using EntitlementBLL.Interfaces; using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; namespace EntitlementSL.Endpoints.Subscription; // System-to-system caller (SqlWorkbench's rollout/provisioning gating, tracker §40) — no // MROLEVSMENU grant is realistically available to an automated caller, so this follows the // established convention for exactly this situation (e.g. SwSL's own ~80 endpoints called by // EntitlementBLL.Onboarding.SqlWorkbenchClient): AllowAnonymous() with [MenuRights] commented // out, relying on network/deployment-boundary trust, not a human role check. //[MenuRights("entsnapshot", RightOperation.View)] public class GetClientEntitlementSnapshot : BaseEndpoint> { private readonly IClientEntitlementSnapshotBLL _SnapshotBLL; public GetClientEntitlementSnapshot(IClientEntitlementSnapshotBLL snapshotBLL) => _SnapshotBLL = snapshotBLL; public override void Configure() { Get("/lic/Subscription.svc/GetClientEntitlementSnapshot"); AllowAnonymous(); } public record Params( [property: FromHeader] string Login, [property: QueryParam] int ClientId ); // Not cached — this feeds live gating decisions (rollout campaign target resolution); // subscription/support/feature state must always be read live, never stale. protected override string? GetCacheKey(Params req, LoginDTO loginDTO) => null; protected override async Task> ExecuteAsync(Params req, LoginDTO loginDTO, CancellationToken ct) { var result = await _SnapshotBLL.GetSnapshotAsync(req.ClientId, ct).ConfigureAwait(false); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, loginDTO); } }