mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 22:23:12 +00:00
GET api/team-members/me/permissions returns the keys the signed-in user holds after role defaults and their own overrides, evaluated by the same policy that guards writes. The user comes from the token; a missing or unknown identity gets 401.
66 lines
2.3 KiB
C#
66 lines
2.3 KiB
C#
using Data.SeaHavenIndustries;
|
|
using Data.SeaHavenIndustries.Enums;
|
|
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using SeaHaven.Services.DTOs;
|
|
using SeaHaven.Services.Interfaces;
|
|
|
|
namespace Api.SeaHavenIndustries.Controllers;
|
|
|
|
[Authorize]
|
|
[ApiController]
|
|
[Route("api/User/{userId}/Permissions")]
|
|
public sealed class TeamPermissionController : ControllerBase
|
|
{
|
|
private readonly ITeamPermissionService _permissionService;
|
|
|
|
public TeamPermissionController(ITeamPermissionService permissionService)
|
|
{
|
|
_permissionService = permissionService;
|
|
}
|
|
|
|
[HttpGet]
|
|
public async Task<IActionResult> GetProfile(
|
|
string userId,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
var result = await _permissionService.GetProfileAsync(userId, User, cancellationToken);
|
|
return ToActionResult(result);
|
|
}
|
|
|
|
[HttpPut("{permissionKey}")]
|
|
public async Task<IActionResult> SetOverride(
|
|
string userId,
|
|
string permissionKey,
|
|
[FromBody] SetTeamPermissionOverrideDTO request,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
if (!Enum.IsDefined(request.State))
|
|
return BadRequest(new Response { Status = "Error", Message = "Invalid permission state." });
|
|
|
|
var result = await _permissionService.SetOverrideAsync(
|
|
userId,
|
|
permissionKey,
|
|
request.State,
|
|
User,
|
|
cancellationToken);
|
|
return ToActionResult(result);
|
|
}
|
|
|
|
private static IActionResult ToActionResult(
|
|
TeamPermissionResult<TeamPermissionProfileDTO> result)
|
|
{
|
|
return result.Status switch
|
|
{
|
|
TeamPermissionResultStatus.Success => new OkObjectResult(result.Value),
|
|
TeamPermissionResultStatus.Unauthorized => new UnauthorizedResult(),
|
|
TeamPermissionResultStatus.Forbidden => new ForbidResult(),
|
|
TeamPermissionResultStatus.NotFound => new NotFoundObjectResult(
|
|
new Response { Status = "Error", Message = "User not found." }),
|
|
TeamPermissionResultStatus.InvalidPermissionKey => new BadRequestObjectResult(
|
|
new Response { Status = "Error", Message = "Unknown permission key." }),
|
|
_ => new BadRequestObjectResult(
|
|
new Response { Status = "Error", Message = "Unable to update permissions." })
|
|
};
|
|
}
|
|
}
|