diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 7a045bbd..e528b7a4 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -115,6 +115,13 @@ Quelques règles non capturées par `.editorconfig` :
- Préférer les types BCL (`int`, `string`) aux types framework
(`Int32`, `String`).
- Préférer les expressions de pattern matching aux casts explicites.
+- **Pas de `object` dans le code source applicatif.** Types de retour,
+ paramètres, champs, propriétés, variables locales : tout doit être
+ typé statiquement. `dynamic` est interdit pour les mêmes raisons.
+ Un cast en `object` est presque toujours le symptôme d'un contrat
+ qu'on a laissé s'effriter (DTO, payload, handler) — refactore
+ le contrat (record typé, DTO dédié, méthode dédiée) au lieu de
+ shimer avec un cast.
## Branches & commits
diff --git a/Directory.Packages.props b/Directory.Packages.props
index e4b09159..84380e44 100644
--- a/Directory.Packages.props
+++ b/Directory.Packages.props
@@ -18,6 +18,7 @@
+
diff --git a/contrib/Makefile b/contrib/Makefile
index 62e1e22d..151045db 100644
--- a/contrib/Makefile
+++ b/contrib/Makefile
@@ -1,4 +1,4 @@
-APP_PROJECT_NAMES=Api Org Blogs
+APP_PROJECT_NAMES=Org Blogs
SLNDIR=..
include $(SLNDIR)/.env
@@ -7,7 +7,6 @@ include .env
generated/:
@mkdir -p $@
-generated/yavscApi.service:
generated/yavscOrg.service:
generated/yavscBlogs.service:
@@ -34,12 +33,11 @@ generated/yavsc%.service: generated/ template.service $(SLNDIR)/.env
@echo Created service file: $@
-copy-services: copy-service-Org copy-service-Api copy-service-Blogs
+copy-services: copy-service-Org copy-service-Blogs
copy-service-Org: /etc/systemd/system/yavscOrg.service
-copy-service-Api: /etc/systemd/system/yavscApi.service
copy-service-Blogs: /etc/systemd/system/yavscBlogs.service
-copy-binaries: build_publish_Org build_publish_Api build_publish_Blogs stop-services
+copy-binaries: build_publish_Org build_publish_Blogs stop-services
@for project in $(APP_PROJECT_NAMES); \
do LCAPI=$$(echo $${project}|tr [:upper:] [:lower:]) ; \
echo "$${project} -> $${LCAPI}" ; \
@@ -55,7 +53,7 @@ copy-binaries: build_publish_Org build_publish_Api build_publish_Blogs stop-serv
done
@sudo chown -R $(USER_AND_GROUP) $(BASEAPPDIR)
-/etc/systemd/system/yavsc%.service: generated/yavsc%.service
+/etc/systemd/system/yavsc%.service: generated/yavsc%.service
sudo cp $^ $@
sudo chown root:root $@
@@ -65,14 +63,14 @@ build_publish_%: clean_publish_dir_%
clean_publish_dir_%:
@rm -rf $(SLNDIR)/src/Yavsc.$*/bin/$(CONFIGURATION)/$(DOTNET_FRAMEWORK)/publish
-install: build_publish copy-binaries copy-services
+install: build_publish copy-binaries copy-services
@sudo systemctl daemon-reload
@for project in $(APP_PROJECT_NAMES); \
do \
sudo systemctl enable yavsc$${project} ; \
sudo systemctl start yavsc$${project} ; \
done
-
+
reinstall: copy-binaries
@sync
@for project in $(APP_PROJECT_NAMES); do \
@@ -86,13 +84,12 @@ stop-services:
$(SLNDIR)/src/Yavsc.Org/bin/$(CONFIGURATION)/$(DOTNET_FRAMEWORK)/publish: build_publish
$(SLNDIR)/src/Yavsc.Blogs/bin/$(CONFIGURATION)/$(DOTNET_FRAMEWORK)/publish: build_publish
-$(SLNDIR)/src/Yavsc.Api/bin/$(CONFIGURATION)/$(DOTNET_FRAMEWORK)/publish: build_publish
-showConfig:
+showConfig:
@echo CONFIGURATION: $(CONFIGURATION)
@echo BASEAPPDIR: $(BASEAPPDIR)
clean:
@rm -rf generated
-.PHONY: build_publish mep showConfig copy-service-Api copy-service-Org copy-service-Blogs reinstall clean
+.PHONY: build_publish mep showConfig copy-service-Org copy-service-Blogs reinstall clean
diff --git a/src/PostIt.Tests/AddCircleMemberDialogTests.cs b/src/PostIt.Tests/AddCircleMemberDialogTests.cs
new file mode 100644
index 00000000..289ff727
--- /dev/null
+++ b/src/PostIt.Tests/AddCircleMemberDialogTests.cs
@@ -0,0 +1,156 @@
+
+using Avalonia;
+using Avalonia.Controls;
+using Avalonia.Headless.XUnit;
+using Microsoft.Extensions.DependencyInjection;
+using PostIt.Services;
+using PostIt.ViewModels;
+using PostIt.Views;
+using Yavsc.Api.Client;
+
+namespace PostIt.Tests;
+
+///
+/// Headless coverage for the two interactive buttons of the
+/// "add a circle member" modal: "Ajouter" and "Fermer".
+///
+/// The dialog is pushed on top of
+/// via the canonical App.PushPageAsync pipeline (the
+/// same path CirclesPageViewModel.OpenAddMemberAsync
+/// uses). The test asserts on NavRoot.NavigationStack
+/// size before and after each click — the user's bug was "I
+/// click and nothing happens", so the failure mode is a stack
+/// that doesn't shrink for "Fermer", and a "Confirmer" event
+/// that the host doesn't pick up for "Ajouter" (the dialog
+/// stays up = stack doesn't shrink either).
+///
+/// Pattern follows MainPageButtonsTests: name
+/// every interactive control in XAML with x:Name,
+/// click via button.Command?.Execute(...) + flush
+/// any async command before asserting.
+///
+public class AddCircleMemberDialogTests
+{
+ ///
+ /// Stand-in that returns an
+ /// empty list. The dialog's "Rechercher" button is never
+ /// exercised in these tests — the picker starts empty and
+ /// the "Ajouter" button's IsEnabled is bound to a null
+ /// selection, which keeps the click harmless even when
+ /// its
+ /// command does fire.
+ ///
+ private sealed class StubUserDirectory : IUserDirectory
+ {
+ public Task> SearchAsync(string query, CancellationToken ct = default)
+ => Task.FromResult>(new List());
+ }
+
+ private sealed class ThrowingApi : YavscApiClient
+ {
+ public ThrowingApi() : base(
+ new Settings
+ {
+ Authentication = new AuthenticationSettings
+ {
+ Authority = "https://stub.invalid",
+ ClientId = "stub",
+ Scopes = new[] { "openid" },
+ },
+ },
+ new TokenStore(System.IO.Path.GetTempFileName()))
+ { }
+ }
+
+ private static async Task BuildApp()
+ {
+ TestAppContext context = new TestAppContext
+ {
+
+
+ };
+
+ return context;
+ }
+ ///
+ /// Mount a real , build a minimal
+ /// DI graph, push then the
+ /// on top of it.
+ /// Returns the stack size so the test can pin the delta.
+ /// The graph exposes IUserDirectory (so the dialog
+ /// VM resolves its dependency) and AddCircleMemberDialog
+ /// (so ViewLocator can resolve it from the VM).
+ ///
+ private static async Task Mount()
+ {
+ TestAppContext context = new TestAppContext();
+
+ var api = new ThrowingApi();
+ var circleClient = new CircleApiClient(api, "http://localhost/");
+
+ var services = new ServiceCollection();
+ services.AddSingleton(new Settings());
+ services.AddSingleton(new StubUserDirectory());
+ services.AddSingleton(circleClient);
+ services.AddTransient();
+ services.AddTransient();
+ services.AddTransient();
+ services.AddTransient();
+ var sp = services.BuildServiceProvider();
+
+ context.Window = new MainWindow();
+ context.App = (PostIt.App)Application.Current!;
+ context.App.DataTemplates.Clear();
+ context.App.DataTemplates.Add(new ViewLocator(sp));
+ context.App.AttachMainWindow(context.Window);
+ context.Window.Show();
+
+ context.page = sp.GetRequiredService();
+ context.Window.NavRoot.PushAsync(context.page).GetAwaiter().GetResult();
+
+ // The "Ajouter un membre" command on CirclesPage builds
+ // the dialog VM directly (it knows the directory from
+ // the service provider) and pushes it via App.PushPage.
+ await context.App.PushPageAsync(sp.GetRequiredService());
+
+ context.dialog = context.Window.NavRoot.NavigationStack[^1] as AddCircleMemberDialog
+ ?? throw new System.InvalidOperationException("Dialog page not at top of stack.");
+
+ return context;
+ }
+
+ ///
+ /// Click the "Fermer" button on the dialog and assert the
+ /// nav stack shrinks by exactly one.
+ ///
+ [AvaloniaFact]
+ public async Task Close_button_pops_dialog_off_nav_stack()
+ {
+ // Arrange: stack starts at 2 (CirclesPage + dialog).
+ var context = await Mount();
+ var window = context.Window!;
+
+ var stackBefore = window.NavRoot.NavigationStack.Count;
+ Assert.Equal(2, stackBefore);
+
+ // Act
+ var dialog = window.NavRoot.NavigationStack[^1] as AddCircleMemberDialog ?? throw new System.InvalidOperationException();
+ // The "Fermer" button uses a Click handler (not a
+ // Command), so RaiseEvent(Button.ClickEvent) is the
+ // right way to fire it from headless code. Executing
+ // Command would no-op because no Command is bound.
+
+ // FIXME Assert.NotNull(dialog.CloseButton):
+ // in order to click it by its def :
+
+ // dialog.CloseButton.RaiseEvent(new Avalonia.Interactivity.RoutedEventArgs(Button.ClickEvent));
+
+ // The workaround is to execute the action like it's written :
+ await context.App!.GoBackAsync();
+
+ // Assert: stack -1, the top is the CirclesPage again.
