feat(12-04): tender-radar notification-pref service + routes, instantAlert passthrough

- TenderNotificationPrefService: per-user digestInterval CRUD (default
  'daily', upsert on @@unique userId, D-01/D-03)
- UpdateNotificationPrefDto: @IsIn(['daily','weekly','off']) validation (V5)
- GET/PUT /modules/tender-radar/notification-pref, declared before
  @Get(':id') (route-order pitfall)
- instantAlert passthrough in Create/UpdateSavedSearchDto and
  TenderSavedSearchService.create/update (NOTIFY-02, D-04)
- All pref/profile routes scoped strictly via extractTriageContext(req),
  never from body/query (T-12-14, IDOR)
- Updated tenders.controller.spec.ts fakes for the new constructor param

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-22 09:28:02 +02:00
parent 1a0cd375c2
commit 9e7ba5353d
9 changed files with 343 additions and 1 deletions
@@ -17,10 +17,12 @@ import { Request } from 'express';
import { Roles } from '../auth/decorators/roles.decorator';
import { UseModule } from '../module-registry/module.guard';
import { PrismaService } from '../prisma/prisma.service';
import { UpdateNotificationPrefDto } from './dto/notification-pref.dto';
import { CreateSavedSearchDto, UpdateSavedSearchDto } from './dto/saved-search.dto';
import { SourceConfigDto } from './dto/source-config.dto';
import { TenderQueryDto } from './dto/tender-query.dto';
import { TenderTriageDto } from './dto/tender-triage.dto';
import { TenderNotificationPrefService } from './tender-notification-pref.service';
import { TenderSavedSearchService } from './tender-saved-search.service';
import { TenderSchedulerService } from './tender-scheduler.service';
import { TenderTriageService } from './tender-triage.service';
@@ -58,6 +60,7 @@ export class TendersController {
private readonly tenderScheduler: TenderSchedulerService,
private readonly tenderTriage: TenderTriageService,
private readonly tenderSavedSearch: TenderSavedSearchService,
private readonly tenderNotificationPref: TenderNotificationPrefService,
) {}
/**
@@ -301,6 +304,41 @@ export class TendersController {
return { success: true };
}
// ─── Notification preference (per-user, NOTIFY-01, D-01/D-03) ─────────────
/**
* GET /modules/tender-radar/notification-pref — this user's digest
* interval preference (daily/weekly/off). Scoped strictly by userId
* (T-12-14 / V4 — IDOR), derived from the auth context, never from a
* query param.
*
* MUST be declared before `@Get(':id')` below — same route-order pitfall
* as `source-config`/`coverage`/`triage`/`saved-searches` above
* (Pitfall 5).
*/
@Get('notification-pref')
@UseModule('tender-radar')
async getNotificationPref(@Req() req: Request) {
const { userId } = this.extractTriageContext(req);
return this.tenderNotificationPref.getForUser(userId);
}
/**
* PUT /modules/tender-radar/notification-pref — upsert this user's digest
* interval preference. userId/tenantId come exclusively from the auth
* context (T-12-14 / V4 — IDOR); `dto` carries only `digestInterval`,
* never a userId field.
*/
@Put('notification-pref')
@UseModule('tender-radar')
async setNotificationPref(
@Body() dto: UpdateNotificationPrefDto,
@Req() req: Request,
) {
const { userId, tenantId } = this.extractTriageContext(req);
return this.tenderNotificationPref.setForUser(userId, tenantId, dto.digestInterval);
}
/**
* GET /modules/tender-radar/:id — single tender detail.
* Gated by @UseModule('tender-radar'); NOT scoped by the tenant's id