Commit graph

433 commits

Author SHA1 Message Date
Alexandre Brandizzi
11a753a2e9 docs(media): note the server now enforces the 90-second video limit 2026-09-24 21:39:07 -03:00
Alexandre Brandizzi
b5da537c93 fix(media): classify client uploads by the server's type rule
A foreign declared type (e.g. video/3gpp on a .jpg) gave the file the video
size allowance in the browser while the server sizes it as a photo. Use the
same rule as the server: an allowlisted type decides, otherwise the extension.
2026-09-24 21:31:03 -03:00
Alexandre Brandizzi
f65a48077d fix(vendor-portal): validate uploads against the server allowlist
Any image/* or video/* type passed the client check, so GIF, WebP and WebM
were only rejected after upload. Resolve the kind from the same allowlist
the server uses: an allowlisted browser type, otherwise the extension.
2026-09-24 21:01:36 -03:00
Alexandre Brandizzi
44e96cf2a3 fix(media): apply the SH-116 media contract to every upload surface
Photos up to 10 MB (JPG/PNG/HEIC), videos up to 100 MB and 90 s (MP4/MOV),
at most 10 photos and 3 videos per work order, pre-validated with stable
generic messages on the Photos & Videos modal, the Completion Doc media tab,
Extra Docs and the vendor portal. Video duration is read from metadata when
the browser can; unreadable metadata never blocks. Mobile MIME variants
(empty type, octet-stream with a video extension, QuickTime) stay accepted.
The signed completion PDF keeps its 50 MB cap.
2026-09-24 20:59:26 -03:00
npalseahaven
4965b8a076
Merge pull request #224 from Sea-Haven-Industries/refactor/dispatch-detail-modal-split-v2
Some checks failed
Frontend checks / static (push) Waiting to run
Frontend checks / build (push) Waiting to run
Frontend checks / unit (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Frontend checks / browser-smoke (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / ci-complete (push) Blocked by required conditions
Deploy Web / Resolve target (push) Has been cancelled
Deploy Web / Deploy SPA to (push) Has been cancelled
refactor(vendor-portal,settings): move state and fetch logic into hook
2026-09-22 14:17:57 +00:00
Alexandre Brandizzi
e769b5fcc2
Merge pull request #227 from Sea-Haven-Industries/feat/ab/sh-288-event-notifications
Some checks are pending
Frontend checks / static (push) Waiting to run
Frontend checks / build (push) Waiting to run
Frontend checks / unit (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Frontend checks / browser-smoke (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / ci-complete (push) Blocked by required conditions
Deploy Web / Resolve target (push) Waiting to run
Deploy Web / Deploy SPA to (push) Blocked by required conditions
feat(notifications): open assignment, comment, mention and uplift items where they happened (SH-288, SH-289, SH-290, SH-215)
2026-09-21 20:58:57 +00:00
cb6fd48916
Merge branch 'main' into refactor/dispatch-detail-modal-split-v2 2026-09-21 16:54:40 -04:00
Alexandre Brandizzi
93f68f84e4 fix(workorders): cap completion documents at 50 MB 2026-09-21 15:39:47 -03:00
Alexandre Brandizzi
ca2b3b5134 fix(work-orders): raise media upload limit to 200 MB 2026-09-21 15:09:51 -03:00
Cursor Agent
647accc737
Merge remote-tracking branch 'origin/main' into feat/ab/sh-288-event-notifications
Co-authored-by: adam <adam@seahavenind.com>
2026-09-20 21:53:34 +00:00
Alexandre Brandizzi
3e5fba4d2b
Merge pull request #225 from Sea-Haven-Industries/feat/ab/sh-292-notification-center
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
Deploy Web / Resolve target (push) Waiting to run
Deploy Web / Deploy SPA to (push) Blocked by required conditions
SH-292: Notification Center panel and feed
2026-09-18 23:33:59 +00:00
Alexandre Brandizzi
cbfed3dde8
Merge pull request #226 from Sea-Haven-Industries/feat/ab/sh-209-uplift-detail-modal
SH-209: Align the Uplift Detail modal with the spec
2026-09-18 23:33:55 +00:00
Alexandre Brandizzi
f25a3dd628
Merge pull request #228 from Sea-Haven-Industries/fix/ab/sh-379-poc-persist
Persist manual POC edits via dedicated POC endpoint (SH-379)
2026-09-18 23:33:52 +00:00
Alexandre Brandizzi
7fdf85fc47
Merge branch 'main' into feat/ab/sh-304-services-registry-ui 2026-09-18 19:21:21 -03:00
Alexandre Brandizzi
7c1243eec3
Merge branch 'main' into feat/ab/sh-304-services-registry-ui 2026-09-18 19:09:49 -03:00
Alexandre Brandizzi
744d7af7bb
Merge branch 'main' into feat/ab/sh-382-extra-doc-view 2026-09-18 19:09:47 -03:00
Alexandre Brandizzi
1a7a4ba58f fix(work-orders): open extra documents without credentialed CORS (SH-382)
Viewing a work-order extra document called the authorized content endpoint
with `credentials: "include"`. The API replies `Access-Control-Allow-Origin: *`,
and in credentialed mode the browser rejects a wildcard origin outright, so the
fetch threw, `openExtraDocContent` fell into its catch, closed the tab and
toasted "Unable to open this document." — QA CT-03.

