Feature/breadboard #4
@@ -17,7 +17,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
|
||||||
var people = await medicalDocsService.GetPeopleAsync();
|
var people = await medicalDocsService.GetPeopleAsync(userId.Value);
|
||||||
return Ok(people);
|
return Ok(people);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -31,13 +31,68 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
if (string.IsNullOrWhiteSpace(request.Name))
|
if (string.IsNullOrWhiteSpace(request.Name))
|
||||||
return BadRequest(new { error = "Name is required" });
|
return BadRequest(new { error = "Name is required" });
|
||||||
|
|
||||||
var person = await medicalDocsService.CreatePersonAsync(request.Name.Trim(), request.DateOfBirth, request.Notes);
|
var person = await medicalDocsService.CreatePersonAsync(userId.Value, request.Name.Trim(), request.DateOfBirth, request.Notes);
|
||||||
if (person == null)
|
if (person == null)
|
||||||
return StatusCode(500, new { error = "Failed to create person" });
|
return StatusCode(500, new { error = "Failed to create person" });
|
||||||
|
|
||||||
return Ok(person);
|
return Ok(person);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// --- People Access ---
|
||||||
|
|
||||||
|
[HttpGet("people/{personId}/access")]
|
||||||
|
public async Task<IActionResult> GetPersonAccess(long personId)
|
||||||
|
{
|
||||||
|
var userId = GetUserIdFromAuth();
|
||||||
|
if (userId == null) return Unauthorized();
|
||||||
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
|
var users = await medicalDocsService.GetPeopleAccessAsync(personId);
|
||||||
|
return Ok(users);
|
||||||
|
}
|
||||||
|
|
||||||
|
[HttpPost("people/{personId}/access")]
|
||||||
|
public async Task<IActionResult> GrantPersonAccess(long personId, [FromBody] GrantAccessRequest request)
|
||||||
|
{
|
||||||
|
var userId = GetUserIdFromAuth();
|
||||||
|
if (userId == null) return Unauthorized();
|
||||||
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
|
if (string.IsNullOrWhiteSpace(request.Username))
|
||||||
|
return BadRequest(new { error = "Username is required" });
|
||||||
|
|
||||||
|
var targetUser = await dbExecutor.ExecuteReaderAsync(
|
||||||
|
"SELECT id FROM app.users WHERE LOWER(username) = LOWER(@username)",
|
||||||
|
reader => reader.GetInt64(0),
|
||||||
|
new { username = request.Username.Trim() });
|
||||||
|
|
||||||
|
if (targetUser == 0)
|
||||||
|
return NotFound(new { error = "User not found" });
|
||||||
|
|
||||||
|
var success = await medicalDocsService.GrantAccessAsync(personId, targetUser);
|
||||||
|
if (!success)
|
||||||
|
return StatusCode(500, new { error = "Failed to grant access" });
|
||||||
|
|
||||||
|
return Ok(new { success = true });
|
||||||
|
}
|
||||||
|
|
||||||
|
[HttpDelete("people/{personId}/access/{targetUserId}")]
|
||||||
|
public async Task<IActionResult> RevokePersonAccess(long personId, long targetUserId)
|
||||||
|
{
|
||||||
|
var userId = GetUserIdFromAuth();
|
||||||
|
if (userId == null) return Unauthorized();
|
||||||
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
|
var success = await medicalDocsService.RevokeAccessAsync(personId, targetUserId);
|
||||||
|
if (!success)
|
||||||
|
return BadRequest(new { error = "Cannot revoke access — at least one user must have access" });
|
||||||
|
|
||||||
|
return Ok(new { success = true });
|
||||||
|
}
|
||||||
|
|
||||||
// --- Documents ---
|
// --- Documents ---
|
||||||
|
|
||||||
[HttpGet("documents")]
|
[HttpGet("documents")]
|
||||||
@@ -46,6 +101,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (personId.HasValue && !await HasPersonAccess(userId.Value, personId.Value)) return Forbid();
|
||||||
|
|
||||||
if (limit < 1 || limit > 100) limit = 50;
|
if (limit < 1 || limit > 100) limit = 50;
|
||||||
if (offset < 0) offset = 0;
|
if (offset < 0) offset = 0;
|
||||||
@@ -75,6 +131,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0)
|
if (personId <= 0)
|
||||||
return BadRequest(new { error = "personId is required" });
|
return BadRequest(new { error = "personId is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
if (limit < 1 || limit > 100) limit = 50;
|
if (limit < 1 || limit > 100) limit = 50;
|
||||||
if (offset < 0) offset = 0;
|
if (offset < 0) offset = 0;
|
||||||
@@ -92,6 +149,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0)
|
if (personId <= 0)
|
||||||
return BadRequest(new { error = "personId is required" });
|
return BadRequest(new { error = "personId is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
var tags = await medicalDocsService.GetPersonTagsAsync(personId);
|
var tags = await medicalDocsService.GetPersonTagsAsync(personId);
|
||||||
return Ok(tags);
|
return Ok(tags);
|
||||||
@@ -104,6 +162,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
if (file == null || file.Length == 0)
|
if (file == null || file.Length == 0)
|
||||||
return BadRequest(new { error = "No file provided" });
|
return BadRequest(new { error = "No file provided" });
|
||||||
@@ -126,6 +185,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (request.PersonId <= 0)
|
if (request.PersonId <= 0)
|
||||||
return BadRequest(new { error = "Person is required" });
|
return BadRequest(new { error = "Person is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, request.PersonId)) return Forbid();
|
||||||
if (string.IsNullOrWhiteSpace(request.Title))
|
if (string.IsNullOrWhiteSpace(request.Title))
|
||||||
return BadRequest(new { error = "Title is required" });
|
return BadRequest(new { error = "Title is required" });
|
||||||
|
|
||||||
@@ -144,6 +204,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "document", id)) return Forbid();
|
||||||
|
|
||||||
var doc = await medicalDocsService.GetDocumentByIdAsync(id);
|
var doc = await medicalDocsService.GetDocumentByIdAsync(id);
|
||||||
if (doc == null) return NotFound(new { error = "Document not found" });
|
if (doc == null) return NotFound(new { error = "Document not found" });
|
||||||
@@ -157,6 +218,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "document", id)) return Forbid();
|
||||||
|
|
||||||
var doc = await medicalDocsService.GetDocumentByIdAsync(id);
|
var doc = await medicalDocsService.GetDocumentByIdAsync(id);
|
||||||
if (doc == null) return NotFound(new { error = "Document not found" });
|
if (doc == null) return NotFound(new { error = "Document not found" });
|
||||||
@@ -176,6 +238,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "document", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.UpdateDocumentAsync(id, request.Title, request.Description, request.DocumentDate, request.Classification, request.DoctorId);
|
var success = await medicalDocsService.UpdateDocumentAsync(id, request.Title, request.Description, request.DocumentDate, request.Classification, request.DoctorId);
|
||||||
if (!success) return NotFound(new { error = "Document not found" });
|
if (!success) return NotFound(new { error = "Document not found" });
|
||||||
@@ -189,6 +252,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "document", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.DeleteDocumentAsync(id);
|
var success = await medicalDocsService.DeleteDocumentAsync(id);
|
||||||
if (!success) return NotFound(new { error = "Document not found" });
|
if (!success) return NotFound(new { error = "Document not found" });
|
||||||
@@ -204,6 +268,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "document", id)) return Forbid();
|
||||||
|
|
||||||
var doc = await medicalDocsService.GetDocumentByIdAsync(id);
|
var doc = await medicalDocsService.GetDocumentByIdAsync(id);
|
||||||
if (doc == null) return NotFound(new { error = "Document not found" });
|
if (doc == null) return NotFound(new { error = "Document not found" });
|
||||||
@@ -260,12 +325,13 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "document", id)) return Forbid();
|
||||||
|
|
||||||
var tags = await medicalDocsService.GetDocumentTagsAsync(id);
|
var tags = await medicalDocsService.GetDocumentTagsAsync(id);
|
||||||
return Ok(tags);
|
return Ok(tags);
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- Doctors ---
|
// --- Doctors (shared, no per-person access check) ---
|
||||||
|
|
||||||
[HttpGet("doctors")]
|
[HttpGet("doctors")]
