7c9d7c1223
(req as any) und @Req() req: any durch AuthenticatedRequest ersetzt in
dashboard, favorites, calendar, groups, module-grants, module-registry,
tenders, dkv, ldap, settings; @CurrentUser() in user.controller auf AuthUser.
Die abwehrenden Pruefungen ("No tenant context", "No user context") bleiben
lebendig, weil user auf dem Anfragetyp wahlfrei ist - genau das beschreibt
den Zustand auf oeffentlichen Wegen.
Nebengewinn ohne neue Zusicherungen: req.tenantId as string | undefined
(dkv, settings), file.buffer as Buffer und file.mimetype as string
(dkv, user) sind weggefallen, weil der Typ sie jetzt traegt.
BEFUND 1 (D-03, gemeldet) dashboard.controller.ts:74 alt: der Handler las
req.user?.role NACH extractContext und gab sie an getWidgets(role: Role)
weiter, das eine Rolle zwingend verlangt. Die Annahme "hier gibt es immer
einen Aufrufer" stimmt - die Pruefung "No user context" erzwingt sie -, aber
sie stand in einer anderen Methode, wo der Compiler sie nicht sehen konnte.
extractContext gibt die Rolle jetzt mit zurueck: keine neue Pruefung, kein
erfundener Wert, gleiche Reihenfolge, gleiche Meldungen.
BEFUND 2 (D-03, gemeldet) tenders.controller.ts:142: resolveRequestingTenantId
erklaerte string | undefined, liest aber req.tenantId, das TenantGuard fuer
einen SUPER_ADMIN ohne Mandanten auf null setzt. Die Erklaerung war also nie
vollstaendig. Erweitert auf string | null | undefined, und buildTenderWhere
nimmt string | null - beides nur Erklaerung, kein Verhalten: die Funktion
entscheidet seit jeher ueber Wahrheitswert und faellt bei beiden zu
(nur global sichtbare Ausschreibungen).
Fixtures in user.controller.spec.ts ergaenzt (username, mustChangePassword,
originalname, size). Testzahlen unveraendert.
noExplicitAny in apps/api/src: 137 -> 66. type-check 4/4, lint 5/5,
apps/api 72/1143, apps/web 73/531, tenant.guard.ts unveraendert.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TPPB4ApQxzSU1rwV2Ffj9J
248 lines
9.4 KiB
TypeScript
248 lines
9.4 KiB
TypeScript
import {
|
|
BadRequestException,
|
|
Body,
|
|
Controller,
|
|
Delete,
|
|
Get,
|
|
NotFoundException,
|
|
Param,
|
|
Post,
|
|
Put,
|
|
Query,
|
|
Req,
|
|
Res,
|
|
UploadedFile,
|
|
UseInterceptors,
|
|
} from '@nestjs/common';
|
|
import { FileInterceptor } from '@nestjs/platform-express';
|
|
import { Role } from '@prisma/client';
|
|
import { Roles } from '../auth/decorators/roles.decorator';
|
|
import type {
|
|
AuthenticatedRequest,
|
|
UploadedFileLike,
|
|
} from '../auth/types/auth-user';
|
|
import type { Response } from 'express';
|
|
import { DkvSchedulerService } from './dkv-scheduler.service';
|
|
import { DkvService } from './dkv.service';
|
|
import { DkvConfigDto } from './dto/dkv-config.dto';
|
|
import { DkvHistoryQueryDto } from './dto/dkv-history.dto';
|
|
import { CreateVehicleDto, UpdateVehicleDto } from './dto/dkv-vehicle.dto';
|
|
|
|
/**
|
|
* DkvController — all /dkv/* routes, ADMIN-only (V4).
|
|
*
|
|
* Every handler carries @Roles(Role.ADMIN, Role.SUPER_ADMIN).
|
|
* Global JwtAuthGuard enforces JWT authentication; RolesGuard enforces the
|
|
* @Roles decorator. No route is publicly accessible.
|
|
*
|
|
* Tenant extraction: `req.tenantId` set by TenantGuard (runs after auth guards).
|
|
* All operations are scoped to the authenticated tenant's data.