The endpoint authenticates with the bearer token the ky beforeRequest hook
attaches, not cookies, so credentials mode was dead weight. List, upload and
delete never set it, which is why only viewing failed. Drop the option and
guard the request shape in a test (JSDOM cannot enforce CORS).
2026-09-18 16:35:01 -03:00
Codex Review Integration
84568dd737 refactor(workorders): extract board patch api module
work-orders-api.ts exceeded the 500-line godfile cap after adding
updatePoc. Move patchBoardField/updatePoc and their shared response
handling into work-order-board-patch-api.ts and re-export through
workOrdersApi, mirroring workOrderBoardDocumentsApi.
2026-09-18 15:03:59 -03:00
Codex Review Integration
3b1da21abb fix(workorders): preserve partial POC edits 2026-09-18 15:00:01 -03:00
Codex Review Integration
5b0c758a9f fix(workorders): persist manual POC edits via dedicated POC endpoint (SH-379)
The UI dropped manual POC edits before they reached the API: the patch
mapper listed pocName/pocPhone/pocNotes as local-only keys and the
slide-over draft excluded them from Save, so the optimistic edit vanished
on refetch and the completion freeze captured the Site contact instead.

- Emit one composite POC op from table patches and route it through a new
  workOrdersApi.updatePoc (PATCH workorders/{id}/poc), reusing the board
  patch row/error contract (409 conflict with currentState, 422 validation).
- Include POC scalars in slide-over edit keys so dirty state and Save carry
  them; site dialog and slide-over now both persist POC edits.
2026-09-18 14:44:06 -03:00
Codex Review Integration
75c2c1c1fa Merge remote-tracking branch 'origin/feat/ab/sh-292-notification-center' into HEAD
# Conflicts:
#	src/app/(protected)/workorders/_components/detail/use-slide-over-edit-state.ts
#	src/app/(protected)/workorders/_components/detail/use-work-order-slide-over.ts
#	src/app/(protected)/workorders/_components/detail/work-order-slide-over.tsx
#	src/app/(protected)/workorders/_components/list/work-orders-list-page-panels.tsx
#	src/app/(protected)/workorders/_hooks/use-work-orders-list-page.ts
2026-09-18 14:35:17 -03:00
Codex Review Integration
062a1e26c8 fix: resolve notification review findings 2026-09-18 14:23:43 -03:00
albrand
74e7c526e8 fix(notifications): re-open tab and match API mentions for event highlights
Re-apply the requested slide-over tab on every open via an open counter, so a
second comment/mention notification for the work order already on screen still
switches to Comments and re-scrolls to the highlighted comment. Treat a board
comment's mentions id array (plain @Name text) as a mention alongside encoded
@[id:name] tokens so mention items highlight and comment items exclude them.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-09-18 14:01:55 -03:00
Codex Review Integration
299f471612 Merge commit '988c96c' into feat/ab/sh-288-event-notifications
# Conflicts:
#	src/components/notifications/notification-row.tsx
#	src/components/notifications/use-notification-center.ts
#	src/domain/notifications/utils/notification-target-url.ts
2026-09-18 13:43:48 -03:00
Codex Review Integration
ae941bc93d feat(notifications): open comment, mention, assignment and uplift items where they happened
Comment and mention items open the work order on the Comments tab with the
comments they were raised for highlighted; a grouped assignment opens the
dispatcher's own open queue; uplift decisions open the work order's uplifts.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 13:42:13 -03:00
Codex Review Integration
988c96c42d fix(notifications): keep vendor reminder actions and refresh header baselines
