using CMSBLL.DataSourceProxy; using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; namespace CMSSL.Endpoints.Cms; // Client-side-fetch proxy (Site/Page platform Phase 12): the ONLY way a ClientSideFetch-bound // block's FE island ever reaches an external DataSource. It never talks to the third-party // endpoint directly and never sees its Vault secret — this endpoint resolves Domain -> Site/ // TenantId exactly like GetSiteDocument (never trusting a client-supplied TenantId), then // delegates to the same fetch+auth+mapping+cache logic the server-merge path uses. public class GetBlockData : BaseEndpoint { private readonly IDataSourceProxyBLL _proxyBll; public GetBlockData(IDataSourceProxyBLL proxyBll) => _proxyBll = proxyBll; public override void Configure() { Get("/CMS/GetBlockData"); AllowAnonymous(); } public record Parameters( [property: QueryParam] string Domain, [property: QueryParam] string DataSourceCode, [property: QueryParam] string? ParamsJson, [property: FromHeader] string Login ); protected override async Task> ExecuteAsync(Parameters req, LoginDTO login, CancellationToken ct) { try { var result = await _proxyBll.ResolveDataForDomainAsync(req.Domain, req.DataSourceCode, req.ParamsJson, login, ct); if (result is null) return await GB5Shared.ResponseStandard.Response.CreateExceptionError( new Exception("Site not found."), CacheKeyLevel.NOT_REQUIRED, login, "Site not found.", 404); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, login); } catch (Exception ex) { return await GB5Shared.ResponseStandard.Response.CreateExceptionError(ex, CacheKeyLevel.NOT_REQUIRED, login, ex.Message, 500); } } }