Commit graph

234 commits

Author SHA1 Message Date
Alexandre Brandizzi
d33ba34db9 fix(vendor-portal): vendors revise only uplift requests they raised
A work-order request stores the requested increase, not a total. Letting
the vendor revise one after changes were requested rewrote RequestedNTE
as a total while it still read as a work-order request, corrupting its
amount and the NTE it would be approved to. Revise now answers not-found
for any request the vendor did not raise and leaves the row untouched.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 02:35:06 -03:00
Alexandre Brandizzi
eb2b442775 fix(uplifts): one per-path uplift amount for queue, approval and exposure
Work-order requests store the requested increase in RequestedNTE; vendor
portal requests store the requested NTE total. The queue Delta, the
pending and approved exposure totals, the work-order uplift list, the
board summary and the notification Delta now all read one definition
(UpliftAmount) that honours both meanings and translates to SQL.

Approving a work-order request now adds its increase to the dispatch NTE
instead of replacing the NTE with the increase; vendor requests still end
at their requested total.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 02:32:58 -03:00
Alexandre Brandizzi
f40ad7c1ef fix(uplifts): pending exposure header sums the row deltas
The approvals header summed the whole RequestedNTE for work-order-path
requests, while each Pending row shows RequestedNTE - CurrentNTE. When a
work order already had an NTE the header overstated exposure by that NTE.

The header now sums the same Delta the rows display, over the same rows
the Pending tab lists (non-deleted request on a non-deleted dispatch).
The unused duplicate aggregate is removed so one definition remains.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 02:10:41 -03:00
Alexandre Brandizzi
50e5553e57
Merge pull request #177 from Sea-Haven-Industries/fix/ab/sh-397-uplift-decision-audit
Some checks are pending
Backend CI / Build and test (push) Waiting to run
Backend CI / architecture (push) Waiting to run
Backend CI / review (push) Waiting to run
Backend CI / ci-complete (push) Blocked by required conditions
fix(uplifts): let admins decide uplifts whose dispatch has no work order
2026-09-25 02:45:18 +00:00
Alexandre Brandizzi
59b8cdaf7d
Merge pull request #168 from Sea-Haven-Industries/fix/sh-327-request-uplifts-permission
fix(uplifts): enforce request permission at service boundary
2026-09-25 02:35:19 +00:00
Alexandre Brandizzi
c5d82a996a fix(uplifts): audit uplift decisions on the dispatch's resolved work order
Approve, reject, request-changes, expiry and escalation staged their work
order audit with WorkOrderId = dispatch.WorkOrderId ?? 0. WorkOrderAuditLogs
requires a real work order, so any uplift on a dispatch without an owning
work order failed to save: the decision returned a 500 and the request stayed
Pending, and the expiry sweep failed on it every run.

The audit now goes to the work order the uplift resolves to through the
existing owner-or-linked read that revoke already uses. When none resolves,
the status change is saved on the request and no audit row is written.
2026-09-24 23:30:16 -03:00
Alexandre Brandizzi
8185875ad2
Merge pull request #176 from Sea-Haven-Industries/fix/ab/sh-327-admin-approves-uplifts
fix(uplifts): Admin passes uplift approval checks regardless of tier config (SH-327)
2026-09-25 02:13:26 +00:00
Alexandre Brandizzi
beb091fcc8 Merge remote-tracking branch 'origin/main' into lane/sh-327
# Conflicts:
#	Api.SeaHavenIndustries.Tests/WorkOrderUpliftControllerTests.cs
2026-09-24 23:00:18 -03:00
Alexandre Brandizzi
1e2f39a5fa chore(uplifts): drop ticket key from source comments 2026-09-24 22:57:09 -03:00
Alexandre Brandizzi
cfb05a906f fix(uplifts): Admin passes uplift approval checks regardless of tier config (SH-327)
UserCanApprove only accepted roles listed in Approvals:Tier1Roles/Tier2Roles,
so an environment whose config omits Admin denied every approval surface to
admins: can-approve, per-row CanDecide, approve/reject/request-changes and
evidence download. Admin now short-circuits the check; tier-role config still
governs every other role.
2026-09-24 22:34:32 -03:00
Alexandre Brandizzi
cc7cda4818 Merge remote-tracking branch 'origin/main' into lane/sh-327 2026-09-24 22:28:15 -03:00
Alexandre Brandizzi
24ad21d7f2 Merge remote-tracking branch 'origin/main' into lane/sh-387 2026-09-24 22:25:54 -03:00
Alexandre Brandizzi
7b7df4463e
Merge pull request #174 from Sea-Haven-Industries/fix/ab/sh-393-uplift-scope
Some checks are pending
Backend CI / Build and test (push) Waiting to run
Backend CI / architecture (push) Waiting to run
Backend CI / review (push) Waiting to run
Backend CI / ci-complete (push) Blocked by required conditions
fix(uplifts): uplifts created from a work order show on that work order (SH-393)
2026-09-25 00:54:42 +00:00
Alexandre Brandizzi
89376e99e4 fix(uplifts): resolve work-order uplifts through owned dispatches (SH-393)
Board create left the new primary dispatch with no WorkOrderId, so uplifts
created on those work orders were written to a dispatch the work order's
uplift reads never resolve: not listed, allowance never consumed, queue WO
number blank. The same orphan made ApptDate/vendor patches fail with
"A primary dispatch is required".

