using GB5Shared.DTO.Framework.Login; using Newtonsoft.Json; namespace CMSBLL.Common; // Shared by every BLL that composes data for an anonymous, domain-resolved public request // (SiteDocumentBLL, DataSourceProxyBLL) — the caller's own LoginDTO.ClientId has no necessary // relationship to the tenant that owns the resolved Site (the caller may have no login context // at all, or may be a service account shared across every tenant), so every tenant-filtered // query these flows make must run against a login carrying the domain-resolved TenantId, never // the caller's original ClientId. See SiteDocumentBLL.ComposeAsync's original doc comment for // the bug this fixed. public static class LoginTenantRebase { // JSON round-trip rather than a hand-picked field list — LoginDTO has ~80 properties and // QueryExecutor's exact connection-resolution needs aren't all enumerated here; cloning // everything serializable and then overriding just ClientId is the only way to be sure // DatabaseName/DatabaseType/etc. all survive intact. LoginDTO's few [JsonIgnore] fields are // WIP-callback-only state, irrelevant to this read-only composition. public static LoginDTO RebaseTenant(LoginDTO original, int tenantId) { var clone = JsonConvert.DeserializeObject(JsonConvert.SerializeObject(original)) ?? new LoginDTO(); clone.ClientId = tenantId; return clone; } }