using System.Threading;
using System.Threading.Tasks;
namespace GB5Shared.Auth.Jwt
{
///
/// Shared HMAC-SHA256 access-token issuance mechanics — the part every hand-rolled per-module
/// JWT service (DXPJwtService, ClientJwtService, ...) used to duplicate byte-for-byte. Each
/// consumer keeps its own claims type, its own options (issuer/audience/lifetimes), and its
/// own Vault path; only the actual JwtSecurityToken construction and signing is shared here.
///
public interface IJwtAccessTokenIssuer
{
///
/// Signs and returns an access token for . The signing key is
/// resolved via at .
///
Task IssueAsync(
IJwtClaimsSource claims,
string signingKeyVaultPath,
string issuer,
string audience,
int accessTokenMinutes,
CancellationToken ct);
}
}