|
||||||
public async Task<IActionResult> GetDoctors()
|
public async Task<IActionResult> GetDoctors()
|
||||||
@@ -335,6 +401,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0)
|
if (personId <= 0)
|
||||||
return BadRequest(new { error = "personId is required" });
|
return BadRequest(new { error = "personId is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
var conditions = await medicalDocsService.GetConditionsAsync(personId);
|
var conditions = await medicalDocsService.GetConditionsAsync(personId);
|
||||||
return Ok(conditions);
|
return Ok(conditions);
|
||||||
@@ -349,6 +416,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (request.PersonId <= 0)
|
if (request.PersonId <= 0)
|
||||||
return BadRequest(new { error = "Person is required" });
|
return BadRequest(new { error = "Person is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, request.PersonId)) return Forbid();
|
||||||
if (string.IsNullOrWhiteSpace(request.Name))
|
if (string.IsNullOrWhiteSpace(request.Name))
|
||||||
return BadRequest(new { error = "Name is required" });
|
return BadRequest(new { error = "Name is required" });
|
||||||
|
|
||||||
@@ -365,6 +433,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "condition", id)) return Forbid();
|
||||||
|
|
||||||
if (string.IsNullOrWhiteSpace(request.Name))
|
if (string.IsNullOrWhiteSpace(request.Name))
|
||||||
return BadRequest(new { error = "Name is required" });
|
return BadRequest(new { error = "Name is required" });
|
||||||
@@ -381,6 +450,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "condition", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.DeleteConditionAsync(id);
|
var success = await medicalDocsService.DeleteConditionAsync(id);
|
||||||
if (!success) return NotFound(new { error = "Condition not found" });
|
if (!success) return NotFound(new { error = "Condition not found" });
|
||||||
@@ -399,6 +469,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0)
|
if (personId <= 0)
|
||||||
return BadRequest(new { error = "personId is required" });
|
return BadRequest(new { error = "personId is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
var prescriptions = await medicalDocsService.GetPrescriptionsAsync(personId);
|
var prescriptions = await medicalDocsService.GetPrescriptionsAsync(personId);
|
||||||
return Ok(prescriptions);
|
return Ok(prescriptions);
|
||||||
@@ -413,6 +484,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (request.PersonId <= 0)
|
if (request.PersonId <= 0)
|
||||||
return BadRequest(new { error = "Person is required" });
|
return BadRequest(new { error = "Person is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, request.PersonId)) return Forbid();
|
||||||
if (string.IsNullOrWhiteSpace(request.MedicationName))
|
if (string.IsNullOrWhiteSpace(request.MedicationName))
|
||||||
return BadRequest(new { error = "Medication name is required" });
|
return BadRequest(new { error = "Medication name is required" });
|
||||||
|
|
||||||
@@ -429,6 +501,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "prescription", id)) return Forbid();
|
||||||
|
|
||||||
if (string.IsNullOrWhiteSpace(request.MedicationName))
|
if (string.IsNullOrWhiteSpace(request.MedicationName))
|
||||||
return BadRequest(new { error = "Medication name is required" });
|
return BadRequest(new { error = "Medication name is required" });
|
||||||
@@ -445,6 +518,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "prescription", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.DeletePrescriptionAsync(id);
|
var success = await medicalDocsService.DeletePrescriptionAsync(id);
|
||||||
if (!success) return NotFound(new { error = "Prescription not found" });
|
if (!success) return NotFound(new { error = "Prescription not found" });
|
||||||
@@ -460,6 +534,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "prescription", id)) return Forbid();
|
||||||
|
|
||||||
var pickups = await medicalDocsService.GetPickupsAsync(id);
|
var pickups = await medicalDocsService.GetPickupsAsync(id);
|
||||||
return Ok(pickups);
|
return Ok(pickups);
|
||||||
@@ -471,6 +546,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "prescription", id)) return Forbid();
|
||||||
|
|
||||||
var pickup = await medicalDocsService.CreatePickupAsync(id, request.PickupDate, request.Quantity, request.Pharmacy, request.Cost, request.Notes);
|
var pickup = await medicalDocsService.CreatePickupAsync(id, request.PickupDate, request.Quantity, request.Pharmacy, request.Cost, request.Notes);
|
||||||
if (pickup == null)
|
if (pickup == null)
|
||||||
@@ -485,6 +561,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "pickup", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.DeletePickupAsync(id);
|
var success = await medicalDocsService.DeletePickupAsync(id);
|
||||||
if (!success) return NotFound(new { error = "Pickup not found" });
|
if (!success) return NotFound(new { error = "Pickup not found" });
|
||||||
@@ -503,6 +580,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0)
|
if (personId <= 0)
|
||||||
return BadRequest(new { error = "personId is required" });
|
return BadRequest(new { error = "personId is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
var providers = await medicalDocsService.GetProvidersAsync(personId);
|
var providers = await medicalDocsService.GetProvidersAsync(personId);
|
||||||
return Ok(providers);
|
return Ok(providers);
|
||||||
@@ -517,6 +595,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (request.PersonId <= 0)
|
if (request.PersonId <= 0)
|
||||||
return BadRequest(new { error = "Person is required" });
|
return BadRequest(new { error = "Person is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, request.PersonId)) return Forbid();
|
||||||
if (string.IsNullOrWhiteSpace(request.Name))
|
if (string.IsNullOrWhiteSpace(request.Name))
|
||||||
return BadRequest(new { error = "Name is required" });
|
return BadRequest(new { error = "Name is required" });
|
||||||
|
|
||||||
@@ -533,6 +612,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "provider", id)) return Forbid();
|
||||||
|
|
||||||
if (string.IsNullOrWhiteSpace(request.Name))
|
if (string.IsNullOrWhiteSpace(request.Name))
|
||||||
return BadRequest(new { error = "Name is required" });
|
return BadRequest(new { error = "Name is required" });
|
||||||
@@ -549,6 +629,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "provider", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.DeleteProviderAsync(id);
|
var success = await medicalDocsService.DeleteProviderAsync(id);
|
||||||
if (!success) return NotFound(new { error = "Provider not found" });
|
if (!success) return NotFound(new { error = "Provider not found" });
|
||||||
@@ -564,6 +645,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "provider", id)) return Forbid();
|
||||||
|
|
||||||
var payments = await medicalDocsService.GetProviderPaymentsAsync(id);
|
var payments = await medicalDocsService.GetProviderPaymentsAsync(id);
|
||||||
return Ok(payments);
|
return Ok(payments);
|
||||||
@@ -575,6 +657,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "provider", id)) return Forbid();
|
||||||
|
|
||||||
if (request.Amount <= 0)
|
if (request.Amount <= 0)
|
||||||
return BadRequest(new { error = "Amount must be greater than 0" });
|
return BadRequest(new { error = "Amount must be greater than 0" });
|
||||||
@@ -592,6 +675,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "provider-payment", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.DeleteProviderPaymentAsync(id);
|
var success = await medicalDocsService.DeleteProviderPaymentAsync(id);
|
||||||
if (!success) return NotFound(new { error = "Payment not found" });
|
if (!success) return NotFound(new { error = "Payment not found" });
|
||||||
@@ -610,6 +694,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0)
|
if (personId <= 0)
|
||||||
return BadRequest(new { error = "personId is required" });
|
return BadRequest(new { error = "personId is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
var bills = await medicalDocsService.GetBillsAsync(personId, providerId);
|
var bills = await medicalDocsService.GetBillsAsync(personId, providerId);
|
||||||
return Ok(bills);
|
return Ok(bills);
|
||||||
