import { ConfigService } from "@nestjs/config"; import { ModuleRef } from "@nestjs/core"; import { EmailService } from "../../../core/email/services/email.service"; import { SecurityService } from "../../../core/security/services/security.service"; import { AuthPostLoginDataDTO } from "../../auth/dtos/auth.post.login.dto"; import { ClsService } from "nestjs-cls"; import { BaseConfigInterface } from "../../../config/interfaces"; import { AbstractService } from "../../../core/neo4j/abstracts/abstract.service"; import { JsonApiDataInterface } from "../../../core/jsonapi/interfaces/jsonapi.data.interface"; import { JsonApiService } from "../../../core/jsonapi/services/jsonapi.service"; import { Neo4jService } from "../../../core/neo4j/services/neo4j.service"; import { AuthPostRegisterDataDTO } from "../../auth/dtos/auth.post.register.dto"; import { AuthCode } from "../../auth/entities/auth.code"; import { Auth, AuthDescriptor } from "../../auth/entities/auth"; import { AuthRepository } from "../../auth/repositories/auth.repository"; import { CompanyRepository } from "../../company/repositories/company.repository"; import { DiscordUserService } from "../../discord-user/services/discord-user.service"; import { GoogleUserService } from "../../google-user/services/google-user.service"; import { TwoFactorService } from "../../two-factor/services/two-factor.service"; import { User } from "../../user/entities/user"; import { UserRepository } from "../../user/repositories/user.repository"; import { UserService } from "../../user/services/user.service"; import { WaitlistService } from "../../waitlist/services/waitlist.service"; import { PendingRegistrationService } from "./pending-registration.service"; import { TrialQueueService } from "./trial-queue.service"; /** * Every method here is a bespoke, non-CRUD auth flow (login, register, * refresh, code exchange, password reset/activation) — none maps onto * AbstractService's generic find/findById/create/put/patch/delete, and none * of their names collide with it, so no renames were needed (see * AuthRepository for the two that did). Extending AbstractService is for * descriptor typing consistency; the inherited generic methods are simply * unused. * * SATELLITE DEPENDENCIES: `twoFactorService`, `discordUserService`, * `waitlistService` and `trialQueueService` are `@Optional()` so that an * application can compose an auth module without the corresponding * foundation modules. The package `AuthModule` still imports every one of * them, so package consumers see no behavioural change; each guarded branch * below documents what happens when the dependency is absent. They are typed * `X | undefined` rather than `x?: X` because a `?` parameter cannot precede * a required one and the constructor order is preserved verbatim. A union type * makes TypeScript emit `Object` for `design:paramtypes`, so each one MUST also * carry an explicit `@Inject(...)` token — without it Nest cannot resolve the * provider and silently injects `undefined` even when the module supplies it. */ export declare class AuthService extends AbstractService { private readonly authRepository; private readonly userService; private readonly users; private readonly companyRepository; private readonly emailService; private readonly security; private readonly neo4j; private readonly moduleRef; private readonly configService; private readonly pendingRegistrationService; private readonly discordUserService; private readonly googleUserService; private readonly trialQueueService; private readonly waitlistService; private readonly twoFactorService; protected readonly descriptor: import("../../..").EntityDescriptor; private readonly logger; constructor(jsonApiService: JsonApiService, authRepository: AuthRepository, userService: UserService, users: UserRepository, companyRepository: CompanyRepository, emailService: EmailService, security: SecurityService, clsService: ClsService, neo4j: Neo4jService, moduleRef: ModuleRef, configService: ConfigService, pendingRegistrationService: PendingRegistrationService, discordUserService: DiscordUserService | undefined, googleUserService: GoogleUserService, trialQueueService: TrialQueueService | undefined, waitlistService: WaitlistService | undefined, twoFactorService: TwoFactorService | undefined); /** * Lazily resolves the registration hook from the module container. * This allows app modules loaded after AuthModule to provide the hook. * Returns undefined if no hook is registered. */ private getRegistrationHook; private get appConfig(); private get authConfig(); /** * Locale used for transactional emails and for the `/…` prefix of * the links inside them. Defaults to "en", which is the value every existing * consumer was hardcoded to. */ private get emailLocale(); findCurrentAuth(): Promise; createAuth(params: { user: User; refreshToken?: string; }): Promise; createToken(params: { user: User; refreshToken?: string; }): Promise; createCode(params: { authCodeId: string; authId: string; }): Promise; refreshToken(params: { refreshToken: string; }): Promise; login(params: { data: AuthPostLoginDataDTO; }): Promise; /** * The companies the authenticated (or company-selection scoped) user may act * for. Backs the selection screen and the company switcher. */ findCompanies(): Promise; /** * Exchanges a company-selection (or full) token for a session scoped to * `companyId`, carrying that company's roles. */ selectCompany(params: { companyId: string; }): Promise; /** * Complete the 2FA login after successful verification. * Called by the 2FA controller after verifying TOTP, passkey, or backup code. * * @param userId - The user's ID (extracted from pending session) * @returns Full auth token response */ completeTwoFactorLogin(userId: string): Promise; register(params: { data: AuthPostRegisterDataDTO; }): Promise; findAuthByCode(params: { code: string; }): Promise; deleteByToken(params: { token: string; }): Promise; startResetPassword(email: string, lng?: string): Promise; validateCode(code: string): Promise; resetPassword(code: string, password: string): Promise; acceptInvitation(code: string, password: string): Promise; activateAccount(code: string): Promise; completeOAuthRegistration(params: { pendingId: string; termsAcceptedAt: string; marketingConsent: boolean; marketingConsentAt: string | null; }): Promise<{ code: string; }>; /** * Send notification to all platform administrators about a new user registration. * Errors are logged but not thrown to avoid blocking the activation flow. */ private notifyAdminsOfRegistration; } //# sourceMappingURL=auth.service.d.ts.map