Files
ERP-core/Backend/PROGRESS.md
T
ImanThiyanga 057dd5aedc feat: Implement Category, Item, UOM, Vendor, and Warehouse services with CRUD operations
- Added CategoryService for managing categories with listing, tree structure, and creation functionalities.
- Introduced ItemService for item management, including listing, detail retrieval, creation, updating, and status management.
- Created UomService for handling unit of measure operations, including listing and creation.
- Developed VendorService for vendor management, supporting listing, detail retrieval, creation, updating, and status management.
- Implemented WarehouseService for warehouse and bin management, including listing warehouses, creating warehouses, and managing bins within warehouses.
- Added interfaces for each service to define the contract for service implementations.
- Generated Entity Framework Core model snapshot for database migrations.
2026-07-10 10:44:30 +05:30

6.5 KiB

Backend — PROGRESS (Phase 1: Inventory & Supply Chain)

Legend: [ ] not started · [~] in progress · [x] done Spec: docs/10-BACKEND-PHASE1.md (model + rules) · docs/11-BACKEND-PHASE1.md (API) Convention: docs/01-DOC-GUIDE.md §6. Update this file in the same commit as the code. When ticking [x], append a short note + any deviation.

0. Bootstrap

  • Solution + Web API project (net10.0), packages restored (00-CORE §5.4)
  • Folder structure per 00-CORE §5.3
  • [~] ErpDbContext + Npgsql wired; InitialCreate migration created (Infra/Persistence/Migrations, 8 master-data tables) — not yet applied: dotnet ef database update fails 28P01 password authentication failed for user "postgres" (local Postgres is running on :5432 but the postgres/postgres dev creds in appsettings.Development.json don't match this box). Generated SQL script validates cleanly. Action needed: set the real local creds, then ASPNETCORE_ENVIRONMENT=Development dotnet ef database update.
  • Serilog, JWT, Swagger, HealthChecks, ProblemDetails in Program.cs (JWT bearer validated; endpoints not yet [Authorize]-gated — see §6 auth note)
  • IUnitOfWork + UnitOfWork (transaction boundary)
  • Generic repository base + interfaces
  • ICurrentUser (audit stamp from token sub)
  • ProblemDetails middleware + domain exception → code mapping (System/Errors; full §7 catalog added to ErrorCodes)

1. Master Data

Code complete for all items below (2026-07-09): entities, EF configs, DTOs, services, controllers — solution builds clean, app boots, and the generated OpenAPI exposes every path in docs/11 §2. Marked [~] (not [x]) because the security gate (00-CORE §8) is not yet fully met: the foundational auth control (02-SECURITY B.1) and the audit trail (B.3, the AR-01 compensating control) land in §6, and the schema is not yet applied to a DB. No live DB integration test has run (creds blocker above). Flip to [x] once §6 auth+audit are in and endpoints are exercised against Postgres.

  • Item: entity + config + enums (ItemType, TrackingMode; EntityStatus added) — xmin/RowVersion concurrency token (Npgsql), unique SKU
  • [~] Item: repository (generic) + service + controller (CRUD, narrow DTOs, ETag/If-Match→412, SKU_DUPLICATE, reference validation) — server-controlled fields excluded (02-SECURITY C.1)
  • [~] UOM + UOM conversions (GET/POST /uoms, PUT /items/{id}/uom-conversions full-replace upsert)
  • [~] Category (hierarchy, GET /categories?tree=true nested build, parent-exists validation)
  • [~] Vendor (CRUD, ETag/If-Match, unique code, deactivate via PATCH /vendors/{id}/status)
  • [~] Warehouse + Bin (/warehouses, nested /warehouses/{id}/bins, bin code unique per warehouse)
  • [~] Item reorder settings (PUT /items/{id}/reorder full-replace upsert, warehouse-exists validation)

2. Procurement

  • Requisition (+ lines) + submit
  • RFQ + quotations + comparison
  • Purchase Order: create (auto-approve, approvalRequired flag), edit-while-open, approve (no-op), cancel
  • Purchase Return (outbound movement, reason code)

3. Goods Receipt

  • GRN create (against PO / direct), over-receipt tolerance
  • GRN confirm → FIFO layer + ledger + PO qtyReceived (single UoW txn, Idempotency-Key)
  • Inspection hold release / reject

4. Stock Core

  • StockLayer + StockLedger entities/config (ledger append-only)
  • FifoCostingService (consume oldest-first with row lock; valuation)
  • Stock enquiry (onHand / available / onHold / inTransit)
  • Ledger query · Valuation query

5. Stock Transactions

  • Transfer: create → dispatch (consume, In-Transit) → receive (dest layer, cost-preserving)
  • Adjustment (auto-post, mandatory reason code)
  • Count (cycle/full → enter counts → variance → post)
  • Reorder alerts (query) + suggest requisition

6. Cross-cutting

Auth-enforcement gap (open): JWT bearer validation is wired, but no token issuer exists yet and controllers are not [Authorize]-gated, so §1 endpoints are currently open. This is the AR-01/NFR-03 control surface — gate all v1 endpoints (fallback authorization policy) in the same change as POST /auth/login, then re-run the 02-SECURITY B.1 checklist and flip §1 items to [x].

  • Audit log on every mutation (who/when/old→new)
  • Document numbering sequences (per type, per year)
  • Auth: simple in-app login → JWT (POST /auth/login)
  • JournalEntryStub emitted per stock movement (data only)
  • Negative-stock policy enforcement (default block)
  • FEFO picking for perishables; block expired / on-hold issue

Deferred (Phase 2+ — do NOT build now, hooks only)

  • Vendor invoice + three-way match
  • Reservation/allocation fulfilment
  • RBAC policy enforcement + approval workflow activation

Done

2026-07-09 — Bootstrap verified + Master Data (§1) implemented

  • Bootstrap scaffolding confirmed against 00-CORE §5 (solution, packages, Program.cs wiring, UoW, generic repo, ICurrentUser, ProblemDetails handler). Added enum-as-string JSON (JsonStringEnumConverter) and registered the 5 master-data services.
  • Domain: 3 enums (ItemType, TrackingMode, EntityStatus) + 8 entities (Category, Uom, UomConversion, Item, ItemReorder, Vendor, Warehouse, Bin) with one IEntityTypeConfiguration each; FKs Restrict (masters deactivate, not cascade-delete), unique indexes (SKU, vendor/warehouse code, uom name, bin code per-warehouse), decimal precision, xmin concurrency token on Item/Vendor.
  • API: 5 controllers, lowercase routes matching docs/11 §2 exactly (verified via generated swagger.json). ETag/If-Match (428 if missing, 412 on mismatch), narrow request DTOs (no over-posting), PagedResponse<T> list envelope (§1.4), PageQuery with pageSize clamp ≤200 (B.6).
  • Migration InitialCreate generated (xmin correctly produces no DDL — uses the PG system column).
  • Verified: dotnet build clean (0 warn/0 err); app boots (Now listening… Application started); /api/meta 200; swagger.json 200 with all 13 master-data paths; DI resolves controller→service→repo→DbContext (a DB-backed call reaches Npgsql, failing only on creds).
  • Blocked / follow-ups: (1) apply migration — needs real local Postgres creds (see §0 note); (2) auth enforcement + audit trail — §6 (security gate for [x]); (3) no DELETE master endpoints — MASTER_IN_USE code reserved until transaction tables exist (deactivate-only per FR-MD-08).