import { MJAuthBase } from '../mjexplorer-auth-base.service'; import { OktaAuthOptions } from '@okta/okta-auth-js'; import { StandardUserInfo, StandardAuthToken, StandardAuthError, TokenRefreshResult } from '../auth-types'; import * as i0 from "@angular/core"; /** * Okta authentication provider implementation - v3.0.0 * * Implements the abstract methods from MJAuthBase to hide Okta-specific details. * The key abstraction is that Okta stores the JWT in IDToken.idToken, * but consumers never need to know this detail. */ export declare class MJOktaProvider extends MJAuthBase { private oktaConfig; static readonly PROVIDER_TYPE = "okta"; readonly type = "okta"; private oktaAuth; private isRefreshing; /** * Factory function to provide Angular dependencies required by Okta * Stored as a static property for the factory to access without instantiation */ static angularProviderFactory: (environment: Record) => { provide: string; useValue: { clientId: unknown; domain: unknown; issuer: {}; redirectUri: {}; scopes: {}; }; }[]; constructor(oktaConfig: OktaAuthOptions & { domain?: string; }); initialize(): Promise; protected loginInternal(options?: Record): Promise; protected logoutInternal(): Promise; handleCallback(): Promise; /** * Extract ID token from Okta's storage * * Okta stores the JWT in IDToken.idToken * This is the key abstraction - consumers never need to know about Okta's structure! */ protected extractIdTokenInternal(): Promise; /** * Extract complete token info from Okta * * Maps Okta's token structure to StandardAuthToken */ protected extractTokenInfoInternal(): Promise; /** * Extract user info from Okta claims * * Maps Okta's IDToken structure to StandardUserInfo */ protected extractUserInfoInternal(): Promise; /** * Refresh token using Okta's token renewal * * Uses renewTokens() to get new tokens silently */ protected refreshTokenInternal(): Promise; /** * Classify Okta-specific errors into semantic types * * Maps Okta error patterns to AuthErrorType enum. * Updated for okta-auth-js v7.x error codes. * * Error sources: * - errorCode: From Okta SDK errors (AuthSdkError, AuthApiError) * - error: From OAuth /token endpoint responses (invalid_grant, access_denied, etc.) */ protected classifyErrorInternal(error: unknown): StandardAuthError; /** * Map Okta IDToken to StandardUserInfo */ private mapOktaTokenToStandard; /** * Get profile picture URL from Okta * * Okta may include picture URL in user claims, similar to Auth0. * If available, we can also fetch from Okta's /userinfo endpoint. */ protected getProfilePictureUrlInternal(): Promise; /** * Handle session expiry - no-op for Okta * * Okta uses refresh tokens, so it doesn't need interactive re-authentication * when tokens expire. If refresh fails, the base class will throw an error * and the user must log out/in manually. */ protected handleSessionExpiryInternal(): Promise; getRequiredConfig(): string[]; validateConfig(config: Record): boolean; static ɵfac: i0.ɵɵFactoryDeclaration; static ɵprov: i0.ɵɵInjectableDeclaration; } //# sourceMappingURL=mjexplorer-okta-provider.service.d.ts.map