001// -------------------------------------------------------------------------------- 002// Copyright 2002-2026 Echo Three, LLC 003// 004// Licensed under the Apache License, Version 2.0 (the "License"); 005// you may not use this file except in compliance with the License. 006// You may obtain a copy of the License at 007// 008// http://www.apache.org/licenses/LICENSE-2.0 009// 010// Unless required by applicable law or agreed to in writing, software 011// distributed under the License is distributed on an "AS IS" BASIS, 012// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 013// See the License for the specific language governing permissions and 014// limitations under the License. 015// -------------------------------------------------------------------------------- 016 017package com.echothree.control.user.payment.server.command; 018 019import com.echothree.control.user.payment.common.form.DeletePartyPaymentMethodForm; 020import com.echothree.model.control.party.common.PartyTypes; 021import com.echothree.model.control.payment.server.control.PartyPaymentMethodControl; 022import com.echothree.model.control.payment.server.logic.PartyPaymentMethodLogic; 023import com.echothree.model.control.security.common.SecurityRoleGroups; 024import com.echothree.model.control.security.common.SecurityRoles; 025import com.echothree.model.data.user.common.pk.UserVisitPK; 026import com.echothree.util.common.command.BaseResult; 027import com.echothree.util.common.command.SecurityResult; 028import com.echothree.util.common.validation.FieldDefinition; 029import com.echothree.util.common.validation.FieldType; 030import com.echothree.util.server.control.BaseSimpleCommand; 031import com.echothree.util.server.control.CommandSecurityDefinition; 032import com.echothree.util.server.control.PartyTypeDefinition; 033import com.echothree.util.server.control.SecurityRoleDefinition; 034import java.util.List; 035import javax.enterprise.context.Dependent; 036import javax.inject.Inject; 037 038@Dependent 039public class DeletePartyPaymentMethodCommand 040 extends BaseSimpleCommand<DeletePartyPaymentMethodForm> { 041 042 private final static CommandSecurityDefinition COMMAND_SECURITY_DEFINITION; 043 private final static List<FieldDefinition> FORM_FIELD_DEFINITIONS; 044 045 static { 046 COMMAND_SECURITY_DEFINITION = new CommandSecurityDefinition(List.of( 047 new PartyTypeDefinition(PartyTypes.UTILITY.name(), null), 048 new PartyTypeDefinition(PartyTypes.CUSTOMER.name(), null), 049 new PartyTypeDefinition(PartyTypes.EMPLOYEE.name(), List.of( 050 new SecurityRoleDefinition(SecurityRoleGroups.PartyPaymentMethod.name(), SecurityRoles.Delete.name()) 051 )) 052 )); 053 054 FORM_FIELD_DEFINITIONS = List.of( 055 new FieldDefinition("PartyPaymentMethodName", FieldType.ENTITY_NAME, true, null, null) 056 ); 057 } 058 059 @Inject 060 PartyPaymentMethodControl partyPaymentMethodControl; 061 062 @Inject 063 PartyPaymentMethodLogic partyPaymentMethodLogic; 064 065 066 /** Creates a new instance of DeletePartyPaymentMethodCommand */ 067 public DeletePartyPaymentMethodCommand() { 068 super(COMMAND_SECURITY_DEFINITION, FORM_FIELD_DEFINITIONS, false); 069 } 070 071 @Override 072 protected SecurityResult security() { 073 // Execute the standard security check using COMMAND_SECURITY_DEFINITION. 074 var securityResult = super.security(); 075 076 // If that passed, continue checking the executing Party vs. the Party owning the 077 // PartyPaymentMethod. 078 if(securityResult == null) { 079 var party = getParty(); 080 var partyTypeName = party.getLastDetail().getPartyType().getPartyTypeName(); 081 082 // If the executing Party is a CUSTOMER... 083 if(partyTypeName.equals(PartyTypes.CUSTOMER.name())) { 084 var partyPaymentMethodName = form.getPartyPaymentMethodName(); 085 var partyPaymentMethod = partyPaymentMethodControl.getPartyPaymentMethodByNameForUpdate(partyPaymentMethodName); 086 087 if(partyPaymentMethod != null) { 088 // ...and the PartyPaymentMethod isn't for the executing Party, return an 089 // InsufficientSecurity error. 090 if(!partyPaymentMethod.getLastDetail().getParty().equals(party)) { 091 securityResult = getInsufficientSecurityResult(); 092 } 093 } 094 } 095 } 096 097 return securityResult; 098 } 099 100 @Override 101 protected BaseResult execute() { 102 var partyPaymentMethodName = form.getPartyPaymentMethodName(); 103 104 partyPaymentMethodLogic.deletePartyPaymentMethod(this, partyPaymentMethodName, getPartyPK()); 105 106 return null; 107 } 108 109}