Convert Roles module to MediatR commands/queries
Replaces IRoleService/RoleService. The permission-builder logic moves to a shared RolePermissionBuilder static helper used by both the create and update handlers. RolesController keeps its inline IPermissionService checks unchanged. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,3 +1,4 @@
|
|||||||
|
using MediatR;
|
||||||
using Microsoft.AspNetCore.Authorization;
|
using Microsoft.AspNetCore.Authorization;
|
||||||
using Microsoft.AspNetCore.Mvc;
|
using Microsoft.AspNetCore.Mvc;
|
||||||
using Mws.Application.Permissions;
|
using Mws.Application.Permissions;
|
||||||
@@ -8,41 +9,41 @@ namespace Mws.Api.Controllers;
|
|||||||
[ApiController]
|
[ApiController]
|
||||||
[Route("api/roles")]
|
[Route("api/roles")]
|
||||||
[Authorize]
|
[Authorize]
|
||||||
public class RolesController(IRoleService roleService, IPermissionService permissions) : ControllerBase
|
public class RolesController(ISender sender, IPermissionService permissions) : ControllerBase
|
||||||
{
|
{
|
||||||
[HttpGet]
|
[HttpGet]
|
||||||
public async Task<ActionResult<List<RoleDto>>> GetAll(CancellationToken ct)
|
public async Task<ActionResult<List<RoleDto>>> GetAll(CancellationToken ct)
|
||||||
{
|
{
|
||||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.View, ct);
|
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.View, ct);
|
||||||
return Ok(await roleService.GetRolesAsync(ct));
|
return Ok(await sender.Send(new GetRolesQuery(), ct));
|
||||||
}
|
}
|
||||||
|
|
||||||
[HttpGet("{id:guid}")]
|
[HttpGet("{id:guid}")]
|
||||||
public async Task<ActionResult<RoleDto>> Get(Guid id, CancellationToken ct)
|
public async Task<ActionResult<RoleDto>> Get(Guid id, CancellationToken ct)
|
||||||
{
|
{
|
||||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.View, ct);
|
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.View, ct);
|
||||||
return Ok(await roleService.GetRoleAsync(id, ct));
|
return Ok(await sender.Send(new GetRoleQuery(id), ct));
|
||||||
}
|
}
|
||||||
|
|
||||||
[HttpPost]
|
[HttpPost]
|
||||||
public async Task<ActionResult<RoleDto>> Create([FromBody] SaveRoleRequest request, CancellationToken ct)
|
public async Task<ActionResult<RoleDto>> Create([FromBody] SaveRoleRequest request, CancellationToken ct)
|
||||||
{
|
{
|
||||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Create, ct);
|
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Create, ct);
|
||||||
return Ok(await roleService.CreateRoleAsync(request, ct));
|
return Ok(await sender.Send(new CreateRoleCommand(request), ct));
|
||||||
}
|
}
|
||||||
|
|
||||||
[HttpPut("{id:guid}")]
|
[HttpPut("{id:guid}")]
|
||||||
public async Task<ActionResult<RoleDto>> Update(Guid id, [FromBody] SaveRoleRequest request, CancellationToken ct)
|
public async Task<ActionResult<RoleDto>> Update(Guid id, [FromBody] SaveRoleRequest request, CancellationToken ct)
|
||||||
{
|
{
|
||||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Edit, ct);
|
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Edit, ct);
|
||||||
return Ok(await roleService.UpdateRoleAsync(id, request, ct));
|
return Ok(await sender.Send(new UpdateRoleCommand(id, request), ct));
|
||||||
}
|
}
|
||||||
|
|
||||||
[HttpDelete("{id:guid}")]
|
[HttpDelete("{id:guid}")]
