shoc-backend/SeaHaven.DataServices/Interfaces/IForgetPasswordDataService.cs
Alexandre Brandizzi bcc9b6d7a2 fix(auth): invalidate every pending reset code for an email together
Two concurrent first requests can leave two pending codes for one email.
Exhausting or using one now deletes all of them, so a sibling code cannot
become live afterwards.
2026-09-25 12:31:17 -03:00

24 lines
1.1 KiB
C#

using Data.SeaHavenIndustries;
namespace SeaHaven.DataServices.Interfaces
{
public interface IForgetPasswordDataService
{
/// <summary>Deletes every pending code for the email, then stores the new one.</summary>
Task ReplaceCodeAsync(string email, string userId, string codeHash, string codeSalt, DateTime expiresAtUtc, CancellationToken cancellationToken);
/// <summary>Returns the pending code for exactly this email, or null.</summary>
Task<ForgetPasswordCode?> GetByEmailAsync(string email, CancellationToken cancellationToken);
/// <summary>
/// Atomically consumes one attempt when the code is unexpired and has fewer
/// than <paramref name="maxAttempts"/> consumed. Returns false otherwise.
/// </summary>
Task<bool> TryConsumeAttemptAsync(int id, int maxAttempts, DateTime nowUtc, CancellationToken cancellationToken);
/// <summary>Gives back an attempt consumed by a check that matched.</summary>
Task RefundAttemptAsync(int id, CancellationToken cancellationToken);
Task RemoveByEmailAsync(string email, CancellationToken cancellationToken);
}
}