@@ -624,6 +709,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (request.PersonId <= 0)
|
if (request.PersonId <= 0)
|
||||||
return BadRequest(new { error = "Person is required" });
|
return BadRequest(new { error = "Person is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, request.PersonId)) return Forbid();
|
||||||
if (request.TotalAmount <= 0)
|
if (request.TotalAmount <= 0)
|
||||||
return BadRequest(new { error = "Amount must be greater than 0" });
|
return BadRequest(new { error = "Amount must be greater than 0" });
|
||||||
|
|
||||||
@@ -640,6 +726,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "bill", id)) return Forbid();
|
||||||
|
|
||||||
if (request.TotalAmount <= 0)
|
if (request.TotalAmount <= 0)
|
||||||
return BadRequest(new { error = "Amount must be greater than 0" });
|
return BadRequest(new { error = "Amount must be greater than 0" });
|
||||||
@@ -656,6 +743,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "bill", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.DeleteBillAsync(id);
|
var success = await medicalDocsService.DeleteBillAsync(id);
|
||||||
if (!success) return NotFound(new { error = "Bill not found" });
|
if (!success) return NotFound(new { error = "Bill not found" });
|
||||||
@@ -669,6 +757,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "bill", id)) return Forbid();
|
||||||
|
|
||||||
if (request.DocumentId <= 0)
|
if (request.DocumentId <= 0)
|
||||||
return BadRequest(new { error = "Document is required" });
|
return BadRequest(new { error = "Document is required" });
|
||||||
@@ -686,6 +775,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "bill", billId)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.UnlinkDocumentFromBillAsync(billId, docId);
|
var success = await medicalDocsService.UnlinkDocumentFromBillAsync(billId, docId);
|
||||||
if (!success) return NotFound(new { error = "Link not found" });
|
if (!success) return NotFound(new { error = "Link not found" });
|
||||||
@@ -701,6 +791,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "bill", id)) return Forbid();
|
||||||
|
|
||||||
var charges = await medicalDocsService.GetChargesAsync(id);
|
var charges = await medicalDocsService.GetChargesAsync(id);
|
||||||
return Ok(charges);
|
return Ok(charges);
|
||||||
@@ -712,6 +803,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "bill", id)) return Forbid();
|
||||||
|
|
||||||
if (string.IsNullOrWhiteSpace(request.Description))
|
if (string.IsNullOrWhiteSpace(request.Description))
|
||||||
return BadRequest(new { error = "Description is required" });
|
return BadRequest(new { error = "Description is required" });
|
||||||
@@ -731,6 +823,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
var userId = GetUserIdFromAuth();
|
var userId = GetUserIdFromAuth();
|
||||||
if (userId == null) return Unauthorized();
|
if (userId == null) return Unauthorized();
|
||||||
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
if (!await HasMedicalAccess(userId.Value)) return Forbid();
|
||||||
|
if (!await HasResourceAccess(userId.Value, "bill-charge", id)) return Forbid();
|
||||||
|
|
||||||
var success = await medicalDocsService.DeleteChargeAsync(id);
|
var success = await medicalDocsService.DeleteChargeAsync(id);
|
||||||
if (!success) return NotFound(new { error = "Charge not found" });
|
if (!success) return NotFound(new { error = "Charge not found" });
|
||||||
@@ -749,6 +842,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0)
|
if (personId <= 0)
|
||||||
return BadRequest(new { error = "personId is required" });
|
return BadRequest(new { error = "personId is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
if (limit < 1 || limit > 200) limit = 100;
|
if (limit < 1 || limit > 200) limit = 100;
|
||||||
if (offset < 0) offset = 0;
|
if (offset < 0) offset = 0;
|
||||||
@@ -768,6 +862,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0 || doctorId <= 0)
|
if (personId <= 0 || doctorId <= 0)
|
||||||
return BadRequest(new { error = "personId and doctorId are required" });
|
return BadRequest(new { error = "personId and doctorId are required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
var data = await medicalDocsService.GetVisitPrepAsync(personId, doctorId);
|
var data = await medicalDocsService.GetVisitPrepAsync(personId, doctorId);
|
||||||
return Ok(data);
|
return Ok(data);
|
||||||
@@ -782,6 +877,7 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (request.PersonId <= 0 || request.DoctorId <= 0)
|
if (request.PersonId <= 0 || request.DoctorId <= 0)
|
||||||
return BadRequest(new { error = "personId and doctorId are required" });
|
return BadRequest(new { error = "personId and doctorId are required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, request.PersonId)) return Forbid();
|
||||||
|
|
||||||
var data = await medicalDocsService.GetVisitPrepAsync(request.PersonId, request.DoctorId);
|
var data = await medicalDocsService.GetVisitPrepAsync(request.PersonId, request.DoctorId);
|
||||||
var doctor = await medicalDocsService.GetDoctorByIdAsync(request.DoctorId);
|
var doctor = await medicalDocsService.GetDoctorByIdAsync(request.DoctorId);
|
||||||
@@ -801,12 +897,13 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
|
|
||||||
if (personId <= 0)
|
if (personId <= 0)
|
||||||
return BadRequest(new { error = "personId is required" });
|
return BadRequest(new { error = "personId is required" });
|
||||||
|
if (!await HasPersonAccess(userId.Value, personId)) return Forbid();
|
||||||
|
|
||||||
var summary = await medicalDocsService.GetBillSummaryAsync(personId);
|
var summary = await medicalDocsService.GetBillSummaryAsync(personId);
|
||||||
return Ok(summary);
|
return Ok(summary);
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- Auth helpers (same pattern as AdminApi) ---
|
// --- Auth helpers ---
|
||||||
|
|
||||||
private async Task<bool> HasMedicalAccess(long userId)
|
private async Task<bool> HasMedicalAccess(long userId)
|
||||||
{
|
{
|
||||||
@@ -815,6 +912,18 @@ public class MedicalDocsApi(DbExecutor dbExecutor, MedicalDocsService medicalDoc
|
|||||||
new { UserId = userId });
|
new { UserId = userId });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private async Task<bool> HasPersonAccess(long userId, long personId)
|
||||||
|
{
|
||||||
|
return await medicalDocsService.HasAccessToPersonAsync(userId, personId);
|
||||||
|
}
|
||||||
|
|
||||||
|
private async Task<bool> HasResourceAccess(long userId, string resourceType, long resourceId)
|
||||||
|
{
|
||||||
|
var personId = await medicalDocsService.GetPersonIdForResourceAsync(resourceType, resourceId);
|
||||||
|
if (personId == null) return false;
|
||||||
|
return await medicalDocsService.HasAccessToPersonAsync(userId, personId.Value);
|
||||||
|
}
|
||||||
|
|
||||||
private long? GetUserIdFromAuth()
|
private long? GetUserIdFromAuth()
|
||||||
{
|
{
|
||||||
var userIdClaim = User.FindFirst(ClaimTypes.NameIdentifier)?.Value;
|
var userIdClaim = User.FindFirst(ClaimTypes.NameIdentifier)?.Value;
|
||||||
@@ -851,3 +960,4 @@ public record LinkDocumentRequest(long DocumentId);
|
|||||||
public record CreateChargeRequest(string Description, decimal Amount);
|
public record CreateChargeRequest(string Description, decimal Amount);
|
||||||
public record ProcessBatchRequest(List<long> DocumentIds);
|
public record ProcessBatchRequest(List<long> DocumentIds);
|
||||||
public record VisitPrepSummaryRequest(long PersonId, long DoctorId);
|
public record VisitPrepSummaryRequest(long PersonId, long DoctorId);
|
||||||
|
public record GrantAccessRequest(string Username);
|
||||||
|
|||||||
@@ -0,0 +1,12 @@
|
|||||||
|
CREATE TABLE app.password_reset_tokens (
|
||||||
|
id BIGSERIAL PRIMARY KEY,
|
||||||
|
user_id BIGINT NOT NULL,
|
||||||
|
token_hash VARCHAR(64) NOT NULL,
|
||||||
|
created_at TIMESTAMPTZ DEFAULT CURRENT_TIMESTAMP,
|
||||||
|
expires_at TIMESTAMPTZ NOT NULL,
|
||||||
|
used_at TIMESTAMPTZ NULL,
|
||||||
|
FOREIGN KEY (user_id) REFERENCES app.users(id) ON DELETE CASCADE
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_prt_token_hash ON app.password_reset_tokens(token_hash);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_prt_user_id ON app.password_reset_tokens(user_id);
