namespace SeaHaven.Services.Helpers { /// Server-derived claim type names emitted at token issuance. public static class SeaHavenClaimTypes { /// CRM account id from ApplicationUser.AccountId (never from request body). public const string AccountId = "account_id"; /// Explicit org-wide media scope; value . public const string OrgScope = "org_scope"; /// Signed org-wide elevation (Admin without AccountId). public const string OrgScopeAll = "all"; /// /// A keyed hash of the account's security stamp at sign-in. Never the stamp /// itself: the token is readable by whoever holds it. /// public const string SessionStamp = "session_stamp"; } /// Resolved media tenant scope from signed claims (fail-closed when Missing). public abstract record MediaAccountScope { private MediaAccountScope() { } public sealed record Account(int AccountId) : MediaAccountScope; public sealed record OrgWide : MediaAccountScope; public sealed record Missing : MediaAccountScope; } }