Skip to main content

EmailPasswordProvider

@webda/auth


Class: EmailPasswordProvider<T>

Defined in: packages/auth/src/email/emailpassword.service.ts:134

Email + password login method

The password policy is process-wide: resolve() registers the one of this provider and stop() restores the default. With several instances the last one resolved wins.

Known residual exposure: Auth.Email.Register answers AccountExists for a registered email (enumeration), and login timing differs slightly for known emails. An unverified squatter owning an email blocks its registration until the real owner goes through account recovery.

Under allowedEmailDomains an email must be verified: with verification "after" or "none" a new registration is unverified and therefore refused (EMAIL_DOMAIN_NOT_ALLOWED); use "before".

Webda Modda​

EmailPasswordProvider

Extends​

  • Service<T>

Type Parameters​

T​

T extends EmailPasswordParameters = EmailPasswordParameters

Implements​

Constructors​

Constructor​

new EmailPasswordProvider<T>(name, params): EmailPasswordProvider<T>

Defined in: packages/core/lib/services/service.d.ts:72

Service

Parameters​

name​

string

The name of the service

params​

T

The parameters block define in the configuration file

Returns​

EmailPasswordProvider<T>

Inherited from​

Service<T>.constructor

Properties​

_compiledCapabilities​

protected _compiledCapabilities: Record<string, any>

Defined in: packages/core/lib/services/iservice.d.ts:39

Capabilities detected at compile-time from @WebdaCapability-tagged interfaces.

Populated during Service.resolve by reading the service's entry in webda.module.json. Each key is a capability name (e.g., "request-filter"), and the value is an empty object {} by default. Override getCapabilities to provide capability-specific configuration or to conditionally disable capabilities.

See​

getCapabilities

Implementation of​

AuthProvider._compiledCapabilities

Inherited from​

Service._compiledCapabilities


[WEBDA_EVENTS]​

[WEBDA_EVENTS]: object

Defined in: packages/core/lib/services/service.d.ts:50

Set the Webda events here

Implementation of​

AuthProvider.[WEBDA_EVENTS]

Inherited from​

Service.[WEBDA_EVENTS]


logger​

protected logger: Logger

Defined in: packages/core/lib/services/service.d.ts:59

Logger with class context

Implementation of​

AuthProvider.logger

Inherited from​

Service.logger


metrics?​

protected optional metrics?: object

Defined in: packages/core/lib/services/service.d.ts:63

Get metrics

Implementation of​

AuthProvider.metrics

Inherited from​

Service.metrics


name​

readonly name: string

Defined in: packages/core/lib/services/iservice.d.ts:19

Implementation of​

AuthProvider.name

Inherited from​

Service.name


parameters​

readonly parameters: T

Defined in: packages/core/lib/services/iservice.d.ts:20

Implementation of​

AuthProvider.parameters

Inherited from​

Service.parameters


pendingMails​

protected pendingMails: Set<Promise<void>>

Defined in: packages/auth/src/email/emailpassword.service.ts:502

Mails sent without being awaited


providerName​

readonly providerName: "email" = "email"

Defined in: packages/auth/src/email/emailpassword.service.ts:140

Unique provider name, used in ident keys ("email", "google")

Implementation of​

AuthProvider.providerName


createConfiguration?​

static optional createConfiguration?: (params) => any

Defined in: packages/core/lib/services/iservice.d.ts:24

Create configuration set by the application on load

Parameters​

params​

any

Returns​

any

Inherited from​

Service.createConfiguration


filterConfiguration?​

static optional filterConfiguration?: (params) => any

Defined in: packages/core/lib/services/iservice.d.ts:28

Create configuration set by the application on load

Parameters​

params​

any

Returns​

any

Inherited from​

Service.filterConfiguration


Parameters​

static Parameters: typeof EmailPasswordParameters = EmailPasswordParameters

Defined in: packages/auth/src/email/emailpassword.service.ts:138

Service parameters

Overrides​

Service.Parameters

Methods​

__clean()​

abstract __clean(): Promise<void>

Defined in: packages/core/lib/services/service.d.ts:215

Clean the service data, can only be used in test mode

Returns​

Promise<void>

Implementation of​

AuthProvider.__clean

Inherited from​

Service.__clean


addListener()​

addListener<Key>(eventName, listener): this

Defined in: packages/core/lib/events/asynceventemitter.d.ts:80

Type Parameters​

Key​

Key extends never

Parameters​

eventName​

Key

the event name

listener​

(event) => void | Promise<void>

the event listener

Returns​

this

this for chaining

See​

EventEmitter.addListener

Implementation of​

AuthProvider.addListener

Inherited from​

Service.addListener


addRoute()​

protected addRoute(url, methods, executer, openapi?, override?): void

Defined in: packages/core/lib/services/service.d.ts:177

Add a route dynamicaly

Parameters​

url​

string

of the route can contains dynamic part like {uuid}

methods​

HttpMethodType[]

