Compare commits

...

12 Commits

2 changed files with 335 additions and 4 deletions

View File

@@ -1,10 +1,13 @@
<?php
namespace App\Application;
use phpDocumentor\Reflection\Types\Integer;
class EmployeeApplication{
private $pdo;
private $cryptographyService;
private $asserts;
private $settings;
function __construct($employeeSettings, $mysql, $cryptographyService, $asserts){
$this->settings = $employeeSettings;
@@ -20,7 +23,12 @@ class EmployeeApplication{
* @return array
*/
function listEmployeeTypes(){
$stmt = $this->pdo->prepare("SELECT id, name FROM employeeType WHERE status = 'ACTIVE'");
$stmt = $this->pdo->prepare("SELECT
id, name
FROM
employeeType
WHERE
status = 'ACTIVE'");
$stmt->execute();
$results = $stmt->fetchAll();
@@ -34,9 +42,9 @@ class EmployeeApplication{
}
/**
* @param $firstName varbinary
* @param $middleName varbinary
* @param $lastName varbinary or null
* @param $firstName binary
* @param $middleName binary
* @param $lastName binary or null
* @param $birthDate date yyyy-mm-dd
* @param $email string
* @param $phone string
@@ -150,5 +158,290 @@ class EmployeeApplication{
return $response;
}
/**
* @param $idEmployee
* @return Integer
*/
function getIdPersonByIdEmployee($idEmployee){
$stmt = $this->pdo->prepare("SELECT
COALESCE((SELECT
idPerson
FROM
employees
WHERE
id = :idEmployee),
0) AS id");
$stmt->execute(array(':idEmployee' => $idEmployee));
$results = $stmt->fetchAll();
if(!$results){
exit($this->databaseSelectQueryErrorMessage);
}
$stmt = null;
return $results[0]['id'];
}
/**
* @param $code
* @return mixed
*/
function getIdEmployeeTypeByCode($code){
$stmt = $this->pdo->prepare("SELECT COALESCE((SELECT
et.id
FROM
employees e
INNER JOIN
employeeType et ON et.id = e.idEmployeeType
WHERE
e.code = :code), 0) AS id");
$stmt->execute(array(':code' => $code));
$results = $stmt->fetchAll();
if(!$results){
exit($this->databaseSelectQueryErrorMessage);
}
$stmt = null;
return $results[0]['id'];
}
/**
* Gets the data associated with the employee
*
* @param $idEmployee
* @return array
*/
function getEmployeeDataById($idEmployee){
$stmt = $this->pdo->prepare("SELECT
p.id AS idPerson,
p.firstName,
p.middleName,
IFNULL(p.lastName, '') AS lastName,
p.email,
p.phone,
e.code,
e.contractType
FROM
employees e
INNER JOIN
persons p ON p.id = e.idPerson
WHERE
e.id = :idEmployee");
$stmt->execute(array(':idEmployee' => $idEmployee));
$results = $stmt->fetchAll();
if(!$results){
exit($this->databaseSelectQueryErrorMessage);
}
$stmt = null;
return $results[0];
}
/**
* Acts as a man in the middle for the getEmployeeDataById method to decrypt the contents
* and make the necesary data manipulations
*
* @param $idEmployee
* @return array
*/
function proxyGetEmployeeDataById($idEmployee){
$employeeData = $this->getEmployeeDataById($idEmployee);
$response = array(
"idPerson" => (int)$employeeData['idPerson'],
"firstName" => $this->cryptographyService->decryptString($employeeData['firstName']),
"middleName" => $this->cryptographyService->decryptString($employeeData['middleName']),
"lastName" => strlen($employeeData['lastName']) > 0
? $this->cryptographyService->decryptString($employeeData['lastName'])
: '',
"email" => $this->cryptographyService->decryptString($employeeData['email']),
"phone" => $employeeData['phone'],
"code" => $employeeData['code'],
"contractType" => $employeeData['contractType']
);
return $response;
}
/**
* @param $idPerson integer
* @param $firstName binary
* @param $middleName binary
* @param $lastName binary
* @param $birthDate date
* @param $email binary
* @param $phone string
*/
function updatePerson($idPerson, $firstName, $middleName, $lastName, $birthDate, $email, $phone){
try {
$stmt = $this->pdo->prepare("UPDATE persons
SET
firstName = :firstName,
middleName = :middleName,
lastName = :lastName,
birthDate = :birthDate,
email = :email,
phone = :phone
WHERE
id = :idPerson");
$this->pdo->beginTransaction();
$stmt->execute(array(':firstName' => $firstName, ':middleName' => $middleName, ':lastName' => $lastName,
':birthDate' => $birthDate, ':email' => $email, ':phone' => $phone, ':idPerson' => $idPerson));
$this->pdo->commit();
$stmt = null;
} catch( PDOExecption $e ) {
$this->pdo->rollback();
}
}
/**
* @param $idEmployee integer
* @param $code string
* @param $idEmployeeType integer
* @param $contractType string
*/
function updateEmployee($idEmployee, $code, $idEmployeeType, $contractType){
try {
$stmt = $this->pdo->prepare("UPDATE employees
SET
idEmployeeType = :idEmployeeType,
code = :code,
contractType = :contractType
WHERE
id = :idEmployee");
$this->pdo->beginTransaction();
$stmt->execute(array(':idEmployeeType' => $idEmployeeType, ':code' => $code, ':contractType' => $contractType,
':idEmployee' => $idEmployee));
$this->pdo->commit();
$stmt = null;
} catch( PDOExecption $e ) {
$this->pdo->rollback();
}
}
/**
* @param $requestData object
* @return array
*/
function updateEmployeeData($requestData){
// Getting and validating the data
$idEmployee = $requestData['idEmployee'];
$idPerson = $this->getIdPersonByIdEmployee($idEmployee);
$code = $requestData['code'];
$firstName = $requestData['firstName'];
$this->asserts->firstName($firstName);
$middleName = $requestData['middleName'];
$this->asserts->middleName($middleName);
$lastName = isset($requestData['lastName']) ? $requestData['lastName'] : null;
$birthDate = $requestData['birthDate'];
$this->asserts->birthDate($birthDate);
$email = $requestData['email'];
$this->asserts->email($email);
$phone = $requestData['phone'];
$this->asserts->phone($phone);
$idEmployeeType = $requestData{'idEmployeeType'};
$contractType = $requestData{'contractType'};
// Encrypting the sensitive data
$securedFirstName = $this->cryptographyService->encryptString($firstName);
$securedMiddleName = $this->cryptographyService->encryptString($middleName);
if (isset($lastName)) {
$securedLastName = $this->cryptographyService->encryptString($lastName);
} else {
$securedLastName = null;
}
$securedEmail = $this->cryptographyService->encryptString($email);
// Update process
$this->updatePerson($idPerson, $securedFirstName, $securedMiddleName, $securedLastName,
$birthDate, $securedEmail, $phone);
$this->updateEmployee($idEmployee, $code, $idEmployeeType, $contractType);
$response = array(
"fullName" => "$firstName $middleName $lastName",
"idEmployee" => $idEmployee,
"email" => $email,
"phone" => $phone,
"birthDate" => $birthDate,
"idEmployeeType" => $idEmployeeType,
"contractType" => $contractType
);
return $response;
}
function disableEmployeeRecord($idEmployee){
try {
$stmt = $this->pdo->prepare("UPDATE employees
SET
status = 'INACTIVE'
WHERE
id = :idEmployee");
$this->pdo->beginTransaction();
$stmt->execute(array(':idEmployee' => $idEmployee));
$this->pdo->commit();
$stmt = null;
} catch( PDOExecption $e ) {
$this->pdo->rollback();
}
}
/**
* Intended for internal use
*
* This method will bring a list of ids of all the employees that are
* currently active in the system
*
* @return array
*/
function getIdEmployeeFromAllActiveEmployees(){
$stmt = $this->pdo->prepare("SELECT
id
FROM
employees
WHERE
status = 'ACTIVE';");
$stmt->execute();
$results = $stmt->fetchAll();
if(!$results){
exit($this->databaseSelectQueryErrorMessage);
}
$stmt = null;
return $results;
}
function listAllActiveEmployees(){
$ids = $this->getIdEmployeeFromAllActiveEmployees();
$result = array();
foreach($ids as $row){
$result[] = $this->proxyGetEmployeeDataById($row['id']);
}
return $result;
}
}
?>

