Commit graph

78 commits

Author SHA1 Message Date
Arthur Bassi
d75f78651b feat(work-orders): include unresolved prior-week rows on GET board 2026-09-02 09:49:56 -03:00
Arthur Bassi
03c069d10d fix(work-orders): detach shared dispatch on vendor fork
Keep same-vendor saves idempotent and drop stale DispatchWorkOrders so listing and uplift follow the new primary.
2026-09-01 09:42:41 -03:00
Arthur Bassi
ca0404272e fix(work-orders): accept linked primary dispatch on vendor board patch
Vendor PATCH treated a GET-echoed id as foreign when belong-check used only WorkOrderId.
2026-08-31 15:48:33 -03:00
Arthur Bassi
e3a2507908 fix(users): compose full Name on user list 2026-08-31 10:22:27 -03:00
Alexandre Brandizzi
b605d5be02
fix: return vendor duplicate name conflict (#92)
Some checks failed
Validate and deploy dev / Validate deployable source bundle (push) Has been cancelled
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Has been cancelled
2026-08-27 14:55:09 -03:00
Alexandre Brandizzi
31a4af7da3
fix: omit unmapped sites from work order options (#89)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
2026-08-26 16:39:25 -04:00
Arthur Bassi
2718fdd294 fix(locations): gate account assignment by scope and active accounts
Reject soft-deleted accounts and stop account-scoped callers from assigning or stealing locations across tenants.
2026-08-26 14:16:59 -03:00
Arthur Bassi
2e56ec7678 fix(work-orders): keep location account server-owned and forward create cancellation
Stop client writes from changing Locations.AccountId, make the SH-221 migration discoverable, and thread the board-create CancellationToken through lookup and persistence.
2026-08-26 10:00:02 -03:00
Arthur Bassi
61923b2a7d feat(work-orders): stamp board create account from location
Org-wide create no longer depends on customer name. POST /workorders/board requires locationId and stamps WorkOrder.AccountId from Location.AccountId.
2026-08-26 09:12:48 -03:00
Alexandre Brandizzi
5857f8483a
fix(vendors): complete directory contact fallbacks (#86)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
* fix(vendors): complete directory contact fallbacks

* fix(vendors): normalize location labels

* fix(vendors): keep company location authoritative
2026-08-25 19:33:47 -04:00
Arthur Bassi
14b85c64a8
Merge branch 'dev' into feat/sh-117-aveta-required 2026-08-25 17:19:30 -03:00
Arthur Bassi
7245897d56
Merge branch 'dev' into feat/sh-117-aveta-required 2026-08-25 12:12:07 -03:00
Arthur Bassi
12dc3d51d9
Merge branch 'dev' into feat/board-week-only-pagination 2026-08-25 12:01:19 -03:00
Arthur Bassi
04958e6121 fix(work-orders): keep GET /board to scheduled-in-week rows only (SH-165) 2026-08-24 18:29:18 -03:00
Arthur Bassi
15315edf08 feat(work-orders): persist avetaRequired on board create, patch, and search
Expose avetaRequired and originalDate on list rows so the frontend can round-trip the Aveta checkbox and Reschedule hover.
2026-08-24 15:14:31 -03:00
Alexandre Brandizzi
9c3da9b5e3 fix(vendors): keep location fallback atomic 2026-08-21 09:40:51 -03:00
Alexandre Brandizzi
d0a90483b3 fix(vendors): show canonical list contact data 2026-08-21 09:32:58 -03:00
Alexandre Brandizzi
ec9b36ce29
Merge branch 'dev' into feat/sh-250-roster-additive-patch 2026-08-19 10:27:57 -03:00
Alexandre Brandizzi
33d0b2cebf
Merge branch 'dev' into feat/sh-250-roster-additive-patch 2026-08-18 17:46:41 -03:00
Alexandre Brandizzi
5386d6129d
Merge branch 'dev' into feature/sh-196-wo-uplifts 2026-08-18 17:46:38 -03:00
Alexandre Brandizzi
9ef2512e14 fix(vendor-roster): conflict on colliding rename, reject no-op company update (SH-250)
Two review findings on the additive PATCH path:

