using System; namespace GB5Shared.Auth.Jwt { // Slim projection of GB5Shared/Query/FrameWork/User/UserQB.USER_DETAIL / PG_USER_DETAIL — // the same, already-proven, tenant-filtered (WHERE a.TENANTID=@clientid) query // AuthenticationDAL.GetUser uses for every other login path. Deliberately NOT the // FrameworkDAL.DTO.User.UserDTO the DAL itself maps into (that type isn't visible to any of // the 4 module hosts) — only the columns KeycloakLoginDTOResolver actually needs are declared // here; Dapper ignores the rest of the query's columns automatically. Deliberately excludes // MFAUserSecretKey/MFAQRCode — never propagate those past the DB row (Authentication_Analysis.md // CRITICAL-7). public class KeycloakUserLookupDTO { public int UserId { get; set; } public string UserCode { get; set; } public string UserName { get; set; } public int RoleId { get; set; } public int UserWorkOuId { get; set; } public string UserWorkOuCode { get; set; } public string UserWorkOuName { get; set; } public int UserWorkPeriodId { get; set; } public int UserWorkPartyBranchId { get; set; } public int UserWorkPartyId { get; set; } public int UserWorkStoreId { get; set; } public DateTime UserWorkDate { get; set; } public byte CheckModeofOperation { get; set; } public int UserCriteriaConfigId { get; set; } public string UserDateFormat { get; set; } public string UserTimeFormat { get; set; } public string UserCurrencyFormat { get; set; } public string UserQuantityFormat { get; set; } public string UserDelimiter { get; set; } public string UserLoginName { get; set; } public string UserPrimaryMail { get; set; } public int WorkFinanceBookId { get; set; } public int TimeZoneId { get; set; } public int TimeZone { get; set; } public string TimeZoneDisplayName { get; set; } public int CounterOperationId { get; set; } public byte SelectlistOperationType { get; set; } public int ExpiryTime { get; set; } public int GraceTime { get; set; } public int IsIpBasedCheckingRequired { get; set; } public int TempAttachmentOption { get; set; } } }