shoc-backend/SeaHaven.Services/Interfaces/ISessionStampCache.cs
Alexandre Brandizzi b7be07411e fix(auth): end earlier sessions when a password or account status changes
Tokens now carry a keyed hash of the account's security stamp, and every
authenticated request compares it with the stored stamp (cached for 60 s,
evicted in-process on change). A password reset or change, a deactivation
and a deletion all rotate or remove the stamp, so tokens issued before them
get 401. Tokens without the claim get 401 too.
2026-09-25 19:08:33 -03:00

20 lines
777 B
C#

namespace SeaHaven.Services.Interfaces
{
/// <summary>
/// The process-wide cache of expected session stamp values, keyed by user id.
/// Registered as a singleton.
/// </summary>
public interface ISessionStampCache
{
/// <summary>Changes on every removal; a read that spans one is not cached.</summary>
long Generation { get; }
/// <summary>True with the cached value (null: the account matches nothing) while it is fresh.</summary>
bool TryGet(string userId, out string? expected);
/// <summary>Caches a value read at <paramref name="generation"/>, unless a removal has happened since.</summary>
void Set(string userId, string? expected, long generation);
void Remove(string userId);
}
}