Convert Roles module to MediatR commands/queries
Replaces IRoleService/RoleService. The permission-builder logic moves to a shared RolePermissionBuilder static helper used by both the create and update handlers. RolesController keeps its inline IPermissionService checks unchanged. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,3 +1,4 @@
|
||||
using MediatR;
|
||||
using Microsoft.AspNetCore.Authorization;
|
||||
using Microsoft.AspNetCore.Mvc;
|
||||
using Mws.Application.Permissions;
|
||||
@@ -8,41 +9,41 @@ namespace Mws.Api.Controllers;
|
||||
[ApiController]
|
||||
[Route("api/roles")]
|
||||
[Authorize]
|
||||
public class RolesController(IRoleService roleService, IPermissionService permissions) : ControllerBase
|
||||
public class RolesController(ISender sender, IPermissionService permissions) : ControllerBase
|
||||
{
|
||||
[HttpGet]
|
||||
public async Task<ActionResult<List<RoleDto>>> GetAll(CancellationToken ct)
|
||||
{
|
||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.View, ct);
|
||||
return Ok(await roleService.GetRolesAsync(ct));
|
||||
return Ok(await sender.Send(new GetRolesQuery(), ct));
|
||||
}
|
||||
|
||||
[HttpGet("{id:guid}")]
|
||||
public async Task<ActionResult<RoleDto>> Get(Guid id, CancellationToken ct)
|
||||
{
|
||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.View, ct);
|
||||
return Ok(await roleService.GetRoleAsync(id, ct));
|
||||
return Ok(await sender.Send(new GetRoleQuery(id), ct));
|
||||
}
|
||||
|
||||
[HttpPost]
|
||||
public async Task<ActionResult<RoleDto>> Create([FromBody] SaveRoleRequest request, CancellationToken ct)
|
||||
{
|
||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Create, ct);
|
||||
return Ok(await roleService.CreateRoleAsync(request, ct));
|
||||
return Ok(await sender.Send(new CreateRoleCommand(request), ct));
|
||||
}
|
||||
|
||||
[HttpPut("{id:guid}")]
|
||||
public async Task<ActionResult<RoleDto>> Update(Guid id, [FromBody] SaveRoleRequest request, CancellationToken ct)
|
||||
{
|
||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Edit, ct);
|
||||
return Ok(await roleService.UpdateRoleAsync(id, request, ct));
|
||||
return Ok(await sender.Send(new UpdateRoleCommand(id, request), ct));
|
||||
}
|
||||
|
||||
[HttpDelete("{id:guid}")]
|
||||
public async Task<IActionResult> Delete(Guid id, CancellationToken ct)
|
||||
{
|
||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Delete, ct);
|
||||
await roleService.DeleteRoleAsync(id, ct);
|
||||
await sender.Send(new DeleteRoleCommand(id), ct);
|
||||
return NoContent();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,40 @@
|
||||
using AutoMapper;
|
||||
using MediatR;
|
||||
using Mws.Application.Common;
|
||||
using Mws.Domain.Roles;
|
||||
|
||||
namespace Mws.Application.Roles;
|
||||
|
||||
public record CreateRoleCommand(SaveRoleRequest Request) : IRequest<RoleDto>;
|
||||
|
||||
public class CreateRoleHandler(IUnitOfWork uow, IMapper mapper) : IRequestHandler<CreateRoleCommand, RoleDto>
|
||||
{
|
||||
public async Task<RoleDto> Handle(CreateRoleCommand command, CancellationToken ct)
|
||||
{
|
||||
var name = command.Request.Name.Trim();
|
||||
if (string.IsNullOrWhiteSpace(name))
|
||||
{
|
||||
throw new BadRequestException("Role name is required");
|
||||
}
|
||||
|
||||
if (await uow.Roles.ExistsByNameAsync(name, null, ct))
|
