mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-05 21:12:11 +00:00
Uplift evidence uploads now share the work-order photo limit and the RequestUplifts check used when creating an uplift. Co-authored-by: Arthur Bassi <bassi-arthurr@users.noreply.github.com>
42 lines
1.6 KiB
C#
42 lines
1.6 KiB
C#
using System.Security.Claims;
|
|
using SeaHaven.DataServices.Interfaces;
|
|
using SeaHaven.Services.Constants;
|
|
using SeaHaven.Services.DTOs;
|
|
using SeaHaven.Services.Interfaces;
|
|
|
|
namespace SeaHaven.Services.Helpers
|
|
{
|
|
/// <summary>
|
|
/// Shared gate for creating an uplift and uploading its evidence. Both paths load the
|
|
/// caller's database role and overrides, then require <see cref="TeamPermissionKeys.RequestUplifts"/>.
|
|
/// </summary>
|
|
public static class WorkOrderUpliftRequestAuthorization
|
|
{
|
|
public static async Task EnsureCanRequestUpliftAsync(
|
|
ITeamPermissionOverrideDataService permissionUsers,
|
|
ITeamPermissionPolicy permissionPolicy,
|
|
ClaimsPrincipal user,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
var userId = user.FindFirstValue(ClaimTypes.NameIdentifier);
|
|
var permissionUser = string.IsNullOrWhiteSpace(userId)
|
|
? null
|
|
: await permissionUsers.GetUserAsync(userId, cancellationToken);
|
|
|
|
if (permissionUser is null)
|
|
{
|
|
throw new UpliftForbiddenException(
|
|
UpliftForbiddenException.RequestUpliftsDeniedMessage);
|
|
}
|
|
|
|
if (!permissionPolicy.IsAllowed(
|
|
permissionUser.RoleName,
|
|
TeamPermissionKeys.RequestUplifts,
|
|
permissionUser.Overrides))
|
|
{
|
|
throw new UpliftForbiddenException(
|
|
UpliftForbiddenException.RequestUpliftsDeniedMessage);
|
|
}
|
|
}
|
|
}
|
|
}
|