Add Template, Edit and Delete now follow the permissions the server
computes for the signed-in user, role defaults plus their individual
overrides, instead of role defaults alone. The actions stay hidden while
the permissions load or when they fail to load.
Add the Completion Docs page under Data Management: a searchable template
table, a read-only detail panel, add and edit with a live document preview,
and delete behind a confirmation that counts the open work orders still
using the template and links to them. Add, edit and delete are hidden for
users whose role lacks the matching template permission.
The preview shares the work-order completion document's page frame,
header, safety bullets and procedure heading so the two stay identical.
The UI dropped manual POC edits before they reached the API: the patch
mapper listed pocName/pocPhone/pocNotes as local-only keys and the
slide-over draft excluded them from Save, so the optimistic edit vanished
on refetch and the completion freeze captured the Site contact instead.
- Emit one composite POC op from table patches and route it through a new
workOrdersApi.updatePoc (PATCH workorders/{id}/poc), reusing the board
patch row/error contract (409 conflict with currentState, 422 validation).
- Include POC scalars in slide-over edit keys so dirty state and Save carry
them; site dialog and slide-over now both persist POC edits.
The shared ky instance declared Content-Type: application/json for every
request. Ky bakes instance headers into the Request it builds, so a FormData
body left with that header, and the beforeRequest hook that deleted it ran
after the boundary had already been dropped: the multipart body went out
with no Content-Type at all. ASP.NET then cannot bind [FromForm] fields, so
the completion-doc upload (dialog and slide-over "Upload signed PDF")
returned 400 "The file field is required.", media category updates arrived
without category or workOrderVersion, and the legacy edit form post lost its
fields.
Drop the instance-wide Content-Type. Ky still sets application/json for
json bodies, and the runtime sets multipart/form-data with the boundary.
The old unit test tolerated a missing header, and ran under jsdom whose
FormData the Node Request cannot serialize. It now runs in the node
environment and requires a multipart Content-Type whose boundary matches the
body. A Pixel 7 viewport e2e covers the signed PDF upload and JPG/MP4/MOV
media upload plus categorize.
Three conflicts, all where dev refactored code this branch had instrumented:
- api.ts — dev extracted the session-expiry helper into
lib/auth/expire-session. Took dev's import, dropped the now-duplicate local
copy, kept the tracing import.
- work-order-board-documents-api.ts — dev replaced the ky upload with
uploadFormWithProgress, an XHR path that exists because ky's
onUploadProgress streams the body and browsers refuse that over HTTP/1.1.
Kept dev's helper and wrapped it in traceHttpOperation so the upload stays
instrumented; neither change is lost.
- work-orders-api.test.ts — kept both mock surfaces, since the merged
work-orders-api calls apiRequestRaw while other code uses the ky instance.
getMediaContent arrived from dev calling `api.get` directly, which this file
no longer imports; routed it through apiRequestRaw like its siblings, which
also brings it under tracing.
* fix(work-orders): address wizard create review findings
[recover] remove malicious eslint payload (was 166c63e4)
* fix(work-orders): remove legacy completedDate EditWorkorder path
[recover] remove malicious eslint payload (was f4e6132b)
* fix(work-orders): use local calendar day for completedDate
Restore todayIso() after parent merge reintroduced UTC slice, and keep the wizard-date-utils regression test.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(work-orders): send wizard status and clear POC notes on site change
Map draft.status to lifecycleStatus on board create, and reset pocNotes with POC fields when the wizard site changes.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(query): scope broadcast channel per account and clear on auth
Isolate TanStack Query broadcast by userId, dispose and clear on
logout/401, and extract vendor filter drawers for governance.
* feat(work-orders): board wizard create with service notes
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(work-orders): enforce single-service wizard create per SH-118
Use single service selection in the wizard and omit extraServices from board create.
* fix(vendors): restore filter drawer labels for e2e and visual CI
Use VendorFilterOptions again and keep the Apply filters footer label expected
by vendor Playwright specs and the committed visual baseline.
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
Split oversized API/mapper/UI modules and extract focused helpers so the
exact head satisfies godfile and complexity ratchets without relaxing thresholds.
* feat(vendors): align directory UI with prototype
* fix(vendors): report the filtered total
* fix(vendors): keep company input in sync
* fix(vendors): scope facets to directory status