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
CREATE TABLE IF NOT EXISTS app.medical_people_access (
|
||||||
|
id BIGSERIAL PRIMARY KEY,
|
||||||
|
person_id BIGINT NOT NULL REFERENCES app.medical_people(id) ON DELETE CASCADE,
|
||||||
|
user_id BIGINT NOT NULL REFERENCES app.users(id) ON DELETE CASCADE,
|
||||||
|
created_at TIMESTAMPTZ DEFAULT CURRENT_TIMESTAMP,
|
||||||
|
UNIQUE(person_id, user_id)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_mpa_user_id ON app.medical_people_access(user_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_mpa_person_id ON app.medical_people_access(person_id);
|
||||||
@@ -9,3 +9,9 @@ public class MedicalPerson
|
|||||||
public DateTime CreatedAt { get; set; }
|
public DateTime CreatedAt { get; set; }
|
||||||
public DateTime UpdatedAt { get; set; }
|
public DateTime UpdatedAt { get; set; }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public class PersonAccessUser
|
||||||
|
{
|
||||||
|
public long Id { get; set; }
|
||||||
|
public string Username { get; set; } = string.Empty;
|
||||||
|
}
|
||||||
|
|||||||
@@ -21,6 +21,7 @@
|
|||||||
</a>
|
</a>
|
||||||
<h1>Welcome back, @Model.Dashboard?.Username!</h1>
|
<h1>Welcome back, @Model.Dashboard?.Username!</h1>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="quick-actions">
|
<div class="quick-actions">
|
||||||
@if (Model.Dashboard?.EmailVerified == false)
|
@if (Model.Dashboard?.EmailVerified == false)
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -60,11 +60,14 @@
|
|||||||
<div class="invalid-feedback"></div>
|
<div class="invalid-feedback"></div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<div class="form-options">
|
||||||
<div class="checkbox-wrapper">
|
<div class="checkbox-wrapper">
|
||||||
<input type="checkbox" id="rememberMe" name="rememberMe"
|
<input type="checkbox" id="rememberMe" name="rememberMe"
|
||||||
@(Model.RememberMe ? "checked" : "") />
|
@(Model.RememberMe ? "checked" : "") />
|
||||||
<label for="rememberMe">Remember me</label>
|
<label for="rememberMe">Remember me</label>
|
||||||
</div>
|
</div>
|
||||||
|
<a href="/LoginHelp" class="forgot-password-link">Forgot password?</a>
|
||||||
|
</div>
|
||||||
|
|
||||||
<button type="submit" class="btn-primary">Sign In</button>
|
<button type="submit" class="btn-primary">Sign In</button>
|
||||||
</form>
|
</form>
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ public class LoginModel(AuthService authService) : PageModel
|
|||||||
public string? SuccessMessage { get; set; }
|
public string? SuccessMessage { get; set; }
|
||||||
public string? WarningMessage { get; set; }
|
public string? WarningMessage { get; set; }
|
||||||
|
|
||||||
public void OnGet([FromQuery] string? registered, [FromQuery] string? verified)
|
public void OnGet([FromQuery] string? registered, [FromQuery] string? verified, [FromQuery] string? reset)
|
||||||
{
|
{
|
||||||
// Check if user is already logged in
|
// Check if user is already logged in
|
||||||
var userId = HttpContext.Session.GetString("UserId");
|
var userId = HttpContext.Session.GetString("UserId");
|
||||||
@@ -41,6 +41,12 @@ public class LoginModel(AuthService authService) : PageModel
|
|||||||
{
|
{
|
||||||
SuccessMessage = "Email verified! You can now sign in.";
|
SuccessMessage = "Email verified! You can now sign in.";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Show success message if password was just reset
|
||||||
|
if (reset == "true")
|
||||||
|
{
|
||||||
|
SuccessMessage = "Your password has been reset. You can now sign in with your new password.";
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public async Task<IActionResult> OnPostAsync()
|
public async Task<IActionResult> OnPostAsync()
|
||||||
|
|||||||
@@ -0,0 +1,102 @@
|
|||||||
|
@page
|
||||||
|
@model Media.JoshHeaps.Net.Pages.LoginHelpModel
|
||||||
|
@{
|
||||||
|
ViewData["Title"] = "Login Help";
|
||||||
|
Layout = "_Layout";
|
||||||
|
}
|
||||||
|
|
||||||
|
@section Styles {
|
||||||
|
<link rel="stylesheet" href="~/css/auth.css" asp-append-version="true" />
|
||||||
|
}
|
||||||
|
|
||||||
|
@section Scripts {
|
||||||
|
<script src="~/js/auth.js" asp-append-version="true"></script>
|
||||||
|
}
|
||||||
|
|
||||||
|
<div class="auth-container">
|
||||||
|
<div class="auth-card">
|
||||||
|
@if (Model.ShowResetForm)
|
||||||
|
{
|
||||||
|
<div class="auth-header">
|
||||||
|
<h1>Reset Password</h1>
|
||||||
|
<p>Enter your new password below</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if (!string.IsNullOrEmpty(Model.ErrorMessage))
|
||||||
|
{
|
||||||
|
<div class="alert alert-danger">
|
||||||
|
@Model.ErrorMessage
|
||||||
|
</div>
|
||||||
|
}
|
||||||
|
|
||||||
|
<form id="resetPasswordForm" method="post" asp-page-handler="ResetPassword">
|
||||||
|
@Html.AntiForgeryToken()
|
||||||
|
<input type="hidden" name="Token" value="@Model.Token" />
|
||||||
|
|
||||||
|
<div class="form-group">
|
||||||
|
<label for="newPassword" class="form-label">New Password</label>
|
||||||
|
<div class="password-wrapper">
|
||||||
|
<input type="password" class="form-control" id="newPassword" name="NewPassword"
|
||||||
|
autocomplete="new-password" required minlength="8" />
|
||||||
|
<button type="button" class="password-toggle">Show</button>
|
||||||
|
</div>
|
||||||
|
<div class="invalid-feedback"></div>
|
||||||
|
<div class="password-strength">
|
||||||
|
<div class="password-strength-bar"></div>
|
||||||
|
</div>
|
||||||
|
<div class="password-strength-text"></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="form-group">
|
||||||
|
<label for="confirmPassword" class="form-label">Confirm Password</label>
|
||||||
|
<div class="password-wrapper">
|
||||||
|
<input type="password" class="form-control" id="confirmPassword" name="ConfirmPassword"
|
||||||
|
autocomplete="new-password" required minlength="8" />
|
||||||
|
<button type="button" class="password-toggle">Show</button>
|
||||||
|
</div>
|
||||||
|
<div class="invalid-feedback"></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<button type="submit" class="btn-primary">Reset Password</button>
|
||||||
|
</form>
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
<div class="auth-header">
|
||||||
|
<h1>Forgot Password</h1>
|
||||||
|
<p>Enter your email to receive a reset link</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if (!string.IsNullOrEmpty(Model.ErrorMessage))
|
||||||
|
{
|
||||||
|
<div class="alert alert-danger">
|
||||||
|
@Model.ErrorMessage
|
||||||
|
</div>
|
||||||
|
}
|
||||||
|
|
||||||
|
@if (!string.IsNullOrEmpty(Model.SuccessMessage))
|
||||||
|
{
|
||||||
|
<div class="alert alert-success">
|
||||||
|
@Model.SuccessMessage
|
||||||
|
</div>
|
||||||
|
}
|
||||||
|
|
||||||
|
<form id="requestResetForm" method="post" asp-page-handler="RequestReset">
|
||||||
|
@Html.AntiForgeryToken()
|
||||||
|
|
||||||
|
<div class="form-group">
|
||||||
|
<label for="email" class="form-label">Email Address</label>
|
||||||
|
<input type="email" class="form-control" id="email" name="Email"
|
||||||
|
value="@Model.Email" autocomplete="email" required />
|
||||||
|
<div class="invalid-feedback"></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<button type="submit" class="btn-primary">Send Reset Link</button>
|
||||||
|
</form>
|
||||||
|
}
|
||||||
|
|
||||||
|
<div class="auth-footer">
|
||||||
|
<p>Remember your password? <a href="/Login">Sign in</a></p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,111 @@
|
|||||||
|
using Media.JoshHeaps.Net.Services;
|
||||||
|
using Microsoft.AspNetCore.Mvc;
|
||||||
|
using Microsoft.AspNetCore.Mvc.RazorPages;
|
||||||
|
|
||||||
|
namespace Media.JoshHeaps.Net.Pages;
|
||||||
|
|
||||||
|
public class LoginHelpModel(AuthService authService, EmailService emailService, ILogger<LoginHelpModel> logger) : PageModel
|
||||||
|
{
|
||||||
|
[BindProperty]
|
||||||
|
public string Email { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[BindProperty]
|
||||||
|
public string Token { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[BindProperty]
|
||||||
|
public string NewPassword { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
[BindProperty]
|
||||||
|
public string ConfirmPassword { get; set; } = string.Empty;
