using System; using System.Threading; using System.Threading.Tasks; using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using GB5Shared.Vault; using static FrameworkDAL.Constant.Constant; namespace FrameworkSL.Endpoints.Vault { /// /// Reads a secret from HashiCorp Vault via . /// No module should ever hold its own Vault client — this endpoint (and the shared /// GB5Shared.Vault.IVaultService function it calls) is the only supported access path. /// public class GetSecretEndpoint : BaseEndpoint> { private readonly IVaultService _vaultService; public GetSecretEndpoint(IVaultService vaultService) { _vaultService = vaultService; } public override void Configure() { Get("/Vault/GetSecret"); AllowAnonymous(); } public record GetSecretParameters( [property: FromHeader] string Login, [property: QueryParam] string Key ); protected override async Task> ExecuteAsync(GetSecretParameters req, LoginDTO LoginDTO, CancellationToken ct) { try { var value = await _vaultService.GetSecretAsync(req.Key, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse( new { Key = req.Key, Value = value }, CacheKeyLevel.NOT_REQUIRED, LoginDTO); } catch (Exception ex) { return await GB5Shared.ResponseStandard.Response.CreateExceptionError(ex, CacheKeyLevel.NOT_REQUIRED, LoginDTO, ex.Message, 500); } } } }