import { Algorithm } from "jsonwebtoken"; import { CredentialsConfig, PKCEConfig, AuthRouteConfig, TokenAuthStrategyConfig, PersistenceConfig, ContextOperationConfig } from "../../types"; import { ExternalIdentityConfig } from "./external-identity.types"; export interface OAuth2Endpoints { authorizationUrl: string; tokenUrl: string; userInfoUrl?: string; introspectionUrl?: string; revocationUrl?: string; logoutUrl?: string; } export interface OAuth2StateConfig { persistence?: PersistenceConfig; context?: ContextOperationConfig; generateState?: () => string | Promise; validateState?: (storedState: TContext, returnedState: string) => boolean | Promise; } export interface OAuth2NonceConfig { persistence?: PersistenceConfig; context?: ContextOperationConfig; generateNonce?: () => string | Promise; validateNonce?: (storedNonce: string | null, returnedNonce: string) => boolean | Promise; } export type JwksConfig = { jwksUri: string; issuer: string; algorithms?: Algorithm[]; audience?: string; }; export interface OAuth2StrategyConfig extends TokenAuthStrategyConfig { autoLogoutOnRefreshFailure?: boolean; clientId: string; clientSecret: string; redirectUri: string; scope?: string | string[]; audience?: string; responseType?: "code" | "token" | "id_token" | string; grantType: "authorization_code" | "client_credentials" | "password" | "refresh_token" | string; endpoints: OAuth2Endpoints; credentials?: CredentialsConfig; pkce?: PKCEConfig; routes: { login: AuthRouteConfig; callback: AuthRouteConfig; logout?: AuthRouteConfig; refresh?: AuthRouteConfig; revoke?: AuthRouteConfig; [key: string]: AuthRouteConfig; }; state?: OAuth2StateConfig; nonce?: OAuth2NonceConfig; jwks?: JwksConfig; } export interface OAuth2ProviderConfig extends Omit, "endpoints" | "grantType" | "routes"> { grantType?: "authorization_code"; endpoints?: Partial; externalIdentity?: ExternalIdentityConfig & { issueAppTokens?: boolean; }; routes?: OAuth2StrategyConfig["routes"]; }