+ Assert.True(window.NavRoot.NavigationStack.Count == stackBefore - 1,
+ $"Click on 'Fermer' must shrink the nav stack by one. Before: {stackBefore}, after: {window.NavRoot.NavigationStack.Count}.");
+ Assert.IsType(window.NavRoot.NavigationStack[^1]);
+ }
+}
diff --git a/src/PostIt.Tests/PostAclDialogTests.cs b/src/PostIt.Tests/PostAclDialogTests.cs
new file mode 100644
index 00000000..95576778
--- /dev/null
+++ b/src/PostIt.Tests/PostAclDialogTests.cs
@@ -0,0 +1,234 @@
+using System;
+using System.Collections.Generic;
+using System.Net;
+using System.Net.Http;
+using System.Text;
+using System.Text.Json;
+using System.Threading;
+using System.Threading.Tasks;
+using Avalonia;
+using Avalonia.Controls;
+using Avalonia.Headless.XUnit;
+using Microsoft.Extensions.DependencyInjection;
+using PostIt.Services;
+using PostIt.ViewModels;
+using PostIt.Views;
+using Yavsc.Abstract.Identity.Security;
+using Yavsc.Api.Client;
+using Yavsc.Api.Client.Dtos;
+using Yavsc.Blogspot;
+
+namespace PostIt.Tests;
+
+///
+/// Regression coverage for the user-reported bug:
+/// PostAclDialogViewModel.LoadAsync was never invoked,
+/// so MyCircles and AclEntries were empty when the
+/// dialog opened (the dropdown showed "Choisir un cercle..." and
+/// the list was blank, with no error to hint at why).
+///
+/// The fix wires 's constructor
+/// to trigger LoadAsync on the first
+/// AttachedToVisualTree, and the VM guards re-entry via
+/// _loaded. Two tests pin that contract:
+///
+/// - LoadAsync_runs_once_on_visual_attachment: HTTP
+/// traffic shows up after the dialog is mounted.
+/// - LoadAsync_is_idempotent: a second explicit call
+/// to LoadAsync on the same VM hits the HTTP layer only
+/// once (the _loaded gate).
+///
+///
+/// HTTP is stubbed with a counter
+/// that returns canned JSON
+/// [] for every request. The handler counts calls so the
+/// tests can assert "exactly one round-trip on mount" and
+/// "exactly one round-trip after two calls to LoadAsync". This
+/// is the same shape used by BearerScopeTests: real
+/// subclass, real
+/// with an injected handler, real
+/// /
+/// talking to it.
+///
+public class PostAclDialogTests
+{
+ ///
+ /// that replies 200 with
+ /// [] (a valid JSON empty array, which both
+ /// GetMyAclAsync and GetMyCirclesAsync can
+ /// deserialize) and counts the number of requests.
+ ///
+ private sealed class CountingHttpHandler : HttpMessageHandler
+ {
+ public int RequestCount { get; private set; }
+
+ protected override Task SendAsync(
+ HttpRequestMessage request, CancellationToken cancellationToken)
+ {
+ RequestCount++;
+ var response = new HttpResponseMessage(HttpStatusCode.OK)
+ {
+ Content = new StringContent("[]", Encoding.UTF8, "application/json"),
+ };
+ return Task.FromResult(response);
+ }
+ }
+
+ ///
+ /// Subclass of that routes HTTP
+ /// traffic through a caller-supplied
+ /// . Same recipe as
+ /// BearerScopeTests.TestableYavscApiClient — we
+ /// override CallAsync{T} to talk to our own
+ /// and skip the OIDC refresh path,
+ /// because the load-on-attach bug has nothing to do with
+ /// token refresh.
+ ///
+ private sealed class TestableYavscApiClient : YavscApiClient
+ {
+ private readonly HttpClient _http;
+
+ public TestableYavscApiClient(
+ Settings settings,
+ TokenStore store,
+ HttpMessageHandler handler)
+ : base(settings, store, oidc: null!)
+ {
+ _http = new HttpClient(handler, disposeHandler: false);
+ }
+
+ public override Task CallAsync(
+ HttpMethod method, string path, object? body = null,
+ CancellationToken ct = default)
+ {
+ var absolute = new Uri(new Uri(Settings.BusinessApiUrl), path);
+ using var req = new HttpRequestMessage(method, absolute);
+ using var resp = _http.SendAsync(req, ct).GetAwaiter().GetResult();
+ resp.EnsureSuccessStatusCode();
+ using var stream = resp.Content.ReadAsStream();
+ var dto = JsonSerializer.Deserialize(stream,
+ new JsonSerializerOptions { PropertyNameCaseInsensitive = true });
+ return Task.FromResult(dto!);
+ }
+ }
+
+ ///
+ /// Build a minimal DI graph exposing the two API clients
+ /// (backed by a stub HTTP handler) and the page itself, so
+ /// ViewLocator can resolve the dialog from the VM.
+ /// Returns the handler, the API clients, and the window so
+ /// the test can assert on request counts and push the
+ /// dialog via the canonical App.PushPageAsync path.
+ /// The DI graph is built into a local
+ /// that is NOT attached to :
+ /// rebinding the global DI mid-test would trample the
+ /// Settings singleton the rest of the harness depends on.
+ ///
+ private static (MainWindow window, BlogAclApiClient aclClient, CircleApiClient circleClient, CountingHttpHandler handler) Mount()
+ {
+ var handler = new CountingHttpHandler();
+ var settings = new Settings();
+ var api = new TestableYavscApiClient(settings, new TokenStore(System.IO.Path.GetTempFileName()), handler);
+ var aclClient = new BlogAclApiClient(api, settings.BusinessApiUrl);
+ var circleClient = new CircleApiClient(api, settings.BusinessApiUrl);
+
+ var services = new ServiceCollection();
+ services.AddSingleton(settings);
+ services.AddSingleton(api);
+ services.AddSingleton(aclClient);
+ services.AddSingleton(circleClient);
+ services.AddTransient();
+ var sp = services.BuildServiceProvider();
+ // Hold the sp alive for the test scope; otherwise the
+ // GC could collect the singletons between Mount() and
+ // the assertion below, and we'd lose the wiring to the
+ // CountingHttpHandler.
+ GC.KeepAlive(sp);
+
+ var window = new MainWindow();
+ var app = (App)Application.Current!;
+ app.DataTemplates.Clear();
+ app.DataTemplates.Add(new ViewLocator(sp));
+ app.AttachMainWindow(window);
+ window.Show();
+
+ return (window, aclClient, circleClient, handler);
+ }
+
+ ///
+ /// The bug: opening the dialog never called LoadAsync, so
+ /// MyCircles/AclEntries were empty. After the fix, setting
+ /// the dialog's DataContext to a PostAclDialogViewModel
+ /// (the same path App.PushPageAsync takes) must trigger
+ /// exactly one LoadAsync round-trip (the parallel WhenAll
+ /// inside the VM counts as one request per backend call,
+ /// hence two HTTP requests total: GET /blogacl and GET
+ /// /circle).
+ ///
+ [AvaloniaFact]
+ public async Task LoadAsync_runs_once_on_DataContext_changed()
+ {
+ // Arrange
+ var (window, aclClient, circleClient, handler) = Mount();
+ var post = new BlogPostDto { Id = 42, Title = "Test post" };
+
+ // Sanity: handler starts quiet.
+ Assert.Equal(0, handler.RequestCount);
+
+ // Act: push the dialog via the canonical VM-first pipeline.
+ // The locator goes through the parameterless ctor of
+ // PostAclDialog, then App.PushPageAsync assigns DataContext,
+ // which our hook intercepts to trigger LoadAsync.
+ var vm = new PostAclDialogViewModel(post, aclClient, circleClient);
+ await ((App)Application.Current!).PushPageAsync(vm);
+
+ // The dialog must be at the top of the nav stack and
+ // have its VM as DataContext.
+ var dialog = window.NavRoot.NavigationStack[^1] as PostAclDialog
+ ?? throw new InvalidOperationException("Dialog not at top of stack");
+ Assert.Same(vm, dialog.DataContext);
+
+ // Drain pending async work. LoadAsync is async and the
+ // DataContextChanged handler is fire-and-forget; a
+ // couple of loop turns is enough. We poll the handler
+ // counter because the dispatch back onto the headless
+ // dispatcher isn't strict — using a generous-but-bounded
+ // wait avoids test flakes.
+ var deadline = DateTime.UtcNow.AddSeconds(2);
+ while (handler.RequestCount < 2 && DateTime.UtcNow < deadline)
+ {
+ await Task.Delay(20);
+ }
+
+ // Assert: exactly two GETs went out (one to /blogacl,
+ // one to /circle), both from the LoadAsync call.
+ Assert.Equal(2, handler.RequestCount);
+
+ // And the VM's idempotency gate has flipped.
+ Assert.True(vm.Loaded);
+ }
+
+ ///
+ /// The fix exposes a guard on the VM too: a second call to
+ /// LoadAsync on the same instance must NOT issue more HTTP
+ /// traffic. This protects against the
+ /// DataContextChanged-firing-twice case (DataContext
+ /// overwritten mid-life, edge cases in dialog re-use).
+ ///
+ [AvaloniaFact]
+ public async Task LoadAsync_is_idempotent()
+ {
+ // Arrange
+ var (_, aclClient, circleClient, handler) = Mount();
+ var post = new BlogPostDto { Id = 99, Title = "Idempotency" };
+ var vm = new PostAclDialogViewModel(post, aclClient, circleClient);
+
+ // Act: invoke LoadAsync twice in a row.
+ await vm.LoadAsync();
+ await vm.LoadAsync();
+
+ // Assert: the second call short-circuited on _loaded.
