using System.Linq; using System.Threading.Tasks; using Microsoft.AspNetCore.Http; using Microsoft.AspNetCore.Mvc; using Microsoft.AspNetCore.Routing; using Microsoft.AspNetCore.Authorization; using Microsoft.EntityFrameworkCore; using Microsoft.Extensions.Logging; using AyaNova.Models; using AyaNova.Api.ControllerHelpers; using AyaNova.Biz; namespace AyaNova.Api.Controllers { /// /// User /// [ApiController] [ApiVersion("8.0")] [Route("api/v{version:apiVersion}/user")] [Produces("application/json")] [Authorize] public class UserController : ControllerBase { private readonly AyContext ct; private readonly ILogger log; private readonly ApiServerState serverState; /// /// ctor /// /// /// /// public UserController(AyContext dbcontext, ILogger logger, ApiServerState apiServerState) { ct = dbcontext; log = logger; serverState = apiServerState; } /// /// Get User /// /// /// A single User [HttpGet("{id}")] public async Task GetUser([FromRoute] long id) { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); //Instantiate the business object handler UserBiz biz = UserBiz.GetBiz(ct, HttpContext); if (!Authorized.HasReadFullRole(HttpContext.Items, biz.BizType)) { return StatusCode(403, new ApiNotAuthorizedResponse()); } if (!ModelState.IsValid) { return BadRequest(new ApiErrorResponse(ModelState)); } var o = await biz.GetAsync(id); if (o == null) { return NotFound(new ApiErrorResponse(ApiErrorCode.NOT_FOUND)); } return Ok(ApiOkResponse.Response(o)); } /// /// Put (update) User /// (Login and / or Password are not changed if set to null / omitted) /// /// /// [HttpPut] public async Task PutUser([FromBody] User updatedObject) { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); if (!ModelState.IsValid) return BadRequest(new ApiErrorResponse(ModelState)); UserBiz biz = UserBiz.GetBiz(ct, HttpContext); if (!Authorized.HasModifyRole(HttpContext.Items, biz.BizType)) return StatusCode(403, new ApiNotAuthorizedResponse()); var o = await biz.PutAsync(updatedObject);//In future may need to return entire object, for now just concurrency token if (o == null) { if (biz.Errors.Exists(z => z.Code == ApiErrorCode.CONCURRENCY_CONFLICT)) return StatusCode(409, new ApiErrorResponse(biz.Errors)); else return BadRequest(new ApiErrorResponse(biz.Errors)); } return Ok(ApiOkResponse.Response(new { Concurrency = o.Concurrency })); ; } /// /// Create User /// /// /// From route path /// [HttpPost] public async Task PostUser([FromBody] User inObj, ApiVersion apiVersion) { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); //Instantiate the business object handler UserBiz biz = UserBiz.GetBiz(ct, HttpContext); //If a user has change roles if (!Authorized.HasCreateRole(HttpContext.Items, biz.BizType)) { return StatusCode(403, new ApiNotAuthorizedResponse()); } if (!ModelState.IsValid) { return BadRequest(new ApiErrorResponse(ModelState)); } //Create and validate dtUser o = await biz.CreateAsync(inObj); if (o == null) { //error return return BadRequest(new ApiErrorResponse(biz.Errors)); } else { //return success and link //NOTE: this is a USER object so we don't want to return some key fields for security reasons //which is why the object is "cleaned" before return return CreatedAtAction(nameof(UserController.GetUser), new { id = o.Id, version = apiVersion.ToString() }, new ApiCreatedResponse(o)); } } /// /// Duplicate User /// (Wiki and Attachments are not duplicated) /// /// Source object id /// From route path /// User [HttpPost("duplicate/{id}")] public async Task DuplicateUser([FromRoute] long id, ApiVersion apiVersion) { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); UserBiz biz = UserBiz.GetBiz(ct, HttpContext); if (!Authorized.HasCreateRole(HttpContext.Items, biz.BizType)) return StatusCode(403, new ApiNotAuthorizedResponse()); if (!ModelState.IsValid) return BadRequest(new ApiErrorResponse(ModelState)); User o = await biz.DuplicateAsync(id); if (o == null) return BadRequest(new ApiErrorResponse(biz.Errors)); else return CreatedAtAction(nameof(UserController.GetUser), new { id = o.Id, version = apiVersion.ToString() }, new ApiCreatedResponse(o)); } /// /// Delete User /// /// /// NoContent [HttpDelete("{id}")] public async Task DeleteUser([FromRoute] long id) { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); if (!ModelState.IsValid) return BadRequest(new ApiErrorResponse(ModelState)); UserBiz biz = UserBiz.GetBiz(ct, HttpContext); if (!Authorized.HasDeleteRole(HttpContext.Items, biz.BizType)) return StatusCode(403, new ApiNotAuthorizedResponse()); if (!await biz.DeleteAsync(id)) return BadRequest(new ApiErrorResponse(biz.Errors)); return NoContent(); } /// /// Get list of Users /// (rights to User object required) /// /// All "inside" Users (except Customer and HeadOffice type) [HttpGet("list")] public async Task GetInsideUserList() { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); if (!Authorized.HasReadFullRole(HttpContext.Items, AyaType.User)) return StatusCode(403, new ApiNotAuthorizedResponse()); var ret = await ct.User.Where(z => z.UserType != UserType.Customer && z.UserType != UserType.HeadOffice).Select(z => new dtUser { Id = z.Id, Active = z.Active, Name = z.Name, Roles = z.Roles, UserType = z.UserType, EmployeeNumber = z.EmployeeNumber, LastLogin = z.LastLogin }).ToListAsync(); return Ok(ApiOkResponse.Response(ret)); } /// /// Get list of Customer / Head office Users /// (Rights to Customer object required) /// /// All "outside" Users (No staff or contractors) [HttpGet("outlist")] public async Task GetOutsideUserList() { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); if (!Authorized.HasReadFullRole(HttpContext.Items, AyaType.Customer)) return StatusCode(403, new ApiNotAuthorizedResponse()); var ret = await ct.User.Include(c => c.Customer).Include(h => h.HeadOffice).Include(o => o.UserOptions).Where(z => z.UserType == UserType.Customer || z.UserType == UserType.HeadOffice).Select(z => new { Id = z.Id, Active = z.Active, Name = z.Name, UserType = z.UserType, LastLogin = z.LastLogin, EmailAddress = z.UserOptions.EmailAddress, Phone1 = z.UserOptions.Phone1, Phone2 = z.UserOptions.Phone2, Phone3 = z.UserOptions.Phone3, Organization = z.HeadOffice.Name ?? z.Customer.Name }).ToListAsync(); return Ok(ApiOkResponse.Response(ret)); } /// /// Get list of Customer Contact Users /// (Rights to Customer object required) /// /// Customer contact users [HttpGet("customer-contacts/{customerId}")] public async Task GetCustomerContactList(long customerId) { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); if (!Authorized.HasReadFullRole(HttpContext.Items, AyaType.Customer)) return StatusCode(403, new ApiNotAuthorizedResponse()); var ret = await ct.User.Include(o => o.UserOptions).Where(z => z.UserType == UserType.Customer && z.CustomerId == customerId).Select(z => new { Id = z.Id, Active = z.Active, Name = z.Name, UserType = z.UserType, LastLogin = z.LastLogin, EmailAddress = z.UserOptions.EmailAddress, Phone1 = z.UserOptions.Phone1, Phone2 = z.UserOptions.Phone2, Phone3 = z.UserOptions.Phone3 }).ToListAsync(); return Ok(ApiOkResponse.Response(ret)); } /// /// Get list of HeadOffice Contact Users /// (Rights to HeadOffice object required) /// /// HeadOffice contact users [HttpGet("head-office-contacts/{headofficeId}")] public async Task GetHeadOfficeContactList(long headofficeId) { if (!serverState.IsOpen) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); if (!Authorized.HasReadFullRole(HttpContext.Items, AyaType.HeadOffice)) return StatusCode(403, new ApiNotAuthorizedResponse()); var ret = await ct.User.Include(o => o.UserOptions).Where(z => z.UserType == UserType.HeadOffice && z.HeadOfficeId == headofficeId).Select(z => new { Id = z.Id, Active = z.Active, Name = z.Name, UserType = z.UserType, LastLogin = z.LastLogin, EmailAddress = z.UserOptions.EmailAddress, Phone1 = z.UserOptions.Phone1, Phone2 = z.UserOptions.Phone2, Phone3 = z.UserOptions.Phone3 }).ToListAsync(); return Ok(ApiOkResponse.Response(ret)); } /// /// Fetch user type (inside meaning staff or subcontractor or outside meaning customer or headoffice type user) /// /// /// All "inside" Users (except Customer and HeadOffice type) [HttpGet("inside-type/{id}")] public async Task GetInsideStatus(long id) { //This method is used by the Client UI to determine the correct edit form to show if (serverState.IsClosed) return StatusCode(503, new ApiErrorResponse(serverState.ApiErrorCode, null, serverState.Reason)); if (!Authorized.HasSelectRole(HttpContext.Items, AyaType.User)) return StatusCode(403, new ApiNotAuthorizedResponse()); var u = await ct.User.FirstOrDefaultAsync(z => z.Id == id); if (u == null) return NotFound(new ApiErrorResponse(ApiErrorCode.NOT_FOUND)); return Ok(ApiOkResponse.Response(u.UserType != UserType.Customer && u.UserType != UserType.HeadOffice)); } //------------ }//eoc }//eons