refactor(quick-260921-m34): Aufgabe 2b - getypte Anfrage in elf Controllern, zwei Befunde gemeldet
(req as any) und @Req() req: any durch AuthenticatedRequest ersetzt in
dashboard, favorites, calendar, groups, module-grants, module-registry,
tenders, dkv, ldap, settings; @CurrentUser() in user.controller auf AuthUser.
Die abwehrenden Pruefungen ("No tenant context", "No user context") bleiben
lebendig, weil user auf dem Anfragetyp wahlfrei ist - genau das beschreibt
den Zustand auf oeffentlichen Wegen.
Nebengewinn ohne neue Zusicherungen: req.tenantId as string | undefined
(dkv, settings), file.buffer as Buffer und file.mimetype as string
(dkv, user) sind weggefallen, weil der Typ sie jetzt traegt.
BEFUND 1 (D-03, gemeldet) dashboard.controller.ts:74 alt: der Handler las
req.user?.role NACH extractContext und gab sie an getWidgets(role: Role)
weiter, das eine Rolle zwingend verlangt. Die Annahme "hier gibt es immer
einen Aufrufer" stimmt - die Pruefung "No user context" erzwingt sie -, aber
sie stand in einer anderen Methode, wo der Compiler sie nicht sehen konnte.
extractContext gibt die Rolle jetzt mit zurueck: keine neue Pruefung, kein
erfundener Wert, gleiche Reihenfolge, gleiche Meldungen.
BEFUND 2 (D-03, gemeldet) tenders.controller.ts:142: resolveRequestingTenantId
erklaerte string | undefined, liest aber req.tenantId, das TenantGuard fuer
einen SUPER_ADMIN ohne Mandanten auf null setzt. Die Erklaerung war also nie
vollstaendig. Erweitert auf string | null | undefined, und buildTenderWhere
nimmt string | null - beides nur Erklaerung, kein Verhalten: die Funktion
entscheidet seit jeher ueber Wahrheitswert und faellt bei beiden zu
(nur global sichtbare Ausschreibungen).
Fixtures in user.controller.spec.ts ergaenzt (username, mustChangePassword,
originalname, size). Testzahlen unveraendert.
noExplicitAny in apps/api/src: 137 -> 66. type-check 4/4, lint 5/5,
apps/api 72/1143, apps/web 73/531, tenant.guard.ts unveraendert.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TPPB4ApQxzSU1rwV2Ffj9J
This commit is contained in:
@@ -13,6 +13,7 @@ import {
|
||||
} from '@nestjs/common';
|
||||
import { Role } from '@prisma/client';
|
||||
import { Roles } from '../auth/decorators/roles.decorator';
|
||||
import type { AuthenticatedRequest } from '../auth/types/auth-user';
|
||||
import {
|
||||
CreateFieldMappingDto,
|
||||
CreateLdapConfigDto,
|
||||
@@ -41,7 +42,7 @@ export class LdapController {
|
||||
*/
|
||||
@Get('config')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async getConfig(@Req() req: any) {
|
||||
async getConfig(@Req() req: AuthenticatedRequest) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -65,7 +66,7 @@ export class LdapController {
|
||||
*/
|
||||
@Post('config')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async createConfig(@Req() req: any, @Body() dto: CreateLdapConfigDto) {
|
||||
async createConfig(@Req() req: AuthenticatedRequest, @Body() dto: CreateLdapConfigDto) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -92,7 +93,7 @@ export class LdapController {
|
||||
*/
|
||||
@Patch('config')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async updateConfig(@Req() req: any, @Body() dto: UpdateLdapConfigDto) {
|
||||
async updateConfig(@Req() req: AuthenticatedRequest, @Body() dto: UpdateLdapConfigDto) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -123,7 +124,7 @@ export class LdapController {
|
||||
*/
|
||||
@Post('test-connection')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async testConnection(@Req() req: any, @Body() dto: TestConnectionDto) {
|
||||
async testConnection(@Req() req: AuthenticatedRequest, @Body() dto: TestConnectionDto) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -158,7 +159,7 @@ export class LdapController {
|
||||
*/
|
||||
@Get('groups')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async listGroups(@Req() req: any) {
|
||||
async listGroups(@Req() req: AuthenticatedRequest) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -189,7 +190,7 @@ export class LdapController {
|
||||
*/
|
||||
@Post('groups/import')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async importGroups(@Req() req: any, @Body() dto: ImportGroupsDto) {
|
||||
async importGroups(@Req() req: AuthenticatedRequest, @Body() dto: ImportGroupsDto) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -225,7 +226,7 @@ export class LdapController {
|
||||
*/
|
||||
@Get('users/search')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async searchUsers(@Req() req: any, @Query('q') q: string) {
|
||||
async searchUsers(@Req() req: AuthenticatedRequest, @Query('q') q: string) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -256,7 +257,7 @@ export class LdapController {
|
||||
*/
|
||||
@Post('users/import')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async importUsers(@Req() req: any, @Body() dto: ImportUsersDto) {
|
||||
async importUsers(@Req() req: AuthenticatedRequest, @Body() dto: ImportUsersDto) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -292,7 +293,7 @@ export class LdapController {
|
||||
*/
|
||||
@Post('sync')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async triggerSync(@Req() req: any) {
|
||||
async triggerSync(@Req() req: AuthenticatedRequest) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -326,7 +327,7 @@ export class LdapController {
|
||||
*/
|
||||
@Post('config/mappings')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async addFieldMapping(@Req() req: any, @Body() dto: CreateFieldMappingDto) {
|
||||
async addFieldMapping(@Req() req: AuthenticatedRequest, @Body() dto: CreateFieldMappingDto) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
@@ -351,7 +352,7 @@ export class LdapController {
|
||||
*/
|
||||
@Delete('config/mappings/:id')
|
||||
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
||||
async removeFieldMapping(@Req() req: any, @Param('id') id: string) {
|
||||
async removeFieldMapping(@Req() req: AuthenticatedRequest, @Param('id') id: string) {
|
||||
const tenantId = req.tenantId;
|
||||
if (!tenantId) {
|
||||
throw new BadRequestException('No tenant context');
|
||||
|
||||
Reference in New Issue
Block a user