/** * PKCE (Proof Key for Code Exchange) Service * * Implements RFC 7636 for protection against authorization code interception. * PKCE is required for public clients and recommended for all clients. * * @see https://datatracker.ietf.org/doc/html/rfc7636 */ export declare class OAuthPkceService { /** Allowed characters for code verifier (RFC 7636 Section 4.1) */ private static readonly VERIFIER_CHARS; /** Minimum length for code verifier */ private static readonly MIN_VERIFIER_LENGTH; /** Maximum length for code verifier */ private static readonly MAX_VERIFIER_LENGTH; /** * Generates a cryptographically secure code verifier. * * The code verifier is a high-entropy random string that the client * creates and stores. It must be between 43-128 characters using * only unreserved URI characters. * * @param length - Length of verifier (default 64, range 43-128) * @returns A URL-safe code verifier string */ generateCodeVerifier(length?: number): string; /** * Generates a code challenge from a code verifier. * * The code challenge is derived from the code verifier using the * specified transformation method. The challenge is sent in the * authorization request. * * @param verifier - The code verifier string * @param method - Challenge method: 'S256' (recommended) or 'plain' * @returns The code challenge string * * @example * const verifier = pkceService.generateCodeVerifier(); * const challenge = pkceService.generateCodeChallenge(verifier, 'S256'); */ generateCodeChallenge(verifier: string, method: "S256" | "plain"): string; /** * Validates a code verifier against a stored code challenge. * * This method is called during token exchange to verify that the * client presenting the authorization code is the same client that * initiated the authorization request. * * @param verifier - The code verifier from the token request * @param challenge - The stored code challenge from the authorization request * @param method - The challenge method used ('S256' or 'plain') * @returns true if the verifier matches the challenge * * @example * const isValid = pkceService.validateCodeChallenge( * req.body.code_verifier, * storedCode.codeChallenge, * storedCode.codeChallengeMethod * ); */ validateCodeChallenge(verifier: string, challenge: string, method: "S256" | "plain"): boolean; /** * Validates that a code verifier matches RFC 7636 requirements. * * @param verifier - The code verifier to validate * @returns true if the verifier is valid */ isValidVerifier(verifier: string): boolean; /** * Validates that a challenge method is supported. * * @param method - The challenge method to validate * @returns true if the method is supported */ isValidChallengeMethod(method: string): method is "S256" | "plain"; } //# sourceMappingURL=oauth.pkce.service.d.ts.map