mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 16:33:12 +00:00
Replace all hardcoded credentials with configuration-injected values:
- SQL Server connection strings -> ${CONNECTION_STRING} env-var placeholders (4 appsettings files)
- SendGrid API keys -> ${SENDGRID_API_KEY} (incl. commented copies in SendMessage.cs)
- JWT signing secret -> ${JWT_SECRET} (3 appsettings files)
- AWS access key pair in UploadFileHp.cs -> DI-injected IAmazonS3 (SDK default credential chain)
- Google Maps API keys in App.razor / Home.razor -> IConfiguration lookup
- Legacy SMTP credentials in SendMessage.cs comments -> placeholders
Add .env.example documenting required environment variables and a
Configuration & Secrets section in BACKEND_ARCHITECTURE.md.
All exposed credentials were rotated 2026-06-05 prior to this scrub.
Source: github-audit-report.md Criticals 1-2 (Agent A4).
Verified: dotnet build 0 errors; secret-pattern grep clean.
109 lines
4.4 KiB
C#
109 lines
4.4 KiB
C#
using System.Net.Mail;
|
|
using System.Net;
|
|
using Data.SeaHavenIndustries;
|
|
using Microsoft.AspNetCore.Identity;
|
|
using Microsoft.Extensions.Options;
|
|
using System.Configuration;
|
|
using Humanizer.Bytes;
|
|
using SendGrid;
|
|
using SendGrid.Helpers.Mail;
|
|
|
|
namespace SeaHavenIndustries.Helper
|
|
{
|
|
public class SendMessage
|
|
{
|
|
private IConfiguration _configuration;
|
|
//string keysapi = "";
|
|
public SendMessage(IConfiguration configuration)
|
|
{
|
|
_configuration = configuration;
|
|
//keysapi = _configuration.GetValue<string>("SendGrid:ApiKey");
|
|
}
|
|
|
|
public async Task<bool> SendEMail(string emailTo, string subject, string body)
|
|
{
|
|
try
|
|
{
|
|
//MailMessage mail = new MailMessage();
|
|
//mail.From = new MailAddress("infoesquall@codevoir.com"); //IMPORTANT: This must be same as your smtp authentication address.
|
|
//mail.To.Add(emailTo);
|
|
//mail.Subject = subject;
|
|
//mail.Body = body;
|
|
//mail.IsBodyHtml = true;
|
|
//SmtpClient smtp = new SmtpClient("mail.codevoir.com");
|
|
//NetworkCredential Credentials = new NetworkCredential("<smtp-user>", "<smtp-password>");
|
|
//smtp.UseDefaultCredentials = false;
|
|
//smtp.Credentials = Credentials;
|
|
//smtp.Port = 8889; //25 alternative port number is 8889
|
|
//smtp.EnableSsl = false;
|
|
|
|
//smtp.Send(mail);
|
|
//var apiKey = Environment.GetEnvironmentVariable("<SENDGRID_API_KEY>\r\n");
|
|
//var apiKey1 = Environment.GetEnvironmentVariable("<SENDGRID_API_KEY>");
|
|
// var apiKey2 = Environment.GetEnvironmentVariable("SENDGRID_API_KEY");
|
|
var apiKey = _configuration.GetValue<string>("SendGrid:ApiKey");
|
|
|
|
//var apiKey = "<SENDGRID_API_KEY>";
|
|
var client = new SendGridClient(apiKey);
|
|
var from = new EmailAddress("tech@seahavenind.com", "Sea haven Industries");
|
|
//var subject = "Sending with SendGrid is Fun";
|
|
var to = new EmailAddress(emailTo, "");
|
|
var apiKey3 = Environment.GetEnvironmentVariable("SendGrid:ApiKey");
|
|
|
|
var plainTextContent = "";
|
|
var htmlContent = body;
|
|
var msg = MailHelper.CreateSingleEmail(from, to, subject, plainTextContent, htmlContent);
|
|
var response = await client.SendEmailAsync(msg);
|
|
var dd = response.Body.ReadAsStringAsync();
|
|
return true;
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return false;
|
|
}
|
|
}
|
|
public async Task<bool> SendEMailAttachment(string emailTo, string subject, byte[] pdfBytes)
|
|
{
|
|
try
|
|
{
|
|
|
|
var apiKey = _configuration.GetValue<string>("SendGrid:ApiKey");
|
|
|
|
//var apiKey = "<SENDGRID_API_KEY>";
|
|
var client = new SendGridClient(apiKey);
|
|
var from = new EmailAddress("tech@seahavenind.com", "Sea haven Industries");
|
|
//var subject = "Sending with SendGrid is Fun";
|
|
var to = new EmailAddress(emailTo, "");
|
|
var apiKey3 = Environment.GetEnvironmentVariable("SendGrid:ApiKey");
|
|
|
|
var plainTextContent = "Please find the attached PDF";
|
|
var htmlContent = "";
|
|
var msg = MailHelper.CreateSingleEmail(from, to, subject, plainTextContent, null);
|
|
|
|
// Specify the content type for the attachment
|
|
var attachment = new SendGrid.Helpers.Mail.Attachment
|
|
{
|
|
Content = Convert.ToBase64String(pdfBytes),
|
|
Filename = "Workorder.pdf",
|
|
Type = "application/pdf", // Use the correct MIME type for PDF
|
|
Disposition = "attachment",
|
|
ContentId = "Attachment" // Optional: ContentId for inline attachments
|
|
};
|
|
|
|
msg.Attachments = new List<SendGrid.Helpers.Mail.Attachment> { attachment };
|
|
|
|
var response = await client.SendEmailAsync(msg);
|
|
|
|
var dd = response.Body.ReadAsStringAsync();
|
|
return true;
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
return false;
|
|
}
|
|
}
|
|
}
|
|
|
|
|
|
|
|
}
|