- Board create backfills Dispatch.WorkOrderId after the first save.
- Uplift create resolves its dispatch through the read-side scope
  (non-deleted, owned or linked); otherwise the stable
  "no primary dispatch" error.
- Data-only migration assigns existing orphaned primaries to the single
  work order naming them primary; idempotent.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-24 21:22:13 -03:00
Alexandre Brandizzi
3b626cca58 fix: make team member creation atomic 2026-09-23 03:35:23 -03:00
Alexandre Brandizzi
8af9ad076f fix: map concurrent uplift inserts to conflict 2026-09-23 01:26:15 -03:00
Alexandre Brandizzi
0b39d92723 Merge remote-tracking branch 'origin/main' into HEAD
# Conflicts:
#	SeaHavenIndustries.Tests/WorkOrderUpliftServiceTests.cs
2026-09-23 00:57:01 -03:00
Alexandre Brandizzi
ff6a5945f1 fix(uplifts): honor current permissions and denial contract 2026-09-22 23:24:17 -03:00
Alexandre Brandizzi
9156107e72 fix(uplifts): enforce request permission at service boundary 2026-09-22 23:09:47 -03:00
Alexandre Brandizzi
5c5c01b2e8 fix(uplifts): attribute audit to requested work order
Use the operation work order when staging uplift audit logs so a dispatch linked through DispatchWorkOrders cannot write the event to its primary work order. Add coverage for the cross-work-order fallback case.
2026-09-22 21:29:35 -03:00
Alexandre Brandizzi
d282799127 Fix SH-387 uplift creation without primary dispatch 2026-09-22 16:44:31 -03:00
Adam Moussa
019eb86894
Merge branch 'main' into feat/ab/sh-288-event-notifications 2026-09-18 19:11:15 -04:00
Alexandre Brandizzi
e1ce3e439b
Merge pull request #149 from Sea-Haven-Industries/feat/ab/sh-292-notification-center
SH-292: Notification Center feed endpoint
2026-09-18 22:54:54 +00:00
Alexandre Brandizzi
0b3084a274
Merge pull request #155 from Sea-Haven-Industries/fix/ab/sh-379-manual-poc-override
Persist manual POC override with audit and site-follow (SH-379)
2026-09-18 22:54:51 +00:00
Alexandre Brandizzi
582af8fb2c fix(workorders): compare manual POC against the followed contact, not any site contact
The manual POC "follow the site" clear-rule compared the edit against every
live Site contact. A work order only ever displays one of them, so editing to
a different live contact (Site has Alice primary and Bob; WO shows Alice; edit
to Bob) matched, cleared the override, and left the row showing Alice with no
audit row written — the SH-379 symptom on a different input. A work order with
a linked WorkOrderContacts POC hit the same bug when the dispatcher typed the
Site's primary: the override cleared and the linked contact showed instead.

Compare the edit against the single contact the work order actually follows —
the linked WorkOrderContacts POC, or else the Site primary (ResolvePrimary) —
matching the board projection's override -> linked -> site precedence, and
store the override whenever the edit differs from it. The create path in
WorkOrderBoardCreateService had the same any-contact rule and gets the same
fix; a supplied PocContactId that is not a live Site contact leaves no follow
target, so the typed POC is stored.

