mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 08:23:12 +00:00
Require an authenticated ClaimsPrincipal at service entry and filter tracked work orders with board base scope so deleted/template rows surface as NotFound without disclosure.
45 lines
1.5 KiB
C#
45 lines
1.5 KiB
C#
using System.Security.Claims;
|
|
using Data.SeaHavenIndustries.Enums;
|
|
using SeaHaven.Services.DTOs;
|
|
|
|
namespace SeaHaven.Services.Interfaces
|
|
{
|
|
public interface IWorkOrderMediaService
|
|
{
|
|
Task<IReadOnlyList<WorkOrderMediaFileDto>?> GetMediaAsync(int workOrderId, CancellationToken cancellationToken = default);
|
|
|
|
/// <summary>
|
|
/// Authorizes the caller and validates the work order is mutable before any blob storage write.
|
|
/// </summary>
|
|
Task EnsureCanMutateMediaAsync(
|
|
int workOrderId,
|
|
ClaimsPrincipal user,
|
|
string? actorId,
|
|
CancellationToken cancellationToken = default);
|
|
|
|
Task<WorkOrderMediaFileDto> AddMediaAsync(
|
|
int workOrderId,
|
|
WorkOrderMediaCategory? category,
|
|
string fileUrl,
|
|
ClaimsPrincipal user,
|
|
string? actorId,
|
|
CancellationToken cancellationToken = default);
|
|
|
|
Task<WorkOrderMediaFileDto> UpdateMediaCategoryAsync(
|
|
int workOrderId,
|
|
int mediaId,
|
|
WorkOrderMediaCategory category,
|
|
string? workOrderVersion,
|
|
ClaimsPrincipal user,
|
|
string? actorId,
|
|
CancellationToken cancellationToken = default);
|
|
|
|
Task DeleteMediaAsync(
|
|
int workOrderId,
|
|
int mediaId,
|
|
string? workOrderVersion,
|
|
ClaimsPrincipal user,
|
|
string? actorId,
|
|
CancellationToken cancellationToken = default);
|
|
}
|
|
}
|