Skip to main content

GoogleAuthentication

@webda/google-auth


Class: GoogleAuthentication<T>

Defined in: google-auth/src/google-auth.service.ts:92

Sign in with Google (OpenID Connect)

The browser flow (GET /auth/google, GET /auth/google/callback) uses PKCE and a nonce, exchanges the code and verifies the returned ID token for client_id. Auth.Google.Token accepts a Google ID token, as token or as the id_token of tokens (v3 body), whose audience is client_id or one of audiences (never an access token). Credentials are stored encrypted on the ident and emitted with GoogleAuth.Tokens after the login.

Webda Modda​

GoogleAuthentication

Extends​

Type Parameters​

T​

T extends GoogleParameters = GoogleParameters

Constructors​

Constructor​

new GoogleAuthentication<T>(name, params): GoogleAuthentication<T>

Defined in: core/lib/services/service.d.ts:72

Service

Parameters​

name​

string

The name of the service

params​

T

The parameters block define in the configuration file

Returns​

GoogleAuthentication<T>

Inherited from​

OAuthProvider< T, GoogleAuthEvents >.constructor

Properties​

_compiledCapabilities​

protected _compiledCapabilities: Record<string, any>

Defined in: core/lib/services/iservice.d.ts:39

Capabilities detected at compile-time from @WebdaCapability-tagged interfaces.

Populated during Service.resolve by reading the service's entry in webda.module.json. Each key is a capability name (e.g., "request-filter"), and the value is an empty object {} by default. Override getCapabilities to provide capability-specific configuration or to conditionally disable capabilities.

See​

getCapabilities

Inherited from​

OAuthProvider._compiledCapabilities


[WEBDA_EVENTS]​

[WEBDA_EVENTS]: GoogleAuthEvents

Defined in: core/lib/services/service.d.ts:50

Set the Webda events here

Inherited from​

OAuthProvider.[WEBDA_EVENTS]


logger​

protected logger: Logger

Defined in: core/lib/services/service.d.ts:59

Logger with class context

Inherited from​

OAuthProvider.logger


metrics?​

protected optional metrics?: object

Defined in: core/lib/services/service.d.ts:63

Get metrics

Inherited from​

OAuthProvider.metrics


name​

readonly name: string

Defined in: core/lib/services/iservice.d.ts:19

Inherited from​

OAuthProvider.name


parameters​

readonly parameters: T

Defined in: core/lib/services/iservice.d.ts:20

Inherited from​

OAuthProvider.parameters


providerName​

readonly providerName: "google" = "google"

Defined in: google-auth/src/google-auth.service.ts:98

Unique provider name, used in ident keys ("google")

Overrides​

OAuthProvider.providerName


verifier​

protected verifier: OAuth2Client

Defined in: google-auth/src/google-auth.service.ts:101

Client verifying ID tokens: one per service so the Google certificates cache is reused


createConfiguration?​

static optional createConfiguration?: (params) => any

Defined in: core/lib/services/iservice.d.ts:24

Create configuration set by the application on load

Parameters​

params​

any

Returns​

any

Inherited from​

OAuthProvider.createConfiguration


filterConfiguration?​

static optional filterConfiguration?: (params) => any

Defined in: core/lib/services/iservice.d.ts:28

Create configuration set by the application on load

Parameters​

params​

any

Returns​

any

Inherited from​

OAuthProvider.filterConfiguration


Parameters​

static Parameters: typeof GoogleParameters = GoogleParameters

Defined in: google-auth/src/google-auth.service.ts:96

Overrides​

OAuthProvider.Parameters

Methods​

__clean()​

abstract __clean(): Promise<void>

Defined in: core/lib/services/service.d.ts:215

Clean the service data, can only be used in test mode

Returns​

Promise<void>

Inherited from​

OAuthProvider.__clean


addListener()​

addListener<Key>(eventName, listener): this

Defined in: core/lib/events/asynceventemitter.d.ts:80

Type Parameters​

Key​

Key extends "GoogleAuth.Tokens"