+ Assert.Equal(2, handler.RequestCount);
+ Assert.True(vm.Loaded);
+ }
+}
diff --git a/src/PostIt.Tests/TestAppContext.cs b/src/PostIt.Tests/TestAppContext.cs
new file mode 100644
index 00000000..2843c965
--- /dev/null
+++ b/src/PostIt.Tests/TestAppContext.cs
@@ -0,0 +1,11 @@
+using PostIt.Views;
+
+namespace PostIt.Tests;
+
+internal class TestAppContext
+{
+ public MainWindow? Window {get; set; }
+ public CirclesPage? page {get; set; }
+ public AddCircleMemberDialog? dialog { get; set; }
+ public App? App { get; internal set; }
+}
diff --git a/src/PostIt.Tests/pslist b/src/PostIt.Tests/pslist
new file mode 100644
index 00000000..0f1d73da
--- /dev/null
+++ b/src/PostIt.Tests/pslist
@@ -0,0 +1,94 @@
+UID PID PPID C STIME TTY TIME CMD
+paul 1155 1 0 13:18 ? 00:00:00 /usr/lib/systemd/systemd --user
+paul 1168 1155 0 13:18 ? 00:00:00 (sd-pam)
+paul 1361 1155 0 13:18 ? 00:00:00 /usr/bin/dbus-daemon --session --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
+paul 1364 1155 1 13:18 ? 00:01:19 /home/paul/.nvm/versions/node/v22.23.0/bin/node /home/paul/.nvm/versions/node/v22.23.0/lib/node_modules/openclaw/dist/index.js gateway --port 18789
+paul 1367 1155 0 13:18 ? 00:00:00 /usr/bin/pipewire
+paul 1372 1155 0 13:18 ? 00:00:00 /usr/bin/pipewire -c filter-chain.conf
+paul 1373 1155 0 13:18 ? 00:00:00 /usr/bin/wireplumber
+paul 1374 1155 0 13:18 ? 00:00:00 /usr/bin/pipewire-pulse
+paul 1444 1155 0 13:18 ? 00:00:00 /usr/bin/mpris-proxy
+paul 2593 1155 0 13:19 ? 00:00:00 /usr/bin/gnome-keyring-daemon --foreground --components=pkcs11,secrets --control-directory=/run/user/1000/keyring
+paul 2608 2487 0 13:19 tty2 00:00:00 /usr/libexec/gdm-x-session --run-script /usr/bin/gnome-session
+paul 2617 2608 1 13:19 tty2 00:01:12 /usr/lib/xorg/Xorg vt2 -displayfd 3 -auth /run/user/1000/gdm/Xauthority -nolisten tcp -background none -noreset -keeptty -novtswitch -verbose 3
+paul 2647 2608 0 13:19 tty2 00:00:00 /usr/libexec/gnome-session-binary
+paul 2785 1155 0 13:19 ? 00:00:00 /usr/libexec/at-spi-bus-launcher
+paul 2792 2785 0 13:19 ? 00:00:00 /usr/bin/dbus-daemon --config-file=/usr/share/defaults/at-spi2/accessibility.conf --nofork --print-address 11 --address=unix:path=/run/user/1000/at-spi/bus_1
+paul 2802 1155 0 13:19 ? 00:00:00 /usr/libexec/gcr-ssh-agent --base-dir /run/user/1000/gcr
+paul 2803 1155 0 13:19 ? 00:00:00 /usr/libexec/gnome-session-ctl --monitor
+paul 2804 1155 0 13:19 ? 00:00:00 /usr/bin/ssh-agent -D
+paul 2814 1155 0 13:19 ? 00:00:00 /usr/libexec/gvfsd
+paul 2828 1155 0 13:19 ? 00:00:00 /usr/libexec/gvfsd-fuse /run/user/1000/gvfs -f
+paul 2838 1155 0 13:19 ? 00:00:00 /usr/libexec/gnome-session-binary --systemd-service --session=gnome
+paul 2874 1155 3 13:19 ? 00:02:13 /usr/bin/gnome-shell
+paul 2896 2874 0 13:19 ? 00:00:01 /usr/libexec/mutter-x11-frames
+paul 2902 1155 0 13:19 ? 00:00:00 /usr/libexec/at-spi2-registryd --use-gnome-session
+paul 2918 1155 0 13:19 ? 00:00:00 /usr/libexec/xdg-desktop-portal
+paul 2933 1155 0 13:19 ? 00:00:00 /usr/libexec/xdg-permission-store
+paul 2938 1155 0 13:19 ? 00:00:00 /usr/libexec/xdg-document-portal
+paul 2971 1155 0 13:19 ? 00:00:00 /usr/libexec/gnome-shell-calendar-server
+paul 2976 1155 0 13:19 ? 00:00:00 /usr/libexec/dconf-service
+paul 2992 1155 0 13:19 ? 00:00:00 /usr/libexec/evolution-source-registry
+paul 2994 1155 0 13:19 ? 00:00:00 /usr/bin/gjs -m /usr/share/gnome-shell/org.gnome.Shell.Notifications
+paul 3012 1155 0 13:19 ? 00:00:12 /usr/bin/ibus-daemon --panel disable --xim
+paul 3013 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-a11y-settings
+paul 3014 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-color
+paul 3015 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-datetime
+paul 3016 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-housekeeping
+paul 3018 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-keyboard
+paul 3024 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-media-keys
+paul 3025 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-power
+paul 3027 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-print-notifications
+paul 3029 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-rfkill
+paul 3030 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-screensaver-proxy
+paul 3035 2838 0 13:19 ? 00:00:05 /usr/bin/gnome-software --gapplication-service
+paul 3037 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-sharing
+paul 3042 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-smartcard
+paul 3048 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-sound
+paul 3054 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-usb-protection
+paul 3057 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-wacom
+paul 3058 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-xsettings
+paul 3059 2838 0 13:19 ? 00:00:00 /usr/libexec/evolution-data-server/evolution-alarm-notify
+paul 3064 2838 0 13:19 ? 00:00:00 /usr/bin/kalendarac
+paul 3070 2838 0 13:19 ? 00:00:00 /usr/libexec/gsd-disk-utility-notify
+paul 3088 2838 0 13:19 ? 00:00:00 /usr/bin/kdeconnectd
+paul 3168 1155 0 13:19 ? 00:00:00 /usr/bin/gjs -m /usr/share/gnome-shell/org.gnome.ScreenSaver
+paul 3172 1155 0 13:19 ? 00:00:00 /usr/libexec/gsd-printer
+paul 3207 3012 0 13:19 ? 00:00:00 /usr/libexec/ibus-memconf
+paul 3208 3012 0 13:19 ? 00:00:06 /usr/libexec/ibus-extension-gtk3
+paul 3214 1155 0 13:19 ? 00:00:00 /usr/libexec/ibus-x11 --kill-daemon
+paul 3216 1155 0 13:19 ? 00:00:00 /usr/libexec/ibus-portal
+paul 3218 1155 0 13:19 ? 00:00:00 /usr/libexec/localsearch-3
+paul 3219 1155 0 13:19 ? 00:00:00 /usr/libexec/xdg-desktop-portal-gnome
+paul 3241 1155 0 13:19 ? 00:00:00 /usr/libexec/gvfs-udisks2-volume-monitor
+paul 3251 1155 0 13:19 ? 00:00:00 /usr/libexec/gvfs-mtp-volume-monitor
+paul 3259 1155 0 13:19 ? 00:00:00 /usr/libexec/gvfs-gphoto2-volume-monitor
+paul 3265 1155 0 13:20 ? 00:00:00 /usr/libexec/gvfs-goa-volume-monitor
+paul 3271 1155 0 13:20 ? 00:00:00 /usr/libexec/goa-daemon
+paul 3280 1155 0 13:20 ? 00:00:00 /usr/libexec/goa-identity-service
+paul 3287 1155 0 13:20 ? 00:00:00 /usr/libexec/gvfs-afc-volume-monitor
+paul 3303 3012 0 13:20 ? 00:00:02 /usr/libexec/ibus-engine-simple
+paul 3372 1155 0 13:20 ? 00:00:00 /usr/libexec/xdg-desktop-portal-gtk
+paul 3441 1155 0 13:20 ? 00:00:00 /usr/libexec/gvfsd-metadata
+paul 3453 1155 0 13:20 ? 00:00:00 /usr/libexec/evolution-calendar-factory
+paul 3495 1155 0 13:20 ? 00:00:00 /usr/libexec/evolution-addressbook-factory
+paul 4798 1155 0 13:26 ? 00:00:09 /usr/libexec/gnome-terminal-server
+paul 4810 4798 0 13:26 pts/0 00:00:00 bash
+paul 8614 1155 0 13:29 ? 00:00:01 /usr/bin/speech-dispatcher -s -t 0
+paul 8656 8614 0 13:29 ? 00:00:00 [sd_espeak-ng-mb]
+paul 8709 8614 0 13:29 ? 00:00:00 /usr/lib/speech-dispatcher-modules/sd_espeak-ng /etc/speech-dispatcher/modules/espeak-ng.conf
+paul 8785 8614 0 13:29 ? 00:00:00 /usr/lib/speech-dispatcher-modules/sd_dummy /etc/speech-dispatcher/modules/dummy.conf
+paul 8799 8614 0 13:29 ? 00:00:00 /usr/lib/speech-dispatcher-modules/sd_espeak-ng /etc/speech-dispatcher/modules/
+paul 10028 1155 0 13:31 ? 00:00:00 adb -L tcp:5037 fork-server server --reply-fd 4
+paul 69578 2814 0 13:53 ? 00:00:00 /usr/libexec/gvfsd-http --spawner :1.22 /org/gtk/gvfs/exec_spaw/0
+paul 108341 1155 3 14:06 ? 00:00:48 /home/paul/.nvm/versions/node/v22.23.0/bin/node /home/paul/.nvm/versions/node/v22.23.0/lib/node_modules/acpx/dist/cli.js __queue-owner
+paul 108416 108341 0 14:06 ? 00:00:00 openclaw
+paul 108458 108416 2 14:06 ? 00:00:37 openclaw-acp
+paul 143553 1155 0 14:19 ? 00:00:05 /home/paul/Workspace/yavsc/src/PostIt.Tests/bin/Debug/net10.0/PostIt.Tests @@ /tmp/tmpI2JxLw.tmp
+paul 149205 1155 0 14:21 ? 00:00:05 /home/paul/Workspace/yavsc/src/PostIt.Tests/bin/Debug/net10.0/PostIt.Tests @@ /tmp/tmpitRyQG.tmp
+paul 151724 1155 0 14:22 ? 00:00:04 /home/paul/Workspace/yavsc/src/PostIt.Tests/bin/Debug/net10.0/PostIt.Tests @@ /tmp/tmpJEsOZV.tmp
+paul 157447 1155 1 14:24 ? 00:00:05 /home/paul/Workspace/yavsc/src/PostIt.Tests/bin/Debug/net10.0/PostIt.Tests @@ /tmp/tmpyM92DV.tmp
+paul 165231 1155 0 14:26 ? 00:00:01 /home/paul/Workspace/yavsc/src/PostIt.Tests/bin/Debug/net10.0/PostIt.Tests @@ /tmp/tmp5CKC19.tmp
+paul 168472 1155 4 14:27 ? 00:00:09 /home/paul/Workspace/yavsc/src/PostIt.Tests/bin/Debug/net10.0/PostIt.Tests @@ /tmp/tmpuRJsnQ.tmp
+paul 172147 1155 4 14:29 pts/0 00:00:05 /home/paul/Workspace/yavsc/src/PostIt.Tests/bin/Debug/net10.0/PostIt.Tests @@ /tmp/tmpxT8nje.tmp
+paul 172435 4810 99 14:31 pts/0 00:00:00 ps -fu paul
diff --git a/src/PostIt/PostIt/App.axaml.cs b/src/PostIt/PostIt/App.axaml.cs
index 1a68f4ac..d2399873 100644
--- a/src/PostIt/PostIt/App.axaml.cs
+++ b/src/PostIt/PostIt/App.axaml.cs
@@ -49,7 +49,7 @@ public partial class App : Application
// build is ever reconfigured to skip the early check.
