mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
Reject soft-deleted accounts and stop account-scoped callers from assigning or stealing locations across tenants.
211 lines
7.8 KiB
C#
211 lines
7.8 KiB
C#
using Api.SeaHavenIndustries.DTOs;
|
|
using Api.SeaHavenIndustries.Helper;
|
|
using Data.SeaHavenIndustries;
|
|
using FluentValidation;
|
|
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Http;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.Extensions.Logging;
|
|
using SeaHaven.Services.DTOs;
|
|
using SeaHaven.Services.Interfaces;
|
|
|
|
namespace Api.SeaHavenIndustries.Controllers
|
|
{
|
|
[Authorize]
|
|
[ApiController]
|
|
[Route("api/[controller]")]
|
|
[Route("api/locations")]
|
|
public class LocationController : Controller
|
|
{
|
|
private readonly ILocationService _locationService;
|
|
private readonly ILogger<LocationController> _logger;
|
|
|
|
public LocationController(ILocationService locationService, ILogger<LocationController> logger)
|
|
{
|
|
_locationService = locationService;
|
|
_logger = logger;
|
|
}
|
|
|
|
[HttpGet("sites")]
|
|
public async Task<IActionResult> GetSites(string? search = null)
|
|
{
|
|
var data = await _locationService.GetSiteOptionsAsync(search);
|
|
return Ok(data);
|
|
}
|
|
|
|
[HttpGet("GetLocationList")]
|
|
public async Task<IActionResult> GetLocationList(string? search = "", int page = 1, int pageSize = 10, CancellationToken cancellationToken = default)
|
|
{
|
|
var pagedResult = await _locationService.GetLocationListPagedAsync(page, pageSize, search, cancellationToken);
|
|
|
|
var data = pagedResult.Items.Select(l => new
|
|
{
|
|
Id = l.Id,
|
|
Name = l.Name,
|
|
Title = l.Title,
|
|
Address = l.Address1,
|
|
Address1 = l.Address1,
|
|
Address2 = l.Address2,
|
|
City = l.City,
|
|
State = l.State,
|
|
ZipCode = l.Zip,
|
|
Phone = l.PhoneNumber,
|
|
Contact = (string?)null,
|
|
ContactEmail = l.Email,
|
|
Status = l.Status,
|
|
AccountId = l.AccountId
|
|
});
|
|
|
|
var viewModel = new Pagination_DTO
|
|
{
|
|
Data = data,
|
|
PageNumber = page,
|
|
PageSize = pageSize,
|
|
TotalCount = pagedResult.TotalCount,
|
|
TotalPages = (int)Math.Ceiling(pagedResult.TotalCount / (double)pageSize)
|
|
};
|
|
|
|
return Ok(viewModel);
|
|
}
|
|
|
|
[HttpGet("{id}")]
|
|
public async Task<IActionResult> GetLocationById(int id, CancellationToken cancellationToken)
|
|
{
|
|
var location = await _locationService.GetLocationDetailAsync(id, cancellationToken);
|
|
|
|
if (location == null)
|
|
return NotFound(new Response { Status = "Error", Message = "Location not found" });
|
|
|
|
var result = new
|
|
{
|
|
location.Id,
|
|
location.Name,
|
|
location.Title,
|
|
Address = location.Address1,
|
|
location.Address1,
|
|
location.Address2,
|
|
location.City,
|
|
location.State,
|
|
ZipCode = location.Zip,
|
|
Phone = location.PhoneNumber,
|
|
Contact = (string?)null,
|
|
ContactEmail = location.Email,
|
|
location.Status,
|
|
location.AccountId
|
|
};
|
|
|
|
return Ok(result);
|
|
}
|
|
|
|
[HttpPost]
|
|
public async Task<IActionResult> AddLocation([FromBody] Location_DTO model, CancellationToken cancellationToken)
|
|
{
|
|
try
|
|
{
|
|
await _locationService.CreateLocationFromRequestAsync(MapToCreateRequest(model), User, cancellationToken);
|
|
return Ok(new DataResponse { Message = "Location Created Successfully", Status = "200" });
