namespace SeaHaven.Services.Helpers
{
/// Server-derived claim type names emitted at token issuance.
public static class SeaHavenClaimTypes
{
/// CRM account id from ApplicationUser.AccountId (never from request body).
public const string AccountId = "account_id";
/// Explicit org-wide media scope; value .
public const string OrgScope = "org_scope";
/// Signed org-wide elevation (Admin without AccountId).
public const string OrgScopeAll = "all";
///
/// A keyed hash of the account's security stamp at sign-in. Never the stamp
/// itself: the token is readable by whoever holds it.
///
public const string SessionStamp = "session_stamp";
}
/// Resolved media tenant scope from signed claims (fail-closed when Missing).
public abstract record MediaAccountScope
{
private MediaAccountScope() { }
public sealed record Account(int AccountId) : MediaAccountScope;
public sealed record OrgWide : MediaAccountScope;
public sealed record Missing : MediaAccountScope;
}
}