mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 09:33:13 +00:00
Stamp WorkOrder.AccountId on all create paths and filter board/list/search/detail by server-derived account claims so scoped callers cannot cross accounts. Co-authored-by: Cursor <cursoragent@cursor.com>
59 lines
2.6 KiB
C#
59 lines
2.6 KiB
C#
using System.Security.Claims;
|
|
using Data.SeaHavenIndustries.Enums;
|
|
using SeaHaven.DataServices.Interfaces;
|
|
using SeaHaven.Services.DTOs;
|
|
using SeaHaven.Services.Exceptions;
|
|
using SeaHaven.Services.Helpers;
|
|
using SeaHaven.Services.Interfaces;
|
|
|
|
namespace SeaHaven.Services.Implementation
|
|
{
|
|
public class WorkOrderBoardCancelService : IWorkOrderBoardCancelService
|
|
{
|
|
private readonly IWorkOrderBoardMutationDataService _mutationData;
|
|
private readonly IWorkOrderBoardService _boardService;
|
|
private readonly IWorkOrderAuditService _auditService;
|
|
|
|
public WorkOrderBoardCancelService(
|
|
IWorkOrderBoardMutationDataService mutationData,
|
|
IWorkOrderBoardService boardService,
|
|
IWorkOrderAuditService auditService)
|
|
{
|
|
_mutationData = mutationData;
|
|
_boardService = boardService;
|
|
_auditService = auditService;
|
|
}
|
|
|
|
public async Task<WorkOrderBoardRowDto> CancelAsync(
|
|
int workOrderId,
|
|
ClaimsPrincipal user,
|
|
string? actorId)
|
|
{
|
|
var workOrder = await _mutationData.GetTrackedWorkOrderAsync(workOrderId, CancellationToken.None);
|
|
|
|
if (workOrder == null)
|
|
throw new WorkOrderBoardValidationException("NotFound", "Work order not found.");
|
|
|
|
if (workOrder.LifecycleStatus == LifecycleStatus.Canceled)
|
|
{
|
|
var existing = await _boardService.GetBoardRowAsync(workOrderId, user);
|
|
return existing ?? throw new WorkOrderBoardValidationException("NotFound", "Work order not found.");
|
|
}
|
|
|
|
if (workOrder.LifecycleStatus == LifecycleStatus.Completed)
|
|
throw new WorkOrderBoardValidationException("CancelNotAllowed", "Work order cannot be canceled in its current status.");
|
|
|
|
var oldStatus = workOrder.LifecycleStatus?.ToString() ?? workOrder.Status ?? "";
|
|
workOrder.LifecycleStatus = LifecycleStatus.Canceled;
|
|
workOrder.Status = WorkOrderDerivedFields.GetLifecycleStatusLabel(LifecycleStatus.Canceled);
|
|
if (workOrder.LegacyStatus == null && workOrder.Status != null)
|
|
workOrder.LegacyStatus = workOrder.Status;
|
|
|
|
await _auditService.StageStatusChangedAsync(workOrderId, oldStatus, LifecycleStatus.Canceled.ToString(), actorId);
|
|
await _mutationData.SaveAsync(CancellationToken.None);
|
|
|
|
var row = await _boardService.GetBoardRowAsync(workOrderId, user);
|
|
return row ?? throw new WorkOrderBoardValidationException("NotFound", "Work order not found.");
|
|
}
|
|
}
|
|
}
|