mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 14:13:12 +00:00
Pass ClaimsPrincipal into GetCommentsAsync and filter via GetAllForAccountAsync so account-scoped callers cannot enumerate cross-tenant comments. ADR + cross-account tests updated.
117 lines
4.3 KiB
C#
117 lines
4.3 KiB
C#
using Data.SeaHavenIndustries;
|
|
using Microsoft.EntityFrameworkCore;
|
|
using SeaHaven.DataServices.Helpers;
|
|
using SeaHaven.DataServices.Interfaces;
|
|
|
|
namespace SeaHaven.DataServices.Implementation
|
|
{
|
|
public class CommentDataService : ICommentDataService
|
|
{
|
|
private readonly ApplicationDbContext _context;
|
|
|
|
public CommentDataService(ApplicationDbContext context)
|
|
{
|
|
_context = context;
|
|
}
|
|
|
|
public async Task<Comments?> GetByIdAsync(int id)
|
|
{
|
|
return await _context.Comments.FindAsync(id);
|
|
}
|
|
|
|
public async Task<IEnumerable<Comments>> GetAllAsync()
|
|
{
|
|
return await _context.Comments
|
|
.Include(c => c.ApplicationUser)
|
|
.ToListAsync();
|
|
}
|
|
|
|
public async Task<IEnumerable<Comments>> GetAllForAccountAsync(int? accountId)
|
|
{
|
|
var workOrders = WorkOrderBoardQueryFilters.ApplyBaseScope(_context.workOrders.AsNoTracking());
|
|
if (accountId.HasValue)
|
|
workOrders = WorkOrderBoardQueryFilters.ApplyAccountScope(workOrders, accountId.Value);
|
|
|
|
return await (
|
|
from c in _context.Comments.AsNoTracking().Include(c => c.ApplicationUser)
|
|
join w in workOrders on c.WorkerOrderId equals w.Id
|
|
orderby c.CreatedDate
|
|
select c
|
|
).ToListAsync();
|
|
}
|
|
|
|
public async Task<IEnumerable<Comments>> GetByWorkOrderIdAsync(int workOrderId)
|
|
{
|
|
return await _context.Comments
|
|
.Where(c => c.WorkerOrderId == workOrderId)
|
|
.Include(c => c.ApplicationUser)
|
|
.OrderBy(c => c.CreatedDate)
|
|
.ToListAsync();
|
|
}
|
|
|
|
public async Task<IEnumerable<Comments>> GetByDispatchIdAsync(int dispatchId)
|
|
{
|
|
return await _context.Comments
|
|
.Where(c => c.DispatchId == dispatchId)
|
|
.Include(c => c.ApplicationUser)
|
|
.OrderBy(c => c.CreatedDate)
|
|
.ToListAsync();
|
|
}
|
|
|
|
public async Task<Comments> AddAsync(Comments comment)
|
|
{
|
|
comment.CreatedDate = DateTime.UtcNow;
|
|
await _context.Comments.AddAsync(comment);
|
|
await _context.SaveChangesAsync();
|
|
return comment;
|
|
}
|
|
|
|
public async Task UpdateAsync(Comments comment)
|
|
{
|
|
_context.Comments.Update(comment);
|
|
await _context.SaveChangesAsync();
|
|
}
|
|
|
|
public async Task DeleteAsync(int id)
|
|
{
|
|
var entity = await GetByIdAsync(id);
|
|
if (entity != null)
|
|
{
|
|
_context.Comments.Remove(entity);
|
|
await _context.SaveChangesAsync();
|
|
}
|
|
}
|
|
|
|
public async Task<bool> ExistsAsync(int id)
|
|
{
|
|
return await _context.Comments.AnyAsync(c => c.Id == id);
|
|
}
|
|
|
|
public async Task StageAsync(Comments comment, CancellationToken cancellationToken)
|
|
{
|
|
await _context.Comments.AddAsync(comment, cancellationToken);
|
|
}
|
|
|
|
public async Task<IReadOnlyList<PortalCommentData>> GetVendorViewableForDispatchAsync(int dispatchId, CancellationToken cancellationToken)
|
|
{
|
|
return await (from c in _context.Comments
|
|
where c.DispatchId == dispatchId
|
|
&& c.CommentType != "internal"
|
|
&& (c.IsDeleted == null || c.IsDeleted == false)
|
|
join u in _context.Users on c.UserId equals u.Id into users
|
|
from u in users.DefaultIfEmpty()
|
|
orderby c.CreatedDate
|
|
select new PortalCommentData
|
|
{
|
|
Id = c.Id,
|
|
Commenttext = c.Commenttext,
|
|
Commenter = c.Commenter,
|
|
CommentType = c.CommentType,
|
|
CreatedDate = c.CreatedDate,
|
|
UserId = c.UserId,
|
|
UserFirstName = u != null ? u.FirstName : null,
|
|
UserLastName = u != null ? u.LastName : null
|
|
}).ToListAsync(cancellationToken);
|
|
}
|
|
}
|
|
}
|