mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
Tokens now carry a keyed hash of the account's security stamp, and every authenticated request compares it with the stored stamp (cached for 60 s, evicted in-process on change). A password reset or change, a deactivation and a deletion all rotate or remove the stamp, so tokens issued before them get 401. Tokens without the claim get 401 too.
20 lines
777 B
C#
20 lines
777 B
C#
namespace SeaHaven.Services.Interfaces
|
|
{
|
|
/// <summary>
|
|
/// The process-wide cache of expected session stamp values, keyed by user id.
|
|
/// Registered as a singleton.
|
|
/// </summary>
|
|
public interface ISessionStampCache
|
|
{
|
|
/// <summary>Changes on every removal; a read that spans one is not cached.</summary>
|
|
long Generation { get; }
|
|
|
|
/// <summary>True with the cached value (null: the account matches nothing) while it is fresh.</summary>
|
|
bool TryGet(string userId, out string? expected);
|
|
|
|
/// <summary>Caches a value read at <paramref name="generation"/>, unless a removal has happened since.</summary>
|
|
void Set(string userId, string? expected, long generation);
|
|
|
|
void Remove(string userId);
|
|
}
|
|
}
|