using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Mvc; using System.Security.Claims; using vendorApproverBackend.DTOs; using vendorApproverBackend.Responses; using vendorApproverBackend.Services; namespace vendorApproverBackend.Controllers; [ApiController] [Route("api/linked-accounts")] [Authorize(Roles = "ADMIN,EMPLOYEE,FINANCIAL,MANAGER,PERFERMANCE_MANAGER")] public class LinkedAccountController : ControllerBase { private readonly LinkedAccountService _linkedAccountService; public LinkedAccountController(LinkedAccountService linkedAccountService) { _linkedAccountService = linkedAccountService; } [HttpGet] public async Task>> GetLinkedAccounts([FromQuery] string deviceId) { if (string.IsNullOrEmpty(deviceId)) return BadRequest("deviceId is required."); var accounts = await _linkedAccountService.GetLinkedAccountsAsync(deviceId); return Ok(accounts); } [HttpDelete("forget")] public async Task ForgetAccount([FromQuery] string deviceId) { if (string.IsNullOrEmpty(deviceId)) return BadRequest("deviceId is required."); var userIdClaim = User.FindFirst("userId")?.Value ?? User.FindFirst(ClaimTypes.NameIdentifier)?.Value; if (userIdClaim == null) return Unauthorized(); var userId = long.Parse(userIdClaim); var result = await _linkedAccountService.ForgetAccountAsync(userId, deviceId); if (!result) return NotFound("Device not linked to this account."); return Ok("Account forgotten on this device."); } // POST api/linked-accounts/switch // Pre-authorized: requires a valid JWT, no password needed [HttpPost("switch")] public async Task> SwitchAccount([FromBody] SwitchAccountRequest request) { if (string.IsNullOrEmpty(request.Email) || string.IsNullOrEmpty(request.DeviceId)) return BadRequest("Email and deviceId are required."); var response = await _linkedAccountService.SwitchAccountAsync(request.Email, request.DeviceId); if (response == null) return NotFound("Account not found, not active, or not linked to this device."); return Ok(response); } } public record SwitchAccountRequest(string Email, string DeviceId);