Files
tasq/lib/providers/workforce_provider.dart
T
redz1029 3cb980b629 QA hardening: security RLS fixes, Flutter 3.47.5 upgrade, UI/validation fixes
Security — enforce write authorization server-side (was UI/RPC-only):
- it_service_requests RLS: block cross-office read/edit + self-approve (QA-015)
- pass_slips RLS: owner can complete but not self-approve (QA-046)
- swap_requests RLS: scope select/update to participants + admin (QA-047)
- storage: tighten it_service_attachments + task_attachments write/delete (QA-027)
- admin_user_management edge function: allow programmers to manage users (QA-016)

Fixes:
- workforce generator "uncovered shifts" false alarms (QA-043/044)
- network-map VLAN + New-location dialog validation, disabled-until-valid (QA-048)
- de-flake time-of-day-dependent dashboard metrics test (QA-045)

Toolchain:
- upgrade to Flutter 3.47.5 / Dart 3.13.4; font_awesome_flutter 11.0.0,
  flutter_quill 11.6.0, pdfrx 2.6.5; clear resulting deprecations (QA-002)

analyze clean; 139 tests pass; web build succeeds. Report + evidence in docs/qa/.

Note: also carries the in-progress Brick model cleanup already present in the
working tree. QA-001 (AI keys public in the build) is deferred by owner decision.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-09-26 11:52:16 +08:00

