using System.Collections.Generic; using System.Security.Claims; using GB5Shared.Auth.Jwt; namespace FrameworkBLL.GOP.Worker.AI { /// /// Claims embedded in the access token GOP's AIExtractNodeExecutor presents to the external /// Enterprise AI engine (AI-Enterprise-v1.0, a separate Python/FastAPI service — see /// app/core/auth.py in that repo). Claim names are deliberately the engine's own literal /// "tenantId"/"userId" (not GB5's usual snake_case convention) because that repo's /// generate_token.py/auth.py read the JWT payload by those exact keys — this side has no say /// over that contract. /// public class AIExtractAccessTokenClaims : IJwtClaimsSource { public int TenantId { get; set; } public int UserId { get; set; } // ClaimValueTypes.Integer64 makes JwtPayload emit a raw JSON number (matching the // engine's own generate_token.py example, {"tenantId":1,"userId":1} — no quotes). // A default Claim would serialize as a quoted string, which app/core/auth.py's // payload.get("tenantId") would still read but that isn't the contract to rely on. public IEnumerable ToClaims() => new[] { new Claim("tenantId", TenantId.ToString(), ClaimValueTypes.Integer64), new Claim("userId", UserId.ToString(), ClaimValueTypes.Integer64) }; } }