mirror of
https://gitlab.com/openstapps/openstapps.git
synced 2026-10-09 11:12:48 +00:00
WIP
This commit is contained in:
@@ -13,23 +13,23 @@ const config = {
|
|||||||
default: {
|
default: {
|
||||||
client: {
|
client: {
|
||||||
clientId: '1cac3f99-33fa-4234-8438-979f07e0cdab',
|
clientId: '1cac3f99-33fa-4234-8438-979f07e0cdab',
|
||||||
scopes: '',
|
scopes: 'openid profile email offline_access',
|
||||||
url: 'https://cas.rz.uni-frankfurt.de/cas/oauth2.0',
|
url: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc',
|
||||||
},
|
},
|
||||||
endpoints: {
|
endpoints: {
|
||||||
authorization: 'https://cas.rz.uni-frankfurt.de/cas/oauth2.0/authorize',
|
authorization: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc/authorize',
|
||||||
endSession: 'https://cas.rz.uni-frankfurt.de/cas/logout',
|
endSession: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc/end-session',
|
||||||
mapping: {
|
mapping: {
|
||||||
id: '$.id',
|
id: '$.preferred_username',
|
||||||
email: '$.attributes.mailPrimaryAddress',
|
email: '$.mailPrimaryAddress',
|
||||||
familyName: '$.attributes.sn',
|
familyName: '$.family_name',
|
||||||
givenName: '$.attributes.givenName',
|
givenName: '$.given_name',
|
||||||
name: '$.attributes.givenName',
|
name: '$.name',
|
||||||
role: '$.attributes.eduPersonPrimaryAffiliation',
|
role: '$.eduPersonPrimaryAffiliation',
|
||||||
studentId: '$.attributes.employeeNumber',
|
studentId: '$.employeeNumber',
|
||||||
},
|
},
|
||||||
token: 'https://cas.rz.uni-frankfurt.de/cas/oauth2.0/accessToken',
|
token: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc/token',
|
||||||
userinfo: 'https://cas.rz.uni-frankfurt.de/cas/oauth2.0/profile',
|
userinfo: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc/userinfo',
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -36,7 +36,7 @@
|
|||||||
"format:fix": "prettier --write . --ignore-path ../../.gitignore",
|
"format:fix": "prettier --write . --ignore-path ../../.gitignore",
|
||||||
"lint": "tsc --noEmit && eslint --ext .ts src/",
|
"lint": "tsc --noEmit && eslint --ext .ts src/",
|
||||||
"lint:fix": "eslint --fix --ext .ts src/",
|
"lint:fix": "eslint --fix --ext .ts src/",
|
||||||
"start": "cross-env NODE_CONFIG_ENV=elasticsearch ALLOW_NO_TRANSPORT=true node app.js",
|
"start": "cross-env NODE_CONFIG_ENV=elasticsearch ALLOW_NO_TRANSPORT=true NODE_APP_INSTANCE=\"f-u\" node app.js",
|
||||||
"start:debug": "cross-env STAPPS_LOG_LEVEL=31 NODE_CONFIG_ENV=elasticsearch ALLOW_NO_TRANSPORT=true node app.js",
|
"start:debug": "cross-env STAPPS_LOG_LEVEL=31 NODE_CONFIG_ENV=elasticsearch ALLOW_NO_TRANSPORT=true node app.js",
|
||||||
"test": "pnpm run test:unit",
|
"test": "pnpm run test:unit",
|
||||||
"test:integration": "sh integration-test.sh",
|
"test:integration": "sh integration-test.sh",
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import {CapacitorConfig} from '@capacitor/cli';
|
import {CapacitorConfig} from '@capacitor/cli';
|
||||||
|
|
||||||
const config: CapacitorConfig = {
|
const config: CapacitorConfig = {
|
||||||
appId: 'de.anyschool.app',
|
appId: 'de.unifrankfurt.app',
|
||||||
appName: 'StApps',
|
appName: 'StApps',
|
||||||
webDir: 'www/browser',
|
webDir: 'www/browser',
|
||||||
cordova: {
|
cordova: {
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ def capacitor_pods
|
|||||||
pod 'CapacitorShare', :path => '../../../../node_modules/.pnpm/@capacitor+share@8.0.1_@capacitor+core@8.2.0/node_modules/@capacitor/share'
|
pod 'CapacitorShare', :path => '../../../../node_modules/.pnpm/@capacitor+share@8.0.1_@capacitor+core@8.2.0/node_modules/@capacitor/share'
|
||||||
pod 'CapacitorSplashScreen', :path => '../../../../node_modules/.pnpm/@capacitor+splash-screen@8.0.1_@capacitor+core@8.2.0/node_modules/@capacitor/splash-screen'
|
pod 'CapacitorSplashScreen', :path => '../../../../node_modules/.pnpm/@capacitor+splash-screen@8.0.1_@capacitor+core@8.2.0/node_modules/@capacitor/splash-screen'
|
||||||
pod 'TransistorsoftCapacitorBackgroundFetch', :path => '../../../../node_modules/.pnpm/@transistorsoft+capacitor-background-fetch@8.0.0_@capacitor+core@8.2.0/node_modules/@transistorsoft/capacitor-background-fetch'
|
pod 'TransistorsoftCapacitorBackgroundFetch', :path => '../../../../node_modules/.pnpm/@transistorsoft+capacitor-background-fetch@8.0.0_@capacitor+core@8.2.0/node_modules/@transistorsoft/capacitor-background-fetch'
|
||||||
pod 'CapacitorSecureStoragePlugin', :path => '../../../../node_modules/.pnpm/capacitor-secure-storage-plugin@0.12.0_@capacitor+core@8.2.0/node_modules/capacitor-secure-storage-plugin'
|
pod 'CapacitorSecureStoragePlugin', :path => '../../../../node_modules/.pnpm/capacitor-secure-storage-plugin@0.13.0_@capacitor+core@8.2.0/node_modules/capacitor-secure-storage-plugin'
|
||||||
pod 'CordovaPlugins', :path => '../capacitor-cordova-ios-plugins'
|
pod 'CordovaPlugins', :path => '../capacitor-cordova-ios-plugins'
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
@@ -41,7 +41,7 @@
|
|||||||
"resources:ios": "capacitor-assets generate --ios --iconBackgroundColor $(grep -oE \"^@include ion-color\\(primary, #[a-fA-F0-9]{3,6}\" src/theme/colors.scss | grep -oE \"#[a-fA-F0-9]{3,6}\") --splashBackgroundColor $(grep -oE \"^@include ion-color\\(primary, #[a-fA-F0-9]{3,6}\" src/theme/colors.scss | grep -oE \"#[a-fA-F0-9]{3,6}\")",
|
"resources:ios": "capacitor-assets generate --ios --iconBackgroundColor $(grep -oE \"^@include ion-color\\(primary, #[a-fA-F0-9]{3,6}\" src/theme/colors.scss | grep -oE \"#[a-fA-F0-9]{3,6}\") --splashBackgroundColor $(grep -oE \"^@include ion-color\\(primary, #[a-fA-F0-9]{3,6}\" src/theme/colors.scss | grep -oE \"#[a-fA-F0-9]{3,6}\")",
|
||||||
"run:android": "ionic capacitor run android --livereload --external",
|
"run:android": "ionic capacitor run android --livereload --external",
|
||||||
"start": "ionic serve",
|
"start": "ionic serve",
|
||||||
"start:external": "ionic serve --external",
|
"start:external": "ionic serve --external --ssl=true",
|
||||||
"start:prod": "ionic serve --prod",
|
"start:prod": "ionic serve --prod",
|
||||||
"start:virtual-host": "ionic serve --public-host=mobile.app.uni-frankfurt.de --ssl=true --open=false",
|
"start:virtual-host": "ionic serve --public-host=mobile.app.uni-frankfurt.de --ssl=true --open=false",
|
||||||
"test": "ng test --code-coverage",
|
"test": "ng test --code-coverage",
|
||||||
@@ -81,7 +81,7 @@
|
|||||||
"@maplibre/ngx-maplibre-gl": "22.1.0",
|
"@maplibre/ngx-maplibre-gl": "22.1.0",
|
||||||
"@ngx-translate/core": "15.0.0",
|
"@ngx-translate/core": "15.0.0",
|
||||||
"@ngx-translate/http-loader": "8.0.0",
|
"@ngx-translate/http-loader": "8.0.0",
|
||||||
"@openid/appauth": "1.3.2",
|
"@openid/appauth": "1.4.0",
|
||||||
"@openstapps/api": "workspace:*",
|
"@openstapps/api": "workspace:*",
|
||||||
"@openstapps/collection-utils": "workspace:*",
|
"@openstapps/collection-utils": "workspace:*",
|
||||||
"@openstapps/core": "workspace:*",
|
"@openstapps/core": "workspace:*",
|
||||||
@@ -93,8 +93,7 @@
|
|||||||
"deepmerge": "4.3.1",
|
"deepmerge": "4.3.1",
|
||||||
"form-data": "4.0.6",
|
"form-data": "4.0.6",
|
||||||
"geojson": "0.5.0",
|
"geojson": "0.5.0",
|
||||||
"ionic-appauth": "2.1.0",
|
"ionicons": "8.0.13",
|
||||||
"ionicons": "8.1.0",
|
|
||||||
"jsonpath-plus": "10.3.0",
|
"jsonpath-plus": "10.3.0",
|
||||||
"maplibre-gl": "6.4.1",
|
"maplibre-gl": "6.4.1",
|
||||||
"material-symbols": "0.17.1",
|
"material-symbols": "0.17.1",
|
||||||
|
|||||||
@@ -18,13 +18,14 @@ import {App, URLOpenListenerEvent} from '@capacitor/app';
|
|||||||
import {Platform, ToastController} from '@ionic/angular/standalone';
|
import {Platform, ToastController} from '@ionic/angular/standalone';
|
||||||
import {SettingsProvider} from './modules/settings/settings.provider';
|
import {SettingsProvider} from './modules/settings/settings.provider';
|
||||||
import {InAppReviewProvider} from './modules/settings/in-app-review/in-app-review.provider';
|
import {InAppReviewProvider} from './modules/settings/in-app-review/in-app-review.provider';
|
||||||
import {AuthHelperService} from './modules/auth/auth-helper.service';
|
import {AuthProvider} from "./modules/auth/auth.provider";
|
||||||
import {environment} from '../environments/environment';
|
import {environment} from '../environments/environment';
|
||||||
import {Capacitor} from '@capacitor/core';
|
import {Capacitor} from '@capacitor/core';
|
||||||
import {ScheduleSyncService} from './modules/background/schedule/schedule-sync.service';
|
import {ScheduleSyncService} from './modules/background/schedule/schedule-sync.service';
|
||||||
import {Keyboard, KeyboardResize} from '@capacitor/keyboard';
|
import {Keyboard, KeyboardResize} from '@capacitor/keyboard';
|
||||||
import {AppVersionService} from './modules/about/app-version.service';
|
import {AppVersionService} from './modules/about/app-version.service';
|
||||||
import {SplashScreen} from '@capacitor/splash-screen';
|
import {SplashScreen} from '@capacitor/splash-screen';
|
||||||
|
import {AuthHelperService} from "./modules/auth/auth-helper.service";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* TODO
|
* TODO
|
||||||
@@ -45,6 +46,8 @@ export class AppComponent implements AfterContentInit {
|
|||||||
|
|
||||||
private readonly zone = inject(NgZone);
|
private readonly zone = inject(NgZone);
|
||||||
|
|
||||||
|
private readonly authProvider = inject(AuthProvider);
|
||||||
|
|
||||||
private readonly authHelper = inject(AuthHelperService);
|
private readonly authHelper = inject(AuthHelperService);
|
||||||
|
|
||||||
private readonly toastController = inject(ToastController);
|
private readonly toastController = inject(ToastController);
|
||||||
@@ -129,9 +132,8 @@ export class AppComponent implements AfterContentInit {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private async authNotificationsInit() {
|
private async authNotificationsInit() {
|
||||||
this.authHelper
|
this.authProvider
|
||||||
.getProvider()
|
.events$.subscribe(action => this.showMessage(this.authHelper.getAuthMessage(action)));
|
||||||
.events$.subscribe(action => this.showMessage(this.authHelper.getAuthMessage('default', action)));
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async showMessage(message?: string) {
|
private async showMessage(message?: string) {
|
||||||
|
|||||||
@@ -57,7 +57,6 @@ import {AssessmentsModule} from './modules/assessments/assessments.module';
|
|||||||
import {ServiceHandlerInterceptor} from './_helpers/service-handler.interceptor';
|
