Files
ThreadNet-Web/src/utils/oidc/authorize.ts
T

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

112 lines
4.0 KiB
TypeScript
Raw Normal View History

/*
2024-09-09 14:57:16 +01:00
Copyright 2024 New Vector Ltd.
Copyright 2023 The Matrix.org Foundation C.I.C.
SPDX-License-Identifier: AGPL-3.0-only OR GPL-3.0-only OR LicenseRef-Element-Commercial
2024-09-09 14:57:16 +01:00
Please see LICENSE files in the repository root for full details.
*/
import { completeAuthorizationCodeGrant, generateOidcAuthorizationUrl } from "matrix-js-sdk/src/oidc/authorize";
2025-02-05 13:25:06 +00:00
import { type QueryDict } from "matrix-js-sdk/src/utils";
import { type OidcClientConfig } from "matrix-js-sdk/src/matrix";
2025-01-21 13:54:57 +00:00
import { secureRandomString } from "matrix-js-sdk/src/randomstring";
2025-02-05 13:25:06 +00:00
import { type IdTokenClaims } from "oidc-client-ts";
2023-10-19 15:46:37 +13:00
import { OidcClientError } from "./error";
import PlatformPeg from "../../PlatformPeg";
2023-10-19 15:46:37 +13:00
/**
* Start OIDC authorization code flow
* Generates auth params, stores them in session storage and
* Navigates to configured authorization endpoint
* @param delegatedAuthConfig from discovery
* @param clientId this client's id as registered with configured issuer
* @param homeserverUrl target homeserver
* @param identityServerUrl OPTIONAL target identity server
* @returns Promise that resolves after we have navigated to auth endpoint
*/
export const startOidcLogin = async (
delegatedAuthConfig: OidcClientConfig,
clientId: string,
homeserverUrl: string,
identityServerUrl?: string,
2023-10-12 10:44:46 +13:00
isRegistration?: boolean,
): Promise<void> => {
const redirectUri = PlatformPeg.get()!.getOidcCallbackUrl().href;
2025-01-21 13:54:57 +00:00
const nonce = secureRandomString(10);
2023-10-12 10:44:46 +13:00
const prompt = isRegistration ? "create" : undefined;
const authorizationUrl = await generateOidcAuthorizationUrl({
metadata: delegatedAuthConfig,
redirectUri,
clientId,
homeserverUrl,
identityServerUrl,
nonce,
2023-10-12 10:44:46 +13:00
prompt,
urlState: PlatformPeg.get()?.getOidcClientState(),
});
window.location.href = authorizationUrl;
};
2023-07-11 16:09:18 +12:00
/**
* Gets `code` and `state` query params
*
* @param queryParams
* @returns code and state
* @throws when code and state are not valid strings
*/
const getCodeAndStateFromQueryParams = (queryParams: QueryDict): { code: string; state: string } => {
const code = queryParams["code"];
const state = queryParams["state"];
if (!code || typeof code !== "string" || !state || typeof state !== "string") {
2023-10-19 15:46:37 +13:00
throw new Error(OidcClientError.InvalidQueryParameters);
2023-07-11 16:09:18 +12:00
}
return { code, state };
};
2023-09-19 12:06:19 +12:00
type CompleteOidcLoginResponse = {
// url of the homeserver selected during login
homeserverUrl: string;
// identity server url as discovered during login
identityServerUrl?: string;
// accessToken gained from OIDC token issuer
accessToken: string;
// refreshToken gained from OIDC token issuer, when falsy token cannot be refreshed
refreshToken?: string;
// idToken gained from OIDC token issuer
idToken: string;
2023-09-19 12:06:19 +12:00
// this client's id as registered with the OIDC issuer
clientId: string;
// issuer used during authentication
issuer: string;
2023-10-04 17:06:04 +13:00
// claims of the given access token; used during token refresh to validate new tokens
idTokenClaims: IdTokenClaims;
2023-09-19 12:06:19 +12:00
};
2023-07-11 16:09:18 +12:00
/**
* Attempt to complete authorization code flow to get an access token
* @param queryParams the query-parameters extracted from the real query-string of the starting URI.
2023-09-19 12:06:19 +12:00
* @returns Promise that resolves with a CompleteOidcLoginResponse when login was successful
2023-07-11 16:09:18 +12:00
* @throws When we failed to get a valid access token
*/
2023-09-19 12:06:19 +12:00
export const completeOidcLogin = async (queryParams: QueryDict): Promise<CompleteOidcLoginResponse> => {
2023-07-11 16:09:18 +12:00
const { code, state } = getCodeAndStateFromQueryParams(queryParams);
2023-10-04 17:06:04 +13:00
const { homeserverUrl, tokenResponse, idTokenClaims, identityServerUrl, oidcClientSettings } =
await completeAuthorizationCodeGrant(code, state);
2023-07-11 16:09:18 +12:00
return {
2023-09-19 12:06:19 +12:00
homeserverUrl,
identityServerUrl,
2023-07-11 16:09:18 +12:00
accessToken: tokenResponse.access_token,
2023-09-19 12:06:19 +12:00
refreshToken: tokenResponse.refresh_token,
idToken: tokenResponse.id_token,
clientId: oidcClientSettings.clientId,
issuer: oidcClientSettings.issuer,
2023-10-04 17:06:04 +13:00
idTokenClaims,
2023-07-11 16:09:18 +12:00
};
};