namespace EntitlementBLL.Options;
/// Which environment a ClientProvisioning ChangeRequest waits for before
/// ClientOnboardingOrchestratorBLL continues to subscription creation + reference-data sync.
/// Starts as a config value per the user's own confirmed direction (§31.1 Phase 3): begin
/// human-approve for simplicity, move to auto-approve later once trusted — a mode switch,
/// not a rewrite.
public enum OnboardingApprovalMode : byte
{
/// A GOODBOOKS_ADMIN approves the CR via SqlWorkbench's own UI/API — the
/// orchestrator only submits and then waits for the "sqlworkbench.changerequest.executed"
/// event. No system credential is needed for this mode.
HumanApprove = 0,
/// The orchestrator calls SqlWorkbench's own ApproveChangeRequest immediately
/// after submitting, using a configured system-account LoginDTO. Not yet exercised live —
/// flip only once HumanApprove mode has been proven in a real environment.
AutoApprove = 1
}
///
/// Config for the client-onboarding orchestrator (Thread 6/§31 Phase 3): which real
/// MSWDBSERVER/MSWDBMODEL a new client's database gets created on, how CR approval is
/// gated, and (optionally) which pre-registered reference-data sync job to trigger once the
/// database is live. Bound from "Entitlement:Onboarding".
///
public class OnboardingOptions
{
public const string SectionName = "Entitlement:Onboarding";
public OnboardingApprovalMode ApprovalMode { get; set; } = OnboardingApprovalMode.HumanApprove;
/// SW.MSWDBSERVER.DBSERVERID a new client's database is created on. Resolved
/// 2026-08-05 (tracker §31.11) to 1 — the real MSWDBSERVER row for 217.216.78.142,
/// registered and verified live in §31.7. Exact per-client/per-tier server granularity
/// (i.e. whether every client shares this one row) is still an open business decision
/// (§31.3/§31.4) — this single configured default holds until that's resolved. Default
/// here is -1 (throws in StartOnboardingAsync) only as a safety net for an environment
/// where appsettings.json hasn't been filled in — the real environment's value lives in
/// EntitlementSL/appsettings.json, not this class.
public int DefaultDbServerId { get; set; } = -1;
/// SW.MSWDBMODEL.DBMODELID identifying which baseline UpgradePackage a new
/// client's database is provisioned from (scripts-mode). Resolved 2026-08-05 (tracker
/// §31.11) to 1 — the real "ENTITLEMENT_BASELINE_V1" row loaded and verified live in
/// §31.8/§31.10 (a genuine, live-tested Entitlement-schema-only baseline — see that
/// section's own scope caveat: it assumes the base Framework/legacy schema already
/// exists on the target, it does not create one from nothing).
public int DefaultDbModelId { get; set; } = -1;
/// SW.MSWUPGRADEPACKAGE.PACKAGEID applied to the freshly-created database.
/// Resolved 2026-08-05 (tracker §31.11) to 1 — "ENTITLEMENT_BASELINE_V1_PKG", the real
/// Released package containing the 8 baseline DdlScripts, live-verified end-to-end
/// against a real created database (EntTestDb1) in §31.10.1.
public int DefaultUpgradePackageId { get; set; } = -1;
/// FrameworkSL TDSYNCJOB.SYNCJOBID to trigger once the client's database is
/// live, seeding it with central reference data. Null = skip the sync-trigger step
/// entirely and log why — no standard "new client baseline" dataset has been registered
/// yet (§31.1 Phase 2: which of the ~15 "every client needs this" tables, and their
/// seed-once-vs-recurring cadence, are still open per-table business decisions, §31.2).
/// Deliberately NOT auto-creating a new DBOBJECT/MDATASET/DBINSTANCE/TDSYNCJOB per
/// client here — that would bake in table/cadence choices nobody has actually made yet.
public int? DefaultOnboardingSyncJobId { get; set; }
/// MENTITLEMENTPLAN.PLANID granted to every self-service trial signup
/// (QuickStart Step 4 / StartSelfServiceTrialAsync) — deliberately NOT caller-supplied,
/// unlike StartOnboardingAsync's PlanId, since an anonymous visitor could otherwise
/// request any paid tier for free. -1 = not configured; StartSelfServiceTrialAsync
/// throws rather than silently picking an arbitrary plan.
public int DefaultTrialPlanId { get; set; } = -1;
/// Central Keycloak host (e.g. "https://ssodev.goodbookserp.in") a new SaaS tenant's
/// realm gets provisioned on and MSERVERCONFIG.KEYCLOAKHOST is set to — GB5 Repo-Wide
/// Authentication Hardening plan, "Entitlement provisioning wiring" phase. Null/empty =
/// skip Keycloak provisioning entirely and log why, same "best-effort, off until configured"
/// convention as DefaultOnboardingSyncJobId above — never fails an otherwise-successful
/// onboarding. Only tenants with DeploymentType=SaaS get auto-provisioned; OnPrem/BYOCloud/
/// Hybrid stay AuthMode=Native (the default) unless a human deliberately configures Keycloak
/// for them later — Keycloak is optional per deployment, not assumed.
public string? KeycloakHost { get; set; }
/// Redirect URI template for the new tenant's auto-provisioned GB5WEB-equivalent
/// Keycloak client — "{realm}" is replaced with the new realm name (the tenant's own
/// ConnectionName). E.g. "https://{realm}.goodbookserp.in/*" for a per-tenant subdomain
/// scheme, or a single fixed FE origin if every SaaS tenant shares one FE domain. Only used
/// when KeycloakHost above is configured.
public string? KeycloakClientRedirectUriPattern { get; set; }
}