using MediatR; using mws.backend.dotnet.application.Audit; using mws.backend.dotnet.application.Common; namespace mws.backend.dotnet.application.Permissions; public record DeleteRoleCommand(Guid Id) : IRequest, IAuditableRequest { public string Action => "Role.Delete"; public string EntityType => "Role"; public Guid? EntityId => Id; } public class DeleteRoleHandler(IUnitOfWork uow, IAuditContext auditContext) : IRequestHandler { public async Task Handle(DeleteRoleCommand command, CancellationToken ct) { var role = await uow.Roles.GetByIdAsync(command.Id, ct) ?? throw new NotFoundException("Role not found"); if (role.IsSystem) { throw new BadRequestException("Cannot delete a system role"); } if (await uow.Users.ExistsByRoleIdAsync(command.Id, ct)) { throw new BadRequestException("Cannot delete a role that is assigned to accounts"); } uow.Roles.Remove(role); await uow.SaveChangesAsync(ct); auditContext.EntityName = role.Name; } }