Commit graph

74 commits

Author SHA1 Message Date
Arthur Bassi
7a81b6d279 test(work-orders): add Phase 0 domain unit tests 2026-07-02 09:19:28 -03:00
Arthur Bassi
49e5de5152 feat(work-orders): add audit, field lock and sync merge services 2026-07-02 09:17:59 -03:00
Arthur Bassi
e244c32bc9 feat(work-orders): add EF config and Phase 0 migration 2026-07-02 09:17:59 -03:00
Arthur Bassi
568961642f feat(work-orders): add domain enums and aggregate root fields 2026-07-02 09:17:59 -03:00
12fd5efe8b Merge branch 'main' into dev 2026-06-22 18:57:13 -04:00
Adam Moussa
b2aeb35a55
Add starter unit tests for validators, DTO mappers, and PagedResult (#9) 2026-06-22 18:56:46 -04:00
Adam Moussa
1f3972ae49
Add calendar/events backend API (#8)
* Align EntityFrameworkCore.SqlServer and Tools to 8.0.8

* Add calendar/events backend API

Cherry-picked from main-backup (19994ef); scratch notes file removed.

* Require authentication on CalendarController

Security review found [Authorize] commented out, leaving all 6 calendar
endpoints anonymous. Enforce auth to match the API convention (17/23
controllers).

* Add CalendarController unit tests (xUnit + EF InMemory)
2026-06-22 18:46:46 -04:00
dd1ffba06d Add CODEOWNERS requiring internal-dev review 2026-06-22 18:23:54 -04:00
d4d94a2e89 Add CI workflow calling org ci-dotnet reusable 2026-06-22 18:23:54 -04:00
Adam Moussa
02ff65b647
Add CODEOWNERS requiring internal-dev review (#6)
Assign all files to the internal-dev team so every pull request needs an
approving review from an internal-dev member, giving internal engineering
oversight of changes. The org main-branch-protection ruleset enforces this
via required code-owner review; the internal-dev team has write access, so
it is an eligible code owner.
2026-06-22 16:47:27 -04:00
Adam Moussa
f53a276f1d
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#5)
Add the callable PR labeler workflow. README badges skipped: no root
README.md exists in this repo (only BACKEND_ARCHITECTURE.md). Dependabot
unchanged.

Part of INFRA-47 (INFRA-56, INFRA-57).
2026-06-11 14:14:27 -04:00
Adam Moussa
3a61885c71
Add dependency-review caller workflow (#3)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:27:11 -04:00
Adam Moussa
047ad23c81
Merge pull request #4 from Sea-Haven-Industries/fix/remove-hardcoded-secrets
fix(security): remove hardcoded secrets from source
2026-06-05 12:00:30 -04:00
c887d6d9d8 fix(security): remove hardcoded secrets from source
Replace all hardcoded credentials with configuration-injected values:
- SQL Server connection strings -> ${CONNECTION_STRING} env-var placeholders (4 appsettings files)
- SendGrid API keys -> ${SENDGRID_API_KEY} (incl. commented copies in SendMessage.cs)
- JWT signing secret -> ${JWT_SECRET} (3 appsettings files)
- AWS access key pair in UploadFileHp.cs -> DI-injected IAmazonS3 (SDK default credential chain)
- Google Maps API keys in App.razor / Home.razor -> IConfiguration lookup
- Legacy SMTP credentials in SendMessage.cs comments -> placeholders

Add .env.example documenting required environment variables and a
Configuration & Secrets section in BACKEND_ARCHITECTURE.md.

