using System;
using System.Threading;
using System.Threading.Tasks;
using FastEndpoints;
using GB5Shared.DTO.Framework.Login;
using GB5Shared.DTO.Framework.ResponseStandard;
using GB5Shared.FastEndPoint;
using GB5Shared.Vault;
using static FrameworkDAL.Constant.Constant;
namespace FrameworkSL.Endpoints.Vault
{
///
/// Reads a secret from HashiCorp Vault via .
/// No module should ever hold its own Vault client — this endpoint (and the shared
/// GB5Shared.Vault.IVaultService function it calls) is the only supported access path.
///
public class GetSecretEndpoint : BaseEndpoint>
{
private readonly IVaultService _vaultService;
public GetSecretEndpoint(IVaultService vaultService)
{
_vaultService = vaultService;
}
public override void Configure()
{
Get("/Vault/GetSecret");
AllowAnonymous();
}
public record GetSecretParameters(
[property: FromHeader] string Login,
[property: QueryParam] string Key
);
protected override async Task> ExecuteAsync(GetSecretParameters req, LoginDTO LoginDTO, CancellationToken ct)
{
try
{
var value = await _vaultService.GetSecretAsync(req.Key, ct);
return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(
new { Key = req.Key, Value = value }, CacheKeyLevel.NOT_REQUIRED, LoginDTO);
}
catch (Exception ex)
{
return await GB5Shared.ResponseStandard.Response.CreateExceptionError(ex, CacheKeyLevel.NOT_REQUIRED, LoginDTO, ex.Message, 500);
}
}
}
}