USE [Elyse_DB]
GO
/****** Object:  StoredProcedure [controlling].[usp_DEL_restricted_form_id]    Script Date: Sat 05-09-2026 7:01:55 AM ******/
SET ANSI_NULLS ON
GO
SET QUOTED_IDENTIFIER ON
GO
-- =============================================
-- Author:		Silkwood Software
-- Create date: 02-08-2023
-- Description:	Initial creation
-- Deletes a form id but not if owned by others
-- Input is a form id
-- Output is a message and transaction status
-- 05-08-2023 Added user authentication
-- =============================================
CREATE PROCEDURE [controlling].[usp_DEL_restricted_form_id]

     @id_to_delete bigint             = NULL,
	 @message nvarchar(1000)          = '' OUTPUT,
	 @transaction_status nvarchar(50) = NULL OUTPUT

AS
BEGIN
	-- SET NOCOUNT ON added to prevent extra result sets from
	-- interfering with SELECT statements.
	SET NOCOUNT ON;
  DECLARE 
  		@nopermissionmessage nvarchar(200)      = '', -- Communicates that the user does not have the required permission
	    @connectedusersid varbinary(100)        = SUSER_SID(ORIGINAL_LOGIN()),   -- The SID of the connected user
	    @username nvarchar(150)                 = ORIGINAL_LOGIN(),     -- The username 
		@tempuserauth_status nchar(10)          = '',     -- Temporary value for authentication sp.
		@userauthentication_status nchar(10)    = 'Fail', -- The outcome of the authentication check of the user 
		                                                  -- Defaults to Fail until it is set to Pass.
        @tempmessage nvarchar(300)              = '',
	    @transactionmessage nvarchar(300)       = '', -- Communicates what was the outcome of the transaction
	    @validationmessage nvarchar(200)        = '', -- Communicates that the transaction failed due to data validation
	    @notexistmessage nvarchar(200)          = '', -- Communicates that the form group id does not exist
		@norecordmessage nvarchar(200)          = '', -- Communicates that no record id was supplied
		@transaction_ready nchar(10)            = 'Ready',
        @data_validation_status nchar(10)       = 'Pass';


  -- Parameters which have been initialised at declaration but not explicitly set might be output as null to calling functions.
  SET @transaction_status = 'Transaction not attempted';  

-- Connected user authentication
  -- Authenticate the connected user for the role
  EXEC [internal].[usp_AUTHENTICATE_user_role] 
        @role_to_check = 'Controller',
		@user_authentication_result = @tempuserauth_status OUTPUT;
  IF @tempuserauth_status = 'Fail'
    BEGIN  -- The user does not have permission for this action
	    SET @userauthentication_status = 'Fail';
		SET @transaction_ready         = 'Fail';
	    EXEC internal.usp_SEL_message 
            @message_id   = 'NoPermission', 
			@message_text = @tempmessage OUTPUT;
	    IF (@tempmessage IS NOT NULL) 
  	       SET @nopermissionmessage = ISNULL(@username, '') + '  ' + @tempmessage;
	    ELSE 
		   SET @nopermissionmessage = 'A database level message error occurred on NoPermission.';
	END

	 -- Authenticate the user for that form group
	  EXEC [internal].[usp_AUTHENTICATE_user_form] 
			@form_id_to_check = @id_to_delete,
			@user_authentication_result = @tempuserauth_status OUTPUT;
	  IF @tempuserauth_status = 'Fail'
		BEGIN  -- The user does not have permission for this action
			SET @userauthentication_status = 'Fail';
			SET @transaction_ready         = 'Fail';
			EXEC internal.usp_SEL_message 
				@message_id   = 'NoPermission', 
				@message_text = @tempmessage OUTPUT;
			IF (@tempmessage IS NOT NULL) 
  			SET @nopermissionmessage = ISNULL(@username, '') + '  ' + @tempmessage;
			ELSE 
				SET @nopermissionmessage = 'A database level message error occurred on NoPermission.';
		END

