using System.Security.Claims; using System.Threading; using System.Threading.Tasks; using GB5Shared.DTO.Framework.Login; namespace GB5Shared.Auth.Jwt { // The still-to-be-built bridge from a validated Keycloak identity to a real GB5 LoginDTO — // "the actual missing link" the GB5 Repo-Wide Authentication Hardening plan calls out: // SSOService.cs's OIDC flow already produces a verified identity, but nothing today maps that // identity (sub/preferred_username/realm roles) to the corresponding MUSER row to get the // real UserId/RoleId/ClientId a LoginDTO needs. Deliberately left UNREGISTERED in DI for now — // BaseEndPoint.GetLoginDTOFromRequestAsync resolves this via TryResolve() (returns null, // not a throw, when nothing is registered), so the dual-mode bridge stays fully inert and // falls through to today's trusted-header path until a real implementation exists and a host // registers it. public interface IKeycloakLoginDTOResolver { Task ResolveAsync(ClaimsPrincipal principal, CancellationToken ct = default); } }