import {ServiceHandlerInterceptor} from './_helpers/service-handler.interceptor';
|
||||||
import {RoutingStackService} from './util/routing-stack.service';
|
import {RoutingStackService} from './util/routing-stack.service';
|
||||||
import {SCLanguageCode, SCSettingValue} from '@openstapps/core';
|
import {SCLanguageCode, SCSettingValue} from '@openstapps/core';
|
||||||
import {DefaultAuthService} from './modules/auth/default-auth.service';
|
|
||||||
import {NavigationModule} from './modules/menu/navigation/navigation.module';
|
import {NavigationModule} from './modules/menu/navigation/navigation.module';
|
||||||
import {browserFactory, SimpleBrowser} from './util/browser.factory';
|
import {browserFactory, SimpleBrowser} from './util/browser.factory';
|
||||||
import {getDateFnsLocale} from './translation/dfns-locale';
|
import {getDateFnsLocale} from './translation/dfns-locale';
|
||||||
@@ -67,6 +66,7 @@ import {Capacitor} from '@capacitor/core';
|
|||||||
import {SplashScreen} from '@capacitor/splash-screen';
|
import {SplashScreen} from '@capacitor/splash-screen';
|
||||||
import * as maplibregl from 'maplibre-gl';
|
import * as maplibregl from 'maplibre-gl';
|
||||||
import {Protocol} from 'pmtiles';
|
import {Protocol} from 'pmtiles';
|
||||||
|
import {AuthProvider} from "./modules/auth/auth.provider";
|
||||||
|
|
||||||
registerLocaleData(localeDe);
|
registerLocaleData(localeDe);
|
||||||
|
|
||||||
@@ -82,7 +82,7 @@ export function initializerFactory(
|
|||||||
configProvider: ConfigProvider,
|
configProvider: ConfigProvider,
|
||||||
translateService: TranslateService,
|
translateService: TranslateService,
|
||||||
_routingStackService: RoutingStackService,
|
_routingStackService: RoutingStackService,
|
||||||
defaultAuthService: DefaultAuthService,
|
authProvider: AuthProvider,
|
||||||
dateFnsConfigurationService: DateFnsConfigurationService,
|
dateFnsConfigurationService: DateFnsConfigurationService,
|
||||||
) {
|
) {
|
||||||
return async () => {
|
return async () => {
|
||||||
@@ -111,7 +111,7 @@ export function initializerFactory(
|
|||||||
setDefaultOptions({locale: dateFnsLocale});
|
setDefaultOptions({locale: dateFnsLocale});
|
||||||
dateFnsConfigurationService.setLocale(dateFnsLocale);
|
dateFnsConfigurationService.setLocale(dateFnsLocale);
|
||||||
|
|
||||||
await defaultAuthService.init();
|
await authProvider.init();
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
logger.warn(error);
|
logger.warn(error);
|
||||||
}
|
}
|
||||||
@@ -201,7 +201,7 @@ export function createTranslateLoader(http: HttpClient) {
|
|||||||
ConfigProvider,
|
ConfigProvider,
|
||||||
TranslateService,
|
TranslateService,
|
||||||
RoutingStackService,
|
RoutingStackService,
|
||||||
DefaultAuthService,
|
AuthProvider,
|
||||||
DateFnsConfigurationService,
|
DateFnsConfigurationService,
|
||||||
],
|
],
|
||||||
useFactory: initializerFactory,
|
useFactory: initializerFactory,
|
||||||
|
|||||||
@@ -15,9 +15,9 @@
|
|||||||
import {Injectable, inject} from '@angular/core';
|
import {Injectable, inject} from '@angular/core';
|
||||||
import {ConfigProvider} from '../config/config.provider';
|
import {ConfigProvider} from '../config/config.provider';
|
||||||
import {SCAssessment, SCUuid} from '@openstapps/core';
|
import {SCAssessment, SCUuid} from '@openstapps/core';
|
||||||
import {DefaultAuthService} from '../auth/default-auth.service';
|
|
||||||
import {HttpClient} from '@angular/common/http';
|
import {HttpClient} from '@angular/common/http';
|
||||||
import {uniqBy, keyBy} from '@openstapps/collection-utils';
|
import {uniqBy, keyBy} from '@openstapps/collection-utils';
|
||||||
|
import {AuthProvider} from "../auth/auth.provider";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
*
|
*
|
||||||
@@ -53,7 +53,7 @@ export function toAssessmentMap(data: SCAssessment[]): Record<SCUuid, SCAssessme
|
|||||||
export class AssessmentsProvider {
|
export class AssessmentsProvider {
|
||||||
readonly configProvider = inject(ConfigProvider);
|
readonly configProvider = inject(ConfigProvider);
|
||||||
|
|
||||||
readonly defaultAuth = inject(DefaultAuthService);
|
readonly authProvider = inject(AuthProvider);
|
||||||
|
|
||||||
readonly http = inject(HttpClient);
|
readonly http = inject(HttpClient);
|
||||||
|
|
||||||
@@ -97,7 +97,7 @@ export class AssessmentsProvider {
|
|||||||
this.cache = this.http
|
this.cache = this.http
|
||||||
.get<{data: SCAssessment[]}>(`${url}/${this.assessmentPath}`, {
|
.get<{data: SCAssessment[]}>(`${url}/${this.assessmentPath}`, {
|
||||||
headers: {
|
headers: {
|
||||||
Authorization: `Bearer ${accessToken ?? (await this.defaultAuth.getValidToken()).accessToken}`,
|
Authorization: `Bearer ${accessToken ?? (await this.authProvider.getValidToken()).accessToken}`,
|
||||||
},
|
},
|
||||||
})
|
})
|
||||||
.toPromise()
|
.toPromise()
|
||||||
|
|||||||
+38
-16
@@ -13,13 +13,16 @@
|
|||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
* this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
*/
|
*/
|
||||||
import {Component, inject} from '@angular/core';
|
import {Component, inject} from '@angular/core';
|
||||||
import {NavController} from '@ionic/angular/standalone';
|
|
||||||
import {Router} from '@angular/router';
|
import {Router} from '@angular/router';
|
||||||
import {AuthActions, IAuthAction} from 'ionic-appauth';
|
|
||||||
import {AuthHelperService} from '../../auth-helper.service';
|
|
||||||
import {takeUntilDestroyed} from '@angular/core/rxjs-interop';
|
import {takeUntilDestroyed} from '@angular/core/rxjs-interop';
|
||||||
import {Observable} from 'rxjs';
|
import {NavController} from '@ionic/angular/standalone';
|
||||||
import {DefaultAuthService} from '../../default-auth.service';
|
|
||||||
|
import {
|
||||||
|
AuthActions,
|
||||||
|
AuthProvider,
|
||||||
|
IAuthAction,
|
||||||
|
} from '../../auth.provider';
|
||||||
|
import {AuthHelperService} from '../../auth-helper.service';
|
||||||
|
|
||||||
@Component({
|
@Component({
|
||||||
templateUrl: 'auth-callback-page.component.html',
|
templateUrl: 'auth-callback-page.component.html',
|
||||||
@@ -33,23 +36,42 @@ export class AuthCallbackPageComponent {
|
|||||||
|
|
||||||
private authHelper = inject(AuthHelperService);
|
private authHelper = inject(AuthHelperService);
|
||||||
|
|
||||||
private auth = inject(DefaultAuthService);
|
private authProvider = inject(AuthProvider);
|
||||||
|
|
||||||
constructor() {
|
constructor() {
|
||||||
const events: Observable<IAuthAction> = this.auth.events$;
|
this.authProvider.events$
|
||||||
|
.pipe(takeUntilDestroyed())
|
||||||
|
.subscribe(action => {
|
||||||
|
void this.postCallback(action);
|
||||||
|
});
|
||||||
|
|
||||||
events.pipe(takeUntilDestroyed()).subscribe((action: IAuthAction) => this.postCallback(action));
|
this.authProvider.authorizationCallback(
|
||||||
this.auth.authorizationCallback(window.location.origin + this.router.url);
|
window.location.href,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
async postCallback(action: IAuthAction) {
|
private async postCallback(
|
||||||
if (action.action === AuthActions.SignInSuccess) {
|
action: IAuthAction,
|
||||||
const originPath = await this.authHelper.getOriginPath();
|
): Promise<void> {
|
||||||
this.navCtrl.navigateRoot(originPath ?? 'profile');
|
switch (action.action) {
|
||||||
this.authHelper.deleteOriginPath();
|
case AuthActions.SignInSuccess: {
|
||||||
|
const originPath =
|
||||||
|
await this.authHelper.getOriginPath();
|
||||||
|
|
||||||
|
await this.authHelper.deleteOriginPath();
|
||||||
|
|
||||||
|
await this.navCtrl.navigateRoot(
|
||||||
|
originPath ?? 'profile',
|
||||||
|
);
|
||||||
|
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
case AuthActions.SignInFailed: {
|
||||||
|
await this.navCtrl.navigateRoot('profile');
|
||||||
|
|
||||||
|
break;
|
||||||
}
|
}
|
||||||
if (action.action === AuthActions.SignInFailed) {
|
|
||||||
this.navCtrl.navigateRoot('profile');
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -16,13 +16,13 @@
|
|||||||
import {Injectable, inject} from '@angular/core';
|
import {Injectable, inject} from '@angular/core';
|
||||||
import {CanActivate, NavigationExtras, Router, RouterStateSnapshot} from '@angular/router';
|
import {CanActivate, NavigationExtras, Router, RouterStateSnapshot} from '@angular/router';
|
||||||
import {ActivatedProtectedRouteSnapshot} from './protected.routes';
|
import {ActivatedProtectedRouteSnapshot} from './protected.routes';
|
||||||
import {AuthHelperService} from './auth-helper.service';
|
import {AuthProvider} from "./auth.provider";
|
||||||
|
|
||||||
@Injectable({
|
@Injectable({
|
||||||
providedIn: 'root',
|
providedIn: 'root',
|
||||||
})
|
})
|
||||||
export class AuthGuardService implements CanActivate {
|
export class AuthGuardService implements CanActivate {
|
||||||
private authHelper = inject(AuthHelperService);
|
private authProvider = inject(AuthProvider);
|
||||||
|
|
||||||
private router = inject(Router);
|
private router = inject(Router);
|
||||||
|
|
||||||
@@ -32,7 +32,7 @@ export class AuthGuardService implements CanActivate {
|
|||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
await this.authHelper.getProvider().getValidToken();
|
await this.authProvider.getValidToken();
|
||||||
} catch {
|
} catch {
|
||||||
const originNavigation = this.router.currentNavigation();
|
const originNavigation = this.router.currentNavigation();
|
||||||
let extras: NavigationExtras = {};
|
let extras: NavigationExtras = {};
|
||||||
@@ -41,7 +41,7 @@ export class AuthGuardService implements CanActivate {
|
|||||||
extras = {queryParams: {origin_path: url}};
|
extras = {queryParams: {origin_path: url}};
|
||||||
}
|
}
|
||||||
this.router.navigate(['profile'], extras);
|
this.router.navigate(['profile'], extras);
|
||||||
await this.authHelper.getProvider().signIn();
|
await this.authProvider.signIn();
|
||||||
|
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,118 +1,251 @@
|
|||||||
/*
|
import {AuthActions, AuthProvider} from './auth.provider';
|
||||||
* Copyright (C) 2023 StApps
|
|
||||||
* This program is free software: you can redistribute it and/or modify it
|
|
||||||
* under the terms of the GNU General Public License as published by the Free
|
|
||||||
* Software Foundation, version 3.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful, but WITHOUT
|
|
||||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
||||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
|
||||||
* more details.
