OAuthProvider
Abstract Class: OAuthProvider<T, E>
Defined in: packages/auth/src/oauth/oauth.service.ts:283
Base of the OAuth 2.0 / OpenID Connect login providers
Exposes, under url (default /auth/<providerName>):
GET <url>{?redirect}: starts a login with a randomstate, a PKCE (S256) verifier and an OpenIDnonce, kept in a dedicated encrypted cookie (10 min, HttpOnly, SameSite=Lax, pathurl), then redirects to the provider;redirectmust matchauthorized_urisGET <url>/callback: consumes that cookie, checks the state, exchanges the code (handleCallback) and hands the identity toAuthentication.complete(); never throws, failures go toredirects.failure?reason=<CODE>- operation
Auth.<Provider>.Token(POST auth/<providerName>/token, JSON body{ token }or{ tokens }) for non-browser clients; it never links an identity to the session user
Subclasses implement providerName, getAuthorizationUrl, handleCallback and handleToken; the provider of the
returned identities is always forced to providerName.
Extends
Service<T,E>
Type Parameters
T
T extends OAuthProviderParameters = OAuthProviderParameters
E
E extends AsyncEventUnknown = { }
Implements
Constructors
Constructor
new OAuthProvider<
T,E>(name,params):OAuthProvider<T,E>
Defined in: packages/core/lib/services/service.d.ts:72
Service
Parameters
name
string
The name of the service
params
T
The parameters block define in the configuration file
Returns
OAuthProvider<T, E>
Inherited from
Service<T, E>.constructor
Properties
_compiledCapabilities
protected_compiledCapabilities:Record<string,any>
Defined in: packages/core/lib/services/iservice.d.ts:39
Capabilities detected at compile-time from @WebdaCapability-tagged interfaces.
Populated during Service.resolve by reading the service's entry in
webda.module.json. Each key is a capability name (e.g., "request-filter"),
and the value is an empty object {} by default. Override getCapabilities
to provide capability-specific configuration or to conditionally disable capabilities.
See
getCapabilities
Implementation of
AuthProvider._compiledCapabilities
Inherited from
Service._compiledCapabilities
[WEBDA_EVENTS]
[WEBDA_EVENTS]:
E
Defined in: packages/core/lib/services/service.d.ts:50
Set the Webda events here
Implementation of
Inherited from
Service.[WEBDA_EVENTS]
logger
protectedlogger:Logger
Defined in: packages/core/lib/services/service.d.ts:59
Logger with class context
Implementation of
Inherited from
Service.logger
metrics?
protectedoptionalmetrics?:object
Defined in: packages/core/lib/services/service.d.ts:63
Get metrics
Implementation of
Inherited from
Service.metrics
name
readonlyname:string
Defined in: packages/core/lib/services/iservice.d.ts:19
Implementation of
Inherited from
Service.name
parameters
readonlyparameters:T
Defined in: packages/core/lib/services/iservice.d.ts:20
Implementation of
Inherited from
Service.parameters
providerName
abstractreadonlyproviderName:string
Defined in: packages/auth/src/oauth/oauth.service.ts:293
Unique provider name, used in ident keys ("google")
Implementation of
createConfiguration?
staticoptionalcreateConfiguration?: (params) =>any
Defined in: packages/core/lib/services/iservice.d.ts:24
Create configuration set by the application on load
Parameters
params
any
Returns
any
Inherited from
Service.createConfiguration
filterConfiguration?
