shoc-backend/SeaHaven.Services/Interfaces/ISessionStampService.cs
Alexandre Brandizzi b7be07411e fix(auth): end earlier sessions when a password or account status changes
Tokens now carry a keyed hash of the account's security stamp, and every
authenticated request compares it with the stored stamp (cached for 60 s,
evicted in-process on change). A password reset or change, a deactivation
and a deletion all rotate or remove the stamp, so tokens issued before them
get 401. Tokens without the claim get 401 too.
2026-09-25 19:08:33 -03:00

21 lines
914 B
C#

namespace SeaHaven.Services.Interfaces
{
/// <summary>
/// Ties a sign-in token to the account's security stamp, so a password reset or
/// change, a deactivation, or a deletion ends every session issued before it.
/// </summary>
public interface ISessionStampService
{
/// <summary>The value a token carries for <paramref name="securityStamp"/>.</summary>
string ClaimValueFor(string securityStamp);
/// <summary>
/// True when <paramref name="claimValue"/> matches the stamp of an account that
/// exists and is not deleted. Stored stamps are cached briefly.
/// </summary>
Task<bool> IsCurrentAsync(string userId, string? claimValue, CancellationToken cancellationToken);
/// <summary>Drops the cached stamp; call after a change to the stamp or the account is saved.</summary>
void Forget(string userId);
}
}