- AddTechniciansAsync can rename via CompanyFields.Name and write NormalizedName
  against the unique index, but the save had no guard. A colliding rename
  surfaced as an unhandled 500 from the PATCH action instead of a stable client
  conflict. Pre-check the normalized name against other live companies and throw
  VendorRosterDuplicateNameException, with a scoped catch around the save for the
  race where a competing rename commits in between. The controller maps it to a
  409 alongside the existing concurrency conflict.
- Empty-payload validation only rejected a null CompanyFields, so an all-blank
  CompanyFields object was forwarded as a company update, bumping RowVersion and
  rewriting every technician's LastModificationTime without changing any company
  data. Blank fields now collapse to no company change, and a request with
  neither technicians nor a real company value fails validation.
2026-08-18 17:33:16 -03:00
Alexandre Brandizzi
11a355bb7a feat(vendor-roster): additive PATCH endpoint for technician adds (SH-250, SH-246)
PATCH /api/vendor-company-roster/{companyId} inserts the submitted
technicians and optionally updates company fields. Technicians absent
from the payload are never removed or deactivated, so the Add Vendor
flow can no longer soft-delete an existing roster via the full-snapshot
PUT. Stale rowVersion still 409s; unknown company 404s. POST (create)
and PUT (reconcile) behaviour is unchanged.
2026-08-18 12:14:12 -03:00
Alexandre Brandizzi
577b7add31 feat(vendors): server-owned canonical trades vocabulary for SH-249 2026-08-18 12:11:13 -03:00
arthur.bassi
aeface594a fix(work-orders): serialize uplift create and atomic cancel (SH-196) 2026-08-18 10:20:05 -03:00
Arthur Bassi
fa05b22df6 chore(work-orders): merge SH-121 facets and keep SH-184 IsAddOn migration 2026-08-17 10:28:03 -03:00
arthur.bassi
4c15669aff fix(work-orders): enforce SH-196 cumulative allowance and one pending per WO
Auto-approval now uses the WO-scoped $500/$5,000 Emergency cap instead of dispatch NTE, rejects a second open request across dispatches, and cancelling a WO withdraws pending uplifts with audit.
2026-08-14 10:36:35 -03:00
Arthur Bassi
17c2e968cd feat(work-orders): board search facets for SH-121/SH-196 2026-08-13 16:34:21 -03:00
arthur.bassi
b81cfbb005 feat(work-orders): WO-scoped uplift endpoints and board summary (SH-196)
Expose workorders/{id}/uplifts list/create/cancel/revoke for the SH-196 dialog, aggregate upliftSummary on board rows, and add service/controller regression tests.
2026-08-13 14:49:56 -03:00
Arthur Bassi
05dd262e80 fix(work-orders): derive Past Due from DueDate instead of ScheduledDate
Past Due must track the deadline (Due Date), not Schedule On. Keep dueDate and scheduledDate PATCH mutations independent so rescheduling alone does not clear Past Due.
2026-08-13 13:28:25 -03:00
Arthur Bassi
aaeeb90f1a feat(work-orders): expose pendingUpliftCount on board rows (SH-188)
Aggregate Pending uplift requests across all dispatches tied to a work
order so the board/search/detail contract can drive the Completed gate.
2026-08-12 09:43:10 -03:00
Arthur Bassi
afcb4fde8d Merge branch 'dev' into feature/wo-board-completed-date-media 2026-08-11 15:20:17 -03:00
Arthur Bassi
de0f6da8fb fix(work-orders): scope legacy GET GetComments by account [SH-221]
Pass ClaimsPrincipal into GetCommentsAsync and filter via
GetAllForAccountAsync so account-scoped callers cannot enumerate
cross-tenant comments. ADR + cross-account tests updated.
2026-08-11 15:18:29 -03:00
Arthur Bassi
3c090e2757 fix(work-orders): scope comments and completion-doc by account [SH-221]
Close the remaining SH-221 bypass: board/legacy comments and completion-doc now enforce server-derived account scope, authorize before blob storage, and cover cross-account regressions.
2026-08-11 14:52:02 -03:00
Arthur Bassi
62a4828e2f fix(work-orders): scope legacy list/detail GETs by account [SH-221]
Close the remaining SH-221 read gap so Getworkorders, filtered lists, and GetWorkorderById enforce the same server-derived account boundary as board/media.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 11:57:37 -03:00
Arthur Bassi
1edcf479ae fix(work-orders): apply account scope across create and reads [SH-221]
Stamp WorkOrder.AccountId on all create paths and filter board/list/search/detail by server-derived account claims so scoped callers cannot cross accounts.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 10:45:37 -03:00
Alexandre Brandizzi
24283b320a feat(uplifts): complete SH-101 approval lifecycle 2026-08-11 08:58:19 -03:00
Arthur Bassi
ea2dedf579 !fix(work-orders): fail-closed media account scope with org_scope claim [SH-221] 2026-08-06 10:26:04 -03:00
Arthur Bassi
fdc315d8fe !feat(work-orders): enforce media account scope and AddMedia freshness [SH-221] 2026-08-06 09:47:34 -03:00
Arthur Bassi
6b18327d6b fix(work-orders): authorize GET media and forward cancellation
Enforce claims-derived read scope on media list and thread CancellationToken through detail data reads so HTTP cancel stops EF work.
2026-08-04 14:14:37 -03:00
Arthur Bassi
899da0eb4f fix(work-orders): enforce media auth and base scope on mutations
Require an authenticated ClaimsPrincipal at service entry and filter
tracked work orders with board base scope so deleted/template rows
surface as NotFound without disclosure.
2026-08-04 11:08:18 -03:00
Arthur Bassi
2ec85d1193 fix(work-orders): harden media upload contract for review blockers
Enforce MIME/extension/magic-byte validation, auth and workOrderVersion concurrency, audit on category changes, and validate-before-store with blob compensate.
2026-08-04 11:08:18 -03:00
Alexandre Brandizzi
669e9b2932
feat(vendors): add company roster management (SH-198) (#48)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
* feat(vendors): add company roster management

