40d7e740ef
## Summary - Removes unreachable dead code in `verifyJwtToken` — a legacy API key verification block where the condition (`!payload.type && type === API_KEY`) was logically impossible. Also removes the now-unused `isLegacyApiKey` parameter and `generateAppSecretLegacy` method. - Adds explicit token type validation after JWT decode in `verifyLoginToken`, `verifyRefreshToken`, and `verifyTransientToken`. Each function now rejects tokens whose `type` field doesn't match what's expected (defense-in-depth — the HMAC secret already binds the type, but this makes the contract explicit). ## Test plan - [x] Updated existing specs for login-token, refresh-token, renew-token services — all 16 tests passing - [x] Lint clean Made with [Cursor](https://cursor.com) --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>