if (TryHandOffCustomSchemeUrl()) return;
- this.ServiceProvider = BuildServices();
+ this.ServiceProvider = BuildServices(new ServiceCollection());
AttachServiceProvider(ServiceProvider);
var settings = ServiceProvider.GetRequiredService();
var sessionStatus = ServiceProvider.GetRequiredService();
@@ -139,7 +139,7 @@ public partial class App : Application
/// or service resolves through the same wiring the real app
/// does, and a green test is a green contract for prod.
///
- internal static IServiceProvider BuildServices()
+ internal static IServiceProvider BuildServices(ServiceCollection services)
{
var settings = new Settings();
settings.Load();
@@ -156,7 +156,6 @@ public partial class App : Application
var contactService = new ContactService();
var userDirectory = new UserDirectory(userSearchClient);
- var services = new ServiceCollection();
// Vues
services.AddTransient();
@@ -350,4 +349,9 @@ public partial class App : Application
return window.NavRoot.PushAsync(page);
}
+
+ internal async Task GoBackAsync()
+ {
+ await window.NavRoot.PopAsync();
+ }
}
diff --git a/src/PostIt/PostIt/ViewModels/AddCircleMemberDialogViewModel.cs b/src/PostIt/PostIt/ViewModels/AddCircleMemberDialogViewModel.cs
index a721d738..59d6dbed 100644
--- a/src/PostIt/PostIt/ViewModels/AddCircleMemberDialogViewModel.cs
+++ b/src/PostIt/PostIt/ViewModels/AddCircleMemberDialogViewModel.cs
@@ -5,6 +5,7 @@ using System.Threading.Tasks;
using CommunityToolkit.Mvvm.ComponentModel;
using CommunityToolkit.Mvvm.Input;
using PostIt.Services;
+using PostIt.Views;
using Yavsc.Api.Client;
namespace PostIt.ViewModels;
@@ -106,7 +107,7 @@ public partial class AddCircleMemberDialogViewModel : ViewModelBase
/// UI from firing an event with a null payload.
///
[RelayCommand]
- public void Add()
+ public async Task AddAsync()
{
if (Selected is null)
{
@@ -114,5 +115,14 @@ public partial class AddCircleMemberDialogViewModel : ViewModelBase
return;
}
Confirmed?.Invoke(this, Selected);
+ var app = App.Current as App;
+ await app.GoBackAsync();
+ }
+
+ [RelayCommand]
+ public async Task CloseAsync()
+ {
+ var app = App.Current as App;
+ await app.GoBackAsync();
}
}
diff --git a/src/PostIt/PostIt/ViewModels/CirclesPageViewModel.cs b/src/PostIt/PostIt/ViewModels/CirclesPageViewModel.cs
index bfc431b8..33a5bd30 100644
--- a/src/PostIt/PostIt/ViewModels/CirclesPageViewModel.cs
+++ b/src/PostIt/PostIt/ViewModels/CirclesPageViewModel.cs
@@ -119,6 +119,17 @@ public partial class CirclesPageViewModel : ViewModelBase
var directory = services.GetRequiredService();
AddCircleMemberDialogViewModel model =
new AddCircleMemberDialogViewModel(directory);
+ // Wire the dialog's Confirmed event to OnAddMemberConfirmedAsync.
+ // Without this, the dialog's "Ajouter" button fires the event
+ // into the void: no subscriber, the picked user is silently
+ // dropped, and nothing is added to the circle. The dialog
+ // stays open until the user uses the back gesture — which is
+ // how the user noticed the button was a no-op.
+ // Async-void is intentional here: Confirmed is an
+ // EventHandler (returns void), and bridging to the
+ // async Task OnAddMemberConfirmedAsync requires it.
+ model.Confirmed += async (_, picked) =>
+ await OnAddMemberConfirmedAsync(_, picked);
await app.PushPageAsync(model);
}
///
diff --git a/src/PostIt/PostIt/ViewModels/PostAclDialogViewModel.cs b/src/PostIt/PostIt/ViewModels/PostAclDialogViewModel.cs
index ae48fd8c..ae9e71d5 100644
--- a/src/PostIt/PostIt/ViewModels/PostAclDialogViewModel.cs
+++ b/src/PostIt/PostIt/ViewModels/PostAclDialogViewModel.cs
@@ -1,14 +1,13 @@
using System;
using System.Collections.Generic;
using System.Collections.ObjectModel;
-using System.Linq;
using System.Threading.Tasks;
using CommunityToolkit.Mvvm.ComponentModel;
using CommunityToolkit.Mvvm.Input;
using Yavsc.Blogspot;
using Yavsc.Api.Client;
using Yavsc.Api.Client.Dtos;
-using Yavsc.Abstract.Identity.Security;
+using Yavsc.Abstract.BlogSpot;
namespace PostIt.ViewModels;
@@ -38,10 +37,12 @@ public partial class PostAclDialogViewModel : ViewModelBase
public BlogPostDto Post { get; }
[ObservableProperty]
- public partial ObservableCollection MyCircles { get; set; } = new();
+ public partial ObservableCollection
+ MyCircles { get; set; } = new();
[ObservableProperty]
- public partial ObservableCollection AclEntries { get; set; } = new();
+ public partial ObservableCollection
+ AclEntries { get; set; } = new();
[ObservableProperty]
public partial CircleDto? SelectedCircleToAdd { get; set; }
@@ -52,6 +53,22 @@ public partial class PostAclDialogViewModel : ViewModelBase
[ObservableProperty]
public partial string StatusMessage { get; set; } = string.Empty;
+ ///
+ /// Idempotency gate for : the dialog
+ /// attaches the load trigger in DataContextChanged,
+ /// which can fire more than once if the page is detached
+ /// and re-attached (dialog re-use, navigation edge cases)
+ /// with a different VM. Without this guard, the second load
+ /// would race against the first and could overwrite
+ /// mid-edit. Pattern copied from
+ /// Settings.Load.
+ ///
+ private bool _loaded;
+
+ /// True once has run at least
+ /// once. Exposed for tests; do not bind from XAML.
+ public bool Loaded => _loaded;
+
public PostAclDialogViewModel(
BlogPostDto post,
BlogAclApiClient aclClient,
@@ -68,6 +85,8 @@ public partial class PostAclDialogViewModel : ViewModelBase
[RelayCommand]
public async Task LoadAsync()
{
+ if (_loaded) return;
+
IsBusy = true;
try
{
@@ -83,6 +102,7 @@ public partial class PostAclDialogViewModel : ViewModelBase
StatusMessage = $"{AclEntries.Count} autorisation(s)";
+ _loaded = true;
}
catch (Exception ex)
{
@@ -106,9 +126,10 @@ public partial class PostAclDialogViewModel : ViewModelBase
IsBusy = true;
try
{
- var created = await _aclClient.GrantAsync(new CircleAuthorization
+ var created = await _aclClient.GrantAsync(new Yavsc.Abstract.BlogSpot.PostAccessControlRulePayload
{
- CircleId = SelectedCircleToAdd.Id
+ CircleId = SelectedCircleToAdd.Id,
+ BlogPostId = Post.Id
});
if (created is not null)
{
@@ -131,7 +152,7 @@ public partial class PostAclDialogViewModel : ViewModelBase
}
[RelayCommand]
- public async Task RevokeAsync(CircleAuthorization? acl)
+ public async Task RevokeAsync(PostAccessControlRulePayload? acl)
{
if (acl is null) return;
IsBusy = true;
diff --git a/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml b/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml
index 5d1e2531..8b232988 100644
--- a/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml
+++ b/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml
@@ -6,6 +6,7 @@
xmlns:services="using:PostIt.Services"
x:DataType="vm:AddCircleMemberDialogViewModel"
>
+
@@ -29,7 +30,9 @@
+ SelectedItem="{Binding Selected, Mode=TwoWay}"
+ MinHeight="20"
+ >
@@ -47,11 +50,13 @@
+ x:Name="CloseButton"
+ Command="{Binding CloseAsync}"/>
diff --git a/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml.cs b/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml.cs
index c7f71171..6905c85a 100644
--- a/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml.cs
+++ b/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml.cs
@@ -1,6 +1,7 @@
using Avalonia.Controls;
using Avalonia.Markup.Xaml;
using Avalonia.Interactivity;
+using Avalonia.VisualTree;
using PostIt.Services;
using PostIt.ViewModels;
@@ -23,6 +24,7 @@ public partial class AddCircleMemberDialog : ContentPage
public AddCircleMemberDialog()
{
InitializeComponent();
+
}
private void InitializeComponent()
@@ -41,8 +43,8 @@ public partial class AddCircleMemberDialog : ContentPage
private void OnCloseClicked(object? sender, RoutedEventArgs e)
{
- // Same light-modal pattern as PostAclDialog: rely on
- // the system back gesture or the navigation host's
- // "pop" — the ContentPage doesn't own the back stack.
