using System.Security.Claims; namespace SeaHaven.Services.Interfaces { /// /// Server-derived work-order account scope (SH-221): claims for authenticated callers, /// unique Accounts.Name ↔ Customer for org-wide / unauthenticated creates. /// public interface IWorkOrderAccountResolver { /// /// Account filter for reads. Null = org-wide (skip ApplyAccountScope). /// Throws Forbidden when scope is Missing. /// int? ResolveAccountFilter(ClaimsPrincipal user); /// /// Authenticated create: claim account_id, or org-wide Customer unique match. /// Missing scope → Forbidden. Unresolvable org-wide Customer → AccountUnresolved. /// Task ResolveForAuthenticatedCreateAsync( ClaimsPrincipal user, string? customer, CancellationToken cancellationToken = default); /// /// Ingest/webhook/sync create: unique Customer → Accounts.Id or AccountUnresolved. /// Task ResolveForUnauthenticatedCreateAsync( string? customer, CancellationToken cancellationToken = default); /// /// Best-effort Customer lookup (no throw). Null when blank, missing, or ambiguous. /// Task TryResolveFromCustomerAsync( string? customer, CancellationToken cancellationToken = default); } }