shoc-backend/Api.SeaHavenIndustries/Infrastructure
Alexandre Brandizzi b7be07411e fix(auth): end earlier sessions when a password or account status changes
Tokens now carry a keyed hash of the account's security stamp, and every
authenticated request compares it with the stored stamp (cached for 60 s,
evicted in-process on change). A password reset or change, a deactivation
and a deletion all rotate or remove the stamp, so tokens issued before them
get 401. Tokens without the claim get 401 too.
2026-09-25 19:08:33 -03:00
..
AwsWorkOrderWebhookSecretProvider.cs fix(work-orders): satisfy producer contract review 2026-07-27 16:33:06 -03:00
DynamoSyncExternalSource.cs refactor: enforce backend boundaries and optimize dispatch (#30) 2026-07-24 17:35:34 -03:00
IdentityRegistration.cs feat(auth): enforce one password policy on every password-setting path (SH-386) 2026-09-25 11:06:42 -03:00
JwtAuthenticationRegistration.cs fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00
PortAdapters.cs feat(work-orders): stream stored WO media safely 2026-09-08 11:09:55 -03:00
ProcurementWorkOrderClient.cs feat: complete SH-133 procurement reconciliation 2026-07-24 22:13:25 -03:00