shoc-backend/SeaHaven.DataServices
Alexandre Brandizzi b7be07411e fix(auth): end earlier sessions when a password or account status changes
Tokens now carry a keyed hash of the account's security stamp, and every
authenticated request compares it with the stored stamp (cached for 60 s,
evicted in-process on change). A password reset or change, a deactivation
and a deletion all rotate or remove the stamp, so tokens issued before them
get 401. Tokens without the claim get 401 too.
2026-09-25 19:08:33 -03:00
..
DependencyInjection backend changes 2026-05-14 11:00:12 -05:00
Dto feat(team-members): invite registration with emailed code confirmation (SH-385) 2026-09-25 11:49:10 -03:00
Exceptions fix: map concurrent uplift inserts to conflict 2026-09-23 01:26:15 -03:00
Helpers Merge remote-tracking branch 'origin/main' into HEAD 2026-09-25 16:40:36 -03:00
Implementation fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00
Interfaces fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00
Models feat(notifications): SEV response-window alerts and breach acknowledgement 2026-09-25 11:16:21 -03:00
Properties fix: distinguish uplift request key conflicts 2026-09-23 01:39:16 -03:00
SeaHaven.DataServices.csproj refactor 2026-04-28 18:55:14 -05:00