All exposed credentials were rotated 2026-06-05 prior to this scrub.
Source: github-audit-report.md Criticals 1-2 (Agent A4).
Verified: dotnet build 0 errors; secret-pattern grep clean.
2026-06-05 11:56:54 -04:00
Adam Moussa
50a4bf57f8
Merge pull request #2 from Sea-Haven-Industries/Dev
Dev
2026-05-14 17:35:05 -04:00
npalOmega
57d378125f fixing architecture 2026-05-14 11:09:17 -05:00
npalOmega
59385cf5b1 backend changes 2026-05-14 11:00:12 -05:00
npalOmega
5e4d9894e9 backend architectural template 2026-05-06 10:49:33 -05:00
npalOmega
ac76b201de refactor 2026-04-28 18:55:14 -05:00
npalOmega
64adcae4ed fixes for Dev changes 2026-04-24 12:12:16 -05:00
Adam Moussa
06bde26aff Wire FollowUp controller for real CRUD
Adds GetById and Delete; switches list filter from completed=bool to
status=string; expands list payload with FK ids, ScheduleStartTime, and
joined CreatedByName so the frontend edit form can prefill and the list
can show who created each item. Requires auth and stamps createdby from
the logged-in user on Create.
2026-04-20 13:49:45 -04:00
Adam Moussa
899ee7b83d Add NTE uplift workflow and vendor PO detail API
Introduces DispatchUpliftRequest entity and tier-gated approval flow:
vendors request a new NTE from the portal, dispatchers approve or deny
in SHOC, and requests above a configurable threshold require a higher
role. Adds DispatchController for PO-centric list/detail used by the
new Vendor POs page. Seeds Dispatcher and Manager roles.
2026-04-20 13:25:56 -04:00
Adam Moussa
b36ccd2758 Merge feature/vendor-portal into dev 2026-04-20 12:45:04 -04:00
Adam Moussa
73be673444 Add vendor portal with token-based authentication
- VendorAccessToken model + unique-index migration; TokenLifetimeDays config
- VendorPortalTokenService: CSPRNG token generation, rotation, revocation
- VendorPortalController: public portal API guarded by X-Vendor-Token header;
  dispatches list/detail, accept, vendor status transitions, cancel request,
  checklist updates, signoffs (vendor + customer), comments with dispatcher
  attribution via AspNetUsers join
- VendorController: portal-token admin endpoints (get / rotate / revoke)
- WorkOrderController: dispatch email now uses vendor portal URL and HTML-encodes
  user fields; AddDispatchComment now stores CommentType='dispatcher' with the
  SHOC user's name so portal can attribute the author
- DispatchPublicController: deprecated per-dispatch GET accept flow returns a
  static 'link no longer active' page (no state mutation)
2026-04-20 12:01:53 -04:00
Adam Moussa
6e0f891ca3 Update TODO with completed items and vendor portal next steps 2026-04-17 16:33:17 -04:00
Adam Moussa
3355df111f Add locationId filter to GetWorkOrderList
- Accept locationId query parameter for server-side location filtering
- Used by dispatch modal to find all WOs at the same site
2026-04-17 16:13:18 -04:00
Adam Moussa
575e8ab6fc Add dispatcher verification as final dispatch gate
- VerifiedBy and VerifiedAt fields on Dispatch model
- VerifyDispatch endpoint validates all checklist items complete + both signoffs present
- Returns missing items list if validation fails
- Sets status to Verified, logs to audit trail
- GetDispatchById includes verifiedBy and verifiedAt
- Migration for new fields
2026-04-17 16:03:34 -04:00
Adam Moussa
81472bf729 Add dispatch sign-offs with signature capture
- DispatchSignoff model (DispatchId, SignoffType, Name, Signature base64, SignatureMethod, SignedAt)
- AddDispatchSignoff endpoint — one per type per dispatch, validates no duplicate
- GetDispatchById includes signoffs in response
- Migration for DispatchSignoffs table
2026-04-17 15:51:20 -04:00
Adam Moussa
c482fa0558 Add vendor accept via email link
- DispatchPublicController with public GET /api/dispatch/accept/{token}
- Updates dispatch status to Acknowledged with timestamp
