shoc-backend/SeaHaven.Services/Helpers/WorkOrderMediaFileRules.cs
Alexandre Brandizzi d073a503d1 feat(work-orders): board completedDate + media categorize contract
Expose completedDate on PATCH /workorders/{id}/board so CompDoc can leave legacy EditWorkorder. Allow optional media category on upload, PATCH category afterward, and enforce JPG/PNG/MP4/MOV allowlist (SH-116).
2026-08-04 11:08:18 -03:00

51 lines
1.6 KiB
C#

using Microsoft.AspNetCore.Http;
namespace SeaHaven.Services.Helpers
{
/// <summary>SH-116 media type allowlist for board work-order uploads.</summary>
public static class WorkOrderMediaFileRules
{
private static readonly HashSet<string> AllowedContentTypes = new(StringComparer.OrdinalIgnoreCase)
{
"image/jpeg",
"image/png",
"video/mp4",
"video/quicktime"
};
private static readonly HashSet<string> AllowedExtensions = new(StringComparer.OrdinalIgnoreCase)
{
".jpg",
".jpeg",
".png",
".mp4",
".mov"
};
public static bool IsAllowed(IFormFile file)
{
if (file == null)
return false;
var contentTypeOk = !string.IsNullOrWhiteSpace(file.ContentType)
&& AllowedContentTypes.Contains(file.ContentType.Trim());
var extension = Path.GetExtension(file.FileName ?? "");
var extensionOk = !string.IsNullOrWhiteSpace(extension)
&& AllowedExtensions.Contains(extension);
// Accept when either MIME or extension matches the advertised contract (JPG/PNG/MP4/MOV).
return contentTypeOk || extensionOk;
}
public static void EnsureAllowed(IFormFile file)
{
if (!IsAllowed(file))
{
throw new Exceptions.WorkOrderBoardValidationException(
"UnsupportedMediaType",
"Supported media types are JPG, PNG, MP4, and MOV.");
}
}
}
}