package com.flightticket.config;

import io.swagger.v3.oas.models.Components;
import io.swagger.v3.oas.models.OpenAPI;
import io.swagger.v3.oas.models.info.Contact;
import io.swagger.v3.oas.models.info.Info;
import io.swagger.v3.oas.models.info.License;
import io.swagger.v3.oas.models.security.SecurityRequirement;
import io.swagger.v3.oas.models.security.SecurityScheme;
import io.swagger.v3.oas.models.servers.Server;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;

import java.util.List;

@Configuration
public class OpenApiConfig {
    
    @Value("${server.port:8080}")
    private String serverPort;
    
    @Bean
    public OpenAPI customOpenAPI() {
        final String securitySchemeName = "bearerAuth";
        
        return new OpenAPI()
                .info(new Info()
                        .title("B2B Flight Ticketing Platform API")
                        .version("1.0.0")
                        .description("""
                                A comprehensive B2B flight ticketing platform that enables non-IATA agencies to search, 
                                book, and issue flight tickets through a master IATA agency's Amadeus connection.
                                
                                ## Key Features
                                - OAuth 2.0/Keycloak authentication with MFA for admin roles
                                - Multi-tenant architecture with complete data isolation
                                - Prepaid wallet system with atomic transactions
                                - Real-time flight search via Amadeus GDS
                                - PNR creation and ticket issuance
                                - Comprehensive audit logging
                                - Role-based access control (SUPER_ADMIN, AGENCY_ADMIN, HR_USER, FINANCE_USER, AGENT)
                                - Agency subscription management (MONTHLY/ANNUAL)
                                - Automated subscription deactivation
                                - Rate limiting and API throttling
                                
                                ## Authentication
                                All endpoints (except /api/v1/auth/login) require a valid JWT token obtained from the login endpoint.
                                Admin roles (SUPER_ADMIN, AGENCY_ADMIN) require MFA verification.
                                
                                ## Multi-Tenancy
                                The platform supports multiple sub-agencies with complete data isolation. Each agency has:
                                - Unique matricule number
                                - Separate wallet with prepaid credits
                                - Custom markup configuration
                                - Independent user management
                                - Subscription-based access (MONTHLY or ANNUAL)
                                
                                ## Workflow
                                1. Super_Admin creates and verifies agencies
                                2. Agency_Admin manages users within their agency
                                3. Finance_User manages wallet recharges
                                4. Agents search flights, create bookings, and issue tickets
                                5. All transactions are logged and auditable
                                """)
                        .contact(new Contact()
                                .name("B2B Flight Platform Support")
                                .email("support@b2bflight.com"))
                        .license(new License()
                                .name("Proprietary")
                                .url("https://b2bflight.com/license")))
                .servers(List.of(
                        new Server()
                                .url("http://localhost:" + serverPort)
                                .description("Local Development Server"),
                        new Server()
                                .url("https://api.b2bflight.com")
                                .description("Production Server")))
                .addSecurityItem(new SecurityRequirement().addList(securitySchemeName))
                .components(new Components()
                        .addSecuritySchemes(securitySchemeName,
                                new SecurityScheme()
                                        .name(securitySchemeName)
                                        .type(SecurityScheme.Type.HTTP)
                                        .scheme("bearer")
                                        .bearerFormat("JWT")
                                        .description("""
                                                JWT token obtained from /api/v1/auth/login endpoint.
                                                
                                                The token contains:
                                                - User ID and username
                                                - Agency ID (for non-Super_Admin users)
                                                - Roles and permissions
                                                - Token expiration time
                                                
                                                Include the token in the Authorization header as: Bearer {token}
                                                """)));
    }
}
