syntax = "proto3";

package freeexile.auth;

enum AccountStatus {
  STATUS_UNSPECIFIED = 0;
  STATUS_PENDING_ACTIVATION = 1;
  STATUS_ACTIVE = 2;
  STATUS_SUSPENDED = 3;
  STATUS_BANNED = 4;
}

enum OAuthProviderType {
  PROVIDER_UNSPECIFIED = 0;
  PROVIDER_GOOGLE = 1;
  PROVIDER_APPLE = 2;
  PROVIDER_FACEBOOK = 3;
}

enum CaptchaType {
  CAPTCHA_MATH = 0;
  CAPTCHA_POW = 1;
}

message CaptchaChallengeRequest {
  string client_ip = 1;
  CaptchaType preferred_type = 2;
}

message CaptchaChallengeResponse {
  string challenge_id = 1;
  CaptchaType captcha_type = 2;
  string question_or_seed = 3; // Arithmetic expression (e.g., "34 + 19") or PoW seed
  uint32 difficulty = 4;       // Target difficulty (leading zeros for PoW, 0 for math)
  uint64 expires_at_ms = 5;
  string signature = 6;        // HMAC-SHA256 signature for stateless validation
}

message QuickRegisterRequest {
  string email = 1;
  string password = 2;
  string username = 3;         // Optional, auto-generated from email prefix if empty
  string captcha_id = 4;
  string captcha_solution = 5; // User answer or PoW nonce
  string client_ip = 6;
}

message QuickRegisterResponse {
  bool success = 1;
  string message = 2;
  string account_id = 3;
  string email = 4;
  bool requires_verification = 5;
  uint32 code_expires_in_seconds = 6;
}

message VerifyEmailRequest {
  string email = 1;
  string verification_code = 2; // 6-digit numeric OTP
  string activation_token = 3;   // Optional UUID / hash activation token from link
}

message VerifyEmailResponse {
  bool success = 1;
  string message = 2;
  string account_id = 3;
  string access_token = 4;
  string refresh_token = 5;
  uint32 expires_in_seconds = 6;
}

message ResendVerificationCodeRequest {
  string email = 1;
  string client_ip = 2;
  string captcha_id = 3;
  string captcha_solution = 4;
}

message ResendVerificationCodeResponse {
  bool success = 1;
  string message = 2;
  uint32 cooldown_seconds = 3;
}

message LoginRequest {
  string email = 1;
  string password = 2;
  string captcha_id = 3;
  string captcha_solution = 4; // Required if failed attempts > threshold or risk high
  string client_ip = 5;
}

message LoginResponse {
  bool success = 1;
  string message = 2;
  string access_token = 3;
  string refresh_token = 4;
  string account_id = 5;
  string username = 6;
  AccountStatus status = 7;
  bool requires_captcha = 8;
}

message OAuthLoginRequest {
  OAuthProviderType provider = 1;
  string auth_code_or_token = 2;
  string redirect_uri = 3;
  string client_ip = 4;
}

message OAuthLoginResponse {
  bool success = 1;
  string message = 2;
  string access_token = 3;
  string refresh_token = 4;
  string account_id = 5;
  string username = 6;
  bool is_new_account = 7;
}

message RefreshTokenRequest {
  string refresh_token = 1;
}

message RefreshTokenResponse {
  bool success = 1;
  string message = 2;
  string access_token = 3;
  string refresh_token = 4;
  uint32 expires_in_seconds = 5;
}
