shoc-backend/SeaHaven.DataServices/Implementation/WorkOrderMediaDataService.cs
Arthur Bassi 2ec85d1193 fix(work-orders): harden media upload contract for review blockers
Enforce MIME/extension/magic-byte validation, auth and workOrderVersion concurrency, audit on category changes, and validate-before-store with blob compensate.
2026-08-04 11:08:18 -03:00

42 lines
1.8 KiB
C#

using Data.SeaHavenIndustries;
using Microsoft.EntityFrameworkCore;
using SeaHaven.DataServices.Interfaces;
namespace SeaHaven.DataServices.Implementation
{
public class WorkOrderMediaDataService : IWorkOrderMediaDataService
{
private readonly ApplicationDbContext _context;
public WorkOrderMediaDataService(ApplicationDbContext context)
{
_context = context;
}
public Task<WorkOrder?> GetTrackedWorkOrderAsync(int workOrderId, CancellationToken cancellationToken)
=> _context.workOrders.FirstOrDefaultAsync(w => w.Id == workOrderId, cancellationToken);
public Task<WorkOrderAttachments?> GetTrackedAttachmentAsync(int mediaId, int workOrderId, CancellationToken cancellationToken)
=> _context.workOrderAttachments.FirstOrDefaultAsync(
a => a.Id == mediaId && a.WorkorderId == workOrderId && a.IsDeleted != true,
cancellationToken);
public void TrackAttachment(WorkOrderAttachments attachment)
=> _context.workOrderAttachments.Add(attachment);
public void SetExpectedWorkOrderVersion(WorkOrder workOrder, byte[] version)
=> _context.Entry(workOrder).Property(w => w.RowVersion).OriginalValue = version;
public void MarkWorkOrderModified(WorkOrder workOrder)
{
// Force a WO update so the RowVersion concurrency token is enforced when only
// attachment rows change (category-only Extra mutations).
var entry = _context.Entry(workOrder);
if (entry.State == EntityState.Unchanged)
entry.Property(w => w.Attachments).IsModified = true;
}
public Task SaveAsync(CancellationToken cancellationToken)
=> _context.SaveChangesAsync(cancellationToken);
}
}