using System.Security.Claims; using SeaHaven.Services.Exceptions; namespace SeaHaven.Services.Helpers { /// Whose work orders the Notification Center covers for the signed-in user. public static class NotificationAudience { // Dispatchers see their own work orders. Roles that already see every dispatcher's // work on the dashboard see the whole account, including work nobody owns yet. public static (string? DispatcherId, bool SeesUnassigned) Resolve(ClaimsPrincipal user) { if (user.IsInRole("Dispatcher")) { var dispatcherId = user.FindFirstValue(ClaimTypes.NameIdentifier); if (string.IsNullOrWhiteSpace(dispatcherId)) throw new WorkOrderBoardValidationException("Forbidden", "Dispatcher identity is required."); return (dispatcherId, false); } if (user.IsInRole("Admin") || user.IsInRole("Manager") || user.IsInRole("Scheduler")) return (null, true); throw new WorkOrderBoardValidationException("Forbidden", "Notifications require an authorized role."); } } }