import { ConfigService } from "@nestjs/config"; import { BaseConfigInterface } from "../../../config/interfaces/base.config.interface"; import { OAuthRepository } from "../repositories/oauth.repository"; export interface GenerateAccessTokenParams { clientId: string; userId?: string; companyId?: string; scope: string; grantType: string; lifetimeSeconds?: number; } export interface GenerateRefreshTokenParams { clientId: string; userId: string; companyId?: string; scope: string; accessTokenId: string; lifetimeSeconds?: number; } export interface AccessTokenValidationResult { tokenId: string; clientId: string; userId: string | null; companyId: string | null; scope: string; grantType: string; expiresAt: Date; } export interface RefreshTokenValidationResult { tokenId: string; clientId: string; userId: string; companyId: string | null; scope: string; rotationCounter: number; expiresAt: Date; } /** * OAuth Token Service * * Handles generation, validation, and revocation of OAuth tokens. * Uses opaque tokens with SHA256 hashes stored in the database. */ export declare class OAuthTokenService { private readonly oauthRepository; private readonly configService; /** Access token length in bytes (32 bytes = 256 bits) */ private static readonly ACCESS_TOKEN_BYTES; /** Refresh token length in bytes (48 bytes = 384 bits) */ private static readonly REFRESH_TOKEN_BYTES; constructor(oauthRepository: OAuthRepository, configService: ConfigService); /** * Generates an opaque access token. * * The token is a cryptographically random string. Only its SHA256 hash * is stored in the database. * * @returns The token string and expiration info */ generateAccessToken(params: GenerateAccessTokenParams): Promise<{ token: string; expiresIn: number; tokenId: string; }>; /** * Generates an opaque refresh token. * * Refresh tokens are longer than access tokens and include a rotation * counter that is incremented each time the token is used. * * @returns The token string */ generateRefreshToken(params: GenerateRefreshTokenParams): Promise<{ token: string; tokenId: string; }>; /** * Validates an access token. * * Checks that the token: * - Exists (by hash lookup) * - Has not expired * - Has not been revoked * * @param token - The raw access token string * @returns Validation result or null if invalid */ validateAccessToken(token: string): Promise; /** * Validates a refresh token. * * Checks that the token: * - Exists (by hash lookup) * - Has not expired * - Has not been revoked * * @param token - The raw refresh token string * @returns Validation result or null if invalid */ validateRefreshToken(token: string): Promise; /** * Revokes an access token. * * @param token - The raw access token string */ revokeAccessToken(token: string): Promise; /** * Revokes a refresh token. * * @param token - The raw refresh token string */ revokeRefreshToken(token: string): Promise; /** * Revokes all tokens for a user-client combination. * * Used when a user revokes access for an application or * when implementing logout across all sessions. */ revokeAllUserTokens(userId: string, clientId: string): Promise; /** * Gets token metadata for introspection (RFC 7662). * * @param token - The raw token string * @param tokenTypeHint - Optional hint about token type * @returns Token metadata or { active: false } if invalid */ introspectToken(token: string, tokenTypeHint?: "access_token" | "refresh_token"): Promise<{ active: boolean; scope?: string; client_id?: string; username?: string; token_type?: string; exp?: number; iat?: number; sub?: string; aud?: string; }>; /** * Cleans up expired tokens from the database. * * Should be called periodically (e.g., daily) to remove expired tokens. */ cleanupExpiredTokens(): Promise; } //# sourceMappingURL=oauth.token.service.d.ts.map