"""Engagement CRUD endpoints (flat, sprint 0).""" from __future__ import annotations from flask import Blueprint, abort, jsonify from sqlalchemy import select from mimic.api._helpers import jsonify_model, parse_body, parse_uuid from mimic.db.models import Engagement from mimic.db.types import EngagementStatus from mimic.extensions import db from mimic.rbac import Permission, require_perm from mimic.schemas import EngagementCreate, EngagementRead, EngagementUpdate bp = Blueprint("engagements", __name__) @bp.get("") @require_perm(Permission.ENGAGEMENT_READ) def list_engagements(): stmt = select(Engagement).order_by(Engagement.created_at.desc()) rows = db.session.execute(stmt).scalars().all() return jsonify([EngagementRead.model_validate(row).model_dump(mode="json") for row in rows]) @bp.post("") @require_perm(Permission.ENGAGEMENT_CREATE) def create_engagement(): payload = parse_body(EngagementCreate) engagement = Engagement( client_name=payload.client_name, description=payload.description, c2_type=payload.c2_type, start_date=payload.start_date, end_date=payload.end_date, status=EngagementStatus.DRAFT, ) db.session.add(engagement) db.session.commit() return jsonify_model(EngagementRead.model_validate(engagement), status=201) @bp.get("/") @require_perm(Permission.ENGAGEMENT_READ) def get_engagement(eid: str): engagement = db.session.get(Engagement, parse_uuid(eid)) if engagement is None: abort(404) return jsonify_model(EngagementRead.model_validate(engagement)) @bp.put("/") @require_perm(Permission.ENGAGEMENT_UPDATE) def update_engagement(eid: str): engagement = db.session.get(Engagement, parse_uuid(eid)) if engagement is None: abort(404) payload = parse_body(EngagementUpdate) for field, value in payload.model_dump(exclude_unset=True).items(): setattr(engagement, field, value) db.session.commit() return jsonify_model(EngagementRead.model_validate(engagement)) @bp.delete("/") @require_perm(Permission.ENGAGEMENT_DELETE) def delete_engagement(eid: str): engagement = db.session.get(Engagement, parse_uuid(eid)) if engagement is None: abort(404) engagement.status = EngagementStatus.ARCHIVED db.session.commit() return "", 204