import { MJAuthBase } from '../mjexplorer-auth-base.service'; import { StandardUserInfo, StandardAuthToken, StandardAuthError, TokenRefreshResult } from '../auth-types'; import * as i0 from "@angular/core"; /** * Configuration interface for the Cognito provider. * Populated from environment config via the `angularProviderFactory`. */ interface CognitoConfig { userPoolId: string; userPoolClientId: string; region?: string; /** Cognito Hosted UI domain, e.g. 'myapp.auth.us-east-1.amazoncognito.com' */ domain: string; /** OAuth redirect URI. Defaults to window.location.origin */ redirectUri?: string; /** OAuth scopes. Defaults to ['openid', 'profile', 'email'] */ scopes?: string[]; /** When true, skips redirect callback processing (for MCP OAuth callback path) */ skipRedirectCallback?: boolean; } /** * AWS Cognito authentication provider implementation - v3.0.0 * * Implements the abstract methods from MJAuthBase to hide Cognito-specific details. * Uses AWS Amplify v6 (tree-shakeable subpath imports) for authentication. * * Key abstraction: Cognito stores tokens in Amplify's internal storage, accessed * via `fetchAuthSession().tokens?.idToken?.toString()`. Consumers never need to * know this detail. * * ## Cognito Hosted UI Flow * This provider uses the Cognito Hosted UI for login via `signInWithRedirect()`. * The flow is: redirect to Hosted UI -> user authenticates -> redirect back with * authorization code -> Amplify exchanges code for tokens (PKCE). */ export declare class MJCognitoProvider extends MJAuthBase { private cognitoConfig; static readonly PROVIDER_TYPE = "cognito"; readonly type = "cognito"; private _initialized; private _hubListenerCancel; /** * Factory function to provide Angular dependencies required by the Cognito provider. * Returns a config injection token following the Okta provider pattern. */ static angularProviderFactory: (environment: Record) => { provide: string; useValue: CognitoConfig; }[]; constructor(cognitoConfig: CognitoConfig); initialize(): Promise; protected loginInternal(_options?: Record): Promise; protected logoutInternal(): Promise; handleCallback(): Promise; /** * Extract ID token from Cognito via Amplify's fetchAuthSession. * * Cognito stores the JWT in session.tokens.idToken. The .toString() * call extracts the raw JWT string. Consumers never need to know this detail. */ protected extractIdTokenInternal(): Promise; /** * Extract complete token info from Cognito session. * Maps Amplify's token structure to StandardAuthToken. */ protected extractTokenInfoInternal(): Promise; /** * Extract user info from Cognito user attributes. * Maps Cognito's attribute structure to StandardUserInfo. */ protected extractUserInfoInternal(): Promise; /** * Refresh token using Amplify's fetchAuthSession with forceRefresh. * * Amplify v6 handles the entire refresh token exchange internally: * fetchAuthSession({ forceRefresh: true }) uses the stored refresh token * to obtain new ID and access tokens from Cognito. */ protected refreshTokenInternal(): Promise; /** * Classify Cognito/Amplify-specific errors into semantic types. * * Maps Amplify v6 error names and messages to AuthErrorType enum. */ protected classifyErrorInternal(error: unknown): StandardAuthError; /** * Get profile picture URL from Cognito user attributes. * * Cognito can store a `picture` attribute if configured in the user pool. * Returns null if the attribute is not set. */ protected getProfilePictureUrlInternal(): Promise; /** * Handle session expiry by redirecting to Cognito Hosted UI. * * Cognito uses refresh tokens (responseType: 'code'), so silent refresh * usually works. If it fails, we redirect to the Hosted UI for * re-authentication. This will navigate the browser and may never return. */ protected handleSessionExpiryInternal(): Promise; private ensureInitialized; /** * Refresh user info from Cognito and update the reactive state. */ private refreshUserInfo; /** * Map Cognito user attributes to StandardUserInfo. * * Cognito attributes use snake_case keys (email, given_name, family_name, etc.) * and all values are strings (including booleans like email_verified = 'true'). */ private mapCognitoAttributesToStandard; /** * Extract OAuth scopes from an access token's payload. */ private extractScopes; /** * Cancel the Hub event listener if active. */ private cancelHubListener; getRequiredConfig(): string[]; validateConfig(config: Record): boolean; static ɵfac: i0.ɵɵFactoryDeclaration; static ɵprov: i0.ɵɵInjectableDeclaration; } export {}; //# sourceMappingURL=mjexplorer-cognito-provider.service.d.ts.map