import { OnDestroy } from '@angular/core'; import { MJAuthBase } from '../mjexplorer-auth-base.service'; import { StandardUserInfo, StandardAuthToken, StandardAuthError, TokenRefreshResult } from '../auth-types'; import * as i0 from "@angular/core"; /** * Resolved configuration for the WorkOS AuthKit client. * Provided via the `'workosConfig'` injection token (see `angularProviderFactory`). */ export interface WorkOSAuthConfig { /** WorkOS AuthKit client ID (e.g. `client_01H...`). Required. */ clientId: string; /** OAuth redirect URI registered in the WorkOS dashboard. Defaults to `window.location.origin`. */ redirectUri?: string; /** Override the WorkOS API hostname (rarely needed; for proxies / custom domains). */ apiHostname?: string; /** Enables AuthKit dev mode (localStorage session, no third-party cookies). */ devMode?: boolean; } /** * WorkOS (AuthKit) authentication provider — browser side. * * Wraps the vanilla-JS `@workos-inc/authkit-js` SDK behind {@link MJAuthBase} so the rest of * MemberJunction never sees WorkOS-specific details. AuthKit issues a JWT **access token** * (returned by `getAccessToken()`) that MJ sends to the GraphQL API as a Bearer token; the * server validates it via `@memberjunction/auth-providers`' `WorkOSProvider`. * * Unlike the Auth0/MSAL/Okta providers, AuthKit is not an Angular library — there is no module * to import. This provider creates the client itself in {@link initialize} using config supplied * through the `'workosConfig'` injection token. * * > **Email note:** `getUser()` always returns the user's email for display here, but the * > **access token** only carries `email` if a WorkOS JWT Template adds it. MJ resolves users by * > email server-side, so configuring that template is required. See `WORKOS.md` in * > `@memberjunction/auth-providers`. */ export declare class MJWorkOSProvider extends MJAuthBase implements OnDestroy { private workosConfig; static readonly PROVIDER_TYPE = "workos"; readonly type = "workos"; private client; private initPromise; /** * Factory function to provide the Angular dependencies required by WorkOS. * Stored as a static property so the factory can read it without instantiation. */ static angularProviderFactory: (environment: Record) => { provide: string; useValue: { clientId: string; redirectUri: string; apiHostname: string | undefined; devMode: boolean; }; }[]; constructor(workosConfig: WorkOSAuthConfig); /** * Initialize the AuthKit client. `createClient()` constructs the client AND processes any * pending OAuth redirect (it reads the `code` from the URL and exchanges it), so once it * resolves the session — if any — is already established and `getUser()` is populated. * * Idempotent and concurrency-safe: parallel callers share a single in-flight promise. */ initialize(): Promise; private createAndSyncClient; /** * Pushes the current AuthKit session into MJ's reactive streams. */ private syncSessionState; protected loginInternal(options?: Record): Promise; protected logoutInternal(): Promise; handleCallback(): Promise; ngOnDestroy(): void; /** * Extract the access token (a JWT) from AuthKit. `getAccessToken()` returns a valid token, * silently refreshing first if the current one is near expiry. Throws when there is no * session — we translate that to `null` so callers can treat it as "not authenticated". */ protected extractIdTokenInternal(): Promise; /** * Extract complete token info. The expiry comes from the JWT's `exp` claim, decoded with the * SDK's `getClaims()` helper. */ protected extractTokenInfoInternal(): Promise; /** * Extract user info from AuthKit's in-memory user (always populated when authenticated, * regardless of which claims the access token carries). */ protected extractUserInfoInternal(): Promise; /** * Force a token refresh through AuthKit's refresh-token rotation. */ protected refreshTokenInternal(): Promise; /** * Map WorkOS / AuthKit SDK errors to semantic `AuthErrorType` values. */ protected classifyErrorInternal(error: unknown): StandardAuthError; /** * WorkOS includes the profile picture URL on the user object — no extra API call needed. */ protected getProfilePictureUrlInternal(): Promise; /** * No-op. WorkOS uses rotating refresh tokens, so it doesn't need interactive * re-authentication when an access token expires; if refresh fails the base class surfaces * the error and the user re-logs in manually. */ protected handleSessionExpiryInternal(): Promise; private ensureInitialized; /** * Map a WorkOS `User` to the framework-standard `StandardUserInfo`. * WorkOS exposes `firstName`/`lastName` as `string | null`; we normalize null → undefined. */ private mapWorkOSUserToStandard; getRequiredConfig(): string[]; validateConfig(config: Record): boolean; static ɵfac: i0.ɵɵFactoryDeclaration; static ɵprov: i0.ɵɵInjectableDeclaration; } //# sourceMappingURL=mjexplorer-workos-provider.service.d.ts.map