panels-origin/api/work_program_http.ts
Cursor Agent aed2f4531b
Implement client IAM v2: roles per tenant, CRUD matrix, scope, and panel UI
- Add IAM v2 auth with role_id, is_owner, status checks, and API key without tenant_admin bypass
- Enforce CRUD permissions and project/warehouse scope across API routes
- Rewrite usuarios.vue with ribbon, tree, user/role management, and permission matrix
- Add dynamic menu, route guards, usePermissions/useScope composables
- Apply role templates on create; filter project docs by category; hide cost tab without permission
- Add iam_test unit tests; update bootstrap and SaaS tenant admin to use role_id

Co-authored-by: alberto.martinez <alberto.martinez@mrdev.mx>
2026-09-08 18:16:59 +00:00

175 lines
6.9 KiB
TypeScript

import type { Context, Hono } from "hono";
import type { AuthUser } from "./auth.ts";
import { requireCoreAuth } from "./scope.ts";
import type { Db } from "./db.ts";
import { projectById } from "./db.ts";
import { requireAnyPermission, requirePermission } from "./permissions.ts";
import { denyUnlessProjectScope } from "./scope_enforcement.ts";
import {
createEmptyWorkProgram,
exportWorkProgram,
generateWorkProgram,
getVsCost,
getWorkProgram,
importWorkProgramExcel,
listConcepts,
listPartidas,
previewWorkProgramExcel,
recalculatePartidas,
updateConceptSlot,
updatePartidaAmount,
updateProgress,
} from "./work_program.ts";
type App = Hono<{ Variables: { user: AuthUser; db: Db } }>;
const viewAuth = [...requireCoreAuth, requirePermission("work_program.view")] as const;
async function ensureProject(c: Context, id: number): Promise<boolean> {
return await denyUnlessProjectScope(c, id);
}
async function readUpload(c: { req: { formData: () => Promise<FormData> } }): Promise<Uint8Array> {
const form = await c.req.formData();
const file = form.get("file");
if (!(file instanceof File)) throw new Error("Archivo Excel requerido (campo file)");
return new Uint8Array(await file.arrayBuffer());
}
export function registerWorkProgramRoutes(app: App) {
app.get("/v1/projects/:id/work-program", ...viewAuth, async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const data = await getWorkProgram(db, id);
return c.json({ ok: true, data });
});
app.get("/v1/projects/:id/work-program/concepts", ...viewAuth, async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const data = await listConcepts(db, id);
return c.json({ ok: true, data });
});
app.get("/v1/projects/:id/work-program/partidas", ...viewAuth, async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const data = await listPartidas(db, id);
return c.json({ ok: true, data });
});
app.get("/v1/projects/:id/work-program/vs-cost", ...requireCoreAuth, requirePermission("cost_control.view"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const data = await getVsCost(db, id);
return c.json({ ok: true, data });
});
app.post("/v1/projects/:id/work-program/preview", ...requireCoreAuth, requirePermission("work_program.create"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const bytes = await readUpload(c);
const preview = await previewWorkProgramExcel(bytes, id, db);
return c.json({ ok: true, data: preview });
});
app.post("/v1/projects/:id/work-program/import", ...requireCoreAuth, requirePermission("work_program.create"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const bytes = await readUpload(c);
const createChapters = c.req.query("create_chapters") !== "false";
const data = await importWorkProgramExcel(db, id, bytes, { createChapters });
return c.json({ ok: true, data });
});
app.post("/v1/projects/:id/work-program", ...requireCoreAuth, requirePermission("work_program.create"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const data = await createEmptyWorkProgram(db, id);
return c.json({ ok: true, data });
});
app.post("/v1/projects/:id/work-program/generate", ...requireCoreAuth, requirePermission("work_program.create"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const body = await c.req.json().catch(() => ({})) as { strategy?: string };
const data = await generateWorkProgram(db, id, body.strategy || "keyword");
return c.json({ ok: true, data });
});
app.post("/v1/projects/:id/work-program/recalculate-partidas", ...requireCoreAuth, requirePermission("work_program.update"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const env = await recalculatePartidas(db, id);
return c.json({ ok: true, data: env });
});
app.patch("/v1/projects/:id/work-program/concepts/:itemId/periods/:periodId", ...requireCoreAuth, requirePermission("work_program.update"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const body = await c.req.json() as { start_pct?: number; end_pct?: number };
const data = await updateConceptSlot(
db,
id,
Number(c.req.param("itemId")),
Number(c.req.param("periodId")),
Number(body.start_pct ?? 0),
Number(body.end_pct ?? 0),
);
return c.json({ ok: true, data });
});
app.patch("/v1/projects/:id/work-program/partidas/:chapterId/periods/:periodId", ...requireCoreAuth, requirePermission("work_program.update"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const body = await c.req.json() as { amount?: number };
const data = await updatePartidaAmount(
db,
id,
Number(c.req.param("chapterId")),
Number(c.req.param("periodId")),
Number(body.amount ?? 0),
);
return c.json({ ok: true, data });
});
app.patch("/v1/projects/:id/work-program/progress/:itemId/periods/:periodId", ...requireCoreAuth, requirePermission("work_program.update"), async (c) => {
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const db = c.get("db");
const body = await c.req.json() as { pct_complete?: number };
const data = await updateProgress(
db,
id,
Number(c.req.param("itemId")),
Number(c.req.param("periodId")),
Number(body.pct_complete ?? 0),
);
return c.json({ ok: true, data });
});
app.get("/v1/projects/:id/work-program/export", ...viewAuth, async (c) => {
const db = c.get("db");
const id = Number(c.req.param("id"));
if (!await ensureProject(c, id)) return;
const kind = (c.req.query("kind") === "partida" ? "partida" : "concepto") as "concepto" | "partida";
const project = await projectById(db, id);
if (!project) return c.json({ error: "Proyecto no encontrado" }, 404);
const bytes = await exportWorkProgram(db, id, kind, String(project.name || "Obra"));
const filename = kind === "partida" ? "programa-partidas.xlsx" : "programa-conceptos.xlsx";
c.header("Content-Type", "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet");
c.header("Content-Disposition", `attachment; filename="${filename}"`);
return c.body(bytes.slice());
});
}