@@ -454,23 +454,38 @@ private async Task PopulateStudentInfoAsync(UserInfoResult result)
454454 }
455455
456456 /// <summary>
457- /// Get current or future term for student - equivalent to getCurrentOrFutureTermForUser in SIS.cfc
457+ /// Get current or future term for student - equivalent to getCurrentOrFutureTermForUser in SIS.cfc.
458+ ///
459+ /// Runs over its own connection built from the AAUD connection string rather than
460+ /// _aaudContext, which this class otherwise uses only for EF entity queries - mixing raw
461+ /// SQL and EF entities on the same context causes auth failures. No database qualifier on
462+ /// the proc name either, so this follows whatever database the connection string points at,
463+ /// same as the SIS raw SQL calls below.
458464 /// </summary>
459465 private async Task < string ? > GetCurrentOrFutureTermForStudentAsync ( UserInfoResult result , string pidm )
460466 {
461467 try
462468 {
469+ var connectionString = _configuration . GetConnectionString ( "AAUD" )
470+ ?? throw new InvalidOperationException ( "Connection string 'AAUD' not configured" ) ;
471+
472+ await using var connection = new Microsoft . Data . SqlClient . SqlConnection ( connectionString ) ;
473+ await using var command = new Microsoft . Data . SqlClient . SqlCommand (
474+ "EXEC dbo.usp_get_CurrentOrFutureTermForUser @pidm = @pidm, @loginID = NULL, @termCode = @termCode OUTPUT" ,
475+ connection ) ;
476+
477+ command . Parameters . Add ( new Microsoft . Data . SqlClient . SqlParameter ( "@pidm" , pidm ) ) ;
478+
463479 var termCodeParam = new Microsoft . Data . SqlClient . SqlParameter
464480 {
465481 ParameterName = "@termCode" ,
466482 SqlDbType = System . Data . SqlDbType . Int ,
467483 Direction = System . Data . ParameterDirection . Output
468484 } ;
485+ command . Parameters . Add ( termCodeParam ) ;
469486
470- await _aaudContext . Database . ExecuteSqlRawAsync (
471- "EXEC AAUD.dbo.usp_get_CurrentOrFutureTermForUser @pidm = @pidm, @loginID = NULL, @termCode = @termCode OUTPUT" ,
472- new Microsoft . Data . SqlClient . SqlParameter ( "@pidm" , pidm ) ,
473- termCodeParam ) ;
487+ await connection . OpenAsync ( ) ;
488+ await command . ExecuteNonQueryAsync ( ) ;
474489
475490 var value = termCodeParam . Value ;
476491 return value == null || value == DBNull . Value ? null : value . ToString ( ) ;
@@ -723,7 +738,7 @@ private async Task PopulateIamInfoAsync(UserInfoResult result)
723738 // Get people information - equivalent to iamPeople.getById() in ColdFusion
724739 var peopleResponse = await iamApi . SearchForPerson ( iamId : result . IamId ) ;
725740 _logger . LogDebug ( "IAM people response data count {Count}, error {Error}" ,
726- peopleResponse . Data ? . Count ( ) , peopleResponse . ErrorMessage ?? "none" ) ;
741+ peopleResponse . Data ? . Count ( ) , LogSanitizer . SanitizeString ( peopleResponse . ErrorMessage ) ?? "none" ) ;
727742 if ( peopleResponse . Data ? . Any ( ) == true )
728743 {
729744 result . IamPeople = peopleResponse . Data . ToList ( ) ;
@@ -739,7 +754,7 @@ private async Task PopulateIamInfoAsync(UserInfoResult result)
739754 // Get employee associations - equivalent to iamAssociations.getEmployeeAssociations() in ColdFusion
740755 var associationsResponse = await iamApi . GetEmployeeAssociations ( result . IamId ) ;
741756 _logger . LogDebug ( "IAM associations response data count {Count}, error {Error}" ,
742- associationsResponse . Data ? . Count ( ) , associationsResponse . ErrorMessage ?? "none" ) ;
757+ associationsResponse . Data ? . Count ( ) , LogSanitizer . SanitizeString ( associationsResponse . ErrorMessage ) ?? "none" ) ;
743758 if ( associationsResponse . Data ? . Any ( ) == true )
744759 {
745760 result . IamAssociations = associationsResponse . Data . ToList ( ) ;
@@ -1513,9 +1528,14 @@ query SearchUsers($name: String!) {
15131528 }
15141529 else
15151530 {
1531+ // No candidates is the common case - most VIPER users don't have an
1532+ // Instinct account. That's not a failure, so leave Valid false and
1533+ // ErrorMessage unset: PopulateInstinctInfoAsync only flags "Instinct" as
1534+ // an unavailable section when ErrorMessage is set, and this isn't one.
15161535 // Do not include other candidates' names from the search results here -
15171536 // they belong to unrelated people and would leak into this user's directory page.
1518- result . ErrorMessage = $ "User found in API but no name match. Variations tried: { string . Join ( ", " , nameVariations ) } .";
1537+ _logger . LogDebug ( "Instinct API: no account matched {LastName}, {FirstName}. Variations tried: {Variations}" ,
1538+ LogSanitizer . SanitizeString ( lastName ) , LogSanitizer . SanitizeString ( firstName ) , string . Join ( ", " , nameVariations ) ) ;
15191539 }
15201540 }
15211541 else
@@ -1548,7 +1568,7 @@ private static void AppendError(InstinctResult result, string msg)
15481568 if ( string . IsNullOrWhiteSpace ( apiUrl ) )
15491569 {
15501570 const string errMsg = "Instinct:ApiUrl is not configured" ;
1551- _logger . LogWarning ( "Instinct API: {ErrorMessage}" , errMsg ) ;
1571+ _logger . LogWarning ( "Instinct API: {ErrorMessage}" , LogSanitizer . SanitizeString ( errMsg ) ) ;
15521572 AppendError ( result , errMsg ) ;
15531573 return null ;
15541574 }
@@ -1586,7 +1606,7 @@ private static void AppendError(InstinctResult result, string msg)
15861606 if ( string . IsNullOrEmpty ( password ) )
15871607 {
15881608 string errMsg = "Password is null or empty in configuration" ;
1589- _logger . LogWarning ( "Instinct auth: {ErrorMessage}" , errMsg ) ;
1609+ _logger . LogWarning ( "Instinct auth: {ErrorMessage}" , LogSanitizer . SanitizeString ( errMsg ) ) ;
15901610 AppendError ( result , errMsg ) ;
15911611 return null ;
15921612 }
@@ -1629,7 +1649,7 @@ private static void AppendError(InstinctResult result, string msg)
16291649 {
16301650 var responseContent = await response . Content . ReadAsStringAsync ( ) ;
16311651 string errMsg = $ "Token POST request failed (Status: { response . StatusCode } ): { responseContent } ";
1632- _logger . LogWarning ( "Instinct auth: {ErrorMessage}" , errMsg ) ;
1652+ _logger . LogWarning ( "Instinct auth: {ErrorMessage}" , LogSanitizer . SanitizeString ( errMsg ) ) ;
16331653 AppendError ( result , errMsg ) ;
16341654 }
16351655 }
0 commit comments