Files
ersatztv/ErsatzTV.Application/MediaCollections/Commands/CreatePlaylistHandler.cs
T
timothyandClaude Opus 4.8 216130b4d7 fix(#172): API hardening — null-name 500s, duplicate template items, unreachable 404
Clears the still-live findings from #172 (verified against main; #2/#4/#7 and the
auth/search/Trakt tail were already deliberate-documented or fixed since 2026-07-07).

- Null/empty Name → 500 (10 create/replace handlers). Block/Template/DecoTemplate/Deco
  Create+Replace/Update + UpdateFFmpegProfile did `request.Name.Length > 50` on a
  client-nullable string → unhandled NullReferenceException → HTTP 500 (no global
  exception filter). Now `string.IsNullOrWhiteSpace(request.Name) || .Length > 50` →
  422; also rejects empty/whitespace names, matching the group-create handlers'
  NotEmpty behavior. CreatePlaylist coalesces null→"" at the DTO so it was an
  empty-name persist, not a 500; guarded the same way.
- ReplaceTemplateItems overlap validation iterated with an `item == otherItem`
  record value-equality skip, so two exact-duplicate items were value-equal and
  bypassed the intersection check (both persisted). Now index-based (i != j) so
  duplicates register as a self-intersection and are rejected 422.
- Trimmed the unreachable 404 ProducesResponseType from POST /api/blocks/groups and
  POST /api/templates/groups (a create has no parent lookup that can 404); v1.json
  regenerated.
- Regression tests: all 10 name-guard paths + the duplicate-items path (19 cases).
- Docs: decisions.md entry + api-conventions.md §3b null-safe-validation bullet.

fixes #172

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 01:16:52 +02:00

51 lines
2.0 KiB
C#

using ErsatzTV.Core;
using ErsatzTV.Core.Domain;
using ErsatzTV.Infrastructure.Data;
using Microsoft.EntityFrameworkCore;
namespace ErsatzTV.Application.MediaCollections;
public class CreatePlaylistHandler(IDbContextFactory<TvContext> dbContextFactory)
: IRequestHandler<CreatePlaylist, Either<BaseError, PlaylistViewModel>>
{
public async Task<Either<BaseError, PlaylistViewModel>> Handle(
CreatePlaylist request,
CancellationToken cancellationToken)
{
await using TvContext dbContext = await dbContextFactory.CreateDbContextAsync(cancellationToken);
Validation<BaseError, Playlist> validation = await Validate(dbContext, request);
return await validation.Apply(profile => PersistPlaylist(dbContext, profile));
}
private static async Task<PlaylistViewModel> PersistPlaylist(TvContext dbContext, Playlist playlist)
{
await dbContext.Playlists.AddAsync(playlist);
await dbContext.SaveChangesAsync();
return Mapper.ProjectToViewModel(playlist);
}
private static async Task<Validation<BaseError, Playlist>> Validate(TvContext dbContext, CreatePlaylist request) =>
await ValidatePlaylistName(dbContext, request).MapT(name => new Playlist
{
PlaylistGroupId = request.PlaylistGroupId,
Name = name
});
private static async Task<Validation<BaseError, string>> ValidatePlaylistName(
TvContext dbContext,
CreatePlaylist request)
{
if (string.IsNullOrWhiteSpace(request.Name) || request.Name.Length > 50)
{
return BaseError.New($"Playlist name \"{request.Name}\" is invalid");
}
bool duplicate = await dbContext.Playlists
.AnyAsync(r => r.PlaylistGroupId == request.PlaylistGroupId && r.Name == request.Name);
return duplicate
? BaseError.New($"A playlist named \"{request.Name}\" already exists in that playlist group")
: Success<BaseError, string>(request.Name);
}
}