Commit graph

11 commits

Author SHA1 Message Date
Alexandre Brandizzi
b9f9725c73 fix: recalculate add-on at reschedule time, not creation time
A reschedule moves the work order into its new week at the moment of the
reschedule, so Add-On now compares that moment with the new week's cutoff,
matching the prototype. Moves within the same week keep the current value.
Previously an older work order moved into a week already past its cutoff
stayed off because it was created before that cutoff (SH-412).
2026-10-01 16:10:19 -03:00
Alexandre Brandizzi
c02749a4ea fix: run work order edit reschedule under the mutation lock
UpdateWorkOrderAsync loaded the work order, applied the shared schedule
side effects (RescheduleCount, OriginalDate/OriginalWeek, lifecycle,
IsAddOn) and saved with no gate, transaction or row lock, so a
concurrent reschedule could interleave with the read-modify-write.

The read, the mutation, the save and the audit entry now run through
IWorkOrderDataService.ExecuteWorkOrderMutationAsync, which uses the
shared WorkOrderMutationLock: the per-work-order in-process gate, a
transaction, and an UPDLOCK on the work order row on SQL Server. A
reschedule committed by another holder of the lock is read before the
edit applies its own date and increments RescheduleCount.

Adds a regression test that holds the gate, commits a reschedule, and
asserts the edit waits and then builds on the committed schedule.
2026-10-01 00:19:37 -03:00
Alexandre Brandizzi
24436c9864 fix: apply shared schedule side effects on work order edit
Route edit-path ScheduledDate changes through WorkOrderBoardFieldMutations.ApplyScheduledDate so OriginalDate/OriginalWeek, RescheduleCount and lifecycle promotion match the board PATCH path, and audit those changes.
2026-10-01 00:10:43 -03:00
Alexandre Brandizzi
ac5550365f fix: recalculate add-on on work order reschedule 2026-09-30 23:58:20 -03:00
Arthur Bassi
de0f6da8fb fix(work-orders): scope legacy GET GetComments by account [SH-221]
Pass ClaimsPrincipal into GetCommentsAsync and filter via
GetAllForAccountAsync so account-scoped callers cannot enumerate
cross-tenant comments. ADR + cross-account tests updated.
2026-08-11 15:18:29 -03:00
Arthur Bassi
3c090e2757 fix(work-orders): scope comments and completion-doc by account [SH-221]
Close the remaining SH-221 bypass: board/legacy comments and completion-doc now enforce server-derived account scope, authorize before blob storage, and cover cross-account regressions.
2026-08-11 14:52:02 -03:00
Arthur Bassi
62a4828e2f fix(work-orders): scope legacy list/detail GETs by account [SH-221]
Close the remaining SH-221 read gap so Getworkorders, filtered lists, and GetWorkorderById enforce the same server-derived account boundary as board/media.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 11:57:37 -03:00
Arthur Bassi
1edcf479ae fix(work-orders): apply account scope across create and reads [SH-221]
Stamp WorkOrder.AccountId on all create paths and filter board/list/search/detail by server-derived account claims so scoped callers cannot cross accounts.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 10:45:37 -03:00
Alexandre Brandizzi
7d245eb717
refactor: enforce backend boundaries and optimize dispatch (#30)
* refactor(api): enforce service and data-service boundaries

* refactor(api): complete feature service boundaries

* refactor(identity): enforce service and data boundaries

* refactor(vendors): enforce service and data boundaries

* refactor(workorders): enforce service and data boundaries

* refactor(backend): enforce architecture and optimize dispatch

* style(backend): format changed architecture files

* fix(architecture): address backend review follow-ups

* fix(backend): sanitize exception disclosure in changed API endpoints

Replace raw exception-message disclosure (ex.Message) returned to API
callers with a stable sanitized public message plus correlated structured
internal logging, across the endpoints changed in this PR.

- Add SanitizedErrors helper: logs the original exception at Error with a
  generated correlation id and returns a stable public message referencing
  it so support can trace without exposing internals.
- Inject ILogger<T> into the 14 changed controllers and route every
  ex.Message/dbex.Message disclosure through the helper, preserving status
  codes, response shapes, and business data (e.g. OpenWorkOrders).
- Leave FluentValidation (vex.Errors) and existing fixed-message catches
  untouched; out-of-scope controllers (Account/Contact/Employee/Asset/
  PMSchedule) are unchanged.
- Add focused tests proving internal exception text is not returned and
  that Error logging carrying the original exception is invoked.

* fix(architecture): abstract job run state access

* style: format board update service

* test: use collection assertion idiom
2026-07-24 17:35:34 -03:00
npalOmega
59385cf5b1 backend changes 2026-05-14 11:00:12 -05:00
npalOmega
ac76b201de refactor 2026-04-28 18:55:14 -05:00