namespace PartnerBLL.Options;
///
/// Partner M2M (client-credentials) JWT configuration, bound from appsettings "Partner:M2MJwt".
/// Mirrors DXPJwtOptions/ClientJwtOptions' shape, minus RefreshTokenDays — this is a stateless
/// service-to-service credential, not a human session: a partner backend just re-presents its
/// API key when the access token expires, rather than exchanging a refresh token.
///
/// The signing key at Vault path "partner/m2m-jwt-signing-key" is shared between Partner (the
/// issuer) and Entitlement (the validator, via its "PartnerM2MJwtBearer" scheme) — a deliberate,
/// documented exception to "each module signs only its own tokens," consistent with this
/// codebase's existing symmetric-HMAC-everywhere convention rather than introducing new
/// asymmetric-crypto infrastructure for this one cross-module case.
///
public class PartnerM2MJwtOptions
{
public const string SectionName = "Partner:M2MJwt";
public string Issuer { get; set; } = "GB5-Partner";
public string Audience { get; set; } = "GB5-Entitlement-Partner-M2M";
/// Access-token lifetime in minutes — deliberately short, since there is no
/// revocation list for the token itself (only for the underlying API key).
public int AccessTokenMinutes { get; set; } = 15;
}