mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-08-26 18:42:49 +00:00
fix: portal cannot load last-mile confirmation request
LAST_MILE_REQUESTS URL constants were missing the /api prefix every other endpoint in URLS.ts carries — all five calls (get, submit, contract view/document/sign) 404'd against the deployed API, so the departure notification's confirm link never loaded for the customer. Also widen GET /last-mile-requests/:id from @BookingStaff to @MixedAudience with the same ownership check submit()/sign() already use — the confirm page calls this as its first request, before the customer has done anything else, so it can't be staff-only. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -91,11 +91,15 @@ export class LastMileRequestsController {
|
||||
return this.contractService.sign(id, dto, user?.id ?? null);
|
||||
}
|
||||
|
||||
// Customer-facing like :id/contract/view — the portal's confirm page opens
|
||||
// this straight from the departure notification link before the customer
|
||||
// has done anything else, so it can't be staff-only. Service ownership-
|
||||
// checks against the resolved company; staff may also open it.
|
||||
@Get(':id')
|
||||
@BookingStaff(FREIGHT_PERMS.lastMile.requestView)
|
||||
@MixedAudience(FREIGHT_PERMS.lastMile.requestView)
|
||||
@ApiOperation({ summary: 'Get a last-mile confirmation request by ID' })
|
||||
findOne(@Param('id', ParseUUIDPipe) id: string) {
|
||||
return this.requestsService.findById(id);
|
||||
findOne(@Param('id', ParseUUIDPipe) id: string, @CurrentUser() user: TCurrentUser) {
|
||||
return this.requestsService.findById(id, user?.id ?? null);
|
||||
}
|
||||
|
||||
// No @BookingStaff — the customer (portal) fills this, not backoffice staff.
|
||||
|
||||
@@ -199,11 +199,25 @@ export class LastMileRequestsService {
|
||||
};
|
||||
}
|
||||
|
||||
async findById(id: string): Promise<LastMileRequest> {
|
||||
/**
|
||||
* `userId` is set only when a portal customer calls this directly (the
|
||||
* confirm-page deep link from the departure notification, before they've
|
||||
* submitted or signed anything) — staff and every internal caller pass
|
||||
* nothing and skip the check, same convention as submit()/sign().
|
||||
*/
|
||||
async findById(id: string, userId?: string | null): Promise<LastMileRequest> {
|
||||
const record = await this.requestsRepository.findById(id, {
|
||||
relations: { booking: { company: true } },
|
||||
});
|
||||
if (!record) throw new NotFoundException(`Last-mile request ${id} not found`);
|
||||
|
||||
if (userId) {
|
||||
const companyId = await this.bookingsService.resolveCustomerCompanyId(userId);
|
||||
if (companyId && record.booking?.companyId && companyId !== record.booking.companyId) {
|
||||
throw new BadRequestException('This request does not belong to your company');
|
||||
}
|
||||
}
|
||||
|
||||
return record;
|
||||
}
|
||||
|
||||
|
||||
@@ -224,10 +224,10 @@ export const URL_CONSTANTS = {
|
||||
},
|
||||
|
||||
LAST_MILE_REQUESTS: {
|
||||
BY_ID: (id: string) => `/last-mile-requests/${id}`,
|
||||
SUBMIT: (id: string) => `/last-mile-requests/${id}/submit`,
|
||||
CONTRACT_VIEW: (id: string) => `/last-mile-requests/${id}/contract/view`,
|
||||
CONTRACT_DOCUMENT: (id: string) => `/last-mile-requests/${id}/contract/document`,
|
||||
CONTRACT_SIGN: (id: string) => `/last-mile-requests/${id}/contract/sign`,
|
||||
BY_ID: (id: string) => `/api/last-mile-requests/${id}`,
|
||||
SUBMIT: (id: string) => `/api/last-mile-requests/${id}/submit`,
|
||||
CONTRACT_VIEW: (id: string) => `/api/last-mile-requests/${id}/contract/view`,
|
||||
CONTRACT_DOCUMENT: (id: string) => `/api/last-mile-requests/${id}/contract/document`,
|
||||
CONTRACT_SIGN: (id: string) => `/api/last-mile-requests/${id}/contract/sign`,
|
||||
},
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user