMemberController.cs
2026-09-25 12:45:03 -03:00
Alexandre Brandizzi
3249ea4b6f Merge remote-tracking branch 'origin/main' into fix/ab/sh-403-reset-code-hardening 2026-09-25 12:38:22 -03:00
Alexandre Brandizzi
236199ab7a
Merge pull request #187 from Sea-Haven-Industries/feat/ab/sh-331-sites-api
Sites API: unique site codes, safe delete, open work orders, site notes
2026-09-25 15:26:09 +00:00
Alexandre Brandizzi
c841e130be fix(auth): harden password reset codes against guessing and email enumeration
Forgot Password answers every address the same way and emails a code only
to an active account. Codes are stored as salted SHA-256 hashes, expire 15
minutes after issue, are replaced by a newer request, and are checked only
against the email they were issued to. Five failed checks delete the code;
attempts are reserved with one conditional UPDATE so concurrent guesses
cannot exceed the budget. VerificationCode requires the email, and email and
code are accepted in the JSON body so they stay out of URLs.

The three anonymous endpoints are rate limited to 10 requests per 15
minutes per client IP. Forwarded headers are trusted only through loopback
and private hops, since the API sits behind the EB load balancer and nginx.
The migration adds hash, salt, expiry and attempt columns and deletes the
old plaintext rows.
2026-09-25 12:21:29 -03:00
Alexandre Brandizzi
c0ae8479ce feat(team-members): invite registration with emailed code confirmation (SH-385) 2026-09-25 11:49:10 -03:00
Alexandre Brandizzi
c3865e56ac Sites API: site code uniqueness, soft delete with role check, open work orders, site notes
- Reject duplicate site codes per client (case-insensitive); site code is immutable once set
- Delete tombstones the site and requires the DeleteSites permission (Admin, Scheduler)
- GET /api/locations/{id}/open-work-orders returns the open count and ids
- PATCH /api/locations/{id}/contact-info saves contacts and notes from the work-order Site dialog
- Add nullable Locations.Notes, used as the site-level POC notes fallback
2026-09-25 11:19:29 -03:00
Alexandre Brandizzi
7c097c2750 feat(completion-templates): author templates with safety note and ordered procedures
Adds an extra safety note and an ordered procedure list to completion
document templates, name search, creator and last-updated audit fields,
a tenant-scoped count of open work orders that depend on a template, and
a delete that unlinks Services while they keep requiring a document.
Writes are gated by the create/edit/delete completion template team
permissions instead of the Admin role.
2026-09-25 11:00:22 -03:00
Alexandre Brandizzi
e02f9774dc Keep work-order uplift requests read-only in the Vendor Portal
A vendor could withdraw (or cancel) an uplift a dispatcher raised from the work
order. Withdraw and its cancel alias now refuse requests with createdby set,
using the portal's not-found response, and the portal read model reports
RaisedByVendor so the portal can hide Revise and Withdraw on those requests.
2026-09-25 02:52:03 -03:00
Alexandre Brandizzi
eb2b442775 fix(uplifts): one per-path uplift amount for queue, approval and exposure
Work-order requests store the requested increase in RequestedNTE; vendor
portal requests store the requested NTE total. The queue Delta, the
pending and approved exposure totals, the work-order uplift list, the
board summary and the notification Delta now all read one definition
(UpliftAmount) that honours both meanings and translates to SQL.

Approving a work-order request now adds its increase to the dispatch NTE
instead of replacing the NTE with the increase; vendor requests still end
at their requested total.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 02:32:58 -03:00
Alexandre Brandizzi
fa979605b4 feat(uplifts): expose dispatcher, technician and schedule on queue read (SH-209)
The uplift detail modal needs the work order's assigned dispatcher, the
requesting vendor's technician and the scheduled date. They now resolve
from the same effective work order and vendor as the existing queue row,
so the modal no longer depends on a separate work-order fetch that
account-scoped staff cannot read.
2026-09-18 12:49:25 -03:00
Alexandre Brandizzi
41957d52a7 merge: rebase queue flags onto SH-210 decisions, drop duplicated contract fields
#144 branched from the SH-210 decision-actions commit before the SH-207/SH-208
read-contract corrections landed, so it re-implemented workOrderClosed,
attachmentCount, decidedByName, and pendingExposureTotal with stale semantics:
it projected WorkerOrderNumber (the CRM external id) instead of InternalWONumber
(what the board renders) and summed raw RequestedNTE, which double-counts the new
NTE total on vendor-portal rows across sequential approvals.

