using EntitlementBLL.Interfaces; using EntitlementDAL.DTOs; using EntitlementDAL.Interfaces; using GB5Shared.DTO.Framework.Login; using GB5Shared.GenerateAutoNumber; using GB5Shared.QueryExecutor; using GB5Shared.Resource.Response; using GB5Shared.Telemetry; using static GB5Shared.GB5Constant.Constant; namespace EntitlementBLL.Implementations; public class FeatureBLL : IFeatureBLL { private readonly IFeatureDAL _FeatureDAL; private readonly AutoNumber _AutoNumber; private readonly IQueryExecutor _QueryExecutor; public FeatureBLL(IFeatureDAL featureDAL, AutoNumber autoNumber, IQueryExecutor queryExecutor) { _FeatureDAL = featureDAL; _AutoNumber = autoNumber; _QueryExecutor = queryExecutor; } public async Task GetAsync(int featureId, LoginDTO login, CancellationToken ct) => await _FeatureDAL.GetByIdAsync(featureId, login, ct).ConfigureAwait(false); public async Task> GetListAsync(bool isAdminAuthenticated, bool? isExposedToPie, LoginDTO login, CancellationToken ct) { // Defense in depth — never trust the caller-supplied flag alone (an anonymous caller // could pass isExposedToPie=false or omit it entirely and still must never receive the // full admin catalog). Only a verified GOODBOOKS_ADMIN caller can ever get the unfiltered // list; an admin may still opt into the PIE-only subset by passing isExposedToPie=true. bool pieOnly = isAdminAuthenticated ? isExposedToPie == true : true; return await _FeatureDAL.GetListFilteredAsync(pieOnly, login, ct).ConfigureAwait(false); } public async Task SaveAsync(FeatureDTO dto, LoginDTO login, CancellationToken ct) { if (dto is null) throw new ArgumentNullException(nameof(dto)); if (string.IsNullOrWhiteSpace(dto.FeatureCode)) throw new ArgumentException("FeatureCode is required.", nameof(dto)); if (string.IsNullOrWhiteSpace(dto.FeatureName)) throw new ArgumentException("FeatureName is required.", nameof(dto)); bool isNew = dto.FeatureId == 0; var tx = await _QueryExecutor.BeginTransactionAsync(login).ConfigureAwait(false); try { GB5Trace.Step("validate-entitlement-feature", new { dto.FeatureId, isNew }); var now = DateTime.UtcNow; if (isNew) { var auto = await _AutoNumber.GetNumberAsync(1, AUTONUMBERCONSTANT.ENTITLEMENTFEATURE, login).ConfigureAwait(false); dto.FeatureId = auto.StartNumber; dto.CreatedById = login.UserId; dto.CreatedOn = now; } dto.ModifiedById = login.UserId; dto.ModifiedOn = now; GB5Trace.Step("save-entitlement-feature", new { dto.FeatureId, isNew }); if (isNew) await _FeatureDAL.SaveAsync(dto, login, tx, ct).ConfigureAwait(false); else await _FeatureDAL.UpdateAsync(dto, login, tx, ct).ConfigureAwait(false); await _QueryExecutor.CommitAsync(tx).ConfigureAwait(false); return isNew ? $"{SuccessResponse.SaveSuccessMessage} {dto.FeatureId}" : SuccessResponse.UpdateSuccess; } catch (Exception ex) { await _QueryExecutor.RollbackAsync(tx).ConfigureAwait(false); GB5Trace.MarkFailed("save-entitlement-feature-failed", ex); throw; } } public async Task DeleteAsync(int featureId, LoginDTO login, CancellationToken ct) { var tx = await _QueryExecutor.BeginTransactionAsync(login).ConfigureAwait(false); try { GB5Trace.Step("delete-entitlement-feature", new { featureId }); await _FeatureDAL.DeleteAsync(featureId, login, tx, ct).ConfigureAwait(false); await _QueryExecutor.CommitAsync(tx).ConfigureAwait(false); return SuccessResponse.DeleteSuccessMessage; } catch (Exception ex) { await _QueryExecutor.RollbackAsync(tx).ConfigureAwait(false); GB5Trace.MarkFailed("delete-entitlement-feature-failed", ex); throw; } } }