feat(12-04): tender-radar notification-pref service + routes, instantAlert passthrough
- TenderNotificationPrefService: per-user digestInterval CRUD (default
'daily', upsert on @@unique userId, D-01/D-03)
- UpdateNotificationPrefDto: @IsIn(['daily','weekly','off']) validation (V5)
- GET/PUT /modules/tender-radar/notification-pref, declared before
@Get(':id') (route-order pitfall)
- instantAlert passthrough in Create/UpdateSavedSearchDto and
TenderSavedSearchService.create/update (NOTIFY-02, D-04)
- All pref/profile routes scoped strictly via extractTriageContext(req),
never from body/query (T-12-14, IDOR)
- Updated tenders.controller.spec.ts fakes for the new constructor param
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -17,10 +17,12 @@ import { Request } from 'express';
|
||||
import { Roles } from '../auth/decorators/roles.decorator';
|
||||
import { UseModule } from '../module-registry/module.guard';
|
||||
import { PrismaService } from '../prisma/prisma.service';
|
||||
import { UpdateNotificationPrefDto } from './dto/notification-pref.dto';
|
||||
import { CreateSavedSearchDto, UpdateSavedSearchDto } from './dto/saved-search.dto';
|
||||
import { SourceConfigDto } from './dto/source-config.dto';
|
||||
import { TenderQueryDto } from './dto/tender-query.dto';
|
||||
import { TenderTriageDto } from './dto/tender-triage.dto';
|
||||
import { TenderNotificationPrefService } from './tender-notification-pref.service';
|
||||
import { TenderSavedSearchService } from './tender-saved-search.service';
|
||||
import { TenderSchedulerService } from './tender-scheduler.service';
|
||||
import { TenderTriageService } from './tender-triage.service';
|
||||
@@ -58,6 +60,7 @@ export class TendersController {
|
||||
private readonly tenderScheduler: TenderSchedulerService,
|
||||
private readonly tenderTriage: TenderTriageService,
|
||||
private readonly tenderSavedSearch: TenderSavedSearchService,
|
||||
private readonly tenderNotificationPref: TenderNotificationPrefService,
|
||||
) {}
|
||||
|
||||
/**
|
||||
@@ -301,6 +304,41 @@ export class TendersController {
|
||||
return { success: true };
|
||||
}
|
||||
|
||||
// ─── Notification preference (per-user, NOTIFY-01, D-01/D-03) ─────────────
|
||||
|
||||
/**
|
||||
* GET /modules/tender-radar/notification-pref — this user's digest
|
||||
* interval preference (daily/weekly/off). Scoped strictly by userId
|
||||
* (T-12-14 / V4 — IDOR), derived from the auth context, never from a
|
||||
* query param.
|
||||
*
|
||||
* MUST be declared before `@Get(':id')` below — same route-order pitfall
|
||||
* as `source-config`/`coverage`/`triage`/`saved-searches` above
|
||||
* (Pitfall 5).
|
||||
*/
|
||||
@Get('notification-pref')
|
||||
@UseModule('tender-radar')
|
||||
async getNotificationPref(@Req() req: Request) {
|
||||
const { userId } = this.extractTriageContext(req);
|
||||
return this.tenderNotificationPref.getForUser(userId);
|
||||
}
|
||||
|
||||
/**
|
||||
* PUT /modules/tender-radar/notification-pref — upsert this user's digest
|
||||
* interval preference. userId/tenantId come exclusively from the auth
|
||||
* context (T-12-14 / V4 — IDOR); `dto` carries only `digestInterval`,
|
||||
* never a userId field.
|
||||
*/
|
||||
@Put('notification-pref')
|
||||
@UseModule('tender-radar')
|
||||
async setNotificationPref(
|
||||
@Body() dto: UpdateNotificationPrefDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const { userId, tenantId } = this.extractTriageContext(req);
|
||||
return this.tenderNotificationPref.setForUser(userId, tenantId, dto.digestInterval);
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /modules/tender-radar/:id — single tender detail.
|
||||
* Gated by @UseModule('tender-radar'); NOT scoped by the tenant's id
|
||||
|
||||
Reference in New Issue
Block a user