Merge origin/feat/ab/sh-210-uplift-decisions (#141, what lands) in and resolve
every conflict in #141's favour, so those fields and their granted-amount
exposure math now come from #141 rather than being duplicated here. Keep only the
two deltas #144 actually adds on top of #141:

- attachmentCount counts non-deleted UpliftEvidence documents on the dispatch,
  not every completion document, so completion photos no longer inflate the chip;
- the queue read resolves the effective work order via the primary-plus-linked
  (DispatchWorkOrders) convention the sibling reads use, so a dispatch linked only
  through that table surfaces its WO context, closed flag, and exposure. Covered
  by an in-memory test and a SQLite relational test that proves the fallback
  translates to SQL.

Drop the superseded attachment-count test that asserted completion documents
count, and align the relational test to seed InternalWONumber.
2026-09-17 12:52:13 -03:00
Alexandre Brandizzi
1eadb82f28
Merge branch 'dev' into feat/ab/sh-210-uplift-decisions 2026-09-17 12:30:20 -03:00
albrand
dfd248cfcb feat(uplifts): expose queue closed flag, attachments, decider, pending exposure (SH-207, SH-208)
The approvals queue frontend needs four list-contract additions the read
contract PRs do not carry yet: workOrderClosed so the Approved tab can
disable Revoke on terminal work orders (mirroring the SH-196 revoke
guard), attachmentCount from non-deleted UpliftEvidence documents so the
+N chip renders, decidedByName for the Approved By column, and the
queue-wide pendingExposureTotal for the header total.
2026-09-16 22:48:47 -03:00
Alexandre Brandizzi
e0e45d5ed3 feat(uplifts): expose approval queue contract fields (SH-208) 2026-09-16 22:32:23 -03:00
Alexandre Brandizzi
3cb1e3e3f3 feat(uplifts): add approval queue read contract (SH-207) 2026-09-16 20:03:35 -03:00
Alexandre Brandizzi
33f517620b feat(work-orders): link service selections to registry 2026-09-16 18:02:57 -03:00
Alexandre Brandizzi
45f98e8154 Merge remote-tracking branch 'origin/dev' into feat/ab/sh-303-services-registry
# Conflicts:
#	Data.SeaHavenIndustries/Auth/ApplicationDbContext.cs
2026-09-16 17:15:38 -03:00
Alexandre Brandizzi
06f9450485 feat(services): add global services registry 2026-09-16 17:07:59 -03:00
Alexandre Brandizzi
8515676f4d feat(vendors): add admin-assigned vendor company Area
Seed an organization-wide Area catalogue (East, Central, West, California)
with stable ids, add a nullable AreaId to VendorCompany, allow only Admins
to change it through the roster endpoints, expose areas facet metadata and
an areas[n] company-directory filter with the __unassigned__ sentinel.
2026-09-16 11:34:45 -03:00
Alexandre Brandizzi
4872fe5ba1 feat(locations): manage ordered site contacts 2026-09-15 19:03:54 -03:00
Arthur Bassi
e0139d4601 feat(work-orders): capture Site/Vendor/POC snapshot on Completed
Freeze effective live values on first Completed transition and project them on GET.
2026-09-10 15:46:25 -03:00
Arthur Bassi
61923b2a7d feat(work-orders): stamp board create account from location
Org-wide create no longer depends on customer name. POST /workorders/board requires locationId and stamps WorkOrder.AccountId from Location.AccountId.
2026-08-26 09:12:48 -03:00
Arthur Bassi
3a7a1b1f09 docs(work-orders): drop ticket key from AvetaRequired xml comment 2026-08-25 12:03:19 -03:00
Arthur Bassi
15315edf08 feat(work-orders): persist avetaRequired on board create, patch, and search
Expose avetaRequired and originalDate on list rows so the frontend can round-trip the Aveta checkbox and Reschedule hover.
2026-08-24 15:14:31 -03:00
Alexandre Brandizzi
0b246724d9 fix: align vendor trades with confirmed taxonomy 2026-08-20 11:44:07 -03:00
arthur.bassi
2222d04fcb Merge remote-tracking branch 'origin/dev' into feature/sh-218-additional-contacts 2026-08-18 20:52:34 -03:00
Alexandre Brandizzi
5386d6129d
Merge branch 'dev' into feature/sh-196-wo-uplifts 2026-08-18 17:46:38 -03:00
Alexandre Brandizzi
d843ac221d
Merge branch 'dev' into feature/sh-218-additional-contacts 2026-08-18 17:46:36 -03:00
Alexandre Brandizzi
577b7add31 feat(vendors): server-owned canonical trades vocabulary for SH-249 2026-08-18 12:11:13 -03:00
Arthur Bassi
92a3b3f045 chore(work-orders): merge origin/dev into SH-218 additional contacts
Keep IsAddOn create tests from dev alongside additional-contacts coverage.
2026-08-18 11:53:26 -03:00
Arthur Bassi
fa05b22df6 chore(work-orders): merge SH-121 facets and keep SH-184 IsAddOn migration 2026-08-17 10:28:03 -03:00
Arthur Bassi
17c2e968cd feat(work-orders): board search facets for SH-121/SH-196 2026-08-13 16:34:21 -03:00
Arthur Bassi
36ef0b00f5 feat(work-orders): persist additionalContacts on create, board GET and PATCH (SH-218)
Add JSON column, DTO/mapper, create + PATCH field, board projection, FluentValidation,
and regression tests for additional POC contacts round-trip.
2026-08-13 16:11:36 -03:00
arthur.bassi
b81cfbb005 feat(work-orders): WO-scoped uplift endpoints and board summary (SH-196)
Expose workorders/{id}/uplifts list/create/cancel/revoke for the SH-196 dialog, aggregate upliftSummary on board rows, and add service/controller regression tests.
2026-08-13 14:49:56 -03:00
Arthur Bassi
97e042f552 feat(work-orders): persist IsAddOn frozen at create (SH-126)
Add set-once IsAddOn with server cutoff at create, board DTO exposure, legacy type-7 backfill, and Types=AddOn search compat. Aligns with FE PR #61 frozen contract.
2026-08-13 13:30:09 -03:00
Arthur Bassi
afcb4fde8d Merge branch 'dev' into feature/wo-board-completed-date-media 2026-08-11 15:20:17 -03:00
Alexandre Brandizzi
24283b320a feat(uplifts): complete SH-101 approval lifecycle 2026-08-11 08:58:19 -03:00
Arthur Bassi
fdc315d8fe !feat(work-orders): enforce media account scope and AddMedia freshness [SH-221] 2026-08-06 09:47:34 -03:00
Alexandre Brandizzi
669e9b2932
feat(vendors): add company roster management (SH-198) (#48)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
* feat(vendors): add company roster management

