import { ConfigService } from "@nestjs/config"; import { BaseConfigInterface } from "../../../config/interfaces/base.config.interface"; import { OAuthRepository } from "../repositories/oauth.repository"; import { OAuthClientService } from "./oauth.client.service"; import { OAuthPkceService } from "./oauth.pkce.service"; import { OAuthTokenService } from "./oauth.token.service"; export interface AuthorizeParams { responseType: string; clientId: string; redirectUri: string; scope?: string; state?: string; codeChallenge?: string; codeChallengeMethod?: string; userId: string; } export interface TokenCodeParams { grantType: "authorization_code"; code: string; redirectUri: string; clientId: string; clientSecret?: string; codeVerifier?: string; } export interface ClientCredentialsParams { grantType: "client_credentials"; clientId: string; clientSecret: string; scope?: string; } export interface RefreshTokenParams { grantType: "refresh_token"; refreshToken: string; clientId: string; clientSecret?: string; scope?: string; } export interface TokenResponse { access_token: string; token_type: "Bearer"; expires_in: number; refresh_token?: string; scope?: string; } export interface RevokeParams { token: string; tokenTypeHint?: "access_token" | "refresh_token"; clientId: string; clientSecret?: string; } export interface IntrospectParams { token: string; tokenTypeHint?: "access_token" | "refresh_token"; clientId: string; clientSecret: string; } export interface ConsentInfoParams { clientId: string; redirectUri: string; scope?: string; } export interface ConsentInfoResponse { client: { id: string; type: "oauth-clients"; attributes: { name: string; description?: string; }; }; scopes: Array<{ scope: string; name: string; description: string; }>; } export interface ConsentApproveParams { clientId: string; redirectUri: string; scope?: string; state?: string; codeChallenge?: string; codeChallengeMethod?: string; userId: string; } export interface ConsentDenyParams { redirectUri: string; state?: string; } /** * Main OAuth Service * * Orchestrates OAuth2 flows including authorization code, client credentials, * and refresh token grants. Implements RFC 6749, RFC 7009, and RFC 7662. */ export declare class OAuthService { private readonly oauthRepository; private readonly clientService; private readonly tokenService; private readonly pkceService; private readonly configService; constructor(oauthRepository: OAuthRepository, clientService: OAuthClientService, tokenService: OAuthTokenService, pkceService: OAuthPkceService, configService: ConfigService); /** * Initiates the authorization code flow. * * Validates the request, generates an authorization code, and returns * the code to be included in the redirect response. * * @returns Authorization code and state */ initiateAuthorization(params: AuthorizeParams): Promise<{ code: string; state?: string; }>; /** * Exchanges an authorization code for tokens. * * Validates the code, PKCE verifier (if applicable), and issues * access and refresh tokens. */ exchangeAuthorizationCode(params: TokenCodeParams): Promise; /** * Processes a client credentials grant. * * Issues an access token directly to the client (no user involvement). * Only available to confidential clients. */ clientCredentialsGrant(params: ClientCredentialsParams): Promise; /** * Processes a refresh token grant. * * Validates the refresh token and issues new access/refresh tokens. * Supports token rotation if configured. */ refreshTokenGrant(params: RefreshTokenParams): Promise; /** * Revokes a token (RFC 7009). * * Always returns success, even if the token was invalid or already revoked. * This prevents token fishing attacks. */ revokeToken(params: RevokeParams): Promise; /** * Introspects a token (RFC 7662). * * Returns token metadata for valid tokens, or { active: false } for * invalid, expired, or revoked tokens. */ introspectToken(params: IntrospectParams): Promise<{ active: boolean; scope?: string; client_id?: string; username?: string; token_type?: string; exp?: number; iat?: number; sub?: string; aud?: string; iss?: string; }>; /** * Gets client information for the consent screen. * * Validates the client and redirect URI, then returns the client info * and scope descriptions for display on the consent screen. */ getConsentInfo(params: ConsentInfoParams): Promise; /** * Approves the authorization request and issues an authorization code. * * Called after the user has consented to the authorization. * Returns a redirect URL with the authorization code. */ approveAuthorization(params: ConsentApproveParams): Promise<{ redirectUrl: string; }>; /** * Denies the authorization request. * * Returns a redirect URL with an access_denied error. */ denyAuthorization(params: ConsentDenyParams): Promise<{ redirectUrl: string; }>; } //# sourceMappingURL=oauth.service.d.ts.map