namespace RecruitmentDAL.DTO.Career { // Request shape for POST /Career/SubmitApplication — the public apply-flow body. Deliberately // narrow: a career-site applicant supplies only their own identity/contact details, the resume // reference produced by a prior, separate upload through the generic Attachment mechanism // (see GB5Shared.Attachment.IAttachmentUploadService — this DTO just carries the resulting // reference string, it does not accept a file stream itself), which JobRequisition they are // applying to, and explicit GDPR consent. No CandidateId/ApplicationId/CurrentStageId/ // TenantId/audit fields are accepted from the client — those are resolved/stamped server-side // in RecruitmentBLL.Career.CareerBLL.SubmitApplication. public class CareerApplicationSubmissionDTO { public string FirstName { get; set; } public string LastName { get; set; } public string Email { get; set; } public string Phone { get; set; } // Reference (URL or resolvable attachment key) produced by a prior call to the generic // Attachment upload mechanism — not a raw file upload on this endpoint. public string ResumeUrl { get; set; } public int JobRequisitionId { get; set; } // GDPR — must be explicitly true or the submission is rejected with a validation error; // never silently defaulted. See Candidate.ConsentGiven/ConsentDate. public bool ConsentGiven { get; set; } } }