the HTTP methods

executer​

Function

Method to execute for this route

openapi?​

OpenAPIWebdaDefinition

the OpenAPI specification

override?​

boolean

whether to override existing

Returns​

void

Implementation of​

AuthProvider.addRoute

Inherited from​

Service.addRoute


authorizeClientEvent()​

authorizeClientEvent(_event, _context): boolean

Defined in: packages/core/lib/services/service.d.ts:153

Authorize a public event subscription

Parameters​

_event​

string

the event name

_context​

OperationContext

the execution context

Returns​

boolean

true if the condition is met

Implementation of​

AuthProvider.authorizeClientEvent

Inherited from​

Service.authorizeClientEvent


buildLink(path, token): string

Defined in: packages/auth/src/email/emailpassword.service.ts:201

Absolute link for an emailed token

Parameters​

path​

string

path under the provider url

token​

string

token

Returns​

string

url


changePassword()​

changePassword(current, next): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:669

Change the current user's password: revokes the refresh tokens and ends the other sessions of the user, the calling cookie session is re-stamped and stays logged in

Parameters​

current​

string

current password

next​

string

new password

Returns​

Promise<void>


completeVerify()​

protected completeVerify(claims, ctx): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:557

Complete a verification; nothing changes unless every check passes

Parameters​

claims​

verified token claims

email​

string

email of the token

sub?​

string

user id

ctx​

any

context

Returns​

Promise<void>


computeParameters()​

computeParameters(): void

Defined in: packages/core/lib/services/service.d.ts:77

Used to compute or derivate input parameter to attribute

Returns​

void

Deprecated​

Implementation of​

AuthProvider.computeParameters

Inherited from​

Service.computeParameters


countAttempt()​

protected countAttempt(ident): Promise<boolean>

Defined in: packages/auth/src/email/emailpassword.service.ts:244

Count a login attempt before verifying it and decide whether the ident is locked

Rule, equivalent to isLocked(ident, failedBeforeDelay, lockout) on the state before this attempt: _loginAttempts is incremented first (atomically; the new value is returned by the memory repository and re-read otherwise), so this attempt is locked when the count of PREVIOUS attempts (_loginAttempts - 1) is at least failedBeforeDelay, unless that lock has expired, ie _lastLoginAttemptAt as read when this call started is older than lockout. _lastLoginAttemptAt is only refreshed by attempts that are not refused, so hammering a locked ident does not extend the lock; a count reaching the threshold without timestamp is an expired lock. Both are top-level attributes: stores implement atomic increment and single attribute set on them (nested-path atomic operations are not portable across stores). The timestamp is a plain set (last writer wins); the counter is never written back from a snapshot. A burst starting exactly when an expired lock is read is verified as a whole: it is bounded to one burst per lock window.

Parameters​

ident​

Ident

the ident

Returns​

Promise<boolean>

true when this attempt must be refused without checking the password


emit()​

emit<Key>(event, data): Promise<void>

Defined in: packages/core/lib/services/service.d.ts:204

Emit the event with data and wait for Promise to finish if listener returned a Promise

Type Parameters​

Key​

Key extends never

Parameters​

event​

Key

the event name

data​

object[Key]

the data to process

Returns​

Promise<void>

Implementation of​

AuthProvider.emit

Inherited from​

Service.emit


flushMails()​

flushMails(): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:507

Wait for the mails sent without being awaited (logged out verification, recovery)

Returns​

Promise<void>


getCapabilities()​

getCapabilities(): Record<string, any>

Defined in: packages/core/lib/services/iservice.d.ts:61

Return the capabilities of this service.

By default returns capabilities detected at compile-time from

Returns​

Record<string, any>

the result

Webda Capability-tagged​

interfaces in webda.module.json.

