Compare commits
39 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a1b3985469 | |||
| 5cf9588728 | |||
| 9260b4de9b | |||
| 46e971ef25 | |||
| f8b9ee8f6c | |||
| 4108062416 | |||
| 03bc85b788 | |||
| 9158cd8c82 | |||
| 951961b798 | |||
| f02c89b3cb | |||
| 295ec5799f | |||
| fe9e8a780f | |||
| 92c4b14a6c | |||
| 80b130dffb | |||
| 62a5d857de | |||
| f72b24fcaa | |||
| 7c5faabc2d | |||
| 582782b0fe | |||
| 250cf89abb | |||
| c9a84e235b | |||
| baaf51ba99 | |||
| 5d18d5d576 | |||
| ed2ee87c68 | |||
| 6c7f53350f | |||
| 0e4bcf174b | |||
| cb9fd7dfa8 | |||
| 4b2914cd5d | |||
| ae7627fcf2 | |||
| 67150425e4 | |||
| 0415794473 | |||
| 9e1aa57987 | |||
| 22f86451e3 | |||
| 7ac30bb454 | |||
| 4e84a15db7 | |||
| 783696fa97 | |||
| 0aa05f10f2 | |||
| 08a4c28868 | |||
| badb26a81f | |||
| 057dd5aedc |
@@ -29,3 +29,10 @@ yarn-error.log*
|
||||
.DS_Store
|
||||
Thumbs.db
|
||||
.idea/
|
||||
|
||||
# ── Migrations ─────────────────────────────────────────────────────────
|
||||
# New EF Core migrations are not committed. Note the 4 migrations already in
|
||||
# Backend/ERPCore/Infra/Persistence/Migrations/ stay tracked — .gitignore does
|
||||
# not apply to tracked files — so edits to those still get committed as normal.
|
||||
# Untracking them too takes `git rm --cached`.
|
||||
**/Migrations/
|
||||
|
||||
@@ -0,0 +1,37 @@
|
||||
namespace ERPCore.Common.Http;
|
||||
|
||||
/// <summary>
|
||||
/// Encodes the PostgreSQL xmin concurrency token (a <see cref="uint"/>) as an
|
||||
/// opaque, quoted HTTP ETag and parses <c>If-Match</c> values back. Round-trips
|
||||
/// via base64 so the value is stable and content-type agnostic
|
||||
/// (docs/11-BACKEND-PHASE1.md §1.6).
|
||||
/// </summary>
|
||||
public static class ETag
|
||||
{
|
||||
/// <summary>Quoted ETag string for a row-version token, e.g. <c>"0RsAAA=="</c>.</summary>
|
||||
public static string From(uint rowVersion)
|
||||
=> "\"" + Convert.ToBase64String(BitConverter.GetBytes(rowVersion)) + "\"";
|
||||
|
||||
/// <summary>Parse an <c>If-Match</c> header value (quoted, optionally weak) to a token.</summary>
|
||||
public static bool TryParse(string? ifMatch, out uint rowVersion)
|
||||
{
|
||||
rowVersion = 0;
|
||||
if (string.IsNullOrWhiteSpace(ifMatch)) return false;
|
||||
|
||||
var v = ifMatch.Trim();
|
||||
if (v.StartsWith("W/", StringComparison.OrdinalIgnoreCase)) v = v[2..].Trim();
|
||||
v = v.Trim('"');
|
||||
|
||||
try
|
||||
{
|
||||
var bytes = Convert.FromBase64String(v);
|
||||
if (bytes.Length != sizeof(uint)) return false;
|
||||
rowVersion = BitConverter.ToUInt32(bytes);
|
||||
return true;
|
||||
}
|
||||
catch (FormatException)
|
||||
{
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
namespace ERPCore.Common.Http;
|
||||
|
||||
/// <summary>
|
||||
/// Pairs a response DTO with the aggregate's current row-version so the controller
|
||||
/// can emit an <c>ETag</c> header without the token leaking into the JSON body.
|
||||
/// </summary>
|
||||
public sealed record ETagged<T>(T Value, uint RowVersion);
|
||||
@@ -0,0 +1,32 @@
|
||||
using ERPCore.Common.Http;
|
||||
using ERPCore.Infra.Auth;
|
||||
using ERPCore.System.Errors;
|
||||
using Microsoft.AspNetCore.Authorization;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Base for the v1 API controllers. Centralises ETag / If-Match handling
|
||||
/// (docs/11-BACKEND-PHASE1.md §1.6) so concurrency behaviour is uniform.
|
||||
/// Each controller declares its own explicit lowercase <c>[Route]</c> to match
|
||||
/// the API contract paths (docs/11 §1.1). Every v1 endpoint requires a valid
|
||||
/// AuthHex token satisfying the ERP door policy (docs/10 A.4).
|
||||
/// </summary>
|
||||
[ApiController]
|
||||
[Produces("application/json")]
|
||||
[Authorize(JwtAuthExtensions.ErpAccessPolicy)]
|
||||
public abstract class ApiControllerBase : ControllerBase
|
||||
{
|
||||
/// <summary>Parse a mandatory <c>If-Match</c> header, or 428 if absent/malformed.</summary>
|
||||
protected uint RequireIfMatch()
|
||||
{
|
||||
var header = Request.Headers.IfMatch.ToString();
|
||||
if (!ETag.TryParse(header, out var rowVersion))
|
||||
throw new DomainException("PRECONDITION_REQUIRED", "A valid If-Match header is required for this update.", 428);
|
||||
return rowVersion;
|
||||
}
|
||||
|
||||
/// <summary>Emit the strong <c>ETag</c> response header for a row-version token.</summary>
|
||||
protected void SetETag(uint rowVersion) => Response.Headers.ETag = ETag.From(rowVersion);
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
using ERPCore.Dtos.Audit;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Read-only audit trail (FR-X-02; auditor role). Extends the documented §11 API —
|
||||
/// the audit trail is required (AR-01 compensating control) and read access is the
|
||||
/// only way to consume it.
|
||||
/// </summary>
|
||||
[Route("api/v1/audit-logs")]
|
||||
public sealed class AuditLogsController : ApiControllerBase
|
||||
{
|
||||
private readonly IAuditService _audit;
|
||||
|
||||
public AuditLogsController(IAuditService audit) => _audit = audit;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<AuditLogDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<AuditLogDto>>> List(
|
||||
[FromQuery] string? entityType, [FromQuery] int? entityId, [FromQuery] int? userId,
|
||||
[FromQuery] DateOnly? from, [FromQuery] DateOnly? to, [FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _audit.ListLogsAsync(entityType, entityId, userId, from, to, query, ct));
|
||||
}
|
||||
@@ -0,0 +1,297 @@
|
||||
using ERPCore.Dtos.Auth;
|
||||
using ERPCore.Dtos.Rbac;
|
||||
using ERPCore.Infra.Auth;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using ERPCore.System.Errors;
|
||||
using Microsoft.AspNetCore.Authorization;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Fronts the external AuthHex identity service (API_REFERENCE.md) so the
|
||||
/// frontend never calls AuthHex directly. Sessions are delivered as httpOnly
|
||||
/// Secure cookies (docs/02-SECURITY.md §B.2) via <see cref="AuthCookieWriter"/>
|
||||
/// — response bodies never carry raw tokens. Does not inherit
|
||||
/// <see cref="ApiControllerBase"/>: most actions here are pre-session and need
|
||||
/// <see cref="AllowAnonymousAttribute"/>, and the ETag/If-Match handling that
|
||||
/// base provides doesn't apply to auth flows.
|
||||
/// </summary>
|
||||
[ApiController]
|
||||
[Produces("application/json")]
|
||||
[Route("api/v1/auth")]
|
||||
[Authorize(JwtAuthExtensions.ErpAccessPolicy)]
|
||||
public sealed class AuthController : ControllerBase
|
||||
{
|
||||
private readonly IAuthUserService _users;
|
||||
private readonly IAuthRecoveryService _recovery;
|
||||
private readonly IAuthAltService _alt;
|
||||
private readonly IRoleService _roles;
|
||||
|
||||
public AuthController(IAuthUserService users, IAuthRecoveryService recovery, IAuthAltService alt, IRoleService roles)
|
||||
{
|
||||
_users = users;
|
||||
_recovery = recovery;
|
||||
_alt = alt;
|
||||
_roles = roles;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Authoritative current-session info for the frontend: role + the sidebar nav
|
||||
/// codes it may see (docs/10 C.9 shadow-Role sync). Replaces the frontend's
|
||||
/// previous reliance on a stale, untrusted `roleId` cached in localStorage.
|
||||
/// </summary>
|
||||
[HttpGet("me")]
|
||||
[ProducesResponseType(typeof(MeResponseDto), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<MeResponseDto>> Me(CancellationToken ct)
|
||||
{
|
||||
var roleCode = User.FindFirst(AuthHexClaims.RoleCode)?.Value;
|
||||
return Ok(await _roles.GetMeAsync(roleCode, ct));
|
||||
}
|
||||
|
||||
// ---- Session-issuing (UserManager) ------------------------------------
|
||||
|
||||
[HttpPost("register")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(AuthSessionResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<AuthSessionResponse>> Register([FromBody] RegisterRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _users.RegisterAsync(request, ct);
|
||||
AuthCookieWriter.WriteSession(Response, result.AccessToken, result.RefreshToken, result.Body.ExpiresIn);
|
||||
return Ok(result.Body);
|
||||
}
|
||||
|
||||
[HttpPost("login")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(AuthSessionResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<AuthSessionResponse>> Login([FromBody] LoginRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _users.LoginAsync(request, ct);
|
||||
AuthCookieWriter.WriteSession(Response, result.AccessToken, result.RefreshToken, result.Body.ExpiresIn);
|
||||
return Ok(result.Body);
|
||||
}
|
||||
|
||||
[HttpPost("login/otp/verify")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(OtpLoginVerifiedResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<OtpLoginVerifiedResponse>> VerifyLoginOtp([FromBody] VerifyOtpForLoginRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _users.VerifyOtpForLoginAsync(request, ct);
|
||||
AuthCookieWriter.WriteSession(Response, result.AccessToken, result.RefreshToken, result.Body.ExpiresIn);
|
||||
return Ok(result.Body);
|
||||
}
|
||||
|
||||
[HttpPost("refresh-token")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(AuthSessionResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<AuthSessionResponse>> RefreshToken([FromBody] RefreshTokenRequest request, CancellationToken ct)
|
||||
{
|
||||
if (!Request.Cookies.TryGetValue(JwtAuthExtensions.RefreshTokenCookie, out var refreshToken) || string.IsNullOrEmpty(refreshToken))
|
||||
throw new DomainException(ErrorCodes.RefreshTokenMissing, "No refresh session cookie present.", 401);
|
||||
|
||||
var result = await _users.RefreshTokenAsync(refreshToken, request, ct);
|
||||
AuthCookieWriter.WriteSession(Response, result.AccessToken, result.RefreshToken, result.Body.ExpiresIn);
|
||||
return Ok(result.Body);
|
||||
}
|
||||
|
||||
// ---- Profile / sessions (UserManager) ---------------------------------
|
||||
|
||||
[HttpGet("users/{userId:guid}")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(GetUserDetailsResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<GetUserDetailsResponse>> GetUserDetails(Guid userId, CancellationToken ct)
|
||||
=> Ok(await _users.GetUserDetailsAsync(userId, ct));
|
||||
|
||||
[HttpGet("sessions")]
|
||||
[ProducesResponseType(typeof(List<SessionDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<List<SessionDto>>> GetSessions(CancellationToken ct)
|
||||
=> Ok(await _users.GetUserSessionsAsync(RequireBearerToken(), ct));
|
||||
|
||||
[HttpPost("status")]
|
||||
[ValidateCsrf]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
public async Task<IActionResult> ChangeStatus([FromBody] ChangeUserStatusRequest request, CancellationToken ct)
|
||||
{
|
||||
await _users.ChangeUserStatusAsync(request, RequireBearerToken(), ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
[HttpPost("lock")]
|
||||
[ValidateCsrf]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
public async Task<IActionResult> Lock([FromBody] LockUserAccountRequest request, CancellationToken ct)
|
||||
{
|
||||
await _users.LockUserAccountAsync(request, RequireBearerToken(), ct);
|
||||
AuthCookieWriter.ClearSession(Response);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
[HttpPost("change-password")]
|
||||
[ValidateCsrf]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
public async Task<IActionResult> ChangePassword([FromBody] ChangeUserPasswordRequest request, CancellationToken ct)
|
||||
{
|
||||
await _users.ChangeUserPasswordAsync(request, RequireBearerToken(), ct);
|
||||
AuthCookieWriter.ClearSession(Response);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
[HttpPost("verify-password")]
|
||||
[ProducesResponseType(typeof(VerifyPasswordResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<VerifyPasswordResponse>> VerifyPassword([FromBody] VerifyPasswordRequest request, CancellationToken ct)
|
||||
=> Ok(await _users.VerifyPasswordAsync(request, RequireBearerToken(), ct));
|
||||
|
||||
/// <summary>
|
||||
/// Ends the session: revokes it upstream where possible, and always clears our cookies.
|
||||
/// <para>
|
||||
/// <c>userId</c> is optional because callers usually cannot supply it — AuthHex returns
|
||||
/// <c>user.userId: null</c> in its own login/register response, so a browser has no id
|
||||
/// to send. It is resolved from the session token's <c>UserId</c> claim instead.
|
||||
/// </para>
|
||||
/// <para>
|
||||
/// The cookies are cleared even if the upstream revoke fails or no user can be
|
||||
/// resolved: a logout that leaves the caller holding a live session cookie is worse
|
||||
/// than one that leaves a stale session server-side (which lapses on its own).
|
||||
/// </para>
|
||||
/// </summary>
|
||||
[HttpPost("logout")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
public async Task<IActionResult> Logout([FromBody] LogoutRequest? request, CancellationToken ct)
|
||||
{
|
||||
var userId = request?.UserId ?? ResolveTokenUserId();
|
||||
if (userId is not null)
|
||||
{
|
||||
try
|
||||
{
|
||||
await _users.LogoutUserAsync(new LogoutRequest { UserId = userId.Value }, ct);
|
||||
}
|
||||
catch (DomainException)
|
||||
{
|
||||
// Upstream unreachable or already-revoked — fall through and clear anyway.