|
||||||
|
|
||||||
|
public string? ErrorMessage { get; set; }
|
||||||
|
public string? SuccessMessage { get; set; }
|
||||||
|
public bool ShowResetForm { get; set; }
|
||||||
|
|
||||||
|
public async Task<IActionResult> OnGetAsync([FromQuery] string? token)
|
||||||
|
{
|
||||||
|
// Redirect if already logged in
|
||||||
|
var userId = HttpContext.Session.GetString("UserId");
|
||||||
|
if (!string.IsNullOrEmpty(userId))
|
||||||
|
return Redirect("/Landing");
|
||||||
|
|
||||||
|
if (!string.IsNullOrEmpty(token))
|
||||||
|
{
|
||||||
|
var (valid, error) = await authService.ValidatePasswordResetTokenAsync(token);
|
||||||
|
if (valid)
|
||||||
|
{
|
||||||
|
ShowResetForm = true;
|
||||||
|
Token = token;
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
ErrorMessage = error;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return Page();
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<IActionResult> OnPostRequestResetAsync()
|
||||||
|
{
|
||||||
|
// Redirect if already logged in
|
||||||
|
var userId = HttpContext.Session.GetString("UserId");
|
||||||
|
if (!string.IsNullOrEmpty(userId))
|
||||||
|
return Redirect("/Landing");
|
||||||
|
|
||||||
|
if (string.IsNullOrWhiteSpace(Email))
|
||||||
|
{
|
||||||
|
ErrorMessage = "Please enter your email address.";
|
||||||
|
return Page();
|
||||||
|
}
|
||||||
|
|
||||||
|
var (success, error, token, username) = await authService.RequestPasswordResetAsync(Email.Trim());
|
||||||
|
|
||||||
|
if (!success)
|
||||||
|
{
|
||||||
|
logger.LogError("Password reset request failed for {Email}: {Error}", Email, error);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Send email if we got a token back (user exists and is eligible)
|
||||||
|
if (token != null)
|
||||||
|
{
|
||||||
|
await emailService.SendPasswordResetEmailAsync(Email.Trim(), username ?? Email.Split('@')[0], token);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Always show the same message regardless of whether the email exists
|
||||||
|
SuccessMessage = "If an account exists with that email, you will receive a password reset link shortly.";
|
||||||
|
return Page();
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<IActionResult> OnPostResetPasswordAsync()
|
||||||
|
{
|
||||||
|
// Redirect if already logged in
|
||||||
|
var userId = HttpContext.Session.GetString("UserId");
|
||||||
|
if (!string.IsNullOrEmpty(userId))
|
||||||
|
return Redirect("/Landing");
|
||||||
|
|
||||||
|
if (string.IsNullOrWhiteSpace(NewPassword) || NewPassword.Length < 8)
|
||||||
|
{
|
||||||
|
ErrorMessage = "Password must be at least 8 characters.";
|
||||||
|
ShowResetForm = true;
|
||||||
|
return Page();
|
||||||
|
}
|
||||||
|
|
||||||
|
if (NewPassword != ConfirmPassword)
|
||||||
|
{
|
||||||
|
ErrorMessage = "Passwords do not match.";
|
||||||
|
ShowResetForm = true;
|
||||||
|
return Page();
|
||||||
|
}
|
||||||
|
|
||||||
|
var (success, error) = await authService.ResetPasswordAsync(Token, NewPassword);
|
||||||
|
|
||||||
|
if (!success)
|
||||||
|
{
|
||||||
|
ErrorMessage = error;
|
||||||
|
return Page();
|
||||||
|
}
|
||||||
|
|
||||||
|
return Redirect("/Login?reset=true");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -285,6 +285,23 @@
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<!-- Share Access Modal -->
|
||||||
|
<div class="doc-viewer-overlay" id="shareAccessOverlay" style="display:none" onclick="medDocsCloseShareModal(event)">
|
||||||
|
<div class="doc-viewer-modal" style="max-width:420px;max-height:400px;" onclick="event.stopPropagation()">
|
||||||
|
<div class="doc-viewer-header">
|
||||||
|
<span class="doc-viewer-title">Share Patient Access</span>
|
||||||
|
<button class="doc-viewer-close" onclick="medDocsCloseShareModal()" title="Close">×</button>
|
||||||
|
</div>
|
||||||
|
<div class="doc-viewer-body" style="padding:1rem;overflow-y:auto;">
|
||||||
|
<div id="shareAccessList" style="margin-bottom:1rem;"></div>
|
||||||
|
<div style="display:flex;gap:0.5rem;">
|
||||||
|
<input type="text" id="shareUsername" placeholder="Username..." class="form-input" style="flex:1;" />
|
||||||
|
<button class="btn btn-primary btn-sm" onclick="medDocsGrantAccess()">Grant</button>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
@section Scripts {
|
@section Scripts {
|
||||||
<script src="~/js/medical-docs/state.js" asp-append-version="true"></script>
|
<script src="~/js/medical-docs/state.js" asp-append-version="true"></script>
|
||||||
<script src="~/js/medical-docs/tabs.js" asp-append-version="true"></script>
|
<script src="~/js/medical-docs/tabs.js" asp-append-version="true"></script>
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
using System.Security.Cryptography;
|
||||||
|
using System.Text;
|
||||||
using Media.JoshHeaps.Net;
|
using Media.JoshHeaps.Net;
|
||||||
using Media.JoshHeaps.Net.Models;
|
using Media.JoshHeaps.Net.Models;
|
||||||
|
|
||||||
@@ -302,4 +304,173 @@ public class AuthService(DbExecutor db)
|
|||||||
new { userId, lastLogin = DateTime.UtcNow }
|
new { userId, lastLogin = DateTime.UtcNow }
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public static string GenerateSecureToken()
|
||||||
|
{
|
||||||
|
var bytes = RandomNumberGenerator.GetBytes(32);
|
||||||
|
return Convert.ToBase64String(bytes)
|
||||||
|
.Replace("+", "-")
|
||||||
|
.Replace("/", "_")
|
||||||
|
.TrimEnd('=');
|
||||||
|
}
|
||||||
|
|
||||||
|
public static string HashToken(string token)
|
||||||
|
{
|
||||||
|
var bytes = SHA256.HashData(Encoding.UTF8.GetBytes(token));
|
||||||
|
return Convert.ToHexString(bytes).ToLowerInvariant();
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<(bool Success, string? Error, string? Token, string? Username)> RequestPasswordResetAsync(string email)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
var userRow = await db.ExecuteReaderAsync(
|
||||||
|
"SELECT id, username, is_active, locked_until FROM app.users WHERE email = @email",
|
||||||
|
reader => new
|
||||||
|
{
|
||||||
|
UserId = reader.GetInt64(0),
|
||||||
|
Username = reader.GetString(1),
|
||||||
|
IsActive = reader.GetBoolean(2),
|
||||||
|
LockedUntil = reader.IsDBNull(3) ? (DateTime?)null : reader.GetDateTime(3)
|
||||||
|
},
|
||||||
|
new { email }
|
||||||
|
);
|
||||||
|
|
||||||
|
if (userRow == null)
|
||||||
|
{
|
||||||
|
// Artificial delay to prevent timing-based email enumeration
|
||||||
|
await Task.Delay(Random.Shared.Next(100, 300));
|
||||||
|
return (true, null, null, null);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Silently succeed for inactive/locked accounts (don't reveal state)
|
||||||
|
if (!userRow.IsActive ||
|
||||||
|
(userRow.LockedUntil.HasValue && userRow.LockedUntil.Value > DateTime.UtcNow))
|
||||||
|
{
|
||||||
|
return (true, null, null, null);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Rate limit: max 3 requests per hour
|
||||||
|
var recentCount = await db.ExecuteAsync<long>(
|
||||||
|
@"SELECT COUNT(*) FROM app.password_reset_tokens
|
||||||
|
WHERE user_id = @userId AND created_at > @cutoff",
|
||||||
|
new { userId = userRow.UserId, cutoff = DateTimeOffset.UtcNow.AddHours(-1) }
|
||||||
|
);
|
||||||
|
|
||||||
|
if (recentCount >= 3)
|
||||||
|
{
|
||||||
|
return (true, null, null, null);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Invalidate all existing unused tokens for this user
|
||||||
|
await db.ExecuteNonQueryAsync(
|
||||||
|
@"UPDATE app.password_reset_tokens
|
||||||
|
SET used_at = @now
|
||||||
|
WHERE user_id = @userId AND used_at IS NULL",
|
||||||
|
new { userId = userRow.UserId, now = DateTimeOffset.UtcNow }
|
||||||
|
);
|
||||||
|
|
||||||
|
// Generate and store new token
|
||||||
|
var token = GenerateSecureToken();
|
||||||
|
var tokenHash = HashToken(token);
|
||||||
|
var expiresAt = DateTimeOffset.UtcNow.AddHours(1);
|
||||||
|
|
||||||
|
await db.ExecuteNonQueryAsync(
|
||||||
|
@"INSERT INTO app.password_reset_tokens (user_id, token_hash, expires_at)
|
||||||
|
VALUES (@userId, @tokenHash, @expiresAt)",
|
||||||
|
new { userId = userRow.UserId, tokenHash, expiresAt }
|
||||||
|
);
|
||||||
|
|
||||||
|
return (true, null, token, userRow.Username);
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
