001// --------------------------------------------------------------------------------
002// Copyright 2002-2026 Echo Three, LLC
003//
004// Licensed under the Apache License, Version 2.0 (the "License");
005// you may not use this file except in compliance with the License.
006// You may obtain a copy of the License at
007//
008//     http://www.apache.org/licenses/LICENSE-2.0
009//
010// Unless required by applicable law or agreed to in writing, software
011// distributed under the License is distributed on an "AS IS" BASIS,
012// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
013// See the License for the specific language governing permissions and
014// limitations under the License.
015// --------------------------------------------------------------------------------
016
017package com.echothree.control.user.payment.server.command;
018
019import com.echothree.control.user.payment.common.form.DeletePartyPaymentMethodForm;
020import com.echothree.model.control.party.common.PartyTypes;
021import com.echothree.model.control.payment.server.control.PartyPaymentMethodControl;
022import com.echothree.model.control.payment.server.logic.PartyPaymentMethodLogic;
023import com.echothree.model.control.security.common.SecurityRoleGroups;
024import com.echothree.model.control.security.common.SecurityRoles;
025import com.echothree.model.data.user.common.pk.UserVisitPK;
026import com.echothree.util.common.command.BaseResult;
027import com.echothree.util.common.command.SecurityResult;
028import com.echothree.util.common.validation.FieldDefinition;
029import com.echothree.util.common.validation.FieldType;
030import com.echothree.util.server.control.BaseSimpleCommand;
031import com.echothree.util.server.control.CommandSecurityDefinition;
032import com.echothree.util.server.control.PartyTypeDefinition;
033import com.echothree.util.server.control.SecurityRoleDefinition;
034import java.util.List;
035import javax.enterprise.context.Dependent;
036import javax.inject.Inject;
037
038@Dependent
039public class DeletePartyPaymentMethodCommand
040        extends BaseSimpleCommand<DeletePartyPaymentMethodForm> {
041    
042    private final static CommandSecurityDefinition COMMAND_SECURITY_DEFINITION;
043    private final static List<FieldDefinition> FORM_FIELD_DEFINITIONS;
044    
045    static {
046        COMMAND_SECURITY_DEFINITION = new CommandSecurityDefinition(List.of(
047                new PartyTypeDefinition(PartyTypes.UTILITY.name(), null),
048                new PartyTypeDefinition(PartyTypes.CUSTOMER.name(), null),
049                new PartyTypeDefinition(PartyTypes.EMPLOYEE.name(), List.of(
050                        new SecurityRoleDefinition(SecurityRoleGroups.PartyPaymentMethod.name(), SecurityRoles.Delete.name())
051                ))
052        ));
053
054        FORM_FIELD_DEFINITIONS = List.of(
055                new FieldDefinition("PartyPaymentMethodName", FieldType.ENTITY_NAME, true, null, null)
056        );
057    }
058
059    @Inject
060    PartyPaymentMethodControl partyPaymentMethodControl;
061
062    @Inject
063    PartyPaymentMethodLogic partyPaymentMethodLogic;
064
065    
066    /** Creates a new instance of DeletePartyPaymentMethodCommand */
067    public DeletePartyPaymentMethodCommand() {
068        super(COMMAND_SECURITY_DEFINITION, FORM_FIELD_DEFINITIONS, false);
069    }
070
071    @Override
072    protected SecurityResult security() {
073        // Execute the standard security check using COMMAND_SECURITY_DEFINITION.
074        var securityResult = super.security();
075
076        // If that passed, continue checking the executing Party vs. the Party owning the
077        // PartyPaymentMethod.
078        if(securityResult == null) {
079            var party = getParty();
080            var partyTypeName = party.getLastDetail().getPartyType().getPartyTypeName();
081
082            // If the executing Party is a CUSTOMER...
083            if(partyTypeName.equals(PartyTypes.CUSTOMER.name())) {
084                var partyPaymentMethodName = form.getPartyPaymentMethodName();
085                var partyPaymentMethod = partyPaymentMethodControl.getPartyPaymentMethodByNameForUpdate(partyPaymentMethodName);
086
087                if(partyPaymentMethod != null) {
088                    // ...and the PartyPaymentMethod isn't for the executing Party, return an
089                    // InsufficientSecurity error.
090                    if(!partyPaymentMethod.getLastDetail().getParty().equals(party)) {
091                        securityResult = getInsufficientSecurityResult();
092                    }
093                }
094            }
095        }
096
097        return securityResult;
098    }
099
100    @Override
101    protected BaseResult execute() {
102        var partyPaymentMethodName = form.getPartyPaymentMethodName();
103
104        partyPaymentMethodLogic.deletePartyPaymentMethod(this, partyPaymentMethodName, getPartyPK());
105
106        return null;
107    }
108    
109}