shoc-backend/SeaHaven.Services
Alexandre Brandizzi 498f49a2d8 fix(auth): end earlier sessions when a user's role or account changes
A token carries the user's roles and account, so a demoted admin kept admin
claims until the token expired. The team member update and the admin user
edit now rotate the security stamp and evict the cached value when the role,
account or user name changes. Permission overrides are read per request and
are not in the token.
2026-09-25 19:26:25 -03:00
..
Configuration feat(permissions): protect configured account owner (SH-329) 2026-09-16 21:40:22 -03:00
Constants feat(team-members): support pending member creation (SH-325) 2026-09-16 21:41:55 -03:00
DependencyInjection fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00
DTOs Merge pull request #184 from Sea-Haven-Industries/feat/ab/sh-322-overdue-type 2026-09-25 19:52:19 +00:00
Exceptions Sites API: site code uniqueness, soft delete with role check, open work orders, site notes 2026-09-25 11:19:29 -03:00
Helpers Merge remote-tracking branch 'origin/main' into fix/ab/sh-409-invalidate-sessions-on-reset 2026-09-25 19:22:33 -03:00
Implementation fix(auth): end earlier sessions when a user's role or account changes 2026-09-25 19:26:25 -03:00
Interfaces Merge remote-tracking branch 'origin/main' into fix/ab/sh-409-invalidate-sessions-on-reset 2026-09-25 19:22:33 -03:00
Validation feat(locations): manage ordered site contacts 2026-09-15 19:03:54 -03:00
SeaHaven.Services.csproj refactor: enforce backend boundaries and optimize dispatch (#30) 2026-07-24 17:35:34 -03:00