using SeaHaven.Services.DTOs; namespace SeaHaven.Services.Interfaces { public interface IAuthenticationService { Task LoginAsync(string? username, string? password, CancellationToken cancellationToken); /// Builds the same signed session payload that a successful login returns. Task CreateSessionAsync(Data.SeaHavenIndustries.ApplicationUser user, CancellationToken cancellationToken); Task ChangePasswordAsync(string userId, string? currentPassword, string? newPassword, CancellationToken cancellationToken); Task UpdateProfileAsync(string userId, UpdateProfileRequestDTO dto, CancellationToken cancellationToken); /// /// Emails a reset code when the address belongs to an active account. Gives no /// indication either way, so callers cannot learn which emails are registered. /// Task ForgetPasswordAsync(string? email, CancellationToken cancellationToken); /// Checks a code against the one issued to this email only. Task VerifyCodeAsync(string? email, string? code, CancellationToken cancellationToken); Task ResetPasswordAsync(string? email, string? code, string? password, CancellationToken cancellationToken); } }