|
|
||||||
*
|
|
||||||
* You should have received a copy of the GNU General Public License along with
|
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
|
||||||
*/
|
|
||||||
import {TestBed} from '@angular/core/testing';
|
|
||||||
import {AuthHelperService} from './auth-helper.service';
|
import {AuthHelperService} from './auth-helper.service';
|
||||||
import {ConfigProvider} from '../config/config.provider';
|
|
||||||
import {StorageProvider} from '../storage/storage.provider';
|
const AUTH_ORIGIN_PATH = 'stapps.auth.origin_path';
|
||||||
import {DefaultAuthService} from './default-auth.service';
|
const AUTH_MESSAGE_PREFIX = 'auth.messages.default';
|
||||||
import {Browser} from 'ionic-appauth';
|
const END_SESSION_ENDPOINT = 'https://idp.example.org/logout';
|
||||||
import {Requestor, StorageBackend} from '@openid/appauth';
|
|
||||||
import {TranslateService} from '@ngx-translate/core';
|
const USER_MAPPING = {
|
||||||
import {StAppsWebHttpClient} from '../data/stapps-web-http-client.provider';
|
id: '$.sub',
|
||||||
import {provideHttpClient, withInterceptorsFromDi} from '@angular/common/http';
|
givenName: '$.given_name',
|
||||||
import {SimpleBrowser} from '../../util/browser.factory';
|
familyName: '$.family_name',
|
||||||
import {LoggerTestingModule} from 'ngx-logger/testing';
|
email: '$.attributes.mail',
|
||||||
|
role: '$.role',
|
||||||
|
};
|
||||||
|
|
||||||
|
interface TestAlertButton {
|
||||||
|
text: string;
|
||||||
|
role?: string;
|
||||||
|
cssClass?: string;
|
||||||
|
handler?: () => Promise<void> | void;
|
||||||
|
}
|
||||||
|
|
||||||
describe('AuthHelperService', () => {
|
describe('AuthHelperService', () => {
|
||||||
let authHelperService: AuthHelperService;
|
let service: AuthHelperService;
|
||||||
const storageProviderSpy = jasmine.createSpyObj('StorageProvider', ['init', 'get', 'has', 'put', 'search']);
|
|
||||||
const translateServiceSpy = jasmine.createSpyObj('TranslateService', ['setDefaultLang', 'use']);
|
let translateService: jasmine.SpyObj<{instant(key: string): string}>;
|
||||||
const defaultAuthServiceMock = jasmine.createSpyObj('DefaultAuthService', ['init', 'setupConfiguration']);
|
let configProvider: jasmine.SpyObj<{getAnyValue(key: string): unknown}>;
|
||||||
const authHelperServiceMock = jasmine.createSpyObj('AuthHelperService', ['constructor']);
|
let storageProvider: jasmine.SpyObj<{
|
||||||
const simpleBrowserMock = jasmine.createSpyObj('SimpleBrowser', ['open']);
|
get<T>(key: string): Promise<T>;
|
||||||
const configProvider = jasmine.createSpyObj('ConfigProvider', {
|
put(key: string, value: unknown): Promise<unknown>;
|
||||||
getAnyValue: {
|
delete(key: string): Promise<unknown>;
|
||||||
default: {
|
}>;
|
||||||
endpoints: {
|
let authProvider: jasmine.SpyObj<Pick<AuthProvider, 'getEndSessionEndpoint'>>;
|
||||||
mapping: {
|
let browser: jasmine.SpyObj<{open(url: string): Promise<void>}>;
|
||||||
id: '$.id',
|
let alertController: jasmine.SpyObj<{create(options: unknown): Promise<unknown>}>;
|
||||||
email: '$.attributes.mailPrimaryAddress',
|
let alert: jasmine.SpyObj<{present(): Promise<void>}>;
|
||||||
givenName: '$.attributes.givenName',
|
|
||||||
familyName: '$.attributes.sn',
|
function createService(authConfig: unknown = {default: {endpoints: {mapping: USER_MAPPING}}}) {
|
||||||
name: '$.attributes.sn',
|
configProvider.getAnyValue.and.returnValue(authConfig);
|
||||||
role: '$.attributes.eduPersonPrimaryAffiliation',
|
|
||||||
studentId: '$.attributes.employeeNumber',
|
return new AuthHelperService(
|
||||||
},
|
translateService as any,
|
||||||
},
|
configProvider as any,
|
||||||
},
|
storageProvider as any,
|
||||||
},
|
authProvider as any,
|
||||||
});
|
browser as any,
|
||||||
|
alertController as any,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Options passed to the most recent AlertController.create() call. */
|
||||||
|
function lastAlertOptions(): {header: string; message: string; buttons: TestAlertButton[]} {
|
||||||
|
return alertController.create.calls.mostRecent().args[0] as any;
|
||||||
|
}
|
||||||
|
|
||||||
|
function alertButton(role: string): TestAlertButton {
|
||||||
|
const button = lastAlertOptions().buttons.find(b => b.role === role);
|
||||||
|
if (!button) {
|
||||||
|
throw new Error(`No alert button with role "${role}"`);
|
||||||
|
}
|
||||||
|
return button;
|
||||||
|
}
|
||||||
|
|
||||||
beforeEach(() => {
|
beforeEach(() => {
|
||||||
TestBed.configureTestingModule({
|
translateService = jasmine.createSpyObj('TranslateService', ['instant']);
|
||||||
imports: [LoggerTestingModule],
|
translateService.instant.and.callFake((key: string) => `translated:${key}`);
|
||||||
providers: [
|
|
||||||
StAppsWebHttpClient,
|
configProvider = jasmine.createSpyObj('ConfigProvider', ['getAnyValue']);
|
||||||
{
|
|
||||||
provide: TranslateService,
|
storageProvider = jasmine.createSpyObj('StorageProvider', ['get', 'put', 'delete']);
|
||||||
useValue: translateServiceSpy,
|
storageProvider.put.and.resolveTo();
|
||||||
},
|
storageProvider.delete.and.resolveTo();
|
||||||
{
|
|
||||||
provide: StorageProvider,
|
authProvider = jasmine.createSpyObj('AuthProvider', ['getEndSessionEndpoint']);
|
||||||
useValue: storageProviderSpy,
|
authProvider.getEndSessionEndpoint.and.resolveTo(END_SESSION_ENDPOINT);
|
||||||
},
|
|
||||||
{
|
browser = jasmine.createSpyObj('SimpleBrowser', ['open']);
|
||||||
provider: DefaultAuthService,
|
browser.open.and.resolveTo();
|
||||||
useValue: defaultAuthServiceMock,
|
|
||||||
},
|
alert = jasmine.createSpyObj('HTMLIonAlertElement', ['present']);
|
||||||
{
|
alert.present.and.resolveTo();
|
||||||
provide: ConfigProvider,
|
|
||||||
useValue: configProvider,
|
alertController = jasmine.createSpyObj('AlertController', ['create']);
|
||||||
},
|
alertController.create.and.resolveTo(alert);
|
||||||
Browser,
|
|
||||||
StorageBackend,
|
service = createService();
|
||||||
Requestor,
|
});
|
||||||
{
|
|
||||||
provider: AuthHelperService,
|
describe('userConfigurationMap', () => {
|
||||||
useValue: authHelperServiceMock,
|
it('reads the user mapping from the default auth provider', () => {
|
||||||
},
|
expect(configProvider.getAnyValue).toHaveBeenCalledWith('auth');
|
||||||
{
|
expect(service.userConfigurationMap).toEqual(USER_MAPPING as any);
|
||||||
provide: SimpleBrowser,
|
});
|
||||||
useValue: simpleBrowserMock,
|
|
||||||
},
|
it('falls back to an empty mapping when no default auth provider is configured', () => {
|
||||||
provideHttpClient(withInterceptorsFromDi()),
|
service = createService({});
|
||||||
],
|
|
||||||
|
expect(service.userConfigurationMap).toEqual({} as any);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('getAuthMessage', () => {
|
||||||
|
it('returns the translated message for SignInSuccess', () => {
|
||||||
|
expect(service.getAuthMessage({action: AuthActions.SignInSuccess})).toBe(
|
||||||
|
`translated:${AUTH_MESSAGE_PREFIX}.logged_in_success`,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns the translated message for SignOutSuccess', () => {
|
||||||
|
expect(service.getAuthMessage({action: AuthActions.SignOutSuccess})).toBe(
|
||||||
|
`translated:${AUTH_MESSAGE_PREFIX}.logged_out_success`,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns undefined for all other actions without translating', () => {
|
||||||
|
const otherActions = Object.values(AuthActions).filter(
|
||||||
|
action => action !== AuthActions.SignInSuccess && action !== AuthActions.SignOutSuccess,
|
||||||
|
);
|
||||||
|
|
||||||
|
for (const action of otherActions) {
|
||||||
|
expect(service.getAuthMessage({action})).withContext(action).toBeUndefined();
|
||||||
|
}
|
||||||
|
expect(translateService.instant).not.toHaveBeenCalled();
|
||||||
});
|
});
|
||||||
authHelperService = TestBed.inject(AuthHelperService);
|
|
||||||
});
|
});
|
||||||
|
|
||||||
describe('getUserFromUserInfo', () => {
|
describe('getUserFromUserInfo', () => {
|
||||||
it('should provide user configuration from userInfo', async () => {
|
it('maps user info fields via the configured JSONPath mapping', () => {
|
||||||
const userConfiguration = authHelperService.getUserFromUserInfo({
|
const user = service.getUserFromUserInfo({
|
||||||
attributes: {
|
sub: 'user-123',
|
||||||
eduPersonPrimaryAffiliation: 'student',
|
given_name: 'Erika',
|
||||||
employeeNumber: '123456',
|
family_name: 'Mustermann',
|
||||||
givenName: 'Erika',
|
attributes: {mail: 'erika@example.org'},
|
||||||
mailPrimaryAddress: 'emuster@anyschool.de',
|
role: 'employee',
|
||||||
oauthClientId: '123-abc-123',
|
|
||||||
sn: 'Musterfrau',
|
|
||||||
uid: 'emuster',
|
|
||||||
},
|
|
||||||
id: 'emuster',
|
|
||||||
client_id: '123-abc-123',
|
|
||||||
});
|
});
|
||||||
|
|
||||||
expect(userConfiguration).toEqual({
|
expect(user).toEqual(
|
||||||
id: 'emuster',
|
jasmine.objectContaining({
|
||||||
|
id: 'user-123',
|
||||||
givenName: 'Erika',
|
givenName: 'Erika',
|
||||||
familyName: 'Musterfrau',
|
