using EntitlementBLL.Interfaces; using EntitlementDAL.DTOs; using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; using GB5Shared.Authorization; namespace EntitlementSL.Endpoints.ClientProvisioning; // Internal-staff-only — creates a brand-new tenant's identity (MCLIENT + first admin MUSER) // from nothing. Gated via [MenuRights], not a JWT role, matching the Thread 0 §20 convention // (GOODBOOKS_ADMIN has no backing JWT scheme; this uses the same Login-header + MROLEVSMENU // check as every other GB5 module). A menu-seed migration registering "entclientprovisioning" // as a real MMENU row is a small, separate follow-up (Thread 1 §2.2's own §22.2) — not bundled // into this pass. [MenuRights("entclientprovisioning", RightOperation.Insert)] public class CreateClient : BaseEndpoint> { private readonly IClientProvisioningBLL _ClientProvisioningBLL; public CreateClient(IClientProvisioningBLL clientProvisioningBLL) => _ClientProvisioningBLL = clientProvisioningBLL; public override void Configure() { Post("/lic/ClientProvisioning.svc/CreateClient"); AllowAnonymous(); } public record Params( [property: FromHeader] string Login, [property: FromBody] CreateClientRequestDTO CreateClientRequestDTO ); /// NOT_REQUIRED — a one-time creation action, never cached. protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { var result = await _ClientProvisioningBLL.CreateClientAsync(req.CreateClientRequestDTO, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, loginDTO); } }