|
||||
}
|
||||
}
|
||||
|
||||
AuthCookieWriter.ClearSession(Response);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
/// <summary>AuthHex's identity claim, present when the request carried a valid session.</summary>
|
||||
private Guid? ResolveTokenUserId()
|
||||
=> Guid.TryParse(User.FindFirst(AuthHexClaims.UserId)?.Value, out var id) ? id : null;
|
||||
|
||||
[HttpPut("me")]
|
||||
[ValidateCsrf]
|
||||
[ProducesResponseType(typeof(UserSummaryDto), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<UserSummaryDto?>> UpdateMe([FromBody] UpdateUserRequest request, CancellationToken ct)
|
||||
=> Ok(await _users.UpdateUserAsync(request, RequireBearerToken(), ct));
|
||||
|
||||
// ---- 2FA (UserManager) -------------------------------------------------
|
||||
|
||||
[HttpPost("2fa/initiate")]
|
||||
[ValidateCsrf]
|
||||
[ProducesResponseType(typeof(TwoFaSetupResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<TwoFaSetupResponse>> InitiateTwoFa(CancellationToken ct)
|
||||
=> Ok(await _users.InitiateTwoFaSetupAsync(RequireBearerToken(), ct));
|
||||
|
||||
[HttpPost("2fa/complete")]
|
||||
[ValidateCsrf]
|
||||
[ProducesResponseType(typeof(CompleteTwoFaSetupResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<CompleteTwoFaSetupResponse>> CompleteTwoFa([FromBody] CompleteTwoFaSetupRequest request, CancellationToken ct)
|
||||
=> Ok(await _users.CompleteTwoFaSetupAsync(request, RequireBearerToken(), ct));
|
||||
|
||||
[HttpPost("2fa/verify")]
|
||||
[ValidateCsrf]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
public async Task<IActionResult> VerifyTwoFa([FromBody] VerifyTwoFaRequest request, CancellationToken ct)
|
||||
{
|
||||
await _users.VerifyTwoFaAsync(request, RequireBearerToken(), ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
[HttpPost("2fa/disable")]
|
||||
[ValidateCsrf]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
public async Task<IActionResult> DisableTwoFa([FromBody] DisableTwoFaRequest request, CancellationToken ct)
|
||||
{
|
||||
await _users.DisableTwoFaAsync(request, RequireBearerToken(), ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
[HttpGet("2fa/status")]
|
||||
[ProducesResponseType(typeof(TwoFaStatusResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<TwoFaStatusResponse>> GetTwoFaStatus(CancellationToken ct)
|
||||
=> Ok(await _users.GetTwoFaStatusAsync(RequireBearerToken(), ct));
|
||||
|
||||
// ---- Recovery -----------------------------------------------------------
|
||||
|
||||
[HttpPost("recovery/forgot-password")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(ForgotPasswordResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<ForgotPasswordResponse>> ForgotPassword([FromBody] ForgotPasswordRequest request, CancellationToken ct)
|
||||
=> Ok(await _recovery.ForgotPasswordAsync(request, ct));
|
||||
|
||||
[HttpPost("recovery/verify-otp")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(VerifyRecoveryOtpResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<VerifyRecoveryOtpResponse>> VerifyRecoveryOtp([FromBody] VerifyRecoveryOtpRequest request, CancellationToken ct)
|
||||
=> Ok(await _recovery.VerifyOtpAsync(request, ct));
|
||||
|
||||
[HttpPost("recovery/reset-password")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
public async Task<IActionResult> ResetPassword([FromBody] ResetPasswordRequest request, CancellationToken ct)
|
||||
{
|
||||
await _recovery.ResetPasswordAsync(request, ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
[HttpPost("recovery/reset-password-token")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
public async Task<IActionResult> ResetPasswordWithToken([FromBody] ResetPasswordWithTokenRequest request, CancellationToken ct)
|
||||
{
|
||||
await _recovery.ResetPasswordWithTokenAsync(request, ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
// ---- Availability / OTP (AltOptionManager) -----------------------------
|
||||
|
||||
[HttpPost("availability")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(IsAvailableResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<IsAvailableResponse>> CheckAvailability([FromBody] IsAvailableRequest request, CancellationToken ct)
|
||||
=> Ok(await _alt.IsAvailableAsync(request, ct));
|
||||
|
||||
[HttpPost("otp/send")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(SendOtpResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<SendOtpResponse>> SendOtp([FromBody] SendOtpRequest request, CancellationToken ct)
|
||||
=> Ok(await _alt.SendOtpAsync(request, ct));
|
||||
|
||||
[HttpPost("otp/verify")]
|
||||
[AllowAnonymous]
|
||||
[ProducesResponseType(typeof(OtpLoginVerifiedResponse), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<OtpLoginVerifiedResponse>> VerifyAltOtp([FromBody] VerifyAltOtpRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _alt.VerifyOtpAsync(request, ct);
|
||||
AuthCookieWriter.WriteSession(Response, result.AccessToken, result.RefreshToken, result.Body.ExpiresIn);
|
||||
return Ok(result.Body);
|
||||
}
|
||||
|
||||
// ---- Helpers --------------------------------------------------------------
|
||||
|
||||
/// <summary>The token that authenticated this request — Bearer header if present, else the session cookie.</summary>
|
||||
private string RequireBearerToken()
|
||||
{
|
||||
var header = Request.Headers.Authorization.ToString();
|
||||
if (!string.IsNullOrEmpty(header) && header.StartsWith("Bearer ", StringComparison.OrdinalIgnoreCase))
|
||||
return header["Bearer ".Length..];
|
||||
|
||||
if (Request.Cookies.TryGetValue(JwtAuthExtensions.AccessTokenCookie, out var cookieToken) && !string.IsNullOrEmpty(cookieToken))
|
||||
return cookieToken;
|
||||
|
||||
// [Authorize] already guaranteed one of the above was present to authenticate this request.
|
||||
throw new DomainException(ErrorCodes.AuthUpstreamError, "No bearer token found on an authenticated request.", 500);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,67 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Brands;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Brand master endpoints (docs/11-BACKEND-PHASE1.md §2.6).</summary>
|
||||
[Route("api/v1/brands")]
|
||||
public sealed class BrandsController : ApiControllerBase
|
||||
{
|
||||
private readonly IBrandService _brands;
|
||||
|
||||
public BrandsController(IBrandService brands) => _brands = brands;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<BrandDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<BrandDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] EntityStatus? status, CancellationToken ct)
|
||||
=> Ok(await _brands.ListAsync(query, status, ct));
|
||||
|
||||
[HttpGet("{brandId:int}")]
|
||||
[ProducesResponseType(typeof(BrandDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<BrandDto>> GetById(int brandId, CancellationToken ct)
|
||||
{
|
||||
var result = await _brands.GetAsync(brandId, ct);
|
||||
if (result is null) return NotFound();
|
||||
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(BrandDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<BrandDto>> Create([FromBody] CreateBrandRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _brands.CreateAsync(request, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Created($"/api/v1/brands/{result.Value.BrandId}", result.Value);
|
||||
}
|
||||
|
||||
[HttpPut("{brandId:int}")]
|
||||
[ProducesResponseType(typeof(BrandDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<BrandDto>> Update(int brandId, [FromBody] UpdateBrandRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _brands.UpdateAsync(brandId, request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Deactivate/reactivate. Masters are never hard-deleted (FR-MD-08).</summary>
|
||||
[HttpPatch("{brandId:int}/status")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<IActionResult> SetStatus(int brandId, [FromBody] UpdateBrandStatusRequest request, CancellationToken ct)
|
||||
{
|
||||
await _brands.SetStatusAsync(brandId, request.Status, ct);
|
||||
return NoContent();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,96 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Categories;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Category endpoints (docs/11-BACKEND-PHASE1.md §2.3), including the subcategories
|
||||
/// nested beneath each category. The hierarchy is exactly two levels deep — the old
|
||||
/// <c>?tree=true</c> parameter is gone along with the self-nesting model.
|
||||
/// </summary>
|
||||
[Route("api/v1/categories")]
|
||||
public sealed class CategoriesController : ApiControllerBase
|
||||
{
|
||||
private readonly ICategoryService _categories;
|
||||
|
||||
public CategoriesController(ICategoryService categories) => _categories = categories;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<CategoryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<CategoryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] EntityStatus? status, CancellationToken ct)
|
||||
=> Ok(await _categories.ListAsync(query, status, ct));
|
||||
|
||||
[HttpGet("{categoryId:int}")]
|
||||
[ProducesResponseType(typeof(CategoryDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<CategoryDto>> GetById(int categoryId, CancellationToken ct)
|
||||
{
|
||||
var result = await _categories.GetAsync(categoryId, ct);
|
||||
if (result is null) return NotFound();
|
||||
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(CategoryDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<CategoryDto>> Create([FromBody] CreateCategoryRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _categories.CreateAsync(request, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Created($"/api/v1/categories/{result.Value.CategoryId}", result.Value);
|
||||
}
|
||||
|
||||
[HttpPut("{categoryId:int}")]
|
||||
[ProducesResponseType(typeof(CategoryDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<CategoryDto>> Update(
|
||||
int categoryId, [FromBody] UpdateCategoryRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _categories.UpdateAsync(categoryId, request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Deactivate/reactivate. Masters are never hard-deleted (FR-MD-08).</summary>
|
||||
[HttpPatch("{categoryId:int}/status")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<IActionResult> SetStatus(
|
||||
int categoryId, [FromBody] UpdateCategoryStatusRequest request, CancellationToken ct)
|
||||
{
|
||||
await _categories.SetStatusAsync(categoryId, request.Status, ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
// Subcategories — nested under their parent category (docs/11 §2.3).
|
||||
// Updates live on SubCategoriesController at /api/v1/subcategories/{id}.
|
||||
|
||||
[HttpGet("{categoryId:int}/subcategories")]
|
||||
[ProducesResponseType(typeof(PagedResponse<SubCategoryDto>), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<PagedResponse<SubCategoryDto>>> ListSubCategories(
|
||||
int categoryId, [FromQuery] PageQuery query, [FromQuery] EntityStatus? status, CancellationToken ct)
|
||||
=> Ok(await _categories.ListSubCategoriesAsync(categoryId, query, status, ct));
|
||||
|
||||
[HttpPost("{categoryId:int}/subcategories")]
|
||||
[ProducesResponseType(typeof(SubCategoryDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<SubCategoryDto>> CreateSubCategory(
|
||||
int categoryId, [FromBody] CreateSubCategoryRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _categories.CreateSubCategoryAsync(categoryId, request, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Created($"/api/v1/subcategories/{result.Value.SubCategoryId}", result.Value);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,62 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Grn;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Goods-receipt endpoints (docs/11 §4).</summary>
|
||||
[Route("api/v1/grns")]
|
||||
public sealed class GrnsController : ApiControllerBase
|
||||
{
|
||||
private readonly IGrnService _grns;
|
||||
|
||||
public GrnsController(IGrnService grns) => _grns = grns;
|
||||
|
||||
/// <summary>List GRNs, newest first.</summary>
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<GrnSummaryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<GrnSummaryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] GrnStatus? status, [FromQuery] int? poId,
|
||||
[FromQuery] int? vendorId, [FromQuery] int? warehouseId, CancellationToken ct)
|
||||
=> Ok(await _grns.ListAsync(query, status, poId, vendorId, warehouseId, ct));
|
||||
|
||||
[HttpGet("{grnId:int}")]
|
||||
[ProducesResponseType(typeof(GrnDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<GrnDto>> GetById(int grnId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _grns.GetAsync(grnId, ct);
|
||||
return dto is null ? NotFound() : Ok(dto);
|
||||
}
|
||||
|
||||
/// <summary>Create a Draft GRN against a PO or direct. Cost is PO-derived for PO lines.</summary>
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(GrnDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<GrnDto>> Create([FromBody] CreateGrnRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _grns.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/grns/{dto.GrnId}", dto);
|
||||
}
|
||||
|
||||
/// <summary>Confirm: create FIFO layers + inbound ledger + update PO receipts (single UoW txn).</summary>
|
||||
[HttpPost("{grnId:int}/confirm")]
|
||||
[ProducesResponseType(typeof(GrnConfirmResultDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<GrnConfirmResultDto>> Confirm(
|
||||
int grnId, [FromHeader(Name = "Idempotency-Key")] string? idempotencyKey, CancellationToken ct)
|
||||
=> Ok(await _grns.ConfirmAsync(grnId, idempotencyKey, ct));
|
||||
|
||||
/// <summary>Release or reject an inspection-hold line (FR-GRN-05).</summary>
|
||||
[HttpPost("{grnId:int}/lines/{grnLineId:int}/release")]
|
||||
[ProducesResponseType(typeof(ReleaseLineResultDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<ReleaseLineResultDto>> Release(
|
||||
int grnId, int grnLineId, [FromBody] ReleaseLineRequest request, CancellationToken ct)
|
||||
=> Ok(await _grns.ReleaseLineAsync(grnId, grnLineId, request.Action, ct));
|
||||
}
|
||||
@@ -0,0 +1,73 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.ItemTypes;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Item type master endpoints (docs/11-BACKEND-PHASE1.md §2.7) — the Color/Size/Material
|
||||
/// dimension names. <c>GET</c> is the reason this master exists: it populates the item
|
||||
/// builder's dropdown. Items never reference an item type; the chosen values are encoded
|
||||
/// into the client-generated SKU (docs/10 Part C.9).
|
||||
/// </summary>
|
||||
[Route("api/v1/item-types")]
|
||||
public sealed class ItemTypesController : ApiControllerBase
|
||||
{
|
||||
private readonly IItemTypeService _itemTypes;
|
||||
|
||||
public ItemTypesController(IItemTypeService itemTypes) => _itemTypes = itemTypes;
|
||||
|
||||
/// <summary>Feeds the frontend item-builder dropdown; filter <c>status=Active</c> for selectable rows.</summary>
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<ItemTypeDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<ItemTypeDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] EntityStatus? status, CancellationToken ct)
|
||||
=> Ok(await _itemTypes.ListAsync(query, status, ct));
|
||||
|
||||
[HttpGet("{itemTypeId:int}")]
|
||||
[ProducesResponseType(typeof(ItemTypeDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<ItemTypeDto>> GetById(int itemTypeId, CancellationToken ct)
|
||||
{
|
||||
var result = await _itemTypes.GetAsync(itemTypeId, ct);
|
||||
if (result is null) return NotFound();
|
||||
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(ItemTypeDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<ItemTypeDto>> Create([FromBody] CreateItemTypeRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _itemTypes.CreateAsync(request, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Created($"/api/v1/item-types/{result.Value.ItemTypeId}", result.Value);
|
||||
}
|
||||
|
||||
[HttpPut("{itemTypeId:int}")]
|
||||
[ProducesResponseType(typeof(ItemTypeDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<ItemTypeDto>> Update(int itemTypeId, [FromBody] UpdateItemTypeRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _itemTypes.UpdateAsync(itemTypeId, request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Deactivate/reactivate. Masters are never hard-deleted (FR-MD-08).</summary>
|
||||
[HttpPatch("{itemTypeId:int}/status")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<IActionResult> SetStatus(int itemTypeId, [FromBody] UpdateItemTypeStatusRequest request, CancellationToken ct)
|
||||
{
|
||||
await _itemTypes.SetStatusAsync(itemTypeId, request.Status, ct);
|
||||
return NoContent();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,91 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Items;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Item master endpoints (docs/11-BACKEND-PHASE1.md §2.1–2.2).</summary>
|
||||
[Route("api/v1/items")]
|
||||
public sealed class ItemsController : ApiControllerBase
|
||||
{
|
||||
private readonly IItemService _items;
|
||||
|
||||
public ItemsController(IItemService items) => _items = items;
|
||||
|
||||
/// <summary>List items with optional filters and paging.</summary>
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<ItemListItemDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<ItemListItemDto>>> List(
|
||||
[FromQuery] PageQuery query,
|
||||
[FromQuery] EntityStatus? status,
|
||||
[FromQuery] int? categoryId,
|
||||
[FromQuery] int? subCategoryId,
|
||||
[FromQuery] int? brandId,
|
||||
[FromQuery] TrackingMode? trackingMode,
|
||||
CancellationToken ct)
|
||||
=> Ok(await _items.ListAsync(query, status, categoryId, subCategoryId, brandId, trackingMode, ct));
|
||||
|
||||
/// <summary>Get a single item; returns an <c>ETag</c> for optimistic concurrency.</summary>
|
||||
[HttpGet("{itemId:int}")]
|
||||
[ProducesResponseType(typeof(ItemDetailDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<ItemDetailDto>> GetById(int itemId, CancellationToken ct)
|
||||
{
|
||||
var result = await _items.GetAsync(itemId, ct);
|
||||
if (result is null) return NotFound();
|
||||
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Create an item (SKU unique). Server sets status and timestamps.</summary>
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(ItemDetailDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status400BadRequest)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<ItemDetailDto>> Create([FromBody] CreateItemRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _items.CreateAsync(request, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Created($"/api/v1/items/{result.Value.ItemId}", result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Full update; requires <c>If-Match</c> (412 on stale ETag).</summary>
|
||||
[HttpPut("{itemId:int}")]
|
||||
[ProducesResponseType(typeof(ItemDetailDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<ItemDetailDto>> Update(int itemId, [FromBody] UpdateItemRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _items.UpdateAsync(itemId, request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Activate / deactivate the item (FR-MD-08 — deactivate, not delete).</summary>
|
||||
[HttpPatch("{itemId:int}/status")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<IActionResult> SetStatus(int itemId, [FromBody] UpdateItemStatusRequest request, CancellationToken ct)
|
||||
{
|
||||
await _items.SetStatusAsync(itemId, request.Status, ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
/// <summary>Replace the item's per-warehouse reorder settings (FR-MD-05).</summary>
|
||||
[HttpPut("{itemId:int}/reorder")]
|
||||
[ProducesResponseType(typeof(ItemReorderSettingsDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<ItemReorderSettingsDto>> UpdateReorder(int itemId, [FromBody] UpdateReorderRequest request, CancellationToken ct)
|
||||
=> Ok(await _items.UpdateReorderAsync(itemId, request, ct));
|
||||
|
||||
/// <summary>Replace the item's UOM conversions (FR-MD-02).</summary>
|
||||
[HttpPut("{itemId:int}/uom-conversions")]
|
||||
[ProducesResponseType(typeof(ItemUomConversionsDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<ItemUomConversionsDto>> UpdateUomConversions(int itemId, [FromBody] UpdateUomConversionsRequest request, CancellationToken ct)
|
||||
=> Ok(await _items.UpdateUomConversionsAsync(itemId, request, ct));
|
||||
}
|
||||
@@ -0,0 +1,24 @@
|
||||
using ERPCore.Dtos.Audit;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Read-only GL-ready journal stubs (FR-STK-13; consumed by the Accounting phase).