familyName: 'Mustermann',
|
||||||
name: 'Erika Musterfrau',
|
email: 'erika@example.org',
|
||||||
email: 'emuster@anyschool.de',
|
role: 'employee',
|
||||||
role: 'student',
|
}),
|
||||||
studentId: '123456',
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('builds the name from given name and family name', () => {
|
||||||
|
const user = service.getUserFromUserInfo({
|
||||||
|
sub: 'user-123',
|
||||||
|
given_name: 'Erika',
|
||||||
|
family_name: 'Mustermann',
|
||||||
|
role: 'student',
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(user.name).toBe('Erika Mustermann');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('keeps the default name when the family name is missing', () => {
|
||||||
|
const user = service.getUserFromUserInfo({
|
||||||
|
sub: 'user-123',
|
||||||
|
given_name: 'Erika',
|
||||||
|
role: 'student',
|
||||||
|
});
|
||||||
|
|
||||||
|
expect(user.name).toBe('');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns the default user when no mapping is configured', () => {
|
||||||
|
service = createService({});
|
||||||
|
|
||||||
|
expect(service.getUserFromUserInfo({sub: 'user-123'})).toEqual({
|
||||||
|
id: '',
|
||||||
|
name: '',
|
||||||
|
role: 'student',
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('origin path', () => {
|
||||||
|
it('stores the origin path', async () => {
|
||||||
|
await service.setOriginPath('/profile');
|
||||||
|
|
||||||
|
expect(storageProvider.put).toHaveBeenCalledOnceWith(AUTH_ORIGIN_PATH, '/profile');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns the stored origin path', async () => {
|
||||||
|
storageProvider.get.and.resolveTo('/profile');
|
||||||
|
|
||||||
|
expect(await service.getOriginPath()).toBe('/profile');
|
||||||
|
expect(storageProvider.get).toHaveBeenCalledOnceWith(AUTH_ORIGIN_PATH);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns undefined when reading the origin path fails', async () => {
|
||||||
|
storageProvider.get.and.rejectWith(new Error('Value not found'));
|
||||||
|
|
||||||
|
expect(await service.getOriginPath()).toBeUndefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('deletes the origin path', async () => {
|
||||||
|
await service.deleteOriginPath();
|
||||||
|
|
||||||
|
expect(storageProvider.delete).toHaveBeenCalledOnceWith(AUTH_ORIGIN_PATH);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('endBrowserSession', () => {
|
||||||
|
it('does nothing when the provider has no end-session endpoint', async () => {
|
||||||
|
authProvider.getEndSessionEndpoint.and.resolveTo(undefined);
|
||||||
|
|
||||||
|
await service.endBrowserSession();
|
||||||
|
|
||||||
|
expect(alertController.create).not.toHaveBeenCalled();
|
||||||
|
expect(browser.open).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('presents a translated confirmation alert', async () => {
|
||||||
|
await service.endBrowserSession();
|
||||||
|
|
||||||
|
const options = lastAlertOptions();
|
||||||
|
expect(options.header).toBe(`translated:${AUTH_MESSAGE_PREFIX}.log_out_alert.header`);
|
||||||
|
expect(options.message).toBe(`translated:${AUTH_MESSAGE_PREFIX}.log_out_alert.message`);
|
||||||
|
expect(options.buttons.map(b => b.role)).toEqual(['cancel', 'confirm']);
|
||||||
|
expect(alert.present).toHaveBeenCalledTimes(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does not open the end-session endpoint before confirmation', async () => {
|
||||||
|
await service.endBrowserSession();
|
||||||
|
|
||||||
|
expect(browser.open).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('opens the end-session endpoint when the user confirms', async () => {
|
||||||
|
await service.endBrowserSession();
|
||||||
|
|
||||||
|
await alertButton('confirm').handler?.();
|
||||||
|
|
||||||
|
expect(browser.open).toHaveBeenCalledOnceWith(END_SESSION_ENDPOINT);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does not open the end-session endpoint when the user cancels', async () => {
|
||||||
|
await service.endBrowserSession();
|
||||||
|
|
||||||
|
const cancelButton = alertButton('cancel');
|
||||||
|
await cancelButton.handler?.();
|
||||||
|
|
||||||
|
expect(cancelButton.handler).toBeUndefined();
|
||||||
|
expect(browser.open).not.toHaveBeenCalled();
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -14,35 +14,38 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
import {Injectable, inject} from '@angular/core';
|
import {Injectable, inject} from '@angular/core';
|
||||||
import {AuthActions, IAuthAction} from 'ionic-appauth';
|
import {AlertController} from '@ionic/angular/standalone';
|
||||||
import {TranslateService} from '@ngx-translate/core';
|
import {TranslateService} from '@ngx-translate/core';
|
||||||
import {JSONPath} from 'jsonpath-plus';
|
|
||||||
import {
|
import {
|
||||||
SCAuthorizationProvider,
|
SCAuthorizationProvider,
|
||||||
SCAuthorizationProviderType,
|
|
||||||
SCUserConfiguration,
|
SCUserConfiguration,
|
||||||
SCUserConfigurationMap,
|
SCUserConfigurationMap,
|
||||||
} from '@openstapps/core';
|
} from '@openstapps/core';
|
||||||
|
import {JSONPath} from 'jsonpath-plus';
|
||||||
|
|
||||||
|
import {SimpleBrowser} from '../../util/browser.factory';
|
||||||
import {ConfigProvider} from '../config/config.provider';
|
import {ConfigProvider} from '../config/config.provider';
|
||||||
import {StorageProvider} from '../storage/storage.provider';
|
import {StorageProvider} from '../storage/storage.provider';
|
||||||
import {DefaultAuthService} from './default-auth.service';
|
import {
|
||||||
import {SimpleBrowser} from '../../util/browser.factory';
|
AuthActions, AuthProvider,
|
||||||
import {AlertController} from '@ionic/angular/standalone';
|
IAuthAction,
|
||||||
|
} from './auth.provider';
|
||||||
|
|
||||||
const AUTH_ORIGIN_PATH = 'stapps.auth.origin_path';
|
const AUTH_ORIGIN_PATH = 'stapps.auth.origin_path';
|
||||||
|
const AUTH_MESSAGE_PREFIX = 'auth.messages.default';
|
||||||
|
|
||||||
@Injectable({
|
@Injectable({
|
||||||
providedIn: 'root',
|
providedIn: 'root',
|
||||||
})
|
})
|
||||||
export class AuthHelperService {
|
export class AuthHelperService {
|
||||||
|
private authProvider = inject(AuthProvider);
|
||||||
|
|
||||||
private translateService = inject(TranslateService);
|
private translateService = inject(TranslateService);
|
||||||
|
|
||||||
private configProvider = inject(ConfigProvider);
|
private configProvider = inject(ConfigProvider);
|
||||||
|
|
||||||
private storageProvider = inject(StorageProvider);
|
private storageProvider = inject(StorageProvider);
|
||||||
|
|
||||||
private defaultAuth = inject(DefaultAuthService);
|
|
||||||
|
|
||||||
private browser = inject(SimpleBrowser);
|
private browser = inject(SimpleBrowser);
|
||||||
|
|
||||||
private alertController = inject(AlertController);
|
private alertController = inject(AlertController);
|
||||||
@@ -58,87 +61,134 @@ export class AuthHelperService {
|
|||||||
).default?.endpoints.mapping ?? {};
|
).default?.endpoints.mapping ?? {};
|
||||||
}
|
}
|
||||||
|
|
||||||
public getAuthMessage(provider: SCAuthorizationProviderType, action: IAuthAction) {
|
public getAuthMessage(
|
||||||
let message: string | undefined;
|
action: IAuthAction,
|
||||||
|
): string | undefined {
|
||||||
switch (action.action) {
|
switch (action.action) {
|
||||||
case AuthActions.SignInSuccess: {
|
case AuthActions.SignInSuccess:
|
||||||
message = this.translateService.instant(`auth.messages.${provider}.logged_in_success`);
|
return this.translateService.instant(
|
||||||
break;
|
`${AUTH_MESSAGE_PREFIX}.logged_in_success`,
|
||||||
|
);
|
||||||
|
|
||||||
|
case AuthActions.SignOutSuccess:
|
||||||
|
return this.translateService.instant(
|
||||||
|
`${AUTH_MESSAGE_PREFIX}.logged_out_success`,
|
||||||
|
);
|
||||||
|
|
||||||
|
default:
|
||||||
|
return undefined;
|
||||||
}
|
}
|
||||||
case AuthActions.SignOutSuccess: {
|
|
||||||
message = this.translateService.instant(`auth.messages.${provider}.logged_out_success`);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return message;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
getUserFromUserInfo(userInfo: object) {
|
public getUserFromUserInfo(
|
||||||
|
userInfo: object,
|
||||||
|
): SCUserConfiguration {
|
||||||
const user: SCUserConfiguration = {
|
const user: SCUserConfiguration = {
|
||||||
id: '',
|
id: '',
|
||||||
name: '',
|
name: '',
|
||||||
role: 'student',
|
role: 'student',
|
||||||
};
|
};
|
||||||
|
|
||||||
for (const key in this.userConfigurationMap) {
|
for (const key in this.userConfigurationMap) {
|
||||||
user[key as keyof SCUserConfiguration] = JSONPath({
|
const userKey =
|
||||||
path: this.userConfigurationMap[key as keyof SCUserConfiguration] as string,
|
key as keyof SCUserConfiguration;
|
||||||
|
|
||||||
|
user[userKey] = JSONPath({
|
||||||
|
path:
|
||||||
|
this.userConfigurationMap[
|
||||||
|
userKey
|
||||||
|
] as string,
|
||||||
json: userInfo,
|
json: userInfo,
|
||||||
})[0];
|
})[0];
|
||||||
}
|
}
|
