ce76046a29
- consolidate API ownership and remove dead vendor code - add Stripe billing, learning paths, and public CV hardening - add migration, recovery, security, audit, and browser gates
18 lines
868 B
C#
18 lines
868 B
C#
namespace JobTrackerApi.Models;
|
|
|
|
// Server-side record of a JWT issued via AppSessionIssuer. The JWT carries this row's Id as its
|
|
// "sid" claim; Program.cs's "local" JwtBearer OnTokenValidated looks the row up on every request
|
|
// so a session can actually be revoked before its JWT naturally expires (previously the JWT alone
|
|
// was the credential -- see AppSessionIssuer). Same shape/rationale as TrustedDevice, but this
|
|
// tracks the *session* itself rather than a "skip 2FA" cookie.
|
|
public sealed class UserSession
|
|
{
|
|
public string Id { get; set; } = "";
|
|
public string UserId { get; set; } = "";
|
|
public string? DeviceLabel { get; set; }
|
|
public DateTimeOffset CreatedAtUtc { get; set; }
|
|
public DateTimeOffset LastSeenAtUtc { get; set; }
|
|
public DateTimeOffset ExpiresAtUtc { get; set; }
|
|
public DateTimeOffset? RevokedAtUtc { get; set; }
|
|
}
|