Replaces MatchesAnySiteContact with Matches(name, phone, contact); comment and
PR-body wording updated to state the followed-contact rule. Adds tests for the
second-site-contact edit, the linked-contact-differs edit, and the
second-site-contact create case.
2026-09-18 18:56:29 -03:00
Alexandre Brandizzi
cbecc7b4ea fix(workorders): persist manual POC override with audit and site-follow (SH-379)
Editing a work order's POC never reached the backend: no update path wrote
PocName/PocPhone/PocNotes, so the optimistic UI edit was lost on refetch and
the completion freeze captured the Site contact instead of the manual value,
and nothing was audited.

- Add tenant-scoped PATCH api/workorders/{id}/poc via new WorkOrderPocService
  + WorkOrderPocDataService: persists the override, stages FieldChanged audit
  entries (which also write field locks so sync never overwrites a manual POC),
  and enforces row-version concurrency and terminal-status read-only rules.
- Lock semantics (SH-190): a manual POC away from the Site's live contacts is
  stored WO-level; an edit equal to a live Site contact (or blanking name+phone)
  stores nothing so the WO follows the Site. PocCustomized exposes the state.
- Board projection, completion freeze and create now share one Site-contact
  fallback (first non-deleted contact by SiteContactOrder) so a never-overridden
  WO keeps following the Site, including at create when the wizard prefills it.
- Route contract baseline gains PATCH {id:int}/poc.
2026-09-18 14:30:54 -03:00
Alexandre Brandizzi
9784dcf895 Merge remote-tracking branch 'origin/feat/ab/sh-292-notification-center' into feat/ab/sh-288-event-notifications 2026-09-18 13:20:22 -03:00
Alexandre Brandizzi
e668e13912 feat(notifications): feed assignments, comments, mentions and uplift decisions to the user they concern
Adds the personal producers behind GET /api/notifications without changing its shape:
new assignments (SH-288), unanswered comments on work the user takes part in (SH-289),
@mentions, and decisions on uplifts the user requested (SH-215).
2026-09-18 13:15:33 -03:00
Alexandre Brandizzi
c9fa4a49af style(notifications): fix object initializer indentation in NotificationFeedService 2026-09-18 13:09:46 -03:00
Alexandre Brandizzi
aad3facaf1 fix(notifications): ignore soft-deleted dispatches and cap conflicts by recency
No Vendor treated any non-terminal dispatch as an assigned vendor without
checking IsDeleted, so a soft-deleted dispatch hid the work order from both
No Vendor and Vendor Conflict (the conflict query already drops deleted
dispatches). GetNoVendorAsync and the vendor-reminder assigned-work-order rule
now skip soft-deleted dispatches, keeping the asserted parity between the feed
and the reminders.

