mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 04:53:11 +00:00
Tokens now carry a keyed hash of the account's security stamp, and every authenticated request compares it with the stored stamp (cached for 60 s, evicted in-process on change). A password reset or change, a deactivation and a deletion all rotate or remove the stamp, so tokens issued before them get 401. Tokens without the claim get 401 too.
21 lines
914 B
C#
21 lines
914 B
C#
namespace SeaHaven.Services.Interfaces
|
|
{
|
|
/// <summary>
|
|
/// Ties a sign-in token to the account's security stamp, so a password reset or
|
|
/// change, a deactivation, or a deletion ends every session issued before it.
|
|
/// </summary>
|
|
public interface ISessionStampService
|
|
{
|
|
/// <summary>The value a token carries for <paramref name="securityStamp"/>.</summary>
|
|
string ClaimValueFor(string securityStamp);
|
|
|
|
/// <summary>
|
|
/// True when <paramref name="claimValue"/> matches the stamp of an account that
|
|
/// exists and is not deleted. Stored stamps are cached briefly.
|
|
/// </summary>
|
|
Task<bool> IsCurrentAsync(string userId, string? claimValue, CancellationToken cancellationToken);
|
|
|
|
/// <summary>Drops the cached stamp; call after a change to the stamp or the account is saved.</summary>
|
|
void Forget(string userId);
|
|
}
|
|
}
|