No Vendor opens the work order form on vendor assignment and Vendor Conflict
links each work order, as the vendor reminders did. Header baselines include the
notification bell, and the top bar user menu moves to its own component to stay
within the function-size gate. The vendor e2e now covers the feed contract.
2026-09-18 13:34:12 -03:00
Codex Review Integration
dcf944d7dc SH-292: Notification Center bell panel and feed page
Header bell panel and /notifications page share one feed from GET /api/notifications: labeled sections with live counts, unread styling, session-only dismiss and clear all (acknowledge rows excluded), and deep links to the unassigned queue and a work order's tab via ?wo=&tab=.
2026-09-18 12:55:54 -03:00
Codex Review Integration
3c84d851c0 feat(uplifts): align uplift detail modal with SH-209
Two sections, Work order and Uplift request, divided by a single rule.
Work order shows Service, Vendor / Technician, Assigned Dispatcher and
Scheduled from the queue item, so it no longer fetches the work order
and no longer degrades to Unavailable for account-scoped staff. Uplift
request shows Requested By, Requested At, the justification in a
bordered block, the approved-on-WO breakdown and a horizontal
attachment row whose chips open the evidence in a new tab. Every field
renders data or an explicit placeholder. The footer shows Reject and
Approve for pending uplifts, Revoke for approved ones and nothing for
read-only records; closing is the header X.
2026-09-18 12:53:55 -03:00
npal
62e5d46b0f fix: address PR #224 review findings and extract task-template copy (SH-378)
Three real behavior deltas flagged in review, each closing a gap
against the "no behavior change" claim:

- use-vendor-portal-session.ts: add retry:false and
  meta:{suppressErrorToast:true} so an invalid/expired token fails
  fast with a single request and no duplicate global toast (this was
  also the root cause of the failing e2e test - the toast and the
  inline error message both had role="alert", tripping a strict-mode
  locator match)
- task-template-schema.ts: trim the name before validating so a
  whitespace-only name is rejected, matching the old manual
  form.name.trim() check
- task-template-detail-form.tsx: block Enter-triggered implicit
  submission on the Template Name / Description inputs, since the
  original page had no <form> element and Enter did nothing
- task-template-items-field.tsx: surface a visible error when a
  loaded item has empty text, since the schema already blocked save
  in that case but gave no way to see why; use-task-template-editor.ts
  now eagerly validates after loading a template so this reflects
  reality immediately instead of only after an unrelated edit

Also extract every user-facing string in the task-templates feature
into TASK_TEMPLATE_COPY (task-template-constants.ts) instead of
inline literals scattered across 5 files.

6 new regression tests cover all of the above; full suite (36 tests
across the 2 refactored areas) still green.
2026-09-18 10:46:16 -05:00
Alexandre Brandizzi
c9562650ca
Merge branch 'dev' into fix/ab/sh-364-inline-technician-registration 2026-09-18 11:59:16 -03:00
Alexandre Brandizzi
e780bafdd8
Merge branch 'dev' into feat/ab/sh-304-services-registry-ui 2026-09-18 11:59:13 -03:00
npal
5645c7e02b Merge remote-tracking branch 'origin/dev' into refactor/dispatch-detail-modal-split-v2 2026-09-17 18:10:34 -05:00
npal
a93747f119 refactor(vendor-portal,settings): move state and fetch logic into hooks (SH-378)
vendor-portal-provider.tsx and task-templates.tsx mixed data-fetching,
state, and rendering in one file, with no caching and hand-rolled form
state. This is a pure refactor with no behavior change.

