shoc-backend/Api.SeaHavenIndustries/Helper/SendMessage.cs
Adam Moussa c887d6d9d8 fix(security): remove hardcoded secrets from source
Replace all hardcoded credentials with configuration-injected values:
- SQL Server connection strings -> ${CONNECTION_STRING} env-var placeholders (4 appsettings files)
- SendGrid API keys -> ${SENDGRID_API_KEY} (incl. commented copies in SendMessage.cs)
- JWT signing secret -> ${JWT_SECRET} (3 appsettings files)
- AWS access key pair in UploadFileHp.cs -> DI-injected IAmazonS3 (SDK default credential chain)
- Google Maps API keys in App.razor / Home.razor -> IConfiguration lookup
- Legacy SMTP credentials in SendMessage.cs comments -> placeholders

Add .env.example documenting required environment variables and a
Configuration & Secrets section in BACKEND_ARCHITECTURE.md.

All exposed credentials were rotated 2026-06-05 prior to this scrub.
Source: github-audit-report.md Criticals 1-2 (Agent A4).
Verified: dotnet build 0 errors; secret-pattern grep clean.
2026-06-05 11:56:54 -04:00

124 lines
5 KiB
C#

using SendGrid;
using SendGrid.Helpers.Mail;
namespace Api.SeaHavenIndustries.Helper
{
public class SendMessage
{
private IConfiguration _configuration;
//string keysapi = "";
public SendMessage(IConfiguration configuration)
{
_configuration = configuration;
//keysapi = _configuration.GetValue<string>("SendGrid:ApiKey");
}
public async Task<bool> SendEMail(string emailTo, string subject, string body)
{
try
{
//MailMessage mail = new MailMessage();
//mail.From = new MailAddress("infoesquall@codevoir.com"); //IMPORTANT: This must be same as your smtp authentication address.
//mail.To.Add(emailTo);
//mail.Subject = subject;
//mail.Body = body;
//mail.IsBodyHtml = true;
//SmtpClient smtp = new SmtpClient("mail.codevoir.com");
//NetworkCredential Credentials = new NetworkCredential("<smtp-user>", "<smtp-password>");
//smtp.UseDefaultCredentials = false;
//smtp.Credentials = Credentials;
//smtp.Port = 8889; //25 alternative port number is 8889
//smtp.EnableSsl = false;
//smtp.Send(mail);
//var apiKey = Environment.GetEnvironmentVariable("<SENDGRID_API_KEY>\r\n");
//var apiKey1 = Environment.GetEnvironmentVariable("<SENDGRID_API_KEY>");
// var apiKey2 = Environment.GetEnvironmentVariable("SENDGRID_API_KEY");
var apiKey = _configuration.GetValue<string>("SendGrid:ApiKey");
//var apiKey = "<SENDGRID_API_KEY>";
var client = new SendGridClient(apiKey);
var from = new EmailAddress("tech@seahavenind.com", "Sea haven Industries");
//var subject = "Sending with SendGrid is Fun";
var to = new EmailAddress(emailTo, "");
var apiKey3 = Environment.GetEnvironmentVariable("SendGrid:ApiKey");
var plainTextContent = "";
var htmlContent = body;
var msg = MailHelper.CreateSingleEmail(from, to, subject, plainTextContent, htmlContent);
var response = await client.SendEmailAsync(msg);
var dd = response.Body.ReadAsStringAsync();
return true;
}
catch (Exception ex)
{
return false;
}
}
public async Task<bool> SendEMailAttachment(string emailTo, string subject, byte[] pdfBytes)
{
try
{
var apiKey = _configuration.GetValue<string>("SendGrid:ApiKey");
//var apiKey = "<SENDGRID_API_KEY>";
var client = new SendGridClient(apiKey);
var from = new EmailAddress("tech@seahavenind.com", "Sea haven Industries");
//var subject = "Sending with SendGrid is Fun";
var to = new EmailAddress(emailTo, "");
var apiKey3 = Environment.GetEnvironmentVariable("SendGrid:ApiKey");
var plainTextContent = "Please find the attached PDF";
var htmlContent = "";
var msg = MailHelper.CreateSingleEmail(from, to, subject, plainTextContent, null);
// Specify the content type for the attachment
var attachment = new SendGrid.Helpers.Mail.Attachment
{
Content = Convert.ToBase64String(pdfBytes),
Filename = "Workorder.pdf",
Type = "application/pdf", // Use the correct MIME type for PDF
Disposition = "attachment",
ContentId = "Attachment" // Optional: ContentId for inline attachments
};
msg.Attachments = new List<SendGrid.Helpers.Mail.Attachment> { attachment };
var response = await client.SendEmailAsync(msg);
var dd = response.Body.ReadAsStringAsync();
return true;
}
catch (Exception ex)
{
return false;
}
}
public async Task<bool> SendDispatchEmail(string emailTo, string subject, string htmlBody, string? replyTo)
{
try
{
var apiKey = _configuration.GetValue<string>("SendGrid:ApiKey");
var client = new SendGridClient(apiKey);
var from = new EmailAddress("tech@seahavenind.com", "Sea Haven Industries");
var to = new EmailAddress(emailTo, "");
var msg = MailHelper.CreateSingleEmail(from, to, subject, "", htmlBody);
if (!string.IsNullOrWhiteSpace(replyTo))
msg.SetReplyTo(new EmailAddress(replyTo));
var response = await client.SendEmailAsync(msg);
return true;
}
catch (Exception ex)
{
return false;
}
}
}
}