import { MJAuthBase } from '../mjexplorer-auth-base.service'; import { StandardUserInfo, StandardAuthToken, StandardAuthError, TokenRefreshResult, SessionScope } from '../auth-types'; import * as i0 from "@angular/core"; /** * Client-side auth provider for MemberJunction-issued magic-link sessions. * * Unlike MSAL/Auth0, there is no interactive login and no SDK: the session * token (minted server-side when the user redeemed their invite) arrives in the * URL fragment — `#token=` — when `/magic-link/redeem` redirects the * browser to Explorer. This provider extracts it, stashes it in sessionStorage * (per-tab, so it dies with the tab), decodes the claims for display, and hands * the token to the GraphQL client via `getIdToken()`. The server validates it * through the standard JWKS path. * * Set `AUTH_TYPE: 'magic-link'` in the Explorer environment to use this * provider. There are no refresh tokens — when the session expires the user * must redeem a fresh link. */ export declare class MJMagicLinkProvider extends MJAuthBase { static readonly PROVIDER_TYPE = "magic-link"; readonly type = "magic-link"; private token; private claims; constructor(); /** * True if a magic-link session token is present for this page load — either * arriving in the URL fragment (`#token=`, from the redeem redirect) or * already stashed in sessionStorage from earlier in this tab. * * Used at module-config time (`AuthServicesModule.forRoot`) to auto-select the * magic-link provider even when `AUTH_TYPE` names a different primary IdP, so a * single Explorer deployment can serve both SSO users and magic-link guests. * Falls back cleanly to the primary IdP when no token is present (e.g. after a * guest's session expires or logs out). */ static hasSessionToken(): boolean; initialize(): Promise; protected loginInternal(): Promise; protected logoutInternal(): Promise; handleCallback(): Promise; protected extractIdTokenInternal(): Promise; protected extractTokenInfoInternal(): Promise; protected extractUserInfoInternal(): Promise; protected refreshTokenInternal(): Promise; protected classifyErrorInternal(error: unknown): StandardAuthError; protected getProfilePictureUrlInternal(): Promise; protected handleSessionExpiryInternal(): Promise; /** * Magic-link sessions are locked to the single app the invite scoped to * (`mj_app_id`), so the shell hides app-switching and keeps the user there. */ GetSessionScope(): SessionScope | null; getRequiredConfig(): string[]; validateConfig(): boolean; /** Reads `token` from the URL fragment (`#token=...`). */ private readTokenFromHash; /** Removes the token from the address bar without reloading. */ private stripHash; /** * Decodes a JWT payload (no verification — the server validates via JWKS). * UTF-8-safe: external users routinely have non-ASCII names, which a plain * `atob` would mangle. Also restores base64url padding `atob` needs. */ private decode; private isExpired; private toUserInfo; static ɵfac: i0.ɵɵFactoryDeclaration; static ɵprov: i0.ɵɵInjectableDeclaration; } //# sourceMappingURL=mjexplorer-magic-link-provider.service.d.ts.map