b1e38ac374
Completes VS-10/VS-12/VS-14 and makes the solution and Host actually
build and boot for the first time on this branch (main did not build
before this commit).
Root-cause fixes required to reach a green build/boot (not scoped to
J/K/L but blocking any verification of it):
- Restore Polly PackageVersion accidentally deleted from
Directory.Packages.props (broke KArtSell.Host).
- Remove MediatR dependency from Compliance/VS-04 (package was never
installed; ICommand/ICommandHandler/IMediator never existed) and
wire Endpoint -> Handler directly per this repo's convention.
- Migrate FastEndpoints v5 API calls (SendOkAsync/SendAsync/
SendCreatedAtAsync/SendNotFoundAsync, Description().WithName()) to
the v7 Send.* fluent API across ~10 endpoint files.
- Fix migrations 0036/0038/0039/0040: rewritten from invalid T-SQL
(`IF NOT EXISTS ... BEGIN ... END`) to idiomatic Postgres
(`CREATE TABLE/INDEX IF NOT EXISTS`) — these could not apply to any
fresh database before this fix.
- Collapse 3 duplicate cross-cutting abstractions that shadowed the
BuildingBlocks versions and caused type-mismatch compile errors:
IKrxDataService, IOutboxWriter (ReconcileTradeHandler), IClock
(ApprovalWorkflow/ApprovalPolicy).
- Inject IClock (BuildingBlocks.Time) in place of direct
DateTime.Now/UtcNow across 19 files to satisfy the architecture
test AGENTS.md#DateTime-abstraction rule (13/13 architecture tests
now pass, was 12/13).
- Register all new and previously-unregistered slices in
Program.cs DI (SellDecision, TradeExecution, PortfolioReconciliation,
Compliance, Features/ApprovalWorkflow) — the Host had never
successfully completed a boot with this code present.
- Disable ("[DontRegister]") the older, route-colliding
ApprovalWorkflow/ (Workstream H) endpoint set in favor of
Features/ApprovalWorkflow/ (Workstream G, matches the documented
Features/<Slice>/ convention); kept for its existing test coverage.
See TECH_DEBT-017 for the follow-up decision needed.
Verified: dotnet build 0 errors/0 warnings; architecture tests 13/13;
unit tests 54/54 + 18/18; integration tests 34/36 (2 failures are a
local test-DB migration-journal/schema mismatch, not a code defect);
Host boots cleanly and registers all 34 endpoints.
New tech debt recorded: DEBT-017 (duplicate VS-03 implementation),
DEBT-018 (outbox write not co-transactional with entity write in
TradeExecution/PortfolioReconciliation), DEBT-019 (duplicate
BuildingBlocks-shadowing abstractions, partially resolved).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
95 lines
3.2 KiB
C#
95 lines
3.2 KiB
C#
using FastEndpoints;
|
|
using KArtSell.BuildingBlocks.Time;
|
|
using Microsoft.AspNetCore.Http;
|
|
using Microsoft.Extensions.Logging;
|
|
|
|
namespace KArtSell.Modules.ModelOperations.Compliance;
|
|
|
|
/// <summary>
|
|
/// Submit GDPR right-to-be-forgotten request.
|
|
/// POST /compliance/gdpr-request
|
|
/// </summary>
|
|
public class SubmitGdprRequestDto
|
|
{
|
|
public Guid CustomerId { get; set; }
|
|
public string Reason { get; set; } = "Right to be forgotten (GDPR Article 17)";
|
|
}
|
|
|
|
public class GdprRequestResponseDto
|
|
{
|
|
public Guid GdprTrackingId { get; set; }
|
|
public string Status { get; set; } = "IN_PROGRESS";
|
|
public DateTime EstimatedCompletion { get; set; }
|
|
public string Message { get; set; } = string.Empty;
|
|
}
|
|
|
|
public class SubmitGdprRequestEndpoint : Endpoint<SubmitGdprRequestDto, GdprRequestResponseDto>
|
|
{
|
|
private readonly ProcessGdprRequestHandler _handler;
|
|
private readonly IClock _clock;
|
|
private readonly ILogger<SubmitGdprRequestEndpoint> _logger;
|
|
|
|
public SubmitGdprRequestEndpoint(ProcessGdprRequestHandler handler, IClock clock, ILogger<SubmitGdprRequestEndpoint> logger)
|
|
{
|
|
_handler = handler;
|
|
_clock = clock;
|
|
_logger = logger;
|
|
}
|
|
|
|
public override void Configure()
|
|
{
|
|
Post("/compliance/gdpr-request");
|
|
AllowAnonymous(); // RBAC enforced at handler level (Data Admin/Compliance Officer role)
|
|
Summary(x =>
|
|
{
|
|
x.Summary = "Submit GDPR Request";
|
|
x.Description = "Submit right-to-be-forgotten request for customer data redaction";
|
|
});
|
|
}
|
|
|
|
public override async Task HandleAsync(SubmitGdprRequestDto req, CancellationToken ct)
|
|
{
|
|
try
|
|
{
|
|
var trackingId = Guid.NewGuid();
|
|
var now = _clock.UtcNow.UtcDateTime;
|
|
var correlationId = HttpContext.Request.Headers.TryGetValue("X-Correlation-ID", out var header)
|
|
? Guid.Parse(header.ToString())
|
|
: Guid.NewGuid();
|
|
|
|
var command = new ProcessGdprRequestCommand
|
|
{
|
|
TrackingId = trackingId,
|
|
CustomerId = req.CustomerId,
|
|
RequestDate = now,
|
|
Reason = req.Reason,
|
|
CorrelationId = correlationId
|
|
};
|
|
|
|
await _handler.Handle(command, ct);
|
|
|
|
var response = new GdprRequestResponseDto
|
|
{
|
|
GdprTrackingId = trackingId,
|
|
Status = "IN_PROGRESS",
|
|
EstimatedCompletion = now.AddHours(24),
|
|
Message = $"GDPR request {trackingId} submitted. Redaction will complete within 24 hours."
|
|
};
|
|
|
|
await Send.ResponseAsync(response, StatusCodes.Status202Accepted, ct);
|
|
|
|
_logger.LogInformation(
|
|
"GDPR request {TrackingId} submitted for customer {CustomerId}",
|
|
trackingId, req.CustomerId);
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
_logger.LogError(ex, "Failed to submit GDPR request for customer {CustomerId}", req.CustomerId);
|
|
await Send.ResponseAsync(
|
|
new GdprRequestResponseDto { Message = "Failed to submit request" },
|
|
StatusCodes.Status500InternalServerError,
|
|
ct);
|
|
}
|
|
}
|
|
}
|