shoc-backend/SeaHaven.Services
Alexandre Brandizzi b7be07411e fix(auth): end earlier sessions when a password or account status changes
Tokens now carry a keyed hash of the account's security stamp, and every
authenticated request compares it with the stored stamp (cached for 60 s,
evicted in-process on change). A password reset or change, a deactivation
and a deletion all rotate or remove the stamp, so tokens issued before them
get 401. Tokens without the claim get 401 too.
2026-09-25 19:08:33 -03:00
..
Configuration feat(permissions): protect configured account owner (SH-329) 2026-09-16 21:40:22 -03:00
Constants feat(team-members): support pending member creation (SH-325) 2026-09-16 21:41:55 -03:00
DependencyInjection fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00
DTOs Merge pull request #184 from Sea-Haven-Industries/feat/ab/sh-322-overdue-type 2026-09-25 19:52:19 +00:00
Exceptions Sites API: site code uniqueness, soft delete with role check, open work orders, site notes 2026-09-25 11:19:29 -03:00
Helpers fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00
Implementation fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00
Interfaces fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00
Validation feat(locations): manage ordered site contacts 2026-09-15 19:03:54 -03:00
SeaHaven.Services.csproj refactor: enforce backend boundaries and optimize dispatch (#30) 2026-07-24 17:35:34 -03:00