shoc-backend/SeaHaven.DataServices/Implementation/CommentDataService.cs
Arthur Bassi de0f6da8fb fix(work-orders): scope legacy GET GetComments by account [SH-221]
Pass ClaimsPrincipal into GetCommentsAsync and filter via
GetAllForAccountAsync so account-scoped callers cannot enumerate
cross-tenant comments. ADR + cross-account tests updated.
2026-08-11 15:18:29 -03:00

117 lines
4.3 KiB
C#

using Data.SeaHavenIndustries;
using Microsoft.EntityFrameworkCore;
using SeaHaven.DataServices.Helpers;
using SeaHaven.DataServices.Interfaces;
namespace SeaHaven.DataServices.Implementation
{
public class CommentDataService : ICommentDataService
{
private readonly ApplicationDbContext _context;
public CommentDataService(ApplicationDbContext context)
{
_context = context;
}
public async Task<Comments?> GetByIdAsync(int id)
{
return await _context.Comments.FindAsync(id);
}
public async Task<IEnumerable<Comments>> GetAllAsync()
{
return await _context.Comments
.Include(c => c.ApplicationUser)
.ToListAsync();
}
public async Task<IEnumerable<Comments>> GetAllForAccountAsync(int? accountId)
{
var workOrders = WorkOrderBoardQueryFilters.ApplyBaseScope(_context.workOrders.AsNoTracking());
if (accountId.HasValue)
workOrders = WorkOrderBoardQueryFilters.ApplyAccountScope(workOrders, accountId.Value);
return await (
from c in _context.Comments.AsNoTracking().Include(c => c.ApplicationUser)
join w in workOrders on c.WorkerOrderId equals w.Id
orderby c.CreatedDate
select c
).ToListAsync();
}
public async Task<IEnumerable<Comments>> GetByWorkOrderIdAsync(int workOrderId)
{
return await _context.Comments
.Where(c => c.WorkerOrderId == workOrderId)
.Include(c => c.ApplicationUser)
.OrderBy(c => c.CreatedDate)
.ToListAsync();
}
public async Task<IEnumerable<Comments>> GetByDispatchIdAsync(int dispatchId)
{
return await _context.Comments
.Where(c => c.DispatchId == dispatchId)
.Include(c => c.ApplicationUser)
.OrderBy(c => c.CreatedDate)
.ToListAsync();
}
public async Task<Comments> AddAsync(Comments comment)
{
comment.CreatedDate = DateTime.UtcNow;
await _context.Comments.AddAsync(comment);
await _context.SaveChangesAsync();
return comment;
}
public async Task UpdateAsync(Comments comment)
{
_context.Comments.Update(comment);
await _context.SaveChangesAsync();
}
public async Task DeleteAsync(int id)
{
var entity = await GetByIdAsync(id);
if (entity != null)
{
_context.Comments.Remove(entity);
await _context.SaveChangesAsync();
}
}
public async Task<bool> ExistsAsync(int id)
{
return await _context.Comments.AnyAsync(c => c.Id == id);
}
public async Task StageAsync(Comments comment, CancellationToken cancellationToken)
{
await _context.Comments.AddAsync(comment, cancellationToken);
}
public async Task<IReadOnlyList<PortalCommentData>> GetVendorViewableForDispatchAsync(int dispatchId, CancellationToken cancellationToken)
{
return await (from c in _context.Comments
where c.DispatchId == dispatchId
&& c.CommentType != "internal"
&& (c.IsDeleted == null || c.IsDeleted == false)
join u in _context.Users on c.UserId equals u.Id into users
from u in users.DefaultIfEmpty()
orderby c.CreatedDate
select new PortalCommentData
{
Id = c.Id,
Commenttext = c.Commenttext,
Commenter = c.Commenter,
CommentType = c.CommentType,
CreatedDate = c.CreatedDate,
UserId = c.UserId,
UserFirstName = u != null ? u.FirstName : null,
UserLastName = u != null ? u.LastName : null
}).ToListAsync(cancellationToken);
}
}
}