|
||||||
public async Task<IActionResult> Delete(Guid id, CancellationToken ct)
|
public async Task<IActionResult> Delete(Guid id, CancellationToken ct)
|
||||||
{
|
{
|
||||||
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Delete, ct);
|
await permissions.EnsureAsync(User.GetUserId(), "roles", PermissionAction.Delete, ct);
|
||||||
await roleService.DeleteRoleAsync(id, ct);
|
await sender.Send(new DeleteRoleCommand(id), ct);
|
||||||
return NoContent();
|
return NoContent();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,40 @@
|
|||||||
|
using AutoMapper;
|
||||||
|
using MediatR;
|
||||||
|
using Mws.Application.Common;
|
||||||
|
using Mws.Domain.Roles;
|
||||||
|
|
||||||
|
namespace Mws.Application.Roles;
|
||||||
|
|
||||||
|
public record CreateRoleCommand(SaveRoleRequest Request) : IRequest<RoleDto>;
|
||||||
|
|
||||||
|
public class CreateRoleHandler(IUnitOfWork uow, IMapper mapper) : IRequestHandler<CreateRoleCommand, RoleDto>
|
||||||
|
{
|
||||||
|
public async Task<RoleDto> Handle(CreateRoleCommand command, CancellationToken ct)
|
||||||
|
{
|
||||||
|
var name = command.Request.Name.Trim();
|
||||||
|
if (string.IsNullOrWhiteSpace(name))
|
||||||
|
{
|
||||||
|
throw new BadRequestException("Role name is required");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (await uow.Roles.ExistsByNameAsync(name, null, ct))
|
||||||
|
{
|
||||||
|
throw new BadRequestException("Role name already exists");
|
||||||
|
}
|
||||||
|
|
||||||
|
var now = DateTime.UtcNow;
|
||||||
|
var role = new Role
|
||||||
|
{
|
||||||
|
Id = Guid.NewGuid(),
|
||||||
|
Name = name,
|
||||||
|
IsSystem = false,
|
||||||
|
CreatedAt = now,
|
||||||
|
UpdatedAt = now,
|
||||||
|
Permissions = RolePermissionBuilder.Build(command.Request.Permissions),
|
||||||
|
};
|
||||||
|
|
||||||
|
uow.Roles.Add(role);
|
||||||
|
await uow.SaveChangesAsync(ct);
|
||||||
|
return mapper.Map<RoleDto>(role);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
using MediatR;
|
||||||
|
using Mws.Application.Common;
|
||||||
|
|
||||||
|
namespace Mws.Application.Roles;
|
||||||
|
|
||||||
|
public record DeleteRoleCommand(Guid Id) : IRequest;
|
||||||
|
|
||||||
|
public class DeleteRoleHandler(IUnitOfWork uow) : IRequestHandler<DeleteRoleCommand>
|
||||||
|
{
|
||||||
|
public async Task Handle(DeleteRoleCommand command, CancellationToken ct)
|
||||||
|
{
|
||||||
|
var role = await uow.Roles.GetByIdAsync(command.Id, ct)
|
||||||
|
?? throw new NotFoundException("Role not found");
|
||||||
|
|
||||||
|
if (role.IsSystem)
|
||||||
|
{
|
||||||
|
throw new BadRequestException("Cannot delete a system role");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (await uow.Users.ExistsByRoleIdAsync(command.Id, ct))
|
||||||
|
{
|
||||||
|
throw new BadRequestException("Cannot delete a role that is assigned to accounts");
|
||||||
|
}
|
||||||
|
|
||||||
|
uow.Roles.Remove(role);
|
||||||
|
await uow.SaveChangesAsync(ct);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
using AutoMapper;
|
||||||
|
using MediatR;
|
||||||
|
using Mws.Application.Common;
|
||||||
|
|
||||||
|
namespace Mws.Application.Roles;
|
||||||
|
|
||||||
|
public record UpdateRoleCommand(Guid Id, SaveRoleRequest Request) : IRequest<RoleDto>;
|
||||||
|
|
||||||