View File

@@ -41,6 +41,12 @@ $app->get('/api/employee/types', function (Request $request, Response $response,
->write(json_encode($this->employeeApplication->listEmployeeTypes()));
});
$app->get('/api/employee/all', function (Request $request, Response $response, array $args) {
return $response->withStatus(200)
->withHeader('Content-Type', 'application/json')
->write(json_encode($this->employeeApplication->listAllActiveEmployees()));
});
$app->post('/api/employee', function ($request, $response) {
$requestData = $request->getParsedBody();
@@ -48,3 +54,35 @@ $app->post('/api/employee', function ($request, $response) {
->withHeader('Content-Type', 'application/json')
->write(json_encode($this->employeeApplication->saveNewEmployee($requestData)));
});
$app->put('/api/employee', function ($request, $response) {
$requestData = $request->getParsedBody();
return $response->withStatus(200)
->withHeader('Content-Type', 'application/json')
->write(json_encode($this->employeeApplication->updateEmployeeData($requestData)));
});
$app->DELETE('/api/employee/{idEmployee}', function (Request $request, Response $response, array $args) {
$idEmployee = $args['idEmployee'];
return $response->withStatus(200)
->withHeader('Content-Type', 'application/json')
->write(json_encode($this->employeeApplication->disableEmployeeRecord($idEmployee)));
});
$app->get('/api/employee/type/{code}', function (Request $request, Response $response, array $args) {
$code = $args['code'];
return $response->withStatus(200)
->withHeader('Content-Type', 'application/json')
->write(json_encode($this->employeeApplication->getIdEmployeeTypeByCode($code)));
});
$app->get('/api/employee/{idEmployee}', function (Request $request, Response $response, array $args) {
$idEmployee = $args['idEmployee'];
return $response->withStatus(200)
->withHeader('Content-Type', 'application/json')
->write(json_encode($this->employeeApplication->proxyGetEmployeeDataById($idEmployee)));
});