return (false, $"Password reset request failed: {ex.Message}", null, null);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<(bool Valid, string? Error)> ValidatePasswordResetTokenAsync(string token)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
var tokenHash = HashToken(token);
|
||||||
|
|
||||||
|
var tokenRow = await db.ExecuteReaderAsync(
|
||||||
|
@"SELECT expires_at, used_at FROM app.password_reset_tokens
|
||||||
|
WHERE token_hash = @tokenHash",
|
||||||
|
reader => new
|
||||||
|
{
|
||||||
|
ExpiresAt = reader.GetFieldValue<DateTimeOffset>(0),
|
||||||
|
UsedAt = reader.IsDBNull(1) ? (DateTimeOffset?)null : reader.GetFieldValue<DateTimeOffset>(1)
|
||||||
|
},
|
||||||
|
new { tokenHash }
|
||||||
|
);
|
||||||
|
|
||||||
|
if (tokenRow == null)
|
||||||
|
return (false, "Invalid or expired reset link. Please request a new one.");
|
||||||
|
|
||||||
|
if (tokenRow.UsedAt.HasValue)
|
||||||
|
return (false, "This reset link has already been used. Please request a new one.");
|
||||||
|
|
||||||
|
if (tokenRow.ExpiresAt < DateTimeOffset.UtcNow)
|
||||||
|
return (false, "This reset link has expired. Please request a new one.");
|
||||||
|
|
||||||
|
return (true, null);
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
return (false, $"Token validation failed: {ex.Message}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<(bool Success, string? Error)> ResetPasswordAsync(string token, string newPassword)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
var tokenHash = HashToken(token);
|
||||||
|
|
||||||
|
var tokenRow = await db.ExecuteReaderAsync(
|
||||||
|
@"SELECT id, user_id, expires_at, used_at FROM app.password_reset_tokens
|
||||||
|
WHERE token_hash = @tokenHash",
|
||||||
|
reader => new
|
||||||
|
{
|
||||||
|
Id = reader.GetInt64(0),
|
||||||
|
UserId = reader.GetInt64(1),
|
||||||
|
ExpiresAt = reader.GetFieldValue<DateTimeOffset>(2),
|
||||||
|
UsedAt = reader.IsDBNull(3) ? (DateTimeOffset?)null : reader.GetFieldValue<DateTimeOffset>(3)
|
||||||
|
},
|
||||||
|
new { tokenHash }
|
||||||
|
);
|
||||||
|
|
||||||
|
if (tokenRow == null)
|
||||||
|
return (false, "Invalid or expired reset link. Please request a new one.");
|
||||||
|
|
||||||
|
if (tokenRow.UsedAt.HasValue)
|
||||||
|
return (false, "This reset link has already been used. Please request a new one.");
|
||||||
|
|
||||||
|
if (tokenRow.ExpiresAt < DateTimeOffset.UtcNow)
|
||||||
|
return (false, "This reset link has expired. Please request a new one.");
|
||||||
|
|
||||||
|
// Hash new password and update user
|
||||||
|
var passwordHash = HashPassword(newPassword);
|
||||||
|
await db.ExecuteNonQueryAsync(
|
||||||
|
@"UPDATE app.users
|
||||||
|
SET password_hash = @passwordHash, failed_login_attempts = 0, locked_until = NULL
|
||||||
|
WHERE id = @userId",
|
||||||
|
new { userId = tokenRow.UserId, passwordHash }
|
||||||
|
);
|
||||||
|
|
||||||
|
// Mark token as used
|
||||||
|
await db.ExecuteNonQueryAsync(
|
||||||
|
"UPDATE app.password_reset_tokens SET used_at = @now WHERE id = @tokenId",
|
||||||
|
new { tokenId = tokenRow.Id, now = DateTimeOffset.UtcNow }
|
||||||
|
);
|
||||||
|
|
||||||
|
return (true, null);
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
return (false, $"Password reset failed: {ex.Message}");
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -107,7 +107,7 @@ If you didn't create an account, you can safely ignore this email.
|
|||||||
try
|
try
|
||||||
{
|
{
|
||||||
var appUrl = config["AppUrl"] ?? "http://localhost:5000";
|
var appUrl = config["AppUrl"] ?? "http://localhost:5000";
|
||||||
var resetUrl = $"{appUrl}/ResetPassword?token={resetToken}";
|
var resetUrl = $"{appUrl}/LoginHelp?token={resetToken}";
|
||||||
|
|
||||||
var message = new MimeMessage();
|
var message = new MimeMessage();
|
||||||
message.From.Add(new MailboxAddress(
|
message.From.Add(new MailboxAddress(
|
||||||
|
|||||||
@@ -447,7 +447,7 @@ Only include fields you can confidently extract. Return ONLY the JSON object, no
|
|||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
_logger.LogError("claude CLI exited with code {ExitCode}: {Stderr}", process.ExitCode, stderr);
|
_logger.LogError("claude CLI exited with code {ExitCode}.\nStderr: {Stderr}\nStdout: {Stdout}", process.ExitCode, stderr, stdout);
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -6,12 +6,16 @@ public class MedicalDocsService(DbExecutor db, IWebHostEnvironment environment,
|
|||||||
{
|
{
|
||||||
// --- People ---
|
// --- People ---
|
||||||
|
|
||||||
public async Task<List<MedicalPerson>> GetPeopleAsync()
|
public async Task<List<MedicalPerson>> GetPeopleAsync(long userId)
|
||||||
{
|
{
|
||||||
try
|
try
|
||||||
{
|
{
|
||||||
return await db.ExecuteListReaderAsync(
|
return await db.ExecuteListReaderAsync(
|
||||||
"SELECT id, name, date_of_birth, notes, created_at, updated_at FROM app.medical_people ORDER BY name",
|
@"SELECT mp.id, mp.name, mp.date_of_birth, mp.notes, mp.created_at, mp.updated_at
|
||||||
|
FROM app.medical_people mp
|
||||||
|
JOIN app.medical_people_access mpa ON mpa.person_id = mp.id
|
||||||
|
WHERE mpa.user_id = @userId
|
||||||
|
ORDER BY mp.name",
|
||||||
reader => new MedicalPerson
|
reader => new MedicalPerson
|
||||||
{
|
{
|
||||||
Id = reader.GetInt64(0),
|
Id = reader.GetInt64(0),
|
||||||
@@ -20,7 +24,8 @@ public class MedicalDocsService(DbExecutor db, IWebHostEnvironment environment,
|
|||||||
Notes = reader.IsDBNull(3) ? null : reader.GetString(3),
|
Notes = reader.IsDBNull(3) ? null : reader.GetString(3),
|
||||||
CreatedAt = reader.GetDateTime(4),
|
CreatedAt = reader.GetDateTime(4),
|
||||||
UpdatedAt = reader.GetDateTime(5)
|
UpdatedAt = reader.GetDateTime(5)
|
||||||
});
|
},
|
||||||
|
new { userId });
|
||||||
}
|
}
|
||||||
catch (Exception ex)
|
catch (Exception ex)
|
||||||
{
|
{
|
||||||
@@ -29,12 +34,12 @@ public class MedicalDocsService(DbExecutor db, IWebHostEnvironment environment,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public async Task<MedicalPerson?> CreatePersonAsync(string name, DateTime? dateOfBirth = null, string? notes = null)
|
public async Task<MedicalPerson?> CreatePersonAsync(long userId, string name, DateTime? dateOfBirth = null, string? notes = null)
|
||||||
{
|
{
|
||||||
try
|
try
|
||||||
{
|
{
|
||||||
var now = DateTime.UtcNow;
|
var now = DateTime.UtcNow;
|
||||||
return await db.ExecuteReaderAsync(
|
var person = await db.ExecuteReaderAsync(
|
||||||
@"INSERT INTO app.medical_people (name, date_of_birth, notes, created_at, updated_at)
|
@"INSERT INTO app.medical_people (name, date_of_birth, notes, created_at, updated_at)
|
||||||
VALUES (@name, @dateOfBirth, @notes, @createdAt, @updatedAt)
|
VALUES (@name, @dateOfBirth, @notes, @createdAt, @updatedAt)
|
||||||
RETURNING id, name, date_of_birth, notes, created_at, updated_at",
|
RETURNING id, name, date_of_birth, notes, created_at, updated_at",
|
||||||
@@ -48,6 +53,15 @@ public class MedicalDocsService(DbExecutor db, IWebHostEnvironment environment,
|
|||||||
UpdatedAt = reader.GetDateTime(5)
|
UpdatedAt = reader.GetDateTime(5)
|
||||||
},
|
},
|
||||||
new { name, dateOfBirth, notes, createdAt = now, updatedAt = now });
|
new { name, dateOfBirth, notes, createdAt = now, updatedAt = now });
|
||||||
|
|
||||||
|
if (person != null)
|
||||||
|
{
|
||||||
|
await db.ExecuteNonQueryAsync(
|
||||||
|
"INSERT INTO app.medical_people_access (person_id, user_id) VALUES (@personId, @userId) ON CONFLICT DO NOTHING",
|
||||||
|
new { personId = person.Id, userId });
|
||||||
|
}
|
||||||
|
|
||||||
|
return person;
|
||||||
}
|
}
|
||||||
catch (Exception ex)
|
catch (Exception ex)
|
||||||
{
|
{
|
||||||
@@ -56,6 +70,109 @@ public class MedicalDocsService(DbExecutor db, IWebHostEnvironment environment,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// --- People Access ---
|
||||||
|
|
||||||
|
public async Task<bool> HasAccessToPersonAsync(long userId, long personId)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return await db.ExecuteAsync<bool>(
|
||||||
|
"SELECT EXISTS(SELECT 1 FROM app.medical_people_access WHERE user_id = @userId AND person_id = @personId)",
|
||||||
|
new { userId, personId });
