87 lines
4.8 KiB
TypeScript
87 lines
4.8 KiB
TypeScript
|
|
import { type BearerTokenResponse, type DeviceAccessTokenError, type DeviceAccessTokenResponse, type DeviceAuthorizationResponse } from "./authorize.ts";
|
||
|
|
import type { ValidatedAuthMetadata } from "./discover.ts";
|
||
|
|
import { type OAuthRegistrationRequest } from "./register.ts";
|
||
|
|
export * from "./authorize.ts";
|
||
|
|
export * from "./error.ts";
|
||
|
|
export * from "./register.ts";
|
||
|
|
export * from "./tokenRefresher.ts";
|
||
|
|
export * from "./discover.ts";
|
||
|
|
/**
|
||
|
|
* Type representing the persistent context needed for typical OAuth flows
|
||
|
|
*/
|
||
|
|
type Context = {
|
||
|
|
/** The OAuth client ID */
|
||
|
|
clientId: string;
|
||
|
|
/** The desired device ID */
|
||
|
|
deviceId?: string;
|
||
|
|
/** The seed used to generate the challenge code */
|
||
|
|
codeVerifier?: string;
|
||
|
|
/** The URI to redirect the user to with credentials after auth */
|
||
|
|
redirectUri: string;
|
||
|
|
};
|
||
|
|
export declare class OAuth2 {
|
||
|
|
readonly metadata: ValidatedAuthMetadata;
|
||
|
|
/**
|
||
|
|
* Attempts dynamic registration against the configured registration endpoint.
|
||
|
|
* Will ignore any URIs that do not use client_uri as a common base as per the spec.
|
||
|
|
* @param authMetadata - Auth config from {@link MatrixClient.getAuthMetadata}
|
||
|
|
* @param clientMetadata - The metadata for the client which to register,
|
||
|
|
* grant_types & response_types & token_endpoint_auth_method will be sanely calculated if omitted.
|
||
|
|
* @returns Promise<string> resolved with registered clientId
|
||
|
|
* @throws when registration is not supported, on failed request or invalid response
|
||
|
|
*/
|
||
|
|
static registerClient(authMetadata: ValidatedAuthMetadata, clientMetadata: OAuthRegistrationRequest): Promise<string>;
|
||
|
|
readonly context: Required<Context>;
|
||
|
|
constructor(metadata: ValidatedAuthMetadata, context: Context);
|
||
|
|
/**
|
||
|
|
* Generate a URL to attempt authorization with the OP
|
||
|
|
* See https://spec.matrix.org/v1.18/client-server-api/#authorization-code-flow
|
||
|
|
* @param state - A unique opaque identifier, like a transaction ID,
|
||
|
|
* that will allow the client to maintain state between the authorization request and the callback.
|
||
|
|
* The app should use this to key the storage for where the rest of the auth context is saved.
|
||
|
|
* @param responseMode - The manner in which the IdP should send the secrets back to the app. Defaults to `fragment` for privacy.
|
||
|
|
* @param prompt - Optional prompt parameter to pass to the IdP to signal intent, e.g. `create` for User registration.
|
||
|
|
* @param scope - The OAuth2 scope to request, will be generated based on the device ID if omitted.
|
||
|
|
* @returns a Promise with the url as a string
|
||
|
|
*/
|
||
|
|
generateAuthorizationCodeGrantUrl(state: string, responseMode?: "fragment" | "query", prompt?: string, scope?: string): Promise<string>;
|
||
|
|
/**
|
||
|
|
* Attempt to exchange authorization code for bearer token.
|
||
|
|
*
|
||
|
|
* Takes the authorization code returned by the OAuth2 Provider via the authorization URL, and makes a
|
||
|
|
* request to the Token Endpoint, to obtain the access token, refresh token, etc.
|
||
|
|
*
|
||
|
|
* @param code - authorization code as returned by IdP during authorization
|
||
|
|
* @returns a validated bearer token response
|
||
|
|
* @throws An `Error` with `message` set to an entry in {@link OAuth2Error},
|
||
|
|
* when the request fails, or the returned token response is invalid.
|
||
|
|
*/
|
||
|
|
completeAuthorizationCodeGrant(code: string): Promise<BearerTokenResponse>;
|
||
|
|
/**
|
||
|
|
* Refresh the access token using the given refresh token and the refresh token grant
|
||
|
|
* @param refreshToken - the token to use to refresh the access token
|
||
|
|
*/
|
||
|
|
performRefreshTokenGrant(refreshToken: string): Promise<BearerTokenResponse>;
|
||
|
|
/**
|
||
|
|
* Revokes the given token
|
||
|
|
* @param token - the token to remove
|
||
|
|
* @param type - the type of token, acts as a hint to the IdP
|
||
|
|
*/
|
||
|
|
revokeToken(token: string, type?: "access_token" | "refresh_token"): Promise<void>;
|
||
|
|
/**
|
||
|
|
* Begin OAuth2 device authorization flow.
|
||
|
|
* @param scope - the scope to request for authorization.
|
||
|
|
* @returns a promise that resolves to a device access token response,
|
||
|
|
* or an error response if the user denies authorization or the device code expires.
|
||
|
|
*/
|
||
|
|
startDeviceAuthorizationGrant(scope?: string): Promise<DeviceAuthorizationResponse>;
|
||
|
|
/**
|
||
|
|
* Polls the OAuth2 token endpoint until we get a device access token response, or encounter an unrecoverable error.
|
||
|
|
* @param session - The session returned from a previous call to {@link OAuth2.startDeviceAuthorizationGrant}.
|
||
|
|
* @returns a promise that resolves to a device access token response,
|
||
|
|
* or an error response if the user denies authorization or the device code expires.
|
||
|
|
*/
|
||
|
|
waitForDeviceAuthorizationGrant(session: DeviceAuthorizationResponse): Promise<DeviceAccessTokenResponse | DeviceAccessTokenError>;
|
||
|
|
private fetch;
|
||
|
|
}
|
||
|
|
//# sourceMappingURL=index.d.ts.map
|