using EntitlementBLL.Demo; using FastEndpoints; using GB5Shared.Authorization; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; namespace EntitlementSL.Endpoints.Demo; // approvedById is deliberately read from the authenticated Login header's own UserId, never a // caller-supplied query param — DemoSessionBLL.ApproveExtensionAsync itself enforces that only // the session's own OwnerUserId may approve (tracker §49 Decision 5); trusting a spoofable // query-param UserId here would defeat that check entirely. [MenuRights("entdemo", RightOperation.Update)] public class ApproveDemoExtension : BaseEndpoint> { private readonly IDemoSessionBLL _DemoSessionBLL; public ApproveDemoExtension(IDemoSessionBLL demoSessionBLL) => _DemoSessionBLL = demoSessionBLL; public override void Configure() { Post("/Demo/ApproveDemoExtension"); AllowAnonymous(); } public record Params( [property: FromHeader] string Login, [property: QueryParam] int DemoSessionId, [property: QueryParam] DateTime NewExpiresOn); protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { await _DemoSessionBLL.ApproveExtensionAsync(req.DemoSessionId, loginDTO.UserId, req.NewExpiresOn, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse( "Extension approved.", CacheKeyLevel.NOT_REQUIRED, loginDTO); } }