using EntitlementBLL.Legal; using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; namespace EntitlementSL.Endpoints.Legal; // Genuinely public/anonymous — a prospect needs this bundle BEFORE they've created any account, // same posture as SelfProvisionTrial.cs (§50/§51). Read-only, no state mutation, so no rate-limit // tier of its own is needed the way SelfProvisionTrial's own creation call has. public class GetApplicableAgreements : BaseEndpoint> { private readonly IAgreementConsentProvider _Provider; public GetApplicableAgreements(IAgreementConsentProvider provider) => _Provider = provider; public override void Configure() { Get("/Legal/GetApplicableAgreements"); AllowAnonymous(); } public record Params( [property: FromHeader] string Login, [property: QueryParam] string JurisdictionCode, [property: QueryParam] string[] AgreementTypeCodes ); /// CLIENT_LEVEL would be wrong here (no client exists yet) — jurisdiction+type-code /// combination is the only real cache dimension, and this content changes rarely (only on a /// new Publish), so a short OVERALL-style key is safe; kept NOT_REQUIRED for now since this /// mechanism is still Phase 0/placeholder content, not yet worth tuning. protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { var result = await _Provider.GetApplicableAgreementsAsync(req.JurisdictionCode ?? string.Empty, req.AgreementTypeCodes ?? Array.Empty(), loginDTO, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, loginDTO); } }