mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
* feat(vendors): add company roster management * fix(security): remove request-controlled write guards * fix(vendors): synchronize roster company fields * fix(vendors): source facets from companies
355 lines
14 KiB
C#
355 lines
14 KiB
C#
using Api.SeaHavenIndustries.DTOs;
|
|
using Api.SeaHavenIndustries.Helper;
|
|
using Data.SeaHavenIndustries;
|
|
using FluentValidation;
|
|
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.Extensions.Logging;
|
|
using SeaHaven.Services.Interfaces;
|
|
using SeaHaven.Services.DTOs;
|
|
using System.Security.Claims;
|
|
|
|
namespace Api.SeaHavenIndustries.Controllers
|
|
{
|
|
[Authorize]
|
|
[ApiController]
|
|
[Route("api/[controller]")]
|
|
[Route("api/vendors")]
|
|
public class VendorController : Controller
|
|
{
|
|
private readonly IVendorService _vendorService;
|
|
private readonly ILogger<VendorController> _logger;
|
|
|
|
public VendorController(IVendorService vendorService, ILogger<VendorController> logger)
|
|
{
|
|
_vendorService = vendorService;
|
|
_logger = logger;
|
|
}
|
|
|
|
[HttpGet("GetVendorList")]
|
|
public async Task<IActionResult> GetVendorList(
|
|
string? search = "",
|
|
int page = 1,
|
|
int pageSize = 10,
|
|
bool? isActive = true,
|
|
[FromQuery] string[]? companies = null,
|
|
[FromQuery] string[]? trades = null,
|
|
[FromQuery] string[]? locations = null,
|
|
[FromQuery] string[]? jobBuckets = null,
|
|
CancellationToken cancellationToken = default)
|
|
{
|
|
var pagedResult = await _vendorService.GetVendorDirectoryPagedAsync(
|
|
page,
|
|
pageSize,
|
|
search,
|
|
isActive,
|
|
companies,
|
|
trades,
|
|
locations,
|
|
jobBuckets,
|
|
cancellationToken);
|
|
|
|
var data = pagedResult.Items.Select(v => new
|
|
{
|
|
v.Id,
|
|
CompanyName = v.CompanyName,
|
|
v.CompanyId,
|
|
v.ContactName,
|
|
v.Email,
|
|
v.Phone,
|
|
v.CompanyPhone,
|
|
v.PreferredContact,
|
|
v.Address,
|
|
v.City,
|
|
v.State,
|
|
Zip = v.Zipcode,
|
|
v.TradeSpecialties,
|
|
v.GoogleMapsUrl,
|
|
v.Notes,
|
|
v.IsActive,
|
|
v.TotalJobs
|
|
});
|
|
|
|
return Ok(new Pagination_DTO
|
|
{
|
|
Data = data,
|
|
PageNumber = page,
|
|
PageSize = pageSize,
|
|
TotalCount = pagedResult.TotalCount,
|
|
TotalPages = (int)Math.Ceiling(pagedResult.TotalCount / (double)pageSize)
|
|
});
|
|
}
|
|
|
|
[HttpGet("{id}")]
|
|
[HttpGet("GetById")]
|
|
public async Task<IActionResult> GetVendorById([FromRoute] int? id, [FromQuery(Name = "id")] int? queryId)
|
|
{
|
|
var vendorId = id ?? queryId;
|
|
if (vendorId == null)
|
|
return BadRequest(new Response { Status = "Error", Message = "Id is required" });
|
|
|
|
var vendor = await _vendorService.GetVendorByIdAsync(vendorId.Value);
|
|
|
|
if (vendor == null)
|
|
return NotFound(new Response { Status = "Error", Message = "Vendor not found" });
|
|
|
|
return Ok(new
|
|
{
|
|
vendor.Id,
|
|
CompanyName = vendor.Name,
|
|
vendor.CompanyId,
|
|
vendor.ContactName,
|
|
vendor.Email,
|
|
vendor.Phone,
|
|
vendor.CompanyPhone,
|
|
vendor.PreferredContact,
|
|
vendor.Address,
|
|
vendor.City,
|
|
vendor.State,
|
|
Zip = vendor.Zipcode,
|
|
vendor.TradeSpecialties,
|
|
vendor.GoogleMapsUrl,
|
|
vendor.Notes,
|
|
vendor.IsActive,
|
|
vendor.TotalJobs
|
|
});
|
|
}
|
|
|
|
[HttpPost]
|
|
[HttpPost("Create")]
|
|
public async Task<IActionResult> Create([FromBody] Vendor_DTO model)
|
|
{
|
|
try
|
|
{
|
|
var createDto = new CreateVendorDTO
|
|
{
|
|
Name = model.CompanyName ?? throw new ArgumentException("CompanyName is required"),
|
|
CompanyId = model.CompanyId,
|
|
ContactName = model.ContactName,
|
|
Email = model.Email,
|
|
Phone = model.Phone,