Override to disable capabilities based on configuration:

getCapabilities() {
const caps = super.getCapabilities();
if (!this.parameters.enabled) delete caps["request-filter"];
return caps;
}

Implementation of​

AuthProvider.getCapabilities

Inherited from​

Service.getCapabilities


getClientEvents()​

getClientEvents(): string[]

Defined in: packages/core/lib/services/service.d.ts:144

Return the events that an external system can subscribe to

Returns​

string[]

the list of results

Implementation of​

AuthProvider.getClientEvents

Inherited from​

Service.getClientEvents


getIdent()​

protected getIdent(email): Promise<Ident>

Defined in: packages/auth/src/email/emailpassword.service.ts:191

Parameters​

email​

string

normalised email

Returns​

Promise<Ident>

the email ident


getMaxListeners()​

getMaxListeners(): number

Defined in: packages/core/lib/events/asynceventemitter.d.ts:84

Returns​

number

Implementation of​

AuthProvider.getMaxListeners

Inherited from​

Service.getMaxListeners


getMetric()​

getMetric<T>(type, configuration): T

Defined in: packages/core/lib/services/service.d.ts:138

Add service name label

Type Parameters​

T​

T = Gauge<string> | Counter<string> | Histogram<string>

Parameters​

type​

CustomConstructor<T, [MetricConfiguration<T>]>

the type to look up

configuration​

MetricConfiguration<T>

the configuration

Returns​

T

the result

Implementation of​

AuthProvider.getMetric

Inherited from​

Service.getMetric


getName()​

getName(): string

Defined in: packages/core/lib/services/service.d.ts:209

Get service name

Returns​

string

the result string

Implementation of​

AuthProvider.getName

Inherited from​

Service.getName


getOpenApiReplacements()​

getOpenApiReplacements(): any

Defined in: packages/core/lib/services/service.d.ts:182

Return variables for replacement in openapi

Returns​

any

the result

Implementation of​

AuthProvider.getOpenApiReplacements

Inherited from​

Service.getOpenApiReplacements


getOperationId()​

getOperationId(id): string

Defined in: packages/core/lib/services/service.d.ts:167

If undefined is returned it cancel the operation registration

Parameters​

id​

string

the identifier

Returns​

string

the result

Implementation of​

AuthProvider.getOperationId

Inherited from​

Service.getOperationId


getParameters()​

getParameters(): T

Defined in: packages/core/lib/services/service.d.ts:82

Get the service parameters

Returns​

T

the result

Implementation of​

AuthProvider.getParameters

Inherited from​

Service.getParameters


getPublicInfo()​

getPublicInfo(): ProviderInfo

Defined in: packages/auth/src/email/emailpassword.service.ts:183

Returns​

ProviderInfo

public info

Implementation of​

AuthProvider.getPublicInfo


getService()​

getService<T>(name): ServicesMap[T]

Defined in: packages/core/lib/services/service.d.ts:131

Get a service by name

Type Parameters​

T​

T extends keyof ServicesMap

Parameters​

name​

T

the name to use

Returns​

ServicesMap[T]

the result map

Deprecated​

Use useService, might reconsider

Implementation of​

AuthProvider.getService

Inherited from​

Service.getService


getState()​

getState(): ServiceStates

Defined in: packages/core/lib/services/service.d.ts:55

Get the current state

Returns​

ServiceStates

the result

Implementation of​

AuthProvider.getState

Inherited from​

Service.getState


getUrl()​

getUrl(url, _methods): string

Defined in: packages/core/lib/services/service.d.ts:161

Return the full path url based on parameters

Parameters​

url​

string

relative url to service

_methods​

HttpMethodType[]

in case we need filtering (like Store)

Returns​

string

absolute url or undefined if need to skip the Route

Implementation of​

AuthProvider.getUrl

Inherited from​

Service.getUrl


init()​

init(): Promise<EmailPasswordProvider<T>>

Defined in: packages/auth/src/email/emailpassword.service.ts:156

Returns​

Promise<EmailPasswordProvider<T>>

Implementation of​

AuthProvider.init

Overrides​

Service.init


initMetrics()​

initMetrics(): void

Defined in: packages/core/lib/services/service.d.ts:124

Init the metrics

Returns​

void

Implementation of​

AuthProvider.initMetrics

Inherited from​

Service.initMetrics


initOperations()​

initOperations(): void

Defined in: packages/core/lib/services/service.d.ts:186

Init the operations from

Returns​

void

Operation​

decorators on this service

Implementation of​

AuthProvider.initOperations

Inherited from​

Service.initOperations


listeners()​

listeners(eventName): Function[]

Defined in: packages/core/lib/events/asynceventemitter.d.ts:139

Get all listeners for an event

Parameters​

eventName​

never

the event name

Returns​

Function[]

the list of results

Implementation of​

AuthProvider.listeners

Inherited from​

Service.listeners


loadCapabilities()​

protected loadCapabilities(): void

Defined in: packages/core/lib/services/service.d.ts:120

Load capabilities from webda.module.json metadata into _compiledCapabilities.

