namespace RecruitmentDAL.DTO.InternalMobility { // Request shape for POST /InternalMobility/SubmitInternalApplication — the internally- // authenticated-context counterpart to RecruitmentDAL.DTO.Career.CareerApplicationSubmissionDTO // (Phase 6, internal mobility). Deliberately narrower than the public career-site submission: // no FirstName/LastName/Email/Phone/ConsentGiven are accepted from the client — those are // resolved server-side from the employee's own MEMPLOYEE record by // RecruitmentBLL.CandidateConversion.IEmployeeToInternalCandidateBLL, not re-entered. // // EmployeeId is the applying employee's identity. This module has no working Roles()/session // auth (see CLAUDE.md's "AllowAnonymous() everywhere" note), so — same as every other // AllowAnonymous endpoint in this repo — EmployeeId is taken from the request body rather // than derived from an authenticated principal; RecruitmentBLL.InternalMobility. // InternalMobilityBLL.SubmitInternalApplication only ever creates/links a Candidate/ // Application row against whichever EmployeeId is supplied, and never accepts a raw // Candidate/Application/TenantId/audit field from the client (identical posture to // CareerApplicationSubmissionDTO). The route itself is what keeps this off the public // career-site surface — see RecruitmentBLL.Career.CareerBLL.SubmitApplication's own // InternalEmployee-CandidateType guard for the other half of that separation. public class InternalApplicationSubmissionDTO { public int EmployeeId { get; set; } public int JobRequisitionId { get; set; } } }