|
||||
/// Data only — no posting in Phase 1.
|
||||
/// </summary>
|
||||
[Route("api/v1/journal-entries")]
|
||||
public sealed class JournalEntriesController : ApiControllerBase
|
||||
{
|
||||
private readonly IAuditService _audit;
|
||||
|
||||
public JournalEntriesController(IAuditService audit) => _audit = audit;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<JournalEntryStubDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<JournalEntryStubDto>>> List(
|
||||
[FromQuery] string? sourceDocType, [FromQuery] int? sourceDocId, [FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _audit.ListJournalAsync(sourceDocType, sourceDocId, query, ct));
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
using ERPCore.Domain.Entities;
|
||||
using ERPCore.Dtos.Rbac;
|
||||
using ERPCore.Repositories.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
using Microsoft.EntityFrameworkCore;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Read-only sidebar nav tree, used by the Role permission-assignment checkbox
|
||||
/// UI and by `GET /auth/me` (see AuthController) to resolve a role's visible codes.
|
||||
/// NavItem/SubNavItem rows are seeded (NavItemConfiguration/SubNavItemConfiguration)
|
||||
/// to match the frontend's hardcoded sidebar — not admin-editable in this phase.
|
||||
/// </summary>
|
||||
[Route("api/v1/nav")]
|
||||
public sealed class NavController : ApiControllerBase
|
||||
{
|
||||
private readonly IRepository<NavItem> _navItems;
|
||||
|
||||
public NavController(IRepository<NavItem> navItems) => _navItems = navItems;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(List<NavItemDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<List<NavItemDto>>> GetTree(CancellationToken ct)
|
||||
{
|
||||
var items = await _navItems.Query().AsNoTracking()
|
||||
.Include(n => n.Children)
|
||||
.OrderBy(n => n.SortOrder)
|
||||
.ToListAsync(ct);
|
||||
|
||||
var dto = items.Select(n => new NavItemDto(
|
||||
n.NavItemId, n.Code, n.Label, n.Icon, n.Href, n.SortOrder,
|
||||
n.Children.OrderBy(c => c.SortOrder)
|
||||
.Select(c => new SubNavItemDto(c.SubNavItemId, c.Code, c.Label, c.Icon, c.Href, c.SortOrder))
|
||||
.ToList())).ToList();
|
||||
|
||||
return Ok(dto);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
using ERPCore.Dtos.Config;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Product configuration endpoints (docs/11-BACKEND-PHASE1.md §2.8) — the singleton
|
||||
/// feature gate for subcategories/brands/item-types.
|
||||
/// <para>
|
||||
/// <b>Authorization:</b> writes are admitted by the inherited ERP door policy only.
|
||||
/// A dedicated <c>CONFIG_MANAGE</c> permission is reserved for when per-endpoint RBAC
|
||||
/// lands (FR-X-01, currently deferred) — at that point this action gets the attribute
|
||||
/// with no other change. Until then any ERP-admitted user can flip these flags; that is
|
||||
/// the accepted Phase-1 posture, consistent with every other endpoint.
|
||||
/// </para>
|
||||
/// </summary>
|
||||
[Route("api/v1/product-config")]
|
||||
public sealed class ProductConfigController : ApiControllerBase
|
||||
{
|
||||
private readonly IProductConfigService _config;
|
||||
|
||||
public ProductConfigController(IProductConfigService config) => _config = config;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(ProductConfigDto), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<ProductConfigDto>> Get(CancellationToken ct)
|
||||
{
|
||||
var result = await _config.GetAsync(ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
[HttpPut]
|
||||
[ProducesResponseType(typeof(ProductConfigDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status400BadRequest)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<ProductConfigDto>> Update(
|
||||
[FromBody] UpdateProductConfigRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _config.UpdateAsync(request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,93 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Procurement;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Purchase-order endpoints (docs/11 §3.3).</summary>
|
||||
[Route("api/v1/purchase-orders")]
|
||||
public sealed class PurchaseOrdersController : ApiControllerBase
|
||||
{
|
||||
private readonly IPurchaseOrderService _pos;
|
||||
|
||||
public PurchaseOrdersController(IPurchaseOrderService pos) => _pos = pos;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<PurchaseOrderSummaryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<PurchaseOrderSummaryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] PurchaseOrderStatus? status, [FromQuery] int? vendorId, CancellationToken ct)
|
||||
=> Ok(await _pos.ListAsync(query, status, vendorId, ct));
|
||||
|
||||
[HttpGet("{poId:int}")]
|
||||
[ProducesResponseType(typeof(PurchaseOrderDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<PurchaseOrderDto>> GetById(int poId, CancellationToken ct)
|
||||
{
|
||||
var result = await _pos.GetAsync(poId, ct);
|
||||
if (result is null) return NotFound();
|
||||
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Create a PO — auto-approved on creation in Phase 1 (FR-PROC-04). Totals computed server-side.</summary>
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(PurchaseOrderDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<PurchaseOrderDto>> Create([FromBody] CreatePurchaseOrderRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _pos.CreateAsync(request, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Created($"/api/v1/purchase-orders/{result.Value.PoId}", result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Edit while open (FR-PROC-05); requires <c>If-Match</c>. 409 PO_NOT_EDITABLE if closed.</summary>
|
||||
[HttpPut("{poId:int}")]
|
||||
[ProducesResponseType(typeof(PurchaseOrderDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<PurchaseOrderDto>> Update(int poId, [FromBody] UpdatePurchaseOrderRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _pos.UpdateAsync(poId, request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Submit a Draft PO (Draft → Approved). 409 PO_NOT_EDITABLE if not Draft.</summary>
|
||||
[HttpPost("{poId:int}/submit")]
|
||||
[ProducesResponseType(typeof(PurchaseOrderDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<PurchaseOrderDto>> Submit(int poId, CancellationToken ct)
|
||||
=> Ok(await _pos.SubmitAsync(poId, ct));
|
||||
|
||||
/// <summary>Delete a PO — permitted only while Draft (409 PO_NOT_EDITABLE otherwise).</summary>
|
||||
[HttpDelete("{poId:int}")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<IActionResult> Delete(int poId, CancellationToken ct)
|
||||
{
|
||||
await _pos.DeleteAsync(poId, ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
/// <summary>Approve — no-op in Phase 1 (POs auto-approve); transitions PendingApproval→Approved when enabled.</summary>
|
||||
[HttpPost("{poId:int}/approve")]
|
||||
[ProducesResponseType(typeof(PurchaseOrderDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<PurchaseOrderDto>> Approve(int poId, CancellationToken ct)
|
||||
=> Ok(await _pos.ApproveAsync(poId, ct));
|
||||
|
||||
/// <summary>Cancel — 409 if any goods have been received against the PO.</summary>
|
||||
[HttpPost("{poId:int}/cancel")]
|
||||
[ProducesResponseType(typeof(PurchaseOrderDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<PurchaseOrderDto>> Cancel(int poId, [FromBody] CancelPurchaseOrderRequest request, CancellationToken ct)
|
||||
=> Ok(await _pos.CancelAsync(poId, request.Reason, ct));
|
||||
}
|
||||
@@ -0,0 +1,44 @@
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Procurement;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Purchase-return endpoints (docs/11 §3.4).</summary>
|
||||
[Route("api/v1/purchase-returns")]
|
||||
public sealed class PurchaseReturnsController : ApiControllerBase
|
||||
{
|
||||
private readonly IPurchaseReturnService _returns;
|
||||
|
||||
public PurchaseReturnsController(IPurchaseReturnService returns) => _returns = returns;
|
||||
|
||||
/// <summary>List posted returns, newest first.</summary>
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<PurchaseReturnSummaryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<PurchaseReturnSummaryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] int? vendorId, [FromQuery] int? warehouseId, CancellationToken ct)
|
||||
=> Ok(await _returns.ListAsync(query, vendorId, warehouseId, ct));
|
||||
|
||||
/// <summary>Get one return with its lines and the ledger entries it posted.</summary>
|
||||
[HttpGet("{returnId:int}")]
|
||||
[ProducesResponseType(typeof(PurchaseReturnDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<PurchaseReturnDto>> GetById(int returnId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _returns.GetAsync(returnId, ct);
|
||||
return dto is null ? NotFound() : Ok(dto);
|
||||
}
|
||||
|
||||
/// <summary>Create + auto-post a return (outbound movement). 409 if return exceeds available stock.</summary>
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(PurchaseReturnDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status400BadRequest)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<PurchaseReturnDto>> Create([FromBody] CreatePurchaseReturnRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _returns.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/purchase-returns/{dto.ReturnId}", dto);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Reference;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Reason-code reference endpoints (docs/11 §6).</summary>
|
||||
[Route("api/v1/reason-codes")]
|
||||
public sealed class ReasonCodesController : ApiControllerBase
|
||||
{
|
||||
private readonly IReasonCodeService _codes;
|
||||
|
||||
public ReasonCodesController(IReasonCodeService codes) => _codes = codes;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<ReasonCodeDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<ReasonCodeDto>>> List(
|
||||
[FromQuery] ReasonContext? context, [FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _codes.ListAsync(context, query, ct));
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(ReasonCodeDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<ReasonCodeDto>> Create([FromBody] CreateReasonCodeRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _codes.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/reason-codes/{dto.ReasonCodeId}", dto);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Procurement;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Purchase-requisition endpoints (docs/11 §3.1).</summary>
|
||||
[Route("api/v1/requisitions")]
|
||||
public sealed class RequisitionsController : ApiControllerBase
|
||||
{
|
||||
private readonly IRequisitionService _requisitions;
|
||||
|
||||
public RequisitionsController(IRequisitionService requisitions) => _requisitions = requisitions;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<RequisitionSummaryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<RequisitionSummaryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] RequisitionStatus? status, CancellationToken ct)
|
||||
=> Ok(await _requisitions.ListAsync(query, status, ct));
|
||||
|
||||
[HttpGet("{requisitionId:int}")]
|
||||
[ProducesResponseType(typeof(RequisitionDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<RequisitionDto>> GetById(int requisitionId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _requisitions.GetAsync(requisitionId, ct);
|
||||
return dto is null ? NotFound() : Ok(dto);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(RequisitionDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<RequisitionDto>> Create([FromBody] CreateRequisitionRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _requisitions.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/requisitions/{dto.RequisitionId}", dto);
|
||||
}
|
||||
|
||||
[HttpPost("{requisitionId:int}/submit")]
|
||||
[ProducesResponseType(typeof(RequisitionDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<RequisitionDto>> Submit(int requisitionId, CancellationToken ct)
|
||||
=> Ok(await _requisitions.SubmitAsync(requisitionId, ct));
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Procurement;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>RFQ & quotation endpoints (docs/11 §3.2).</summary>
|
||||
[Route("api/v1/rfqs")]
|
||||
public sealed class RfqsController : ApiControllerBase
|
||||
{
|
||||
private readonly IRfqService _rfqs;
|
||||
|
||||
public RfqsController(IRfqService rfqs) => _rfqs = rfqs;
|
||||
|
||||
/// <summary>List RFQs, newest first.</summary>
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<RfqSummaryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<RfqSummaryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] RfqStatus? status, CancellationToken ct)
|
||||
=> Ok(await _rfqs.ListAsync(query, status, ct));
|
||||
|
||||
[HttpGet("{rfqId:int}")]
|
||||
[ProducesResponseType(typeof(RfqDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<RfqDto>> GetById(int rfqId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _rfqs.GetAsync(rfqId, ct);
|
||||
return dto is null ? NotFound() : Ok(dto);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(RfqDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<RfqDto>> Create([FromBody] CreateRfqRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _rfqs.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/rfqs/{dto.RfqId}", dto);
|
||||
}
|
||||
|
||||
[HttpPost("{rfqId:int}/quotations")]
|
||||
[ProducesResponseType(typeof(VendorQuotationDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<VendorQuotationDto>> AddQuotation(int rfqId, [FromBody] CreateQuotationRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _rfqs.AddQuotationAsync(rfqId, request, ct);
|
||||
return Created($"/api/v1/rfqs/{rfqId}/quotations/{dto.QuotationId}", dto);
|
||||
}
|
||||
|
||||
[HttpGet("{rfqId:int}/comparison")]
|
||||
[ProducesResponseType(typeof(RfqComparisonDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<RfqComparisonDto>> Comparison(int rfqId, CancellationToken ct)
|
||||
=> Ok(await _rfqs.GetComparisonAsync(rfqId, ct));
|
||||
}
|
||||
@@ -0,0 +1,88 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Rbac;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Role CRUD + permission assignment (mirrors AuthHex's Role; see docs/10 C.9).</summary>
|
||||
[Route("api/v1/roles")]
|
||||
public sealed class RolesController : ApiControllerBase
|
||||
{
|
||||
private readonly IRoleService _roles;
|
||||
|
||||
public RolesController(IRoleService roles) => _roles = roles;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<RoleDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<RoleDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] EntityStatus? status, CancellationToken ct)
|
||||
=> Ok(await _roles.ListAsync(query, status, ct));
|
||||
|
||||
[HttpGet("{roleId:int}")]
|
||||
[ProducesResponseType(typeof(RoleDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<RoleDto>> GetById(int roleId, CancellationToken ct)
|
||||
{
|
||||
var result = await _roles.GetAsync(roleId, ct);
|
||||
if (result is null) return NotFound();
|
||||
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(RoleDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<RoleDto>> Create([FromBody] CreateRoleRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _roles.CreateAsync(request, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Created($"/api/v1/roles/{result.Value.RoleId}", result.Value);
|
||||
}
|
||||
|
||||
[HttpPut("{roleId:int}")]
|
||||
[ProducesResponseType(typeof(RoleDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<RoleDto>> Update(int roleId, [FromBody] UpdateRoleRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _roles.UpdateAsync(roleId, request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
[HttpPatch("{roleId:int}/status")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<IActionResult> SetStatus(int roleId, [FromBody] UpdateRoleStatusRequest request, CancellationToken ct)
|
||||
{
|
||||
await _roles.SetStatusAsync(roleId, request.Status, ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
[HttpDelete("{roleId:int}")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<IActionResult> Delete(int roleId, CancellationToken ct)
|
||||
{
|
||||
await _roles.DeleteAsync(roleId, ct);
|
||||
return NoContent();
|
||||
}
|
||||
|
||||
[HttpGet("{roleId:int}/permissions")]
|
||||
[ProducesResponseType(typeof(RolePermissionsDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<RolePermissionsDto>> GetPermissions(int roleId, CancellationToken ct)
|
||||
=> Ok(await _roles.GetPermissionsAsync(roleId, ct));
|
||||
|
||||
[HttpPut("{roleId:int}/permissions")]
|
||||
[ProducesResponseType(typeof(RolePermissionsDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<RolePermissionsDto>> AssignPermissions(
|
||||
int roleId, [FromBody] AssignRolePermissionsRequest request, CancellationToken ct)
|
||||
=> Ok(await _roles.AssignPermissionsAsync(roleId, request, ct));
|
||||
}
|
||||
@@ -0,0 +1,44 @@
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Stock;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Stock-adjustment endpoints (docs/11 §5.5).</summary>
|
||||
[Route("api/v1/stock-adjustments")]
|
||||
public sealed class StockAdjustmentsController : ApiControllerBase
|
||||
{
|
||||
private readonly IAdjustmentService _adjustments;
|
||||
|
||||
public StockAdjustmentsController(IAdjustmentService adjustments) => _adjustments = adjustments;
|
||||
|
||||
/// <summary>List posted adjustments, newest first.</summary>
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<AdjustmentSummaryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<AdjustmentSummaryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] int? warehouseId, [FromQuery] int? reasonCodeId, CancellationToken ct)
|
||||
=> Ok(await _adjustments.ListAsync(query, warehouseId, reasonCodeId, ct));
|
||||
|
||||
/// <summary>Get one adjustment with its lines and the ledger entries it posted.</summary>
|
||||
[HttpGet("{adjustmentId:int}")]
|
||||
[ProducesResponseType(typeof(AdjustmentDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<AdjustmentDto>> GetById(int adjustmentId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _adjustments.GetAsync(adjustmentId, ct);
|
||||
return dto is null ? NotFound() : Ok(dto);
|
||||
}
|
||||
|
||||
/// <summary>Create + auto-post an adjustment (mandatory reason code; decrease FIFO-consumes).</summary>
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(AdjustmentDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status400BadRequest)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<AdjustmentDto>> Create([FromBody] CreateAdjustmentRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _adjustments.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/stock-adjustments/{dto.AdjustmentId}", dto);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,70 @@
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Procurement;
|
||||
using ERPCore.Dtos.Stock;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Stock enquiry, ledger, valuation and reorder-alert endpoints (docs/11 §5.1–5.3, §5.7).</summary>
|
||||
[Route("api/v1/stock")]
|
||||
public sealed class StockController : ApiControllerBase
|
||||
{
|
||||
private readonly IStockService _stock;
|
||||
private readonly IReorderService _reorder;
|
||||
|
||||
public StockController(IStockService stock, IReorderService reorder)
|
||||
{
|
||||
_stock = stock;
|
||||
_reorder = reorder;
|
||||
}
|
||||
|
||||
[HttpGet("on-hand")]
|
||||
[ProducesResponseType(typeof(StockOnHandDto), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<StockOnHandDto>> OnHand([FromQuery] int itemId, [FromQuery] int warehouseId, CancellationToken ct)
|
||||
=> Ok(await _stock.GetOnHandAsync(itemId, warehouseId, ct));
|
||||
|
||||
/// <summary>On-hand across every stocked (item, warehouse) pair; both filters optional.</summary>
|
||||
[HttpGet("on-hand/list")]
|
||||
[ProducesResponseType(typeof(PagedResponse<StockOnHandDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<StockOnHandDto>>> OnHandList(
|
||||
[FromQuery] int? itemId, [FromQuery] int? warehouseId, [FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _stock.GetOnHandListAsync(itemId, warehouseId, query, ct));
|
||||
|
||||
/// <summary>
|
||||
/// Immutable movement history. <c>sourceDocType</c>/<c>sourceDocId</c> answer "what did
|
||||
/// this document post?" — the ledger's document reference is polymorphic, so there is
|
||||
/// no FK to navigate instead (docs/10 C.9).