staticoptionalfilterConfiguration?: (params) =>any
Defined in: packages/core/lib/services/iservice.d.ts:28
Create configuration set by the application on load
Parameters
params
any
Returns
any
Inherited from
Service.filterConfiguration
Parameters
staticParameters: typeofOAuthProviderParameters=OAuthProviderParameters
Defined in: packages/auth/src/oauth/oauth.service.ts:290
Service parameters
Overrides
Service.Parameters
Methods
__clean()
abstract__clean():Promise<void>
Defined in: packages/core/lib/services/service.d.ts:215
Clean the service data, can only be used in test mode
Returns
Promise<void>
Implementation of
Inherited from
Service.__clean
addListener()
addListener<
Key>(eventName,listener):this
Defined in: packages/core/lib/events/asynceventemitter.d.ts:80
Type Parameters
Key
Key extends string | number | symbol
Parameters
eventName
Key
the event name
listener
(event) => void | Promise<void>
the event listener
Returns
this
this for chaining
See
EventEmitter.addListener
Implementation of
Inherited from
Service.addListener
addRoute()
protectedaddRoute(url,methods,executer,openapi?,override?):void
Defined in: packages/core/lib/services/service.d.ts:177
Add a route dynamicaly
Parameters
url
string
of the route can contains dynamic part like {uuid}
methods
HttpMethodType[]
the HTTP methods
executer
Function
Method to execute for this route
openapi?
OpenAPIWebdaDefinition
the OpenAPI specification
override?
boolean
whether to override existing
Returns
void
Implementation of
Inherited from
Service.addRoute
allowedRedirect()
protectedallowedRedirect(redirect):string
Defined in: packages/auth/src/oauth/oauth.service.ts:513
Check a post-login target against authorized_uris: same origin, and the listed path or below it; an encoded
slash or backslash in the path is refused
Parameters
redirect
unknown
candidate
Returns
string
the normalised url, undefined when not allowed
authorizeClientEvent()
authorizeClientEvent(
_event,_context):boolean
Defined in: packages/core/lib/services/service.d.ts:153
Authorize a public event subscription
Parameters
_event
string
the event name
_context
OperationContext
the execution context
Returns
boolean
true if the condition is met
Implementation of
AuthProvider.authorizeClientEvent
Inherited from
Service.authorizeClientEvent
callback()
callback(
ctx):Promise<void>
Defined in: packages/auth/src/oauth/oauth.service.ts:671
Provider callback: verify the state, exchange the code, complete the login and redirect; never throws
Parameters
ctx
WebContext
web context
Returns
Promise<void>
checkIdentity()
protectedcheckIdentity(identity):ResolvedIdentity
Defined in: packages/auth/src/oauth/oauth.service.ts:488
Parameters
identity
ResolvedIdentity
identity returned by the subclass
Returns
ResolvedIdentity
the identity
Throws
TokenInvalid when it has no subject
computeParameters()
computeParameters():
void
Defined in: packages/core/lib/services/service.d.ts:77
Used to compute or derivate input parameter to attribute
Returns
void
Deprecated
Implementation of
AuthProvider.computeParameters
Inherited from
Service.computeParameters
consumePending()
protectedconsumePending(ctx):Promise<PendingLogin>
Defined in: packages/auth/src/oauth/oauth.service.ts:571
Read and clear the pending login cookie
Parameters
ctx
WebContext
web context
Returns
Promise<PendingLogin>
the pending login, undefined when absent, invalid, expired or of another provider
emit()
emit<
Key>(event,data):Promise<void>
Defined in: packages/core/lib/services/service.d.ts:204
Emit the event with data and wait for Promise to finish if listener returned a Promise
Type Parameters
Key
Key extends string | number | symbol
Parameters
event
Key
the event name
data
E[Key]
the data to process
Returns
Promise<void>
Implementation of
Inherited from
Service.emit
fail()
protectedfail(ctx,reason):void
Defined in: packages/auth/src/oauth/oauth.service.ts:609
Parameters
ctx
WebContext
web context
reason
string
failure code
Returns
void
getAuthorizationUrl()
abstractgetAuthorizationUrl(request):string|Promise<string>
Defined in: packages/auth/src/oauth/oauth.service.ts:300
Build the authorization url of the provider, sending the PKCE challenge and the nonce
Parameters
request
authorization request
Returns
string | Promise<string>
the url to redirect the browser to
getCapabilities()
getCapabilities():
Record<string,any>
Defined in: packages/core/lib/services/iservice.d.ts:61
Return the capabilities of this service.
By default returns capabilities detected at compile-time from
Returns
Record<string, any>
the result
Webda Capability-tagged
interfaces in webda.module.json.