* fix(security): remove request-controlled write guards

* fix(vendors): synchronize roster company fields

* fix(vendors): source facets from companies
2026-08-03 17:53:24 -03:00
Alexandre Brandizzi
e3c37e54b4 feat: complete SH-133 procurement reconciliation 2026-07-24 22:13:25 -03:00
Alexandre Brandizzi
bdffe77e42 feat: ingest signed procurement work-order webhooks 2026-07-24 21:03:50 -03:00
Alexandre Brandizzi
7d245eb717
refactor: enforce backend boundaries and optimize dispatch (#30)
* refactor(api): enforce service and data-service boundaries

* refactor(api): complete feature service boundaries

* refactor(identity): enforce service and data boundaries

* refactor(vendors): enforce service and data boundaries

* refactor(workorders): enforce service and data boundaries

* refactor(backend): enforce architecture and optimize dispatch

* style(backend): format changed architecture files

* fix(architecture): address backend review follow-ups

* fix(backend): sanitize exception disclosure in changed API endpoints

Replace raw exception-message disclosure (ex.Message) returned to API
callers with a stable sanitized public message plus correlated structured
internal logging, across the endpoints changed in this PR.

- Add SanitizedErrors helper: logs the original exception at Error with a
  generated correlation id and returns a stable public message referencing
  it so support can trace without exposing internals.
- Inject ILogger<T> into the 14 changed controllers and route every
  ex.Message/dbex.Message disclosure through the helper, preserving status
  codes, response shapes, and business data (e.g. OpenWorkOrders).
- Leave FluentValidation (vex.Errors) and existing fixed-message catches
  untouched; out-of-scope controllers (Account/Contact/Employee/Asset/
  PMSchedule) are unchanged.
- Add focused tests proving internal exception text is not returned and
  that Error logging carrying the original exception is invoked.

