shoc-backend/SeaHaven.DataServices/Interfaces/ICommentDataService.cs
Arthur Bassi de0f6da8fb fix(work-orders): scope legacy GET GetComments by account [SH-221]
Pass ClaimsPrincipal into GetCommentsAsync and filter via
GetAllForAccountAsync so account-scoped callers cannot enumerate
cross-tenant comments. ADR + cross-account tests updated.
2026-08-11 15:18:29 -03:00

23 lines
1 KiB
C#

using Data.SeaHavenIndustries;
namespace SeaHaven.DataServices.Interfaces
{
public interface ICommentDataService
{
Task<Comments?> GetByIdAsync(int id);
Task<IEnumerable<Comments>> GetAllAsync();
/// <summary>
/// Comments linked to non-deleted, non-template work orders.
/// When <paramref name="accountId"/> is set, only that account's WOs; null = org-wide.
/// </summary>
Task<IEnumerable<Comments>> GetAllForAccountAsync(int? accountId);
Task<IEnumerable<Comments>> GetByWorkOrderIdAsync(int workOrderId);
Task<IEnumerable<Comments>> GetByDispatchIdAsync(int dispatchId);
Task<Comments> AddAsync(Comments comment);
Task UpdateAsync(Comments comment);
Task DeleteAsync(int id);
Task<bool> ExistsAsync(int id);
Task StageAsync(Comments comment, CancellationToken cancellationToken);
Task<IReadOnlyList<PortalCommentData>> GetVendorViewableForDispatchAsync(int dispatchId, CancellationToken cancellationToken);
}
}