namespace PartnerBLL.Options; /// /// Partner M2M (client-credentials) JWT configuration, bound from appsettings "Partner:M2MJwt". /// Mirrors DXPJwtOptions/ClientJwtOptions' shape, minus RefreshTokenDays — this is a stateless /// service-to-service credential, not a human session: a partner backend just re-presents its /// API key when the access token expires, rather than exchanging a refresh token. /// /// The signing key at Vault path "partner/m2m-jwt-signing-key" is shared between Partner (the /// issuer) and Entitlement (the validator, via its "PartnerM2MJwtBearer" scheme) — a deliberate, /// documented exception to "each module signs only its own tokens," consistent with this /// codebase's existing symmetric-HMAC-everywhere convention rather than introducing new /// asymmetric-crypto infrastructure for this one cross-module case. /// public class PartnerM2MJwtOptions { public const string SectionName = "Partner:M2MJwt"; public string Issuer { get; set; } = "GB5-Partner"; public string Audience { get; set; } = "GB5-Entitlement-Partner-M2M"; /// Access-token lifetime in minutes — deliberately short, since there is no /// revocation list for the token itself (only for the underlying API key). public int AccessTokenMinutes { get; set; } = 15; }