357 lines
12 KiB
Dart

import 'dart:async';
import 'dart:convert';
import 'package:flutter_riverpod/flutter_riverpod.dart';
import 'package:shared_preferences/shared_preferences.dart';
import 'package:supabase_flutter/supabase_flutter.dart';
import '../brick/cache_helpers.dart';
import '../models/app_settings.dart';
import '../models/duty_schedule.model.dart';
import '../models/swap_request.model.dart';
import 'profile_provider.dart';
import 'supabase_provider.dart';
import 'stream_recovery.dart';
import 'realtime_controller.dart';
const _kGeofenceCacheKey = 'geofence_cache_v1';
final geofenceProvider = FutureProvider<GeofenceConfig?>((ref) async {
final client = ref.watch(supabaseClientProvider);
try {
final data = await client
.from('app_settings')
.select()
.eq('key', 'geofence')
.maybeSingle();
final prefs = await SharedPreferences.getInstance();
if (data == null) {
await prefs.setString(_kGeofenceCacheKey, 'null');
return null;
}
final setting = AppSetting.fromMap(data);
await prefs.setString(_kGeofenceCacheKey, jsonEncode(setting.value));
return GeofenceConfig.fromJson(setting.value);
} catch (_) {
// Offline / network failure — fall back to cached config so geofence
// validation still runs during offline check-in.
try {
final prefs = await SharedPreferences.getInstance();
final raw = prefs.getString(_kGeofenceCacheKey);
if (raw == null || raw == 'null') return null;
final json = jsonDecode(raw) as Map<String, dynamic>;
return GeofenceConfig.fromJson(json);
} catch (_) {
return null;
}
}
});
/// Toggle to show/hide past schedules. Defaults to false (hide past).
final showPastSchedulesProvider = StateProvider<bool>((ref) => false);
final dutySchedulesProvider = StreamProvider<List<DutySchedule>>((ref) {
final client = ref.watch(supabaseClientProvider);
// Only recreate stream when user id changes (not on other profile edits).
final profileId = ref.watch(
currentProfileProvider.select((p) => p.valueOrNull?.id),
);
if (profileId == null) {
return Stream.value(const <DutySchedule>[]);
}
// All roles now see all schedules (RLS updated in migration)
final wrapper = StreamRecoveryWrapper<DutySchedule>(
stream: client
.from('duty_schedules')
.stream(primaryKey: ['id'])
.order('start_time', ascending: true),
onPollData: () async {
final data = await client
.from('duty_schedules')
.select()
.order('start_time', ascending: true);
return data.map(DutySchedule.fromMap).toList();
},
fromMap: DutySchedule.fromMap,
channelName: 'duty_schedules',
onStatusChanged: ref.read(realtimeControllerProvider).handleChannelStatus,
onOfflineData: () async {
final all = await cachedListFromBrick<DutySchedule>();
all.sort((a, b) => a.startTime.compareTo(b.startTime));
return all;
},
onCacheMirror: (rows) =>
mirrorBatchToBrick<DutySchedule>(rows, tag: 'duty_schedules'),
);
ref.onDispose(wrapper.dispose);
// Immediate poll so any changes that happened while this provider was
// not alive (e.g. a swap was accepted on another device) are reflected
// right away — before the periodic timer fires.
wrapper.pollNow();
// Periodic safety-net: keep polling so that ownership changes
// (swap accepted → user_id updated on duty_schedules) are always picked
// up even if Supabase Realtime misses the event.
// ponytail: was 3 s, i.e. every client re-downloaded the whole table ~20x a
// minute. Realtime is the primary path; 60 s bounds how stale a missed swap
// can get. Tighten only if swaps need faster convergence.
final dutyRefreshTimer = Timer.periodic(const Duration(seconds: 60), (_) {
wrapper.pollNow();
});
ref.onDispose(dutyRefreshTimer.cancel);
return wrapper.stream.map((result) => result.data);
});
/// Fetch duty schedules by a list of IDs (used by UI when swap requests reference
/// schedules that are not included in the current user's `dutySchedulesProvider`).
final dutySchedulesByIdsProvider =
FutureProvider.family<List<DutySchedule>, List<String>>((ref, ids) async {
if (ids.isEmpty) return const <DutySchedule>[];
final client = ref.watch(supabaseClientProvider);
final quoted = ids.map((id) => '"$id"').join(',');
final inList = '($quoted)';
final rows =
await client
.from('duty_schedules')
.select()
.filter('id', 'in', inList)
as List<dynamic>;
return rows
.map((r) => DutySchedule.fromMap(r as Map<String, dynamic>))
.toList();
});
/// Fetch upcoming duty schedules for a specific user (used by swap UI to
/// let the requester pick a concrete target shift owned by the recipient).
final dutySchedulesForUserProvider =
FutureProvider.family<List<DutySchedule>, String>((ref, userId) async {
final client = ref.watch(supabaseClientProvider);
final nowIso = DateTime.now().toUtc().toIso8601String();
final rows =
await client
.from('duty_schedules')
.select()
.eq('user_id', userId)
/* exclude past schedules by ensuring the shift has not ended */
.gte('end_time', nowIso)
.order('start_time', ascending: true)
as List<dynamic>;
return rows
.map((r) => DutySchedule.fromMap(r as Map<String, dynamic>))
.toList();
});
final swapRequestsProvider = StreamProvider<List<SwapRequest>>((ref) {
final client = ref.watch(supabaseClientProvider);
// Only recreate stream when user id or role changes.
final profileId = ref.watch(
currentProfileProvider.select((p) => p.valueOrNull?.id),
);
final profileRole = ref.watch(
currentProfileProvider.select((p) => p.valueOrNull?.role),
);
if (profileId == null) {
return Stream.value(const <SwapRequest>[]);
}
final isAdmin =
profileRole == 'admin' ||
profileRole == 'programmer' ||