Called during resolve after dependency injection. Reads the service's type name from parameters, looks it up in the application's module metadata (moddas or beans section), and populates _compiledCapabilities with an empty object for each declared capability name.

Fails silently if the application is not available (e.g., in unit tests where services are instantiated without a full application context).

Returns​

void

Example​

// If webda.module.json contains:
// { "moddas": { "MyApp/HawkService": { "capabilities": ["request-filter", "cors-filter"] } } }
// Then after resolve(), this.getCapabilities() returns:
// { "request-filter": {}, "cors-filter": {} }

See​

getCapabilities

Implementation of​

AuthProvider.loadCapabilities

Inherited from​

Service.loadCapabilities


log()​

log(level, ...args): void

Defined in: packages/core/lib/services/service.d.ts:226

Parameters​

level​

WorkerLogLevel

to log

args​

...any[]

additional arguments

Returns​

void

Implementation of​

AuthProvider.log

Inherited from​

Service.log


login()​

login(email, password): Promise<AuthResult>

Defined in: packages/auth/src/email/emailpassword.service.ts:276

Login with email and password

Parameters​

email​

string

email

password​

string

password

Returns​

Promise<AuthResult>

the auth result


off()​

off<Key>(eventName, listener): this

Defined in: packages/core/lib/events/asynceventemitter.d.ts:116

Type Parameters​

Key​

Key extends never

Parameters​

eventName​

Key

the event name

listener​

(event) => void

the event listener

Returns​

this

this for chaining

See​

EventEmitter.off

Implementation of​

AuthProvider.off

Inherited from​

Service.off


on()​

on<Key>(eventName, listener): this

Defined in: packages/core/lib/events/asynceventemitter.d.ts:102

Type Parameters​

Key​

Key extends never

Parameters​

eventName​

Key

the event name

listener​

(event) => void

the event listener

Returns​

this

this for chaining

See​

EventEmitter.once

Implementation of​

AuthProvider.on

Inherited from​

Service.on


once()​

once<Key>(eventName, listener): this

Defined in: packages/core/lib/events/asynceventemitter.d.ts:95

Type Parameters​

Key​

Key extends never

Parameters​

eventName​

Key

the event name

listener​

(event) => void

the event listener

Returns​

this

this for chaining

See​

EventEmitter.once

Implementation of​

AuthProvider.once

Inherited from​

Service.once


protected prepareLink(normalized, userId): Promise<string>

Defined in: packages/auth/src/email/emailpassword.service.ts:450

Check and mark the send throttle of an email ident, then sign the token to email; runs as system

Parameters​

normalized​

string

normalised email

userId​

string

logged user (verify token), undefined for a logged-out register token

Returns​

Promise<string>

the token to send, undefined when nothing must be sent (logged out only)

Throws​

IdentLinkedElsewhere / PreconditionFailed / Throttled (logged in only)


recover()​

recover(token, password): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:624

Set a new password from a recovery link (does not log in): revokes the refresh tokens and ends every session of the user (see Session.authAt), resets the login attempts of the email ident

Parameters​

token​

string

recover token

password​

string

new password

Returns​

Promise<void>


recoverRedirect()​

recoverRedirect(ctx): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:691

Browser landing for recovery links: redirects a valid recover token to redirects.recover without consuming it, anything else to redirects.failure; never throws