|
|
CompanyPhone = model.CompanyPhone,
|
|
PreferredContact = model.PreferredContact,
|
|
Address = model.Address,
|
|
City = model.City,
|
|
State = model.State,
|
|
Zipcode = model.Zip,
|
|
TradeSpecialties = model.TradeSpecialties,
|
|
GoogleMapsUrl = model.GoogleMapsUrl,
|
|
Notes = model.Notes,
|
|
IsActive = model.IsActive ?? true
|
|
};
|
|
|
|
var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
if (userId == null)
|
|
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
|
|
|
|
await _vendorService.CreateVendorAsync(createDto, userId);
|
|
return Ok(new DataResponse { Message = "Vendor Created", Status = "200" });
|
|
}
|
|
catch (ValidationException vex)
|
|
{
|
|
var errors = string.Join(", ", vex.Errors.Select(e => e.ErrorMessage));
|
|
return BadRequest(new Response { Status = "Validation Error", Message = errors });
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
|
|
}
|
|
}
|
|
|
|
[HttpPut("{id}")]
|
|
[HttpPost("Update")]
|
|
public async Task<IActionResult> Update([FromRoute] int? id, [FromBody] EditVendor_DTO model)
|
|
{
|
|
try
|
|
{
|
|
// For named route, id comes from model
|
|
int vendorId = id ?? model.Id;
|
|
if (vendorId == 0)
|
|
return BadRequest(new Response { Status = "Error", Message = "Vendor Id is required" });
|
|
|
|
var updateDto = new UpdateVendorDTO
|
|
{
|
|
Name = model.CompanyName,
|
|
CompanyId = model.CompanyId,
|
|
ContactName = model.ContactName,
|
|
Email = model.Email,
|
|
Phone = model.Phone,
|
|
CompanyPhone = model.CompanyPhone,
|
|
PreferredContact = model.PreferredContact,
|
|
Address = model.Address,
|
|
City = model.City,
|
|
State = model.State,
|
|
Zipcode = model.Zip,
|
|
TradeSpecialties = model.TradeSpecialties,
|
|
GoogleMapsUrl = model.GoogleMapsUrl,
|
|
Notes = model.Notes,
|
|
IsActive = model.IsActive
|
|
};
|
|
|
|
var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
if (userId == null)
|
|
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
|
|
|
|
await _vendorService.UpdateVendorAsync(vendorId, updateDto, userId);
|
|
return Ok(new DataResponse { Message = "Vendor Updated", Status = "200" });
|
|
}
|
|
catch (ValidationException vex)
|
|
{
|
|
var errors = string.Join(", ", vex.Errors.Select(e => e.ErrorMessage));
|
|
return BadRequest(new Response { Status = "Validation Error", Message = errors });
|
|
}
|
|
catch (VendorDeactivationBlockedException dbex)
|
|
{
|
|
return Conflict(new
|
|
{
|
|
Status = "Conflict",
|
|
Message = _logger.Sanitize(dbex, "Vendor cannot be deactivated because it has open work orders"),
|
|
OpenWorkOrders = dbex.OpenWorkOrders
|
|
});
|
|
}
|
|
catch (InvalidOperationException)
|
|
{
|
|
return NotFound(new Response { Status = "Error", Message = "Vendor not found" });
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
|
|
}
|
|
}
|
|
|
|
[HttpDelete("{id}")]
|
|
[HttpPost("Delete")]
|
|
public async Task<IActionResult> Delete([FromRoute] int? id, [FromQuery(Name = "id")] int? queryId = null)
|
|
{
|
|
try
|
|
{
|
|
// Support both route parameter and query string
|
|
int vendorId = id ?? queryId ?? 0;
|
|
if (vendorId == 0)
|
|
return BadRequest(new Response { Status = "Error", Message = "Vendor Id is required" });
|
|
|
|
var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
if (userId == null)
|
|
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
|
|
|
|
await _vendorService.DeleteVendorAsync(vendorId, userId);
|
|
return Ok(new DataResponse { Message = "Vendor Deactivated", Status = "200" });
|
|
}
|
|
catch (VendorDeactivationBlockedException dbex)
|
|
{
|
|
return Conflict(new
|
|
{
|
|
Status = "Conflict",
|
|