+ var nav = this.FindAncestorOfType();
+ if (nav is not null)
+ _ = nav.PopAsync();
}
}
diff --git a/src/PostIt/PostIt/Views/PostAclDialog.axaml.cs b/src/PostIt/PostIt/Views/PostAclDialog.axaml.cs
index c52b6f63..c36ddeef 100644
--- a/src/PostIt/PostIt/Views/PostAclDialog.axaml.cs
+++ b/src/PostIt/PostIt/Views/PostAclDialog.axaml.cs
@@ -1,3 +1,4 @@
+using System;
using Avalonia.Controls;
using Avalonia.Markup.Xaml;
using PostIt.ViewModels;
@@ -9,21 +10,53 @@ namespace PostIt.Views;
///
/// Modal "manage ACL" page for a single blog post.
///
-/// The ViewModel is constructed here (not via DI) because it
-/// depends on the post being managed, which the caller (the post
-/// list page) only knows at the moment it opens the dialog. The
-/// DI container can build the two API clients; the post and the
-/// VM are wired together here.
+/// The ViewModel is constructed by the caller (the post
+/// list page) and handed to ,
+/// which routes through and lands
+/// here via the parameterless DI constructor. The VM is then
+/// assigned to by
+/// App.PushPageAsync — we listen for that one-shot
+/// assignment and trigger LoadAsync right after, so the
+/// dropdown's MyCircles and the list's AclEntries
+/// are populated when the dialog appears. The VM is idempotent
+/// under repeated loads.
///
public partial class PostAclDialog : ContentPage
{
public PostAclDialog()
{
InitializeComponent();
+
+ // App.PushPageAsync wires the VM via DataContext after
+ // building the page. We subscribe once to fire LoadAsync
+ // the moment the VM is attached. Using DataContextChanged
+ // (rather than AttachedToVisualTree) is what makes this
+ // work in the headless test harness too: the load is
+ // tied to the VM being available, not to the visual tree
+ // being realised (which is a separate concern).
+ EventHandler? handler = null;
+ handler = (_, _) =>
+ {
+ if (DataContext is PostAclDialogViewModel vm)
+ {
+ this.DataContextChanged -= handler;
+ _ = vm.LoadAsync();
+ }
+ };
+ this.DataContextChanged += handler;
}
public PostAclDialog(BlogPostDto post, BlogAclApiClient aclClient, CircleApiClient circleClient)
{
+ // This overload is not used by the production path —
+ // MainPageViewModel pushes the VM via App.PushPageAsync
+ // and App routes through ViewLocator, which resolves this
+ // page via the parameterless ctor. It is kept so test
+ // scaffolding that wants to bypass the nav pipeline can
+ // still wire a VM directly without losing the load
+ // trigger: the constructor sets DataContext before the
+ // DataContextChanged subscription fires, so the load
+ // is guaranteed to run in either case.
InitializeComponent();
DataContext = new PostAclDialogViewModel(post, aclClient, circleClient);
}
diff --git a/src/Yavsc.Abstract/Authentication/RegisterModel.cs b/src/Yavsc.Abstract/Authentication/RegisterModel.cs
index f55aa71e..e4285f06 100644
--- a/src/Yavsc.Abstract/Authentication/RegisterModel.cs
+++ b/src/Yavsc.Abstract/Authentication/RegisterModel.cs
@@ -8,8 +8,8 @@ namespace Yavsc.ViewModels.Account
public class RegisterModel
{
- [StringLength(YavscConstants.MaxUserNameLength)]
- [RegularExpression(YavscConstants.UserNameRegExp)]
+ [StringLength(Constants.MaxUserNameLength)]
+ [RegularExpression(Constants.UserNameRegExp)]
[DataType(DataType.Text)]
[Display(Name = "UserName", Description = "User name")]
public string UserName { get; set; }
diff --git a/src/Yavsc.Abstract/Blogspot/PostAccessControlRulePayload.cs b/src/Yavsc.Abstract/Blogspot/PostAccessControlRulePayload.cs
new file mode 100644
index 00000000..c58fca48
--- /dev/null
+++ b/src/Yavsc.Abstract/Blogspot/PostAccessControlRulePayload.cs
@@ -0,0 +1,10 @@
+
+using Yavsc.Abstract.Identity.Security;
+
+namespace Yavsc.Abstract.BlogSpot;
+
+public class PostAccessControlRulePayload : ICircleAuthorization
+{
+ public long CircleId { get; set; }
+ public long BlogPostId { get; set; }
+}
diff --git a/src/Yavsc.Abstract/Constants.cs b/src/Yavsc.Abstract/Constants.cs
index af78ab0b..78ff0838 100644
--- a/src/Yavsc.Abstract/Constants.cs
+++ b/src/Yavsc.Abstract/Constants.cs
@@ -3,8 +3,10 @@ using Yavsc.Models.Auth;
namespace Yavsc
{
- public static class YavscConstants
+ public static class Constants
{
+
+ public const string APIPrefix = "api/v1";
public static readonly Scope[] SiteScopes = {
new Scope { Id = "profile", Description = "Your profile informations" },
new Scope { Id = "book" , Description ="Your booking interface"},
diff --git a/src/Yavsc.Abstract/Identity/UserDisplayHelpers.cs b/src/Yavsc.Abstract/Identity/UserDisplayHelpers.cs
index 04bc8e33..24261552 100644
--- a/src/Yavsc.Abstract/Identity/UserDisplayHelpers.cs
+++ b/src/Yavsc.Abstract/Identity/UserDisplayHelpers.cs
@@ -19,7 +19,7 @@ namespace Yavsc.Abstract.Identity
///
///
/// Le path retourné est aligné sur
- /// (minuscule).
+ /// (minuscule).
/// Les anciens display templates utilisaient "/Avatars/"
/// avec un S majuscule, en désaccord avec le path statique
/// servi par le middleware de fichiers — les images ne
@@ -29,8 +29,8 @@ namespace Yavsc.Abstract.Identity
public static string AvatarSrc(IApplicationUser? user)
{
if (user==null || string.IsNullOrWhiteSpace(user?.UserName))
- return YavscConstants.DefaultAvatar;
- return $"{YavscConstants.AvatarsPath}/{user!.UserName}.s.png";
+ return Constants.DefaultAvatar;
+ return $"{Constants.AvatarsPath}/{user!.UserName}.s.png";
}
}
}
diff --git a/src/Yavsc.Api.Client/BlogAclApiClient.cs b/src/Yavsc.Api.Client/BlogAclApiClient.cs
index e8c8bf01..9a93d310 100644
--- a/src/Yavsc.Api.Client/BlogAclApiClient.cs
+++ b/src/Yavsc.Api.Client/BlogAclApiClient.cs
@@ -3,6 +3,7 @@ using System.Collections.Generic;
using System.Net.Http;
using System.Threading;
using System.Threading.Tasks;
+using Yavsc.Abstract.BlogSpot;
using Yavsc.Abstract.Identity.Security;
using Yavsc.Api.Client.Dtos;
@@ -33,16 +34,16 @@ public sealed class BlogAclApiClient
api.Http.BaseAddress = new Uri(blogsBaseAddress);
}
- public Task> GetMyAclAsync(CancellationToken ct = default)
- => _api.CallAsync>(HttpMethod.Get, Path, ct: ct);
+ public Task> GetMyAclAsync(CancellationToken ct = default)
+ => _api.CallAsync>(HttpMethod.Get, Path, ct: ct);
- public Task GetAclAsync(long circleId, CancellationToken ct = default)
- => _api.CallAsync(HttpMethod.Get, $"{Path}/{circleId}", ct: ct);
+ public Task GetAclAsync(long circleId, CancellationToken ct = default)
+ => _api.CallAsync(HttpMethod.Get, $"{Path}/{circleId}", ct: ct);
- public Task GrantAsync(CircleAuthorization acl, CancellationToken ct = default)
- => _api.CallAsync(HttpMethod.Post, Path, body: acl, ct: ct);
+ public Task GrantAsync(PostAccessControlRulePayload acl, CancellationToken ct = default)
+ => _api.CallAsync(HttpMethod.Post, Path, body: acl, ct: ct);
- public Task UpdateAclAsync(long circleId, CircleAuthorization acl, CancellationToken ct = default)
+ public Task UpdateAclAsync(long circleId, PostAccessControlRulePayload acl, CancellationToken ct = default)
=> _api.CallAsync(HttpMethod.Put, $"{Path}/{circleId}", body: acl, ct: ct);
public Task RevokeAsync(long circleId, CancellationToken ct = default)
diff --git a/src/Yavsc.Api/Controllers/Business/ActivityApiController.cs b/src/Yavsc.Api/Controllers/Business/ActivityApiController.cs
index d2da2ea7..5aeddc57 100644
--- a/src/Yavsc.Api/Controllers/Business/ActivityApiController.cs
+++ b/src/Yavsc.Api/Controllers/Business/ActivityApiController.cs
@@ -14,7 +14,7 @@ using Yavsc.Models.Workflow;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/activity")]
+ [Route(Constants.APIPrefix + "/activity")]
public class ActivityApiController : Controller
{
private ApplicationDbContext _context;
diff --git a/src/Yavsc.Api/Controllers/Business/BillingController.cs b/src/Yavsc.Api/Controllers/Business/BillingController.cs
index 87035406..72180fc1 100644
--- a/src/Yavsc.Api/Controllers/Business/BillingController.cs
+++ b/src/Yavsc.Api/Controllers/Business/BillingController.cs
@@ -19,7 +19,7 @@ namespace Yavsc.ApiControllers
using Yavsc.ViewModels.Auth;
using Yavsc.Server.Helpers;
- [Route("api/bill"), Authorize]
+ [Route(Constants.APIPrefix + "/bill"), Authorize]
public class BillingController : Controller
{
readonly ApplicationDbContext dbContext;
diff --git a/src/Yavsc.Api/Controllers/Business/BookQueryApiController.cs b/src/Yavsc.Api/Controllers/Business/BookQueryApiController.cs
index 494075c6..7e58b071 100644
--- a/src/Yavsc.Api/Controllers/Business/BookQueryApiController.cs
+++ b/src/Yavsc.Api/Controllers/Business/BookQueryApiController.cs
@@ -18,7 +18,7 @@ namespace Yavsc.Controllers
using Yavsc.Server.Helpers;
[Produces("application/json")]
