shoc-backend/SeaHaven.Services
Alexandre Brandizzi fbee138dc8 fix(work-orders): resolve undetermined media MIME from the extension (SH-370)
The media allowlist refused any upload whose multipart part had an empty or
application/octet-stream Content-Type before looking at the extension or the
bytes. Browsers take that header from File.type, which mobile browsers leave
empty when the OS cannot classify a picked file, while the client-side gate
already accepts such files on extension alone. A real JPG/MP4/MOV could pass
the dialog and still be refused by the API.

Only an undetermined type now falls back to the extension. The resolved type
still goes through the SH-171 document/category rule, the extension pairing,
and the magic-byte signature check, so an octet-stream .pdf stays refused for
Completion, Before and After, and a declared type is never overridden.
2026-09-16 13:21:12 -03:00
..
Configuration feat(uplifts): complete SH-101 approval lifecycle 2026-08-11 08:58:19 -03:00
Constants fix(work-orders): satisfy producer contract review 2026-07-27 16:33:06 -03:00
DependencyInjection fix(work-orders): satisfy producer contract review 2026-07-27 16:33:06 -03:00
DTOs feat(locations): manage ordered site contacts 2026-09-15 19:03:54 -03:00
Exceptions feat(work-orders): isolate phase 2 inline edit with optimistic concurrency 2026-07-07 11:26:13 -03:00
Helpers fix(work-orders): resolve undetermined media MIME from the extension (SH-370) 2026-09-16 13:21:12 -03:00
Implementation feat(locations): manage ordered site contacts 2026-09-15 19:03:54 -03:00
Interfaces feat(locations): filter sites by state (#117) 2026-09-15 16:32:30 -03:00
Validation feat(locations): manage ordered site contacts 2026-09-15 19:03:54 -03:00
SeaHaven.Services.csproj refactor: enforce backend boundaries and optimize dispatch (#30) 2026-07-24 17:35:34 -03:00