using DXPBLL.Auth; using DXPDAL.Auth; using DXPDAL.Common; using DXPSL.Common; using GB5Shared.DTO.Framework.Enum; using GB5Shared.DTO.Framework.ResponseStandard; namespace DXPSL.Endpoints.Auth; // NOTE: same RBAC caveat as SaveParty/LinkPartyToTenant — admin/onboarding-gated in a real // deployment; open to any authenticated DXP user for Phase 1.1 testability. public class GrantUserPartyRole : DXPBaseEndpoint> { private readonly IAuthBLL _bll; private readonly IDXPSystemContext _systemContext; public GrantUserPartyRole(IAuthBLL bll, IDXPSystemContext systemContext) { _bll = bll; _systemContext = systemContext; } public override void Configure() => Post("/DXP/Auth/GrantUserPartyRole"); protected override async Task> ExecuteAsync( UserPartyRoleDTO req, DXPCallerContext caller, CancellationToken ct) { var message = await _bll.GrantUserPartyRoleAsync(req, _systemContext.GetSystemLogin(caller.DxpUserId), ct); return new ResponseStandardDTO { Status = FrameworkEnumDTO.ResponseStatus.Ok, Body = message }; } }