using EntitlementBLL.Demo; using FastEndpoints; using GB5Shared.Authorization; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; namespace EntitlementSL.Endpoints.Demo; // Internal (sales/CS rep) action — checks out an instant-access Pooled demo for an already- // registered prospect (RegisterProspect.cs must be called first). Gated the same way every other // internal GOODBOOKS_ADMIN-only action in this module is (Thread 0 §20's [MenuRights] // convention), not a JWT role. [MenuRights("entdemo", RightOperation.Insert)] public class CheckOutPooledSession : BaseEndpoint> { private readonly IDemoSessionBLL _DemoSessionBLL; public CheckOutPooledSession(IDemoSessionBLL demoSessionBLL) => _DemoSessionBLL = demoSessionBLL; public override void Configure() { Post("/Demo/CheckOutPooledSession"); AllowAnonymous(); } public record Params( [property: FromHeader] string Login, [property: FromBody] CheckOutPooledSessionRequest CheckOutPooledSessionRequest ); protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { // Tracker §52 — OwnerUserId is always the REAL calling staff member (from the verified // Login header), never trusted from the request body — a staff member with entdemo // rights could otherwise claim a different colleague as the engagement owner. req.CheckOutPooledSessionRequest.OwnerUserId = loginDTO.UserId; var result = await _DemoSessionBLL.CheckOutPooledSessionAsync(req.CheckOutPooledSessionRequest, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, loginDTO); } }