proposal-system/api/src/ProposalSystem.Api/Controllers/UsersController.cs
Adam Moussa d2e12d3940 Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00

65 lines
2.1 KiB
C#

using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using Microsoft.EntityFrameworkCore;
using ProposalSystem.Application.DTOs;
using ProposalSystem.Application.Interfaces;
using ProposalSystem.Domain.Entities;
using ProposalSystem.Infrastructure.Data;
namespace ProposalSystem.Api.Controllers;
[ApiController]
[Route("api/users")]
[Authorize]
public class UsersController : ControllerBase
{
private readonly ProposalDbContext _db;
private readonly ICurrentUserService _currentUser;
private readonly IAuditService _audit;
public UsersController(ProposalDbContext db, ICurrentUserService currentUser, IAuditService audit)
{
_db = db;
_currentUser = currentUser;
_audit = audit;
}
[HttpGet("me")]
public async Task<ActionResult<UserProfileResponse>> GetMe(CancellationToken ct)
{
var user = await _db.Users
.FirstOrDefaultAsync(u => u.Id == _currentUser.UserId, ct);
if (user == null) return NotFound();
return Ok(new UserProfileResponse(user.Id, user.Email, user.DisplayName, user.Role));
}
[HttpGet]
[Authorize(Roles = "sysadmins")]
public async Task<ActionResult<IReadOnlyList<UserResponse>>> GetAll(CancellationToken ct)
{
var users = await _db.Users
.OrderBy(u => u.DisplayName)
.Select(u => new UserResponse(u.Id, u.Email, u.DisplayName, u.Role, u.IsActive, u.CreatedAt))
.ToListAsync(ct);
return Ok(users);
}
[HttpPut("{id:guid}/role")]
[Authorize(Roles = "sysadmins")]
public async Task<IActionResult> UpdateRole(Guid id, [FromBody] UpdateUserRoleRequest request, CancellationToken ct)
{
var user = await _db.Users.FindAsync(new object[] { id }, ct);
if (user == null) return NotFound();
user.Role = request.Role;
user.UpdatedAt = DateTime.UtcNow;
await _db.SaveChangesAsync(ct);
await _audit.LogAsync(AuditAction.UpdateRole, null, $"User {user.Email} role changed to {request.Role}", ct);
return NoContent();
}
}