using System; namespace GB5Shared.Authorization { /// /// Declares the MROLEVSMENU-backed permission an endpoint requires. Read by /// before ExecuteAsync /// runs; the caller's LoginDTO.RoleId must have the corresponding /// bit allowed for , or the request is denied with HTTP 403. /// Endpoints without this attribute are unaffected — this is opt-in, not a breaking change. /// [AttributeUsage(AttributeTargets.Class, AllowMultiple = false, Inherited = true)] public sealed class MenuRightsAttribute : Attribute { public string MenuCode { get; } public RightOperation Operation { get; } public MenuRightsAttribute(string menuCode, RightOperation operation) { MenuCode = menuCode; Operation = operation; } } }