{"task": {"agent_timeout": 3600, "task": "task_cornflourblue_dotnet_6_jwt_refresh_tokens_api__users", "verifier_timeout": 1800, "instruction": "You are a backend development expert. Please inspect the backend project located in the current directory, determine its programming language and architectural style, and then complete the following code implementation.\n\nImplement the user-domain service methods that back the Users API endpoints.\n\nContext\n- Work within `Services/UserService.cs`. The helper methods at the bottom of the class (`getUserByRefreshToken`, `rotateRefreshToken`, `removeOldRefreshTokens`, `revokeDescendantRefreshTokens`, `revokeRefreshToken`) are already implemented and must be used where appropriate.\n\nRequired behavior\n1. `Authenticate(AuthenticateRequest model, string ipAddress)`\n   - Locate the user by `Username` from `_context.Users` and validate the supplied password with BCrypt.\n   - On invalid credentials, throw `AppException` with the same message currently used elsewhere in the project.\n   - On success, issue a JWT via `_jwtUtils.GenerateJwtToken(user)` and a new refresh token via `_jwtUtils.GenerateRefreshToken(ipAddress)`.\n   - Attach the refresh token to the user, prune expired inactive tokens using `_appSettings.RefreshTokenTTL`, persist the user (`_context.Update` + `_context.SaveChanges`), and return an `AuthenticateResponse` that includes the new JWT and refresh token string.\n\n2. `RefreshToken(string token, string ipAddress)`\n   - Use `getUserByRefreshToken` to resolve the user and fetch the matching refresh token.\n   - If the token is revoked, ensure all descendant tokens are revoked via `revokeDescendantRefreshTokens`, then persist the user before proceeding.\n   - Reject inactive tokens with `AppException`.\n   - Rotate the token by calling `rotateRefreshToken`, append the replacement token to the user\u2019s list, remove expired inactive tokens, update the data store, and issue a fresh JWT. Return an `AuthenticateResponse` with the JWT and replacement refresh token value.\n\n3. `RevokeToken(string token, string ipAddress)`\n   - Resolve the owning user/refresh token pair, ensure the token is active, then revoke it using `revokeRefreshToken` with the provided IP and a descriptive reason (as in the original behavior) before persisting changes.\n\n4. `GetAll()`\n   - Return the enumerable of users tracked by the in-memory `_context`.\n\n5. `GetById(int id)`\n   - Fetch the matching user from `_context.Users`; throw `KeyNotFoundException` with the existing message when the user does not exist.\n\nFramework considerations\n- The service is invoked by ASP.NET Core controllers, so make sure to leave method signatures intact and ensure Entity Framework\u2019s in-memory context is updated before saving.\n- The refresh token collection resides on `User.RefreshTokens`; be careful to maintain its consistency in all flows.\n- The returned `AuthenticateResponse` must match the fields expected by `UsersController` (JWT plus refresh token string) so that cookies can be written.\n\nEdge cases\n- Multiple refresh tokens per user require removing inactive tokens that have exceeded the configured TTL.\n- Reuse of revoked tokens should trigger recursive revocation before issuing replacements.\n- Attempting to revoke or refresh an inactive token must result in `AppException`.\nPlease locate the appropriate place in the project and apply the necessary modifications.\n", "memory": "", "runnable": false, "difficulty": "hard", "language": "", "cpus": "", "instruction_truncated": false, "category": "Identity", "compose": true, "has_solution": true, "oracle": null, "docker_image": "", "taskset": "abc-bench", "tags": []}, "runs": []}