namespace DXPBLL.Options; /// /// DXP vendor-portal JWT configuration, bound from appsettings "DXPJwt". Mirrors /// EntitlementBLL.Options.ClientJwtOptions' shape exactly. /// /// Deliberately the ONLY place these two lifetimes are read from config: DXPJwtService reads /// this once per token issuance and returns the computed expiries directly on DXPTokenPair — no /// other class re-derives or hardcodes either number. Before this class existed, AuthBLL. /// IssueTokensAsync independently hardcoded "15" (access-token minutes, ignoring /// DXPJwt:AccessTokenMinutes entirely) and "30" (refresh-token days, via a comment claiming — /// incorrectly — that it "matched" a config default that was never actually read anywhere). /// public class DXPJwtOptions { public const string SectionName = "DXPJwt"; public string Issuer { get; set; } = "GB5-DXP"; public string Audience { get; set; } = "GB5-DXP-Vendor"; /// Access-token lifetime in minutes. Used for both the JWT's own `exp` claim and the /// `AccessTokenExpiresOn` reported back to the caller — always the same computed value. public int AccessTokenMinutes { get; set; } = 15; /// Refresh-token lifetime in days. Used for both the persisted /// MDXPREFRESHTOKEN.EXPIRESON row and the `RefreshTokenExpiresOn` reported back to the /// caller — always the same computed value. public int RefreshTokenDays { get; set; } = 30; }