- Returns styled HTML confirmation page
- Dispatch email now includes green Accept Dispatch button
- Logs vendor acceptance to audit trail
2026-04-17 15:39:50 -04:00
Adam Moussa
3a25fa8559 Add dispatch checklist items with template support
- DispatchChecklistItem model (DispatchId, WorkOrderId, ItemText, IsCompleted, CompletedBy, CompletedAt)
- DispatchToVendor copies template items when TaskListTemplateId provided
- Supports custom checklist items alongside template items
- UpdateChecklistItem endpoint to toggle completion with user name
- AddChecklistItem endpoint for ad-hoc items
- GetDispatchById includes checklist items in response
- Migration for DispatchChecklistItems table
2026-04-17 15:28:52 -04:00
Adam Moussa
be190836a4 Add multi-WO dispatch support with junction table
- DispatchWorkOrder junction table for 1:N dispatch-to-WO relationship
- Make Dispatch.WorkOrderId nullable (backward compat)
- Add AcceptToken and AcknowledgedAt to Dispatch model
- Dispatch_DTO accepts WorkOrderIds array
- DispatchToVendor creates junction rows, email lists all WOs in table
- GetDispatches queries both junction table and direct FK
- GetDispatchById includes workOrders list from junction table
- Migration with DispatchWorkOrder table
2026-04-17 15:16:28 -04:00
Adam Moussa
1f4bd12cd7 Add Task List Templates with CRUD controller
- TaskListTemplate and TaskListTemplateItem models
- TaskListTemplateController: list, get by ID, create with items, update (replace items), soft delete
- Migration for new tables
2026-04-17 14:57:18 -04:00
Adam Moussa
63f76e9b2c Add dispatch detail modal backend + vendor reply sync
- Add DispatchNumber and CompletedDate to Dispatch model
- Add DispatchId to Comments for per-dispatch vendor threads
- GetDispatchById endpoint with vendor communication thread
- UpdateDispatch endpoint for status, NTE, dates, description
- AddDispatchComment endpoint — saves comment + sends email to vendor with sender name
- BackfillDispatchNumbers endpoint for existing dispatches
- SyncVendorReplies endpoint — pulls from DynamoDB VendorReplies table
- Fix reply-to address to include dispatch number
- Include sender name in dispatch and comment emails
2026-04-17 14:01:03 -04:00
Adam Moussa
17590daf9d Add project TODO tracking deferred work items
- Dispatch detail modal, Front API integration, vendor communication
- Missing pages (profile, settings, calendar)
- Dashboard analytics, PO enhancements, deployment migration
2026-04-17 13:08:12 -04:00
Adam Moussa
f89db3da52 Add server-side status and assignee filters to GetWorkOrderList
- Accept status and assignee query parameters
- Filter in SQL before counting and paginating
- Supports __unassigned for unassigned work orders
- Accurate totalCount reflects filtered results
2026-04-17 12:57:37 -04:00
Adam Moussa
7d764f966d Add server-side sorting to GetWorkOrderList
- Accept sortBy and sortDir query parameters
- Supports sorting by: number, title, location, priority, status,
  createdDate, assignedTo, lastUpdated
- Default sort: lastUpdated desc
- Sort applied in SQL before pagination
2026-04-17 12:50:23 -04:00
Adam Moussa
091390fcad Calculate lastUpdated from comments, audit log, and modification time
- Takes the max of: LastModificationTime, latest comment CreatedDate,
  latest audit log CreatedAt
- Reflects any comment (customer/vendor/internal) or status change
2026-04-17 12:35:14 -04:00
Adam Moussa
0a564499f5 Add lastUpdated field to work order list response 2026-04-17 12:33:30 -04:00
Adam Moussa
7ef7205681 Include InternalWONumber in work order list search
- Search now matches against internal WO number, customer WO number,
  title, and location name/title
2026-04-17 12:31:00 -04:00
Adam Moussa
b072d1fa2d Extract zip code from location address as fallback for distance calc
- Regex extracts 5-digit zip from address string when ZipCode field is empty