||||||
if (user.givenName && user.givenName.length > 0 && user.familyName && user.familyName.length > 0) {
|
|
||||||
user.name = `${user.givenName} ${user.familyName}`;
|
if (
|
||||||
|
user.givenName &&
|
||||||
|
user.familyName
|
||||||
|
) {
|
||||||
|
user.name =
|
||||||
|
`${user.givenName} ${user.familyName}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
return user;
|
return user;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteOriginPath() {
|
public async deleteOriginPath():
|
||||||
return this.storageProvider.delete(AUTH_ORIGIN_PATH);
|
Promise<void> {
|
||||||
|
await this.storageProvider.delete(
|
||||||
|
AUTH_ORIGIN_PATH,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
async setOriginPath(path: string) {
|
public async setOriginPath(
|
||||||
return this.storageProvider.put<string>(AUTH_ORIGIN_PATH, path);
|
path: string,
|
||||||
|
): Promise<void> {
|
||||||
|
await this.storageProvider.put(
|
||||||
|
AUTH_ORIGIN_PATH,
|
||||||
|
path,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
async getOriginPath() {
|
public async getOriginPath():
|
||||||
let originPath: string;
|
Promise<string | undefined> {
|
||||||
try {
|
try {
|
||||||
originPath = await this.storageProvider.get<string>(AUTH_ORIGIN_PATH);
|
return await this.storageProvider.get<string>(
|
||||||
|
AUTH_ORIGIN_PATH,
|
||||||
|
);
|
||||||
} catch {
|
} catch {
|
||||||
|
return undefined;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async endBrowserSession():
|
||||||
|
Promise<void> {
|
||||||
|
const endSessionEndpoint =
|
||||||
|
await this.authProvider
|
||||||
|
.getEndSessionEndpoint();
|
||||||
|
|
||||||
|
if (!endSessionEndpoint) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
return originPath;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
const alert =
|
||||||
* Provides appropriate auth service instance based on type (string) parameter
|
await this.alertController.create({
|
||||||
*/
|
header:
|
||||||
getProvider(): DefaultAuthService {
|
this.translateService.instant(
|
||||||
return this.defaultAuth;
|
`${AUTH_MESSAGE_PREFIX}.log_out_alert.header`,
|
||||||
}
|
),
|
||||||
|
|
||||||
/**
|
message:
|
||||||
* Ends browser session by opening endSessionEndpoint URL of the provider
|
this.translateService.instant(
|
||||||
* @param providerType Type of the provider (e.g. 'default' or 'paia')
|
`${AUTH_MESSAGE_PREFIX}.log_out_alert.message`,
|
||||||
*/
|
),
|
||||||
async endBrowserSession(providerType: SCAuthorizationProviderType) {
|
|
||||||
const endSessionEndpoint = (await this.getProvider().configuration).endSessionEndpoint;
|
|
||||||
|
|
||||||
if (endSessionEndpoint) {
|
|
||||||
const alert: HTMLIonAlertElement = await this.alertController.create({
|
|
||||||
header: this.translateService.instant(`auth.messages.${providerType}.log_out_alert.header`),
|
|
||||||
message: this.translateService.instant(`auth.messages.${providerType}.log_out_alert.message`),
|
|
||||||
buttons: [
|
buttons: [
|
||||||
{
|
{
|
||||||
text: this.translateService.instant('no'),
|
text:
|
||||||
|
this.translateService.instant(
|
||||||
|
'no',
|
||||||
|
),
|
||||||
|
|
||||||
|
role: 'cancel',
|
||||||
cssClass: 'default',
|
cssClass: 'default',
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
text: this.translateService.instant('yes'),
|
text:
|
||||||
|
this.translateService.instant(
|
||||||
|
'yes',
|
||||||
|
),
|
||||||
|
|
||||||
role: 'confirm',
|
role: 'confirm',
|
||||||
cssClass: 'preferred',
|
cssClass: 'preferred',
|
||||||
handler: () => {
|
|
||||||
this.browser.open(new URL(endSessionEndpoint).href);
|
handler: async () => {
|
||||||
|
/*
|
||||||
|
* Only now, after explicit confirmation,
|
||||||
|
* open the IdP end-session endpoint.
|
||||||
|
*/
|
||||||
|
await this.browser.open(
|
||||||
|
endSessionEndpoint,
|
||||||
|
);
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
],
|
],
|
||||||
@@ -146,5 +196,4 @@ export class AuthHelperService {
|
|||||||
|
|
||||||
await alert.present();
|
await alert.present();
|
||||||
}
|
}
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -12,15 +12,5 @@
|
|||||||
* You should have received a copy of the GNU General Public License along with
|
* You should have received a copy of the GNU General Public License along with
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
* this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
*/
|
*/
|
||||||
import {SCAuthorizationProviderType} from '@openstapps/core';
|
|
||||||
|
|
||||||
export const authPaths: {
|
export const AUTH_REDIRECT_PATH = 'auth/callback';
|
||||||
[key in SCAuthorizationProviderType]: {redirect_path: string};
|
|
||||||
} = {
|
|
||||||
default: {
|
|
||||||
redirect_path: 'auth/callback',
|
|
||||||
},
|
|
||||||
paia: {
|
|
||||||
redirect_path: 'auth/paia/callback',
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|||||||
@@ -15,12 +15,12 @@
|
|||||||
|
|
||||||
import {RouterModule, Routes} from '@angular/router';
|
import {RouterModule, Routes} from '@angular/router';
|
||||||
import {NgModule} from '@angular/core';
|
import {NgModule} from '@angular/core';
|
||||||
import {authPaths} from './auth-paths';
|
import {AUTH_REDIRECT_PATH} from './auth-paths';
|
||||||
import {AuthCallbackPageComponent} from './auth-callback/page/auth-callback-page.component';
|
import {AuthCallbackPageComponent} from './auth-callback/page/auth-callback-page.component';
|
||||||
|
|
||||||
const authRoutes: Routes = [
|
const authRoutes: Routes = [
|
||||||
{
|
{
|
||||||
path: authPaths.default.redirect_path,
|
path: AUTH_REDIRECT_PATH,
|
||||||
component: AuthCallbackPageComponent,
|
component: AuthCallbackPageComponent,
|
||||||
},
|
},
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -3,14 +3,12 @@ import {CommonModule} from '@angular/common';
|
|||||||
import {Platform} from '@ionic/angular/standalone';
|
import {Platform} from '@ionic/angular/standalone';
|
||||||
import {Requestor, StorageBackend} from '@openid/appauth';
|
import {Requestor, StorageBackend} from '@openid/appauth';
|
||||||
import {storageFactory} from './factories';
|
import {storageFactory} from './factories';
|
||||||
import {Browser} from 'ionic-appauth';
|
import {requestorFactory} from './factories/requestor.factory';
|
||||||
import {CapacitorBrowser} from 'ionic-appauth/lib/capacitor';
|
|
||||||
import {httpFactory} from './factories/http.factory';
|
|
||||||
import {HttpClient} from '@angular/common/http';
|
import {HttpClient} from '@angular/common/http';
|
||||||
import {AuthRoutingModule} from './auth-routing.module';
|
import {AuthRoutingModule} from './auth-routing.module';
|
||||||
import {TranslateModule} from '@ngx-translate/core';
|
import {TranslateModule} from '@ngx-translate/core';
|
||||||
import {AuthCallbackPageComponent} from './auth-callback/page/auth-callback-page.component';
|
import {AuthCallbackPageComponent} from './auth-callback/page/auth-callback-page.component';
|
||||||
import {DefaultAuthService} from './default-auth.service';
|
import {AuthProvider} from "./auth.provider";
|
||||||
|
|
||||||
@NgModule({
|
@NgModule({
|
||||||
declarations: [AuthCallbackPageComponent],
|
declarations: [AuthCallbackPageComponent],
|
||||||
@@ -23,14 +21,10 @@ import {DefaultAuthService} from './default-auth.service';
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
provide: Requestor,
|
provide: Requestor,
|
||||||
useFactory: httpFactory,
|
useFactory: requestorFactory,
|
||||||
deps: [Platform, HttpClient],
|
deps: [Platform, HttpClient],
|
||||||
},
|
},
|
||||||
{
|
AuthProvider,
|
||||||
provide: Browser,
|
|
||||||
useClass: CapacitorBrowser,
|
|
||||||
},
|
|
||||||
DefaultAuthService,
|
|
||||||
],
|
],
|
||||||
})
|
})
|
||||||
export class AuthModule {}
|
export class AuthModule {}
|
||||||
|
|||||||
@@ -13,69 +13,90 @@
|
|||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
* this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
import {AuthorizationServiceConfigurationJson} from '@openid/appauth';
|
|
||||||
import {IAuthConfig} from 'ionic-appauth';
|
|
||||||
import {SCAuthorizationProvider, SCAuthorizationProviderType} from '@openstapps/core';
|
|
||||||
import {Capacitor} from '@capacitor/core';
|
import {Capacitor} from '@capacitor/core';
|
||||||
import {authPaths} from './auth-paths';
|
import {SCAuthorizationProvider} from '@openstapps/core';
|
||||||
|
import {
|
||||||
|
AuthorizationServiceConfiguration,
|
||||||
|
} from '@openid/appauth';
|
||||||
|
|
||||||
import {environment} from '../../../environments/environment';
|
import {environment} from '../../../environments/environment';
|
||||||
|
import {AUTH_REDIRECT_PATH} from './auth-paths';
|
||||||
|
import type {AuthConfig} from './auth.provider';
|
||||||
|
|
||||||
|
export interface OidcEndpoints {
|
||||||
|
userinfo?: string;
|
||||||
|
endSession?: string;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get configuration of an OAuth2 client
|
* Returns the configuration of the OIDC client.