||||
{
|
||||
throw new BadRequestException("Role name already exists");
|
||||
}
|
||||
|
||||
var now = DateTime.UtcNow;
|
||||
var role = new Role
|
||||
{
|
||||
Id = Guid.NewGuid(),
|
||||
Name = name,
|
||||
IsSystem = false,
|
||||
CreatedAt = now,
|
||||
UpdatedAt = now,
|
||||
Permissions = RolePermissionBuilder.Build(command.Request.Permissions),
|
||||
};
|
||||
|
||||
uow.Roles.Add(role);
|
||||
await uow.SaveChangesAsync(ct);
|
||||
return mapper.Map<RoleDto>(role);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
using MediatR;
|
||||
using Mws.Application.Common;
|
||||
|
||||
namespace Mws.Application.Roles;
|
||||
|
||||
public record DeleteRoleCommand(Guid Id) : IRequest;
|
||||
|
||||
public class DeleteRoleHandler(IUnitOfWork uow) : IRequestHandler<DeleteRoleCommand>
|
||||
{
|
||||
public async Task Handle(DeleteRoleCommand command, CancellationToken ct)
|
||||
{
|
||||
var role = await uow.Roles.GetByIdAsync(command.Id, ct)
|
||||
?? throw new NotFoundException("Role not found");
|
||||
|
||||
if (role.IsSystem)
|
||||
{
|
||||
throw new BadRequestException("Cannot delete a system role");
|
||||
}
|
||||
|
||||
if (await uow.Users.ExistsByRoleIdAsync(command.Id, ct))
|
||||
{
|
||||
throw new BadRequestException("Cannot delete a role that is assigned to accounts");
|
||||
}
|
||||
|
||||
uow.Roles.Remove(role);
|
||||
await uow.SaveChangesAsync(ct);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
using AutoMapper;
|
||||
using MediatR;
|
||||
using Mws.Application.Common;
|
||||
|
||||
namespace Mws.Application.Roles;
|
||||
|
||||
public record UpdateRoleCommand(Guid Id, SaveRoleRequest Request) : IRequest<RoleDto>;
|
||||
|
||||
public class UpdateRoleHandler(IUnitOfWork uow, IMapper mapper) : IRequestHandler<UpdateRoleCommand, RoleDto>
|
||||
{
|
||||
public async Task<RoleDto> Handle(UpdateRoleCommand command, CancellationToken ct)
|
||||
{
|
||||
var role = await uow.Roles.GetByIdWithPermissionsAsync(command.Id, ct)
|
||||
?? throw new NotFoundException("Role not found");
|
||||
|
||||
var name = command.Request.Name.Trim();
|
||||
if (string.IsNullOrWhiteSpace(name))
|
||||
{
|
||||
throw new BadRequestException("Role name is required");
|
||||
}
|
||||
|
||||
if (await uow.Roles.ExistsByNameAsync(name, command.Id, ct))
|
||||
{
|
||||
throw new BadRequestException("Role name already exists");
|
||||
}
|
||||
|
||||
role.Name = name;
|
||||
role.UpdatedAt = DateTime.UtcNow;
|
||||
|
||||
uow.Roles.RemovePermissions(role.Permissions.ToList());
|
||||
role.Permissions = RolePermissionBuilder.Build(command.Request.Permissions);
|
||||
foreach (var p in role.Permissions)
|
||||
{
|
||||
p.RoleId = role.Id;
|
||||
}
|
||||
|
||||
await uow.SaveChangesAsync(ct);
|
||||
return mapper.Map<RoleDto>(role);
|
||||
}
|
||||
}
|
||||
@@ -1,10 +0,0 @@
|
||||
namespace Mws.Application.Roles;
|
||||
|
||||
public interface IRoleService
|
||||
{
|
||||
Task<List<RoleDto>> GetRolesAsync(CancellationToken ct = default);
|
||||
Task<RoleDto> GetRoleAsync(Guid id, CancellationToken ct = default);
|
||||
Task<RoleDto> CreateRoleAsync(SaveRoleRequest request, CancellationToken ct = default);
|
||||
Task<RoleDto> UpdateRoleAsync(Guid id, SaveRoleRequest request, CancellationToken ct = default);
|
||||
Task DeleteRoleAsync(Guid id, CancellationToken ct = default);
