shoc-backend/SeaHaven.Services/DependencyInjection
Alexandre Brandizzi b7be07411e fix(auth): end earlier sessions when a password or account status changes
Tokens now carry a keyed hash of the account's security stamp, and every
authenticated request compares it with the stored stamp (cached for 60 s,
evicted in-process on change). A password reset or change, a deactivation
and a deletion all rotate or remove the stamp, so tokens issued before them
get 401. Tokens without the claim get 401 too.
2026-09-25 19:08:33 -03:00
..
ServicesModule.cs fix(auth): end earlier sessions when a password or account status changes 2026-09-25 19:08:33 -03:00