using EntitlementBLL.Auth; using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using GB5Shared.Resource.Response; using static GB5Shared.GB5Constant.Constant; using GB5Shared.Authorization; namespace EntitlementSL.Endpoints.ClientAuth; // GOODBOOKS_ADMIN-only: today's only unlock path for a client user whose account was locked by // ClientAuthBLL.LoginAsync's failed-login threshold (see Login.cs / ClientAccountLockoutOptions). // No self-service or automatic/timed unlock exists yet — kept deliberately proportionate to what // this item needs: a manual admin action, not a full account-recovery flow. Reused generically for // any of the three MENTITLEMENTCLIENTUSER.STATUS values (Active/Locked/Deleted), not just // unlocking, since one small endpoint covers the whole "admin sets status directly" capability. // Same standard BaseEndpoint + Roles() pattern as CreateClientAdmin.cs — the caller here is an // internal ERP admin via the existing internal auth scheme, not a client-jwt caller. [MenuRights("entdashboard", RightOperation.Update)] public class SetClientUserStatus : BaseEndpoint> { private readonly IClientAuthBLL _ClientAuthBLL; public SetClientUserStatus(IClientAuthBLL clientAuthBLL) => _ClientAuthBLL = clientAuthBLL; public override void Configure() { Post("/lic/ClientAuth.svc/SetClientUserStatus"); AllowAnonymous(); } // Status: 1=Active 2=Locked 3=Deleted (MENTITLEMENTCLIENTUSER.STATUS) public record Body(int ClientUserId, byte Status); public record Params( [property: FromHeader] string Login, [property: FromBody] Body RequestBody ); protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { await _ClientAuthBLL.SetClientUserStatusAsync(req.RequestBody.ClientUserId, req.RequestBody.Status, loginDTO, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(SuccessResponse.UpdateSuccess, CacheKeyLevel.NOT_REQUIRED, loginDTO); } }