|
||||
/// </summary>
|
||||
[HttpGet("ledger")]
|
||||
[ProducesResponseType(typeof(PagedResponse<StockLedgerRowDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<StockLedgerRowDto>>> Ledger(
|
||||
[FromQuery] int? itemId, [FromQuery] int? warehouseId,
|
||||
[FromQuery] DateOnly? from, [FromQuery] DateOnly? to,
|
||||
[FromQuery] string? sourceDocType, [FromQuery] int? sourceDocId,
|
||||
[FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _stock.GetLedgerAsync(itemId, warehouseId, from, to, sourceDocType, sourceDocId, query, ct));
|
||||
|
||||
[HttpGet("valuation")]
|
||||
[ProducesResponseType(typeof(StockValuationDto), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<StockValuationDto>> Valuation([FromQuery] int itemId, [FromQuery] int warehouseId, CancellationToken ct)
|
||||
=> Ok(await _stock.GetValuationAsync(itemId, warehouseId, ct));
|
||||
|
||||
/// <summary>Items at/below their reorder point (FR-STK-10), computed on read.</summary>
|
||||
[HttpGet("reorder-alerts")]
|
||||
[ProducesResponseType(typeof(PagedResponse<ReorderAlertDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<ReorderAlertDto>>> ReorderAlerts(
|
||||
[FromQuery] int? warehouseId, [FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _reorder.GetAlertsAsync(warehouseId, query, ct));
|
||||
|
||||
/// <summary>Create a draft requisition for an item's suggested reorder quantity.</summary>
|
||||
[HttpPost("reorder-alerts/{itemId:int}/requisition")]
|
||||
[ProducesResponseType(typeof(RequisitionDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<RequisitionDto>> SuggestRequisition(
|
||||
int itemId, [FromQuery] int warehouseId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _reorder.CreateSuggestedRequisitionAsync(itemId, warehouseId, ct);
|
||||
return Created($"/api/v1/requisitions/{dto.RequisitionId}", dto);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Stock;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Stock-count endpoints (docs/11 §5.6).</summary>
|
||||
[Route("api/v1/stock-counts")]
|
||||
public sealed class StockCountsController : ApiControllerBase
|
||||
{
|
||||
private readonly ICountService _counts;
|
||||
|
||||
public StockCountsController(ICountService counts) => _counts = counts;
|
||||
|
||||
/// <summary>List counts, newest first.</summary>
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<CountSummaryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<CountSummaryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] CountStatus? status, [FromQuery] int? warehouseId, CancellationToken ct)
|
||||
=> Ok(await _counts.ListAsync(query, status, warehouseId, ct));
|
||||
|
||||
[HttpGet("{countId:int}")]
|
||||
[ProducesResponseType(typeof(CountDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<CountDto>> GetById(int countId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _counts.GetAsync(countId, ct);
|
||||
return dto is null ? NotFound() : Ok(dto);
|
||||
}
|
||||
|
||||
/// <summary>Create a count with system quantities snapshotted (immutable).</summary>
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(CountDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<CountDto>> Create([FromBody] CreateCountRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _counts.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/stock-counts/{dto.CountId}", dto);
|
||||
}
|
||||
|
||||
/// <summary>Enter counted quantities; variance = counted − system.</summary>
|
||||
[HttpPut("{countId:int}/counts")]
|
||||
[ProducesResponseType(typeof(CountDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<CountDto>> EnterCounts(int countId, [FromBody] EnterCountsRequest request, CancellationToken ct)
|
||||
=> Ok(await _counts.EnterCountsAsync(countId, request, ct));
|
||||
|
||||
/// <summary>Post: emit a variance adjustment and close the count.</summary>
|
||||
[HttpPost("{countId:int}/post")]
|
||||
[ProducesResponseType(typeof(CountPostResultDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<CountPostResultDto>> Post(int countId, CancellationToken ct)
|
||||
=> Ok(await _counts.PostAsync(countId, ct));
|
||||
}
|
||||
@@ -0,0 +1,59 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Stock;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Stock-transfer endpoints (docs/11 §5.4).</summary>
|
||||
[Route("api/v1/stock-transfers")]
|
||||
public sealed class StockTransfersController : ApiControllerBase
|
||||
{
|
||||
private readonly ITransferService _transfers;
|
||||
|
||||
public StockTransfersController(ITransferService transfers) => _transfers = transfers;
|
||||
|
||||
/// <summary>List transfers, newest first.</summary>
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<TransferSummaryDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<TransferSummaryDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] TransferStatus? status,
|
||||
[FromQuery] int? srcWarehouseId, [FromQuery] int? destWarehouseId, CancellationToken ct)
|
||||
=> Ok(await _transfers.ListAsync(query, status, srcWarehouseId, destWarehouseId, ct));
|
||||
|
||||
[HttpGet("{transferId:int}")]
|
||||
[ProducesResponseType(typeof(TransferDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<TransferDto>> GetById(int transferId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _transfers.GetAsync(transferId, ct);
|
||||
return dto is null ? NotFound() : Ok(dto);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(TransferDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<TransferDto>> Create([FromBody] CreateTransferRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _transfers.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/stock-transfers/{dto.TransferId}", dto);
|
||||
}
|
||||
|
||||
/// <summary>Dispatch: consume source FIFO layers into in-transit. 409 STOCK_NEGATIVE_BLOCKED if short.</summary>
|
||||
[HttpPost("{transferId:int}/dispatch")]
|
||||
[ProducesResponseType(typeof(DispatchResultDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<DispatchResultDto>> Dispatch(int transferId, CancellationToken ct)
|
||||
=> Ok(await _transfers.DispatchAsync(transferId, ct));
|
||||
|
||||
/// <summary>Receive: create the destination layer at the inherited cost (cost-preserving).</summary>
|
||||
[HttpPost("{transferId:int}/receive")]
|
||||
[ProducesResponseType(typeof(ReceiveResultDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status422UnprocessableEntity)]
|
||||
public async Task<ActionResult<ReceiveResultDto>> Receive(int transferId, [FromBody] ReceiveTransferRequest request, CancellationToken ct)
|
||||
=> Ok(await _transfers.ReceiveAsync(transferId, request, ct));
|
||||
}
|
||||
@@ -0,0 +1,56 @@
|
||||
using ERPCore.Dtos.Categories;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// Subcategory endpoints addressed by their own id (docs/11-BACKEND-PHASE1.md §2.3).
|
||||
/// Listing and creation live under the parent category on <see cref="CategoriesController"/>,
|
||||
/// since a subcategory only exists in the context of one.
|
||||
/// </summary>
|
||||
[Route("api/v1/subcategories")]
|
||||
public sealed class SubCategoriesController : ApiControllerBase
|
||||
{
|
||||
private readonly ICategoryService _categories;
|
||||
|
||||
public SubCategoriesController(ICategoryService categories) => _categories = categories;
|
||||
|
||||
[HttpGet("{subCategoryId:int}")]
|
||||
[ProducesResponseType(typeof(SubCategoryDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<SubCategoryDto>> GetById(int subCategoryId, CancellationToken ct)
|
||||
{
|
||||
var result = await _categories.GetSubCategoryAsync(subCategoryId, ct);
|
||||
if (result is null) return NotFound();
|
||||
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Renames a subcategory. It cannot be moved to another category — see the request DTO.</summary>
|
||||
[HttpPut("{subCategoryId:int}")]
|
||||
[ProducesResponseType(typeof(SubCategoryDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<SubCategoryDto>> Update(
|
||||
int subCategoryId, [FromBody] UpdateSubCategoryRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _categories.UpdateSubCategoryAsync(subCategoryId, request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
/// <summary>Deactivate/reactivate. Masters are never hard-deleted (FR-MD-08).</summary>
|
||||
[HttpPatch("{subCategoryId:int}/status")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<IActionResult> SetStatus(
|
||||
int subCategoryId, [FromBody] UpdateSubCategoryStatusRequest request, CancellationToken ct)
|
||||
{
|
||||
await _categories.SetSubCategoryStatusAsync(subCategoryId, request.Status, ct);
|
||||
return NoContent();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Uoms;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Unit-of-measure endpoints (docs/11-BACKEND-PHASE1.md §2.2).</summary>
|
||||
[Route("api/v1/uoms")]
|
||||
public sealed class UomsController : ApiControllerBase
|
||||
{
|
||||
private readonly IUomService _uoms;
|
||||
|
||||
public UomsController(IUomService uoms) => _uoms = uoms;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<UomDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<UomDto>>> List([FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _uoms.ListAsync(query, ct));
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(UomDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<UomDto>> Create([FromBody] CreateUomRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _uoms.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/uoms/{dto.UomId}", dto);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,53 @@
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Users;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>
|
||||
/// User management: local shadow `User` list/detail + role assignment, and
|
||||
/// account creation orchestrated against AuthHex (see <see cref="IUserManagementService.CreateAsync"/>).
|
||||
/// </summary>
|
||||
[Route("api/v1/users")]
|
||||
public sealed class UsersController : ApiControllerBase
|
||||
{
|
||||
private readonly IUserManagementService _users;
|
||||
|
||||
public UsersController(IUserManagementService users) => _users = users;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<ManagedUserDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<ManagedUserDto>>> List([FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _users.ListAsync(query, ct));
|
||||
|
||||
/// <summary>AuthHex UserType options for the create-user form's select.</summary>
|
||||
[HttpGet("user-types")]
|
||||
[ProducesResponseType(typeof(List<UserTypeOptionDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<List<UserTypeOptionDto>>> ListUserTypes(CancellationToken ct)
|
||||
=> Ok(await _users.ListUserTypesAsync(ct));
|
||||
|
||||
[HttpGet("{userId:int}")]
|
||||
[ProducesResponseType(typeof(ManagedUserDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<ManagedUserDto>> GetById(int userId, CancellationToken ct)
|
||||
{
|
||||
var result = await _users.GetAsync(userId, ct);
|
||||
return result is null ? NotFound() : Ok(result);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(ManagedUserDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<ManagedUserDto>> Create([FromBody] CreateUserRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _users.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/users/{result.UserId}", result);
|
||||
}
|
||||
|
||||
[HttpPut("{userId:int}/role")]
|
||||
[ProducesResponseType(typeof(ManagedUserDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<ManagedUserDto>> UpdateRole(int userId, [FromBody] UpdateUserRoleRequest request, CancellationToken ct)
|
||||
=> Ok(await _users.UpdateRoleAsync(userId, request, ct));
|
||||
}
|
||||
@@ -0,0 +1,65 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Vendors;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Vendor master endpoints (docs/11-BACKEND-PHASE1.md §2.4).</summary>
|
||||
[Route("api/v1/vendors")]
|
||||
public sealed class VendorsController : ApiControllerBase
|
||||
{
|
||||
private readonly IVendorService _vendors;
|
||||
|
||||
public VendorsController(IVendorService vendors) => _vendors = vendors;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<VendorDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<VendorDto>>> List(
|
||||
[FromQuery] PageQuery query, [FromQuery] EntityStatus? status, CancellationToken ct)
|
||||
=> Ok(await _vendors.ListAsync(query, status, ct));
|
||||
|
||||
[HttpGet("{vendorId:int}")]
|
||||
[ProducesResponseType(typeof(VendorDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<VendorDto>> GetById(int vendorId, CancellationToken ct)
|
||||
{
|
||||
var result = await _vendors.GetAsync(vendorId, ct);
|
||||
if (result is null) return NotFound();
|
||||
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(VendorDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<VendorDto>> Create([FromBody] CreateVendorRequest request, CancellationToken ct)
|
||||
{
|
||||
var result = await _vendors.CreateAsync(request, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Created($"/api/v1/vendors/{result.Value.VendorId}", result.Value);
|
||||
}
|
||||
|
||||
[HttpPut("{vendorId:int}")]
|
||||
[ProducesResponseType(typeof(VendorDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status412PreconditionFailed)]
|
||||
public async Task<ActionResult<VendorDto>> Update(int vendorId, [FromBody] UpdateVendorRequest request, CancellationToken ct)
|
||||
{
|
||||
var expected = RequireIfMatch();
|
||||
var result = await _vendors.UpdateAsync(vendorId, request, expected, ct);
|
||||
SetETag(result.RowVersion);
|
||||
return Ok(result.Value);
|
||||
}
|
||||
|
||||
[HttpPatch("{vendorId:int}/status")]
|
||||
[ProducesResponseType(StatusCodes.Status204NoContent)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<IActionResult> SetStatus(int vendorId, [FromBody] UpdateVendorStatusRequest request, CancellationToken ct)
|
||||
{
|
||||
await _vendors.SetStatusAsync(vendorId, request.Status, ct);
|
||||
return NoContent();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,54 @@
|
||||
using ERPCore.Dtos.Common;
|
||||
using ERPCore.Dtos.Warehouses;
|
||||
using ERPCore.Services.Interfaces;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
|
||||
namespace ERPCore.Controllers;
|
||||
|
||||
/// <summary>Warehouse & bin endpoints (docs/11-BACKEND-PHASE1.md §2.5).</summary>
|
||||
[Route("api/v1/warehouses")]
|
||||
public sealed class WarehousesController : ApiControllerBase
|
||||
{
|
||||
private readonly IWarehouseService _warehouses;
|
||||
|
||||
public WarehousesController(IWarehouseService warehouses) => _warehouses = warehouses;
|
||||
|
||||
[HttpGet]
|
||||
[ProducesResponseType(typeof(PagedResponse<WarehouseDto>), StatusCodes.Status200OK)]
|
||||
public async Task<ActionResult<PagedResponse<WarehouseDto>>> List([FromQuery] PageQuery query, CancellationToken ct)
|
||||
=> Ok(await _warehouses.ListAsync(query, ct));
|
||||
|
||||
[HttpGet("{warehouseId:int}")]
|
||||
[ProducesResponseType(typeof(WarehouseDto), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<WarehouseDto>> GetById(int warehouseId, CancellationToken ct)
|
||||
{
|
||||
var dto = await _warehouses.GetAsync(warehouseId, ct);
|
||||
return dto is null ? NotFound() : Ok(dto);
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
[ProducesResponseType(typeof(WarehouseDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<WarehouseDto>> Create([FromBody] CreateWarehouseRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _warehouses.CreateAsync(request, ct);
|
||||
return Created($"/api/v1/warehouses/{dto.WarehouseId}", dto);
|
||||
}
|
||||
|
||||
[HttpGet("{warehouseId:int}/bins")]
|
||||
[ProducesResponseType(typeof(IReadOnlyList<BinDto>), StatusCodes.Status200OK)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
public async Task<ActionResult<IReadOnlyList<BinDto>>> ListBins(int warehouseId, CancellationToken ct)
|
||||
=> Ok(await _warehouses.ListBinsAsync(warehouseId, ct));
|
||||
|
||||
[HttpPost("{warehouseId:int}/bins")]
|
||||
[ProducesResponseType(typeof(BinDto), StatusCodes.Status201Created)]
|
||||
[ProducesResponseType(StatusCodes.Status404NotFound)]
|
||||
[ProducesResponseType(StatusCodes.Status409Conflict)]
|
||||
public async Task<ActionResult<BinDto>> CreateBin(int warehouseId, [FromBody] CreateBinRequest request, CancellationToken ct)
|
||||
{
|
||||
var dto = await _warehouses.CreateBinAsync(warehouseId, request, ct);
|
||||
return Created($"/api/v1/warehouses/{warehouseId}/bins/{dto.BinId}", dto);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
namespace ERPCore.Domain;
|
||||
|
||||
/// <summary>
|
||||
/// Document-type prefixes for <see cref="Entities.NumberSequence"/> and the
|
||||
/// generated document numbers (docs/10 §B.8.2). One prefix per numbered document.