profileRole == 'dispatcher';
final wrapper = StreamRecoveryWrapper<SwapRequest>(
stream: isAdmin
? client
.from('swap_requests')
.stream(primaryKey: ['id'])
.order('created_at', ascending: false)
: client
.from('swap_requests')
.stream(primaryKey: ['id'])
.order('created_at', ascending: false),
onPollData: () async {
final data = await client
.from('swap_requests')
.select()
.inFilter('status', ['pending', 'admin_review'])
.order('created_at', ascending: false);
return data.map(SwapRequest.fromMap).toList();
},
fromMap: SwapRequest.fromMap,
channelName: 'swap_requests',
onStatusChanged: ref.read(realtimeControllerProvider).handleChannelStatus,
onOfflineData: () async {
final all = await cachedListFromBrick<SwapRequest>();
final filtered = isAdmin
? all
: all
.where(
(r) => r.requesterId == profileId || r.recipientId == profileId,
)
.toList();
filtered.sort((a, b) => b.createdAt.compareTo(a.createdAt));
return filtered;
},
onCacheMirror: (rows) =>
mirrorBatchToBrick<SwapRequest>(rows, tag: 'swap_requests'),
);
ref.onDispose(wrapper.dispose);
// Immediate poll: fetch fresh data right away so any status changes that
// happened while this provider was not alive are reflected instantly,
// before the periodic timer fires for the first time.
wrapper.pollNow();
// Periodic safety-net: keep polling to catch any status changes
// that Supabase Realtime may have missed (e.g. when the swap_requests table
// is not yet in the supabase_realtime publication).
// ponytail: was 3 s (see dutySchedulesProvider); 60 s safety net.
final refreshTimer = Timer.periodic(const Duration(seconds: 60), (_) {
wrapper.pollNow();
});
ref.onDispose(refreshTimer.cancel);
return wrapper.stream.map((result) {
// only return requests that are still actionable; once a swap has been
// accepted or rejected we no longer need to bubble it up to the UI for
// either party. admins still see "admin_review" rows so they can act on
// escalated cases.
return result.data.where((row) {
// admins see all swaps; standard users only see swaps they're in
if (!isAdmin && !(row.requesterId == profileId || row.recipientId == profileId)) {
return false;
}
// only keep pending and admin_review statuses
return row.status == 'pending' || row.status == 'admin_review';
}).toList();
});
});
/// IDs of swap requests that were acted on locally (accepted, rejected, etc.).
/// Kept as a global provider so the set survives tab switches — widget state
/// is disposed when the user navigates away from My Schedule.
final locallyRemovedSwapIdsProvider = StateProvider<Set<String>>((ref) => {});
/// IDs of duty_schedules owned by the current user that were created by an accepted swap.
final swappedScheduleIdsProvider = Provider<Set<String>>((ref) {
final schedules = ref.watch(dutySchedulesProvider).valueOrNull ?? [];
return {
for (final s in schedules)
if (s.swapRequestId != null) s.id,
};
});
final workforceControllerProvider = Provider<WorkforceController>((ref) {
final client = ref.watch(supabaseClientProvider);
return WorkforceController(client);
});
class WorkforceController {
WorkforceController(this._client);
final SupabaseClient _client;
Future<void> generateSchedule({
required DateTime startDate,
required DateTime endDate,
}) async {
await _client.rpc(
'generate_duty_schedule',
params: {
'start_date': _formatDate(startDate),
'end_date': _formatDate(endDate),
},
);
}
Future<void> insertSchedules(List<Map<String, dynamic>> schedules) async {
if (schedules.isEmpty) return;
await _client.from('duty_schedules').insert(schedules);
}
Future<String?> checkIn({
required String dutyScheduleId,
required double lat,
required double lng,
}) async {
final data = await _client.rpc(
'duty_check_in',
params: {'p_duty_id': dutyScheduleId, 'p_lat': lat, 'p_lng': lng},
);
return data as String?;
}
Future<String?> requestSwap({
required String requesterScheduleId,
required String targetScheduleId,
required String recipientId,
}) async {
final data = await _client.rpc(
'request_shift_swap',
params: {
'p_shift_id': requesterScheduleId,
'p_target_shift_id': targetScheduleId,
'p_recipient_id': recipientId,
},
);
return data as String?;
}
Future<void> respondSwap({
required String swapId,
required String action,
}) async {
await _client.rpc(
'respond_shift_swap',
params: {'p_swap_id': swapId, 'p_action': action},
);
}
/// Reassign the recipient of a swap request. Only admins/dispatchers are
/// expected to call this; the DB RLS and RPCs will additionally enforce rules.
Future<void> reassignSwap({
required String swapId,
required String newRecipientId,
}) async {
// Prefer using an RPC for server-side validation, but update directly here
await _client
.from('swap_requests')
.update({
'recipient_id': newRecipientId,
'status': 'pending',
'updated_at': DateTime.now().toUtc().toIso8601String(),
})
.eq('id', swapId);
}
Future<void> updateSchedule({
required String scheduleId,
required String userId,
required String shiftType,
required DateTime startTime,
required DateTime endTime,
}) async {
await _client
.from('duty_schedules')
.update({
'user_id': userId,
'shift_type': shiftType,
'start_time': startTime.toUtc().toIso8601String(),
'end_time': endTime.toUtc().toIso8601String(),
})
.eq('id', scheduleId);
}
String _formatDate(DateTime value) {
final date = DateTime(value.year, value.month, value.day);
final month = date.month.toString().padLeft(2, '0');
final day = date.day.toString().padLeft(2, '0');
return '${date.year}-$month-$day';
}
}