mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 03:43:11 +00:00
Tokens now carry a keyed hash of the account's security stamp, and every authenticated request compares it with the stored stamp (cached for 60 s, evicted in-process on change). A password reset or change, a deactivation and a deletion all rotate or remove the stamp, so tokens issued before them get 401. Tokens without the claim get 401 too.
33 lines
1.2 KiB
C#
33 lines
1.2 KiB
C#
namespace SeaHaven.Services.Helpers
|
|
{
|
|
/// <summary>Server-derived claim type names emitted at token issuance.</summary>
|
|
public static class SeaHavenClaimTypes
|
|
{
|
|
/// <summary>CRM account id from <c>ApplicationUser.AccountId</c> (never from request body).</summary>
|
|
public const string AccountId = "account_id";
|
|
|
|
/// <summary>Explicit org-wide media scope; value <see cref="OrgScopeAll"/>.</summary>
|
|
public const string OrgScope = "org_scope";
|
|
|
|
/// <summary>Signed org-wide elevation (Admin without AccountId).</summary>
|
|
public const string OrgScopeAll = "all";
|
|
|
|
/// <summary>
|
|
/// A keyed hash of the account's security stamp at sign-in. Never the stamp
|
|
/// itself: the token is readable by whoever holds it.
|
|
/// </summary>
|
|
public const string SessionStamp = "session_stamp";
|
|
}
|
|
|
|
/// <summary>Resolved media tenant scope from signed claims (fail-closed when Missing).</summary>
|
|
public abstract record MediaAccountScope
|
|
{
|
|
private MediaAccountScope() { }
|
|
|
|
public sealed record Account(int AccountId) : MediaAccountScope;
|
|
|
|
public sealed record OrgWide : MediaAccountScope;
|
|
|
|
public sealed record Missing : MediaAccountScope;
|
|
}
|
|
}
|