fix: code compliance audit and fix across all services
NestJS (6 services): implement @RequirePermission decorator with SetMetadata+Reflector, register APP_GUARD globally, fix as assertions to type guards, add explicit return types, fix import type for express, fix /metrics implicit any, replace native Error with ApplicationError, remove typeorm remnants, register LifecycleService. teacher-bff: add logger, ApplicationError, GlobalErrorFilter, forward real userId to downstream, log downstream failures, migrate health controller to shared/health. Go (2 services): interface to any, doc comments, CORS dev whitelist, JWT secret fail-fast, push-gateway internal API auth, metrics and readyz endpoints, remove dead code. Python (2 services): lifespan return type, dev_mode to bool, data-ana APIRouter, ai POST body model, ClickHouse async wrapping.
This commit is contained in:
@@ -1,20 +1,29 @@
|
||||
import { Body, Controller, Get, Param, Post, Req } from "@nestjs/common";
|
||||
import type { Request } from "express";
|
||||
import {
|
||||
HomeworkService,
|
||||
type AssignHomeworkInput,
|
||||
} from "./homework.service.js";
|
||||
import {
|
||||
Permissions,
|
||||
RequirePermission,
|
||||
} from "../middleware/permission.guard.js";
|
||||
import type { AuthenticatedRequest } from "../middleware/auth.middleware.js";
|
||||
import { UnauthorizedError } from "../shared/errors/application-error.js";
|
||||
|
||||
@Controller("homework")
|
||||
export class HomeworkController {
|
||||
constructor(private readonly homeworkService: HomeworkService) {}
|
||||
|
||||
@Post()
|
||||
@RequirePermission(Permissions.HOMEWORK_CREATE)
|
||||
async assign(
|
||||
@Body() body: AssignHomeworkInput,
|
||||
@Req() req: Request,
|
||||
@Req() req: AuthenticatedRequest,
|
||||
): Promise<{ success: true; data: { id: string } }> {
|
||||
const userId = req.headers["x-user-id"] as string;
|
||||
const userId = req.userId;
|
||||
if (!userId) {
|
||||
throw new UnauthorizedError("Missing x-user-id header");
|
||||
}
|
||||
const result = await this.homeworkService.assignHomework({
|
||||
...body,
|
||||
createdBy: userId,
|
||||
@@ -23,6 +32,7 @@ export class HomeworkController {
|
||||
}
|
||||
|
||||
@Get(":id")
|
||||
@RequirePermission(Permissions.HOMEWORK_READ)
|
||||
async findOne(@Param("id") id: string): Promise<{
|
||||
success: true;
|
||||
data: Awaited<ReturnType<HomeworkService["getHomework"]>>;
|
||||
@@ -32,6 +42,7 @@ export class HomeworkController {
|
||||
}
|
||||
|
||||
@Get("class/:classId")
|
||||
@RequirePermission(Permissions.HOMEWORK_READ)
|
||||
async listByClass(@Param("classId") classId: string): Promise<{
|
||||
success: true;
|
||||
data: Awaited<ReturnType<HomeworkService["listByClass"]>>;
|
||||
@@ -41,6 +52,7 @@ export class HomeworkController {
|
||||
}
|
||||
|
||||
@Post(":id/submit")
|
||||
@RequirePermission(Permissions.HOMEWORK_SUBMIT)
|
||||
async submit(
|
||||
@Param("id") id: string,
|
||||
): Promise<{ success: true; data: { success: true } }> {
|
||||
|
||||
Reference in New Issue
Block a user