| | | 1 | | using Anichron.Core.Data; |
| | | 2 | | using Anichron.Core.Data.Repository; |
| | | 3 | | using Anichron.Core.Domain; |
| | | 4 | | |
| | | 5 | | namespace Anichron.API.Services; |
| | | 6 | | |
| | | 7 | | public interface IAdminUserService |
| | | 8 | | { |
| | | 9 | | Task<List<User>> GetAllAsync(CancellationToken ct); |
| | | 10 | | Task<User?> GetByIdAsync(Guid id, CancellationToken ct); |
| | | 11 | | Task<AuthResult<User>> UpdateAsync(Guid callerId, Guid targetId, bool? isAdmin, bool? isDisabled, CancellationToken |
| | | 12 | | Task<AuthResult> DeleteAsync(Guid callerId, Guid targetId, CancellationToken ct); |
| | | 13 | | } |
| | | 14 | | |
| | 14 | 15 | | public sealed class AdminUserService( |
| | 14 | 16 | | IUserRepository users, |
| | 14 | 17 | | IUnitOfWork unitOfWork, |
| | 14 | 18 | | IClock clock, |
| | 14 | 19 | | ITokenService tokenService) : IAdminUserService |
| | | 20 | | { |
| | | 21 | | public Task<List<User>> GetAllAsync(CancellationToken ct) |
| | 1 | 22 | | => users.GetAllAsync(ct); |
| | | 23 | | |
| | | 24 | | public Task<User?> GetByIdAsync(Guid id, CancellationToken ct) |
| | 2 | 25 | | => users.FindByIdWithConfigsAsync(id, ct); |
| | | 26 | | |
| | | 27 | | public async Task<AuthResult<User>> UpdateAsync(Guid callerId, Guid targetId, bool? isAdmin, bool? isDisabled, Cance |
| | 8 | 28 | | { |
| | 8 | 29 | | if (callerId == targetId) |
| | 1 | 30 | | return AuthResult.Fail<User>(AuthError.CannotModifySelf); |
| | | 31 | | |
| | 7 | 32 | | var user = await users.FindByIdWithConfigsAsync(targetId, ct); |
| | 7 | 33 | | if (user is null) |
| | 1 | 34 | | return AuthResult.Fail<User>(AuthError.UserNotFound); |
| | | 35 | | |
| | 6 | 36 | | if (!isAdmin.HasValue && !isDisabled.HasValue) |
| | 1 | 37 | | return AuthResult.Ok(user); |
| | | 38 | | |
| | 5 | 39 | | if (isAdmin.HasValue) |
| | 1 | 40 | | user.IsAdmin = isAdmin.Value; |
| | | 41 | | |
| | 5 | 42 | | var shouldRevokeSessions = isDisabled == true && !user.IsDisabled; |
| | 5 | 43 | | if (isDisabled.HasValue) |
| | 4 | 44 | | user.IsDisabled = isDisabled.Value; |
| | | 45 | | |
| | | 46 | | // Both writes, or neither: revocation goes through ExecuteUpdateAsync, which bypasses the |
| | | 47 | | // change tracker and commits immediately, so untransacted a failing save would leave the |
| | | 48 | | // sessions revoked and the user mutation lost. |
| | 5 | 49 | | await unitOfWork.ExecuteInTransactionAsync(async () => |
| | 5 | 50 | | { |
| | 5 | 51 | | if (shouldRevokeSessions) |
| | 5 | 52 | | await tokenService.MarkAllSessionsRevokedAsync(targetId, clock.GetCurrentInstant(), ct); |
| | 5 | 53 | | |
| | 5 | 54 | | await unitOfWork.SaveChangesAsync(ct); |
| | 5 | 55 | | }, ct); |
| | | 56 | | |
| | 4 | 57 | | return AuthResult.Ok(user); |
| | 7 | 58 | | } |
| | | 59 | | |
| | | 60 | | public async Task<AuthResult> DeleteAsync(Guid callerId, Guid targetId, CancellationToken ct) |
| | 3 | 61 | | { |
| | 3 | 62 | | if (callerId == targetId) |
| | 1 | 63 | | return AuthResult.Fail(AuthError.CannotModifySelf); |
| | | 64 | | |
| | 2 | 65 | | var user = await users.FindByIdAsync(targetId, ct); |
| | 2 | 66 | | if (user is null) |
| | 1 | 67 | | return AuthResult.Fail(AuthError.UserNotFound); |
| | | 68 | | |
| | | 69 | | // Same revoke-then-save pairing as UpdateAsync, transacted for the same reason — here the |
| | | 70 | | // loss would be a user whose sessions are all revoked but whose row was never deleted. |
| | 1 | 71 | | users.Remove(user); |
| | 1 | 72 | | await unitOfWork.ExecuteInTransactionAsync(async () => |
| | 1 | 73 | | { |
| | 1 | 74 | | await tokenService.MarkAllSessionsRevokedAsync(targetId, clock.GetCurrentInstant(), ct); |
| | 1 | 75 | | await unitOfWork.SaveChangesAsync(ct); |
| | 1 | 76 | | }, ct); |
| | | 77 | | |
| | 1 | 78 | | return AuthResult.Ok(); |
| | 3 | 79 | | } |
| | | 80 | | } |