* fix(architecture): abstract job run state access

* style: format board update service

* test: use collection assertion idiom
2026-07-24 17:35:34 -03:00
Alexandre Brandizzi
e5cf4cec09 merge: integrate origin/dev into PR #22 flag-color base
Brings in dev's Phase 5 (PR #17) + vendor PRs (#25/#28/#29) atop the
Phase 6/7 + flagColor base (PR #22). Preserves dev Phase 1-5 behavior and
PR #22 Phase 6/7 + flagColor behavior.

Conflict resolutions (16 files):
- Migrations Phase4_SearchIndexes/.Designer + Phase5_DomainEvents/.Designer:
  take dev (Phase4 incl. SQL Server SiteCode/InternalWONumber index-compat
  shrink fix; Phase5 identical). ModelSnapshot union: Vendor CompanyId index
  + Phase7 ServiceNotes/ExternalWorkOrderId index.
- ApplicationDbContext: keep dev SiteCode/InternalWONumber MaxLength (Phase1-5
  + unguarded model test) + HEAD CompletionDocTemplate/ExternalWorkOrderId.
- WorkOrderAuditService: unify on dev async staging API; convert Phase6
  CompletionService 2 call sites to await StageFieldChangedAsync (drops
  HEAD sync duplicate; only callers, no test refs).
- Hosted services: take HEAD (retry-on-failure, coherent with Phase7
  WorkOrderJobRunStateAccessor/OpsHealth). Program.cs keeps dev vendor DI
  (ClamAV/VendorDocumentScanWorker/ArgumentExceptionFilter) + HEAD Phase7.
- WorkOrderController: keep HEAD Phase6/7 service params + dev doc comment.
- VendorController/WorkOrderBoardCreateService/QueryFilters/appsettings:
  union / dev-correct.
- WorkOrderBoardUpdateServiceTests: union of HEAD (Phase6/7+flagColor) and
  dev (Phase1-5) test methods.

Verified WorkOrderType.Other (enum 99) is a legit category, not an overdue
sentinel; overdue uses dedicated OperationalFlags.PastDue + IsPastDue, and
'Overdue' is rejected as a WorkOrderType (no PR #23 import needed).

Removed dev duplicate Api.Options.WorkOrderJobRunState (HEAD defines it in
Services.Implementation alongside the Accessor; Services cannot reference Api).
2026-07-24 14:20:16 -03:00
Alexandre Brandizzi
5fa9b4e344 merge: integrate origin/dev into work-orders-phase-5
Brings in merged PR #16 and vendor/Phase 1-4 work from origin/dev into the
Phase 5 (WeekRolled) head. Only conflict was ApplicationDbContextModelSnapshot.cs
(EF model snapshot touched by both sides); resolved by taking dev's latest
snapshot (matches migration 20260723220614) and grafting the
WorkOrderWeekRolledLedger entity + relationship blocks, matching the Phase5
migration Designer exactly. Migration ordering unchanged: Phase5 (20260709)
runs before vendor migrations (20260720-20260723).
2026-07-24 13:51:41 -03:00
Arthur Bassi
7459dca3c6 feat(work-orders): add Phase 5 scheduled domain events (WeekRolled)
Introduce in-process WeekRolled job with idempotent ledger to increment carriedOver for the SHOC board, plus optional PastDue cache and admin reprocess endpoints while keeping isPastDue derived on-read.
2026-07-24 10:13:17 -03:00
Alexandre Brandizzi
4863d1fdaf feat(vendors): complete operations roadmap backend 2026-07-23 19:18:06 -03:00
Alexandre Brandizzi
8cf49afc2c feat(vendors): complete core vendor workflows 2026-07-23 17:02:40 -03:00
Alexandre Brandizzi
1162c68596
feat(vendors): add directory filters and details API (#25)
* feat(vendors): add directory filters and details API

* fix(vendors): preserve omitted status

* fix(vendors): align facet filtering

* fix(vendors): address directory review findings
2026-07-23 15:55:47 +00:00