using System.Collections.Generic; using System.Security.Claims; using GB5Shared.Auth.Jwt; namespace PartnerBLL.Auth; /// /// The claims embedded in a partner M2M access token — deliberately no user/session concept at /// all (unlike DXPAccessTokenClaims/ClientAccessTokenClaims, both of which identify a human): a /// partner backend authenticates as itself, scoped to one PartnerProduct, using whatever /// TPARTNERAPIKEY.SCOPES already restricts it to. /// public class PartnerM2MAccessTokenClaims : IJwtClaimsSource { public int PartnerId { get; set; } public int PartnerProductId { get; set; } public int ApiKeyId { get; set; } public string? Scopes { get; set; } public IEnumerable ToClaims() => new[] { new Claim(PartnerM2MClaimTypes.PartnerId, PartnerId.ToString()), new Claim(PartnerM2MClaimTypes.PartnerProductId, PartnerProductId.ToString()), new Claim(PartnerM2MClaimTypes.ApiKeyId, ApiKeyId.ToString()), new Claim(PartnerM2MClaimTypes.Scopes, Scopes ?? string.Empty) }; }