Parameters​

eventName​

Key

the event name

listener​

(event) => void | Promise<void>

the event listener

Returns​

this

this for chaining

See​

EventEmitter.addListener

Inherited from​

OAuthProvider.addListener


addRoute()​

protected addRoute(url, methods, executer, openapi?, override?): void

Defined in: core/lib/services/service.d.ts:177

Add a route dynamicaly

Parameters​

url​

string

of the route can contains dynamic part like {uuid}

methods​

HttpMethodType[]

the HTTP methods

executer​

Function

Method to execute for this route

openapi?​

OpenAPIWebdaDefinition

the OpenAPI specification

override?​

boolean

whether to override existing

Returns​

void

Inherited from​

OAuthProvider.addRoute


allowedRedirect()​

protected allowedRedirect(redirect): string

Defined in: auth/lib/oauth/oauth.service.d.ts:250

Check a post-login target against authorized_uris: same origin, and the listed path or below it; an encoded slash or backslash in the path is refused

Parameters​

redirect​

unknown

candidate

Returns​

string

the normalised url, undefined when not allowed

Inherited from​

OAuthProvider.allowedRedirect


authorizeClientEvent()​

authorizeClientEvent(_event, _context): boolean

Defined in: core/lib/services/service.d.ts:153

Authorize a public event subscription

Parameters​

_event​

string

the event name

_context​

OperationContext

the execution context

Returns​

boolean

true if the condition is met

Inherited from​

OAuthProvider.authorizeClientEvent


callback()​

callback(ctx): Promise<void>

Defined in: auth/lib/oauth/oauth.service.d.ts:290

Provider callback: verify the state, exchange the code, complete the login and redirect; never throws

Parameters​

ctx​

WebContext

web context

Returns​

Promise<void>

Inherited from​

OAuthProvider.callback


checkIdentity()​

protected checkIdentity(identity): ResolvedIdentity

Defined in: auth/lib/oauth/oauth.service.d.ts:238

Parameters​

identity​

ResolvedIdentity

identity returned by the subclass

Returns​

ResolvedIdentity

the identity

Throws​

TokenInvalid when it has no subject

Inherited from​

OAuthProvider.checkIdentity


computeParameters()​

computeParameters(): void

Defined in: core/lib/services/service.d.ts:77

Used to compute or derivate input parameter to attribute

Returns​

void

Deprecated​

Inherited from​

OAuthProvider.computeParameters


consumePending()​

protected consumePending(ctx): Promise<PendingLogin>

Defined in: auth/lib/oauth/oauth.service.d.ts:269

Read and clear the pending login cookie

Parameters​

ctx​

WebContext

web context

Returns​

Promise<PendingLogin>

the pending login, undefined when absent, invalid, expired or of another provider

Inherited from​

OAuthProvider.consumePending


emit()​

emit<Key>(event, data): Promise<void>

Defined in: core/lib/services/service.d.ts:204

Emit the event with data and wait for Promise to finish if listener returned a Promise

Type Parameters​

Key​

Key extends "GoogleAuth.Tokens"

Parameters​

event​

Key

the event name

data​

GoogleAuthEvents[Key]

the data to process

Returns​

Promise<void>

Inherited from​

OAuthProvider.emit


fail()​

protected fail(ctx, reason): void

Defined in: auth/lib/oauth/oauth.service.d.ts:280

Parameters​

ctx​

WebContext

web context

reason​

string

failure code

Returns​

void

Inherited from​

OAuthProvider.fail


getAuthorizationUrl()​

getAuthorizationUrl(request): string

Defined in: google-auth/src/google-auth.service.ts:126

Parameters​

request​

OAuthAuthorizationRequest

authorization request

Returns​

string

the Google authorization url

Overrides​

OAuthProvider.getAuthorizationUrl


getCapabilities()​

getCapabilities(): Record<string, any>

Defined in: core/lib/services/iservice.d.ts:61

Return the capabilities of this service.

By default returns capabilities detected at compile-time from

Returns​

Record<string, any>

the result

Webda Capability-tagged​

interfaces in webda.module.json.

Override to disable capabilities based on configuration:

getCapabilities() {
const caps = super.getCapabilities();
if (!this.parameters.enabled) delete caps["request-filter"];
return caps;
}

Inherited from​

OAuthProvider.getCapabilities


getClient()​

protected getClient(redirectUri?): OAuth2Client

Defined in: google-auth/src/google-auth.service.ts:114

Parameters​

redirectUri?​

string

callback url

Returns​

OAuth2Client

a Google OAuth client for the authorization url and the code exchange


getClientEvents()​

getClientEvents(): string[]