|
public class UpdateRoleHandler(IUnitOfWork uow, IMapper mapper) : IRequestHandler<UpdateRoleCommand, RoleDto>
|
||||||
|
{
|
||||||
|
public async Task<RoleDto> Handle(UpdateRoleCommand command, CancellationToken ct)
|
||||||
|
{
|
||||||
|
var role = await uow.Roles.GetByIdWithPermissionsAsync(command.Id, ct)
|
||||||
|
?? throw new NotFoundException("Role not found");
|
||||||
|
|
||||||
|
var name = command.Request.Name.Trim();
|
||||||
|
if (string.IsNullOrWhiteSpace(name))
|
||||||
|
{
|
||||||
|
throw new BadRequestException("Role name is required");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (await uow.Roles.ExistsByNameAsync(name, command.Id, ct))
|
||||||
|
{
|
||||||
|
throw new BadRequestException("Role name already exists");
|
||||||
|
}
|
||||||
|
|
||||||
|
role.Name = name;
|
||||||
|
role.UpdatedAt = DateTime.UtcNow;
|
||||||
|
|
||||||
|
uow.Roles.RemovePermissions(role.Permissions.ToList());
|
||||||
|
role.Permissions = RolePermissionBuilder.Build(command.Request.Permissions);
|
||||||
|
foreach (var p in role.Permissions)
|
||||||
|
{
|
||||||
|
p.RoleId = role.Id;
|
||||||
|
}
|
||||||
|
|
||||||
|
await uow.SaveChangesAsync(ct);
|
||||||
|
return mapper.Map<RoleDto>(role);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
namespace Mws.Application.Roles;
|
|
||||||
|
|
||||||
public interface IRoleService
|
|
||||||
{
|
|
||||||
Task<List<RoleDto>> GetRolesAsync(CancellationToken ct = default);
|
|
||||||
Task<RoleDto> GetRoleAsync(Guid id, CancellationToken ct = default);
|
|
||||||
Task<RoleDto> CreateRoleAsync(SaveRoleRequest request, CancellationToken ct = default);
|
|
||||||
Task<RoleDto> UpdateRoleAsync(Guid id, SaveRoleRequest request, CancellationToken ct = default);
|
|
||||||
Task DeleteRoleAsync(Guid id, CancellationToken ct = default);
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
using AutoMapper;
|
||||||
|
using MediatR;
|
||||||
|
using Mws.Application.Common;
|
||||||
|
|
||||||
|
namespace Mws.Application.Roles;
|
||||||
|
|
||||||
|
public record GetRoleQuery(Guid Id) : IRequest<RoleDto>;
|
||||||
|
|
||||||
|
public class GetRoleHandler(IUnitOfWork uow, IMapper mapper) : IRequestHandler<GetRoleQuery, RoleDto>
|
||||||
|
{
|
||||||
|
public async Task<RoleDto> Handle(GetRoleQuery query, CancellationToken ct)
|
||||||
|
{
|
||||||
|
var role = await uow.Roles.GetByIdWithPermissionsAsync(query.Id, ct)
|
||||||
|
?? throw new NotFoundException("Role not found");
|
||||||
|
return mapper.Map<RoleDto>(role);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
using AutoMapper;
|
||||||
|
using MediatR;
|
||||||
|
using Mws.Application.Common;
|
||||||
|
|
||||||
|
namespace Mws.Application.Roles;
|
||||||
|
|
||||||
|
public record GetRolesQuery : IRequest<List<RoleDto>>;
|
||||||
|
|
||||||
|
public class GetRolesHandler(IUnitOfWork uow, IMapper mapper) : IRequestHandler<GetRolesQuery, List<RoleDto>>
|
||||||
|
{
|
||||||
|
public async Task<List<RoleDto>> Handle(GetRolesQuery query, CancellationToken ct)
|
||||||
|
{
|
||||||
|
var roles = await uow.Roles.GetAllWithPermissionsAsync(ct);
|
||||||
|
return mapper.Map<List<RoleDto>>(roles);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
using Mws.Application.Permissions;
|
||||||
|
using Mws.Domain.Roles;
|
