using System.Data.Common; using EntitlementDAL.DTOs; using GB5Shared.DTO.Framework.Login; namespace EntitlementDAL.Interfaces; public interface IClientUserRoleDAL { Task> GetByClientUserAsync(int clientUserId, LoginDTO login, CancellationToken ct); /// Plain role-code strings only — used to build the JWT's Capabilities claim at /// login/refresh with no DTO mapping overhead. Task> GetActiveRoleCodesAsync(int clientUserId, LoginDTO login, CancellationToken ct); Task GrantAsync(ClientUserRoleDTO dto, LoginDTO login, DbTransaction tx, CancellationToken ct); Task RevokeAsync(int clientUserId, string roleCode, LoginDTO login, DbTransaction tx, CancellationToken ct); }