5f97eca804c0106940f92c24bc3a5ba96da97c19
Adds the batch-triage read/write routes (declared before @Get(':id') per
the route-order pitfall, T-11-13) and wires them through
TenderTriageService with userId/tenantId always derived from the request
context, never the body (T-11-10 / V4 IDOR). Extends TenderQueryDto/
buildTenderWhere with favOnly (UI-04): the controller resolves the
current user's favorited tenderIds server-side before building the
where-clause, and an empty favorites list yields zero matches instead of
the unfiltered catalog. Both batch-ids and favIds in-lists are bounded
(T-11-11 DoS). tenders.controller.spec.ts constructor calls updated for
the new TenderTriageService dependency (Rule 3 — required to keep the
existing suite compiling/passing).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Description
Tessera - Modulare Workflow-Automatisierung und Tool-Integration
Releases
15
Tessera 1.9.2
Latest
Languages
TypeScript
91.3%
JavaScript
5%
Rust
1.3%
HTML
1%
Shell
0.5%
Other
0.8%