namespace EntitlementBLL.Onboarding; // Provisions a new tenant's Keycloak realm+client by calling FrameworkSL's already-built // admin-API endpoints (GB5 Repo-Wide Authentication Hardening plan) — EntitlementBLL has zero // reference to FrameworkBLL/FrameworkDAL by design (see ClientUserProvisioner.cs's own comment on // why), so this talks to FrameworkSL over HTTP, the same pattern ISqlWorkbenchClient/ // IReferenceDataSyncClient already use for their own cross-service calls. public interface IKeycloakProvisioningClient { /// /// Creates a Keycloak realm named and one confidential client /// inside it. The client's secret never leaves FrameworkSL — it's written straight to Vault /// there (KeyCloakDAL.CreateClient), at the exact path KeyCloakService.cs's /// ClientSecretVaultPath already reads from, so the new client is immediately usable by the /// real login flow with no further wiring. /// Task ProvisionRealmAndClientAsync( string realmName, string clientId, string clientName, string redirectUriPattern, CancellationToken ct); }