provider.d.ts 3.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768
  1. import { Response } from 'express';
  2. import { OAuthRegisteredClientsStore } from './clients.js';
  3. import { OAuthClientInformationFull, OAuthTokenRevocationRequest, OAuthTokens } from '../../shared/auth.js';
  4. import { AuthInfo } from './types.js';
  5. export type AuthorizationParams = {
  6. state?: string;
  7. scopes?: string[];
  8. codeChallenge: string;
  9. redirectUri: string;
  10. resource?: URL;
  11. };
  12. /**
  13. * Implements an end-to-end OAuth server.
  14. */
  15. export interface OAuthServerProvider {
  16. /**
  17. * A store used to read information about registered OAuth clients.
  18. */
  19. get clientsStore(): OAuthRegisteredClientsStore;
  20. /**
  21. * Begins the authorization flow, which can either be implemented by this server itself or via redirection to a separate authorization server.
  22. *
  23. * This server must eventually issue a redirect with an authorization response or an error response to the given redirect URI. Per OAuth 2.1:
  24. * - In the successful case, the redirect MUST include the `code` and `state` (if present) query parameters.
  25. * - In the error case, the redirect MUST include the `error` query parameter, and MAY include an optional `error_description` query parameter.
  26. */
  27. authorize(client: OAuthClientInformationFull, params: AuthorizationParams, res: Response): Promise<void>;
  28. /**
  29. * Returns the `codeChallenge` that was used when the indicated authorization began.
  30. */
  31. challengeForAuthorizationCode(client: OAuthClientInformationFull, authorizationCode: string): Promise<string>;
  32. /**
  33. * Exchanges an authorization code for an access token.
  34. */
  35. exchangeAuthorizationCode(client: OAuthClientInformationFull, authorizationCode: string, codeVerifier?: string, redirectUri?: string, resource?: URL): Promise<OAuthTokens>;
  36. /**
  37. * Exchanges a refresh token for an access token.
  38. */
  39. exchangeRefreshToken(client: OAuthClientInformationFull, refreshToken: string, scopes?: string[], resource?: URL): Promise<OAuthTokens>;
  40. /**
  41. * Verifies an access token and returns information about it.
  42. */
  43. verifyAccessToken(token: string): Promise<AuthInfo>;
  44. /**
  45. * Revokes an access or refresh token. If unimplemented, token revocation is not supported (not recommended).
  46. *
  47. * If the given token is invalid or already revoked, this method should do nothing.
  48. */
  49. revokeToken?(client: OAuthClientInformationFull, request: OAuthTokenRevocationRequest): Promise<void>;
  50. /**
  51. * Whether to skip local PKCE validation.
  52. *
  53. * If true, the server will not perform PKCE validation locally and will pass the code_verifier to the upstream server.
  54. *
  55. * NOTE: This should only be true if the upstream server is performing the actual PKCE validation.
  56. */
  57. skipLocalPkceValidation?: boolean;
  58. }
  59. /**
  60. * Slim implementation useful for token verification
  61. */
  62. export interface OAuthTokenVerifier {
  63. /**
  64. * Verifies an access token and returns information about it.
  65. */
  66. verifyAccessToken(token: string): Promise<AuthInfo>;
  67. }
  68. //# sourceMappingURL=provider.d.ts.map