Example #1
0
        public async Task <ActionResult> DataQuerySubmission(DataQueryViewModel dataQuery, long?urn, string schoolName)
        {
            ViewBag.ModelState = ModelState;
            if (ModelState.IsValid)
            {
                var emailReference = GenerateEmailReference(dataQuery);
                ViewBag.EmailReference = emailReference;

                var placeholders = new Dictionary <string, dynamic> {
                    { "EmailReference ", emailReference },
                    { "Name", FormFieldSanitizer.SanitizeFormField(dataQuery.Name) },
                    { "Email", dataQuery.Email },
                    { "SchoolTrustName", FormFieldSanitizer.SanitizeFormField(dataQuery.SchoolTrustName) },
                    { "SchoolTrustReferenceNumber", FormFieldSanitizer.SanitizeFormField(dataQuery.SchoolTrustReferenceNumber) },
                    { "DataQuery", dataQuery.DataQuery }
                };

                try
                {
                    await _emailSender.SendDataQueryUserEmailAsync(dataQuery.Email, placeholders);

                    await _emailSender.SendDataQueryDfEEmailAsync(ConfigurationManager.AppSettings["SRMEmailAddress"], placeholders);
                }
                catch (HttpRequestValidationException exc)
                {
                    var enableAITelemetry = WebConfigurationManager.AppSettings["EnableAITelemetry"];

                    if (enableAITelemetry != null && bool.Parse(enableAITelemetry))
                    {
                        var ai = new TelemetryClient();
                        ai.TrackException(exc);
                        ai.TrackTrace($"Data query email rejected due to SQL injection attack!");
                        ai.TrackTrace($"Data query email sending failed for: {dataQuery.Name} - ({dataQuery.Email}) ({dataQuery.SchoolTrustName}) ({dataQuery.SchoolTrustReferenceNumber})");
                    }
                    throw exc;
                }
                catch (Exception exception)
                {
                    var enableAITelemetry = WebConfigurationManager.AppSettings["EnableAITelemetry"];

                    if (enableAITelemetry != null && bool.Parse(enableAITelemetry))
                    {
                        var ai = new TelemetryClient();
                        ai.TrackException(exception);
                        ai.TrackTrace($"Data query email sending error: {exception.Message}");
                        ai.TrackTrace($"Data query email sending failed for: {dataQuery.Name} ({dataQuery.Email}) - ref: {emailReference}");
                    }
                    throw;
                }

                ViewBag.Urn        = urn;
                ViewBag.SchoolName = schoolName;
                return(View("DataQueryConfirmation"));
            }
            else
            {
                ViewBag.Urn        = urn;
                ViewBag.SchoolName = schoolName;
                return(View("DataQueries", dataQuery));
            }
        }