Defined in: core/lib/services/service.d.ts:144

Return the events that an external system can subscribe to

Returns​

string[]

the list of results

Inherited from​

OAuthProvider.getClientEvents


getCookieName()​

protected getCookieName(): string

Defined in: auth/lib/oauth/oauth.service.d.ts:193

Returns​

string

the name of the pending login cookie

Inherited from​

OAuthProvider.getCookieName


getMaxListeners()​

getMaxListeners(): number

Defined in: core/lib/events/asynceventemitter.d.ts:84

Returns​

number

Inherited from​

OAuthProvider.getMaxListeners


getMetric()​

getMetric<T>(type, configuration): T

Defined in: core/lib/services/service.d.ts:138

Add service name label

Type Parameters​

T​

T = Gauge<string> | Counter<string> | Histogram<string>

Parameters​

type​

CustomConstructor<T, [MetricConfiguration<T>]>

the type to look up

configuration​

MetricConfiguration<T>

the configuration

Returns​

T

the result

Inherited from​

OAuthProvider.getMetric


getName()​

getName(): string

Defined in: core/lib/services/service.d.ts:209

Get service name

Returns​

string

the result string

Inherited from​

OAuthProvider.getName


getOpenApiReplacements()​

getOpenApiReplacements(): any

Defined in: core/lib/services/service.d.ts:182

Return variables for replacement in openapi

Returns​

any

the result

Inherited from​

OAuthProvider.getOpenApiReplacements


getOperationId()​

getOperationId(id): string

Defined in: core/lib/services/service.d.ts:167

If undefined is returned it cancel the operation registration

Parameters​

id​

string

the identifier

Returns​

string

the result

Inherited from​

OAuthProvider.getOperationId


getParameters()​

getParameters(): T

Defined in: core/lib/services/service.d.ts:82

Get the service parameters

Returns​

T

the result

Inherited from​

OAuthProvider.getParameters


getPublicInfo()​

getPublicInfo(): ProviderInfo

Defined in: auth/lib/oauth/oauth.service.d.ts:206

Returns​

ProviderInfo

public info

Inherited from​

OAuthProvider.getPublicInfo


getRedirectUri()​

protected getRedirectUri(ctx): string

Defined in: auth/lib/oauth/oauth.service.d.ts:255

Parameters​

ctx​

WebContext

web context

Returns​

string

the callback url sent to the provider

Inherited from​

OAuthProvider.getRedirectUri


getService()​

getService<T>(name): ServicesMap[T]

Defined in: core/lib/services/service.d.ts:131

Get a service by name

Type Parameters​

T​

T extends keyof ServicesMap

Parameters​

name​

T

the name to use

Returns​

ServicesMap[T]

the result map

Deprecated​

Use useService, might reconsider

Inherited from​

OAuthProvider.getService


getState()​

getState(): ServiceStates

Defined in: core/lib/services/service.d.ts:55

Get the current state

Returns​

ServiceStates

the result

Inherited from​

OAuthProvider.getState


getUrl()​

getUrl(url, _methods): string

Defined in: core/lib/services/service.d.ts:161

Return the full path url based on parameters

Parameters​

url​

string

relative url to service

_methods​

HttpMethodType[]

in case we need filtering (like Store)

Returns​

string

absolute url or undefined if need to skip the Route

Inherited from​

OAuthProvider.getUrl


handleCallback()​

handleCallback(request): Promise<ResolvedIdentity>

Defined in: google-auth/src/google-auth.service.ts:147

Exchange the code with the PKCE verifier, verify the returned ID token for client_id and its nonce

Parameters​

request​

OAuthCallbackRequest

code exchange

Returns​

Promise<ResolvedIdentity>

the identity, with the credentials of the exchange

Overrides​

OAuthProvider.handleCallback


handleToken()​

handleToken(request): Promise<ResolvedIdentity>

Defined in: google-auth/src/google-auth.service.ts:174

Verify a Google ID token sent by a client, as token or tokens.id_token

Parameters​

request​

OAuthTokenRequest

token request

Returns​

Promise<ResolvedIdentity>

the identity, with the credentials sent in tokens

Overrides​

OAuthProvider.handleToken


init()​

init(): Promise<GoogleAuthentication<T>>

Defined in: google-auth/src/google-auth.service.ts:104

Returns​

Promise<GoogleAuthentication<T>>

Overrides​

OAuthProvider.init


initMetrics()​

initMetrics(): void

Defined in: core/lib/services/service.d.ts:124

Init the metrics

Returns​

void

Inherited from​

OAuthProvider.initMetrics


initOperations()​

initOperations(): void

Defined in: auth/lib/oauth/oauth.service.d.ts:202

Register Auth.<Provider>.Token: its id and path depend on the provider name

Returns​

void

Inherited from​

OAuthProvider.initOperations


leaveForeignSession()​

protected leaveForeignSession(ctx, identity): Promise<void>

Defined in: auth/lib/oauth/oauth.service.d.ts:232

The token operation never links: with a logged-in session, an identity owned by another user is refused and a new or unowned one starts a fresh session

