namespace EntitlementBLL.Options;
///
/// ECDSA P-256 signing key configuration for the Entitlement bundle service, bound from
/// appsettings "Entitlement:EcdsaKey". The private key is base64-encoded PKCS#8; never commit a
/// real production key here — local dev should use a clearly-fake placeholder or generate one
/// on first run (see EntitlementBundleService's dev-key fallback).
///
public class EcdsaKeyOptions
{
public const string SectionName = "Entitlement:EcdsaKey";
/// Key identifier written into every signed bundle's KEYID / "kid" — supports rotation.
public string KeyId { get; set; } = "dev-key-1";
/// Base64 PKCS#8 private key (ECDSA P-256). DEV-ONLY placeholder when unset —
/// EntitlementBundleService generates an ephemeral in-memory key pair if this is empty,
/// clearly logged as unsuitable for production.
public string? PrivateKeyBase64 { get; set; }
/// Base64 X.509 SubjectPublicKeyInfo public key (ECDSA P-256), used for verification
/// when the signing key was generated out-of-process. Optional — if unset, verification uses
/// the same in-memory key pair as signing (single-process dev scenario only).
public string? PublicKeyBase64 { get; set; }
}