shoc-backend/SeaHaven.Services/Helpers/SeaHavenClaimTypes.cs

34 lines
1.2 KiB
C#
Raw Normal View History

namespace SeaHaven.Services.Helpers
{
/// <summary>Server-derived claim type names emitted at token issuance.</summary>
public static class SeaHavenClaimTypes
{
/// <summary>CRM account id from <c>ApplicationUser.AccountId</c> (never from request body).</summary>
public const string AccountId = "account_id";
/// <summary>Explicit org-wide media scope; value <see cref="OrgScopeAll"/>.</summary>
public const string OrgScope = "org_scope";
/// <summary>Signed org-wide elevation (Admin without AccountId).</summary>
public const string OrgScopeAll = "all";
/// <summary>
/// A keyed hash of the account's security stamp at sign-in. Never the stamp
/// itself: the token is readable by whoever holds it.
/// </summary>
public const string SessionStamp = "session_stamp";
}
/// <summary>Resolved media tenant scope from signed claims (fail-closed when Missing).</summary>
public abstract record MediaAccountScope
{
private MediaAccountScope() { }
public sealed record Account(int AccountId) : MediaAccountScope;
public sealed record OrgWide : MediaAccountScope;
public sealed record Missing : MediaAccountScope;
}
}