namespace GB5Shared.DTO.Framework.ServerConfig { // Lightweight projection of MSERVERCONFIG's auth-resolution columns — returned by // IApplicationConnection.AuthConfigCached so callers (the planned multi-tenant JWT Bearer // issuer/JWKS resolver) don't need the full ServerConfigDTO just to learn whether a tenant // expects Keycloak-issued tokens. AuthMode=0 (Native) is the safe default when no // MSERVERCONFIG row resolves at all — matches "no tenant is expected to present a Keycloak // token" until its row is deliberately configured. public class TenantAuthConfigDTO { public byte AuthMode { get; set; } public string KeycloakHost { get; set; } public string KeycloakRealm { get; set; } public string KeycloakAdminVaultPath { get; set; } // General-purpose, NOT Keycloak-specific — NULL = use the GB5 host's own local/central // Vault for ALL of this tenant's secrets. Set only for tenants running their own separate // Vault server (on-prem/BYOC) — see ServerConfigDTO.VaultAddress. public string VaultAddress { get; set; } public bool IsKeycloak => AuthMode == 1; } }