|
|
*
|
|
* Routes:
|
|
* GET /dkv/config — get module config (no encrypted creds)
|
|
* PUT /dkv/config — save module config; updates scheduler
|
|
* POST /dkv/check-now — manual inbox poll trigger
|
|
* POST /dkv/test-connection — test inbox connection with form values
|
|
* GET /dkv/history — paginated processing history
|
|
* GET /dkv/exports/:filename — download a saved xlsx file
|
|
* GET /dkv/vehicles — list vehicle master records
|
|
* POST /dkv/vehicles — create a vehicle master record
|
|
* PUT /dkv/vehicles/:id — update a vehicle master record
|
|
* DELETE /dkv/vehicles/:id — delete a vehicle master record
|
|
* POST /dkv/vehicles/import — bulk-import from CSV upload
|
|
*/
|
|
@Controller('dkv')
|
|
export class DkvController {
|
|
constructor(
|
|
private readonly dkvService: DkvService,
|
|
private readonly dkvScheduler: DkvSchedulerService,
|
|
) {}
|
|
|
|
// ─── Config ────────────────────────────────────────────────────────────────
|
|
|
|
/** GET /dkv/config — returns module config with username + hasPassword. 404 when not yet configured. */
|
|
@Get('config')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async getConfig(@Req() req: AuthenticatedRequest) {
|
|
const tenantId = this._requireTenant(req);
|
|
const config = await this.dkvService.getConfigForApi(tenantId);
|
|
if (!config) {
|
|
throw new NotFoundException('DKV module not yet configured');
|
|
}
|
|
return config;
|
|
}
|
|
|
|
/**
|
|
* PUT /dkv/config — upsert module config.
|
|
*
|
|
* After saving, re-applies the cron job if isActive is true,
|
|
* or stops the cron job if isActive is false.
|
|
*/
|
|
@Put('config')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async saveConfig(@Req() req: AuthenticatedRequest, @Body() dto: DkvConfigDto) {
|
|
const tenantId = this._requireTenant(req);
|
|
const result = await this.dkvService.saveConfig(tenantId, dto);
|
|
|
|
// Update scheduler to reflect the new interval / active state
|
|
if (dto.isActive && dto.pollIntervalMin) {
|
|
this.dkvScheduler.setInterval(dto.pollIntervalMin, tenantId);
|
|
} else if (dto.isActive === false) {
|
|
this.dkvScheduler.stopJob(tenantId);
|
|
}
|
|
|
|
return result;
|
|
}
|
|
|
|
// ─── Manual trigger + connection test ──────────────────────────────────────
|
|
|
|
/** POST /dkv/check-now — immediately run the inbox processing pipeline. */
|
|
@Post('check-now')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async checkNow(@Req() req: AuthenticatedRequest) {
|
|
const tenantId = this._requireTenant(req);
|
|
return this.dkvService.checkNow(tenantId);
|
|
}
|
|
|
|
/**
|
|
* POST /dkv/test-connection — test inbox connection with current form values.
|
|
* Used by the InboxConfigForm "Verbindung testen" button before saving.
|
|
*/
|
|
@Post('test-connection')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async testConnection(@Req() req: AuthenticatedRequest, @Body() dto: DkvConfigDto) {
|
|
const tenantId = this._requireTenant(req);
|
|
return this.dkvService.testConnection(tenantId, dto);
|
|
}
|
|
|
|
// ─── History ───────────────────────────────────────────────────────────────
|
|
|
|
/**
|
|
* GET /dkv/history?page=1&limit=20 — paginated processing history.
|
|
* T-07-06: pagination parameters validated by DkvHistoryQueryDto.
|
|
*/
|
|
@Get('history')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async getHistory(@Req() req: AuthenticatedRequest, @Query() query: DkvHistoryQueryDto) {
|
|
const tenantId = this._requireTenant(req);
|
|
const page = query.page ?? 1;
|
|
const limit = query.limit ?? 20;
|
|
return this.dkvService.getHistory(tenantId, page, limit);
|
|
}
|
|
|
|
// ─── Export file download ──────────────────────────────────────────────────
|
|
|
|
/**
|
|
* GET /dkv/exports/:filename — stream a DKV xlsx export file as an attachment.
|
|
*
|
|
* T-07-09: DkvService.getExportFile() validates the filename against the
|
|
* `DKV_*.xlsx` whitelist pattern before reading from user-files/. Any filename
|
|
* containing path separators or non-whitelisted characters is rejected.