|
||||||
*/
|
*/
|
||||||
export function getClientConfig(
|
export function getClientConfig(
|
||||||
providerType: SCAuthorizationProviderType,
|
|
||||||
authConfig: {
|
authConfig: {
|
||||||
default?: SCAuthorizationProvider;
|
default: SCAuthorizationProvider;
|
||||||
paia?: SCAuthorizationProvider;
|
|
||||||
},
|
},
|
||||||
): IAuthConfig {
|
): AuthConfig {
|
||||||
const providerConfig = authConfig[providerType] as SCAuthorizationProvider;
|
const provider =
|
||||||
|
authConfig.default;
|
||||||
|
|
||||||
return {
|
return {
|
||||||
end_session_redirect_url: '',
|
server_host: provider.client.url,
|
||||||
|
client_id: provider.client.clientId,
|
||||||
|
scopes: provider.client.scopes,
|
||||||
|
redirect_url: getRedirectUrl(),
|
||||||
pkce: true,
|
pkce: true,
|
||||||
scopes: providerConfig.client.scopes,
|
|
||||||
server_host: providerConfig.client.url,
|
|
||||||
client_id: providerConfig.client.clientId,
|
|
||||||
redirect_url: getRedirectUrl(authPaths[providerType].redirect_path),
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get configuration about endpoints of an OAuth2 server
|
* Returns the AppAuth OAuth/OIDC service configuration.
|
||||||
*/
|
*/
|
||||||
export function getEndpointsConfig(
|
export function getServiceConfiguration(
|
||||||
providerType: SCAuthorizationProviderType,
|
|
||||||
authConfig: {
|
authConfig: {
|
||||||
default?: SCAuthorizationProvider;
|
default: SCAuthorizationProvider;
|
||||||
paia?: SCAuthorizationProvider;
|
|
||||||
},
|
},
|
||||||
): AuthorizationServiceConfigurationJson {
|
): AuthorizationServiceConfiguration {
|
||||||
const providerConfig = authConfig[providerType] as SCAuthorizationProvider;
|
const endpoints =
|
||||||
|
authConfig.default.endpoints;
|
||||||
|
|
||||||
|
return new AuthorizationServiceConfiguration({
|
||||||
|
authorization_endpoint: endpoints.authorization,
|
||||||
|
token_endpoint: endpoints.token,
|
||||||
|
revocation_endpoint: endpoints.revoke || '',
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Returns the additional OIDC endpoints that AppAuth-JS does not expose
|
||||||
|
* through AuthorizationServiceConfiguration.
|
||||||
|
*/
|
||||||
|
export function getOidcEndpoints(
|
||||||
|
authConfig: {
|
||||||
|
default: SCAuthorizationProvider;
|
||||||
|
},
|
||||||
|
): OidcEndpoints {
|
||||||
|
const endpoints = authConfig.default.endpoints;
|
||||||
|
|
||||||
return {
|
return {
|
||||||
authorization_endpoint: providerConfig.endpoints.authorization,
|
userinfo:
|
||||||
end_session_endpoint: providerConfig.endpoints.endSession,
|
endpoints.userinfo,
|
||||||
revocation_endpoint: providerConfig.endpoints.revoke ?? '',
|
|
||||||
token_endpoint: providerConfig.endpoints.token,
|
endSession:
|
||||||
userinfo_endpoint: providerConfig.endpoints.userinfo,
|
endpoints.endSession,
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Return a URL of the app, depending on the platform where it is running
|
* Returns the OIDC redirect URL depending on the current platform.
|
||||||
*/
|
*/
|
||||||
function getRedirectUrl(routePath: string): string {
|
function getRedirectUrl(): string {
|
||||||
let appHost: string;
|
if (Capacitor.isNativePlatform()) {
|
||||||
let appSchema: string;
|
return `${environment.custom_url_scheme}://${environment.app_host}/${AUTH_REDIRECT_PATH}`;
|
||||||
if (environment.production) {
|
|
||||||
appSchema = Capacitor.isNativePlatform() ? environment.custom_url_scheme : 'https';
|
|
||||||
appHost = environment.app_host;
|
|
||||||
} else {
|
|
||||||
appSchema = Capacitor.isNativePlatform()
|
|
||||||
? environment.custom_url_scheme
|
|
||||||
: window.location.protocol.split(':')[0];
|
|
||||||
|
|
||||||
appHost = Capacitor.isNativePlatform() ? environment.app_host : window.location.host;
|
|
||||||
}
|
}
|
||||||
return `${appSchema}://${appHost}/${routePath}`;
|
|
||||||
|
if (environment.production) {
|
||||||
|
return `https://${environment.app_host}/${AUTH_REDIRECT_PATH}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
return `${window.location.origin}/${AUTH_REDIRECT_PATH}`;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,239 @@
|
|||||||
|
import {
|
||||||
|
AppAuthError,
|
||||||
|
AuthorizationServiceConfiguration,
|
||||||
|
StorageBackend,
|
||||||
|
TokenRequestHandler,
|
||||||
|
TokenResponse,
|
||||||
|
} from '@openid/appauth';
|
||||||
|
import {BehaviorSubject, firstValueFrom} from 'rxjs';
|
||||||
|
|
||||||
|
import {AuthProvider, IAuthAction, INVALID_GRANT} from './auth.provider';
|
||||||
|
|
||||||
|
const TOKEN_RESPONSE_KEY = 'token_response';
|
||||||
|
const TOKEN_LIFETIME = 3600;
|
||||||
|
const NOW_MS = Date.parse('2026-01-01T12:00:00Z');
|
||||||
|
const NOW = NOW_MS / 1000;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Creates a token with a real lifetime instead of spying on isValid().
|
||||||
|
*
|
||||||
|
* remainingSeconds > 0 → still valid for that long
|
||||||
|
* remainingSeconds < 0 → expired that many seconds ago
|
||||||
|
* refreshToken: null → token without refresh token
|
||||||
|
*/
|
||||||
|
function makeToken(
|
||||||
|
opts: {accessToken?: string; refreshToken?: string | null; remainingSeconds?: number} = {},
|
||||||
|
): TokenResponse {
|
||||||
|
const remaining = opts.remainingSeconds ?? TOKEN_LIFETIME;
|
||||||
|
|
||||||
|
return new TokenResponse({
|
||||||
|
access_token: opts.accessToken ?? 'access-token',
|
||||||
|
refresh_token: opts.refreshToken === null ? undefined : (opts.refreshToken ?? 'refresh-token'),
|
||||||
|
token_type: 'bearer',
|
||||||
|
expires_in: String(TOKEN_LIFETIME),
|
||||||
|
issued_at: NOW - (TOKEN_LIFETIME - remaining),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Typed access to the private members the tests depend on. */
|
||||||
|
interface AuthProviderInternals {
|
||||||
|
storage: StorageBackend;
|
||||||
|
tokenHandler: TokenRequestHandler;
|
||||||
|
tokenSubject: BehaviorSubject<TokenResponse | undefined>;
|
||||||
|
notify(action: IAuthAction): void;
|
||||||
|
}
|
||||||
|
|
||||||
|
describe('AuthProvider', () => {
|
||||||
|
let provider: AuthProvider;
|
||||||
|
let internals: AuthProviderInternals;
|
||||||
|
|
||||||
|
let storageGetItem: jasmine.Spy;
|
||||||
|
let storageSetItem: jasmine.Spy;
|
||||||
|
let storageRemoveItem: jasmine.Spy;
|
||||||
|
let tokenRequest: jasmine.Spy;
|
||||||
|
|
||||||
|
/** Seeds storage with the given token and loads it through the public API. */
|
||||||
|
async function givenLoadedToken(token: TokenResponse | null): Promise<void> {
|
||||||
|
storageGetItem.and.resolveTo(token ? JSON.stringify(token.toJson()) : null);
|
||||||
|
await provider.loadTokenFromStorage();
|
||||||
|
}
|
||||||
|
|
||||||
|
const isAuthenticated = () => firstValueFrom(provider.isAuthenticated$);
|
||||||
|
const isLoggedIn = () => firstValueFrom(provider.isLoggedIn$);
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
jasmine.clock().install();
|
||||||
|
jasmine.clock().mockDate(new Date(NOW_MS));
|
||||||
|
|
||||||
|
const platform = {is: () => false} as any;
|
||||||
|
const configProvider = {} as any;
|
||||||
|
|
||||||
|
provider = new AuthProvider(platform, configProvider);
|
||||||
|
internals = provider as unknown as AuthProviderInternals;
|
||||||
|
|
||||||
|
(provider as any).authConfigValue = {
|
||||||
|
server_host: 'https://idp.example.org',
|
||||||
|
client_id: 'test-client',
|
||||||
|
redirect_url: 'https://app.example.org/callback',
|
||||||
|
scopes: 'openid profile',
|
||||||
|
pkce: true,
|
||||||
|
};
|
||||||
|
|
||||||
|
(provider as any).localConfiguration = new AuthorizationServiceConfiguration({
|
||||||
|
authorization_endpoint: 'https://idp.example.org/authorize',
|
||||||
|
token_endpoint: 'https://idp.example.org/token',
|
||||||
|
revocation_endpoint: 'https://idp.example.org/revoke',
|
||||||
|
});
|
||||||
|
|
||||||
|
// Never touch real storage or the network.
|
||||||
|
storageGetItem = spyOn(internals.storage, 'getItem').and.resolveTo(null);
|
||||||
|
storageSetItem = spyOn(internals.storage, 'setItem').and.resolveTo();
|
||||||
|
storageRemoveItem = spyOn(internals.storage, 'removeItem').and.resolveTo();
|
||||||
|
tokenRequest = spyOn(internals.tokenHandler, 'performTokenRequest').and.rejectWith(
|
||||||
|
new Error('Unexpected token request'),
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
jasmine.clock().uninstall();
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('isAuthenticated$', () => {
|
||||||
|
it('should provide false through isAuthenticated$ when there is no token response', async () => {
|
||||||
|
// Start authenticated so the test cannot pass on the initial value alone.
|
||||||
|
await givenLoadedToken(makeToken());
|
||||||
|
expect(await isAuthenticated()).toBeTrue();
|
||||||
|
|
||||||
|
await givenLoadedToken(null);
|
||||||
|
|
||||||
|
expect(internals.tokenSubject.value).toBeUndefined();
|
||||||
|
expect(await isAuthenticated()).toBeFalse();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('should provide true through isAuthenticated$ when access token is valid', async () => {
|
||||||
|
await givenLoadedToken(makeToken());
|
||||||
|
|
||||||
|
expect(await isAuthenticated()).toBeTrue();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('should provide false through isAuthenticated$ when access token is invalid', async () => {
|
||||||
|
await givenLoadedToken(makeToken({remainingSeconds: -TOKEN_LIFETIME}));
|
||||||
|
|
||||||
|
expect(await isAuthenticated()).toBeFalse();
|
||||||
|
// Still logged in: a refresh token is available.
