import { OnDestroy } from '@angular/core'; import { MJAuthBase } from '../mjexplorer-auth-base.service'; import { MsalBroadcastService, MsalService, MsalGuard } from '@azure/msal-angular'; import { PublicClientApplication, InteractionType } from '@azure/msal-browser'; import { StandardUserInfo, StandardAuthToken, StandardAuthError, TokenRefreshResult } from '../auth-types'; import * as i0 from "@angular/core"; /** * MSAL (Microsoft Authentication Library) provider implementation - v3.0.0 * * Implements the abstract methods from MJAuthBase to hide MSAL-specific details. * The key abstraction is that MSAL stores the JWT in AuthenticationResult.idToken, * but consumers never need to know this detail. */ export declare class MJMSALProvider extends MJAuthBase implements OnDestroy { auth: MsalService; private msalBroadcastService; static readonly PROVIDER_TYPE = "msal"; readonly type = "msal"; private readonly _destroying$; private readonly _initializationCompleted$; private _initPromise; /** * Factory function to provide Angular dependencies required by MSAL * Stored as a static property for the factory to access without instantiation */ static angularProviderFactory: (environment: Record) => (typeof MsalService | typeof MsalGuard | typeof MsalBroadcastService | { provide: import("@angular/core").InjectionToken; useValue: PublicClientApplication; } | { provide: import("@angular/core").InjectionToken; useValue: { interactionType: InteractionType; authRequest: { scopes: string[]; }; protectedResourceMap?: undefined; }; } | { provide: import("@angular/core").InjectionToken; useValue: { interactionType: InteractionType; protectedResourceMap: Map; authRequest?: undefined; }; })[]; constructor(auth: MsalService, msalBroadcastService: MsalBroadcastService); initialize(): Promise; private _performInitialization; protected loginInternal(options?: Record): Promise; protected logoutInternal(): Promise; handleCallback(): Promise; /** * Extract ID token from MSAL's storage * * MSAL stores the JWT in AuthenticationResult.idToken * This is the key abstraction - consumers never need to know about MSAL's structure! */ protected extractIdTokenInternal(): Promise; /** * Extract complete token info from MSAL * * Maps MSAL's AuthenticationResult to StandardAuthToken */ protected extractTokenInfoInternal(): Promise; /** * Extract user info from MSAL account * * Maps MSAL's AccountInfo structure to StandardUserInfo */ protected extractUserInfoInternal(): Promise; /** * Refresh token using MSAL's silent token acquisition * * MSAL 5.x Best Practices: * - Pass account parameter for reliable silent acquisition * - Use forceRefresh: true to bypass cache and get fresh tokens from Azure AD * - Handle MSAL 5.x specific error codes (timed_out, no_tokens_found, etc.) * * IMPORTANT: This method is called when the server has already rejected the current * token as expired (JWT_EXPIRED). Using CacheLookupPolicy.Default here can return a * cached ID token that is still expired (e.g. when the access token has a longer * lifetime than the ID token). forceRefresh: true ensures a network round-trip to * Azure AD so both the access token and ID token are genuinely refreshed. */ protected refreshTokenInternal(): Promise; /** * Classify MSAL-specific errors into semantic types * * Maps MSAL error classes to AuthErrorType enum. * Updated for MSAL 5.x error codes. */ protected classifyErrorInternal(error: unknown): StandardAuthError; private ensureInitialized; /** * Check if a JWT token is still valid with an optional buffer period. * Decodes the payload to read the `exp` claim without cryptographic verification * (expiry is a timing check, not an authenticity check). * * @param token - The JWT string to check * @param bufferSeconds - Number of seconds before actual expiry to consider the token invalid (default: 0) * @returns true if the token's exp claim is beyond (now + buffer), false otherwise */ private isTokenValid; /** * Map MSAL AccountInfo to StandardUserInfo */ private mapMSALAccountToStandard; /** * Get profile picture URL from Microsoft Graph API * * MSAL requires fetching the photo from Microsoft Graph. * This is the key advantage of encapsulation - consumers don't need * to know about Graph API, they just call getProfilePictureUrl()! */ protected getProfilePictureUrlInternal(): Promise; /** * Handle session expiry by redirecting to Microsoft login * * This method is called by the base class when silent token refresh fails * with INTERACTION_REQUIRED error. It redirects to Microsoft login and never returns. * After authentication, the app will reload and re-initialize with a fresh token. */ protected handleSessionExpiryInternal(): Promise; getRequiredConfig(): string[]; validateConfig(_config: Record): boolean; ngOnDestroy(): void; static ɵfac: i0.ɵɵFactoryDeclaration; static ɵprov: i0.ɵɵInjectableDeclaration; } //# sourceMappingURL=mjexplorer-msal-provider.service.d.ts.map