using EntitlementBLL.Demo; using FastEndpoints; using GB5Shared.Authorization; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; namespace EntitlementSL.Endpoints.Demo; // Internal (sales/CS rep) action โ€” provisions a real, dedicated physical database for an // already-registered prospect (reuses the full onboarding pipeline). Takes a few minutes; the // caller polls GetProvisioningJob/GetDemoSession for status, same pattern as OnboardClient.cs. [MenuRights("entdemo", RightOperation.Insert)] public class StartDedicatedSession : BaseEndpoint> { private readonly IDemoSessionBLL _DemoSessionBLL; public StartDedicatedSession(IDemoSessionBLL demoSessionBLL) => _DemoSessionBLL = demoSessionBLL; public override void Configure() { Post("/Demo/StartDedicatedSession"); AllowAnonymous(); } public record Params( [property: FromHeader] string Login, [property: FromBody] StartDedicatedSessionRequest StartDedicatedSessionRequest ); protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { // Tracker ยง52 โ€” OwnerUserId is always the REAL calling staff member (from the verified // Login header), never trusted from the request body โ€” a staff member with entdemo // rights could otherwise claim a different colleague as the engagement owner. req.StartDedicatedSessionRequest.OwnerUserId = loginDTO.UserId; var result = await _DemoSessionBLL.StartDedicatedSessionAsync(req.StartDedicatedSessionRequest, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, loginDTO); } }