* Align EntityFrameworkCore.SqlServer and Tools to 8.0.8
* Add calendar/events backend API
Cherry-picked from main-backup (19994ef); scratch notes file removed.
* Require authentication on CalendarController
Security review found [Authorize] commented out, leaving all 6 calendar
endpoints anonymous. Enforce auth to match the API convention (17/23
controllers).
* Add CalendarController unit tests (xUnit + EF InMemory)
Assign all files to the internal-dev team so every pull request needs an
approving review from an internal-dev member, giving internal engineering
oversight of changes. The org main-branch-protection ruleset enforces this
via required code-owner review; the internal-dev team has write access, so
it is an eligible code owner.
Add the callable PR labeler workflow. README badges skipped: no root
README.md exists in this repo (only BACKEND_ARCHITECTURE.md). Dependabot
unchanged.
Part of INFRA-47 (INFRA-56, INFRA-57).
* Add dependency-review caller workflow
Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.
* chore: retrigger checks
* chore: retrigger dep review (post-fix)
Adds GetById and Delete; switches list filter from completed=bool to
status=string; expands list payload with FK ids, ScheduleStartTime, and
joined CreatedByName so the frontend edit form can prefill and the list
can show who created each item. Requires auth and stamps createdby from
the logged-in user on Create.
Introduces DispatchUpliftRequest entity and tier-gated approval flow:
vendors request a new NTE from the portal, dispatchers approve or deny
in SHOC, and requests above a configurable threshold require a higher
role. Adds DispatchController for PO-centric list/detail used by the
new Vendor POs page. Seeds Dispatcher and Manager roles.
- VendorAccessToken model + unique-index migration; TokenLifetimeDays config
- VendorPortalTokenService: CSPRNG token generation, rotation, revocation
- VendorPortalController: public portal API guarded by X-Vendor-Token header;
dispatches list/detail, accept, vendor status transitions, cancel request,
checklist updates, signoffs (vendor + customer), comments with dispatcher
attribution via AspNetUsers join
- VendorController: portal-token admin endpoints (get / rotate / revoke)
- WorkOrderController: dispatch email now uses vendor portal URL and HTML-encodes
user fields; AddDispatchComment now stores CommentType='dispatcher' with the
SHOC user's name so portal can attribute the author
- DispatchPublicController: deprecated per-dispatch GET accept flow returns a
static 'link no longer active' page (no state mutation)
- VerifiedBy and VerifiedAt fields on Dispatch model
- VerifyDispatch endpoint validates all checklist items complete + both signoffs present
- Returns missing items list if validation fails
- Sets status to Verified, logs to audit trail
- GetDispatchById includes verifiedBy and verifiedAt
- Migration for new fields
- DispatchSignoff model (DispatchId, SignoffType, Name, Signature base64, SignatureMethod, SignedAt)
- AddDispatchSignoff endpoint — one per type per dispatch, validates no duplicate
- GetDispatchById includes signoffs in response
- Migration for DispatchSignoffs table
- DispatchPublicController with public GET /api/dispatch/accept/{token}
- Updates dispatch status to Acknowledged with timestamp
- Returns styled HTML confirmation page
- Dispatch email now includes green Accept Dispatch button
- Logs vendor acceptance to audit trail
- DispatchWorkOrder junction table for 1:N dispatch-to-WO relationship
- Make Dispatch.WorkOrderId nullable (backward compat)
- Add AcceptToken and AcknowledgedAt to Dispatch model
- Dispatch_DTO accepts WorkOrderIds array
- DispatchToVendor creates junction rows, email lists all WOs in table
- GetDispatches queries both junction table and direct FK
- GetDispatchById includes workOrders list from junction table
- Migration with DispatchWorkOrder table
- TaskListTemplate and TaskListTemplateItem models
- TaskListTemplateController: list, get by ID, create with items, update (replace items), soft delete
- Migration for new tables
- Add DispatchNumber and CompletedDate to Dispatch model
- Add DispatchId to Comments for per-dispatch vendor threads
- GetDispatchById endpoint with vendor communication thread
- UpdateDispatch endpoint for status, NTE, dates, description
- AddDispatchComment endpoint — saves comment + sends email to vendor with sender name
- BackfillDispatchNumbers endpoint for existing dispatches
- SyncVendorReplies endpoint — pulls from DynamoDB VendorReplies table
- Fix reply-to address to include dispatch number
- Include sender name in dispatch and comment emails
- Accept status and assignee query parameters
- Filter in SQL before counting and paginating
- Supports __unassigned for unassigned work orders
- Accurate totalCount reflects filtered results
- Takes the max of: LastModificationTime, latest comment CreatedDate,
latest audit log CreatedAt
- Reflects any comment (customer/vendor/internal) or status change
- Regex extracts 5-digit zip from address string when ZipCode field is empty
- Enables distance calculation for synced locations without structured zip data
- ZipCodeDistance helper with Haversine formula on 33K US zip code centroids
- Loaded as singleton from wwwroot/zipcodes.csv on startup
- Vendor Dropdown endpoint accepts siteZip, returns address and distanceMiles
- Vendors sorted by distance when siteZip provided
- Include locationZip in GetWorkorderById response
- Add ScheduledDate field to Dispatch model and DTO
- Save scheduled date when dispatching to vendor
- Include ScheduledDate in dispatch response projections
- Create Vendor model with company info, trade specialties, active flag
- Create Dispatch model (doubles as Vendor PO) with PO number, NTE, status, reply-to address
- VendorController: CRUD, paginated list, dropdown endpoint with trade filtering
- DispatchToVendor endpoint: multi-vendor dispatch, auto-generated PO numbers (VPO-00001),
HTML email with full WO details via SendGrid, reply-to wo-{number}@int.seahaven.com
- GetDispatches endpoint for listing dispatches by WO
- Include dispatches in GetWorkorderById response
- SendMessage.SendDispatchEmail with reply-to support
- Audit log entry for each dispatch
- Create DropdownOption model with Category, Value, ParentValue for Trade/SubTrade/Problem
- Add DropdownOptionsController with CRUD + ByCategory endpoint with parent filtering
- Add Problem, Trade, SubTrade, VendorNTE, ScheduledDate, CompletedDate, Source to WorkOrder
- Update EditWorkorder_DTO and GetWorkorderById with new fields
- Audit log tracks changes to all new fields
- Seed default Trades (10), SubTrades (20), and Problems (11) on startup
- Add InternalWONumber to WorkOrder model
- Auto-generate 8-digit sequential numbers starting at 10000001
- Generate on new work order creation and DynamoDB sync
- Include in GetWorkorderById and GetWorkOrderList responses
- Add BackfillInternalWONumbers endpoint for existing records
- Add migration for new column
- Accepts JSON body instead of FormData for simple text comments
- Returns new comment with user name for immediate UI update
- Defaults to internal comment type
- Add CommentType field to Comments (customer, vendor, internal)
- Add Status field to EditWorkorder_DTO
- Create WorkOrderAuditLog model tracking field-level changes
- Log all field changes on work order edit and status change
- Include commentType and auditLog in GetWorkorderById response
- Set CommentType=customer on synced comments from DynamoDB
- Add BackfillCommentTypes endpoint for existing data