fix: code compliance audit and fix across all services
NestJS (6 services): implement @RequirePermission decorator with SetMetadata+Reflector, register APP_GUARD globally, fix as assertions to type guards, add explicit return types, fix import type for express, fix /metrics implicit any, replace native Error with ApplicationError, remove typeorm remnants, register LifecycleService. teacher-bff: add logger, ApplicationError, GlobalErrorFilter, forward real userId to downstream, log downstream failures, migrate health controller to shared/health. Go (2 services): interface to any, doc comments, CORS dev whitelist, JWT secret fail-fast, push-gateway internal API auth, metrics and readyz endpoints, remove dead code. Python (2 services): lifespan return type, dev_mode to bool, data-ana APIRouter, ai POST body model, ClickHouse async wrapping.
This commit is contained in:
@@ -8,23 +8,32 @@ import {
|
||||
Put,
|
||||
Req,
|
||||
} from "@nestjs/common";
|
||||
import type { Request } from "express";
|
||||
import {
|
||||
ExamsService,
|
||||
type CreateExamInput,
|
||||
type UpdateExamInput,
|
||||
} from "./exams.service.js";
|
||||
import {
|
||||
Permissions,
|
||||
RequirePermission,
|
||||
} from "../middleware/permission.guard.js";
|
||||
import type { AuthenticatedRequest } from "../middleware/auth.middleware.js";
|
||||
import { UnauthorizedError } from "../shared/errors/application-error.js";
|
||||
|
||||
@Controller("exams")
|
||||
export class ExamsController {
|
||||
constructor(private readonly examsService: ExamsService) {}
|
||||
|
||||
@Post()
|
||||
@RequirePermission(Permissions.EXAM_CREATE)
|
||||
async create(
|
||||
@Body() body: CreateExamInput,
|
||||
@Req() req: Request,
|
||||
@Req() req: AuthenticatedRequest,
|
||||
): Promise<{ success: true; data: { id: string } }> {
|
||||
const userId = req.headers["x-user-id"] as string;
|
||||
const userId = req.userId;
|
||||
if (!userId) {
|
||||
throw new UnauthorizedError("Missing x-user-id header");
|
||||
}
|
||||
const result = await this.examsService.createExam({
|
||||
...body,
|
||||
createdBy: userId,
|
||||
@@ -33,6 +42,7 @@ export class ExamsController {
|
||||
}
|
||||
|
||||
@Get(":id")
|
||||
@RequirePermission(Permissions.EXAM_READ)
|
||||
async findOne(@Param("id") id: string): Promise<{
|
||||
success: true;
|
||||
data: Awaited<ReturnType<ExamsService["getExam"]>>;
|
||||
@@ -42,6 +52,7 @@ export class ExamsController {
|
||||
}
|
||||
|
||||
@Get("class/:classId")
|
||||
@RequirePermission(Permissions.EXAM_READ)
|
||||
async listByClass(@Param("classId") classId: string): Promise<{
|
||||
success: true;
|
||||
data: Awaited<ReturnType<ExamsService["listExamsByClass"]>>;
|
||||
@@ -51,6 +62,7 @@ export class ExamsController {
|
||||
}
|
||||
|
||||
@Put(":id")
|
||||
@RequirePermission(Permissions.EXAM_UPDATE)
|
||||
async update(
|
||||
@Param("id") id: string,
|
||||
@Body() body: UpdateExamInput,
|
||||
@@ -60,6 +72,7 @@ export class ExamsController {
|
||||
}
|
||||
|
||||
@Delete(":id")
|
||||
@RequirePermission(Permissions.EXAM_DELETE)
|
||||
async remove(
|
||||
@Param("id") id: string,
|
||||
): Promise<{ success: true; data: { success: true } }> {
|
||||
|
||||
Reference in New Issue
Block a user