Parameters​

ctx​

any

operation context

identity​

ResolvedIdentity

verified identity

Returns​

Promise<void>

Throws​

IdentLinkedElsewhere when the identity belongs to another user than the session one

Inherited from​

OAuthProvider.leaveForeignSession


listeners()​

listeners(eventName): Function[]

Defined in: core/lib/events/asynceventemitter.d.ts:139

Get all listeners for an event

Parameters​

eventName​

"GoogleAuth.Tokens"

the event name

Returns​

Function[]

the list of results

Inherited from​

OAuthProvider.listeners


loadCapabilities()​

protected loadCapabilities(): void

Defined in: core/lib/services/service.d.ts:120

Load capabilities from webda.module.json metadata into _compiledCapabilities.

Called during resolve after dependency injection. Reads the service's type name from parameters, looks it up in the application's module metadata (moddas or beans section), and populates _compiledCapabilities with an empty object for each declared capability name.

Fails silently if the application is not available (e.g., in unit tests where services are instantiated without a full application context).

Returns​

void

Example​

// If webda.module.json contains:
// { "moddas": { "MyApp/HawkService": { "capabilities": ["request-filter", "cors-filter"] } } }
// Then after resolve(), this.getCapabilities() returns:
// { "request-filter": {}, "cors-filter": {} }

See​

getCapabilities

Inherited from​

OAuthProvider.loadCapabilities


log()​

log(level, ...args): void

Defined in: core/lib/services/service.d.ts:226

Parameters​

level​

WorkerLogLevel

to log

args​

...any[]

additional arguments

Returns​

void

Inherited from​

OAuthProvider.log


login()​

login(ctx): Promise<void>

Defined in: auth/lib/oauth/oauth.service.d.ts:285

Start a login: redirect the browser to the provider

Parameters​

ctx​

WebContext

web context

Returns​

Promise<void>

Inherited from​

OAuthProvider.login


off()​

off<Key>(eventName, listener): this

Defined in: core/lib/events/asynceventemitter.d.ts:116

Type Parameters​

Key​

Key extends "GoogleAuth.Tokens"

Parameters​

eventName​

Key

the event name

listener​

(event) => void

the event listener

Returns​

this

this for chaining

See​

EventEmitter.off

Inherited from​

OAuthProvider.off


on()​

on<Key>(eventName, listener): this

Defined in: core/lib/events/asynceventemitter.d.ts:102

Type Parameters​

Key​

Key extends "GoogleAuth.Tokens"

Parameters​

eventName​

Key

the event name

listener​

(event) => void

the event listener

Returns​

this

this for chaining

See​

EventEmitter.once

Inherited from​

OAuthProvider.on


onAuthenticated()​

protected onAuthenticated(identity, _result, source, request?): Promise<void>

Defined in: google-auth/src/google-auth.service.ts:197

Emit GoogleAuth.Tokens once the login succeeded

Parameters​

identity​

ResolvedIdentity

the identity

_result​

AuthResult

the result

source​

"callback" | "token"

browser callback or token operation

request?​

OAuthTokenRequest

the token operation request

Returns​

Promise<void>

Overrides​

OAuthProvider.onAuthenticated


once()​

once<Key>(eventName, listener): this

Defined in: core/lib/events/asynceventemitter.d.ts:95

Type Parameters​

Key​

Key extends "GoogleAuth.Tokens"

Parameters​

eventName​

Key

the event name

listener​

(event) => void

the event listener

Returns​

this

this for chaining

See​

EventEmitter.once

Inherited from​

OAuthProvider.once


ownIdentity()​

protected ownIdentity(identity): ResolvedIdentity

Defined in: auth/lib/oauth/oauth.service.d.ts:243

Parameters​

identity​

ResolvedIdentity

identity returned by the subclass

Returns​

ResolvedIdentity

the identity, always attributed to this provider

Inherited from​

OAuthProvider.ownIdentity


redirect()​

protected redirect(ctx, url): void

Defined in: auth/lib/oauth/oauth.service.d.ts:275

Redirect without caching

Parameters​

ctx​

WebContext

web context

url​

string

target

Returns​

void

Inherited from​

OAuthProvider.redirect


removeAllListeners()​

removeAllListeners<Key>(eventName?): this

Defined in: core/lib/events/asynceventemitter.d.ts:122

Type Parameters​

Key​

Key extends "GoogleAuth.Tokens"