Override to disable capabilities based on configuration:
getCapabilities() {
const caps = super.getCapabilities();
if (!this.parameters.enabled) delete caps["request-filter"];
return caps;
}
Implementation of
Inherited from
Service.getCapabilities
getClientEvents()
getClientEvents():
string[]
Defined in: packages/core/lib/services/service.d.ts:144
Return the events that an external system can subscribe to
Returns
string[]
the list of results
Implementation of
Inherited from
Service.getClientEvents
getCookieName()
protectedgetCookieName():string
Defined in: packages/auth/src/oauth/oauth.service.ts:345
Returns
string
the name of the pending login cookie
getMaxListeners()
getMaxListeners():
number
Defined in: packages/core/lib/events/asynceventemitter.d.ts:84
Returns
number
Implementation of
Inherited from
Service.getMaxListeners
getMetric()
getMetric<
T>(type,configuration):T
Defined in: packages/core/lib/services/service.d.ts:138
Add service name label
Type Parameters
T
T = Gauge<string> | Counter<string> | Histogram<string>
Parameters
type
CustomConstructor<T, [MetricConfiguration<T>]>
the type to look up
configuration
MetricConfiguration<T>
the configuration
Returns
T
the result
Implementation of
Inherited from
Service.getMetric
getName()
getName():
string
Defined in: packages/core/lib/services/service.d.ts:209
Get service name
Returns
string
the result string
Implementation of
Inherited from
Service.getName
getOpenApiReplacements()
getOpenApiReplacements():
any
Defined in: packages/core/lib/services/service.d.ts:182
Return variables for replacement in openapi
Returns
any
the result
Implementation of
AuthProvider.getOpenApiReplacements
Inherited from
Service.getOpenApiReplacements
getOperationId()
getOperationId(
id):string
Defined in: packages/core/lib/services/service.d.ts:167
If undefined is returned it cancel the operation registration
Parameters
id
string
the identifier
Returns
string
the result
Implementation of
Inherited from
Service.getOperationId
getParameters()
getParameters():
T
Defined in: packages/core/lib/services/service.d.ts:82
Get the service parameters
Returns
T
the result
Implementation of
Inherited from
Service.getParameters
getPublicInfo()
getPublicInfo():
ProviderInfo
Defined in: packages/auth/src/oauth/oauth.service.ts:404
Returns
ProviderInfo
public info
Implementation of
getRedirectUri()
protectedgetRedirectUri(ctx):string
Defined in: packages/auth/src/oauth/oauth.service.ts:534
Parameters
ctx
WebContext
web context
Returns
string
the callback url sent to the provider
getService()
getService<
T>(name):ServicesMap[T]
Defined in: packages/core/lib/services/service.d.ts:131
Get a service by name
Type Parameters
T
T extends keyof ServicesMap
Parameters
name
T
the name to use
Returns
ServicesMap[T]
the result map
Deprecated
Use useService, might reconsider
Implementation of
Inherited from
Service.getService
getState()
getState():
ServiceStates
Defined in: packages/core/lib/services/service.d.ts:55
Get the current state
Returns
ServiceStates
the result
Implementation of
Inherited from
Service.getState
getUrl()
getUrl(
url,_methods):string
Defined in: packages/core/lib/services/service.d.ts:161
Return the full path url based on parameters
Parameters
url
string
relative url to service
_methods
HttpMethodType[]
in case we need filtering (like Store)
Returns
string
absolute url or undefined if need to skip the Route
Implementation of
Inherited from
Service.getUrl
handleCallback()
abstracthandleCallback(request):Promise<ResolvedIdentity>
Defined in: packages/auth/src/oauth/oauth.service.ts:309
Exchange an authorization code (with the PKCE verifier) and verify the result, including the nonce of an ID token
Parameters
request
code exchange
Returns
Promise<ResolvedIdentity>
the identity proven by the provider
Throws
an HttpError (for example TokenInvalid) whose code is used as the failure reason
handleToken()
abstracthandleToken(request):Promise<ResolvedIdentity>
Defined in: packages/auth/src/oauth/oauth.service.ts:317
