using FLSBLL.Respondent; using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using static GB5Shared.GB5Constant.Constant; namespace FLSSL.Endpoints.Respondent; // Authenticated "my own pending items" — unlike GetFlsPendingForms (which trusts a caller-supplied // RespondentType/RespondentRefId, a real cross-lookup gap kept only for the legitimate // manager/trainer viewing-a-specific-learner case), this endpoint always derives identity from the // Login header itself. RespondentType=0 (Employee), RespondentRefId=login.UserId — LoginDTO.UserId // is numerically the same as MEMPLOYEE.EMPLOYEEID (see PayRollDAL/Query/Employee/EmployeeQB.cs's // MUSER.USERID = MEMPLOYEE.EMPLOYEEID join), the same convention ESS self-service screens already use. public class GetMyPendingForms : BaseEndpoint> { private readonly IFlsRespondentBLL _bll; public GetMyPendingForms(IFlsRespondentBLL bll) => _bll = bll; public override void Configure() { Get("/Respondent/GetMyPendingForms"); AllowAnonymous(); } public record Params([property: FromHeader] string Login); protected override string? GetCacheKey(Params req, LoginDTO login) => $"MyFlsPendingForms:{login.ClientId}:{login.UserId}"; protected override async Task> ExecuteAsync( Params req, LoginDTO login, CancellationToken ct) { try { var result = await _bll.GetPendingFormsAsync(respondentType: 0, respondentRefId: login.UserId, login, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse( result, CacheKeyLevel.USER_LEVEL, login); } catch (Exception ex) { return await GB5Shared.ResponseStandard.Response.CreateExceptionError( ex, CacheKeyLevel.NOT_REQUIRED, login, ex.Message, 500); } } }