package com.codebyte.api.auth.service;

import com.codebyte.api.auth.domain.TokenType;
import com.codebyte.api.common.error.ApiException;
import com.codebyte.api.common.error.ErrorCode;

/**
 * Thrown when a one-time token is unknown, already consumed, or expired. The message never reveals
 * which of those it was, to avoid leaking token state.
 */
public class InvalidTokenException extends ApiException {

    public InvalidTokenException(TokenType type) {
        super(ErrorCode.TOKEN_INVALID, "The %s token is invalid or has expired".formatted(type));
    }
}