|
||||||
|
expect(await isLoggedIn()).toBeTrue();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('should provide true through isAuthenticated$ after an expired token was refreshed', async () => {
|
||||||
|
await givenLoadedToken(makeToken({remainingSeconds: -60}));
|
||||||
|
expect(await isAuthenticated()).toBeFalse();
|
||||||
|
|
||||||
|
tokenRequest.and.resolveTo(makeToken({accessToken: 'new-access-token'}));
|
||||||
|
await provider.getValidToken();
|
||||||
|
|
||||||
|
expect(await isAuthenticated()).toBeTrue();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('getValidToken', () => {
|
||||||
|
it('returns the current token without refreshing when it is valid', async () => {
|
||||||
|
await givenLoadedToken(makeToken({accessToken: 'current-access-token'}));
|
||||||
|
|
||||||
|
const token = await provider.getValidToken();
|
||||||
|
|
||||||
|
expect(tokenRequest).not.toHaveBeenCalled();
|
||||||
|
expect(token.accessToken).toBe('current-access-token');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('refreshes the token when the access token is expired', async () => {
|
||||||
|
await givenLoadedToken(makeToken({remainingSeconds: -60}));
|
||||||
|
tokenRequest.and.resolveTo(
|
||||||
|
makeToken({accessToken: 'new-access-token', refreshToken: 'new-refresh-token'}),
|
||||||
|
);
|
||||||
|
|
||||||
|
const token = await provider.getValidToken();
|
||||||
|
|
||||||
|
expect(tokenRequest).toHaveBeenCalledTimes(1);
|
||||||
|
expect(token.accessToken).toBe('new-access-token');
|
||||||
|
expect(token.refreshToken).toBe('new-refresh-token');
|
||||||
|
expect(storageSetItem).toHaveBeenCalledOnceWith(TOKEN_RESPONSE_KEY, jasmine.any(String));
|
||||||
|
});
|
||||||
|
|
||||||
|
it('refreshes the token when the access token expires within the buffer', async () => {
|
||||||
|
// 5 minutes left, default buffer requires more than 10.
|
||||||
|
await givenLoadedToken(makeToken({remainingSeconds: 5 * 60}));
|
||||||
|
tokenRequest.and.resolveTo(makeToken({accessToken: 'new-access-token'}));
|
||||||
|
|
||||||
|
const token = await provider.getValidToken();
|
||||||
|
|
||||||
|
expect(tokenRequest).toHaveBeenCalledTimes(1);
|
||||||
|
expect(token.accessToken).toBe('new-access-token');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('keeps the previous refresh token when the refresh response contains none', async () => {
|
||||||
|
await givenLoadedToken(makeToken({remainingSeconds: -60, refreshToken: 'old-refresh-token'}));
|
||||||
|
tokenRequest.and.resolveTo(makeToken({accessToken: 'new-access-token', refreshToken: null}));
|
||||||
|
|
||||||
|
const token = await provider.getValidToken();
|
||||||
|
|
||||||
|
expect(token.accessToken).toBe('new-access-token');
|
||||||
|
expect(token.refreshToken).toBe('old-refresh-token');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('rejects without a request when the token is expired and has no refresh token', async () => {
|
||||||
|
await givenLoadedToken(makeToken({remainingSeconds: -60, refreshToken: null}));
|
||||||
|
|
||||||
|
await expectAsync(provider.getValidToken()).toBeRejectedWithError(/No Refresh Token Available/);
|
||||||
|
expect(tokenRequest).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('when refresh fails with invalid_grant', () => {
|
||||||
|
const refreshError = new AppAuthError(INVALID_GRANT);
|
||||||
|
|
||||||
|
beforeEach(async () => {
|
||||||
|
await givenLoadedToken(makeToken({remainingSeconds: -60, refreshToken: 'invalid-refresh-token'}));
|
||||||
|
expect(await isLoggedIn()).toBeTrue();
|
||||||
|
|
||||||
|
tokenRequest.and.rejectWith(refreshError);
|
||||||
|
|
||||||
|
await expectAsync(provider.getValidToken()).toBeRejectedWith(refreshError);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('changes isLoggedIn to false', async () => {
|
||||||
|
expect(await isLoggedIn()).toBeFalse();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('removes the token from storage', () => {
|
||||||
|
expect(storageRemoveItem).toHaveBeenCalledOnceWith(TOKEN_RESPONSE_KEY);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('clears the current token', () => {
|
||||||
|
expect(internals.tokenSubject.value).toBeUndefined();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('when refresh fails with a temporary error', () => {
|
||||||
|
// An AppAuthError that is not invalid_grant, e.g. a network failure.
|
||||||
|
const refreshError = new AppAuthError('Network Error');
|
||||||
|
|
||||||
|
beforeEach(async () => {
|
||||||
|
await givenLoadedToken(makeToken({remainingSeconds: -60}));
|
||||||
|
tokenRequest.and.rejectWith(refreshError);
|
||||||
|
|
||||||
|
await expectAsync(provider.getValidToken()).toBeRejectedWith(refreshError);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('keeps the user logged in', async () => {
|
||||||
|
expect(await isLoggedIn()).toBeTrue();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does not remove the token from storage', () => {
|
||||||
|
expect(storageRemoveItem).not.toHaveBeenCalled();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('keeps the current token for a later retry', () => {
|
||||||
|
expect(internals.tokenSubject.value?.refreshToken).toBe('refresh-token');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,526 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) 2023 StApps
|
|
||||||
* This program is free software: you can redistribute it and/or modify it
|
|
||||||
* under the terms of the GNU General Public License as published by the Free
|
|
||||||
* Software Foundation, version 3.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful, but WITHOUT
|
|
||||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
||||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
|
||||||
* more details.
|
|
||||||
*
|
|
||||||
* You should have received a copy of the GNU General Public License along with
|
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
|
||||||
*/
|
|
||||||
// Temporary use of direct file until the version with bug fix is released
|
|
||||||
// https://github.com/wi3land/ionic-appauth/blob/3716f4fc6b5491b0b75e049be0a47a5af8c4da6f/src/auth-service.ts
|
|
||||||
// Bug: https://github.com/wi3land/ionic-appauth/issues/154
|
|
||||||
import {
|
|
||||||
AuthorizationError,
|
|
||||||
AuthorizationNotifier,
|
|
||||||
AuthorizationRequest,
|
|
||||||
AuthorizationRequestHandler,
|
|
||||||
AuthorizationRequestJson,
|
|
||||||
AuthorizationResponse,
|
|
||||||
AuthorizationServiceConfiguration,
|
|
||||||
BaseTokenRequestHandler,
|
|
||||||
DefaultCrypto,
|
|
||||||
GRANT_TYPE_AUTHORIZATION_CODE,
|
|
||||||
GRANT_TYPE_REFRESH_TOKEN,
|
|
||||||
JQueryRequestor,
|
|
||||||
LocalStorageBackend,
|
|
||||||
Requestor,
|
|
||||||
RevokeTokenRequest,
|
|
||||||
RevokeTokenRequestJson,
|
|
||||||
StorageBackend,
|
|
||||||
StringMap,
|
|
||||||
TokenRequest,
|
|
||||||
TokenRequestHandler,
|
|
||||||
TokenRequestJson,
|
|
||||||
TokenResponse,
|
|
||||||
} from '@openid/appauth';
|
|
||||||
import {
|
|
||||||
ActionHistoryObserver,
|
|
||||||
AuthActionBuilder,
|
|
||||||
AuthActions,
|
|
||||||
AuthObserver,
|
|
||||||
AUTHORIZATION_RESPONSE_KEY,
|
|
||||||
AuthSubject,
|
|
||||||
BaseAuthObserver,
|
|
||||||
Browser,
|
|
||||||
DefaultBrowser,
|
|
||||||
EndSessionHandler,
|
|
||||||
EndSessionRequest,
|
|
||||||
EndSessionRequestJson,
|
|
||||||
IAuthAction,
|
|
||||||
IAuthConfig,
|
|
||||||
IAuthService,
|
|
||||||
IonicAuthorizationRequestHandler,
|
|
||||||
IonicEndSessionHandler,
|
|
||||||
IonicUserInfoHandler,
|
|
||||||
SessionObserver,
|
|
||||||
UserInfoHandler,
|
|
||||||
} from 'ionic-appauth';
|
|
||||||
import {BehaviorSubject, Observable} from 'rxjs';
|
|
||||||
|
|
||||||
const TOKEN_RESPONSE_KEY = 'token_response';
|
|
||||||
const AUTH_EXPIRY_BUFFER = 10 * 60 * -1; // 10 mins in seconds
|
|
||||||
|
|
||||||
export abstract class AuthService implements IAuthService {
|
|
||||||
private _configuration?: AuthorizationServiceConfiguration;
|
|
||||||
|
|
||||||
private _authConfig?: IAuthConfig;
|
|
||||||
|
|
||||||
private _authSubject: AuthSubject = new AuthSubject();
|
|
||||||
|
|
||||||
private _actionHistory: ActionHistoryObserver = new ActionHistoryObserver();
|
|
||||||
|
|
||||||
private _session: SessionObserver = new SessionObserver();
|
|
||||||
|
|
||||||
private _authSubjectV2 = new BehaviorSubject<IAuthAction>(AuthActionBuilder.Init());
|
|
||||||
|
|
||||||
private _tokenSubject = new BehaviorSubject<TokenResponse | undefined>(undefined);
|
|
||||||
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
||||||
private _userSubject = new BehaviorSubject<any>(undefined);
|
|
||||||
|
|
||||||
private _authenticatedSubject = new BehaviorSubject<boolean>(false);
|
|
||||||
|
|
||||||
private _loggedInSubject = new BehaviorSubject<boolean>(false);
|
|
||||||
|
|
||||||
private _initComplete = new BehaviorSubject<boolean>(false);
|
|
||||||
|
|
||||||
protected tokenHandler: TokenRequestHandler;
|
|
||||||
|
|
||||||
protected userInfoHandler: UserInfoHandler;
|
|
||||||
|
|
||||||
protected requestHandler: AuthorizationRequestHandler;
|
|
||||||
|
|
||||||
protected endSessionHandler: EndSessionHandler;
|
|
||||||
|
|
||||||
constructor(
|
|
||||||
protected browser: Browser = new DefaultBrowser(),
|
|
||||||
protected storage: StorageBackend = new LocalStorageBackend(),
|
|
||||||
protected requestor: Requestor = new JQueryRequestor(),
|
|
||||||
) {
|
|
||||||
this.tokenHandler = new BaseTokenRequestHandler(requestor);
|
|
||||||
this.userInfoHandler = new IonicUserInfoHandler(requestor);
|
|
||||||
this.requestHandler = new IonicAuthorizationRequestHandler(browser, storage);
|
|
||||||
this.endSessionHandler = new IonicEndSessionHandler(browser);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @deprecated independant observers have been replaced by Rxjs
|
|
||||||
* this will be removed in a future release
