using System.Collections.Generic; using System.Security.Claims; using GB5Shared.Auth.Jwt; namespace GB5Shared.ExternalAI { /// /// Claims embedded in the access token presented to the external Enterprise AI engine /// (AI-Enterprise-v1.0). Claim names are deliberately the engine's own literal "tenantId"/ /// "userId" (see app/core/auth.py in that repo) — same contract as /// FrameworkBLL.GOP.Worker.AI.AIExtractAccessTokenClaims, generalized here so EAIAdmin/KMS /// don't each redefine the identical shape. /// public class AIEngineAccessTokenClaims : IJwtClaimsSource { public int TenantId { get; set; } public int UserId { get; set; } public IEnumerable ToClaims() => new[] { new Claim("tenantId", TenantId.ToString(), ClaimValueTypes.Integer64), new Claim("userId", UserId.ToString(), ClaimValueTypes.Integer64) }; } }