|
||||
/// </summary>
|
||||
public static class DocumentTypes
|
||||
{
|
||||
public const string Requisition = "PR";
|
||||
public const string Rfq = "RFQ";
|
||||
public const string PurchaseOrder = "PO";
|
||||
public const string Grn = "GRN";
|
||||
public const string Transfer = "TRF";
|
||||
public const string Adjustment = "ADJ";
|
||||
public const string Count = "CNT";
|
||||
public const string PurchaseReturn = "PRET";
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Immutable audit trail entry (FR-X-02) — the compensating control for the deferred
|
||||
/// RBAC (02-SECURITY AR-01/B.3). One row per create/update/delete of an audited
|
||||
/// entity, capturing who / when / what changed (old→new in <see cref="ChangeSet"/>).
|
||||
/// Written automatically by <c>ErpDbContext.SaveChangesAsync</c>. Append-only at the
|
||||
/// app level; DB-role revocation of UPDATE/DELETE is deferred hardening (B.3).
|
||||
/// Model: docs/10 Part C.7.
|
||||
/// </summary>
|
||||
public class AuditLog
|
||||
{
|
||||
public int AuditId { get; set; }
|
||||
public int UserId { get; set; }
|
||||
public string EntityType { get; set; } = string.Empty;
|
||||
public int EntityId { get; set; }
|
||||
public AuditAction Action { get; set; }
|
||||
/// <summary>JSON change set: field→value (create/delete) or field→{old,new} (update).</summary>
|
||||
public string ChangeSet { get; set; } = "{}";
|
||||
public DateTime CreatedAt { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Batch/lot for a batch-tracked item (FR-GRN-04, FR-WH-03). Expiry drives FEFO
|
||||
/// picking of perishables. Model: docs/10 Part C.4.
|
||||
/// </summary>
|
||||
public class Batch
|
||||
{
|
||||
public int BatchId { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public string BatchNo { get; set; } = string.Empty;
|
||||
public DateOnly? ExpiryDate { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Bin / storage location within a warehouse (FR-MD-07, FR-WH-02). Stock is
|
||||
/// tracked to bin level. Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class Bin
|
||||
{
|
||||
public int BinId { get; set; }
|
||||
|
||||
public int WarehouseId { get; set; }
|
||||
public Warehouse? Warehouse { get; set; }
|
||||
|
||||
public string Code { get; set; } = string.Empty;
|
||||
public string? BinType { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Brand master (FR-MD-09). Referenced optionally by <see cref="Item.BrandId"/>.
|
||||
/// Mutable aggregate with a <see cref="RowVersion"/> ETag token. Deactivated, not
|
||||
/// deleted, when referenced (FR-MD-08). Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class Brand
|
||||
{
|
||||
public int BrandId { get; set; }
|
||||
public string Name { get; set; } = string.Empty;
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Item category (FR-MD-04) — the top level of a two-level hierarchy. The optional level
|
||||
/// below is <see cref="SubCategory"/>; categories no longer self-nest (the former
|
||||
/// <c>parent_id</c> tree was replaced in migration #2).
|
||||
/// Mutable aggregate with a <see cref="RowVersion"/> ETag token. Deactivated, not
|
||||
/// deleted, when referenced (FR-MD-08). Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class Category
|
||||
{
|
||||
public int CategoryId { get; set; }
|
||||
public string Name { get; set; } = string.Empty;
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
|
||||
public ICollection<SubCategory> SubCategories { get; set; } = new List<SubCategory>();
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Goods Receipt Note header (FR-GRN-01/02). Raised against a PO or direct
|
||||
/// (<see cref="PoId"/> null). On confirm each line creates a FIFO layer and posts
|
||||
/// an inbound ledger entry. Mutable aggregate with an <see cref="RowVersion"/>
|
||||
/// concurrency token (docs/10 C.10). Model: docs/10 Part C.3.
|
||||
/// </summary>
|
||||
public class Grn
|
||||
{
|
||||
public int GrnId { get; set; }
|
||||
public string DocNo { get; set; } = string.Empty;
|
||||
|
||||
public int? PoId { get; set; }
|
||||
public PurchaseOrder? PurchaseOrder { get; set; }
|
||||
|
||||
public int VendorId { get; set; }
|
||||
public Vendor? Vendor { get; set; }
|
||||
|
||||
public int WarehouseId { get; set; }
|
||||
public Warehouse? Warehouse { get; set; }
|
||||
|
||||
public GrnStatus Status { get; set; } = GrnStatus.Draft;
|
||||
|
||||
public int CreatedBy { get; set; }
|
||||
public User? Creator { get; set; }
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? PostedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token.</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
|
||||
public ICollection<GrnLine> Lines { get; set; } = new List<GrnLine>();
|
||||
}
|
||||
@@ -0,0 +1,64 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// GRN line (FR-GRN-04..08). <see cref="UnitCost"/> is the gross cost received at:
|
||||
/// entered on the line, defaulting to the PO price when omitted (a per-receipt price
|
||||
/// override is now permitted — see docs/02-SECURITY C.3, revised). <see cref="PoUnitPrice"/>
|
||||
/// snapshots the PO price at receipt so the variance survives later PO edits.
|
||||
/// <see cref="NetUnitCost"/> = unitCost after trade discount — this is what the FIFO layer
|
||||
/// costs at (VAT never enters stock value; it is recoverable input tax).
|
||||
/// <see cref="ReceivedValue"/> = qty × netUnitCost (after discount, before VAT).
|
||||
/// <see cref="HoldStatus"/> gates issuability. Model: docs/10 Part C.3.
|
||||
/// </summary>
|
||||
public class GrnLine
|
||||
{
|
||||
public int GrnLineId { get; set; }
|
||||
|
||||
public int GrnId { get; set; }
|
||||
public Grn? Grn { get; set; }
|
||||
|
||||
public int? PoLineId { get; set; }
|
||||
public PoLine? PoLine { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public int UomId { get; set; }
|
||||
public Uom? Uom { get; set; }
|
||||
|
||||
public int? BinId { get; set; }
|
||||
public Bin? Bin { get; set; }
|
||||
|
||||
public int? BatchId { get; set; }
|
||||
public Batch? Batch { get; set; }
|
||||
|
||||
public decimal Qty { get; set; }
|
||||
|
||||
/// <summary>Gross unit cost received at (entered, or PO price when omitted).</summary>
|
||||
public decimal UnitCost { get; set; }
|
||||
|
||||
/// <summary>Snapshot of the PO line price at receipt; null for direct receipts.</summary>
|
||||
public decimal? PoUnitPrice { get; set; }
|
||||
|
||||
/// <summary>Trade discount percentage (0–100), entered.</summary>
|
||||
public decimal DiscountPct { get; set; }
|
||||
|
||||
/// <summary>UnitCost × (1 − DiscountPct/100) — the inventory (FIFO layer) cost.</summary>
|
||||
public decimal NetUnitCost { get; set; }
|
||||
|
||||
/// <summary>VAT percentage (0–100), entered. Recoverable — does not affect stock value.</summary>
|
||||
public decimal VatPct { get; set; }
|
||||
|
||||
/// <summary>Qty × NetUnitCost × VatPct/100.</summary>
|
||||
public decimal VatAmount { get; set; }
|
||||
|
||||
/// <summary>Qty × NetUnitCost (after discount, before VAT).</summary>
|
||||
public decimal ReceivedValue { get; set; }
|
||||
|
||||
/// <summary>Qty × NetUnitCost + VatAmount — payable to the vendor.</summary>
|
||||
public decimal LineTotal { get; set; }
|
||||
|
||||
public HoldStatus HoldStatus { get; set; } = HoldStatus.Available;
|
||||
}
|
||||
@@ -0,0 +1,54 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Item master (FR-MD-01). Mutable aggregate: carries a <see cref="RowVersion"/>
|
||||
/// concurrency token surfaced as an ETag (docs/10 Part C.10). SKU is unique.
|
||||
/// Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class Item
|
||||
{
|
||||
public int ItemId { get; set; }
|
||||
public string Sku { get; set; } = string.Empty;
|
||||
public string Name { get; set; } = string.Empty;
|
||||
public string? Description { get; set; }
|
||||
|
||||
public int CategoryId { get; set; }
|
||||
public Category? Category { get; set; }
|
||||
|
||||
/// <summary>Optional second level below <see cref="CategoryId"/>; must belong to it.</summary>
|
||||
public int? SubCategoryId { get; set; }
|
||||
public SubCategory? SubCategory { get; set; }
|
||||
|
||||
public int? BrandId { get; set; }
|
||||
public Brand? Brand { get; set; }
|
||||
|
||||
public int BaseUomId { get; set; }
|
||||
public Uom? BaseUom { get; set; }
|
||||
|
||||
public int? DefaultVendorId { get; set; }
|
||||
public Vendor? DefaultVendor { get; set; }
|
||||
|
||||
public StockNature StockNature { get; set; }
|
||||
public TrackingMode TrackingMode { get; set; }
|
||||
public string? TaxClass { get; set; }
|
||||
|
||||
/// <summary>
|
||||
/// Optional fixed selling price used by Sales only. <c>null</c> means "use stock value"
|
||||
/// (the item is sold at its FIFO stock cost at sale time); a value is the fixed sale price.
|
||||
/// Never enters costing/GRN/FIFO (docs/10 Part C.1, C.9).
|
||||
/// </summary>
|
||||
public decimal? SalePrice { get; set; }
|
||||
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
|
||||
public ICollection<ItemReorder> ReorderSettings { get; set; } = new List<ItemReorder>();
|
||||
public ICollection<UomConversion> UomConversions { get; set; } = new List<UomConversion>();
|
||||
}
|
||||
@@ -0,0 +1,20 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Reorder policy for an item, optionally per warehouse (FR-MD-05). Reorder alerts
|
||||
/// are computed from these versus available stock (FR-STK-10) — not stored.
|
||||
/// Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class ItemReorder
|
||||
{
|
||||
public int ReorderId { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public int WarehouseId { get; set; }
|
||||
public Warehouse? Warehouse { get; set; }
|
||||
|
||||
public decimal ReorderPoint { get; set; }
|
||||
public decimal ReorderQty { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Item type master (FR-MD-10) — a selectable dimension name such as Color, Size or
|
||||
/// Material.
|
||||
/// <para>
|
||||
/// <b>Deliberately unlinked.</b> Nothing references this entity and it references
|
||||
/// nothing: there is no value table and no join to <see cref="Item"/>. Its only job is
|
||||
/// to feed the frontend's item-builder dropdown via <c>GET /item-types</c>. The chosen
|
||||
/// values (Red, S, M) are encoded by the client into the generated SKU
|
||||
/// (e.g. <c>BL-100-0003</c>) and are never stored or parsed server-side — the item list
|
||||
/// is the record of what was built. See the accepted trade-off in docs/10 Part C.9.
|
||||
/// </para>
|
||||
/// Not to be confused with <see cref="Enums.StockNature"/> (Stocked/NonStocked/Service),
|
||||
/// which is what the old <c>ItemType</c> enum became.
|
||||
/// Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class ItemType
|
||||
{
|
||||
public int ItemTypeId { get; set; }
|
||||
public string Name { get; set; } = string.Empty;
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// GL-ready journal entry emitted per stock movement (FR-STK-13) — data only, no
|
||||
/// posting in Phase 1 (the Accounting module consumes these later). One row per
|
||||
/// ledger entry, referencing the same source document polymorphically. Account
|
||||
/// codes are Phase-1 placeholders until a chart of accounts exists.
|
||||
/// Model: docs/10 Part C.7.
|
||||
/// </summary>
|
||||
public class JournalEntryStub
|
||||
{
|
||||
public int JournalId { get; set; }
|
||||
public string SourceDocType { get; set; } = string.Empty;
|
||||
public int SourceDocId { get; set; }
|
||||
public string DebitAccount { get; set; } = string.Empty;
|
||||
public string CreditAccount { get; set; } = string.Empty;
|
||||
public decimal Amount { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// A top-level sidebar entry (mirrors the frontend's hardcoded nav list,
|
||||
/// components/Layouts/AppSidebar.tsx). Seeded to match the current app routes;
|
||||
/// per-role visibility is controlled via <see cref="Permission"/>/<see cref="RolePermission"/>,
|
||||
/// not by editing these rows through the UI.
|
||||
/// </summary>
|
||||
public class NavItem
|
||||
{
|
||||
public int NavItemId { get; set; }
|
||||
public string Code { get; set; } = string.Empty;
|
||||
public string Label { get; set; } = string.Empty;
|
||||
public string? Icon { get; set; }
|
||||
public string? Href { get; set; }
|
||||
public int SortOrder { get; set; }
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public ICollection<SubNavItem> Children { get; set; } = new List<SubNavItem>();
|
||||
}
|
||||
@@ -0,0 +1,15 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Per-document-type, per-year running counter behind human document numbers
|
||||
/// (FR-X-03): <c>PR-2026-00001</c>, <c>PO-2026-00042</c>, … Numbers are issued
|
||||
/// inside the document's transaction so they are unique and gap-controlled.
|
||||
/// Model: docs/10 Part C.7.
|
||||
/// </summary>
|
||||
public class NumberSequence
|
||||
{
|
||||
public int SequenceId { get; set; }
|
||||
public string DocType { get; set; } = string.Empty;
|
||||
public int Year { get; set; }
|
||||
public int LastNumber { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// A grantable sidebar-visibility unit — exactly one of <see cref="NavItemId"/> /
|
||||
/// <see cref="SubNavItemId"/> is set (enforced in <c>NavSeedService</c>/service layer,
|
||||
/// not by a DB constraint). One row is seeded per <see cref="NavItem"/>/<see cref="SubNavItem"/>;
|
||||
/// <see cref="RolePermission"/> grants it to a role.
|
||||
/// </summary>
|
||||
public class Permission
|
||||
{
|
||||
public int PermissionId { get; set; }
|
||||
public string Code { get; set; } = string.Empty;
|
||||
public int? NavItemId { get; set; }
|
||||
public int? SubNavItemId { get; set; }
|
||||
|
||||
public NavItem? NavItem { get; set; }
|
||||
public SubNavItem? SubNavItem { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Purchase-order line (FR-PROC-03). <see cref="Tax"/> is the line tax rate
|
||||
/// (e.g. 0.18); <see cref="QtyReceived"/> accrues as GRNs confirm (FR-PROC-07).
|
||||
/// Model: docs/10 Part C.2.
|
||||
/// </summary>
|
||||
public class PoLine
|
||||
{
|
||||
public int PoLineId { get; set; }
|
||||
|
||||
public int PoId { get; set; }
|
||||
public PurchaseOrder? PurchaseOrder { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public int UomId { get; set; }
|
||||
public Uom? Uom { get; set; }
|
||||
|
||||
public int WarehouseId { get; set; }
|
||||
public Warehouse? Warehouse { get; set; }
|
||||
|
||||
public decimal Qty { get; set; }
|
||||
public decimal UnitPrice { get; set; }//
|
||||
public decimal Tax { get; set; }
|
||||
public decimal QtyReceived { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Product configuration (FR-MD-11) — a <b>singleton row</b> (single-tenant, docs/00-CORE §1)
|
||||
/// gating optional product master-data features.
