Files
ersatztv/ErsatzTV.Application/Scheduling/Commands/CreateBlockHandler.cs
T
timothyandClaude Opus 4.8 216130b4d7 fix(#172): API hardening — null-name 500s, duplicate template items, unreachable 404
Clears the still-live findings from #172 (verified against main; #2/#4/#7 and the
auth/search/Trakt tail were already deliberate-documented or fixed since 2026-07-07).

- Null/empty Name → 500 (10 create/replace handlers). Block/Template/DecoTemplate/Deco
  Create+Replace/Update + UpdateFFmpegProfile did `request.Name.Length > 50` on a
  client-nullable string → unhandled NullReferenceException → HTTP 500 (no global
  exception filter). Now `string.IsNullOrWhiteSpace(request.Name) || .Length > 50` →
  422; also rejects empty/whitespace names, matching the group-create handlers'
  NotEmpty behavior. CreatePlaylist coalesces null→"" at the DTO so it was an
  empty-name persist, not a 500; guarded the same way.
- ReplaceTemplateItems overlap validation iterated with an `item == otherItem`
  record value-equality skip, so two exact-duplicate items were value-equal and
  bypassed the intersection check (both persisted). Now index-based (i != j) so
  duplicates register as a self-intersection and are rejected 422.
- Trimmed the unreachable 404 ProducesResponseType from POST /api/blocks/groups and
  POST /api/templates/groups (a create has no parent lookup that can 404); v1.json
  regenerated.
- Regression tests: all 10 name-guard paths + the duplicate-items path (19 cases).
- Docs: decisions.md entry + api-conventions.md §3b null-safe-validation bullet.

fixes #172

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 01:16:52 +02:00

69 lines
2.6 KiB
C#

using ErsatzTV.Core;
using ErsatzTV.Core.Domain.Scheduling;
using ErsatzTV.Infrastructure.Data;
using Microsoft.EntityFrameworkCore;
namespace ErsatzTV.Application.Scheduling;
public class CreateBlockHandler(IDbContextFactory<TvContext> dbContextFactory)
: IRequestHandler<CreateBlock, Either<BaseError, BlockViewModel>>
{
public async Task<Either<BaseError, BlockViewModel>> Handle(
CreateBlock request,
CancellationToken cancellationToken)
{
await using TvContext dbContext = await dbContextFactory.CreateDbContextAsync(cancellationToken);
Validation<BaseError, Block> validation = await Validate(dbContext, request);
return await validation.Apply(profile => PersistBlock(dbContext, profile));
}
private static async Task<BlockViewModel> PersistBlock(TvContext dbContext, Block block)
{
await dbContext.Blocks.AddAsync(block);
await dbContext.SaveChangesAsync();
await dbContext.Entry(block).Reference(b => b.BlockGroup).LoadAsync();
return Mapper.ProjectToViewModel(block);
}
private static async Task<Validation<BaseError, Block>> Validate(TvContext dbContext, CreateBlock request)
{
Validation<BaseError, Unit> blockGroupValidation = await ValidateBlockGroupExists(dbContext, request);
Validation<BaseError, string> nameValidation = await ValidateBlockName(dbContext, request);
return (blockGroupValidation, nameValidation).Apply((_, name) => new Block
{
BlockGroupId = request.BlockGroupId,
Name = name,
Minutes = 30
});
}
private static async Task<Validation<BaseError, Unit>> ValidateBlockGroupExists(
TvContext dbContext,
CreateBlock request)
{
bool blockGroupExists = await dbContext.BlockGroups.AnyAsync(bg => bg.Id == request.BlockGroupId);
return blockGroupExists
? Success<BaseError, Unit>(Unit.Default)
: BaseError.New("Block group does not exist");
}
private static async Task<Validation<BaseError, string>> ValidateBlockName(
TvContext dbContext,
CreateBlock request)
{
if (string.IsNullOrWhiteSpace(request.Name) || request.Name.Length > 50)
{
return BaseError.New($"Block name \"{request.Name}\" is invalid");
}
bool duplicate = await dbContext.Blocks
.AnyAsync(r => r.BlockGroupId == request.BlockGroupId && r.Name == request.Name);
return duplicate
? BaseError.New($"A block named \"{request.Name}\" already exists in that block group")
: Success<BaseError, string>(request.Name);
}
}