using EntitlementBLL.Auth; using EntitlementBLL.Interfaces; using EntitlementSL.Common; using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using ErrorResponse = GB5Shared.Resource.Response.ErrorResponse; using static GB5Shared.GB5Constant.Constant; namespace EntitlementSL.Endpoints.ChangeRequest; // Any authenticated client caller (admin or user) can see their own client's request history/status // — scoped to the caller's OWN ClientId from verified JWT claims, never from a query parameter. public class GetMyRequests : BaseEndpoint> { private const string ClientJwtSchemeName = "ClientJwtBearer"; private readonly IChangeRequestBLL _ChangeRequestBLL; public GetMyRequests(IChangeRequestBLL changeRequestBLL) => _ChangeRequestBLL = changeRequestBLL; public override void Configure() { Get("/lic/ChangeRequest.svc/GetMyRequests"); AuthSchemes(ClientJwtSchemeName); Roles(ClientRoleCodes.ClientAdmin, ClientRoleCodes.ClientUser); } public record Params( [property: FromHeader] string Login, [property: QueryParam] int RequestStatus = -1, [property: QueryParam] int Page = 1, [property: QueryParam] int PageSize = 20 ); protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { var caller = ClientCallerContext.FromClaims(HttpContext.User.Claims); if (caller.ClientId <= 0) return await GB5Shared.ResponseStandard.Response.CreateErrorResponse( ErrorResponse.AccessDeniedMessage, CacheKeyLevel.NOT_REQUIRED, loginDTO, statusCode: 403); var result = await _ChangeRequestBLL.GetChangeRequestListAsync(caller.ClientId, req.RequestStatus, req.Page, req.PageSize, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, loginDTO); } }