Parameters​

eventName?​

Key

the event name

Returns​

this

this for chaining

See​

EventEmitter.removeAllListeners

Inherited from​

OAuthProvider.removeAllListeners


removeListener()​

removeListener<Key>(eventName, listener): this

Defined in: core/lib/events/asynceventemitter.d.ts:109

Type Parameters​

Key​

Key extends "GoogleAuth.Tokens"

Parameters​

eventName​

Key

the event name

listener​

(event) => void

the event listener

Returns​

this

this for chaining

See​

EventEmitter.removeListener

Inherited from​

OAuthProvider.removeListener


requireJson()​

protected requireJson(ctx): void

Defined in: auth/lib/oauth/oauth.service.d.ts:224

Refuse a request that is not JSON: cross-site requests can only send form or text/plain bodies without a preflight

Parameters​

ctx​

any

operation context

Returns​

void

Throws​

UnsupportedMediaType when the HTTP request is not application/json

Inherited from​

OAuthProvider.requireJson


requiresClientSecret()​

protected requiresClientSecret(): boolean

Defined in: auth/lib/oauth/oauth.service.d.ts:189

Returns​

boolean

false when the provider works without client secret (public clients)

Inherited from​

OAuthProvider.requiresClientSecret


resolve()​

resolve(): this

Defined in: auth/lib/oauth/oauth.service.d.ts:195

Returns​

this

Inherited from​

OAuthProvider.resolve


sendPendingCookie()​

protected sendPendingCookie(ctx, redirectUri, value?): void

Defined in: auth/lib/oauth/oauth.service.d.ts:263

Set (or clear, without value) the pending login cookie, scoped to the callback path: the path of the effective redirect_uri, which includes any deployment prefix (API Gateway stage, path-stripping proxy) the routes do not see

Parameters​

ctx​

WebContext

web context

redirectUri​

string

callback url

value?​

string

encrypted pending login

Returns​

void

Inherited from​

OAuthProvider.sendPendingCookie


setMaxListeners()​

setMaxListeners(n): this

Defined in: core/lib/events/asynceventemitter.d.ts:88

Parameters​

n​

number

Returns​

this

Inherited from​

OAuthProvider.setMaxListeners


stop()​

stop(): Promise<void>

Defined in: core/lib/services/service.d.ts:86

Shutdown the current service if action need to be taken

Returns​

Promise<void>

Inherited from​

OAuthProvider.stop


toIdentity()​

protected toIdentity(payload, tokens?): ResolvedIdentity

Defined in: google-auth/src/google-auth.service.ts:249

Parameters​

payload​

TokenPayload

verified ID token payload

tokens?​

Credentials

credentials to store

Returns​

ResolvedIdentity

the identity


toJSON()​

toJSON(): string

Defined in: core/lib/services/service.d.ts:191

Prevent service to be serialized

Returns​

string

the result

Inherited from​

OAuthProvider.toJSON


token()​

token(token?, tokens?): Promise<AuthResult>

Defined in: auth/lib/oauth/oauth.service.d.ts:217

Log in with a token obtained by the client from the provider

Requires a JSON request (a cross-site form or text/plain POST is refused). A request carrying a logged-in session never links the identity to that user: an identity owned by another user is refused (IDENT_LINKED_ELSEWHERE), a new or unowned one gets a fresh session.

Parameters​

token?​

string

token (an ID token for OpenID Connect providers)

tokens?​

OAuthTokens

credentials obtained from the provider (v3 body)

Returns​

Promise<AuthResult>

the auth result

Inherited from​

OAuthProvider.token


toString()​

toString(): string

Defined in: core/lib/services/service.d.ts:91

Return service representation

Returns​

string

the result

Inherited from​

OAuthProvider.toString


verifyIdToken()​

protected verifyIdToken(idToken, audiences): Promise<TokenPayload>

Defined in: google-auth/src/google-auth.service.ts:215

Verify an ID token: signature, expiry, issuer (google-auth-library), audience and hosted domain

Parameters​

idToken​

string

ID token

audiences​

string[]

accepted audiences

Returns​

Promise<TokenPayload>

the payload

Throws​

TokenInvalid when the token does not verify

Throws​

EmailDomainNotAllowed when hostedDomain is set and the token is not from that domain