using System; using System.Threading; using System.Threading.Tasks; using GB5Shared.DTO.Framework.Login; using GB5Shared.Resource.Response; using TMSDAL.CustomCode.Reports; using TMSDAL.DTO.Reports; namespace TMSBLL.Reports { // Backend enforcement for MROLEVSMENU's day/record limits, mirroring // AccountsBLL.AccountReports.AccountReportAccessControlBLL -- a REST caller hitting a TMS report // endpoint directly must not be able to bypass limits the frontend would otherwise enforce. // Lighter than the Accounts version: most TMS reports are point-in-time registers, not // period-ledger reports, so a date range is optional here (DaysLimit is only checked when the // caller actually supplied one), and there is no NOOFREADPERIOD equivalent (that concept is // specific to Accounts' financial-period model). public class TmsReportAccessControlBLL : ITmsReportAccessControlBLL { private readonly ITmsReportAccessControlDAL _dal; public TmsReportAccessControlBLL(ITmsReportAccessControlDAL dal) { _dal = dal; } public async Task EnforceAsync(TmsReportCriteria criteria, int maxResult, int menuId, LoginDTO loginDTO, CancellationToken ct) { var limits = await _dal.GetReportAccessLimits(loginDTO.RoleId, menuId, loginDTO, ct).ConfigureAwait(false); if (limits == null) return; if (limits.DaysLimit > 0 && criteria.FromDate.HasValue && criteria.ToDate.HasValue) { var requestedDays = (criteria.ToDate.Value.Date - criteria.FromDate.Value.Date).TotalDays + 1; if (requestedDays > limits.DaysLimit) throw new InvalidOperationException(ErrorResponse.DaysLimitExceededMessage); } if (limits.RecordsLimit > 0 && maxResult > limits.RecordsLimit) throw new InvalidOperationException(ErrorResponse.RecordsLimitExceededMessage); } } }