using System.Collections.Generic;
using System.Security.Claims;
using GB5Shared.Auth.Jwt;
namespace PartnerBLL.Auth;
///
/// The claims embedded in a partner M2M access token — deliberately no user/session concept at
/// all (unlike DXPAccessTokenClaims/ClientAccessTokenClaims, both of which identify a human): a
/// partner backend authenticates as itself, scoped to one PartnerProduct, using whatever
/// TPARTNERAPIKEY.SCOPES already restricts it to.
///
public class PartnerM2MAccessTokenClaims : IJwtClaimsSource
{
public int PartnerId { get; set; }
public int PartnerProductId { get; set; }
public int ApiKeyId { get; set; }
public string? Scopes { get; set; }
public IEnumerable ToClaims() => new[]
{
new Claim(PartnerM2MClaimTypes.PartnerId, PartnerId.ToString()),
new Claim(PartnerM2MClaimTypes.PartnerProductId, PartnerProductId.ToString()),
new Claim(PartnerM2MClaimTypes.ApiKeyId, ApiKeyId.ToString()),
new Claim(PartnerM2MClaimTypes.Scopes, Scopes ?? string.Empty)
};
}