using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using RecruitmentBLL.CandidatePortal; using RecruitmentSL.Common; using ErrorResponse = GB5Shared.Resource.Response.ErrorResponse; using static GB5Shared.GB5Constant.Constant; namespace RecruitmentSL.EndPoints.CandidatePortal { // CandidatePortal-scheme-protected — the calling candidate's identity comes ONLY from the // verified JWT claims (CandidatePortalCallerContext), never from a client-supplied id, so a // candidate can never read another candidate's application history. public class MyApplications : BaseEndpoint> { private const string CandidatePortalScheme = "CandidatePortal"; private readonly ICandidatePortalBLL _BLL; public MyApplications(ICandidatePortalBLL bll) => _BLL = bll; public record Params([property: FromHeader] string Login); public override void Configure() { Get("/CandidatePortal/MyApplications"); AuthSchemes(CandidatePortalScheme); } // Status changes push in real time elsewhere in this module (RecruitmentHub) — skip // caching here so a candidate always sees their latest pipeline stage immediately. protected override string? GetCacheKey(Params req, LoginDTO login) => null; protected override async Task> ExecuteAsync( Params req, LoginDTO login, CancellationToken ct) { var caller = CandidatePortalCallerContext.FromClaims(HttpContext.User.Claims); if (caller.CandidateId <= 0) return await GB5Shared.ResponseStandard.Response.CreateErrorResponse( ErrorResponse.AccessDeniedMessage, CacheKeyLevel.NOT_REQUIRED, login, statusCode: 403); var result = await _BLL.GetMyApplicationsAsync(caller.CandidateId, login, ct).ConfigureAwait(false); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse( result, CacheKeyLevel.NOT_REQUIRED, login); } } }