# abc-bench / task_cornflourblue_dotnet_6_jwt_refresh_tokens_api__users

- taskset: [abc-bench](https://harnessreport.com/tasks/abc-bench.md)
- difficulty: hard
- category: Identity
- language: 
- runnable from the site: no
- agent timeout: 3600s

## Results by harness

_none yet_

## Instruction

```
You are a backend development expert. Please inspect the backend project located in the current directory, determine its programming language and architectural style, and then complete the following code implementation.

Implement the user-domain service methods that back the Users API endpoints.

Context
- Work within `Services/UserService.cs`. The helper methods at the bottom of the class (`getUserByRefreshToken`, `rotateRefreshToken`, `removeOldRefreshTokens`, `revokeDescendantRefreshTokens`, `revokeRefreshToken`) are already implemented and must be used where appropriate.

Required behavior
1. `Authenticate(AuthenticateRequest model, string ipAddress)`
   - Locate the user by `Username` from `_context.Users` and validate the supplied password with BCrypt.
   - On invalid credentials, throw `AppException` with the same message currently used elsewhere in the project.
   - On success, issue a JWT via `_jwtUtils.GenerateJwtToken(user)` and a new refresh token via `_jwtUtils.GenerateRefreshToken(ipAddress)`.
   - Attach the refresh token to the user, prune expired inactive tokens using `_appSettings.RefreshTokenTTL`, persist the user (`_context.Update` + `_context.SaveChanges`), and return an `AuthenticateResponse` that includes the new JWT and refresh token string.

2. `RefreshToken(string token, string ipAddress)`
   - Use `getUserByRefreshToken` to resolve the user and fetch the matching refresh token.
   - If the token is revoked, ensure all descendant tokens are revoked via `revokeDescendantRefreshTokens`, then persist the user before proceeding.
   - Reject inactive tokens with `AppException`.
   - Rotate the token by calling `rotateRefreshToken`, append the replacement token to the user’s list, remove expired inactive tokens, update the data store, and issue a fresh JWT. Return an `AuthenticateResponse` with the JWT and replacement refresh token value.

3. `RevokeToken(string token, string ipAddress)`
   - Resolve the owning user/refresh token pair, ensure the token is active, then revoke it using `revokeRefreshToken` with the provided IP and a descriptive reason (as in the original behavior) before persisting changes.

4. `GetAll()`
   - Return the enumerable of users tracked by the in-memory `_context`.

5. `GetById(int id)`
   - Fetch the matching user from `_context.Users`; throw `KeyNotFoundException` with the existing message when the user does not exist.

Framework considerations
- The service is invoked by ASP.NET Core controllers, so make sure to leave method signatures intact and ensure Entity Framework’s in-memory context is updated before saving.
- The refresh token collection resides on `User.RefreshTokens`; be careful to maintain its consistency in all flows.
- The returned `AuthenticateResponse` must match the fields expected by `UsersController` (JWT plus refresh token string) so that cookies can be written.

Edge cases
- Multiple refresh tokens per user require removing inactive tokens that have exceeded the configured TTL.
- Reuse of revoked tokens should trigger recursive revocation before issuing replacements.
- Attempting to revoke or refresh an inactive token must result in `AppException`.
Please locate the appropriate place in the project and apply the necessary modifications.
```
---
Harness Report runs agent harnesses from their GitHub repos on Harbor tasks and records every model call. Every page is also `.md` and `.json`; index: https://harnessreport.com/llms.txt · MCP: https://harnessreport.com/mcp
