mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-09-02 06:53:38 +00:00
- Implemented a method in to permanently delete wagons without history. - Added corresponding permissions for hard delete actions in . - Updated the UI components to include purge actions, ensuring they are only available to users with the appropriate permissions. - Created modals for confirming permanent deletions in and . - Enhanced API services to handle purge requests for locomotives, wagons, and routes. - Added tests for the purge functionality in both and services to ensure proper behavior and error handling.
93 lines
3.0 KiB
TypeScript
93 lines
3.0 KiB
TypeScript
import {
|
|
Body,
|
|
Controller,
|
|
Delete,
|
|
Get,
|
|
HttpCode,
|
|
HttpStatus,
|
|
Param,
|
|
ParseUUIDPipe,
|
|
Patch,
|
|
Post,
|
|
Query,
|
|
} from '@nestjs/common';
|
|
import { ApiBearerAuth, ApiOperation, ApiTags } from '@nestjs/swagger';
|
|
|
|
import {
|
|
BookingStaff,
|
|
FleetManage,
|
|
StaffReference,
|
|
} from '../../common/booking-guards';
|
|
import { FREIGHT_PERMS } from '../../seed/freight-permissions.registry';
|
|
import { CreateLocomotiveDto } from './dto/create-locomotive.dto';
|
|
import { FilterLocomotivesDto } from './dto/filter-locomotives.dto';
|
|
import { UpdateLocomotiveDto } from './dto/update-locomotive.dto';
|
|
import { LocomotivesService } from './locomotives.service';
|
|
|
|
@ApiTags('locomotives')
|
|
@ApiBearerAuth()
|
|
// No class-level guard: reads are login-only reference data (any staff can
|
|
// fetch a locomotive for a cross-flow view without the fleet:view that drives
|
|
// the Fleet sidebar). Every mutation carries its own @FleetManage().
|
|
@Controller('locomotives')
|
|
export class LocomotivesController {
|
|
constructor(private readonly locomotivesService: LocomotivesService) {}
|
|
|
|
@Get()
|
|
@StaffReference()
|
|
@ApiOperation({ summary: 'List locomotives' })
|
|
findAll(@Query() filter: FilterLocomotivesDto) {
|
|
return this.locomotivesService.findAll(filter);
|
|
}
|
|
|
|
// Must be declared before @Get(':id') so the path isn't captured as an id.
|
|
@Get('paged')
|
|
@StaffReference()
|
|
@ApiOperation({ summary: 'List locomotives, paginated ({items, meta})' })
|
|
findAllPaged(@Query() filter: FilterLocomotivesDto) {
|
|
return this.locomotivesService.findAllPaged(filter);
|
|
}
|
|
|
|
@Get(':id')
|
|
@StaffReference()
|
|
@ApiOperation({ summary: 'Get a locomotive by ID' })
|
|
findOne(@Param('id', ParseUUIDPipe) id: string) {
|
|
return this.locomotivesService.findById(id);
|
|
}
|
|
|
|
@Post()
|
|
@FleetManage(FREIGHT_PERMS.locomotives.create)
|
|
@ApiOperation({ summary: 'Create a locomotive' })
|
|
create(@Body() dto: CreateLocomotiveDto) {
|
|
return this.locomotivesService.create(dto);
|
|
}
|
|
|
|
@Patch(':id')
|
|
@FleetManage(FREIGHT_PERMS.locomotives.update)
|
|
@ApiOperation({ summary: 'Update a locomotive' })
|
|
update(@Param('id', ParseUUIDPipe) id: string, @Body() dto: UpdateLocomotiveDto) {
|
|
return this.locomotivesService.update(id, dto);
|
|
}
|
|
|
|
@Post(':id/decommission')
|
|
@FleetManage(FREIGHT_PERMS.locomotives.delete)
|
|
@ApiOperation({ summary: 'Decommission a locomotive' })
|
|
decommission(@Param('id', ParseUUIDPipe) id: string) {
|
|
return this.locomotivesService.decommission(id);
|
|
}
|
|
|
|
// BookingStaff, not FleetManage: the latter also accepts the coarse
|
|
// fleet:manage key, which would hand an irreversible purge to everyone who
|
|
// can edit the fleet. This action requires its own grant, nothing else.
|
|
@Delete(':id/permanent')
|
|
@BookingStaff(FREIGHT_PERMS.locomotives.hardDelete)
|
|
@HttpCode(HttpStatus.NO_CONTENT)
|
|
@ApiOperation({
|
|
summary:
|
|
'Permanently delete a locomotive (irreversible; refused if any train references it)',
|
|
})
|
|
purge(@Param('id', ParseUUIDPipe) id: string) {
|
|
return this.locomotivesService.purge(id);
|
|
}
|
|
}
|