Parameters​

ctx​

WebContext

web context

Returns​

Promise<void>


register()​

register(email, password, token?, profile?): Promise<any>

Defined in: packages/auth/src/email/emailpassword.service.ts:330

Register with email and password

Parameters​

email​

string

email

password​

string

password

token?​

string

register token from the emailed link (verification "before")

profile?​

any

extra user fields

Returns​

Promise<any>

the auth result, or verification_sent


removeAllListeners()​

removeAllListeners<Key>(eventName?): this

Defined in: packages/core/lib/events/asynceventemitter.d.ts:122

Type Parameters​

Key​

Key extends never

Parameters​

eventName?​

Key

the event name

Returns​

this

this for chaining

See​

EventEmitter.removeAllListeners

Implementation of​

AuthProvider.removeAllListeners

Inherited from​

Service.removeAllListeners


removeListener()​

removeListener<Key>(eventName, listener): this

Defined in: packages/core/lib/events/asynceventemitter.d.ts:109

Type Parameters​

Key​

Key extends never

Parameters​

eventName​

Key

the event name

listener​

(event) => void

the event listener

Returns​

this

this for chaining

See​

EventEmitter.removeListener

Implementation of​

AuthProvider.removeListener

Inherited from​

Service.removeListener


resolve()​

resolve(): this

Defined in: packages/auth/src/email/emailpassword.service.ts:143

Returns​

this

Implementation of​

AuthProvider.resolve

Overrides​

Service.resolve


sendMail()​

protected sendMail(template, to, url, token): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:213

Parameters​

template​

"EMAIL_REGISTER" | "EMAIL_RECOVERY"

mail template

to​

string

recipient

url​

string

link

token​

string

token

Returns​

Promise<void>


sendMailDetached()​

protected sendMailDetached(template, to, url, token): void

Defined in: packages/auth/src/email/emailpassword.service.ts:494

Send a mail without awaiting it; failures are logged without any secret

Parameters​

template​

"EMAIL_REGISTER" | "EMAIL_RECOVERY"

mail template

to​

string

recipient

url​

string

link

token​

string

token

Returns​

void


protected sendUnownedLink(normalized): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:436

Logged-out link: a register link is emailed, without awaiting the mail, only for an unknown or unowned and unverified email whose send throttle allows it; anything else is silently ignored

Parameters​

normalized​

string

normalised email

Returns​

Promise<void>


sessionMatches()​

protected sessionMatches(claims, ctx): boolean

Defined in: packages/auth/src/email/emailpassword.service.ts:546

Parameters​

claims​

verified token claims

sub?​

string

user id

ctx​

any

context

Returns​

boolean

true when the session is logged as the user of the token


setMaxListeners()​

setMaxListeners(n): this

Defined in: packages/core/lib/events/asynceventemitter.d.ts:88

Parameters​

n​

number

Returns​

this

Implementation of​

AuthProvider.setMaxListeners

Inherited from​

Service.setMaxListeners


startRecovery()​

startRecovery(email): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:592

Start password recovery; always succeeds to avoid revealing accounts

Parameters​

email​

string

email

Returns​

Promise<void>


startVerification()​

startVerification(email): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:419

Send (or resend) a verification link

Logged in: the link proves the email for the current account (sub is only in the token, the ident stays unowned until Auth.Email.Verify is called by the same session). Logged out: always answers with no content and never reveals anything; a link is only sent for an unowned or unknown email.

Parameters​

email​

string

email

Returns​

Promise<void>


stop()​

stop(): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:175

Returns​

Promise<void>

Implementation of​

AuthProvider.stop

Overrides​

Service.stop


toJSON()​

toJSON(): string

Defined in: packages/core/lib/services/service.d.ts:191

Prevent service to be serialized

Returns​

string

the result

Implementation of​

AuthProvider.toJSON

Inherited from​

Service.toJSON


toString()​

toString(): string

Defined in: packages/core/lib/services/service.d.ts:91

Return service representation

Returns​

string

the result

Implementation of​

AuthProvider.toString

Inherited from​

Service.toString


verify()​

verify(token): Promise<{ status: "verified"; }>

Defined in: packages/auth/src/email/emailpassword.service.ts:524

Mark an email as verified: only the session of the user named by the token can complete it

Parameters​

token​

string

verify token

Returns​

Promise<{ status: "verified"; }>

status


verifyRedirect()​

verifyRedirect(ctx): Promise<void>

Defined in: packages/auth/src/email/emailpassword.service.ts:709

Browser landing for emailed links: verifies then redirects, never throws

Parameters​

ctx​

WebContext

web context

Returns​

Promise<void>


verifyWith()​

protected verifyWith(token, ctx): Promise<{ status: "verified"; }>

Defined in: packages/auth/src/email/emailpassword.service.ts:534

Verify with an explicit context

Parameters​

token​

string

verify token

ctx​

any

context whose session must match the token

Returns​

Promise<{ status: "verified"; }>

status