namespace DXPBLL.Auth; // Resolves DXP's JWT signing key from HashiCorp Vault — never from appsettings.json, per // CLAUDE.md's "connection strings/secrets stored in Vault" rule. Mirrors // IceImportBLL.Implementations.IceImportSecretResolver's exact construction/caching pattern // (the only existing "Vault-secret-by-key" abstraction in the repo, alongside // GB5Solution/PAY/PAYBLL/Vault/VaultService.cs). public interface IDXPSecretResolver { // KYC field encryption (GSTIN/PAN at rest) — path secret/dxp/kyc-encryption-key. The JWT-key // method this interface used to also expose now lives in the shared // GB5Shared.Auth.Jwt.IJwtSigningKeyResolver. Task GetKycEncryptionKeyAsync(CancellationToken ct); }