|
||||
/// <para>
|
||||
/// <see cref="SubcategoriesEnabled"/> and <see cref="BrandsEnabled"/> are enforced
|
||||
/// server-side: an Item write carrying a subcategory/brand while the flag is off is
|
||||
/// rejected with <c>CONFIG_DISABLED</c>. <see cref="ItemTypesEnabled"/> is
|
||||
/// <b>advisory only</b> — items carry no item-type reference (see <see cref="ItemType"/>),
|
||||
/// so there is nothing on a write to reject; the frontend honours it by hiding the
|
||||
/// builder's type section. Reads are never gated, so existing data stays visible after a
|
||||
/// flag is switched off.
|
||||
/// </para>
|
||||
/// Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class ProductConfig
|
||||
{
|
||||
/// <summary>Always 1 — the singleton row's id.</summary>
|
||||
public const int SingletonId = 1;
|
||||
|
||||
public int ConfigId { get; set; }
|
||||
|
||||
public bool SubcategoriesEnabled { get; set; } = true;
|
||||
public bool BrandsEnabled { get; set; } = true;
|
||||
public bool ItemTypesEnabled { get; set; } = true;
|
||||
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
public int? UpdatedBy { get; set; }
|
||||
public User? UpdatedByUser { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Purchase order header (FR-PROC-03..06). Mutable aggregate with a
|
||||
/// <see cref="RowVersion"/> ETag token; editable while open (FR-PROC-05).
|
||||
/// Phase 1 auto-approves on creation; <see cref="ApprovalRequired"/> is retained
|
||||
/// for the future approval workflow. Totals are computed server-side from lines
|
||||
/// (not stored). Model: docs/10 Part C.2.
|
||||
/// </summary>
|
||||
public class PurchaseOrder
|
||||
{
|
||||
public int PoId { get; set; }
|
||||
public string DocNo { get; set; } = string.Empty;
|
||||
|
||||
public int VendorId { get; set; }
|
||||
public Vendor? Vendor { get; set; }
|
||||
|
||||
public int? RequisitionId { get; set; }
|
||||
public Requisition? Requisition { get; set; }
|
||||
|
||||
public PurchaseOrderStatus Status { get; set; } = PurchaseOrderStatus.Draft;
|
||||
public bool ApprovalRequired { get; set; }
|
||||
|
||||
public int CreatedBy { get; set; }
|
||||
public User? Creator { get; set; }
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
|
||||
public ICollection<PoLine> Lines { get; set; } = new List<PoLine>();
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Purchase return header (FR-PROC-08) — returns received goods to a vendor,
|
||||
/// generating an outbound stock movement. Auto-posts with a mandatory reason code.
|
||||
/// Model: docs/10 Part C.2.
|
||||
/// </summary>
|
||||
public class PurchaseReturn
|
||||
{
|
||||
public int ReturnId { get; set; }
|
||||
public string DocNo { get; set; } = string.Empty;
|
||||
|
||||
public int VendorId { get; set; }
|
||||
public Vendor? Vendor { get; set; }
|
||||
|
||||
public int WarehouseId { get; set; }
|
||||
public Warehouse? Warehouse { get; set; }
|
||||
|
||||
public int ReasonCodeId { get; set; }
|
||||
public ReasonCode? ReasonCode { get; set; }
|
||||
|
||||
public ReturnStatus Status { get; set; } = ReturnStatus.Posted;
|
||||
|
||||
public int CreatedBy { get; set; }
|
||||
public User? Creator { get; set; }
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
|
||||
public ICollection<PurchaseReturnLine> Lines { get; set; } = new List<PurchaseReturnLine>();
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Purchase-return line (FR-PROC-08) referencing the original GRN line for
|
||||
/// traceability. <see cref="Qty"/> is in base UOM. Model: docs/10 Part C.2.
|
||||
/// </summary>
|
||||
public class PurchaseReturnLine
|
||||
{
|
||||
public int ReturnLineId { get; set; }
|
||||
|
||||
public int ReturnId { get; set; }
|
||||
public PurchaseReturn? Return { get; set; }
|
||||
|
||||
public int? GrnLineId { get; set; }
|
||||
public GrnLine? GrnLine { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public decimal Qty { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,15 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Configurable reason code for adjustments, returns and count variances
|
||||
/// (FR-X-04). Model: docs/10 Part C.7.
|
||||
/// </summary>
|
||||
public class ReasonCode
|
||||
{
|
||||
public int ReasonCodeId { get; set; }
|
||||
public string Code { get; set; } = string.Empty;
|
||||
public string Description { get; set; } = string.Empty;
|
||||
public ReasonContext Context { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Purchase requisition header (FR-PROC-01). <see cref="RequestedBy"/> is the audit
|
||||
/// actor from the token (never the body). Model: docs/10 Part C.2.
|
||||
/// </summary>
|
||||
public class Requisition
|
||||
{
|
||||
public int RequisitionId { get; set; }
|
||||
public string DocNo { get; set; } = string.Empty;
|
||||
|
||||
public int RequestedBy { get; set; }
|
||||
public User? Requester { get; set; }
|
||||
|
||||
public RequisitionStatus Status { get; set; } = RequisitionStatus.Draft;
|
||||
public DateTime CreatedAt { get; set; }
|
||||
|
||||
public ICollection<RequisitionLine> Lines { get; set; } = new List<RequisitionLine>();
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>Requisition line (FR-PROC-01). Model: docs/10 Part C.2.</summary>
|
||||
public class RequisitionLine
|
||||
{
|
||||
public int ReqLineId { get; set; }
|
||||
|
||||
public int RequisitionId { get; set; }
|
||||
public Requisition? Requisition { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public decimal Qty { get; set; }
|
||||
public DateOnly? RequiredBy { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Request for Quotation header (FR-PROC-02) raised from a requisition. Vendor
|
||||
/// quotations attach for comparison. Model: docs/10 Part C.2.
|
||||
/// </summary>
|
||||
public class Rfq
|
||||
{
|
||||
public int RfqId { get; set; }
|
||||
public string DocNo { get; set; } = string.Empty;
|
||||
|
||||
public int RequisitionId { get; set; }
|
||||
public Requisition? Requisition { get; set; }
|
||||
|
||||
public RfqStatus Status { get; set; } = RfqStatus.Open;
|
||||
public DateTime CreatedAt { get; set; }
|
||||
|
||||
public ICollection<RfqLine> Lines { get; set; } = new List<RfqLine>();
|
||||
public ICollection<VendorQuotation> Quotations { get; set; } = new List<VendorQuotation>();
|
||||
}
|
||||
@@ -0,0 +1,15 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>RFQ line — an item + quantity being quoted (FR-PROC-02). Model: docs/10 Part C.2.</summary>
|
||||
public class RfqLine
|
||||
{
|
||||
public int RfqLineId { get; set; }
|
||||
|
||||
public int RfqId { get; set; }
|
||||
public Rfq? Rfq { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public decimal Qty { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Local shadow/projection of an AuthHex <c>Role</c> row, mirroring the same
|
||||
/// pattern <see cref="User"/> uses for AuthHex identities: <see cref="AuthRoleId"/>
|
||||
/// maps to AuthHex's Guid <c>RoleId</c>, while the local <see cref="RoleId"/> (int)
|
||||
/// is what <see cref="Permission"/>/<see cref="RolePermission"/>/<see cref="User.RoleId"/>
|
||||
/// FKs reference. AuthHex remains the source of truth; writes are forwarded there
|
||||
/// first (<c>IAuthHexClient</c>) and mirrored here on success.
|
||||
/// </summary>
|
||||
public class Role
|
||||
{
|
||||
public int RoleId { get; set; }
|
||||
public Guid AuthRoleId { get; set; }
|
||||
public string Code { get; set; } = string.Empty;
|
||||
public string Name { get; set; } = string.Empty;
|
||||
public bool IsSystemRole { get; set; }
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>Join row granting a <see cref="Role"/> visibility of a <see cref="Permission"/> (nav node).</summary>
|
||||
public class RolePermission
|
||||
{
|
||||
public int RoleId { get; set; }
|
||||
public int PermissionId { get; set; }
|
||||
|
||||
public Role? Role { get; set; }
|
||||
public Permission? Permission { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Serial number for a serial-tracked item across its lifecycle (FR-WH-04).
|
||||
/// Model: docs/10 Part C.4.
|
||||
/// </summary>
|
||||
public class Serial
|
||||
{
|
||||
public int SerialId { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public string SerialNo { get; set; } = string.Empty;
|
||||
public string Status { get; set; } = "InStock";
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Stock adjustment header (FR-STK-07) — the highest-risk feature in the phase
|
||||
/// (02-SECURITY C.5). Auto-posts in Phase 1 with a mandatory reason code and user
|
||||
/// stamp. Mutable aggregate with an <see cref="RowVersion"/> token (docs/10 C.10).
|
||||
/// Model: docs/10 Part C.6.
|
||||
/// </summary>
|
||||
public class StockAdjustment
|
||||
{
|
||||
public int AdjustmentId { get; set; }
|
||||
public string DocNo { get; set; } = string.Empty;
|
||||
|
||||
public int WarehouseId { get; set; }
|
||||
public Warehouse? Warehouse { get; set; }
|
||||
|
||||
public int ReasonCodeId { get; set; }
|
||||
public ReasonCode? ReasonCode { get; set; }
|
||||
|
||||
public AdjustmentStatus Status { get; set; } = AdjustmentStatus.Posted;
|
||||
|
||||
public int CreatedBy { get; set; }
|
||||
public User? Creator { get; set; }
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public uint RowVersion { get; set; }
|
||||
|
||||
public ICollection<StockAdjustmentLine> Lines { get; set; } = new List<StockAdjustmentLine>();
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Adjustment line (FR-STK-07). <see cref="QtyDelta"/> is a signed base-UOM
|
||||
/// quantity: negative consumes FIFO layers, positive creates a layer at last cost.
|
||||
/// Model: docs/10 Part C.6.
|
||||
/// </summary>
|
||||
public class StockAdjustmentLine
|
||||
{
|
||||
public int AdjLineId { get; set; }
|
||||
|
||||
public int AdjustmentId { get; set; }
|
||||
public StockAdjustment? Adjustment { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public int? BinId { get; set; }
|
||||
public int? BatchId { get; set; }
|
||||
public int? SerialId { get; set; }
|
||||
|
||||
public decimal QtyDelta { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Cycle/full physical count header (FR-STK-08). System quantities are snapshotted
|
||||
/// at creation and are immutable once opened (02-SECURITY C.7); posting emits a
|
||||
/// variance adjustment. Mutable aggregate with an <see cref="RowVersion"/> token.
|
||||
/// Model: docs/10 Part C.6.
|
||||
/// </summary>
|
||||
public class StockCount
|
||||
{
|
||||
public int CountId { get; set; }
|
||||
public string DocNo { get; set; } = string.Empty;
|
||||
|
||||
public int WarehouseId { get; set; }
|
||||
public Warehouse? Warehouse { get; set; }
|
||||
|
||||
public CountType CountType { get; set; }
|
||||
public CountStatus Status { get; set; } = CountStatus.Draft;
|
||||
|
||||
public int CreatedBy { get; set; }
|
||||
public User? Creator { get; set; }
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public uint RowVersion { get; set; }
|
||||
|
||||
public ICollection<StockCountLine> Lines { get; set; } = new List<StockCountLine>();
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Count line (FR-STK-08). <see cref="SystemQty"/> is the immutable snapshot;
|
||||
/// <see cref="Variance"/> = counted − system (in base UOM). Model: docs/10 Part C.6.
|
||||
/// </summary>
|
||||
public class StockCountLine
|
||||
{
|
||||
public int CountLineId { get; set; }
|
||||
|
||||
public int CountId { get; set; }
|
||||
public StockCount? Count { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public int? BinId { get; set; }
|
||||
|
||||
public decimal SystemQty { get; set; }
|
||||
public decimal? CountedQty { get; set; }
|
||||
public decimal? Variance { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// FIFO cost layer — a quantity received at a specific unit cost, consumed
|
||||
/// oldest-first (FR-STK-02). Keyed per item **per warehouse**; quantities and
|
||||
/// <see cref="UnitCost"/> are in the item's base UOM. Answers valuation
|
||||
/// ("what's on hand and at what cost"). Model: docs/10 Part C.5.
|
||||
/// </summary>
|
||||
public class StockLayer
|
||||
{
|
||||
public int LayerId { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public int WarehouseId { get; set; }
|
||||
public Warehouse? Warehouse { get; set; }
|
||||
|
||||
public int? BatchId { get; set; }
|
||||
public Batch? Batch { get; set; }
|
||||
|
||||
public int? SerialId { get; set; }
|
||||
public Serial? Serial { get; set; }
|
||||
|
||||
/// <summary>Originating GRN line — carries the inspection hold status for this stock.</summary>
|
||||
public int? GrnLineId { get; set; }
|
||||
public GrnLine? GrnLine { get; set; }
|
||||
|
||||
public decimal QtyReceived { get; set; }
|
||||
public decimal QtyRemaining { get; set; }
|
||||
public decimal UnitCost { get; set; }
|
||||
public DateTime ReceiptDate { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Immutable, append-only stock ledger (FR-STK-01, FR-X-05). One row per costed
|
||||
/// movement; answers history ("what moved, when, by whom"). The originating
|
||||
/// document is referenced polymorphically via
|
||||
/// <see cref="SourceDocType"/>/<see cref="SourceDocId"/> (no hard FK per type) so
|
||||
/// new transaction types write here without a schema change. Model: docs/10 Part C.5.
|
||||
/// </summary>
|
||||
public class StockLedger
|
||||
{
|
||||
public int LedgerId { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public int WarehouseId { get; set; }
|
||||
public int? BinId { get; set; }
|
||||
public int? BatchId { get; set; }
|
||||
public int? SerialId { get; set; }
|
||||
public int UserId { get; set; }
|
||||
|
||||
public Direction Direction { get; set; }
|
||||
public decimal QtyBase { get; set; }
|
||||
public decimal UnitCost { get; set; }
|
||||
public decimal Value { get; set; }
|
||||
public decimal RunningBalance { get; set; }
|
||||
|
||||
public string SourceDocType { get; set; } = string.Empty;
|
||||
public int SourceDocId { get; set; }
|
||||
public DateTime CreatedAt { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Inter-warehouse stock transfer header (FR-STK-05/06). Dispatch consumes source
|
||||
/// FIFO layers into in-transit; receive creates the destination layer at the
|
||||
/// inherited cost (cost-preserving). Mutable aggregate with an
|
||||
/// <see cref="RowVersion"/> token (docs/10 C.10). Model: docs/10 Part C.6.
|
||||
/// </summary>
|
||||
public class StockTransfer
|
||||
{
|
||||
public int TransferId { get; set; }
|
||||
public string DocNo { get; set; } = string.Empty;
|
||||
|
||||
public int SrcWarehouseId { get; set; }
|
||||
public Warehouse? SrcWarehouse { get; set; }
|
||||
|
||||
public int DestWarehouseId { get; set; }
|
||||
public Warehouse? DestWarehouse { get; set; }
|
||||
|
||||
public TransferStatus Status { get; set; } = TransferStatus.Draft;
|
||||
|
||||
public int CreatedBy { get; set; }
|
||||
public User? Creator { get; set; }
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public uint RowVersion { get; set; }
|
||||
|
||||
public ICollection<StockTransferLine> Lines { get; set; } = new List<StockTransferLine>();
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Transfer line (FR-STK-05/06). <see cref="Qty"/> is in base UOM.
|
||||
/// <para>
|
||||
/// Deviation note: <see cref="UnitCost"/> and <see cref="QtyReceived"/> extend
|
||||
/// docs/10 Part C.6's <c>STOCK_TRANSFER_LINE</c> to make the transfer
|
||||
/// cost-preserving: at dispatch the value-weighted cost of the consumed source
|
||||
/// layers is stored here, and receive recreates the destination layer at that cost
|
||||
/// (supports partial receive via <see cref="QtyReceived"/>).