|
|
}
|
|
catch (ValidationException vex)
|
|
{
|
|
var errors = string.Join(", ", vex.Errors.Select(e => e.ErrorMessage));
|
|
return BadRequest(new Response { Status = "Validation Error", Message = errors });
|
|
}
|
|
catch (UnauthorizedAccessException)
|
|
{
|
|
return StatusCode(StatusCodes.Status403Forbidden, new Response { Status = "Error", Message = "You are not allowed to assign this account." });
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
|
|
}
|
|
}
|
|
|
|
[HttpPut("{id}")]
|
|
public async Task<IActionResult> EditLocation(int id, [FromBody] EditLocation_DTO model, CancellationToken cancellationToken)
|
|
{
|
|
try
|
|
{
|
|
await _locationService.UpdateLocationFromRequestAsync(id, MapToUpdateRequest(model), User, cancellationToken);
|
|
return Ok(new DataResponse { Message = "Location Updated Successfully", Status = "200" });
|
|
}
|
|
catch (ValidationException vex)
|
|
{
|
|
var errors = string.Join(", ", vex.Errors.Select(e => e.ErrorMessage));
|
|
return BadRequest(new Response { Status = "Validation Error", Message = errors });
|
|
}
|
|
catch (UnauthorizedAccessException)
|
|
{
|
|
return StatusCode(StatusCodes.Status403Forbidden, new Response { Status = "Error", Message = "You are not allowed to assign this account." });
|
|
}
|
|
catch (KeyNotFoundException)
|
|
{
|
|
return NotFound(new Response { Status = "Error", Message = "Location not found" });
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
|
|
}
|
|
}
|
|
|
|
[HttpDelete("{id}")]
|
|
public async Task<IActionResult> DeleteLocation(int id, CancellationToken cancellationToken)
|
|
{
|
|
try
|
|
{
|
|
var found = await _locationService.DeleteLocationByIdAsync(id, cancellationToken);
|
|
if (!found)
|
|
return NotFound(new Response { Status = "Error", Message = "Location not found" });
|
|
|
|
return Ok(new DataResponse { Message = "Location Deleted Successfully", Status = "200" });
|
|
}
|
|
catch (KeyNotFoundException)
|
|
{
|
|
return NotFound(new Response { Status = "Error", Message = "Location not found" });
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return StatusCode(500, new Response { Status = "Error", Message = _logger.Sanitize(ex) });
|
|
}
|
|
}
|
|
|
|
[HttpGet("DeleteLocation")]
|
|
public async Task<IActionResult> DeleteLocationByQuery(int id, CancellationToken cancellationToken)
|
|
{
|
|
return await DeleteLocation(id, cancellationToken);
|
|
}
|
|
|
|
private static LocationCreateRequestDTO MapToCreateRequest(Location_DTO model)
|
|
{
|
|
return new LocationCreateRequestDTO
|
|
{
|
|
Name = model.Name,
|
|
Title = model.Title,
|
|
Address = model.Address,
|
|
City = model.City,
|
|
State = model.State,
|
|
ZipCode = model.ZipCode,
|
|
Phone = model.Phone,
|
|
ContactEmail = model.ContactEmail,
|
|
Status = model.Status,
|
|
AccountId = model.GetAccountId()
|
|
};
|
|
}
|
|
|
|
private static LocationUpdateRequestDTO MapToUpdateRequest(EditLocation_DTO model)
|
|
{
|
|
return new LocationUpdateRequestDTO
|
|
{
|
|
Name = model.Name,
|
|
Title = model.Title,
|
|
Address = model.Address,
|
|
City = model.City,
|
|
State = model.State,
|
|
ZipCode = model.ZipCode,
|
|
Phone = model.Phone,
|
|
ContactEmail = model.ContactEmail,
|
|
Status = model.Status,
|
|
AccountId = model.GetAccountId()
|
|
};
|
|
}
|
|
}
|
|
}
|