using FastEndpoints; using GB5Shared.DTO.Framework.Login; using GB5Shared.DTO.Framework.ResponseStandard; using GB5Shared.FastEndPoint; using TMSBLL.Certificate; using static GB5Shared.GB5Constant.Constant; namespace TMSSL.EndPoints.Certificate { // Public endpoint — no Login header required. The opaque token link is the entire // access-control mechanism, mirroring FLS's GetRespondentByToken. public class VerifyCertificate : BaseEndpoint> { private readonly ITrainingCertificateBLL _TrainingCertificateBLL; public VerifyCertificate(ITrainingCertificateBLL trainingCertificateBLL) { _TrainingCertificateBLL = trainingCertificateBLL; } public override void Configure() { Get("/Certificate/VerifyCertificate"); AllowAnonymous(); } public record Parameters( [property: QueryParam] string Token, // Tenant DB name, embedded in the QR-code URL by CertificatePdfPipeline.BuildVerifyUrl — // a scanned link carries no Login header/session, so this is the only way the endpoint // can know which tenant's TTRAININGCERTIFICATE to query. [property: QueryParam] string? Db ); protected override string? GetCacheKey(Parameters req, LoginDTO login) => null; protected override async Task> ExecuteAsync(Parameters req, LoginDTO login, CancellationToken ct) { try { var result = await _TrainingCertificateBLL.VerifyByToken(req.Token, req.Db, ct); return await GB5Shared.ResponseStandard.Response.CreateSuccessResponse(result, CacheKeyLevel.NOT_REQUIRED, login); } catch (Exception ex) { return await GB5Shared.ResponseStandard.Response.CreateExceptionError(ex, CacheKeyLevel.NOT_REQUIRED, login, ex.Message, 500); } } } }