using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Mvc; using vendorApproverBackend.Entities; using vendorApproverBackend.Requests; using vendorApproverBackend.Services; using vendorApproverBackend.Interfaces; using System.Security.Claims; namespace vendorApproverBackend.Controllers { [ApiController] [Route("api/v1/user")] public class UsersController : ControllerBase { private readonly UserService _userService; private readonly IEmailService _emailService; public UsersController(UserService userService, IEmailService emailService) { _userService = userService; _emailService = emailService; } [HttpGet("current_user")] [Authorize(Roles = "ADMIN,EMPLOYEE,VENDOR,FINANCIAL,MANAGER,PERFERMANCE_MANAGER")] public async Task> GetCurrentUser() { var username = User.FindFirstValue(ClaimTypes.Name); if (string.IsNullOrEmpty(username)) { return Unauthorized("Username claim not found in token."); } var user = await _userService.FindByUsernameAsync(username); if (user == null) { return NotFound("User not found."); } return Ok(user); } [HttpPatch("change-password/{userId}")] [Authorize(Roles = "ADMIN,EMPLOYEE,VENDOR,FINANCIAL,MANAGER,PERFERMANCE_MANAGER")] public async Task ChangePassword(long userId, [FromBody] ChangePasswordRequest model) { var userToUpdate = await _userService.FindByIdAsync(userId); if (userToUpdate == null) { return NotFound($"User with ID {userId} not found."); } userToUpdate.Password = model.NewPassword; var result = await _userService.UpdateUserPassAsync(userToUpdate); return Ok(result); } [HttpPost("send-otp-test")] public async Task SendOtpTest([FromBody] SendOtpTestRequest request) { try { if (string.IsNullOrEmpty(request.Email)) { return BadRequest(new { success = false, message = "Email is required" }); } if (string.IsNullOrEmpty(request.OtpCode)) { return BadRequest(new { success = false, message = "OTP code is required" }); } User user; if (request.UserId.HasValue) { user = await _userService.FindByIdAsync(request.UserId.Value); if (user == null) { return NotFound(new { success = false, message = $"User with ID {request.UserId} not found" }); } } else { user = new User { Name = request.UserName ?? "Test User", Email = request.Email }; } await _emailService.SendOtpEmailAsync(request.Email, user, request.OtpCode); return Ok(new { success = true, message = "OTP email sent successfully", details = new { email = request.Email, userName = user.Name, otpCode = request.OtpCode } }); } catch (Exception ex) { return StatusCode(500, new { success = false, message = "Failed to send OTP email", error = ex.Message }); } } [HttpPatch("update_admin_and_employee_profile/{userId}")] [Authorize(Roles = "ADMIN, EMPLOYEE,MANAGER,PERFERMANCE_MANAGER")] public async Task> UpdateEmployeeProfile(long userId, [FromBody] UpdateProfileRequest request) { try { var updatedUser = await _userService.UpdateUserProfileAsync(userId, request); if (updatedUser == null) { return NotFound($"User with ID {userId} not found."); } return Ok(updatedUser); } catch (Exception e) { return StatusCode(StatusCodes.Status406NotAcceptable, $"An error occurred while updating the profile: {e.Message}"); } } [HttpPatch("update_vendor_profile/{UserId}")] [Authorize(Roles = "VENDOR,ADMIN,PERFERMANCE_MANAGER")] public async Task> UpdateVendorProfile(long userId, [FromBody] UpdateVendorProfile request) { try { var updatedUser = await _userService.UpdateVendorProfileAsync(userId, request); if (updatedUser == null) { return NotFound($"Vendor profile not found for user ID {userId}."); } return Ok(updatedUser); } catch (Exception e) { return StatusCode(StatusCodes.Status406NotAcceptable, $"An error occurred while updating the vendor profile: {e.Message}"); } } [HttpPatch("update_password/{userId}")] [Authorize(Roles = "ADMIN,EMPLOYEE,VENDOR,FINANCIAL,MANAGER,PERFERMANCE_MANAGER")] public async Task UpdatePassword(long userId, [FromBody] UpdatePasswordRequest request) { try { var updatedUser = await _userService.UpdateUserPasswordAsync(userId, request); if (updatedUser == null) { return NotFound($"User with ID {userId} not found."); } return Ok(new { Message = "Password updated successfully." }); } catch (InvalidOperationException ex) when (ex.Message == "Old password is not correct.") { return StatusCode(StatusCodes.Status406NotAcceptable, "Old password is not correct."); } catch (Exception e) { return StatusCode(StatusCodes.Status500InternalServerError, $"An error occurred while updating the password: {e.Message}"); } } } }