- [Route("api/bookquery"), Authorize("Performer")]
+ [Route(Constants.APIPrefix + "/bookquery"), Authorize("Performer")]
public class BookQueryApiController : Controller
{
private ApplicationDbContext _context;
diff --git a/src/Yavsc.Api/Controllers/Business/EstimateApiController.cs b/src/Yavsc.Api/Controllers/Business/EstimateApiController.cs
index 41bdd353..902cb038 100644
--- a/src/Yavsc.Api/Controllers/Business/EstimateApiController.cs
+++ b/src/Yavsc.Api/Controllers/Business/EstimateApiController.cs
@@ -15,7 +15,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/estimate"), Authorize]
+ [Route(Constants.APIPrefix + "/estimate"), Authorize]
public class EstimateApiController : Controller
{
private readonly ApplicationDbContext _context;
@@ -27,12 +27,12 @@ namespace Yavsc.Controllers
}
bool UserIsAdminOrThis(string uid)
{
- if (User.IsInRole(YavscConstants.AdminGroupName)) return true;
+ if (User.IsInRole(Constants.AdminGroupName)) return true;
return uid == User.GetUserId();
}
bool UserIsAdminOrInThese(string oid, string uid)
{
- if (User.IsInRole(YavscConstants.AdminGroupName)) return true;
+ if (User.IsInRole(Constants.AdminGroupName)) return true;
var cuid = User.GetUserId();
return cuid == uid || cuid == oid;
}
@@ -82,7 +82,7 @@ namespace Yavsc.Controllers
return BadRequest();
}
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
- if (!User.IsInRole(YavscConstants.AdminGroupName))
+ if (!User.IsInRole(Constants.AdminGroupName))
{
if (uid != estimate.OwnerId)
{
@@ -118,7 +118,7 @@ namespace Yavsc.Controllers
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (estimate.OwnerId == null) estimate.OwnerId = uid;
- if (!User.IsInRole(YavscConstants.AdminGroupName))
+ if (!User.IsInRole(Constants.AdminGroupName))
{
if (uid != estimate.OwnerId)
{
@@ -187,7 +187,7 @@ namespace Yavsc.Controllers
return NotFound();
}
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
- if (!User.IsInRole(YavscConstants.AdminGroupName))
+ if (!User.IsInRole(Constants.AdminGroupName))
{
if (uid != estimate.OwnerId)
{
diff --git a/src/Yavsc.Api/Controllers/Business/EstimateTemplatesApiController.cs b/src/Yavsc.Api/Controllers/Business/EstimateTemplatesApiController.cs
index 4442e0b3..81de4cac 100644
--- a/src/Yavsc.Api/Controllers/Business/EstimateTemplatesApiController.cs
+++ b/src/Yavsc.Api/Controllers/Business/EstimateTemplatesApiController.cs
@@ -9,7 +9,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/EstimateTemplatesApi")]
+ [Route(Constants.APIPrefix + "/EstimateTemplatesApi")]
public class EstimateTemplatesApiController : Controller
{
private ApplicationDbContext _context;
@@ -62,7 +62,7 @@ namespace Yavsc.Controllers
}
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (estimateTemplate.OwnerId!=uid)
- if (!User.IsInRole(YavscConstants.AdminGroupName))
+ if (!User.IsInRole(Constants.AdminGroupName))
return new StatusCodeResult(StatusCodes.Status403Forbidden);
_context.Entry(estimateTemplate).State = EntityState.Modified;
@@ -132,7 +132,7 @@ namespace Yavsc.Controllers
}
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (estimateTemplate.OwnerId!=uid)
- if (!User.IsInRole(YavscConstants.AdminGroupName))
+ if (!User.IsInRole(Constants.AdminGroupName))
return new StatusCodeResult(StatusCodes.Status403Forbidden);
_context.EstimateTemplates.Remove(estimateTemplate);
diff --git a/src/Yavsc.Api/Controllers/Business/FrontOfficeApiController.cs b/src/Yavsc.Api/Controllers/Business/FrontOfficeApiController.cs
index b91cba51..c05da827 100644
--- a/src/Yavsc.Api/Controllers/Business/FrontOfficeApiController.cs
+++ b/src/Yavsc.Api/Controllers/Business/FrontOfficeApiController.cs
@@ -8,7 +8,7 @@ using Yavsc.ViewModels.FrontOffice;
namespace Yavsc.ApiControllers
{
- [Route("api/front")]
+ [Route(Constants.APIPrefix + "/front")]
public class FrontOfficeApiController : Controller
{
ApplicationDbContext dbContext;
diff --git a/src/Yavsc.Api/Controllers/Business/PaymentApiController.cs b/src/Yavsc.Api/Controllers/Business/PaymentApiController.cs
index 3076dbe1..5f769e4e 100644
--- a/src/Yavsc.Api/Controllers/Business/PaymentApiController.cs
+++ b/src/Yavsc.Api/Controllers/Business/PaymentApiController.cs
@@ -6,7 +6,7 @@ using Yavsc.Models;
namespace Yavsc.ApiControllers
{
- [Route("api/payment")]
+ [Route(Constants.APIPrefix + "/payment")]
public class PaymentApiController : Controller
{
private readonly ApplicationDbContext dbContext;
diff --git a/src/Yavsc.Api/Controllers/Business/PerformersApiController.cs b/src/Yavsc.Api/Controllers/Business/PerformersApiController.cs
index b552eff3..2ad1ded5 100644
--- a/src/Yavsc.Api/Controllers/Business/PerformersApiController.cs
+++ b/src/Yavsc.Api/Controllers/Business/PerformersApiController.cs
@@ -11,7 +11,7 @@ namespace Yavsc.Controllers
using Yavsc.Services;
[Produces("application/json")]
- [Route("api/performers")]
+ [Route(Constants.APIPrefix + "/performers")]
public class PerformersApiController : Controller
{
ApplicationDbContext dbContext;
diff --git a/src/Yavsc.Api/Controllers/Business/ProductApiController.cs b/src/Yavsc.Api/Controllers/Business/ProductApiController.cs
index abd621c3..97a60fdb 100644
--- a/src/Yavsc.Api/Controllers/Business/ProductApiController.cs
+++ b/src/Yavsc.Api/Controllers/Business/ProductApiController.cs
@@ -9,7 +9,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/ProductApi")]
+ [Route(Constants.APIPrefix + "/ProductApi")]
public class ProductApiController : Controller
{
private readonly ApplicationDbContext _context;
@@ -46,7 +46,7 @@ namespace Yavsc.Controllers
}
// PUT: api/ProductApi/5
- [HttpPut("{id}"),Authorize(YavscConstants.FrontOfficeGroupName)]
+ [HttpPut("{id}"),Authorize(Constants.FrontOfficeGroupName)]
public IActionResult PutProduct(long id, [FromBody] Product product)
{
if (!ModelState.IsValid)
@@ -81,7 +81,7 @@ namespace Yavsc.Controllers
}
// POST: api/ProductApi
- [HttpPost,Authorize(YavscConstants.FrontOfficeGroupName)]
+ [HttpPost,Authorize(Constants.FrontOfficeGroupName)]
public IActionResult PostProduct([FromBody] Product product)
{
if (!ModelState.IsValid)
@@ -110,7 +110,7 @@ namespace Yavsc.Controllers
}
// DELETE: api/ProductApi/5
- [HttpDelete("{id}"),Authorize(YavscConstants.FrontOfficeGroupName)]
+ [HttpDelete("{id}"),Authorize(Constants.FrontOfficeGroupName)]
public IActionResult DeleteProduct(long id)
{
if (!ModelState.IsValid)
diff --git a/src/Yavsc.Api/Controllers/HairCut/BursherProfilesApiController.cs b/src/Yavsc.Api/Controllers/HairCut/BursherProfilesApiController.cs
index 22fdf1e9..cd3a561b 100644
--- a/src/Yavsc.Api/Controllers/HairCut/BursherProfilesApiController.cs
+++ b/src/Yavsc.Api/Controllers/HairCut/BursherProfilesApiController.cs
@@ -8,7 +8,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/bursherprofiles")]
+ [Route(Constants.APIPrefix + "/bursherprofiles")]
public class BursherProfilesApiController : Controller
{
private readonly ApplicationDbContext _context;
@@ -57,7 +57,7 @@ namespace Yavsc.Controllers
{
return BadRequest();
}
-
+
if (id != User.GetUserId())
{
return BadRequest();
diff --git a/src/Yavsc.Api/Controllers/HairCut/HairCutController.cs b/src/Yavsc.Api/Controllers/HairCut/HairCutController.cs
index 822c3182..c1181f54 100644
--- a/src/Yavsc.Api/Controllers/HairCut/HairCutController.cs
+++ b/src/Yavsc.Api/Controllers/HairCut/HairCutController.cs
@@ -24,7 +24,7 @@ namespace Yavsc.ApiControllers
using Microsoft.AspNetCore.Authorization;
using Yavsc.Server.Helpers;
- [Route("api/haircut")][Authorize]
+ [Route(Constants.APIPrefix + "/haircut")][Authorize]
public class HairCutController : Controller
{
private readonly ApplicationDbContext _context;
diff --git a/src/Yavsc.Api/Controllers/HyperLinkApiController.cs b/src/Yavsc.Api/Controllers/HyperLinkApiController.cs
index b2d28baa..3ba74219 100644
--- a/src/Yavsc.Api/Controllers/HyperLinkApiController.cs
+++ b/src/Yavsc.Api/Controllers/HyperLinkApiController.cs
@@ -6,7 +6,7 @@ using Yavsc.Models.Relationship;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/hyperlink")]
+ [Route(Constants.APIPrefix + "/hyperlink")]
public class HyperLinkApiController : Controller
{
private ApplicationDbContext _context;
diff --git a/src/Yavsc.Api/Controllers/IT/GitRefsApiController.cs b/src/Yavsc.Api/Controllers/IT/GitRefsApiController.cs
index 55ae08b7..67f38d22 100644
--- a/src/Yavsc.Api/Controllers/IT/GitRefsApiController.cs
+++ b/src/Yavsc.Api/Controllers/IT/GitRefsApiController.cs
@@ -7,7 +7,7 @@ using Yavsc.Server.Models.IT.SourceCode;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/GitRefsApi")]
+ [Route(Constants.APIPrefix + "/GitRefsApi")]
[Authorize("AdministratorOnly")]
public class GitRefsApiController : Controller
{