* fix(security): remove request-controlled write guards

* fix(vendors): synchronize roster company fields

* fix(vendors): source facets from companies
2026-08-03 17:53:24 -03:00
Alexandre Brandizzi
36d0a638a2 fix(vendors): return completion documents in portal detail 2026-07-28 14:19:15 -03:00
Alexandre Brandizzi
f701899a83 fix(work-orders): satisfy producer contract review 2026-07-27 16:33:06 -03:00
Alexandre Brandizzi
27bf81b7f8 fix(work-orders): address procurement review findings 2026-07-27 14:40:17 -03:00
Alexandre Brandizzi
e3c37e54b4 feat: complete SH-133 procurement reconciliation 2026-07-24 22:13:25 -03:00
Alexandre Brandizzi
bdffe77e42 feat: ingest signed procurement work-order webhooks 2026-07-24 21:03:50 -03:00
Arthur Bassi
620a36af54
feat(work-orders): enrich board search overdue filters and 0-based paging (#23)
* feat(work-orders): enrich board search overdue filters and 0-based paging

* fix(work-orders): align stacked services with CI build

* fix(tests): pass userDataService in comment service unit test

* fix(work-orders): use dedicated overdue query flag

Stop treating WorkOrderType.Other as an overdue sentinel. Board and advanced search now accept overdue=true while types=Other filters real Other rows; combining both uses OR.

