package jwt import ( "time" "clapclap/internal/uuid" "github.com/golang-jwt/jwt/v5" ) // GenerateActionToken creates a token specifically for one-off actions (like email links) // It includes a "purpose" claim to prevent it from being used as a standard session token. func GenerateActionToken(secret string, userID uuid.UUID, purpose string, duration time.Duration) (string, error) { now := time.Now() token := jwt.NewWithClaims(jwt.SigningMethodHS256, jwt.MapClaims{ "sub": userID.String(), "exp": jwt.NewNumericDate(now.Add(duration)), "iat": jwt.NewNumericDate(now), "purpose": purpose, // CRITICAL: This is what your .Query() middleware validates }) return token.SignedString([]byte(secret)) }