#!/bin/bash
# API Testing Script for B2B Flight Ticketing Platform

set -e

KEYCLOAK_URL="http://localhost:8080"
API_URL="http://localhost:8081"
REALM="b2b-flight-platform"
CLIENT_ID="b2b-flight-backend"
CLIENT_SECRET="b2b-flight-backend-secret"
USERNAME="superadmin"
PASSWORD="admin123"

echo "🔐 B2B Flight Ticketing Platform - API Test"
echo "==========================================="
echo ""

# Get access token
echo "1️⃣  Getting access token..."
TOKEN_RESPONSE=$(curl -s -X POST "${KEYCLOAK_URL}/realms/${REALM}/protocol/openid-connect/token" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "client_id=${CLIENT_ID}" \
  -d "client_secret=${CLIENT_SECRET}" \
  -d "username=${USERNAME}" \
  -d "password=${PASSWORD}" \
  -d "grant_type=password")

ACCESS_TOKEN=$(echo $TOKEN_RESPONSE | jq -r '.access_token')
REFRESH_TOKEN=$(echo $TOKEN_RESPONSE | jq -r '.refresh_token')

if [ "$ACCESS_TOKEN" == "null" ] || [ -z "$ACCESS_TOKEN" ]; then
    echo "❌ Failed to get access token"
    echo "Response: $TOKEN_RESPONSE"
    exit 1
fi

echo "✅ Access token obtained"
echo "   Token: ${ACCESS_TOKEN:0:50}..."
echo ""

# Test public endpoint (no auth required)
echo "2️⃣  Testing public health endpoint..."
HEALTH_RESPONSE=$(curl -s "${API_URL}/actuator/health")
HEALTH_STATUS=$(echo $HEALTH_RESPONSE | jq -r '.status')
echo "   Status: $HEALTH_STATUS"
echo ""

# Test authenticated endpoint - Dashboard
echo "3️⃣  Testing authenticated endpoint (Dashboard)..."
DASHBOARD_RESPONSE=$(curl -s -X GET "${API_URL}/api/backoffice/dashboard" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json")

DASHBOARD_STATUS=$(echo $DASHBOARD_RESPONSE | jq -r 'if type=="object" then "success" else "error" end')

if [ "$DASHBOARD_STATUS" == "success" ]; then
    echo "✅ Dashboard endpoint accessible"
    echo "   Response:"
    echo "$DASHBOARD_RESPONSE" | jq '.'
else
    echo "⚠️  Dashboard response:"
    echo "$DASHBOARD_RESPONSE"
fi
echo ""

# Test getting all agencies
echo "4️⃣  Testing Get All Agencies endpoint..."
AGENCIES_RESPONSE=$(curl -s -X GET "${API_URL}/api/agencies" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json")

echo "   Response:"
echo "$AGENCIES_RESPONSE" | jq '.'
echo ""

# Test system configuration
echo "5️⃣  Testing System Configuration endpoint..."
CONFIG_RESPONSE=$(curl -s -X GET "${API_URL}/api/backoffice/configuration" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json")

echo "   Response:"
echo "$CONFIG_RESPONSE" | jq '.'
echo ""

echo "✅ API Testing Complete!"
echo ""
echo "📋 Summary:"
echo "   - Access Token: ✅ Obtained"
echo "   - Public Endpoint: ✅ Accessible"
echo "   - Authenticated Endpoints: ✅ Working"
echo ""
echo "🔑 Your credentials:"
echo "   Username: ${USERNAME}"
echo "   Password: ${PASSWORD}"
echo "   Access Token: ${ACCESS_TOKEN:0:50}..."
echo ""
echo "💡 To use the API:"
echo "   1. Get a token using the command above"
echo "   2. Include it in requests: -H \"Authorization: Bearer \$TOKEN\""
echo "   3. Access Swagger UI: http://localhost:8081/swagger-ui.html"
echo ""