* test(work-orders): cover overdue date/status boundary and Other type-filter

Lock the PR #23 overdue regression boundary through the public advanced
search service. Prove overdue filtering is driven by past-due date plus
non-terminal status, not by the WorkOrderType.Other sentinel:
- Other + future/not-completed excluded from overdue
- past-due + Scheduled included; past-due + Completed/Canceled excluded
- types=[PM, Other] keeps real Other rows and does not pull past-due rows
- assert 0-based paging (Page=0) is preserved alongside overdue/type filters

---------

Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-07-24 21:12:03 +00:00
Alexandre Brandizzi
7d245eb717
refactor: enforce backend boundaries and optimize dispatch (#30)
* refactor(api): enforce service and data-service boundaries

* refactor(api): complete feature service boundaries

* refactor(identity): enforce service and data boundaries

* refactor(vendors): enforce service and data boundaries

* refactor(workorders): enforce service and data boundaries

* refactor(backend): enforce architecture and optimize dispatch

* style(backend): format changed architecture files

* fix(architecture): address backend review follow-ups

* fix(backend): sanitize exception disclosure in changed API endpoints

Replace raw exception-message disclosure (ex.Message) returned to API
callers with a stable sanitized public message plus correlated structured
internal logging, across the endpoints changed in this PR.

- Add SanitizedErrors helper: logs the original exception at Error with a
  generated correlation id and returns a stable public message referencing
  it so support can trace without exposing internals.
- Inject ILogger<T> into the 14 changed controllers and route every
  ex.Message/dbex.Message disclosure through the helper, preserving status
  codes, response shapes, and business data (e.g. OpenWorkOrders).
- Leave FluentValidation (vex.Errors) and existing fixed-message catches
  untouched; out-of-scope controllers (Account/Contact/Employee/Asset/
  PMSchedule) are unchanged.
- Add focused tests proving internal exception text is not returned and
  that Error logging carrying the original exception is invoked.

* fix(architecture): abstract job run state access

* style: format board update service

* test: use collection assertion idiom
2026-07-24 17:35:34 -03:00
Alexandre Brandizzi
e5cf4cec09 merge: integrate origin/dev into PR #22 flag-color base
Brings in dev's Phase 5 (PR #17) + vendor PRs (#25/#28/#29) atop the
Phase 6/7 + flagColor base (PR #22). Preserves dev Phase 1-5 behavior and
PR #22 Phase 6/7 + flagColor behavior.

Conflict resolutions (16 files):
- Migrations Phase4_SearchIndexes/.Designer + Phase5_DomainEvents/.Designer:
  take dev (Phase4 incl. SQL Server SiteCode/InternalWONumber index-compat
  shrink fix; Phase5 identical). ModelSnapshot union: Vendor CompanyId index
  + Phase7 ServiceNotes/ExternalWorkOrderId index.
- ApplicationDbContext: keep dev SiteCode/InternalWONumber MaxLength (Phase1-5
  + unguarded model test) + HEAD CompletionDocTemplate/ExternalWorkOrderId.
- WorkOrderAuditService: unify on dev async staging API; convert Phase6
  CompletionService 2 call sites to await StageFieldChangedAsync (drops
  HEAD sync duplicate; only callers, no test refs).
- Hosted services: take HEAD (retry-on-failure, coherent with Phase7
  WorkOrderJobRunStateAccessor/OpsHealth). Program.cs keeps dev vendor DI
  (ClamAV/VendorDocumentScanWorker/ArgumentExceptionFilter) + HEAD Phase7.
- WorkOrderController: keep HEAD Phase6/7 service params + dev doc comment.
- VendorController/WorkOrderBoardCreateService/QueryFilters/appsettings:
  union / dev-correct.
- WorkOrderBoardUpdateServiceTests: union of HEAD (Phase6/7+flagColor) and
  dev (Phase1-5) test methods.

Verified WorkOrderType.Other (enum 99) is a legit category, not an overdue
sentinel; overdue uses dedicated OperationalFlags.PastDue + IsPastDue, and
'Overdue' is rejected as a WorkOrderType (no PR #23 import needed).

Removed dev duplicate Api.Options.WorkOrderJobRunState (HEAD defines it in
Services.Implementation alongside the Accessor; Services cannot reference Api).
2026-07-24 14:20:16 -03:00