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
logger.LogError(ex, "Failed to check person access");
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<bool> GrantAccessAsync(long personId, long targetUserId)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
await db.ExecuteNonQueryAsync(
|
||||||
|
"INSERT INTO app.medical_people_access (person_id, user_id) VALUES (@personId, @userId) ON CONFLICT DO NOTHING",
|
||||||
|
new { personId, userId = targetUserId });
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
logger.LogError(ex, "Failed to grant person access");
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<bool> RevokeAccessAsync(long personId, long targetUserId)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
var count = await db.ExecuteAsync<long>(
|
||||||
|
"SELECT COUNT(*) FROM app.medical_people_access WHERE person_id = @personId",
|
||||||
|
new { personId });
|
||||||
|
if (count <= 1)
|
||||||
|
return false;
|
||||||
|
|
||||||
|
await db.ExecuteNonQueryAsync(
|
||||||
|
"DELETE FROM app.medical_people_access WHERE person_id = @personId AND user_id = @userId",
|
||||||
|
new { personId, userId = targetUserId });
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
logger.LogError(ex, "Failed to revoke person access");
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<List<PersonAccessUser>> GetPeopleAccessAsync(long personId)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
return await db.ExecuteListReaderAsync(
|
||||||
|
@"SELECT u.id, u.username FROM app.users u
|
||||||
|
JOIN app.medical_people_access mpa ON mpa.user_id = u.id
|
||||||
|
WHERE mpa.person_id = @personId
|
||||||
|
ORDER BY u.username",
|
||||||
|
reader => new PersonAccessUser
|
||||||
|
{
|
||||||
|
Id = reader.GetInt64(0),
|
||||||
|
Username = reader.GetString(1)
|
||||||
|
},
|
||||||
|
new { personId });
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
logger.LogError(ex, "Failed to get person access list");
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async Task<long?> GetPersonIdForResourceAsync(string resourceType, long resourceId)
|
||||||
|
{
|
||||||
|
try
|
||||||
|
{
|
||||||
|
var sql = resourceType switch
|
||||||
|
{
|
||||||
|
"document" => "SELECT person_id FROM app.medical_documents WHERE id = @id",
|
||||||
|
"condition" => "SELECT person_id FROM app.medical_conditions WHERE id = @id",
|
||||||
|
"prescription" => "SELECT person_id FROM app.medical_prescriptions WHERE id = @id",
|
||||||
|
"pickup" => "SELECT p.person_id FROM app.medical_prescription_pickups pk JOIN app.medical_prescriptions p ON pk.prescription_id = p.id WHERE pk.id = @id",
|
||||||
|
"provider" => "SELECT person_id FROM app.medical_billing_providers WHERE id = @id",
|
||||||
|
"provider-payment" => "SELECT bp.person_id FROM app.medical_provider_payments pp JOIN app.medical_billing_providers bp ON pp.provider_id = bp.id WHERE pp.id = @id",
|
||||||
|
"bill" => "SELECT person_id FROM app.medical_bills WHERE id = @id",
|
||||||
|
"bill-charge" => "SELECT b.person_id FROM app.medical_bill_charges bc JOIN app.medical_bills b ON bc.bill_id = b.id WHERE bc.id = @id",
|
||||||
|
_ => throw new ArgumentException($"Unknown resource type: {resourceType}")
|
||||||
|
};
|
||||||
|
return await db.ExecuteAsync<long?>(sql, new { id = resourceId });
|
||||||
|
}
|
||||||
|
catch (Exception ex)
|
||||||
|
{
|
||||||
|
logger.LogError(ex, "Failed to get person ID for {ResourceType} {ResourceId}", resourceType, resourceId);
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// --- Documents ---
|
// --- Documents ---
|
||||||
|
|
||||||
public async Task<MedicalDocument?> SaveDocumentAsync(long personId, IFormFile file, string? title = null, string? description = null, DateTime? documentDate = null, string? classification = null)
|
public async Task<MedicalDocument?> SaveDocumentAsync(long personId, IFormFile file, string? title = null, string? description = null, DateTime? documentDate = null, string? classification = null)
|
||||||
|
|||||||
@@ -152,6 +152,29 @@
|
|||||||
display: block;
|
display: block;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
.form-options {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: space-between;
|
||||||
|
margin-bottom: 20px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.form-options .checkbox-wrapper {
|
||||||
|
margin-bottom: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.forgot-password-link {
|
||||||
|
color: var(--text-secondary);
|
||||||
|
font-size: 13px;
|
||||||
|
text-decoration: none;
|
||||||
|
transition: color 0.2s ease;
|
||||||
|
}
|
||||||
|
|
||||||
|
.forgot-password-link:hover {
|
||||||
|
color: var(--accent-primary);
|
||||||
|
text-decoration: underline;
|
||||||
|
}
|
||||||
|
|
||||||
.checkbox-wrapper {
|
.checkbox-wrapper {
|
||||||
display: flex;
|
display: flex;
|
||||||
align-items: center;
|
align-items: center;
|
||||||
|
|||||||
@@ -323,6 +323,39 @@
|
|||||||
color: #fff;
|
color: #fff;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
.person-pill-row {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 4px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.person-pill-row .person-pill {
|
||||||
|
flex: 1;
|
||||||
|
min-width: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.person-share-btn {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
width: 28px;
|
||||||
|
height: 28px;
|
||||||
|
padding: 0;
|
||||||
|
background: transparent;
|
||||||
|
border: 1px solid var(--border-primary);
|
||||||
|
border-radius: 50%;
|
||||||
|
color: var(--text-muted);
|
||||||
|
cursor: pointer;
|
||||||
|
transition: all 0.2s ease;
|
||||||
|
flex-shrink: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.person-share-btn:hover {
|
||||||
|
border-color: var(--accent-primary);
|
||||||
|
color: var(--accent-primary);
|
||||||
|
background: var(--bg-tertiary);
|
||||||
|
}
|
||||||
|
|
||||||
/* ======================== */
|
/* ======================== */
|
||||||
/* Form Inputs */
|
/* Form Inputs */
|
||||||
/* ======================== */
|
/* ======================== */
|
||||||
|
|||||||
@@ -336,9 +336,145 @@ function initRegisterForm() {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Password reset form validation
|
||||||
|
function initPasswordResetForm() {
|
||||||
|
const form = document.getElementById('resetPasswordForm');
|
||||||
|
if (!form) return;
|
||||||
|
|
||||||
|
const passwordInput = document.getElementById('newPassword');
|
||||||
|
const confirmPasswordInput = document.getElementById('confirmPassword');
|
||||||
|
|
||||||
|
if (passwordInput) {
|
||||||
|
passwordInput.addEventListener('input', function() {
|
||||||
|
checkPasswordStrength(this.value);
|
||||||
|
if (this.value && validatePassword(this.value)) {
|
||||||
|
clearError(this);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (confirmPasswordInput && confirmPasswordInput.value) {
|
||||||
|
if (confirmPasswordInput.value === this.value) {
|
||||||
|
clearError(confirmPasswordInput);
|
||||||
|
} else {
|
||||||
|
showError(confirmPasswordInput, 'Passwords do not match');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
passwordInput.addEventListener('blur', function() {
|
||||||
|
if (!this.value) {
|
||||||
|
showError(this, 'Password is required');
|
||||||
|
} else if (!validatePassword(this.value)) {
|
||||||
|
showError(this, 'Password must be at least 8 characters');
|
||||||
|
} else {
|
||||||
|
clearError(this);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (confirmPasswordInput) {
|
||||||
|
confirmPasswordInput.addEventListener('input', function() {
|
||||||
|
if (passwordInput && this.value === passwordInput.value) {
|
||||||
|
clearError(this);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
confirmPasswordInput.addEventListener('blur', function() {
|
||||||
|
if (!this.value) {
|
||||||
|
showError(this, 'Please confirm your password');
|
||||||
|
} else if (passwordInput && this.value !== passwordInput.value) {
|
||||||
|
showError(this, 'Passwords do not match');
|
||||||
|
} else {
|
||||||
|
clearError(this);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
form.addEventListener('submit', function(e) {
|
||||||
|
e.preventDefault();
|
||||||