|
||||
/// </para>
|
||||
/// </summary>
|
||||
public class StockTransferLine
|
||||
{
|
||||
public int TransferLineId { get; set; }
|
||||
|
||||
public int TransferId { get; set; }
|
||||
public StockTransfer? Transfer { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public int? SrcBinId { get; set; }
|
||||
public int? DestBinId { get; set; }
|
||||
public int? BatchId { get; set; }
|
||||
public int? SerialId { get; set; }
|
||||
|
||||
public decimal Qty { get; set; }
|
||||
|
||||
/// <summary>Value-weighted unit cost of the consumed source layers (set at dispatch).</summary>
|
||||
public decimal? UnitCost { get; set; }
|
||||
|
||||
/// <summary>Quantity already received at the destination (partial-receive support).</summary>
|
||||
public decimal QtyReceived { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Subcategory — the single optional level below <see cref="Category"/> (FR-MD-04).
|
||||
/// Replaces the former self-referencing CATEGORY.parent_id tree: the hierarchy is
|
||||
/// exactly two levels deep and cannot nest further. Referenced optionally by
|
||||
/// <see cref="Item.SubCategoryId"/>. Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class SubCategory
|
||||
{
|
||||
public int SubCategoryId { get; set; }
|
||||
public string Name { get; set; } = string.Empty;
|
||||
|
||||
public int CategoryId { get; set; }
|
||||
public Category? Category { get; set; }
|
||||
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>A child sidebar entry under a <see cref="NavItem"/> (e.g. Products' children).</summary>
|
||||
public class SubNavItem
|
||||
{
|
||||
public int SubNavItemId { get; set; }
|
||||
public int NavItemId { get; set; }
|
||||
public string Code { get; set; } = string.Empty;
|
||||
public string Label { get; set; } = string.Empty;
|
||||
public string? Icon { get; set; }
|
||||
public string? Href { get; set; }
|
||||
public int SortOrder { get; set; }
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public NavItem? NavItem { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Unit of Measure (FR-MD-02). Referenced as an item's base UOM and as the
|
||||
/// endpoints of a <see cref="UomConversion"/>. Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class Uom
|
||||
{
|
||||
public int UomId { get; set; }
|
||||
public string Name { get; set; } = string.Empty;
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Per-item conversion factor between two UOMs (FR-MD-02/03): quantity in
|
||||
/// <see cref="FromUomId"/> × <see cref="Factor"/> = quantity in <see cref="ToUomId"/>.
|
||||
/// Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class UomConversion
|
||||
{
|
||||
public int ConversionId { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public int FromUomId { get; set; }
|
||||
public Uom? FromUom { get; set; }
|
||||
|
||||
public int ToUomId { get; set; }
|
||||
public Uom? ToUom { get; set; }
|
||||
|
||||
public decimal Factor { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Application user (FR-X-01) — a **local shadow/projection** of an AuthHex identity.
|
||||
/// The local <see cref="UserId"/> (int) is what every `createdBy`/`requestedBy`/
|
||||
/// audit/ledger FK references; <see cref="AuthUserId"/> maps it to the AuthHex
|
||||
/// <c>UserId</c> (GUID) and is JIT-provisioned on first authenticated request
|
||||
/// (docs/10 A.4/C.7). A seeded <c>system</c> user (id 1, null AuthUserId) is the
|
||||
/// fallback actor for unauthenticated/system operations. Model: docs/10 Part C.7.
|
||||
/// </summary>
|
||||
public class User
|
||||
{
|
||||
/// <summary>Seeded fallback actor for unauthenticated/system operations.</summary>
|
||||
public const int SystemUserId = 1;
|
||||
|
||||
public int UserId { get; set; }
|
||||
public string Username { get; set; } = string.Empty;
|
||||
public string DisplayName { get; set; } = string.Empty;
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
/// <summary>AuthHex identity (token <c>UserId</c> GUID); null for the seeded system user.</summary>
|
||||
public Guid? AuthUserId { get; set; }
|
||||
|
||||
/// <summary>Local shadow <see cref="Role"/> assignment; null until an admin assigns one.</summary>
|
||||
public int? RoleId { get; set; }
|
||||
public Role? Role { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Vendor master (FR-MD-06). Mutable aggregate with a <see cref="RowVersion"/>
|
||||
/// ETag token. Deactivated, not deleted, when referenced (FR-MD-08).
|
||||
/// Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class Vendor
|
||||
{
|
||||
public int VendorId { get; set; }
|
||||
public string Code { get; set; } = string.Empty;
|
||||
public string Name { get; set; } = string.Empty;
|
||||
public string? Terms { get; set; }
|
||||
public string? TaxReg { get; set; }
|
||||
public string Currency { get; set; } = "LKR";
|
||||
public EntityStatus Status { get; set; } = EntityStatus.Active;
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
public DateTime? UpdatedAt { get; set; }
|
||||
|
||||
/// <summary>PostgreSQL xmin-backed optimistic concurrency token (ETag source).</summary>
|
||||
public uint RowVersion { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// A vendor's quotation against an RFQ (FR-PROC-02). Per-item pricing lives in
|
||||
/// <see cref="Lines"/>.
|
||||
/// <para>
|
||||
/// Deviation note: docs/10 Part C.2 models <c>VENDOR_QUOTATION</c> with scalar
|
||||
/// <c>unit_price</c>/<c>lead_days</c> and no item reference, which cannot represent
|
||||
/// the per-line pricing the API contract requires (docs/11 §3.2). This header +
|
||||
/// <see cref="VendorQuotationLine"/> split follows the authoritative API shape.
|
||||
/// </para>
|
||||
/// </summary>
|
||||
public class VendorQuotation
|
||||
{
|
||||
public int QuotationId { get; set; }
|
||||
|
||||
public int RfqId { get; set; }
|
||||
public Rfq? Rfq { get; set; }
|
||||
|
||||
public int VendorId { get; set; }
|
||||
public Vendor? Vendor { get; set; }
|
||||
|
||||
public DateTime CreatedAt { get; set; }
|
||||
|
||||
public ICollection<VendorQuotationLine> Lines { get; set; } = new List<VendorQuotationLine>();
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>Per-item quoted price and lead time within a <see cref="VendorQuotation"/> (docs/11 §3.2).</summary>
|
||||
public class VendorQuotationLine
|
||||
{
|
||||
public int QuotationLineId { get; set; }
|
||||
|
||||
public int QuotationId { get; set; }
|
||||
public VendorQuotation? Quotation { get; set; }
|
||||
|
||||
public int ItemId { get; set; }
|
||||
public Item? Item { get; set; }
|
||||
|
||||
public decimal UnitPrice { get; set; }
|
||||
public int LeadDays { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
namespace ERPCore.Domain.Entities;
|
||||
|
||||
/// <summary>
|
||||
/// Warehouse master (FR-MD-07, FR-WH-01). Owns a bin/location hierarchy.
|
||||
/// Model: docs/10-BACKEND-PHASE1.md Part C.1.
|
||||
/// </summary>
|
||||
public class Warehouse
|
||||
{
|
||||
public int WarehouseId { get; set; }
|
||||
public string Code { get; set; } = string.Empty;
|
||||
public string Name { get; set; } = string.Empty;
|
||||
|
||||
public ICollection<Bin> Bins { get; set; } = new List<Bin>();
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>
|
||||
/// Stock-adjustment lifecycle (docs/10 §B.8.1). Phase 1 auto-posts, so
|
||||
/// <see cref="PendingApproval"/> is reserved for the future threshold-approval
|
||||
/// workflow (FR-STK-07). Stored as a string.
|
||||
/// </summary>
|
||||
public enum AdjustmentStatus
|
||||
{
|
||||
Draft,
|
||||
PendingApproval,
|
||||
Posted
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Kind of mutation recorded in the audit trail (FR-X-02). Stored as a string.</summary>
|
||||
public enum AuditAction
|
||||
{
|
||||
Create,
|
||||
Update,
|
||||
Delete
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Stock-count lifecycle (docs/11 §8; docs/10 §B.8.1). Stored as a string.</summary>
|
||||
public enum CountStatus
|
||||
{
|
||||
Draft,
|
||||
Counted,
|
||||
Posted
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Physical-count scope (docs/11 §8; FR-STK-08). Stored as a string.</summary>
|
||||
public enum CountType
|
||||
{
|
||||
Cycle,
|
||||
Full
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Stock-ledger movement direction (docs/11 §8). Stored as a string.</summary>
|
||||
public enum Direction
|
||||
{
|
||||
In,
|
||||
Out
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>
|
||||
/// Lifecycle status for deactivatable master data (Item, Vendor). Masters are
|
||||
/// never hard-deleted while referenced — they are set <see cref="Inactive"/>
|
||||
/// instead (FR-MD-08). Stored as a string.
|
||||
/// </summary>
|
||||
public enum EntityStatus
|
||||
{
|
||||
Active,
|
||||
Inactive
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Goods-receipt-note lifecycle (docs/11 §8; docs/10 §B.8.1). Stored as a string.</summary>
|
||||
public enum GrnStatus
|
||||
{
|
||||
Draft,
|
||||
Confirmed,
|
||||
Closed
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>
|
||||
/// Inspection-hold state of received stock (docs/11 §8; FR-GRN-05). <see cref="OnHold"/>
|
||||
/// stock is on-hand but not issuable until released (FR-WH-07). Stored as a string.
|
||||
/// </summary>
|
||||
public enum HoldStatus
|
||||
{
|
||||
Available,
|
||||
OnHold,
|
||||
Rejected
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>
|
||||
/// Purchase-order lifecycle (docs/11 §8; docs/10 §B.8.1). Phase 1 auto-approves on
|
||||
/// creation, so <see cref="PendingApproval"/> is reserved (not entered) until the
|
||||
/// approval workflow is enabled (FR-PROC-04). Stored as a string.
|
||||
/// </summary>
|
||||
public enum PurchaseOrderStatus
|
||||
{
|
||||
Draft,
|
||||
PendingApproval,
|
||||
Approved,
|
||||
PartiallyReceived,
|
||||
FullyReceived,
|
||||
Closed,
|
||||
Cancelled
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Where a reason code applies (FR-X-04; docs/10 §B.8.3). Stored as a string.</summary>
|
||||
public enum ReasonContext
|
||||
{
|
||||
Adjustment,
|
||||
Return,
|
||||
Count
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Purchase-requisition lifecycle (docs/11 §3.1; docs/10 §B.8.1). Stored as a string.</summary>
|
||||
public enum RequisitionStatus
|
||||
{
|
||||
Draft,
|
||||
Submitted
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Purchase-return lifecycle (docs/11 §3.4). Auto-posts in Phase 1. Stored as a string.</summary>
|
||||
public enum ReturnStatus
|
||||
{
|
||||
Draft,
|
||||
Posted
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>RFQ lifecycle (docs/11 §3.2). Stored as a string.</summary>
|
||||
public enum RfqStatus
|
||||
{
|
||||
Open,
|
||||
Closed
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>
|
||||
/// Whether an item holds stock (FR-MD-01). Values match the <c>stockNature</c> enum in
|
||||
/// docs/11-BACKEND-PHASE1.md §8. Stored as a string in the database.
|
||||
/// Renamed from <c>ItemType</c> so that name could be taken by the ItemType master
|
||||
/// entity (Color/Size/Material) — the two concepts are unrelated (docs/10 Part C.9).
|
||||
/// </summary>
|
||||
public enum StockNature
|
||||
{
|
||||
Stocked,
|
||||
NonStocked,
|
||||
Service
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>
|
||||
/// How on-hand units of an item are individually tracked (FR-MD-01). Values match
|
||||
/// the <c>trackingMode</c> enum in docs/11-BACKEND-PHASE1.md §8. Stored as a string.
