Files
ersatztv/ErsatzTV.Application/Scheduling/Commands/CreateTemplateHandler.cs
T
timothyandClaude Opus 4.8 216130b4d7 fix(#172): API hardening — null-name 500s, duplicate template items, unreachable 404
Clears the still-live findings from #172 (verified against main; #2/#4/#7 and the
auth/search/Trakt tail were already deliberate-documented or fixed since 2026-07-07).

- Null/empty Name → 500 (10 create/replace handlers). Block/Template/DecoTemplate/Deco
  Create+Replace/Update + UpdateFFmpegProfile did `request.Name.Length > 50` on a
  client-nullable string → unhandled NullReferenceException → HTTP 500 (no global
  exception filter). Now `string.IsNullOrWhiteSpace(request.Name) || .Length > 50` →
  422; also rejects empty/whitespace names, matching the group-create handlers'
  NotEmpty behavior. CreatePlaylist coalesces null→"" at the DTO so it was an
  empty-name persist, not a 500; guarded the same way.
- ReplaceTemplateItems overlap validation iterated with an `item == otherItem`
  record value-equality skip, so two exact-duplicate items were value-equal and
  bypassed the intersection check (both persisted). Now index-based (i != j) so
  duplicates register as a self-intersection and are rejected 422.
- Trimmed the unreachable 404 ProducesResponseType from POST /api/blocks/groups and
  POST /api/templates/groups (a create has no parent lookup that can 404); v1.json
  regenerated.
- Regression tests: all 10 name-guard paths + the duplicate-items path (19 cases).
- Docs: decisions.md entry + api-conventions.md §3b null-safe-validation bullet.

fixes #172

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 01:16:52 +02:00

68 lines
2.7 KiB
C#

using ErsatzTV.Core;
using ErsatzTV.Core.Domain.Scheduling;
using ErsatzTV.Infrastructure.Data;
using Microsoft.EntityFrameworkCore;
namespace ErsatzTV.Application.Scheduling;
public class CreateTemplateHandler(IDbContextFactory<TvContext> dbContextFactory)
: IRequestHandler<CreateTemplate, Either<BaseError, TemplateViewModel>>
{
public async Task<Either<BaseError, TemplateViewModel>> Handle(
CreateTemplate request,
CancellationToken cancellationToken)
{
await using TvContext dbContext = await dbContextFactory.CreateDbContextAsync(cancellationToken);
Validation<BaseError, Template> validation = await Validate(dbContext, request);
return await validation.Apply(profile => PersistTemplate(dbContext, profile));
}
private static async Task<TemplateViewModel> PersistTemplate(TvContext dbContext, Template template)
{
await dbContext.Templates.AddAsync(template);
await dbContext.SaveChangesAsync();
await dbContext.Entry(template).Reference(t => t.TemplateGroup).LoadAsync();
return Mapper.ProjectToViewModel(template);
}
private static async Task<Validation<BaseError, Template>> Validate(TvContext dbContext, CreateTemplate request)
{
Validation<BaseError, Unit> templateGroupValidation = await ValidateTemplateGroupExists(dbContext, request);
Validation<BaseError, string> nameValidation = await ValidateTemplateName(dbContext, request);
return (templateGroupValidation, nameValidation).Apply((_, name) => new Template
{
TemplateGroupId = request.TemplateGroupId,
Name = name
});
}
private static async Task<Validation<BaseError, Unit>> ValidateTemplateGroupExists(
TvContext dbContext,
CreateTemplate request)
{
bool templateGroupExists = await dbContext.TemplateGroups.AnyAsync(tg => tg.Id == request.TemplateGroupId);
return templateGroupExists
? Success<BaseError, Unit>(Unit.Default)
: BaseError.New("Template group does not exist");
}
private static async Task<Validation<BaseError, string>> ValidateTemplateName(
TvContext dbContext,
CreateTemplate request)
{
if (string.IsNullOrWhiteSpace(request.Name) || request.Name.Length > 50)
{
return BaseError.New($"Template name \"{request.Name}\" is invalid");
}
bool duplicateName = await dbContext.Templates
.AnyAsync(r => r.TemplateGroupId == request.TemplateGroupId && r.Name == request.Name);
return duplicateName
? BaseError.New($"A template named \"{request.Name}\" already exists in that template group")
: Success<BaseError, string>(request.Name);
}
}