using System.Collections.Generic;
using System.Security.Claims;
using GB5Shared.Auth.Jwt;
namespace FrameworkBLL.GOP.Worker.AI
{
///
/// Claims embedded in the access token GOP's AIExtractNodeExecutor presents to the external
/// Enterprise AI engine (AI-Enterprise-v1.0, a separate Python/FastAPI service — see
/// app/core/auth.py in that repo). Claim names are deliberately the engine's own literal
/// "tenantId"/"userId" (not GB5's usual snake_case convention) because that repo's
/// generate_token.py/auth.py read the JWT payload by those exact keys — this side has no say
/// over that contract.
///
public class AIExtractAccessTokenClaims : IJwtClaimsSource
{
public int TenantId { get; set; }
public int UserId { get; set; }
// ClaimValueTypes.Integer64 makes JwtPayload emit a raw JSON number (matching the
// engine's own generate_token.py example, {"tenantId":1,"userId":1} — no quotes).
// A default Claim would serialize as a quoted string, which app/core/auth.py's
// payload.get("tenantId") would still read but that isn't the contract to rely on.
public IEnumerable ToClaims() => new[]
{
new Claim("tenantId", TenantId.ToString(), ClaimValueTypes.Integer64),
new Claim("userId", UserId.ToString(), ClaimValueTypes.Integer64)
};
}
}