Vendor Conflict applied the section cap in vendor-sweep order, so when overlaps
exceeded the limit newer conflicts could be dropped while Count still counted
every work order. VendorConflictsAsync now orders pairs by recency before the
cap, matching the other per-work-order sections.
2026-09-18 12:59:56 -03:00
Alexandre Brandizzi
fa979605b4 feat(uplifts): expose dispatcher, technician and schedule on queue read (SH-209)
The uplift detail modal needs the work order's assigned dispatcher, the
requesting vendor's technician and the scheduled date. They now resolve
from the same effective work order and vendor as the existing queue row,
so the modal no longer depends on a separate work-order fetch that
account-scoped staff cannot read.
2026-09-18 12:49:25 -03:00
Alexandre Brandizzi
da0b29f769 feat(notifications): serve the Notification Center feed grouped by reason
Adds GET /api/notifications, a per-user read model derived from live
work-order state: Unassigned (grouped, High), No Vendor and Aveta Missing
(per work order, Medium) and Vendor Conflict, account-scoped from claims
and ordered by section severity with a fixed reason tie-break.
2026-09-18 12:40:37 -03:00
Alexandre Brandizzi
8a4de283dc Merge remote-tracking branch 'origin/dev' into feat/ab/sh-326-team-member
# Conflicts:
#	Api.SeaHavenIndustries.Tests/TeamMemberServiceTests.cs
#	SeaHaven.DataServices/Implementation/TeamPermissionOverrideDataService.cs
2026-09-17 14:06:12 -03:00
1a290ea2f7
Merge remote-tracking branch 'origin/dev' into HEAD 2026-09-17 12:50:09 -04:00
Alexandre Brandizzi
bc88ef0577 Merge remote-tracking branch 'origin/dev' into feat/ab/sh-326-team-member 2026-09-17 13:49:21 -03:00
Adam Moussa
1f905fc7dd
Merge branch 'dev' into feat/ab/sh-329-account-owner 2026-09-17 12:36:26 -04:00
Alexandre Brandizzi
679822733a
Merge branch 'dev' into feat/ab/sh-210-uplift-decisions 2026-09-17 12:44:12 -03:00
Alexandre Brandizzi
f4860a3dd9
Merge branch 'dev' into feat/ab/sh-348-region-filter 2026-09-17 12:36:15 -03:00
Adam Moussa
ef371b5917
Merge branch 'dev' into feat/ab/sh-210-uplift-decisions 2026-09-17 11:35:00 -04:00
Alexandre Brandizzi
1eadb82f28
Merge branch 'dev' into feat/ab/sh-210-uplift-decisions 2026-09-17 12:30:20 -03:00
Alexandre Brandizzi
ba8907fad0 fix(team-members): keep full-name round-trip stable on update
Storing the submitted full name in FirstName while leaving a seeded
LastName intact made an unchanged save project a duplicated name
(e.g. "Legacy Manager Manager"). Leave FirstName/LastName untouched when
the submitted name already matches the stored first+last projection, and
otherwise split the submitted name across FirstName/LastName so renames
round-trip cleanly.
2026-09-17 04:22:02 -03:00
Alexandre Brandizzi
564bd70301 fix(dashboard): scope Trend by picker and admit Scheduler to dispatcher picker
ResolveDispatcherScope now admits the Scheduler role, which owns the
viewAllDispatchersOnDashboard permission, so it can load Stats, Workload,
Performance, Regions and Trend instead of being denied.

GetTrendAsync now resolves scope via the shared ResolveDispatcherScope so a
picker DispatcherId selection scopes Trend consistently with the other
endpoints and unauthorized roles fail closed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-09-17 03:37:36 -03:00
Alexandre Brandizzi
5c93e4ecec Merge remote-tracking branch 'origin/dev' into feat/ab/sh-348-region-filter
# Conflicts:
#	SeaHaven.Services/Helpers/DashboardRegions.cs
2026-09-17 02:20:44 -03:00
Alexandre Brandizzi
f564e1b112 Merge remote-tracking branch 'origin/dev' into feat/ab/sh-347-dashboard-contract
# Conflicts:
#	Api.SeaHavenIndustries.Tests/DashboardServiceTests.cs
2026-09-17 02:18:22 -03:00
Alexandre Brandizzi
daf3ed9210 fix(team-members): map duplicate-email race to conflict error (SH-325)
CreateAsync checks FindByEmailAsync and then inserts, so two concurrent
creates with the same email can both pass the check and hit the unique
user-name index. That DbUpdateException was unhandled and surfaced as a
500. Catch it at the CreateAsync call and return the existing
"Email is already in use." message, matching the check-then-insert
converge pattern already used by SetOverrideCoreAsync.
2026-09-17 01:40:40 -03:00
Adam Moussa
7d728d9101
Merge branch 'dev' into feat/ab/sh-187-service-picker 2026-09-17 00:20:59 -04:00
Alexandre Brandizzi
2e983b1f6a
Merge branch 'dev' into feat/ab/sh-303-services-registry 2026-09-17 01:12:07 -03:00
Alexandre Brandizzi
bd98ea5629 merge: carry approval queue contract fields into decisions 2026-09-16 22:32:35 -03:00
Alexandre Brandizzi
e0e45d5ed3 feat(uplifts): expose approval queue contract fields (SH-208) 2026-09-16 22:32:23 -03:00
Alexandre Brandizzi
65b04687bc fix(work-orders): honor edited service labels 2026-09-16 22:30:32 -03:00