using DXPBLL.Auth; using DXPDAL.Common; using DXPSL.Parameters.Auth; using FastEndpoints; using GB5Shared.DTO.Framework.Enum; using GB5Shared.DTO.Framework.ResponseStandard; namespace DXPSL.Endpoints.Auth; // Anonymous — logout only needs the refresh token being revoked; idempotent by design // (AuthBLL.LogoutAsync no-ops silently if the token is already gone/revoked). public class Logout : Endpoint> { private readonly IAuthBLL _bll; private readonly IDXPSystemContext _systemContext; public Logout(IAuthBLL bll, IDXPSystemContext systemContext) { _bll = bll; _systemContext = systemContext; } public override void Configure() { Post("/DXP/Auth/Logout"); AllowAnonymous(); } public override async Task HandleAsync(LogoutParameters req, CancellationToken ct) { await _bll.LogoutAsync(req.RefreshToken, _systemContext.GetSystemLogin(), ct); await Send.ResponseAsync(new ResponseStandardDTO { Status = GB5Shared.DTO.Framework.Enum.FrameworkEnumDTO.ResponseStatus.Ok, Body = "Logged out." }, cancellation: ct); } }