docs(comments): strip internal task/milestone/bundle bookkeeping from code comments
Remove project bookkeeping citations from shipped code comments across the solution: hyphenated task IDs (WP-14, StoreAndForward-025), milestone/task/ issue refs (M3, Task 4, Audit Log #23, #21), Bundle X task-bundle labels, and C/D/K/S/T phase labels. Comment text only — no code logic, string/log literals, or XML-doc structure changed. Genuine descriptions are preserved (only the citation is stripped), and technical lookalikes are retained (UTF-8, SHA-256, T00:00:00, M365, UTC-5, pre-C4/pre-C5 schema versions). Flagged by the new CommentChecker TaskReferenceInComment / TrackingReferenceInComment checks plus targeted grep passes; full solution builds clean, append-only guard tests pass.
This commit is contained in:
@@ -13,7 +13,7 @@ public class JwtTokenService
|
||||
private readonly SecurityOptions _options;
|
||||
private readonly ILogger<JwtTokenService> _logger;
|
||||
|
||||
// Task 1.5 (full canonical claims): these constants are the single source of
|
||||
// (Full canonical claims): these constants are the single source of
|
||||
// truth that every mint site, every authorization policy, and the token
|
||||
// validation parameters reference. Redefining them as aliases of the shared
|
||||
// ZbClaimTypes vocabulary migrates the whole module centrally:
|
||||
@@ -29,7 +29,7 @@ public class JwtTokenService
|
||||
public const string SiteIdClaimType = ZbClaimTypes.ScopeId;
|
||||
public const string LastActivityClaimType = "LastActivity";
|
||||
|
||||
// M2.19 (#15): the cookie session now stores the user's raw LDAP groups and a
|
||||
// The cookie session now stores the user's raw LDAP groups and a
|
||||
// role-mapping refresh anchor so an active interactive session can re-run the
|
||||
// DB-backed RoleMapper (NOT LDAP) mid-session and pick up central role-mapping
|
||||
// changes. These two have no canonical ZbClaimTypes equivalent (the shared
|
||||
@@ -229,7 +229,7 @@ public class JwtTokenService
|
||||
/// claims). Enforcing the idle check here — rather than relying on the caller to
|
||||
/// invoke <see cref="IsIdleTimedOut"/> first — guarantees the documented 30-minute
|
||||
/// idle policy holds regardless of caller discipline; otherwise an idle-expired
|
||||
/// session could be kept alive indefinitely by background refreshes (Security-014).
|
||||
/// session could be kept alive indefinitely by background refreshes.
|
||||
/// </para>
|
||||
/// </summary>
|
||||
/// <param name="currentPrincipal">The current authenticated principal whose claims carry identity and the last-activity anchor.</param>
|
||||
|
||||
Reference in New Issue
Block a user