|
||||
/// </summary>
|
||||
public enum TrackingMode
|
||||
{
|
||||
None,
|
||||
Batch,
|
||||
Serial
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
namespace ERPCore.Domain.Enums;
|
||||
|
||||
/// <summary>Stock-transfer lifecycle (docs/11 §8; docs/10 §B.8.1). Stored as a string.</summary>
|
||||
public enum TransferStatus
|
||||
{
|
||||
Draft,
|
||||
InTransit,
|
||||
Received,
|
||||
Closed
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
using System.Text.Json;
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Dtos.Audit;
|
||||
|
||||
/// <summary>An audit-trail entry (FR-X-02). <c>ChangeSet</c> is the stored JSON, inlined.</summary>
|
||||
public sealed record AuditLogDto(
|
||||
int AuditId, int UserId, string EntityType, int EntityId, AuditAction Action, JsonElement ChangeSet, DateTime CreatedAt);
|
||||
|
||||
/// <summary>A GL-ready journal stub emitted per stock movement (FR-STK-13).</summary>
|
||||
public sealed record JournalEntryStubDto(
|
||||
int JournalId, string SourceDocType, int SourceDocId, string DebitAccount, string CreditAccount, decimal Amount);
|
||||
@@ -0,0 +1,42 @@
|
||||
using System.ComponentModel.DataAnnotations;
|
||||
using System.Text.Json;
|
||||
|
||||
namespace ERPCore.Dtos.Auth;
|
||||
|
||||
public sealed class IsAvailableRequest
|
||||
{
|
||||
[Required] public string Identifier { get; set; } = string.Empty;
|
||||
public string? Recovery { get; set; }
|
||||
}
|
||||
|
||||
public sealed class IsAvailableResponse
|
||||
{
|
||||
public bool? IsAvailable { get; set; }
|
||||
public string? Message { get; set; }
|
||||
/// <summary>Passed through as-is when `Recovery` matched existing users — shape isn't in the documented catalog.</summary>
|
||||
public JsonElement? ExistingUsers { get; set; }
|
||||
}
|
||||
|
||||
public sealed class SendOtpRequest
|
||||
{
|
||||
[Required] public string Identifier { get; set; } = string.Empty;
|
||||
public int NumberOfDigits { get; set; } = 6;
|
||||
public bool NewUser { get; set; }
|
||||
}
|
||||
|
||||
public sealed class SendOtpResponse
|
||||
{
|
||||
public string? ReferenceNumber { get; set; }
|
||||
public DateTime? ExpiresAt { get; set; }
|
||||
public string? RecoveryType { get; set; }
|
||||
}
|
||||
|
||||
public sealed class VerifyAltOtpRequest
|
||||
{
|
||||
[Required] public string ReferenceNumber { get; set; } = string.Empty;
|
||||
[Required] public string OtpCode { get; set; } = string.Empty;
|
||||
public string? Identifier { get; set; }
|
||||
public Guid? UserId { get; set; }
|
||||
public bool NewUser { get; set; }
|
||||
public string? DeviceName { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
using System.ComponentModel.DataAnnotations;
|
||||
|
||||
namespace ERPCore.Dtos.Auth;
|
||||
|
||||
public sealed class ForgotPasswordRequest
|
||||
{
|
||||
[Required] public string Identifier { get; set; } = string.Empty;
|
||||
public bool UseResetLink { get; set; }
|
||||
public int NumberOfDigits { get; set; } = 6;
|
||||
public bool Welcome { get; set; }
|
||||
}
|
||||
|
||||
public sealed class ForgotPasswordResponse
|
||||
{
|
||||
public string? ReferenceNumber { get; set; }
|
||||
public DateTime? ExpiresAt { get; set; }
|
||||
public string? RecoveryType { get; set; }
|
||||
}
|
||||
|
||||
public sealed class VerifyRecoveryOtpRequest
|
||||
{
|
||||
[Required] public string ReferenceNumber { get; set; } = string.Empty;
|
||||
[Required] public string OtpCode { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class VerifyRecoveryOtpResponse
|
||||
{
|
||||
public string? ReferenceNumber { get; set; }
|
||||
public Guid? UserId { get; set; }
|
||||
public bool Verified { get; set; }
|
||||
}
|
||||
|
||||
public sealed class ResetPasswordRequest
|
||||
{
|
||||
[Required] public string ReferenceNumber { get; set; } = string.Empty;
|
||||
[Required, MinLength(8)] public string NewPassword { get; set; } = string.Empty;
|
||||
[Required] public string ConfirmPassword { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class ResetPasswordWithTokenRequest
|
||||
{
|
||||
[Required] public string ResetToken { get; set; } = string.Empty;
|
||||
[Required, MinLength(8)] public string NewPassword { get; set; } = string.Empty;
|
||||
[Required] public string ConfirmPassword { get; set; } = string.Empty;
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
using System.ComponentModel.DataAnnotations;
|
||||
|
||||
namespace ERPCore.Dtos.Auth;
|
||||
|
||||
/// <summary>AuthHex's Role projection (ERP_Auth_Service/API_DOCUMENTATION.md, RoleManager section).</summary>
|
||||
public sealed class AuthHexRoleDto
|
||||
{
|
||||
public Guid RoleId { get; set; }
|
||||
public string? Code { get; set; }
|
||||
public string? Name { get; set; }
|
||||
public bool? IsSystemRole { get; set; }
|
||||
public DateTime CreatedAt { get; set; }
|
||||
}
|
||||
|
||||
public sealed class CreateAuthHexRoleRequest
|
||||
{
|
||||
[Required] public string Code { get; set; } = string.Empty;
|
||||
public string? Name { get; set; }
|
||||
public bool? IsSystemRole { get; set; }
|
||||
}
|
||||
|
||||
public sealed class UpdateAuthHexRoleRequest
|
||||
{
|
||||
[Required] public Guid RoleId { get; set; }
|
||||
public string? Code { get; set; }
|
||||
public string? Name { get; set; }
|
||||
public bool? IsSystemRole { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,191 @@
|
||||
using System.ComponentModel.DataAnnotations;
|
||||
using System.Text.Json;
|
||||
|
||||
namespace ERPCore.Dtos.Auth;
|
||||
|
||||
/// <summary>Shared AuthHex user projection (API_REFERENCE.md §3). Field set is
|
||||
/// AuthHex's best-documented subset; unknown fields are ignored on deserialize.</summary>
|
||||
public sealed class UserSummaryDto
|
||||
{
|
||||
public Guid? UserId { get; set; }
|
||||
public Guid? RoleId { get; set; }
|
||||
public Guid? UserTypeId { get; set; }
|
||||
public string? Fullname { get; set; }
|
||||
public string? UserName { get; set; }
|
||||
public string? Nic { get; set; }
|
||||
public string? Email { get; set; }
|
||||
public string? MobileNumber { get; set; }
|
||||
public bool? EmailVerified { get; set; }
|
||||
public bool? MobileNumberVerified { get; set; }
|
||||
public bool? IsActive { get; set; }
|
||||
public bool? IsLocked { get; set; }
|
||||
}
|
||||
|
||||
/// <summary>Body returned by every session-issuing endpoint. Tokens never appear
|
||||
/// here — they are delivered only as httpOnly cookies (docs/02-SECURITY.md §B.2).</summary>
|
||||
public sealed class AuthSessionResponse
|
||||
{
|
||||
public UserSummaryDto? User { get; set; }
|
||||
public int ExpiresIn { get; set; }
|
||||
}
|
||||
|
||||
public sealed class RegisterRequest
|
||||
{
|
||||
/// <summary>Optional — AuthHex requires a client-supplied id; ERPCore generates one when omitted.</summary>
|
||||
public Guid? UserId { get; set; }
|
||||
[Required] public Guid RoleId { get; set; }
|
||||
[Required] public Guid UserTypeId { get; set; }
|
||||
public string? Fullname { get; set; }
|
||||
public string? UserName { get; set; }
|
||||
public string? Nic { get; set; }
|
||||
public string? Email { get; set; }
|
||||
public string? MobileNumber { get; set; }
|
||||
public string? Password { get; set; }
|
||||
public string? DeviceName { get; set; }
|
||||
public bool? ChkUser { get; set; }
|
||||
}
|
||||
|
||||
public sealed class LoginRequest
|
||||
{
|
||||
[Required] public string Identifier { get; set; } = string.Empty;
|
||||
[Required] public string Password { get; set; } = string.Empty;
|
||||
public Guid? UserTypeId { get; set; }
|
||||
public string? DeviceName { get; set; }
|
||||
}
|
||||
|
||||
public sealed class VerifyOtpForLoginRequest
|
||||
{
|
||||
[Required] public string ReferenceNumber { get; set; } = string.Empty;
|
||||
[Required] public string OtpCode { get; set; } = string.Empty;
|
||||
public string? DeviceName { get; set; }
|
||||
}
|
||||
|
||||
public sealed class OtpLoginVerifiedResponse
|
||||
{
|
||||
public string? ReferenceNumber { get; set; }
|
||||
public Guid? UserId { get; set; }
|
||||
public bool Verified { get; set; }
|
||||
public UserSummaryDto? User { get; set; }
|
||||
public int ExpiresIn { get; set; }
|
||||
}
|
||||
|
||||
public sealed class RefreshTokenRequest
|
||||
{
|
||||
public string? DeviceName { get; set; }
|
||||
}
|
||||
|
||||
public sealed class GetUserDetailsResponse
|
||||
{
|
||||
public UserSummaryDto? User { get; set; }
|
||||
/// <summary>Passed through as-is — AuthHex's Role/UserType shapes aren't in the documented catalog.</summary>
|
||||
public JsonElement? Role { get; set; }
|
||||
public JsonElement? UserType { get; set; }
|
||||
}
|
||||
|
||||
/// <summary>AuthHex's UserType lookup (ERP_Auth_Service/API_DOCUMENTATION.md, listUserTypes).</summary>
|
||||
public sealed class UserTypeDto
|
||||
{
|
||||
public Guid UserTypeId { get; set; }
|
||||
public string? Code { get; set; }
|
||||
public string? Description { get; set; }
|
||||
}
|
||||
|
||||
public sealed class SessionDto
|
||||
{
|
||||
public string? SessionId { get; set; }
|
||||
public string? DeviceName { get; set; }
|
||||
public string? Browser { get; set; }
|
||||
public string? OS { get; set; }
|
||||
public string? IPAddress { get; set; }
|
||||
public DateTime? CreatedAt { get; set; }
|
||||
public DateTime? ExpiresAt { get; set; }
|
||||
public DateTime? RevokedAt { get; set; }
|
||||
public bool? IsActive { get; set; }
|
||||
}
|
||||
|
||||
public sealed class ChangeUserStatusRequest
|
||||
{
|
||||
[Required] public bool IsActive { get; set; }
|
||||
}
|
||||
|
||||
public sealed class LockUserAccountRequest
|
||||
{
|
||||
[Required] public bool IsLocked { get; set; }
|
||||
}
|
||||
|
||||
public sealed class ChangeUserPasswordRequest
|
||||
{
|
||||
[Required] public string CurrentPassword { get; set; } = string.Empty;
|
||||
[Required, MinLength(8)] public string NewPassword { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class VerifyPasswordRequest
|
||||
{
|
||||
[Required] public string Password { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class VerifyPasswordResponse
|
||||
{
|
||||
public bool Valid { get; set; }
|
||||
}
|
||||
|
||||
public sealed class UpdateUserRequest
|
||||
{
|
||||
public string? FullName { get; set; }
|
||||
public string? UserName { get; set; }
|
||||
public string? Nic { get; set; }
|
||||
public string? Address { get; set; }
|
||||
public string? Optional1 { get; set; }
|
||||
public string? Optional2 { get; set; }
|
||||
public string? Email { get; set; }
|
||||
public string? MobileNumber { get; set; }
|
||||
public string? NewPassword { get; set; }
|
||||
public string? CurrentPassword { get; set; }
|
||||
}
|
||||
|
||||
/// <summary>Passthrough — TOTP secret/QR payload shape is only loosely documented
|
||||
/// ("secret key, QR/otpauth URL ... from the third-party service").</summary>
|
||||
public sealed class TwoFaSetupResponse
|
||||
{
|
||||
public JsonElement Data { get; set; }
|
||||
}
|
||||
|
||||
public sealed class CompleteTwoFaSetupRequest
|
||||
{
|
||||
[Required] public string SecretKey { get; set; } = string.Empty;
|
||||
[Required] public string VerificationCode { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class CompleteTwoFaSetupResponse
|
||||
{
|
||||
public List<string> BackupCodes { get; set; } = new();
|
||||
public UserSummaryDto? User { get; set; }
|
||||
}
|
||||
|
||||
public sealed class VerifyTwoFaRequest
|
||||
{
|
||||
[Required] public string VerificationCode { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class DisableTwoFaRequest
|
||||
{
|
||||
[Required] public string VerificationCode { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class TwoFaStatusResponse
|
||||
{
|
||||
public bool IsMfaEnabled { get; set; }
|
||||
public bool IsVerified { get; set; }
|
||||
public DateTime? LastUsedAt { get; set; }
|
||||
public DateTime? VerifiedAt { get; set; }
|
||||
public bool HasBackupCodes { get; set; }
|
||||
}
|
||||
|
||||
public sealed class LogoutRequest
|
||||
{
|
||||
/// <summary>
|
||||
/// Optional: AuthHex returns no <c>userId</c> on login, so browsers cannot supply one.
|
||||
/// When omitted, the controller resolves it from the session token's UserId claim.
|
||||
/// </summary>
|
||||
public Guid? UserId { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
using System.ComponentModel.DataAnnotations;
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Dtos.Brands;
|
||||
|
||||
/// <summary>Brand resource (docs/11-BACKEND-PHASE1.md §2.6).</summary>
|
||||
public sealed record BrandDto(
|
||||
int BrandId, string Name, EntityStatus Status, DateTime CreatedAt, DateTime? UpdatedAt);
|
||||
|
||||
// Request DTOs — narrow: server-controlled fields (status, ids, timestamps)
|
||||
// are intentionally excluded to prevent over-posting (02-SECURITY B.6 / C.1). ----
|
||||
|
||||
public sealed class CreateBrandRequest
|
||||
{
|
||||
[Required, StringLength(200)] public string Name { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class UpdateBrandRequest
|
||||
{
|
||||
[Required, StringLength(200)] public string Name { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class UpdateBrandStatusRequest
|
||||
{
|
||||
[Required, EnumDataType(typeof(EntityStatus))] public EntityStatus Status { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,56 @@
|
||||
using System.ComponentModel.DataAnnotations;
|
||||
using ERPCore.Domain.Enums;
|
||||
|
||||
namespace ERPCore.Dtos.Categories;
|
||||
|
||||
// Category (docs/11-BACKEND-PHASE1.md §2.3) ------------------------------------
|
||||
// The hierarchy is exactly two levels: Category → SubCategory. The former
|
||||
// self-nesting tree (parentId / ?tree=true / CategoryTreeDto) was removed in
|
||||
// migration #2 — see docs/10 Part C.1.
|
||||
|
||||
/// <summary>Category resource — the top level.</summary>
|
||||
public sealed record CategoryDto(
|
||||
int CategoryId, string Name, EntityStatus Status, DateTime CreatedAt, DateTime? UpdatedAt);
|
||||
|
||||
/// <summary>Subcategory resource — the single optional level below a category.</summary>
|
||||
public sealed record SubCategoryDto(
|
||||
int SubCategoryId, int CategoryId, string Name, EntityStatus Status,
|
||||
DateTime CreatedAt, DateTime? UpdatedAt);
|
||||
|
||||
// Request DTOs — narrow: server-controlled fields (status, ids, timestamps)
|
||||
// are intentionally excluded to prevent over-posting (02-SECURITY B.6 / C.1). ----
|
||||
|
||||
public sealed class CreateCategoryRequest
|
||||
{
|
||||
[Required, StringLength(200)] public string Name { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class UpdateCategoryRequest
|
||||
{
|
||||
[Required, StringLength(200)] public string Name { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class UpdateCategoryStatusRequest
|
||||
{
|
||||
[Required, EnumDataType(typeof(EntityStatus))] public EntityStatus Status { get; set; }
|
||||
}
|
||||
|
||||
/// <summary>Body for <c>POST /categories/{categoryId}/subcategories</c>; the parent comes from the route.</summary>
|
||||
public sealed class CreateSubCategoryRequest
|
||||
{
|
||||
[Required, StringLength(200)] public string Name { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Body for <c>PUT /subcategories/{id}</c>. Name only — a subcategory cannot be reparented,
|
||||
/// since moving one would silently invalidate the category of every item referencing it.
|
||||
/// </summary>
|
||||
public sealed class UpdateSubCategoryRequest
|
||||
{
|
||||
[Required, StringLength(200)] public string Name { get; set; } = string.Empty;
|
||||
}
|
||||
|
||||
public sealed class UpdateSubCategoryStatusRequest
|
||||
{
|
||||
[Required, EnumDataType(typeof(EntityStatus))] public EntityStatus Status { get; set; }
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
namespace ERPCore.Dtos.Common;
|
||||
|
||||
/// <summary>
|
||||
/// Shared paging/sorting query binding (docs/11-BACKEND-PHASE1.md §1.5). Page size
|
||||
/// is clamped to <see cref="MaxPageSize"/> to enforce pagination bounds
|
||||
/// (02-SECURITY B.6). Bind from the query string on list endpoints.
|
||||
/// </summary>
|
||||
public class PageQuery
|
||||
{
|
||||
public const int MaxPageSize = 200;
|
||||
public const int DefaultPageSize = 20;
|
||||
|
||||
private int _page = 1;
|
||||
private int _pageSize = DefaultPageSize;
|
||||
|
||||
/// <summary>1-based page number (default 1).</summary>
|
||||
public int Page
|
||||
{
|
||||
get => _page;
|
||||
set => _page = value < 1 ? 1 : value;
|
||||
}
|
||||
|
||||
/// <summary>Page size (default 20, clamped to 1..200).</summary>
|
||||
public int PageSize
|
||||
{
|
||||
get => _pageSize;
|
||||
set => _pageSize = value < 1 ? DefaultPageSize : Math.Min(value, MaxPageSize);
|
||||
}
|
||||
|
||||
/// <summary>Free-text search term (<c>q</c>).</summary>
|
||||
public string? Q { get; set; }
|
||||
|
||||
/// <summary>Sort spec, e.g. <c>name</c> or <c>-createdAt</c>.</summary>
|
||||
public string? Sort { get; set; }
|
||||
|
||||
public int Skip => (Page - 1) * PageSize;
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
namespace ERPCore.Dtos.Common;
|
||||
|
||||
/// <summary>
|
||||
/// List envelope matching docs/11-BACKEND-PHASE1.md §1.4:
|
||||
/// <c>{ "items": [...], "pagination": { page, pageSize, totalItems, totalPages } }</c>.
|
||||
/// </summary>
|
||||
public sealed record PagedResponse<T>(IReadOnlyList<T> Items, PaginationDto Pagination)
|
||||
{
|
||||
public static PagedResponse<T> Create(IReadOnlyList<T> items, int page, int pageSize, int totalItems)
|
||||
{
|
||||
var totalPages = pageSize <= 0 ? 0 : (int)Math.Ceiling(totalItems / (double)pageSize);
|
||||
return new PagedResponse<T>(items, new PaginationDto(page, pageSize, totalItems, totalPages));
|
||||
}
|
||||
}
|
||||
|
||||
/// <summary>Pagination metadata block (docs/11 §1.4).</summary>
|
||||
public sealed record PaginationDto(int Page, int PageSize, int TotalItems, int TotalPages);
|
||||
@@ -0,0 +1,27 @@
|
||||
using System.ComponentModel.DataAnnotations;
|
||||
|
||||
namespace ERPCore.Dtos.Config;
|
||||
|
||||
/// <summary>
|
||||
/// Product configuration resource (docs/11-BACKEND-PHASE1.md §2.8). Singleton.
|
||||
/// <see cref="ItemTypesEnabled"/> is advisory (frontend-honoured) — see the entity docs.
|
||||
/// </summary>
|
||||
public sealed record ProductConfigDto(
|
||||
bool SubcategoriesEnabled, bool BrandsEnabled, bool ItemTypesEnabled,
|
||||
DateTime? UpdatedAt, int? UpdatedBy);
|
||||
|
||||
/// <summary>
|
||||
/// Full replacement of the flags. <c>UpdatedBy</c> is derived from the token, never posted.
|
||||
/// <para>
|
||||
/// The flags are <see cref="bool"/>? deliberately: <c>[Required]</c> on a non-nullable bool
|
||||
/// is a no-op (it always has a value), so a body of <c>{}</c> would bind every flag to
|
||||
/// <c>false</c> and silently switch all three features off. Nullable makes the requirement
|
||||
/// actually bind — an omitted flag is a 400, not an accidental disable.
|
||||
/// </para>
|
||||
/// </summary>
|
||||
public sealed class UpdateProductConfigRequest
|
||||
{
|
||||
[Required] public bool? SubcategoriesEnabled { get; set; }
|
||||
[Required] public bool? BrandsEnabled { get; set; }
|
||||
[Required] public bool? ItemTypesEnabled { get; set; }
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user