public async Task <ActionResult> DataQuerySubmission(DataQueryViewModel dataQuery, long?urn, string schoolName) { ViewBag.ModelState = ModelState; if (ModelState.IsValid) { var emailReference = GenerateEmailReference(dataQuery); ViewBag.EmailReference = emailReference; var placeholders = new Dictionary <string, dynamic> { { "EmailReference ", emailReference }, { "Name", FormFieldSanitizer.SanitizeFormField(dataQuery.Name) }, { "Email", dataQuery.Email }, { "SchoolTrustName", FormFieldSanitizer.SanitizeFormField(dataQuery.SchoolTrustName) }, { "SchoolTrustReferenceNumber", FormFieldSanitizer.SanitizeFormField(dataQuery.SchoolTrustReferenceNumber) }, { "DataQuery", dataQuery.DataQuery } }; try { await _emailSender.SendDataQueryUserEmailAsync(dataQuery.Email, placeholders); await _emailSender.SendDataQueryDfEEmailAsync(ConfigurationManager.AppSettings["SRMEmailAddress"], placeholders); } catch (HttpRequestValidationException exc) { var enableAITelemetry = WebConfigurationManager.AppSettings["EnableAITelemetry"]; if (enableAITelemetry != null && bool.Parse(enableAITelemetry)) { var ai = new TelemetryClient(); ai.TrackException(exc); ai.TrackTrace($"Data query email rejected due to SQL injection attack!"); ai.TrackTrace($"Data query email sending failed for: {dataQuery.Name} - ({dataQuery.Email}) ({dataQuery.SchoolTrustName}) ({dataQuery.SchoolTrustReferenceNumber})"); } throw exc; } catch (Exception exception) { var enableAITelemetry = WebConfigurationManager.AppSettings["EnableAITelemetry"]; if (enableAITelemetry != null && bool.Parse(enableAITelemetry)) { var ai = new TelemetryClient(); ai.TrackException(exception); ai.TrackTrace($"Data query email sending error: {exception.Message}"); ai.TrackTrace($"Data query email sending failed for: {dataQuery.Name} ({dataQuery.Email}) - ref: {emailReference}"); } throw; } ViewBag.Urn = urn; ViewBag.SchoolName = schoolName; return(View("DataQueryConfirmation")); } else { ViewBag.Urn = urn; ViewBag.SchoolName = schoolName; return(View("DataQueries", dataQuery)); } }