Verify a token presented by a non-browser client
Parameters
request
token and/or tokens (at least one is present)
Returns
Promise<ResolvedIdentity>
the identity proven by the provider
Throws
TokenInvalid when the token cannot be verified
init()
init():
Promise<OAuthProvider<T,E>>
Defined in: packages/auth/src/oauth/oauth.service.ts:357
Returns
Promise<OAuthProvider<T, E>>
Implementation of
Overrides
Service.init
initMetrics()
initMetrics():
void
Defined in: packages/core/lib/services/service.d.ts:124
Init the metrics
Returns
void
Implementation of
Inherited from
Service.initMetrics
initOperations()
initOperations():
void
Defined in: packages/auth/src/oauth/oauth.service.ts:385
Register Auth.<Provider>.Token: its id and path depend on the provider name
Returns
void
Implementation of
Overrides
Service.initOperations
leaveForeignSession()
protectedleaveForeignSession(ctx,identity):Promise<void>
Defined in: packages/auth/src/oauth/oauth.service.ts:469
The token operation never links: with a logged-in session, an identity owned by another user is refused and a new or unowned one starts a fresh session
Parameters
ctx
any
operation context
identity
ResolvedIdentity
verified identity
Returns
Promise<void>
Throws
IdentLinkedElsewhere when the identity belongs to another user than the session one
listeners()
listeners(
eventName):Function[]
Defined in: packages/core/lib/events/asynceventemitter.d.ts:139
Get all listeners for an event
Parameters
eventName
keyof E
the event name
Returns
Function[]
the list of results
Implementation of
Inherited from
Service.listeners
loadCapabilities()
protectedloadCapabilities():void
Defined in: packages/core/lib/services/service.d.ts:120
Load capabilities from webda.module.json metadata into _compiledCapabilities.
Called during resolve after dependency injection. Reads the service's
type name from parameters, looks it up in the application's module metadata
(moddas or beans section), and populates _compiledCapabilities with an
empty object for each declared capability name.
Fails silently if the application is not available (e.g., in unit tests where services are instantiated without a full application context).
Returns
void
Example
// If webda.module.json contains:
// { "moddas": { "MyApp/HawkService": { "capabilities": ["request-filter", "cors-filter"] } } }
// Then after resolve(), this.getCapabilities() returns:
// { "request-filter": {}, "cors-filter": {} }
See
getCapabilities
Implementation of
Inherited from
Service.loadCapabilities
log()
log(
level, ...args):void
Defined in: packages/core/lib/services/service.d.ts:226
Parameters
level
WorkerLogLevel
to log
args
...any[]
additional arguments
Returns
void
Implementation of
Inherited from
Service.log
login()
login(
ctx):Promise<void>
Defined in: packages/auth/src/oauth/oauth.service.ts:624
Start a login: redirect the browser to the provider
Parameters
ctx
WebContext
web context
Returns
Promise<void>
off()
off<
Key>(eventName,listener):this
Defined in: packages/core/lib/events/asynceventemitter.d.ts:116
Type Parameters
Key
Key extends string | number | symbol
Parameters
eventName
Key
the event name
listener
(event) => void
the event listener
Returns
this
this for chaining
See
EventEmitter.off
Implementation of
Inherited from
Service.off
on()
on<
Key>(eventName,listener):this
Defined in: packages/core/lib/events/asynceventemitter.d.ts:102
Type Parameters
Key
Key extends string | number | symbol
Parameters
eventName
Key
the event name
listener
(event) => void
the event listener
Returns
this
this for chaining
See
EventEmitter.once
Implementation of
Inherited from
Service.on
onAuthenticated()
protectedonAuthenticated(_identity,_result,_source,_request?):Promise<void>
Defined in: packages/auth/src/oauth/oauth.service.ts:326
Called after a successful Authentication.complete() (status ok or mfa_required)
Parameters
_identity
ResolvedIdentity
the identity
_result
AuthResult
the result
_source
"callback" | "token"
browser callback or token operation
_request?
