using FastEndpoints; using FrameworkBLL.UserLogin; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; using System.Linq; namespace FrameworkSL.Endpoints.UserLogin { /// /// Force-terminates one or more active sessions by LoginEventLogId. /// Admin calls this after viewing GetLoggedInUsersForDashboard. /// Deletes the session rows from MSESSIONSTORE — the next API call from /// each terminated session receives 401 from SessionHeartbeatMiddleware. /// GB4 equivalent: POST /fws/Synchronization.svc/ForceLogOut /// public class ForceLogout : BaseEndpoint> { private readonly ILoggedInUsersBLL _bll; public ForceLogout(ILoggedInUsersBLL bll) => _bll = bll; public override void Configure() { Delete("/UserLogin/ForceLogout"); AllowAnonymous(); } public class ForceLogoutParameters { [FromHeader] public string Login { get; set; } /// /// One or more LoginEventLogIds to force-logout. /// Taken from the EventLogId field in GetLoggedInUsersForDashboard response. /// [FromBody] public List LoginEventLogIds { get; set; } } protected override string? GetCacheKey(ForceLogoutParameters req, LoginDTO login) => null; protected override async Task> ExecuteAsync( ForceLogoutParameters req, LoginDTO login, CancellationToken ct) { if (login is null) return await GB5Shared.ResponseStandard.Response.CreateErrorResponse( "You must be signed in to force-logout other users. Please include a valid Login header and try again.", CacheKeyLevel.NOT_REQUIRED, null!, 401); if (req.LoginEventLogIds is null || req.LoginEventLogIds.Count == 0) return await GB5Shared.ResponseStandard.Response.CreateErrorResponse( "No session IDs were provided. Please send a JSON array of one or more session IDs in the request body. You can get these IDs from the Active Users dashboard.", CacheKeyLevel.NOT_REQUIRED, login, 400); var validIds = req.LoginEventLogIds.Where(id => id > 0).ToList(); if (validIds.Count == 0) return await GB5Shared.ResponseStandard.Response.CreateErrorResponse( "All provided session IDs are invalid. Session IDs must be positive integers greater than zero.", CacheKeyLevel.NOT_REQUIRED, login, 400); try { var result = await _bll.ForceLogoutAsync(validIds, login, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse( result, CacheKeyLevel.NOT_REQUIRED, login); } catch (Exception ex) { return await GB5Shared.ResponseStandard.Response.CreateExceptionError( ex, CacheKeyLevel.NOT_REQUIRED, login, ex.Message, 500); } } } }