aboutsummaryrefslogtreecommitdiffstats
path: root/code/api/src/Endpoints/Internal/PasswordResetRequests/CreateResetRequestRoute.cs
blob: bb72d381d9a94f0ff1ea2154a04fc76da6714bf2 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
namespace IOL.GreatOffice.Api.Endpoints.Internal.PasswordResetRequests;

public class Route : RouteBaseAsync.WithRequest<CreateResetRequestPayload>.WithActionResult
{
    private readonly ILogger<Route> _logger;
    private readonly PasswordResetService _passwordResetService;
    private readonly MainAppDatabase _database;

    public Route(ILogger<Route> logger, PasswordResetService passwordResetService, MainAppDatabase database) {
        _logger = logger;
        _passwordResetService = passwordResetService;
        _database = database;
    }

    /// <summary>
    /// Create a new password reset request.
    /// </summary>
    /// <param name="request"></param>
    /// <param name="cancellationToken"></param>
    /// <returns></returns>
    [AllowAnonymous]
    [HttpPost("~/_/password-reset-request/create")]
    public override async Task<ActionResult> HandleAsync(CreateResetRequestPayload request, CancellationToken cancellationToken = default) {
        if (!request.Username.IsValidEmailAddress()) {
            _logger.LogInformation("Username is invalid, not doing request for password change");
            return KnownProblem("Invalid email address", request.Username + " looks like an invalid email address");
        }

        var tz = GetRequestTimeZone(_logger);
        _logger.LogInformation("Creating forgot password request with local date time: " + tz.LocalDateTime.ToString("u"));

        try {
            var user = _database.Users.SingleOrDefault(c => c.Username.Equals(request.Username));
            if (user != default) {
                await _passwordResetService.AddRequestAsync(user, tz.TimeZoneInfo, cancellationToken);
                return Ok();
            }

            _logger.LogInformation("User was not found, not doing request for password change");
            return Ok();
        } catch (Exception e) {
            _logger.LogError(e, "_/password-reset-request/create threw an exception");
            return Ok();
        }
    }
}