|
|
||||||
|
let isValid = true;
|
||||||
|
|
||||||
|
if (!passwordInput.value) {
|
||||||
|
showError(passwordInput, 'Password is required');
|
||||||
|
isValid = false;
|
||||||
|
} else if (!validatePassword(passwordInput.value)) {
|
||||||
|
showError(passwordInput, 'Password must be at least 8 characters');
|
||||||
|
isValid = false;
|
||||||
|
} else {
|
||||||
|
clearError(passwordInput);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!confirmPasswordInput.value) {
|
||||||
|
showError(confirmPasswordInput, 'Please confirm your password');
|
||||||
|
isValid = false;
|
||||||
|
} else if (confirmPasswordInput.value !== passwordInput.value) {
|
||||||
|
showError(confirmPasswordInput, 'Passwords do not match');
|
||||||
|
isValid = false;
|
||||||
|
} else {
|
||||||
|
clearError(confirmPasswordInput);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (isValid) {
|
||||||
|
const submitBtn = form.querySelector('button[type="submit"]');
|
||||||
|
submitBtn.disabled = true;
|
||||||
|
submitBtn.innerHTML = '<span class="spinner"></span> Resetting...';
|
||||||
|
form.submit();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Request reset form validation
|
||||||
|
function initRequestResetForm() {
|
||||||
|
const form = document.getElementById('requestResetForm');
|
||||||
|
if (!form) return;
|
||||||
|
|
||||||
|
const emailInput = document.getElementById('email');
|
||||||
|
|
||||||
|
if (emailInput) {
|
||||||
|
emailInput.addEventListener('blur', function() {
|
||||||
|
if (!this.value.trim()) {
|
||||||
|
showError(this, 'Email is required');
|
||||||
|
} else if (!validateEmail(this.value)) {
|
||||||
|
showError(this, 'Please enter a valid email address');
|
||||||
|
} else {
|
||||||
|
clearError(this);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
emailInput.addEventListener('input', function() {
|
||||||
|
if (this.value.trim() && validateEmail(this.value)) {
|
||||||
|
clearError(this);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
form.addEventListener('submit', function(e) {
|
||||||
|
e.preventDefault();
|
||||||
|
|
||||||
|
if (!emailInput.value.trim()) {
|
||||||
|
showError(emailInput, 'Email is required');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!validateEmail(emailInput.value)) {
|
||||||
|
showError(emailInput, 'Please enter a valid email address');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
clearError(emailInput);
|
||||||
|
|
||||||
|
const submitBtn = form.querySelector('button[type="submit"]');
|
||||||
|
submitBtn.disabled = true;
|
||||||
|
submitBtn.innerHTML = '<span class="spinner"></span> Sending...';
|
||||||
|
form.submit();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// Initialize on page load
|
// Initialize on page load
|
||||||
document.addEventListener('DOMContentLoaded', function() {
|
document.addEventListener('DOMContentLoaded', function() {
|
||||||
initPasswordToggles();
|
initPasswordToggles();
|
||||||
initLoginForm();
|
initLoginForm();
|
||||||
initRegisterForm();
|
initRegisterForm();
|
||||||
|
initPasswordResetForm();
|
||||||
|
initRequestResetForm();
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -11,7 +11,12 @@
|
|||||||
app.renderPeople = function () {
|
app.renderPeople = function () {
|
||||||
const container = document.getElementById('peopleList');
|
const container = document.getElementById('peopleList');
|
||||||
container.innerHTML = state.people.map(p =>
|
container.innerHTML = state.people.map(p =>
|
||||||
`<button class="person-pill ${p.id === state.selectedPersonId ? 'active' : ''}" onclick="medDocsSelectPerson(${p.id})">${app.escapeHtml(p.name)}</button>`
|
`<div class="person-pill-row">
|
||||||
|
<button class="person-pill ${p.id === state.selectedPersonId ? 'active' : ''}" onclick="medDocsSelectPerson(${p.id})">${app.escapeHtml(p.name)}</button>
|
||||||
|
<button class="person-share-btn" onclick="medDocsOpenShareModal(${p.id}, event)" title="Share access">
|
||||||
|
<svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M16 21v-2a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v2"></path><circle cx="9" cy="7" r="4"></circle><line x1="19" y1="8" x2="19" y2="14"></line><line x1="22" y1="11" x2="16" y2="11"></line></svg>
|
||||||
|
</button>
|
||||||
|
</div>`
|
||||||
).join('');
|
).join('');
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -61,5 +66,86 @@
|
|||||||
app.switchMainTab('documents');
|
app.switchMainTab('documents');
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// --- Share Access ---
|
||||||
|
|
||||||
|
app.openShareModal = async function (personId, event) {
|
||||||
|
event.stopPropagation();
|
||||||
|
state.sharePersonId = personId;
|
||||||
|
document.getElementById('shareAccessOverlay').style.display = '';
|
||||||
|
document.getElementById('shareUsername').value = '';
|
||||||
|
await app.loadShareAccess(personId);
|
||||||
|
};
|
||||||
|
|
||||||
|
app.closeShareModal = function (event) {
|
||||||
|
if (event && event.target !== event.currentTarget) return;
|
||||||
|
document.getElementById('shareAccessOverlay').style.display = 'none';
|
||||||
|
state.sharePersonId = null;
|
||||||
|
};
|
||||||
|
|
||||||
|
app.loadShareAccess = async function (personId) {
|
||||||
|
const container = document.getElementById('shareAccessList');
|
||||||
|
container.innerHTML = '<div style="color:var(--text-muted);">Loading...</div>';
|
||||||
|
|
||||||
|
const res = await fetch(`${app.API}/people/${personId}/access`);
|
||||||
|
if (!res.ok) {
|
||||||
|
container.innerHTML = '<div style="color:var(--text-muted);">Failed to load access list</div>';
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const users = await res.json();
|
||||||
|
state.shareAccessUsers = users;
|
||||||
|
|
||||||
|
if (users.length === 0) {
|
||||||
|
container.innerHTML = '<div style="color:var(--text-muted);">No users have access</div>';
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
container.innerHTML = users.map(u =>
|
||||||
|
`<div style="display:flex;align-items:center;justify-content:space-between;padding:0.4rem 0;border-bottom:1px solid var(--border-primary);">
|
||||||
|
<span>${app.escapeHtml(u.username)}</span>
|
||||||
|
<button class="btn btn-danger btn-sm" onclick="medDocsRevokeAccess(${personId}, ${u.id})" ${users.length <= 1 ? 'disabled title="Cannot remove the last user"' : ''} style="padding:0.15rem 0.5rem;font-size:0.75rem;">×</button>
|
||||||
|
</div>`
|
||||||
|
).join('');
|
||||||
|
};
|
||||||
|
|
||||||
|
app.grantAccess = async function () {
|
||||||
|
const input = document.getElementById('shareUsername');
|
||||||
|
const username = input.value.trim();
|
||||||
|
if (!username || !state.sharePersonId) return;
|
||||||
|
|
||||||
|
const res = await fetch(`${app.API}/people/${state.sharePersonId}/access`, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify({ username })
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!res.ok) {
|
||||||
|
const err = await res.json();
|
||||||
|
alert(err.error || 'Failed to grant access');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
input.value = '';
|
||||||
|
await app.loadShareAccess(state.sharePersonId);
|
||||||
|
};
|
||||||
|
|
||||||
|
app.revokeAccess = async function (personId, targetUserId) {
|
||||||
|
const res = await fetch(`${app.API}/people/${personId}/access/${targetUserId}`, {
|
||||||
|
method: 'DELETE'
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!res.ok) {
|
||||||
|
const err = await res.json();
|
||||||
|
alert(err.error || 'Failed to revoke access');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
await app.loadShareAccess(personId);
|
||||||
|
};
|
||||||
|
|
||||||
window.medDocsSelectPerson = (id) => app.selectPerson(id);
|
window.medDocsSelectPerson = (id) => app.selectPerson(id);
|
||||||
|
window.medDocsOpenShareModal = (id, event) => app.openShareModal(id, event);
|
||||||
|
window.medDocsCloseShareModal = (event) => app.closeShareModal(event);
|
||||||
|
window.medDocsGrantAccess = () => app.grantAccess();
|
||||||
|
window.medDocsRevokeAccess = (personId, userId) => app.revokeAccess(personId, userId);
|
||||||
})(MedDocs);
|
})(MedDocs);
|
||||||
|
|||||||
Reference in New Issue
Block a user