- Enables distance calculation for synced locations without structured zip data
2026-04-17 11:59:34 -04:00
Adam Moussa
521bb0fba2 Add zip-to-zip distance calculation for vendor dispatch
- ZipCodeDistance helper with Haversine formula on 33K US zip code centroids
- Loaded as singleton from wwwroot/zipcodes.csv on startup
- Vendor Dropdown endpoint accepts siteZip, returns address and distanceMiles
- Vendors sorted by distance when siteZip provided
- Include locationZip in GetWorkorderById response
2026-04-17 11:56:06 -04:00
Adam Moussa
ee69a1863a Add vendor scheduled date to dispatch workflow
- Add ScheduledDate field to Dispatch model and DTO
- Save scheduled date when dispatching to vendor
- Include ScheduledDate in dispatch response projections
2026-04-17 11:47:00 -04:00
Adam Moussa
d24c4643f5 Add vendor dispatch workflow backend
- Create Vendor model with company info, trade specialties, active flag
- Create Dispatch model (doubles as Vendor PO) with PO number, NTE, status, reply-to address
- VendorController: CRUD, paginated list, dropdown endpoint with trade filtering
- DispatchToVendor endpoint: multi-vendor dispatch, auto-generated PO numbers (VPO-00001),
  HTML email with full WO details via SendGrid, reply-to wo-{number}@int.seahaven.com
- GetDispatches endpoint for listing dispatches by WO
- Include dispatches in GetWorkorderById response
- SendMessage.SendDispatchEmail with reply-to support
- Audit log entry for each dispatch
2026-04-17 11:37:35 -04:00
Adam Moussa
05b36ef7dd Add configurable dropdowns, new WO fields, and seed data
- Create DropdownOption model with Category, Value, ParentValue for Trade/SubTrade/Problem
- Add DropdownOptionsController with CRUD + ByCategory endpoint with parent filtering
- Add Problem, Trade, SubTrade, VendorNTE, ScheduledDate, CompletedDate, Source to WorkOrder
- Update EditWorkorder_DTO and GetWorkorderById with new fields
- Audit log tracks changes to all new fields
- Seed default Trades (10), SubTrades (20), and Problems (11) on startup
2026-04-17 10:40:38 -04:00
Adam Moussa
78c7850fb2 Add DashboardController with Stats endpoint
- Returns total, open, notDispatched, completed work order counts
2026-04-16 19:25:42 -04:00
Adam Moussa
8959efc06b Add ChangeAssignment endpoint with audit logging
- POST /api/WorkOrder/ChangeAssignment?id=&assignTo=
- Logs old and new user names in audit trail
- Returns updated assignment name
2026-04-16 19:04:59 -04:00
Adam Moussa
d07e24e419 Add InternalWONumber field with auto-generation
- Add InternalWONumber to WorkOrder model
- Auto-generate 8-digit sequential numbers starting at 10000001
- Generate on new work order creation and DynamoDB sync
- Include in GetWorkorderById and GetWorkOrderList responses
- Add BackfillInternalWONumbers endpoint for existing records
- Add migration for new column
2026-04-16 18:42:58 -04:00
Adam Moussa
be70c84add Make Comments_DTO fields nullable for JSON endpoint compatibility
- Text, UserId, CreatedDate are set server-side, not required from client
2026-04-16 18:24:04 -04:00
Adam Moussa
18ca737307 Add JSON-based AddCommentJson endpoint
- Accepts JSON body instead of FormData for simple text comments
- Returns new comment with user name for immediate UI update
- Defaults to internal comment type
2026-04-16 18:22:34 -04:00
Adam Moussa
e1f57d3fb2 Add comment types, audit logging, and WorkOrderAuditLog table
- Add CommentType field to Comments (customer, vendor, internal)
- Add Status field to EditWorkorder_DTO
- Create WorkOrderAuditLog model tracking field-level changes
- Log all field changes on work order edit and status change
- Include commentType and auditLog in GetWorkorderById response
- Set CommentType=customer on synced comments from DynamoDB
- Add BackfillCommentTypes endpoint for existing data
2026-04-16 18:09:57 -04:00