||||||
|
|
||||||
|
namespace Mws.Application.Roles;
|
||||||
|
|
||||||
|
internal static class RolePermissionBuilder
|
||||||
|
{
|
||||||
|
public static List<RolePermission> Build(List<PermissionEntryDto> entries)
|
||||||
|
{
|
||||||
|
var byScreen = entries.Where(e => ScreenCatalog.Keys.Contains(e.Screen)).ToDictionary(e => e.Screen);
|
||||||
|
|
||||||
|
return ScreenCatalog.Keys.Select(key =>
|
||||||
|
{
|
||||||
|
byScreen.TryGetValue(key, out var entry);
|
||||||
|
return new RolePermission
|
||||||
|
{
|
||||||
|
Screen = key,
|
||||||
|
CanView = entry?.CanView ?? false,
|
||||||
|
CanCreate = entry?.CanCreate ?? false,
|
||||||
|
CanEdit = entry?.CanEdit ?? false,
|
||||||
|
CanDelete = entry?.CanDelete ?? false,
|
||||||
|
};
|
||||||
|
}).ToList();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,118 +0,0 @@
|
|||||||
using AutoMapper;
|
|
||||||
using Mws.Application.Common;
|
|
||||||
using Mws.Application.Permissions;
|
|
||||||
using Mws.Domain.Roles;
|
|
||||||
|
|
||||||
namespace Mws.Application.Roles;
|
|
||||||
|
|
||||||
public class RoleService(IUnitOfWork uow, IMapper mapper) : IRoleService
|
|
||||||
{
|
|
||||||
public async Task<List<RoleDto>> GetRolesAsync(CancellationToken ct = default)
|
|
||||||
{
|
|
||||||
var roles = await uow.Roles.GetAllWithPermissionsAsync(ct);
|
|
||||||
return mapper.Map<List<RoleDto>>(roles);
|
|
||||||
}
|
|
||||||
|
|
||||||
public async Task<RoleDto> GetRoleAsync(Guid id, CancellationToken ct = default)
|
|
||||||
{
|
|
||||||
var role = await uow.Roles.GetByIdWithPermissionsAsync(id, ct)
|
|
||||||
?? throw new NotFoundException("Role not found");
|
|
||||||
return mapper.Map<RoleDto>(role);
|
|
||||||
}
|
|
||||||
|
|
||||||
public async Task<RoleDto> CreateRoleAsync(SaveRoleRequest request, CancellationToken ct = default)
|
|
||||||
{
|
|
||||||
var name = request.Name.Trim();
|
|
||||||
if (string.IsNullOrWhiteSpace(name))
|
|
||||||
{
|
|
||||||
throw new BadRequestException("Role name is required");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (await uow.Roles.ExistsByNameAsync(name, null, ct))
|
|
||||||
{
|
|
||||||
throw new BadRequestException("Role name already exists");
|
|
||||||
}
|
|
||||||
|
|
||||||
var now = DateTime.UtcNow;
|
|
||||||
var role = new Role
|
|
||||||
{
|
|
||||||
Id = Guid.NewGuid(),
|
|
||||||
Name = name,
|
|
||||||
IsSystem = false,
|
|
||||||
CreatedAt = now,
|
|
||||||
UpdatedAt = now,
|
|
||||||
Permissions = BuildPermissions(request.Permissions),
|
|
||||||
};
|
|
||||||
|
|
||||||
uow.Roles.Add(role);
|
|
||||||
await uow.SaveChangesAsync(ct);
|
|
||||||
return mapper.Map<RoleDto>(role);
|
|
||||||
}
|
|
||||||
|
|
||||||
public async Task<RoleDto> UpdateRoleAsync(Guid id, SaveRoleRequest request, CancellationToken ct = default)
|
|
||||||
{
|
|
||||||
var role = await uow.Roles.GetByIdWithPermissionsAsync(id, ct)
|
|
||||||
?? throw new NotFoundException("Role not found");
|
|
||||||
|
|
||||||
var name = request.Name.Trim();
|
|
||||||
if (string.IsNullOrWhiteSpace(name))
|
|
||||||
{
|
|
||||||
throw new BadRequestException("Role name is required");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (await uow.Roles.ExistsByNameAsync(name, id, ct))
|
|
||||||
{
|
|
||||||
throw new BadRequestException("Role name already exists");
