mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 15:23:12 +00:00
Pass ClaimsPrincipal into GetCommentsAsync and filter via GetAllForAccountAsync so account-scoped callers cannot enumerate cross-tenant comments. ADR + cross-account tests updated.
23 lines
1 KiB
C#
23 lines
1 KiB
C#
using Data.SeaHavenIndustries;
|
|
|
|
namespace SeaHaven.DataServices.Interfaces
|
|
{
|
|
public interface ICommentDataService
|
|
{
|
|
Task<Comments?> GetByIdAsync(int id);
|
|
Task<IEnumerable<Comments>> GetAllAsync();
|
|
/// <summary>
|
|
/// Comments linked to non-deleted, non-template work orders.
|
|
/// When <paramref name="accountId"/> is set, only that account's WOs; null = org-wide.
|
|
/// </summary>
|
|
Task<IEnumerable<Comments>> GetAllForAccountAsync(int? accountId);
|
|
Task<IEnumerable<Comments>> GetByWorkOrderIdAsync(int workOrderId);
|
|
Task<IEnumerable<Comments>> GetByDispatchIdAsync(int dispatchId);
|
|
Task<Comments> AddAsync(Comments comment);
|
|
Task UpdateAsync(Comments comment);
|
|
Task DeleteAsync(int id);
|
|
Task<bool> ExistsAsync(int id);
|
|
Task StageAsync(Comments comment, CancellationToken cancellationToken);
|
|
Task<IReadOnlyList<PortalCommentData>> GetVendorViewableForDispatchAsync(int dispatchId, CancellationToken cancellationToken);
|
|
}
|
|
}
|