shoc-backend/SeaHaven.Services/Implementation/WorkOrderBoardCancelService.cs
Alexandre Brandizzi 2327097d5e fix(work-orders): symmetric NTE release, terminal guard, serialized cancel (SH-196)
Three contract gaps found reviewing the frontend consumer:

- Revoking an auto-approved uplift never restored the dispatch NTE. Create
  raises NTE for both auto-approved and approved requests, but revoke restored
  it only for Approved, so the allowance was freed while the NTE stayed raised
  and every create -> auto-approve -> revoke cycle compounded the inflation.
  Revoke now compensates for NoApprovalRequired symmetrically.
- Revoke and cancel had no work-order lifecycle check, so a direct API call
  could still mutate uplifts on a Completed or Canceled work order; the board
  dialog's read-only state is UX only. Both now reject terminal work orders in
  the service.
- WorkOrderBoardCancelService read the pending-uplift list outside any gate, so
  an in-flight create could commit after that read and leave a pending uplift on
  a Canceled work order. The cancel flow now runs inside the same per-work-order
  gate as create, so the pending read, withdrawal and status audit serialize
  against it.
2026-08-18 17:41:14 -03:00

76 lines
3.6 KiB
C#

using System.Security.Claims;
using Data.SeaHavenIndustries.Enums;
using SeaHaven.DataServices.Interfaces;
using SeaHaven.Services.DTOs;
using SeaHaven.Services.Exceptions;
using SeaHaven.Services.Helpers;
using SeaHaven.Services.Interfaces;
namespace SeaHaven.Services.Implementation
{
public class WorkOrderBoardCancelService : IWorkOrderBoardCancelService
{
private readonly IWorkOrderBoardMutationDataService _mutationData;
private readonly IWorkOrderBoardService _boardService;
private readonly IWorkOrderAuditService _auditService;
private readonly IWorkOrderUpliftService _upliftService;
private readonly IUpliftDataService _upliftData;
public WorkOrderBoardCancelService(
IWorkOrderBoardMutationDataService mutationData,
IWorkOrderBoardService boardService,
IWorkOrderAuditService auditService,
IWorkOrderUpliftService upliftService,
IUpliftDataService upliftData)
{
_mutationData = mutationData;
_boardService = boardService;
_auditService = auditService;
_upliftService = upliftService;
_upliftData = upliftData;
}
public async Task<WorkOrderBoardRowDto> CancelAsync(
int workOrderId,
ClaimsPrincipal user,
string? actorId)
{
// SH-196: run the whole cancel under the same per-work-order gate that uplift
// create uses. Previously the pending-uplift read happened outside any gate, so
// an in-flight create could commit after that read and leave a pending uplift on
// a Canceled work order, breaking "cancelling a WO with a pending uplift cancels
// that uplift in the same action".
await _upliftData.ExecuteWorkOrderMutationAsync(
workOrderId,
async ct =>
{
var workOrder = await _mutationData.GetTrackedWorkOrderAsync(workOrderId, ct);
if (workOrder == null)
throw new WorkOrderBoardValidationException("NotFound", "Work order not found.");
// Already canceled: nothing to mutate, the row is returned below.
if (workOrder.LifecycleStatus == LifecycleStatus.Canceled)
return false;
if (workOrder.LifecycleStatus == LifecycleStatus.Completed)
throw new WorkOrderBoardValidationException("CancelNotAllowed", "Work order cannot be canceled in its current status.");
var oldStatus = workOrder.LifecycleStatus?.ToString() ?? workOrder.Status ?? "";
workOrder.LifecycleStatus = LifecycleStatus.Canceled;
workOrder.Status = WorkOrderDerivedFields.GetLifecycleStatusLabel(LifecycleStatus.Canceled);
if (workOrder.LegacyStatus == null && workOrder.Status != null)
workOrder.LegacyStatus = workOrder.Status;
await _upliftService.WithdrawPendingForWorkOrderAsync(workOrderId, actorId, ct);
await _auditService.StageStatusChangedAsync(workOrderId, oldStatus, LifecycleStatus.Canceled.ToString(), actorId);
await _mutationData.SaveAsync(ct);
return true;
},
CancellationToken.None);
var row = await _boardService.GetBoardRowAsync(workOrderId, user);
return row ?? throw new WorkOrderBoardValidationException("NotFound", "Work order not found.");
}
}
}