using EntitlementBLL.Legal; using FastEndpoints; using GB5Shared.Authorization; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; namespace EntitlementSL.Endpoints.Legal; // Internal-staff-only authoring surface (tracker §51.6's own explicit P1 gap, built now as part // of the "experience the flow" pass) — gated the same way as OnboardClient.cs/CreateClient.cs // (Thread 0 §20: GOODBOOKS_ADMIN has no backing JWT scheme, so [MenuRights] + AllowAnonymous() // is the real gate here, not Roles()). Menu-seed migration for "entagree" is a small, separate // follow-up, same as every other [MenuRights] code registered in this module. [MenuRights("entagree", RightOperation.Insert)] public class SaveAgreementType : BaseEndpoint> { private readonly IAgreementAuthoringBLL _AuthoringBLL; public SaveAgreementType(IAgreementAuthoringBLL authoringBLL) => _AuthoringBLL = authoringBLL; public override void Configure() { Post("/Legal/SaveAgreementType"); AllowAnonymous(); } public record Params( [property: FromHeader] string Login, [property: FromBody] Body Body ); public record Body(string TypeCode, string TypeName, bool RequiresIndividualAcceptance); protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { var result = await _AuthoringBLL.EnsureTypeAsync(req.Body.TypeCode, req.Body.TypeName, req.Body.RequiresIndividualAcceptance, loginDTO, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, loginDTO); } }