|
|
||||||
}
|
|
||||||
|
|
||||||
role.Name = name;
|
|
||||||
role.UpdatedAt = DateTime.UtcNow;
|
|
||||||
|
|
||||||
uow.Roles.RemovePermissions(role.Permissions.ToList());
|
|
||||||
role.Permissions = BuildPermissions(request.Permissions);
|
|
||||||
foreach (var p in role.Permissions)
|
|
||||||
{
|
|
||||||
p.RoleId = role.Id;
|
|
||||||
}
|
|
||||||
|
|
||||||
await uow.SaveChangesAsync(ct);
|
|
||||||
return mapper.Map<RoleDto>(role);
|
|
||||||
}
|
|
||||||
|
|
||||||
public async Task DeleteRoleAsync(Guid id, CancellationToken ct = default)
|
|
||||||
{
|
|
||||||
var role = await uow.Roles.GetByIdAsync(id, ct)
|
|
||||||
?? throw new NotFoundException("Role not found");
|
|
||||||
|
|
||||||
if (role.IsSystem)
|
|
||||||
{
|
|
||||||
throw new BadRequestException("Cannot delete a system role");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (await uow.Users.ExistsByRoleIdAsync(id, ct))
|
|
||||||
{
|
|
||||||
throw new BadRequestException("Cannot delete a role that is assigned to accounts");
|
|
||||||
}
|
|
||||||
|
|
||||||
uow.Roles.Remove(role);
|
|
||||||
await uow.SaveChangesAsync(ct);
|
|
||||||
}
|
|
||||||
|
|
||||||
private static List<RolePermission> BuildPermissions(List<PermissionEntryDto> entries)
|
|
||||||
{
|
|
||||||
var byScreen = entries.Where(e => ScreenCatalog.Keys.Contains(e.Screen)).ToDictionary(e => e.Screen);
|
|
||||||
|
|
||||||
return ScreenCatalog.Keys.Select(key =>
|
|
||||||
{
|
|
||||||
byScreen.TryGetValue(key, out var entry);
|
|
||||||
return new RolePermission
|
|
||||||
{
|
|
||||||
Screen = key,
|
|
||||||
CanView = entry?.CanView ?? false,
|
|
||||||
CanCreate = entry?.CanCreate ?? false,
|
|
||||||
CanEdit = entry?.CanEdit ?? false,
|
|
||||||
CanDelete = entry?.CanDelete ?? false,
|
|
||||||
};
|
|
||||||
}).ToList();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -6,7 +6,6 @@ using Mws.Application.Common;
|
|||||||
using Mws.Application.Documents;
|
using Mws.Application.Documents;
|
||||||
using Mws.Application.Permissions;
|
using Mws.Application.Permissions;
|
||||||
using Mws.Application.Projects;
|
using Mws.Application.Projects;
|
||||||
using Mws.Application.Roles;
|
|
||||||
using Mws.Application.Tasks;
|
using Mws.Application.Tasks;
|
||||||
using Mws.Infrastructure.Authentication;
|
using Mws.Infrastructure.Authentication;
|
||||||
using Mws.Infrastructure.Persistence;
|
using Mws.Infrastructure.Persistence;
|
||||||
@@ -40,7 +39,6 @@ public static class DependencyInjection
|
|||||||
services.AddScoped<ITokenService, JwtTokenService>();
|
services.AddScoped<ITokenService, JwtTokenService>();
|
||||||
|
|
||||||
services.AddScoped<IPermissionService, PermissionService>();
|
services.AddScoped<IPermissionService, PermissionService>();
|
||||||
services.AddScoped<IRoleService, RoleService>();
|
|
||||||
services.AddScoped<IProjectService, ProjectService>();
|
services.AddScoped<IProjectService, ProjectService>();
|
||||||
services.AddScoped<IProjectMemberService, ProjectMemberService>();
|
services.AddScoped<IProjectMemberService, ProjectMemberService>();
|
||||||
services.AddScoped<IDocumentService, DocumentService>();
|
services.AddScoped<IDocumentService, DocumentService>();
|
||||||
|
|||||||
Reference in New Issue
Block a user