shoc-backend/Api.SeaHavenIndustries/Controllers/VendorCompanyRosterController.cs
Alexandre Brandizzi 669e9b2932
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
feat(vendors): add company roster management (SH-198) (#48)
* feat(vendors): add company roster management

* fix(security): remove request-controlled write guards

* fix(vendors): synchronize roster company fields

* fix(vendors): source facets from companies
2026-08-03 17:53:24 -03:00

143 lines
5.5 KiB
C#

using Api.SeaHavenIndustries.Helper;
using Data.SeaHavenIndustries;
using FluentValidation;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using Microsoft.EntityFrameworkCore;
using Microsoft.Extensions.Logging;
using SeaHaven.DataServices.Models;
using SeaHaven.Services.DTOs;
using SeaHaven.Services.Interfaces;
using System.Security.Claims;
namespace Api.SeaHavenIndustries.Controllers
{
[Authorize]
[ApiController]
[Route("api/vendor-company-roster")]
public class VendorCompanyRosterController : Controller
{
private readonly IVendorCompanyRosterService _rosterService;
private readonly ILogger<VendorCompanyRosterController> _logger;
public VendorCompanyRosterController(
IVendorCompanyRosterService rosterService,
ILogger<VendorCompanyRosterController> logger)
{
_rosterService = rosterService;
_logger = logger;
}
[HttpGet]
public async Task<IActionResult> Get(
[FromQuery] int? vendorId,
[FromQuery] int? companyId,
CancellationToken cancellationToken)
{
var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (userId == null)
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
try
{
var roster = await _rosterService.GetRosterAsync(vendorId, companyId, userId, cancellationToken);
if (roster == null)
return NotFound(new Response { Status = "Error", Message = "Vendor roster not found" });
return Ok(roster);
}
catch (ValidationException vex)
{
var errors = string.Join(", ", vex.Errors.Select(e => e.ErrorMessage));
return BadRequest(new Response { Status = "Validation Error", Message = errors });
}
catch (UnauthorizedAccessException)
{
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
}
catch (Exception ex)
{
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
}
}
[HttpPost]
public async Task<IActionResult> Create([FromBody] CreateVendorRosterDTO model, CancellationToken cancellationToken)
{
var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (userId == null)
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
try
{
var roster = await _rosterService.CreateRosterAsync(model, userId, cancellationToken);
return Ok(roster);
}
catch (ValidationException vex)
{
var errors = string.Join(", ", vex.Errors.Select(e => e.ErrorMessage));
return BadRequest(new Response { Status = "Validation Error", Message = errors });
}
catch (UnauthorizedAccessException)
{
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
}
catch (Exception ex)
{
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
}
}
[HttpPut("{companyId:int}")]
public async Task<IActionResult> Reconcile(
int companyId,
[FromBody] ReconcileVendorRosterDTO model,
CancellationToken cancellationToken)
{
var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (userId == null)
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
try
{
var roster = await _rosterService.ReconcileRosterAsync(companyId, model, userId, cancellationToken);
return Ok(roster);
}
catch (ValidationException vex)
{
var errors = string.Join(", ", vex.Errors.Select(e => e.ErrorMessage));
return BadRequest(new Response { Status = "Validation Error", Message = errors });
}
catch (UnauthorizedAccessException)
{
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
}
catch (KeyNotFoundException)
{
return NotFound(new Response { Status = "Error", Message = "Vendor company not found" });
}
catch (VendorRosterConflictException conflict)
{
return Conflict(new
{
Status = "Conflict",
Message = _logger.Sanitize(conflict, "Vendor roster changes conflict with open work orders"),
BlockedWorkOrders = conflict.BlockedWorkOrders
});
}
catch (DbUpdateConcurrencyException)
{
return Conflict(new
{
Status = "Conflict",
Message = "The vendor company was modified by another user. Refresh and retry.",
Code = 409
});
}
catch (Exception ex)
{
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
}
}
}
}