using System.Threading; using System.Threading.Tasks; namespace GB5Shared.Auth.Jwt { /// /// Resolves a JWT signing key from Vault by path — a thin, JWT-specific wrapper over /// , which already owns caching, retry, and typed /// exceptions. Replaces the hand-rolled per-module secret resolvers (DXPSecretResolver, /// ClientSecretResolver) that each re-implemented the same IMemoryCache + IVaultClient pattern. /// public interface IJwtSigningKeyResolver { Task GetSigningKeyAsync(string vaultPath, CancellationToken ct); } }