mirror of
https://origin.cursor.com/mrdevmx/panels.git
synced 2026-10-09 18:43:18 +00:00
- Add IAM v2 auth with role_id, is_owner, status checks, and API key without tenant_admin bypass - Enforce CRUD permissions and project/warehouse scope across API routes - Rewrite usuarios.vue with ribbon, tree, user/role management, and permission matrix - Add dynamic menu, route guards, usePermissions/useScope composables - Apply role templates on create; filter project docs by category; hide cost tab without permission - Add iam_test unit tests; update bootstrap and SaaS tenant admin to use role_id Co-authored-by: alberto.martinez <alberto.martinez@mrdev.mx>
175 lines
6.9 KiB
TypeScript
175 lines
6.9 KiB
TypeScript
import type { Context, Hono } from "hono";
|
|
import type { AuthUser } from "./auth.ts";
|
|
import { requireCoreAuth } from "./scope.ts";
|
|
import type { Db } from "./db.ts";
|
|
import { projectById } from "./db.ts";
|
|
import { requireAnyPermission, requirePermission } from "./permissions.ts";
|
|
import { denyUnlessProjectScope } from "./scope_enforcement.ts";
|
|
import {
|
|
createEmptyWorkProgram,
|
|
exportWorkProgram,
|
|
generateWorkProgram,
|
|
getVsCost,
|
|
getWorkProgram,
|
|
importWorkProgramExcel,
|
|
listConcepts,
|
|
listPartidas,
|
|
previewWorkProgramExcel,
|
|
recalculatePartidas,
|
|
updateConceptSlot,
|
|
updatePartidaAmount,
|
|
updateProgress,
|
|
} from "./work_program.ts";
|
|
|
|
type App = Hono<{ Variables: { user: AuthUser; db: Db } }>;
|
|
|
|
const viewAuth = [...requireCoreAuth, requirePermission("work_program.view")] as const;
|
|
|
|
async function ensureProject(c: Context, id: number): Promise<boolean> {
|
|
return await denyUnlessProjectScope(c, id);
|
|
}
|
|
|
|
async function readUpload(c: { req: { formData: () => Promise<FormData> } }): Promise<Uint8Array> {
|
|
const form = await c.req.formData();
|
|
const file = form.get("file");
|
|
if (!(file instanceof File)) throw new Error("Archivo Excel requerido (campo file)");
|
|
return new Uint8Array(await file.arrayBuffer());
|
|
}
|
|
|
|
export function registerWorkProgramRoutes(app: App) {
|
|
app.get("/v1/projects/:id/work-program", ...viewAuth, async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const data = await getWorkProgram(db, id);
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.get("/v1/projects/:id/work-program/concepts", ...viewAuth, async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const data = await listConcepts(db, id);
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.get("/v1/projects/:id/work-program/partidas", ...viewAuth, async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const data = await listPartidas(db, id);
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.get("/v1/projects/:id/work-program/vs-cost", ...requireCoreAuth, requirePermission("cost_control.view"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const data = await getVsCost(db, id);
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.post("/v1/projects/:id/work-program/preview", ...requireCoreAuth, requirePermission("work_program.create"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const bytes = await readUpload(c);
|
|
const preview = await previewWorkProgramExcel(bytes, id, db);
|
|
return c.json({ ok: true, data: preview });
|
|
});
|
|
|
|
app.post("/v1/projects/:id/work-program/import", ...requireCoreAuth, requirePermission("work_program.create"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const bytes = await readUpload(c);
|
|
const createChapters = c.req.query("create_chapters") !== "false";
|
|
const data = await importWorkProgramExcel(db, id, bytes, { createChapters });
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.post("/v1/projects/:id/work-program", ...requireCoreAuth, requirePermission("work_program.create"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const data = await createEmptyWorkProgram(db, id);
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.post("/v1/projects/:id/work-program/generate", ...requireCoreAuth, requirePermission("work_program.create"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const body = await c.req.json().catch(() => ({})) as { strategy?: string };
|
|
const data = await generateWorkProgram(db, id, body.strategy || "keyword");
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.post("/v1/projects/:id/work-program/recalculate-partidas", ...requireCoreAuth, requirePermission("work_program.update"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const env = await recalculatePartidas(db, id);
|
|
return c.json({ ok: true, data: env });
|
|
});
|
|
|
|
app.patch("/v1/projects/:id/work-program/concepts/:itemId/periods/:periodId", ...requireCoreAuth, requirePermission("work_program.update"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const body = await c.req.json() as { start_pct?: number; end_pct?: number };
|
|
const data = await updateConceptSlot(
|
|
db,
|
|
id,
|
|
Number(c.req.param("itemId")),
|
|
Number(c.req.param("periodId")),
|
|
Number(body.start_pct ?? 0),
|
|
Number(body.end_pct ?? 0),
|
|
);
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.patch("/v1/projects/:id/work-program/partidas/:chapterId/periods/:periodId", ...requireCoreAuth, requirePermission("work_program.update"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const body = await c.req.json() as { amount?: number };
|
|
const data = await updatePartidaAmount(
|
|
db,
|
|
id,
|
|
Number(c.req.param("chapterId")),
|
|
Number(c.req.param("periodId")),
|
|
Number(body.amount ?? 0),
|
|
);
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.patch("/v1/projects/:id/work-program/progress/:itemId/periods/:periodId", ...requireCoreAuth, requirePermission("work_program.update"), async (c) => {
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const db = c.get("db");
|
|
const body = await c.req.json() as { pct_complete?: number };
|
|
const data = await updateProgress(
|
|
db,
|
|
id,
|
|
Number(c.req.param("itemId")),
|
|
Number(c.req.param("periodId")),
|
|
Number(body.pct_complete ?? 0),
|
|
);
|
|
return c.json({ ok: true, data });
|
|
});
|
|
|
|
app.get("/v1/projects/:id/work-program/export", ...viewAuth, async (c) => {
|
|
const db = c.get("db");
|
|
const id = Number(c.req.param("id"));
|
|
if (!await ensureProject(c, id)) return;
|
|
const kind = (c.req.query("kind") === "partida" ? "partida" : "concepto") as "concepto" | "partida";
|
|
const project = await projectById(db, id);
|
|
if (!project) return c.json({ error: "Proyecto no encontrado" }, 404);
|
|
const bytes = await exportWorkProgram(db, id, kind, String(project.name || "Obra"));
|
|
const filename = kind === "partida" ? "programa-partidas.xlsx" : "programa-conceptos.xlsx";
|
|
c.header("Content-Type", "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet");
|
|
c.header("Content-Disposition", `attachment; filename="${filename}"`);
|
|
return c.body(bytes.slice());
|
|
});
|
|
}
|