2026-08-06 09:47:34 -03:00
|
|
|
namespace SeaHaven.Services.Helpers
|
|
|
|
|
{
|
|
|
|
|
/// <summary>Server-derived claim type names emitted at token issuance.</summary>
|
|
|
|
|
public static class SeaHavenClaimTypes
|
|
|
|
|
{
|
|
|
|
|
/// <summary>CRM account id from <c>ApplicationUser.AccountId</c> (never from request body).</summary>
|
|
|
|
|
public const string AccountId = "account_id";
|
2026-08-06 10:26:04 -03:00
|
|
|
|
|
|
|
|
/// <summary>Explicit org-wide media scope; value <see cref="OrgScopeAll"/>.</summary>
|
|
|
|
|
public const string OrgScope = "org_scope";
|
|
|
|
|
|
|
|
|
|
/// <summary>Signed org-wide elevation (Admin without AccountId).</summary>
|
|
|
|
|
public const string OrgScopeAll = "all";
|
2026-09-25 19:08:33 -03:00
|
|
|
|
|
|
|
|
/// <summary>
|
|
|
|
|
/// A keyed hash of the account's security stamp at sign-in. Never the stamp
|
|
|
|
|
/// itself: the token is readable by whoever holds it.
|
|
|
|
|
/// </summary>
|
|
|
|
|
public const string SessionStamp = "session_stamp";
|
2026-08-06 10:26:04 -03:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// <summary>Resolved media tenant scope from signed claims (fail-closed when Missing).</summary>
|
|
|
|
|
public abstract record MediaAccountScope
|
|
|
|
|
{
|
|
|
|
|
private MediaAccountScope() { }
|
|
|
|
|
|
|
|
|
|
public sealed record Account(int AccountId) : MediaAccountScope;
|
|
|
|
|
|
|
|
|
|
public sealed record OrgWide : MediaAccountScope;
|
|
|
|
|
|
|
|
|
|
public sealed record Missing : MediaAccountScope;
|
2026-08-06 09:47:34 -03:00
|
|
|
}
|
|
|
|
|
}
|