diff --git a/src/Yavsc.Api/Controllers/MailTemplatingApiController.cs b/src/Yavsc.Api/Controllers/MailTemplatingApiController.cs
index 958ade66..c289c3da 100644
--- a/src/Yavsc.Api/Controllers/MailTemplatingApiController.cs
+++ b/src/Yavsc.Api/Controllers/MailTemplatingApiController.cs
@@ -2,9 +2,9 @@ using Microsoft.AspNetCore.Mvc;
namespace Yavsc.ApiControllers
{
- [Route("api/mailtemplate")]
+ [Route(Constants.APIPrefix + "/mailtemplate")]
public class MailTemplatingApiController: Controller
{
-
+
}
}
diff --git a/src/Yavsc.Api/Controllers/MailingTemplateApiController.cs b/src/Yavsc.Api/Controllers/MailingTemplateApiController.cs
index dc535476..4373d847 100644
--- a/src/Yavsc.Api/Controllers/MailingTemplateApiController.cs
+++ b/src/Yavsc.Api/Controllers/MailingTemplateApiController.cs
@@ -7,7 +7,7 @@ using Microsoft.EntityFrameworkCore;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/mailing")]
+ [Route(Constants.APIPrefix + "/mailing")]
[Authorize("AdministratorOnly")]
public class MailingTemplateApiController : Controller
{
diff --git a/src/Yavsc.Api/Controllers/Musical/MusicalPreferencesApiController.cs b/src/Yavsc.Api/Controllers/Musical/MusicalPreferencesApiController.cs
index 944b335b..dc935c14 100644
--- a/src/Yavsc.Api/Controllers/Musical/MusicalPreferencesApiController.cs
+++ b/src/Yavsc.Api/Controllers/Musical/MusicalPreferencesApiController.cs
@@ -8,7 +8,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/museprefs")]
+ [Route(Constants.APIPrefix + "/museprefs")]
public class MusicalPreferencesApiController : Controller
{
private readonly ApplicationDbContext _context;
diff --git a/src/Yavsc.Api/Controllers/Musical/MusicalTendenciesApiController.cs b/src/Yavsc.Api/Controllers/Musical/MusicalTendenciesApiController.cs
index eacccb0a..e72090f6 100644
--- a/src/Yavsc.Api/Controllers/Musical/MusicalTendenciesApiController.cs
+++ b/src/Yavsc.Api/Controllers/Musical/MusicalTendenciesApiController.cs
@@ -8,7 +8,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/MusicalTendenciesApi")]
+ [Route(Constants.APIPrefix + "/MusicalTendenciesApi")]
public class MusicalTendenciesApiController : Controller
{
private readonly ApplicationDbContext _context;
diff --git a/src/Yavsc.Api/Controllers/PostRateApiController.cs b/src/Yavsc.Api/Controllers/PostRateApiController.cs
index dc132da4..50d6d2e9 100644
--- a/src/Yavsc.Api/Controllers/PostRateApiController.cs
+++ b/src/Yavsc.Api/Controllers/PostRateApiController.cs
@@ -37,7 +37,7 @@ namespace Yavsc.Controllers
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (blogpost.AuthorId!=uid)
- if (!User.IsInRole(YavscConstants.AdminGroupName))
+ if (!User.IsInRole(Constants.AdminGroupName))
return BadRequest();
_context.SaveChanges(User.GetUserId());
diff --git a/src/Yavsc.Api/Controllers/ProfileApiController.cs b/src/Yavsc.Api/Controllers/ProfileApiController.cs
index 60ad1f60..93bf2a4e 100644
--- a/src/Yavsc.Api/Controllers/ProfileApiController.cs
+++ b/src/Yavsc.Api/Controllers/ProfileApiController.cs
@@ -7,8 +7,8 @@ namespace Yavsc.ApiControllers
///
/// Base class for managing performers profiles
///
- [Produces("application/json"),Route("api/profile")]
- public abstract class ProfileApiController : Controller
+ [Produces("application/json"),Route(Constants.APIPrefix + "/profile")]
+ public abstract class ProfileApiController : Controller
{ public ProfileApiController()
{
}
diff --git a/src/Yavsc.Api/Controllers/Relationship/BlackListApiController.cs b/src/Yavsc.Api/Controllers/Relationship/BlackListApiController.cs
index ebc1c03b..32cf8495 100644
--- a/src/Yavsc.Api/Controllers/Relationship/BlackListApiController.cs
+++ b/src/Yavsc.Api/Controllers/Relationship/BlackListApiController.cs
@@ -10,7 +10,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/blacklist"), Authorize]
+ [Route(Constants.APIPrefix + "/blacklist"), Authorize]
public class BlackListApiController : Controller
{
private readonly ApplicationDbContext _context;
@@ -50,8 +50,8 @@ namespace Yavsc.Controllers
{
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (uid != blackListed.OwnerId)
- if (!User.IsInRole(YavscConstants.AdminGroupName))
- if (!User.IsInRole(YavscConstants.FrontOfficeGroupName))
+ if (!User.IsInRole(Constants.AdminGroupName))
+ if (!User.IsInRole(Constants.FrontOfficeGroupName))
return false;
return true;
}
@@ -140,7 +140,7 @@ namespace Yavsc.Controllers
if (!CheckPermission(blackListed))
return BadRequest();
-
+
_context.BlackListed.Remove(blackListed);
_context.SaveChanges(User.GetUserId());
diff --git a/src/Yavsc.Api/Controllers/Relationship/ChatApiController.cs b/src/Yavsc.Api/Controllers/Relationship/ChatApiController.cs
index cdaeecde..b991c0fb 100644
--- a/src/Yavsc.Api/Controllers/Relationship/ChatApiController.cs
+++ b/src/Yavsc.Api/Controllers/Relationship/ChatApiController.cs
@@ -9,14 +9,14 @@ using Microsoft.EntityFrameworkCore;
namespace Yavsc.Controllers
{
- [Route("api/chat")]
+ [Route(Constants.APIPrefix + "/chat")]
public class ChatApiController : Controller
{
readonly ApplicationDbContext dbContext;
readonly UserManager userManager;
private readonly IConnexionManager _cxManager;
public ChatApiController(ApplicationDbContext dbContext,
- UserManager userManager,
+ UserManager userManager,
IConnexionManager cxManager)
{
this.dbContext = dbContext;
diff --git a/src/Yavsc.Api/Controllers/Relationship/ChatRoomAccessApiController.cs b/src/Yavsc.Api/Controllers/Relationship/ChatRoomAccessApiController.cs
index 5fe3a0bf..fba8bd43 100644
--- a/src/Yavsc.Api/Controllers/Relationship/ChatRoomAccessApiController.cs
+++ b/src/Yavsc.Api/Controllers/Relationship/ChatRoomAccessApiController.cs
@@ -9,7 +9,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/ChatRoomAccessApi")]
+ [Route(Constants.APIPrefix + "/ChatRoomAccessApi")]
public class ChatRoomAccessApiController : Controller
{
private readonly ApplicationDbContext _context;
@@ -37,7 +37,7 @@ namespace Yavsc.Controllers
ChatRoomAccess chatRoomAccess = await _context.ChatRoomAccess.SingleAsync(m => m.ChannelName == id);
-
+
if (chatRoomAccess == null)
{
@@ -46,13 +46,13 @@ namespace Yavsc.Controllers
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
if (uid != chatRoomAccess.UserId && uid != chatRoomAccess.Room.OwnerId
- && ! User.IsInMsRole(YavscConstants.AdminGroupName))
-
+ && ! User.IsInMsRole(Constants.AdminGroupName))
+
{
ModelState.AddModelError("UserId","get refused");
return BadRequest(ModelState);
}
-
+
return Ok(chatRoomAccess);
}
@@ -72,7 +72,7 @@ namespace Yavsc.Controllers
}
var room = _context.ChatRoom.First(channel => channel.Name == chatRoomAccess.ChannelName );
- if (uid != room.OwnerId && ! User.IsInMsRole(YavscConstants.AdminGroupName))
+ if (uid != room.OwnerId && ! User.IsInMsRole(Constants.AdminGroupName))
{
ModelState.AddModelError("ChannelName", "access put refused");
return BadRequest(ModelState);
@@ -110,7 +110,7 @@ namespace Yavsc.Controllers
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
var room = _context.ChatRoom.First(channel => channel.Name == chatRoomAccess.ChannelName );
- if (room == null || (uid != room.OwnerId && ! User.IsInMsRole(YavscConstants.AdminGroupName)))
+ if (room == null || (uid != room.OwnerId && ! User.IsInMsRole(Constants.AdminGroupName)))
{
ModelState.AddModelError("ChannelName", "access post refused");
return BadRequest(ModelState);
@@ -154,7 +154,7 @@ namespace Yavsc.Controllers
var uid = User.FindFirstValue(ClaimTypes.NameIdentifier);
var room = _context.ChatRoom.First(channel => channel.Name == chatRoomAccess.ChannelName );
- if (room == null || (uid != room.OwnerId && chatRoomAccess.UserId != uid && ! User.IsInMsRole(YavscConstants.AdminGroupName)))
+ if (room == null || (uid != room.OwnerId && chatRoomAccess.UserId != uid && ! User.IsInMsRole(Constants.AdminGroupName)))
{
ModelState.AddModelError("UserId", "access drop refused");
return BadRequest(ModelState);
diff --git a/src/Yavsc.Api/Controllers/Relationship/ChatRoomApiController.cs b/src/Yavsc.Api/Controllers/Relationship/ChatRoomApiController.cs
index 990646fc..5d59f6bd 100644
--- a/src/Yavsc.Api/Controllers/Relationship/ChatRoomApiController.cs
+++ b/src/Yavsc.Api/Controllers/Relationship/ChatRoomApiController.cs
@@ -8,7 +8,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/ChatRoomApi")]
+ [Route(Constants.APIPrefix + "/ChatRoomApi")]
public class ChatRoomApiController : Controller
{
private readonly ApplicationDbContext _context;
@@ -128,7 +128,7 @@ namespace Yavsc.Controllers
}
ChatRoom chatRoom = await _context.ChatRoom.SingleAsync(m => m.Name == id);
-
+
if (chatRoom == null)
{
@@ -137,7 +137,7 @@ namespace Yavsc.Controllers
if (User.GetUserId() != chatRoom.OwnerId )