|
|
*/
|
|
@Get('exports/:filename')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async downloadExport(
|
|
@Req() req: AuthenticatedRequest,
|
|
@Param('filename') filename: string,
|
|
@Res() res: Response,
|
|
) {
|
|
const tenantId = this._requireTenant(req);
|
|
|
|
try {
|
|
const buffer = await this.dkvService.getExportFile(tenantId, filename);
|
|
res.setHeader('Content-Disposition', `attachment; filename="${filename}"`);
|
|
res.setHeader(
|
|
'Content-Type',
|
|
'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet',
|
|
);
|
|
res.send(buffer);
|
|
} catch (error) {
|
|
if (error instanceof NotFoundException || error instanceof BadRequestException) {
|
|
throw error;
|
|
}
|
|
throw error;
|
|
}
|
|
}
|
|
|
|
// ─── Vehicle Master CRUD ───────────────────────────────────────────────────
|
|
|
|
/** GET /dkv/vehicles — list all vehicle master records for this tenant. */
|
|
@Get('vehicles')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async listVehicles(@Req() req: AuthenticatedRequest) {
|
|
const tenantId = this._requireTenant(req);
|
|
return this.dkvService.listVehicles(tenantId);
|
|
}
|
|
|
|
/** POST /dkv/vehicles — create a new vehicle master record. */
|
|
@Post('vehicles')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async createVehicle(@Req() req: AuthenticatedRequest, @Body() dto: CreateVehicleDto) {
|
|
const tenantId = this._requireTenant(req);
|
|
return this.dkvService.createVehicle(tenantId, dto);
|
|
}
|
|
|
|
/** PUT /dkv/vehicles/:id — update an existing vehicle master record. */
|
|
@Put('vehicles/:id')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async updateVehicle(
|
|
@Req() req: AuthenticatedRequest,
|
|
@Param('id') id: string,
|
|
@Body() dto: UpdateVehicleDto,
|
|
) {
|
|
const tenantId = this._requireTenant(req);
|
|
return this.dkvService.updateVehicle(tenantId, id, dto);
|
|
}
|
|
|
|
/** DELETE /dkv/vehicles/:id — delete a vehicle master record. */
|
|
@Delete('vehicles/:id')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
async deleteVehicle(@Req() req: AuthenticatedRequest, @Param('id') id: string) {
|
|
const tenantId = this._requireTenant(req);
|
|
return this.dkvService.deleteVehicle(tenantId, id);
|
|
}
|
|
|
|
/**
|
|
* POST /dkv/vehicles/import — bulk import from a CSV file upload.
|
|
*
|
|
* Accepts a multipart form with:
|
|
* - `file`: the CSV file (field name must be "file")
|
|
* - `mode`: 'merge' (default) or 'replace'
|
|
*
|
|
* FileInterceptor buffers the upload in memory (no disk write).
|
|
* The controller reads `file.buffer.toString('utf-8')` and passes to DkvService.
|
|
*/
|
|
@Post('vehicles/import')
|
|
@Roles(Role.ADMIN, Role.SUPER_ADMIN)
|
|
@UseInterceptors(FileInterceptor('file', {
|
|
limits: { fileSize: 5 * 1024 * 1024 }, // 5 MB — generous for any realistic vehicle list (WR-05)
|
|
}))
|
|
async importVehicles(
|
|
@Req() req: AuthenticatedRequest,
|
|
@UploadedFile() file: UploadedFileLike | undefined,
|
|
@Body('mode') mode: string,
|
|
) {
|
|
const tenantId = this._requireTenant(req);
|
|
|
|
if (!file?.buffer) {
|
|
throw new BadRequestException('No CSV file uploaded (field name must be "file")');
|
|
}
|
|
|
|
const csvText = file.buffer.toString('utf-8');
|
|
const importMode = mode === 'replace' ? 'replace' : 'merge';
|
|
|
|
return this.dkvService.importVehiclesCsv(tenantId, csvText, importMode);
|
|
}
|
|
|
|
// ─── Private helpers ───────────────────────────────────────────────────────
|
|
|
|
/** Extract and validate tenantId from request; throw BadRequestException when absent. */
|
|
private _requireTenant(req: AuthenticatedRequest): string {
|
|
const tenantId = req.tenantId;
|
|
if (!tenantId) {
|
|
throw new BadRequestException('No tenant context');
|
|
}
|
|
return tenantId;
|
|
}
|
|
}
|