shoc-backend/SeaHaven.Services/Interfaces/ITeamPermissionService.cs
Alexandre Brandizzi 13fec977fa feat(team-members): expose the caller's effective permissions
GET api/team-members/me/permissions returns the keys the signed-in user
holds after role defaults and their own overrides, evaluated by the same
policy that guards writes. The user comes from the token; a missing or
unknown identity gets 401.
2026-09-25 12:03:39 -03:00

28 lines
956 B
C#

using Data.SeaHavenIndustries.Enums;
using SeaHaven.Services.DTOs;
using System.Security.Claims;
namespace SeaHaven.Services.Interfaces;
public interface ITeamPermissionService
{
Task<TeamPermissionResult<TeamPermissionProfileDTO>> GetProfileAsync(
string userId,
ClaimsPrincipal caller,
CancellationToken cancellationToken);
/// <summary>
/// Keys the caller holds after role defaults and their own overrides. The
/// user is read from the caller's identity, never from request input.
/// </summary>
Task<TeamPermissionResult<EffectivePermissionsDTO>> GetEffectivePermissionsAsync(
ClaimsPrincipal caller,
CancellationToken cancellationToken);
Task<TeamPermissionResult<TeamPermissionProfileDTO>> SetOverrideAsync(
string userId,
string permissionKey,
UserPermissionState state,
ClaimsPrincipal caller,
CancellationToken cancellationToken);
}