mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 13:03:12 +00:00
Close the remaining SH-221 bypass: board/legacy comments and completion-doc now enforce server-derived account scope, authorize before blob storage, and cover cross-account regressions.
50 lines
2 KiB
C#
50 lines
2 KiB
C#
using Data.SeaHavenIndustries;
|
|
using Microsoft.EntityFrameworkCore;
|
|
using SeaHaven.DataServices.Helpers;
|
|
using SeaHaven.DataServices.Interfaces;
|
|
|
|
namespace SeaHaven.DataServices.Implementation
|
|
{
|
|
public class WorkOrderCompletionDataService : IWorkOrderCompletionDataService
|
|
{
|
|
private readonly ApplicationDbContext _context;
|
|
|
|
public WorkOrderCompletionDataService(ApplicationDbContext context)
|
|
{
|
|
_context = context;
|
|
}
|
|
|
|
public Task<WorkOrder?> GetWorkOrderForCompletionAuthAsync(
|
|
int workOrderId,
|
|
int? accountId,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
var query = WorkOrderBoardQueryFilters.ApplyBaseScope(_context.workOrders.AsNoTracking());
|
|
if (accountId.HasValue)
|
|
query = WorkOrderBoardQueryFilters.ApplyAccountScope(query, accountId.Value);
|
|
|
|
return query.FirstOrDefaultAsync(w => w.Id == workOrderId, cancellationToken);
|
|
}
|
|
|
|
public Task<WorkOrder?> GetTrackedWorkOrderAsync(
|
|
int workOrderId,
|
|
int? accountId,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
var query = WorkOrderBoardQueryFilters.ApplyBaseScope(_context.workOrders);
|
|
if (accountId.HasValue)
|
|
query = WorkOrderBoardQueryFilters.ApplyAccountScope(query, accountId.Value);
|
|
|
|
return query.FirstOrDefaultAsync(w => w.Id == workOrderId, cancellationToken);
|
|
}
|
|
|
|
public void SetExpectedWorkOrderVersion(WorkOrder workOrder, byte[] version)
|
|
=> _context.Entry(workOrder).Property(w => w.RowVersion).OriginalValue = version;
|
|
|
|
public Task<CompletionDocTemplate?> GetTrackedTemplateAsync(int id, CancellationToken cancellationToken)
|
|
=> _context.CompletionDocTemplates.FirstOrDefaultAsync(t => t.Id == id && t.IsDeleted != true, cancellationToken);
|
|
|
|
public Task SaveAsync(CancellationToken cancellationToken)
|
|
=> _context.SaveChangesAsync(cancellationToken);
|
|
}
|
|
}
|