mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 08:23:12 +00:00
Expose completedDate on PATCH /workorders/{id}/board so CompDoc can leave legacy EditWorkorder. Allow optional media category on upload, PATCH category afterward, and enforce JPG/PNG/MP4/MOV allowlist (SH-116).
51 lines
1.6 KiB
C#
51 lines
1.6 KiB
C#
using Microsoft.AspNetCore.Http;
|
|
|
|
namespace SeaHaven.Services.Helpers
|
|
{
|
|
/// <summary>SH-116 media type allowlist for board work-order uploads.</summary>
|
|
public static class WorkOrderMediaFileRules
|
|
{
|
|
private static readonly HashSet<string> AllowedContentTypes = new(StringComparer.OrdinalIgnoreCase)
|
|
{
|
|
"image/jpeg",
|
|
"image/png",
|
|
"video/mp4",
|
|
"video/quicktime"
|
|
};
|
|
|
|
private static readonly HashSet<string> AllowedExtensions = new(StringComparer.OrdinalIgnoreCase)
|
|
{
|
|
".jpg",
|
|
".jpeg",
|
|
".png",
|
|
".mp4",
|
|
".mov"
|
|
};
|
|
|
|
public static bool IsAllowed(IFormFile file)
|
|
{
|
|
if (file == null)
|
|
return false;
|
|
|
|
var contentTypeOk = !string.IsNullOrWhiteSpace(file.ContentType)
|
|
&& AllowedContentTypes.Contains(file.ContentType.Trim());
|
|
|
|
var extension = Path.GetExtension(file.FileName ?? "");
|
|
var extensionOk = !string.IsNullOrWhiteSpace(extension)
|
|
&& AllowedExtensions.Contains(extension);
|
|
|
|
// Accept when either MIME or extension matches the advertised contract (JPG/PNG/MP4/MOV).
|
|
return contentTypeOk || extensionOk;
|
|
}
|
|
|
|
public static void EnsureAllowed(IFormFile file)
|
|
{
|
|
if (!IsAllowed(file))
|
|
{
|
|
throw new Exceptions.WorkOrderBoardValidationException(
|
|
"UnsupportedMediaType",
|
|
"Supported media types are JPG, PNG, MP4, and MOV.");
|
|
}
|
|
}
|
|
}
|
|
}
|