import { OAuthClient } from "../entities/oauth.client.entity"; import { OAuthRepository } from "../repositories/oauth.repository"; export interface CreateClientParams { name: string; description?: string; redirectUris: string[]; allowedScopes: string[]; allowedGrantTypes?: string[]; isConfidential?: boolean; accessTokenLifetime?: number; refreshTokenLifetime?: number; /** Owning user. Optional: dynamically registered clients (RFC 7591) have no owner. */ ownerId?: string; companyId?: string; } export interface UpdateClientParams { name?: string; description?: string; redirectUris?: string[]; allowedScopes?: string[]; isActive?: boolean; } /** * OAuth Client Service * * Manages OAuth client registration, validation, and lifecycle. * Handles client credentials securely using bcrypt hashing. */ export declare class OAuthClientService { private readonly oauthRepository; private static readonly DEFAULT_GRANT_TYPES; constructor(oauthRepository: OAuthRepository); /** * Creates a new OAuth client. * * For confidential clients, generates and returns the client secret. * The secret is only returned once at creation time. * * @returns The created client and the client secret (for confidential clients) */ createClient(params: CreateClientParams): Promise<{ client: OAuthClient; clientSecret?: string; }>; /** * Retrieves a client by its public client ID. */ getClient(clientId: string): Promise; /** * Retrieves all clients owned by a user. */ getClientsByOwner(ownerId: string): Promise; /** * Validates client credentials. * * For confidential clients, validates the client secret using bcrypt. * For public clients, only validates that the client exists. * * @param clientId - The client's public identifier * @param clientSecret - The client secret (required for confidential clients) * @returns The validated client or null if invalid */ validateClient(clientId: string, clientSecret?: string): Promise; /** * Validates a redirect URI against the client's registered URIs. * * Per RFC 6749, redirect URIs must match exactly - no wildcards or * pattern matching is allowed. * * @param client - The OAuth client * @param redirectUri - The redirect URI to validate * @returns true if the redirect URI is valid for this client */ validateRedirectUri(client: OAuthClient, redirectUri: string): boolean; /** * Validates that requested scopes are allowed for the client. * * @param client - The OAuth client * @param requestedScopes - Array of requested scope strings * @returns true if all requested scopes are allowed */ validateScopes(client: OAuthClient, requestedScopes: string[]): boolean; /** * Validates that a grant type is allowed for the client. * * @param client - The OAuth client * @param grantType - The grant type to validate * @returns true if the grant type is allowed */ validateGrantType(client: OAuthClient, grantType: string): boolean; /** * Updates an OAuth client. * * Note: client_id and client_secret cannot be modified. */ updateClient(clientId: string, params: UpdateClientParams): Promise; /** * Regenerates the client secret for a confidential client. * * The new secret is returned only once. The old secret is immediately * invalidated. * * @returns The new client secret */ regenerateSecret(clientId: string): Promise<{ clientSecret: string; }>; /** * Deletes an OAuth client and all associated tokens. */ deleteClient(clientId: string): Promise; /** * Validates a redirect URI format. * * Allowed formats: * - https:// URLs (required for production) * - http://localhost, http://127.0.0.1, http://[::1] (development only) * - http://*.test, http://*.localhost, http://*.local (RFC 6761 reserved TLDs for development) * - Custom schemes (myapp://callback) * * Not allowed: * - Fragment identifiers (#) * - Wildcards */ private isValidRedirectUri; } //# sourceMappingURL=oauth.client.service.d.ts.map