  IF @userauthentication_status = 'Pass' -- Don't do anything if the user is not authorised.
    BEGIN
	 -- Validation checks
	 IF @id_to_delete = 0
		SET @id_to_delete = NULL;
	 -- Check the ID has not been supplied
	 IF @id_to_delete IS NULL
		 BEGIN
		   SET @data_validation_status = 'Fail';
		   SET @transaction_ready      = 'Fail';
		   EXEC internal.usp_SEL_message 
				@message_id = 'NoRecordID', 
				@message_text = @tempmessage OUTPUT;
  		   IF (@tempmessage IS NOT NULL) 
			  SET @norecordmessage = @tempmessage;
		   ELSE 
			   SET @norecordmessage = 'A database level message error occurred on NoNameID.';
		 END
	  ELSE -- A record id has been supplied
		 BEGIN  -- Check if the id does not exist
		   IF NOT EXISTS (SELECT form_id 
							FROM forms.form_identifier_names 
						   WHERE form_id = @id_to_delete) 
			   BEGIN
				 EXEC internal.usp_SEL_message 
					  @message_id   = 'NotExist', 
					  @message_text = @tempmessage OUTPUT;
				 IF (@tempmessage IS NOT NULL) 
  					SET @notexistmessage = CONVERT(nvarchar(10), @id_to_delete) + ' | ' +  @tempmessage;
				 ELSE 
					  SET @notexistmessage = 'A database level message error occurred on NotExist.';
				 SET @data_validation_status = 'Fail';
				 SET @transaction_ready      = 'Fail';
			   END
		 END

	  

	  IF @data_validation_status = 'Fail'  
		BEGIN
		  EXEC internal.usp_SEL_message 
			   @message_id   = 'FailedDataValidation', 
			   @message_text = @tempmessage OUTPUT;
		  IF (@tempmessage IS NOT NULL) 
			  SET @validationmessage = @tempmessage;
		  ELSE 
			   SET @validationmessage = 'A database level message error occurred on FailedDataValidation.';
		END


	-- End of validation checks
    END -- End user authentication = Pass

  -- Execute the delete query
  IF @transaction_ready = 'Ready'
	BEGIN
	  BEGIN TRY
	   BEGIN TRANSACTION;
	     DELETE FROM forms.form_identifier_names 
		       WHERE form_id = @id_to_delete;
	   COMMIT TRANSACTION;
         EXEC internal.usp_SEL_message 
              @message_id   = 'Success', 
              @message_text = @tempmessage OUTPUT;
  	     IF (@tempmessage IS NOT NULL) 
	        SET @transactionmessage = @tempmessage;
	     ELSE 
		     SET @transactionmessage = 'A database level message error occurred on Success.';
	     SET @transaction_status = 'Good';
   	  END TRY
	  BEGIN CATCH

	     IF XACT_STATE() <> 0
            ROLLBACK TRANSACTION;
	  	 
	     SET @transaction_status = 'Bad';
         EXEC internal.usp_SEL_message 
              @message_id   = 'DeleteError', 
              @message_text = @tempmessage OUTPUT;
		 IF (@tempmessage IS NOT NULL) 
		    SET @transactionmessage = @tempmessage + ' | ' + 
		    CONVERT(nvarchar(10),ERROR_NUMBER()) + ' | ' + ERROR_MESSAGE();
		 ELSE 
		      SET @transactionmessage = 'A database level message error occurred on DeleteError.';
	  END CATCH
    END

-- Concatenate the messages
/*
NOTE: "The + (String Concatenation) operator behaves differently when it works with an empty, 
zero-length string than when it works with NULL, or unknown values. A zero-length 
character string can be specified as two single quotation marks without any characters 
inside the quotation marks. A zero-length binary string can be specified as 0x without 
any byte values specified in the hexadecimal constant. Concatenating a zero-length string 
always concatenates the two specified strings. When you work with strings with a null value, 
the result of the concatenation depends on the session settings. Just like arithmetic 
operations that are performed on null values, when a null value is added to a known 
value the result is typically an unknown value, a string concatenation operation that 
is performed with a null value should also produce a null result." 
*/
    IF (@message = '' OR @message IS NULL) SET @message = ' ';
	IF (@transactionmessage <> '')         SET @message = @transactionmessage;
    IF (@validationmessage <> '')          SET @message = @message + ' | ' + @validationmessage;
	IF (@notexistmessage <> '')            SET @message = @message + ' | ' + @notexistmessage;
	IF (@norecordmessage <> '')            SET @message = @message + ' | ' + @norecordmessage;
	IF (@nopermissionmessage <> '')        SET @message = @message + ' | ' + @nopermissionmessage;
	


END
GO