the token operation request (token operation only)
Returns
Promise<void>
once()
once<
Key>(eventName,listener):this
Defined in: packages/core/lib/events/asynceventemitter.d.ts:95
Type Parameters
Key
Key extends string | number | symbol
Parameters
eventName
Key
the event name
listener
(event) => void
the event listener
Returns
this
this for chaining
See
EventEmitter.once
Implementation of
Inherited from
Service.once
ownIdentity()
protectedownIdentity(identity):ResolvedIdentity
Defined in: packages/auth/src/oauth/oauth.service.ts:499
Parameters
identity
ResolvedIdentity
identity returned by the subclass
Returns
ResolvedIdentity
the identity, always attributed to this provider
redirect()
protectedredirect(ctx,url):void
Defined in: packages/auth/src/oauth/oauth.service.ts:600
Redirect without caching
Parameters
ctx
WebContext
web context
url
string
target
Returns
void
removeAllListeners()
removeAllListeners<
Key>(eventName?):this
Defined in: packages/core/lib/events/asynceventemitter.d.ts:122
Type Parameters
Key
Key extends string | number | symbol
Parameters
eventName?
Key
the event name
Returns
this
this for chaining
See
EventEmitter.removeAllListeners
Implementation of
AuthProvider.removeAllListeners
Inherited from
Service.removeAllListeners
removeListener()
removeListener<
Key>(eventName,listener):this
Defined in: packages/core/lib/events/asynceventemitter.d.ts:109
Type Parameters
Key
Key extends string | number | symbol
Parameters
eventName
Key
the event name
listener
(event) => void
the event listener
Returns
this
this for chaining
See
EventEmitter.removeListener
Implementation of
Inherited from
Service.removeListener
requireJson()
protectedrequireJson(ctx):void
Defined in: packages/auth/src/oauth/oauth.service.ts:453
Refuse a request that is not JSON: cross-site requests can only send form or text/plain bodies without a
preflight
Parameters
ctx
any
operation context
Returns
void
Throws
UnsupportedMediaType when the HTTP request is not application/json
requiresClientSecret()
protectedrequiresClientSecret():boolean
Defined in: packages/auth/src/oauth/oauth.service.ts:338
Returns
boolean
false when the provider works without client secret (public clients)
resolve()
resolve():
this
Defined in: packages/auth/src/oauth/oauth.service.ts:350
Returns
this
Implementation of
Overrides
Service.resolve
sendPendingCookie()
protectedsendPendingCookie(ctx,redirectUri,value?):void
Defined in: packages/auth/src/oauth/oauth.service.ts:545
Set (or clear, without value) the pending login cookie, scoped to the callback path: the path of the effective redirect_uri, which includes any deployment prefix (API Gateway stage, path-stripping proxy) the routes do not see
Parameters
ctx
WebContext
web context
redirectUri
string
callback url
value?
string
encrypted pending login
Returns
void
setMaxListeners()
setMaxListeners(
n):this
Defined in: packages/core/lib/events/asynceventemitter.d.ts:88
Parameters
n
number
Returns
this
Implementation of
Inherited from
Service.setMaxListeners
stop()
stop():
Promise<void>
Defined in: packages/core/lib/services/service.d.ts:86
Shutdown the current service if action need to be taken
Returns
Promise<void>
Implementation of
Inherited from
Service.stop
toJSON()
toJSON():
string
Defined in: packages/core/lib/services/service.d.ts:191
Prevent service to be serialized
Returns
string
the result
Implementation of
Inherited from
Service.toJSON
token()
token(
token?,tokens?):Promise<AuthResult>
Defined in: packages/auth/src/oauth/oauth.service.ts:418
Log in with a token obtained by the client from the provider
Requires a JSON request (a cross-site form or text/plain POST is refused). A request carrying a logged-in
session never links the identity to that user: an identity owned by another user is refused
(IDENT_LINKED_ELSEWHERE), a new or unowned one gets a fresh session.
Parameters
token?
string
token (an ID token for OpenID Connect providers)
tokens?
credentials obtained from the provider (v3 body)
Returns
Promise<AuthResult>
the auth result
toString()
toString():
string
Defined in: packages/core/lib/services/service.d.ts:91
Return service representation
Returns
string
the result
Implementation of
Inherited from
Service.toString