shoc-backend/SeaHaven.DataServices
Alexandre Brandizzi af441894d7 fix(permissions): clean up overrides on user delete and converge concurrent override writes (SH-328)
DeleteUserWithCascadeAsync never removed UserPermissionOverrides rows, and
the FK on UserId is Restrict. Once an override was saved for a member, the
admin hard-delete (DeleteUserAsync -> DeleteUserWithCascadeAsync) failed the
foreign key inside the transaction and the controller surfaced it as a 400,
so the user was never deleted. Add an explicit ExecuteDelete on
UserPermissionOverrides before the user is removed, matching how UserRoles is
already cleared in the same method (no schema change).

SetOverrideAsync was check-then-insert on the composite key with no
DbUpdateException handling, so two concurrent PUTs for the same
(UserId, PermissionKey) let the loser violate PK_UserPermissionOverrides and
return 500. Catch the conflict, detach the pending insert, and converge by
updating the persisted row to the caller's requested state.
2026-09-16 20:27:26 -03:00
..
DependencyInjection backend changes 2026-05-14 11:00:12 -05:00
Dto feat(permissions): expose team member permission overrides (SH-328) 2026-09-16 18:02:02 -03:00
Helpers SH-338: filter unscheduled work orders before pagination (#116) 2026-09-15 16:46:40 -03:00
Implementation fix(permissions): clean up overrides on user delete and converge concurrent override writes (SH-328) 2026-09-16 20:27:26 -03:00
Interfaces feat(permissions): expose team member permission overrides (SH-328) 2026-09-16 18:02:02 -03:00
Models feat(vendors): add admin-assigned vendor company Area 2026-09-16 11:34:45 -03:00
Properties feat(vendors): add directory filters and details API (#25) 2026-07-23 15:55:47 +00:00
SeaHaven.DataServices.csproj refactor 2026-04-28 18:55:14 -05:00