/** * @typedef {Object} IdTokenSignerConfig * @property {import('node:crypto').KeyObject | string | Uint8Array} signingKey private (asymmetric) signing key * @property {string} alg JWS alg, e.g. `'RS256'` / `'ES256'` / `'EdDSA'` (never `none`/HS*) * @property {string} [kid] `kid` header so a client picks the right JWKS key * @property {string | number} [expiresIn] id_token lifetime (default `'10m'`) */ /** * @param {IdTokenSignerConfig} config * @returns {{ alg: string, sign: (input: IdTokenInput) => Promise }} * * @typedef {Object} IdTokenInput * @property {string} subject the authenticated resource owner → `sub` * @property {string} clientId → `aud` * @property {string} issuer the AS issuer identifier → `iss` * @property {string} [nonce] the authorization-request `nonce` (replay guard) * @property {number} [authTime] unix seconds of the authentication event → `auth_time` * @property {string} [accessToken] present → bind it via `at_hash` */ export function createIdTokenSigner(config: IdTokenSignerConfig): { alg: string; sign: (input: IdTokenInput) => Promise; }; export type IdTokenSignerConfig = { /** * private (asymmetric) signing key */ signingKey: any | string | Uint8Array; /** * JWS alg, e.g. `'RS256'` / `'ES256'` / `'EdDSA'` (never `none`/HS*) */ alg: string; /** * `kid` header so a client picks the right JWKS key */ kid?: string | undefined; /** * id_token lifetime (default `'10m'`) */ expiresIn?: string | number | undefined; }; export type IdTokenInput = { /** * the authenticated resource owner → `sub` */ subject: string; /** * → `aud` */ clientId: string; /** * the AS issuer identifier → `iss` */ issuer: string; /** * the authorization-request `nonce` (replay guard) */ nonce?: string | undefined; /** * unix seconds of the authentication event → `auth_time` */ authTime?: number | undefined; /** * present → bind it via `at_hash` */ accessToken?: string | undefined; };