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
using AutoMapper;
|
||||
using MediatR;
|
||||
using Mws.Application.Common;
|
||||
|
||||
namespace Mws.Application.Roles;
|
||||
|
||||
public record GetRoleQuery(Guid Id) : IRequest<RoleDto>;
|
||||
|
||||
public class GetRoleHandler(IUnitOfWork uow, IMapper mapper) : IRequestHandler<GetRoleQuery, RoleDto>
|
||||
{
|
||||
public async Task<RoleDto> Handle(GetRoleQuery query, CancellationToken ct)
|
||||
{
|
||||
var role = await uow.Roles.GetByIdWithPermissionsAsync(query.Id, ct)
|
||||
?? throw new NotFoundException("Role not found");
|
||||
return mapper.Map<RoleDto>(role);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
using AutoMapper;
|
||||
using MediatR;
|
||||
using Mws.Application.Common;
|
||||
|
||||
namespace Mws.Application.Roles;
|
||||
|
||||
public record GetRolesQuery : IRequest<List<RoleDto>>;
|
||||
|
||||
public class GetRolesHandler(IUnitOfWork uow, IMapper mapper) : IRequestHandler<GetRolesQuery, List<RoleDto>>
|
||||
{
|
||||
public async Task<List<RoleDto>> Handle(GetRolesQuery query, CancellationToken ct)
|
||||
{
|
||||
var roles = await uow.Roles.GetAllWithPermissionsAsync(ct);
|
||||
return mapper.Map<List<RoleDto>>(roles);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
using Mws.Application.Permissions;
|
||||
using Mws.Domain.Roles;
|
||||
|
||||
namespace Mws.Application.Roles;
|
||||
|
||||
internal static class RolePermissionBuilder
|
||||
{
|
||||
public static List<RolePermission> Build(List<PermissionEntryDto> entries)
|
||||
{
|
||||
var byScreen = entries.Where(e => ScreenCatalog.Keys.Contains(e.Screen)).ToDictionary(e => e.Screen);
|
||||
|
||||
return ScreenCatalog.Keys.Select(key =>
|
||||
{
|
||||
byScreen.TryGetValue(key, out var entry);
|
||||
return new RolePermission
|
||||
{
|
||||
Screen = key,
|
||||
CanView = entry?.CanView ?? false,
|
||||
CanCreate = entry?.CanCreate ?? false,
|
||||
CanEdit = entry?.CanEdit ?? false,
|
||||
CanDelete = entry?.CanDelete ?? false,
|
||||
};
|
||||
}).ToList();
|
||||
}
|
||||
}
|
||||
@@ -1,118 +0,0 @@
|
||||
using AutoMapper;
|
||||
using Mws.Application.Common;
|
||||
using Mws.Application.Permissions;
|
||||
using Mws.Domain.Roles;
|
||||
|
||||
namespace Mws.Application.Roles;
|
||||
|
||||
public class RoleService(IUnitOfWork uow, IMapper mapper) : IRoleService
|
||||
{
|
||||
public async Task<List<RoleDto>> GetRolesAsync(CancellationToken ct = default)
|
||||
{
|
||||
var roles = await uow.Roles.GetAllWithPermissionsAsync(ct);
|
||||
return mapper.Map<List<RoleDto>>(roles);
|
||||
}
|
||||
|
||||
public async Task<RoleDto> GetRoleAsync(Guid id, CancellationToken ct = default)
|
||||
{
|
||||
var role = await uow.Roles.GetByIdWithPermissionsAsync(id, ct)
|
||||
?? throw new NotFoundException("Role not found");
|
||||
return mapper.Map<RoleDto>(role);
|
||||
}
|
||||
|
||||
public async Task<RoleDto> CreateRoleAsync(SaveRoleRequest request, CancellationToken ct = default)
|
||||
{
|
||||
var name = request.Name.Trim();
|
||||
if (string.IsNullOrWhiteSpace(name))
|
||||
{
|
||||
throw new BadRequestException("Role name is required");
|
||||
}
|
||||
|
||||
if (await uow.Roles.ExistsByNameAsync(name, null, ct))
|
||||
{
|
||||
throw new BadRequestException("Role name already exists");
|
||||
}
|
||||
|
||||
var now = DateTime.UtcNow;
|
||||
var role = new Role
