summaryrefslogtreecommitdiff
path: root/Controllers/UserAccountSessionsController.cs
blob: ebeca96f51028ccf36cb10f67abb1722fb0b9dc2 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
using Microsoft.AspNetCore.Identity;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;
using BackendPIA.Forms;
using BackendPIA.Models;
using BackendPIA.Services;
using BackendPIA.Errors;
using BackendPIA.Logics;

namespace BackendPIA.Controllers {
    [Route("api/")]
    [ApiController]
    public class AdministratorSessionsController : ControllerBase {
        private readonly ApplicationDbContext _context;
        private readonly ITokenGenerator _token_generator;
        private readonly UserManager<UserAccount> _manager;

        public AdministratorSessionsController(ITokenGenerator token_generator, UserManager<UserAccount> manager, ApplicationDbContext context) {
            _token_generator = token_generator;
            _manager = manager;
            _context = context;
        }

        [HttpPost("login")]
        public async Task<ActionResult<AuthenticationToken>> Create(UserAccountLoginForm form) {
            CreateUserAccountSessionLogic logic = new CreateUserAccountSessionLogic(_token_generator, _manager, form);
            var result = await logic.Call();

            if(result)
                return Ok(logic.Token);

            return StatusCode(401, new InvalidLoginError(401, "Check your credentials"));
        }

        [Authorize(Policy = "ValidToken")]
        [HttpDelete("logout")]
        public async Task<ActionResult> Delete() {
            string email = HttpContext.User.Claims.Where(c => c.Type.Contains("email")).First().Value;
            DestroyUserAccountSessionLogic logic = new DestroyUserAccountSessionLogic(_manager, email);
            bool result = await logic.Call();

            if(result)
                return Ok();

            return NotFound(new NotFoundError(404, "Couldn't find the user."));
        }

        // [Authorize]
        [HttpPost("refresh")]
        public async Task<ActionResult<AuthenticationToken>> Refresh(AuthenticationToken form) {
            RefreshTokenLogic logic = new RefreshTokenLogic(_token_generator, _manager, form);
            bool result = await logic.Call();

            if(result)
                return Ok(logic.Token);

            return StatusCode(403, new ExpiredSessionError(401, "Check your refresh token"));
        }    
    }
}