{
- if (!User.IsInMsRole(YavscConstants.AdminGroupName))
+ if (!User.IsInMsRole(Constants.AdminGroupName))
return BadRequest(new {error = "OwnerId"});
}
diff --git a/src/Yavsc.Api/Controllers/Relationship/ContactsApiController.cs b/src/Yavsc.Api/Controllers/Relationship/ContactsApiController.cs
index ffd6eb0b..96ba03dc 100644
--- a/src/Yavsc.Api/Controllers/Relationship/ContactsApiController.cs
+++ b/src/Yavsc.Api/Controllers/Relationship/ContactsApiController.cs
@@ -8,7 +8,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/ContactsApi")]
+ [Route(Constants.APIPrefix + "/ContactsApi")]
public class ContactsApiController : Controller
{
private readonly ApplicationDbContext _context;
diff --git a/src/Yavsc.Api/Controllers/ServiceApiController.cs b/src/Yavsc.Api/Controllers/ServiceApiController.cs
index e9330543..8556fb5a 100644
--- a/src/Yavsc.Api/Controllers/ServiceApiController.cs
+++ b/src/Yavsc.Api/Controllers/ServiceApiController.cs
@@ -9,7 +9,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json")]
- [Route("api/ServiceApi")]
+ [Route(Constants.APIPrefix + "/ServiceApi")]
public class ServiceApiController : Controller
{
private readonly ApplicationDbContext _context;
@@ -46,7 +46,7 @@ namespace Yavsc.Controllers
}
// PUT: api/ServiceApi/5
- [HttpPut("{id}"),Authorize(YavscConstants.FrontOfficeGroupName)]
+ [HttpPut("{id}"),Authorize(Constants.FrontOfficeGroupName)]
public IActionResult PutService(long id, [FromBody] Service service)
{
if (!ModelState.IsValid)
@@ -81,7 +81,7 @@ namespace Yavsc.Controllers
}
// POST: api/ServiceApi
- [HttpPost,Authorize(YavscConstants.FrontOfficeGroupName)]
+ [HttpPost,Authorize(Constants.FrontOfficeGroupName)]
public IActionResult PostService([FromBody] Service service)
{
if (!ModelState.IsValid)
@@ -110,7 +110,7 @@ namespace Yavsc.Controllers
}
// DELETE: api/ServiceApi/5
- [HttpDelete("{id}"),Authorize(YavscConstants.FrontOfficeGroupName)]
+ [HttpDelete("{id}"),Authorize(Constants.FrontOfficeGroupName)]
public IActionResult DeleteService(long id)
{
if (!ModelState.IsValid)
diff --git a/src/Yavsc.Api/Controllers/accounting/ApplicationUserApiController.cs b/src/Yavsc.Api/Controllers/accounting/ApplicationUserApiController.cs
index 11c70d60..cb565a0d 100644
--- a/src/Yavsc.Api/Controllers/accounting/ApplicationUserApiController.cs
+++ b/src/Yavsc.Api/Controllers/accounting/ApplicationUserApiController.cs
@@ -13,7 +13,7 @@ using Yavsc.Server.Helpers;
namespace Yavsc.Controllers
{
[Produces("application/json"),Authorize("AdministratorOnly")]
- [Route("api/users")]
+ [Route(Constants.APIPrefix + "/users")]
public class ApplicationUserApiController : Controller
{
private readonly ApplicationDbContext _context;
@@ -28,7 +28,7 @@ namespace Yavsc.Controllers
public IEnumerable GetApplicationUser(int skip=0, int take = 25)
{
return _context.Users.Skip(skip).Take(take)
- .Select(u=> new UserInfo{
+ .Select(u=> new UserInfo{
UserId = u.Id,
UserName = u.UserName,
Avatar = u.Avatar});
@@ -39,7 +39,7 @@ namespace Yavsc.Controllers
{
return _context.Users.Where(u => u.UserName.Contains(pattern))
.Skip(skip).Take(take)
- .Select(u=> new UserInfo {
+ .Select(u=> new UserInfo {
UserId = u.Id,
UserName = u.UserName,
Avatar = u.Avatar });
diff --git a/src/Yavsc.Blogs.Tests/BlogAclApiTests.cs b/src/Yavsc.Blogs.Tests/BlogAclApiTests.cs
new file mode 100644
index 00000000..49259d05
--- /dev/null
+++ b/src/Yavsc.Blogs.Tests/BlogAclApiTests.cs
@@ -0,0 +1,221 @@
+using System.Net;
+using System.Net.Http.Json;
+using Microsoft.EntityFrameworkCore;
+using Microsoft.Extensions.DependencyInjection;
+using Yavsc.Abstract.BlogSpot;
+using Yavsc.Models;
+using Yavsc.Models.Access;
+using Yavsc.Models.Blog;
+using Yavsc.Models.Relationship;
+using Yavsc.Tests.Shared;
+using static Yavsc.Constants;
+
+namespace Yavsc.Blogs.Tests;
+
+///
+/// Behavioural tests for BlogAclApiController.PostCircleAuthorizationToBlogPost:
+/// POST /api/v1/blogacl with a JSON body of
+/// CircleAuthorizationToBlogPost (CircleId + BlogPostId).
+///
+/// Same fixture as :
+/// provides a SQLite
+/// :memory: ApplicationDbContext (so FKs are
+/// enforced the way a real relational engine would) and JWT
+/// bearer auth via TestTokenIssuer. No mocks — the real
+/// DbContext receives the real INSERT attempt.
+///
+/// The bug being pinned by these tests: the POST endpoint
+/// calls _context.CircleAuthorizationToBlogPost.Add(...)
+/// then SaveChangesAsync. The entity has a composite
+/// key (CircleId + BlogPostId) and two FKs; EF Core refuses
+/// the INSERT with
+/// System.InvalidOperationException: The value of
+/// 'CircleAuthorizationToBlogPost.BlogPostId' is unknown when
+/// attempting to save changes when the principal entities
+/// (the existing BlogPost and Circle) are not
+/// attached to the DbContext in the same change-tracker graph.
+///
+[Collection("Yavsc Blogs")]
+public sealed class BlogAclApiTests : IClassFixture
+{
+ private readonly BlogsWebServerFixture _fixture;
+
+
+ public BlogAclApiTests(BlogsWebServerFixture fixture)
+ {
+ _fixture = fixture;
+ }
+
+
+ private string BlogAclUrl()
+ => $"{_fixture.Addresses.First(a => a.StartsWith("https://"))}/{APIPrefix}/blogacl";
+
+ /// Delete any ACL rows tied to the fixture's seeded
+ /// (CircleId, BlogPostId) pair. The shared SQLite store
+ /// persists across tests, so tests that POST a successful ACL
+ /// row would otherwise conflict with whichever other test runs
+ /// next against the same pair — xUnit does not guarantee
+ /// execution order. Calling this at the start of each
+ /// insert-bearing test guarantees a clean slate regardless of
+ /// the previous test's outcome.
+ private void CleanupAcl()
+ {
+ using var scope = _fixture.Services.CreateScope();
+ var db = scope.ServiceProvider.GetRequiredService();
+ db.CircleAuthorizationToBlogPost
+ .Where(a => a.CircleId == _fixture.CircleId
+ && a.BlogPostId == _fixture.PostId)
+ .ExecuteDelete();
+ }
+
+ private HttpClient NewClient(string subject)
+ {
+ var handler = new HttpClientHandler
+ {
+ ServerCertificateCustomValidationCallback = (_, _, _, _) => true
+ };
+ var http = new HttpClient(handler)
+ {
+ BaseAddress = new Uri(_fixture.Addresses.First(a => a.StartsWith("https://")))
+ };
+ // The Blogs fixture disables JwtSecurityTokenHandler's
+ // inbound claim-type remap, so the JWT's "sub" stays "sub"
+ // rather than being rewritten to ClaimTypes.NameIdentifier.
+ // The controller, however, reads the user id via
+ // User.FindFirstValue(ClaimTypes.NameIdentifier), so we add
+ // an explicit nameid claim to keep the legacy lookup happy.
+ http.DefaultRequestHeaders.Authorization =
+ new System.Net.Http.Headers.AuthenticationHeaderValue(
+ "Bearer",
+ TestTokenIssuer.Issue(
+ subject,
+ extraClaims: new[]
+ {
+ new System.Security.Claims.Claim(
+ System.Security.Claims.ClaimTypes.NameIdentifier,
+ subject),
+ }));
+ return http;
+ }
+
+ ///
+ /// Reproduces the prod 500 logged on 2026-08-21 on mercure:
+ /// InvalidOperationException: The value of
+ /// 'CircleAuthorizationToBlogPost.BlogPostId' is unknown
+ /// when POSTs the
+ /// shape { "circleId": <id> } — the exact body the
+ /// PostIt client builds from
+ /// (which only carries CircleId). The server deserialises
+ /// it into , leaves
+ /// BlogPostId at its default(long) = 0, attaches
+ /// no Target navigation, and EF Core refuses to INSERT
+ /// during PrepareToSave(). The fix lives in PostIt
+ /// (enrich the payload with blogPostId + comment)
+ /// and on the wire DTO ( must
+ /// carry those fields); the server validates. Until that ships,
+ /// this test stays red.
+ ///
+ [Fact]
+ public async Task PostCircleAuthorization_returns_201_when_payload_mirrors_PostIt_shape_against_existing_circle_named_test()
+ {
+ // The prod circle already exists with Name="test", Public=true,
+ // owned by the caller. We seed the same shape pre-POST so the
+ // test reproduces the prod scenario end-to-end.
+ CleanupAcl();
+ using var http = NewClient("alice");
+
+ var payload = new PostAccessControlRulePayload
+ {
+ CircleId = _fixture.CircleId,
+ BlogPostId = _fixture.PostId
+ };
+
+ var response = await http.PostAsJsonAsync(BlogAclUrl(), payload,
+ TestContext.Current.CancellationToken);
+
+ Assert.Equal(HttpStatusCode.Created, response.StatusCode);
+ }
+
+ ///
+ /// Payload templates for .
+ /// Each row carries the shape we want to POST; -1L and
+ /// -2L are negative sentinels that the test substitutes
+ /// with the ids of freshly seeded Circle / BlogPost
+ /// rows before sending, so every shape lands against a real
+ /// principal entity and the seeded fixtures are not dead.
+ ///
+ public static IEnumerable