Message = _logger.Sanitize(dbex, "Vendor cannot be deactivated because it has open work orders"),
|
|
OpenWorkOrders = dbex.OpenWorkOrders
|
|
});
|
|
}
|
|
catch (InvalidOperationException)
|
|
{
|
|
return NotFound(new Response { Status = "Error", Message = "Vendor not found" });
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
|
|
}
|
|
}
|
|
|
|
[HttpGet("{id:int}/deactivation-impact")]
|
|
public async Task<IActionResult> GetDeactivationImpact(int id)
|
|
{
|
|
try
|
|
{
|
|
var impact = await _vendorService.GetDeactivationImpactAsync(id);
|
|
return Ok(impact);
|
|
}
|
|
catch (InvalidOperationException)
|
|
{
|
|
return NotFound(new Response { Status = "Error", Message = "Vendor not found" });
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
|
|
}
|
|
}
|
|
|
|
[HttpPut("{id:int}/work-order-update")]
|
|
public async Task<IActionResult> UpdateFromWorkOrder(int id, [FromBody] WorkOrderVendorUpdate_DTO model)
|
|
{
|
|
try
|
|
{
|
|
if (model == null || model.WorkOrderId <= 0)
|
|
return BadRequest(new Response { Status = "Error", Message = "A valid workOrderId is required" });
|
|
|
|
var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
if (userId == null)
|
|
return Unauthorized(new Response { Status = "Error", Message = "User not authenticated" });
|
|
|
|
var dto = new WorkOrderVendorUpdateDTO
|
|
{
|
|
WorkOrderId = model.WorkOrderId,
|
|
ContactName = model.ContactName,
|
|
PreferredContact = model.PreferredContact,
|
|
Phone = model.Phone,
|
|
Email = model.Email,
|
|
Notes = model.Notes
|
|
};
|
|
|
|
var result = await _vendorService.UpdateVendorFromWorkOrderAsync(id, dto, userId);
|
|
return Ok(result);
|
|
}
|
|
catch (ValidationException vex)
|
|
{
|
|
var errors = string.Join(", ", vex.Errors.Select(e => e.ErrorMessage));
|
|
return BadRequest(new Response { Status = "Validation Error", Message = errors });
|
|
}
|
|
catch (InvalidOperationException)
|
|
{
|
|
return NotFound(new Response { Status = "Error", Message = "Vendor or work order link not found" });
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
|
|
}
|
|
}
|
|
|
|
[HttpGet("Dropdown")]
|
|
public async Task<IActionResult> GetDropdown([FromQuery] string? trade = null, [FromQuery] string? siteZip = null, CancellationToken cancellationToken = default)
|
|
{
|
|
var result = await _vendorService.GetDropdownAsync(trade, siteZip, cancellationToken);
|
|
return Ok(result);
|
|
}
|
|
|
|
[HttpGet("facets")]
|
|
public async Task<IActionResult> GetFacets([FromQuery] bool? isActive = null, CancellationToken cancellationToken = default)
|
|
{
|
|
var result = await _vendorService.GetFacetsAsync(isActive, cancellationToken);
|
|
return Ok(result);
|
|
}
|
|
|
|
[HttpGet("{id:int}/portal-token")]
|
|
public async Task<IActionResult> GetPortalToken(int id, CancellationToken cancellationToken = default)
|
|
{
|
|
var result = await _vendorService.GetPortalTokenAsync(id, cancellationToken);
|
|
if (result == null) return NotFound();
|
|
return Ok(result);
|
|
}
|
|
|
|
[HttpPost("{id:int}/portal-token/rotate")]
|
|
public async Task<IActionResult> RotatePortalToken(int id, CancellationToken cancellationToken = default)
|
|
{
|
|
var result = await _vendorService.RotatePortalTokenAsync(id, cancellationToken);
|
|
if (result == null) return NotFound();
|
|
return Ok(result);
|
|
}
|
|
|
|
[HttpPost("{id:int}/portal-token/revoke")]
|
|
public async Task<IActionResult> RevokePortalToken(int id, CancellationToken cancellationToken = default)
|
|
{
|
|
var success = await _vendorService.RevokePortalTokenAsync(id, cancellationToken);
|
|
if (!success) return NotFound();
|
|
return Ok(new { revoked = true });
|
|
}
|
|
}
|
|
}
|