using DXPBLL.Auth; using DXPDAL.Common; using DXPSL.Parameters.Auth; using FastEndpoints; using GB5Shared.DTO.Framework.Enum; using GB5Shared.DTO.Framework.ResponseStandard; namespace DXPSL.Endpoints.Auth; // Anonymous by necessity — the whole point of a refresh call is that the access token has // expired. The refresh token itself (opaque, hashed at rest) is the credential here. public class RefreshToken : Endpoint> { private readonly IAuthBLL _bll; private readonly IDXPSystemContext _systemContext; public RefreshToken(IAuthBLL bll, IDXPSystemContext systemContext) { _bll = bll; _systemContext = systemContext; } public override void Configure() { Post("/DXP/Auth/RefreshToken"); AllowAnonymous(); } public override async Task HandleAsync(RefreshTokenParameters req, CancellationToken ct) { try { var tokens = await _bll.RefreshAsync(req.RefreshToken, req.DeviceInfo, _systemContext.GetSystemLogin(), ct); await Send.ResponseAsync(new ResponseStandardDTO { Status = FrameworkEnumDTO.ResponseStatus.Ok, Body = tokens }, cancellation: ct); } catch (InvalidOperationException ex) { await Send.ResponseAsync(new ResponseStandardDTO { Status = FrameworkEnumDTO.ResponseStatus.Failed, ErrorBody = ex.Message }, statusCode: 401, cancellation: ct); } } }