- vendor-portal-provider.tsx: replace manual useEffect/useState fetch
  with useVendorPortalSession (useQuery), closing the token race
  condition the old key={token} remount was working around
- task-templates.tsx: split into useTaskTemplateEditor hook plus 4
  presentational components; replace hand-rolled form state with
  react-hook-form + zod validation; replace the "new" string sentinel
  with a NEW_TEMPLATE_ID constant
- add 29 tests (hook, component, and full-page integration) confirming
  identical behavior to the original code
2026-09-17 18:05:06 -05:00
Alexandre Brandizzi
1ee4bbef7e
Merge branch 'dev' into fix/ab/sh-339-wizard-complete-image 2026-09-17 15:46:18 -03:00
Codex Review Integration
28ff14d457 Merge remote-tracking branch 'origin/dev' into feat/ab/sh-304-services-registry-ui
# Conflicts:
#	src/test/lib/auth/user-utils.test.ts
2026-09-17 15:34:52 -03:00
Alexandre Brandizzi
bff5ed138b
Merge branch 'dev' into fix/ab/sh-339-wizard-complete-image 2026-09-17 15:30:22 -03:00
Alexandre Brandizzi
d53507731e
Merge branch 'dev' into feat/ab/sh-326-team-member 2026-09-17 15:30:16 -03:00
Codex Review Integration
abe28a3a7f Merge remote-tracking branch 'origin/dev' into fix/ab/sh-364-inline-technician-registration
# Conflicts:
#	src/app/(protected)/workorders/_components/wizard/use-new-wo-wizard-controller.ts
#	src/app/(protected)/workorders/_components/wizard/wizard-step-location-service-select.tsx
#	src/app/(protected)/workorders/_components/wizard/wizard-step-vendor-time.tsx
#	src/test/app/(protected)/workorders/wizard-service-clears-vendor.test.tsx
2026-09-17 15:27:39 -03:00
Alexandre Brandizzi
948ce278de
Merge branch 'dev' into fix/ab/sh-339-wizard-complete-image 2026-09-17 15:16:30 -03:00
Alexandre Brandizzi
9ed8099e71
Merge branch 'dev' into feat/ab/sh-304-services-registry-ui 2026-09-17 15:16:25 -03:00
Alexandre Brandizzi
6eacdc09f6
Merge branch 'dev' into feat/ab/sh-336-dashboard 2026-09-17 15:16:22 -03:00
Alexandre Brandizzi
873e3e32de
Merge branch 'dev' into feat/ab/sh-326-team-member 2026-09-17 15:16:18 -03:00
Alexandre Brandizzi
361f6b65a2
Merge branch 'dev' into feat/ab/sh-304-services-registry-ui 2026-09-17 15:10:25 -03:00
Alexandre Brandizzi
0876e9c3f0
Merge branch 'dev' into feat/ab/sh-336-dashboard 2026-09-17 15:10:22 -03:00
Alexandre Brandizzi
5b6991c93a
Merge branch 'dev' into feat/ab/sh-326-team-member 2026-09-17 15:10:19 -03:00
Alexandre Brandizzi
bca906f900
Merge branch 'dev' into fix/ab/sh-339-wizard-complete-image 2026-09-17 15:02:23 -03:00
Alexandre Brandizzi
534d7ce4d6
Merge branch 'dev' into fix/ab/sh-364-inline-technician-registration 2026-09-17 15:02:19 -03:00
Alexandre Brandizzi
bf916019f9
Merge branch 'dev' into fix/ab/sh-321-wizard-vendor-notes 2026-09-17 15:02:13 -03:00
Codex Review Integration
bbdf418ee3 refactor(services): extract useServiceEditor to satisfy maintainability gate
useServicesRegistryController exceeded the changed-file max-lines-per-function
budget (158 > 150). Move the add/edit form lifecycle into a useServiceEditor
sub-hook; the controller's public return shape and behavior are unchanged.
2026-09-17 14:55:05 -03:00
Alexandre Brandizzi
8d2c947c54
Merge branch 'dev' into fix/ab/sh-339-wizard-complete-image 2026-09-17 14:48:30 -03:00