import type { ClientStore } from "./clientStore.js"; import type { TokenStore } from "./tokenStore.js"; export interface OAuthClientConfig { clientId: string; clientSecret?: string; tokenEndpointAuthMethod: "client_secret_post" | "client_secret_basic" | "none"; redirectUris: string[]; scopes: string[]; } interface TokenResponse { tokenType: "Bearer"; accessToken: string; expiresIn: number; refreshToken: string; scope: string; } interface AuthenticatedToken { subject: string; clientId: string; scopes: string[]; } export declare class OAuthManager { private readonly clients; private readonly loginUser; private readonly loginPassword; private readonly supabaseUrl; private readonly supabaseAnonKey; private readonly store; private readonly clientStore; private readonly authCache; constructor(store: TokenStore, clientStore?: ClientStore | null); isEnabled(): boolean; hasLoginConfig(): boolean; private hasSupabaseLoginConfig; listClients(): OAuthClientConfig[]; getTokenEndpointAuthMethods(): Array; getClientConfigs(): OAuthClientConfig[]; private findClient; validateAuthorizeRequest(input: { responseType: string; clientId: string; redirectUri: string; scope?: string; state?: string; codeChallenge?: string; codeChallengeMethod?: string; }): Promise<{ client: OAuthClientConfig; scope: string[]; state?: string; }>; verifyLogin(username: string, password: string): Promise; signUpWithEmail(email: string, password: string, redirectTo?: string): Promise<{ ok: true; } | { ok: false; error: string; }>; issueAuthorizationCode(input: { clientId: string; redirectUri: string; scope: string[]; subject: string; codeChallenge?: string; codeChallengeMethod?: "S256" | "plain"; }): Promise; exchangeAuthorizationCode(input: { code: string; clientId: string; clientSecret?: string; redirectUri: string; codeVerifier?: string; }): Promise; refreshAccessToken(input: { refreshToken: string; clientId: string; clientSecret?: string; }): Promise; authenticateAccessToken(token: string): Promise; invalidateAuthCache(token: string): void; /** * Revoke a token per RFC 7009. * * Accepts either an access_token or refresh_token. Uses `tokenTypeHint` * to try the likely type first, then falls back to the other. Always * returns `ok: true` — callers must not reveal whether a token existed. * * For confidential clients, `clientId` + `clientSecret` must match the * registered client. For public clients (PKCE), only `clientId` is needed. * * Returns `{ ok: true }` on success. * Throws if `clientId` is unknown or credentials are invalid. */ revokeToken(input: { token: string; tokenTypeHint?: string; clientId: string; clientSecret?: string; }): Promise; private issueTokens; registerDynamicClient(input: { redirectUris: string[]; clientName?: string; tokenEndpointAuthMethod?: string; grantTypes?: string[]; responseTypes?: string[]; scope?: string; }): Promise<{ clientId: string; redirectUris: string[]; tokenEndpointAuthMethod: string; grantTypes: string[]; responseTypes: string[]; scope: string; }>; } export {}; //# sourceMappingURL=oauth.d.ts.map