Files
ersatztv/ErsatzTV.Core/VersionedAggregateExtensions.cs
T
timothyandClaude Opus 4.8 94ebf34ccd
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 7s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 5m24s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 4m25s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
feat(api): optimistic-concurrency contract for replace-all PUTs — PR1 infra + Block reference (#253)
Adds the shared optimistic-concurrency contract so a stale second tab can no longer
silently overwrite a fresher edit. PR1 lands the infra + the Block reference aggregate;
PRs 2–4 fan the same recipe across the other 8 roots (design: #253#issuecomment-8472).

Contract
- `IVersionedAggregate` (`int Version`) on all 9 replace-all roots (ProgramSchedule,
  Block, Template, DecoTemplate, Playlist, Collection, Playout, MultiCollection,
  RerunCollection), EF-mapped `.IsConcurrencyToken()`; one dual-provider migration
  `AddAggregateVersions` (nullable:false, default 0).
- Strong `ETag` of `Version` on the aggregate GET; `If-Match` on the PUT; mismatch →
  412 (distinct from the §3a 409 build-lock guard). Successful PUT returns the new ETag.
- `PreconditionFailedError : BaseError` → 412 in `ApiResults.ToErrorResult`;
  `ConcurrencyHeaders.ParseIfMatch/SetETag`; malformed If-Match → 400; `*`/absent =
  Phase-1 force-write.

Block reference wiring
- Handler: standalone `Either` via `CheckVersion` AFTER validation (never through
  `Apply`, which Join()-flattens the subtype to 422), unconditional `Version++`,
  `SaveChangesWithConcurrencyGuard` backstop (DbUpdateConcurrencyException → 412).
- `BlockViewModel.Version` (header-only, not echoed in the body); controller sets the
  ETag on GET items and on the successful PUT.
- SPA: `client.requestWithMeta` seam; `blocks.getBlockItemsWithMeta` + `replaceBlock`
  If-Match/ETag round-trip; `BlockEditor` holds the ETag, sends If-Match, and on 412
  opens a blocking "changed elsewhere — reload" dialog.

Tests
- Handler contract tests: stale-If-Match → 412 (no mutation), matching/absent → success
  + bump, no-op save still bumps, and a two-context racing save → 412; proven
  non-vacuous (drop `.IsConcurrencyToken()` → the race test fails).
- Controller tests: malformed If-Match → 400, If-Match threaded to the command, ETag on
  GET/PUT, 412 passthrough. SPA: requestWithMeta ETag, replaceBlock If-Match, 412 dialog.

Docs: api-conventions §7a, spa-conventions §4a, domain-model glossary, decisions log.

Refs #253
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-11 16:51:59 +02:00

25 lines
1.2 KiB
C#

using ErsatzTV.Core.Domain;
using ErsatzTV.Core.Errors;
namespace ErsatzTV.Core;
public static class VersionedAggregateExtensions
{
/// <summary>
/// Optimistic-concurrency pre-check (issue #253). When the caller supplied an expected
/// version (from <c>If-Match</c>), fail with <see cref="PreconditionFailedError" /> (→ 412)
/// if it no longer matches the loaded aggregate. An absent expectation is a force-write
/// (Phase 1 back-compat). This returns a standalone <see cref="Either{L,R}" /> so the 412
/// is introduced AFTER the validation pipeline and never flattened to 422 by
/// <see cref="LanguageExtensions.Apply{T,TR}" /> (see api-conventions §7a).
/// </summary>
public static Either<BaseError, T> CheckVersion<T>(this T aggregate, Option<int> expectedVersion)
where T : IVersionedAggregate =>
expectedVersion.Match(
Some: expected => aggregate.Version == expected
? Right<BaseError, T>(aggregate)
: Left<BaseError, T>(new PreconditionFailedError(
"The resource was modified by another request. Reload and try again.")),
None: () => Right<BaseError, T>(aggregate));
}