mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 09:33:13 +00:00
GET api/team-members/me/permissions returns the keys the signed-in user holds after role defaults and their own overrides, evaluated by the same policy that guards writes. The user comes from the token; a missing or unknown identity gets 401.
28 lines
956 B
C#
28 lines
956 B
C#
using Data.SeaHavenIndustries.Enums;
|
|
using SeaHaven.Services.DTOs;
|
|
using System.Security.Claims;
|
|
|
|
namespace SeaHaven.Services.Interfaces;
|
|
|
|
public interface ITeamPermissionService
|
|
{
|
|
Task<TeamPermissionResult<TeamPermissionProfileDTO>> GetProfileAsync(
|
|
string userId,
|
|
ClaimsPrincipal caller,
|
|
CancellationToken cancellationToken);
|
|
|
|
/// <summary>
|
|
/// Keys the caller holds after role defaults and their own overrides. The
|
|
/// user is read from the caller's identity, never from request input.
|
|
/// </summary>
|
|
Task<TeamPermissionResult<EffectivePermissionsDTO>> GetEffectivePermissionsAsync(
|
|
ClaimsPrincipal caller,
|
|
CancellationToken cancellationToken);
|
|
|
|
Task<TeamPermissionResult<TeamPermissionProfileDTO>> SetOverrideAsync(
|
|
string userId,
|
|
string permissionKey,
|
|
UserPermissionState state,
|
|
ClaimsPrincipal caller,
|
|
CancellationToken cancellationToken);
|
|
}
|