In a Rest Api SaaS project developed with .Net Core 3.1.
When the user's subscription expires (needs to pay), what kind of a method would be better to follow.
There are 2 methods that I think of but I think there will be some problems in both of them.
Method 1) Checking the subscription status during JWT generate and not generating JWT if the subscription period has expired:
If I use this method;
Advantage: Since a token is not given to a user whose subscription expires, they will not be able to access other endpoints. I think this will work extremely safe without doing any other coding work.
Disadvantage: When I need to redirect the user to the payment page, I will have to do a special work for the payment endpoints since there are no tokens.(Example: Password Reset Methods) I will get it with query string, I think I can create a special token for this method. But I think there might be a security bug because I couldn't protect this process with my standard authorization method?
Method 2) Even if the subscription expires, jwt will be generated, but membership will be restricted:
If I use this method;
Advantage: I can use my standard authorization method without any problems when I need to direct the user to the payment endpoints or to another endpoints. I will use with jwt and security bugs will be considerably reduced.
Disadvantage: I need to determine endpoints that cannot be accessed on the application for user whose subscription period expired and I will need to code a working service in middleware that will make them inaccessible. (Like to permission methods) This will both do extra coding work and each endpoint will require extra work.
These are my thoughts....
Or other solutions...
How should we restrict a user whose subscription expires and how should we act?
Thank you very much for your information sharing.