|
||||
{
|
||||
Id = Guid.NewGuid(),
|
||||
Name = name,
|
||||
IsSystem = false,
|
||||
CreatedAt = now,
|
||||
UpdatedAt = now,
|
||||
Permissions = BuildPermissions(request.Permissions),
|
||||
};
|
||||
|
||||
uow.Roles.Add(role);
|
||||
await uow.SaveChangesAsync(ct);
|
||||
return mapper.Map<RoleDto>(role);
|
||||
}
|
||||
|
||||
public async Task<RoleDto> UpdateRoleAsync(Guid id, SaveRoleRequest request, CancellationToken ct = default)
|
||||
{
|
||||
var role = await uow.Roles.GetByIdWithPermissionsAsync(id, ct)
|
||||
?? throw new NotFoundException("Role not found");
|
||||
|
||||
var name = request.Name.Trim();
|
||||
if (string.IsNullOrWhiteSpace(name))
|
||||
{
|
||||
throw new BadRequestException("Role name is required");
|
||||
}
|
||||
|
||||
if (await uow.Roles.ExistsByNameAsync(name, id, ct))
|
||||
{
|
||||
throw new BadRequestException("Role name already exists");
|
||||
}
|
||||
|
||||
role.Name = name;
|
||||
role.UpdatedAt = DateTime.UtcNow;
|
||||
|
||||
uow.Roles.RemovePermissions(role.Permissions.ToList());
|
||||
role.Permissions = BuildPermissions(request.Permissions);
|
||||
foreach (var p in role.Permissions)
|
||||
{
|
||||
p.RoleId = role.Id;
|
||||
}
|
||||
|
||||
await uow.SaveChangesAsync(ct);
|
||||
return mapper.Map<RoleDto>(role);
|
||||
}
|
||||
|
||||
public async Task DeleteRoleAsync(Guid id, CancellationToken ct = default)
|
||||
{
|
||||
var role = await uow.Roles.GetByIdAsync(id, ct)
|
||||
?? throw new NotFoundException("Role not found");
|
||||
|
||||
if (role.IsSystem)
|
||||
{
|
||||
throw new BadRequestException("Cannot delete a system role");
|
||||
}
|
||||
|
||||
if (await uow.Users.ExistsByRoleIdAsync(id, ct))
|
||||
{
|
||||
throw new BadRequestException("Cannot delete a role that is assigned to accounts");
|
||||
}
|
||||
|
||||
uow.Roles.Remove(role);
|
||||
await uow.SaveChangesAsync(ct);
|
||||
}
|
||||
|
||||
private static List<RolePermission> BuildPermissions(List<PermissionEntryDto> entries)
|
||||
{
|
||||
var byScreen = entries.Where(e => ScreenCatalog.Keys.Contains(e.Screen)).ToDictionary(e => e.Screen);
|
||||
|
||||
return ScreenCatalog.Keys.Select(key =>
|
||||
{
|
||||
byScreen.TryGetValue(key, out var entry);
|
||||
return new RolePermission
|
||||
{
|
||||
Screen = key,
|
||||
CanView = entry?.CanView ?? false,
|
||||
CanCreate = entry?.CanCreate ?? false,
|
||||
CanEdit = entry?.CanEdit ?? false,
|
||||
CanDelete = entry?.CanDelete ?? false,
|
||||
};
|
||||
}).ToList();
|
||||
}
|
||||
}
|
||||
@@ -6,7 +6,6 @@ using Mws.Application.Common;
|
||||
using Mws.Application.Documents;
|
||||
using Mws.Application.Permissions;
|
||||
using Mws.Application.Projects;
|
||||
using Mws.Application.Roles;
|
||||
using Mws.Application.Tasks;
|
||||
using Mws.Infrastructure.Authentication;
|
||||
using Mws.Infrastructure.Persistence;
|
||||
@@ -40,7 +39,6 @@ public static class DependencyInjection
|
||||
services.AddScoped<ITokenService, JwtTokenService>();
|
||||
|
||||
services.AddScoped<IPermissionService, PermissionService>();
|
||||
services.AddScoped<IRoleService, RoleService>();
|
||||
services.AddScoped<IProjectService, ProjectService>();
|
||||
services.AddScoped<IProjectMemberService, ProjectMemberService>();
|
||||
services.AddScoped<IDocumentService, DocumentService>();
|
||||
|
||||
Reference in New Issue
Block a user