AuthSessionResult
What every flow that establishes a session returns: RegisterAsync, CompleteTwoFactorLoginAsync, RefreshSessionAsync, and CreateSessionAsync. A sign-in that opens one without a second factor carries it on AuthLoginResult.Session.
DANGER
User is the database entity. Never return it from an endpoint: it serializes with the password hash, the surrogate key, and any loaded sessions. Map it to a DTO that exposes only the fields the client needs.
Fields
AccessToken: string
The signed JWT to return to the client. Its lifetime comes from AccessTokenMinutes in the JWT package's configuration.
RefreshToken: string
The refresh token in plain text, the only copy that will ever exist; only its hash is stored. Put it in the refresh-token cookie rather than the response body.
User: TUser
The authenticated user, tracked by the context. It is the database entity and serializes with the password hash, the surrogate key, and any loaded sessions, so map it to a DTO before returning it.
Type signature
public sealed class AuthSessionResult<TUser> where TUser : AuthUser
{
public required string AccessToken { get; init; }
public required string RefreshToken { get; init; }
public required TUser User { get; init; }
}