|
|
||||||
* please use $ suffixed observers in future
|
|
||||||
*/
|
|
||||||
get history(): IAuthAction[] {
|
|
||||||
return [...this._actionHistory.history];
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @deprecated independant observers have been replaced by Rxjs
|
|
||||||
* this will be removed in a future release
|
|
||||||
* please use $ suffixed observers in future
|
|
||||||
*/
|
|
||||||
get session() {
|
|
||||||
return this._session.session;
|
|
||||||
}
|
|
||||||
|
|
||||||
get token$(): Observable<TokenResponse | undefined> {
|
|
||||||
return this._tokenSubject.asObservable();
|
|
||||||
}
|
|
||||||
|
|
||||||
get isAuthenticated$(): Observable<boolean> {
|
|
||||||
return this._authenticatedSubject.asObservable();
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Similar to isAuthenticated$, but will also return true if the token is expired
|
|
||||||
*/
|
|
||||||
get isLoggedIn$(): Observable<boolean> {
|
|
||||||
return this._loggedInSubject.asObservable();
|
|
||||||
}
|
|
||||||
|
|
||||||
get initComplete$(): Observable<boolean> {
|
|
||||||
return this._initComplete.asObservable();
|
|
||||||
}
|
|
||||||
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
||||||
get user$(): Observable<any> {
|
|
||||||
return this._userSubject.asObservable();
|
|
||||||
}
|
|
||||||
|
|
||||||
get events$(): Observable<IAuthAction> {
|
|
||||||
return this._authSubjectV2.asObservable();
|
|
||||||
}
|
|
||||||
|
|
||||||
get authConfig(): IAuthConfig {
|
|
||||||
if (!this._authConfig) throw new Error('AuthConfig Not Defined');
|
|
||||||
|
|
||||||
return this._authConfig;
|
|
||||||
}
|
|
||||||
|
|
||||||
set authConfig(value: IAuthConfig) {
|
|
||||||
this._authConfig = value;
|
|
||||||
}
|
|
||||||
|
|
||||||
get configuration(): Promise<AuthorizationServiceConfiguration> {
|
|
||||||
if (!this._configuration) {
|
|
||||||
return AuthorizationServiceConfiguration.fetchFromIssuer(
|
|
||||||
this.authConfig.server_host,
|
|
||||||
this.requestor,
|
|
||||||
).catch(() => {
|
|
||||||
throw new Error('Unable To Obtain Server Configuration');
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
if (this._configuration == undefined) {
|
|
||||||
throw new Error('Unable To Obtain Server Configuration');
|
|
||||||
} else {
|
|
||||||
return Promise.resolve(this._configuration);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
public async init() {
|
|
||||||
this.setupAuthorizationNotifier();
|
|
||||||
this.loadTokenFromStorage();
|
|
||||||
this.addActionObserver(this._actionHistory);
|
|
||||||
this.addActionObserver(this._session);
|
|
||||||
}
|
|
||||||
|
|
||||||
protected notifyActionListers(action: IAuthAction) {
|
|
||||||
/* eslint-disable unicorn/no-useless-undefined */
|
|
||||||
switch (action.action) {
|
|
||||||
case AuthActions.SignInFailed:
|
|
||||||
case AuthActions.SignOutSuccess:
|
|
||||||
case AuthActions.SignOutFailed: {
|
|
||||||
this._tokenSubject.next(undefined);
|
|
||||||
this._userSubject.next(undefined);
|
|
||||||
this._authenticatedSubject.next(false);
|
|
||||||
this._loggedInSubject.next(false);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case AuthActions.LoadTokenFromStorageFailed: {
|
|
||||||
this._tokenSubject.next(undefined);
|
|
||||||
this._userSubject.next(undefined);
|
|
||||||
this._authenticatedSubject.next(false);
|
|
||||||
this._loggedInSubject.next(false);
|
|
||||||
this._initComplete.next(true);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case AuthActions.SignInSuccess:
|
|
||||||
case AuthActions.RefreshSuccess: {
|
|
||||||
this._tokenSubject.next(action.tokenResponse);
|
|
||||||
this._authenticatedSubject.next(true);
|
|
||||||
this._loggedInSubject.next(true);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case AuthActions.LoadTokenFromStorageSuccess: {
|
|
||||||
this._tokenSubject.next(action.tokenResponse);
|
|
||||||
this._authenticatedSubject.next((action.tokenResponse as TokenResponse).isValid(0));
|
|
||||||
this._loggedInSubject.next(true);
|
|
||||||
this._initComplete.next(true);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case AuthActions.RevokeTokensSuccess: {
|
|
||||||
this._tokenSubject.next(undefined);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case AuthActions.LoadUserInfoSuccess: {
|
|
||||||
this._userSubject.next(action.user);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case AuthActions.LoadUserInfoFailed: {
|
|
||||||
this._userSubject.next(undefined);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
this._authSubjectV2.next(action);
|
|
||||||
this._authSubject.notify(action);
|
|
||||||
}
|
|
||||||
|
|
||||||
protected setupAuthorizationNotifier() {
|
|
||||||
const notifier = new AuthorizationNotifier();
|
|
||||||
this.requestHandler.setAuthorizationNotifier(notifier);
|
|
||||||
notifier.setAuthorizationListener((request, response, error) =>
|
|
||||||
this.onAuthorizationNotification(request, response, error),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
protected onAuthorizationNotification(
|
|
||||||
request: AuthorizationRequest,
|
|
||||||
response: AuthorizationResponse | null,
|
|
||||||
error: AuthorizationError | null,
|
|
||||||
) {
|
|
||||||
const codeVerifier: string | undefined =
|
|
||||||
request.internal != undefined && this.authConfig.pkce ? request.internal.code_verifier : undefined;
|
|
||||||
|
|
||||||
if (response != undefined) {
|
|
||||||
this.requestAccessToken(response.code, codeVerifier);
|
|
||||||
} else if (error == undefined) {
|
|
||||||
throw new Error('Unknown Error With Authentication');
|
|
||||||
} else {
|
|
||||||
throw new Error(error.errorDescription);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async internalAuthorizationCallback(url: string) {
|
|
||||||
this.browser.closeWindow();
|
|
||||||
await this.storage.setItem(AUTHORIZATION_RESPONSE_KEY, url);
|
|
||||||
return this.requestHandler.completeAuthorizationRequestIfPossible();
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async internalEndSessionCallback() {
|
|
||||||
this.browser.closeWindow();
|
|
||||||
this._actionHistory.clear();
|
|
||||||
this.notifyActionListers(AuthActionBuilder.SignOutSuccess());
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async performEndSessionRequest(state?: string): Promise<void> {
|
|
||||||
if (this._tokenSubject.value == undefined) {
|
|
||||||
//if user has no token they should not be logged in in the first place
|
|
||||||
this.endSessionCallback();
|
|
||||||
} else {
|
|
||||||
const requestJson: EndSessionRequestJson = {
|
|
||||||
postLogoutRedirectURI: this.authConfig.end_session_redirect_url,
|
|
||||||
idTokenHint: this._tokenSubject.value.idToken || '',
|
|
||||||
state: state || undefined,
|
|
||||||
};
|
|
||||||
|
|
||||||
const request: EndSessionRequest = new EndSessionRequest(requestJson);
|
|
||||||
const returnedUrl: string | undefined = await this.endSessionHandler.performEndSessionRequest(
|
|
||||||
await this.configuration,
|
|
||||||
request,
|
|
||||||
);
|
|
||||||
|
|
||||||
//callback may come from showWindow or via another method
|
|
||||||
if (returnedUrl != undefined) {
|
|
||||||
this.endSessionCallback();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async performAuthorizationRequest(authExtras?: StringMap, state?: string): Promise<void> {
|
|
||||||
const requestJson: AuthorizationRequestJson = {
|
|
||||||
response_type: AuthorizationRequest.RESPONSE_TYPE_CODE,
|
|
||||||
client_id: this.authConfig.client_id,
|
|
||||||
redirect_uri: this.authConfig.redirect_url,
|
|
||||||
scope: this.authConfig.scopes,
|
|
||||||
extras: authExtras,
|
|
||||||
state: state || undefined,
|
|
||||||
};
|
|
||||||
|
|
||||||
const request = new AuthorizationRequest(requestJson, new DefaultCrypto(), this.authConfig.pkce);
|
|
||||||
|
|
||||||
if (this.authConfig.pkce) await request.setupCodeVerifier();
|
|
||||||
|
|
||||||
return this.requestHandler.performAuthorizationRequest(await this.configuration, request);
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async requestAccessToken(code: string, codeVerifier?: string): Promise<void> {
|
|
||||||
const requestJSON: TokenRequestJson = {
|
|
||||||
grant_type: GRANT_TYPE_AUTHORIZATION_CODE,
|
|
||||||
code: code,
|
|
||||||
refresh_token: undefined,
|
|
||||||
redirect_uri: this.authConfig.redirect_url,
|
|
||||||
client_id: this.authConfig.client_id,
|
|
||||||
extras: codeVerifier
|
|
||||||
? {
|
|
||||||
code_verifier: codeVerifier,
|
|
||||||
client_secret: this.authConfig.client_secret as string,
|
|
||||||
}
|
|
||||||
: {
|
|
||||||
client_secret: this.authConfig.client_secret as string,
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const token: TokenResponse = await this.tokenHandler.performTokenRequest(
|
|
||||||
await this.configuration,
|
|
||||||
new TokenRequest(requestJSON),
|
|
||||||
);
|
|
||||||
await this.storage.setItem(TOKEN_RESPONSE_KEY, JSON.stringify(token.toJson()));
|
|
||||||
this.notifyActionListers(AuthActionBuilder.SignInSuccess(token));
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async requestTokenRefresh() {
|
|
||||||
if (!this._tokenSubject.value) {
|
|
||||||
throw new Error('No Token Defined!');
|
|
||||||
}
|
|
||||||
|
|
||||||
const requestJSON: TokenRequestJson = {
|
|
||||||
grant_type: GRANT_TYPE_REFRESH_TOKEN,
|
|
||||||
refresh_token: this._tokenSubject.value?.refreshToken,
|
|
||||||
redirect_uri: this.authConfig.redirect_url,
|
|
||||||
client_id: this.authConfig.client_id,
|
|
||||||
};
|
|
||||||
|
|
||||||
const token: TokenResponse = await this.tokenHandler.performTokenRequest(
|
|
||||||
await this.configuration,
|
|
||||||
new TokenRequest(requestJSON),
|
|
||||||
);
|
|
||||||
if (!token.accessToken) {
|
|
||||||
throw new Error('No Access Token Defined In Refresh Response');
|
|
||||||
}
|
|
||||||
await this.storage.setItem(TOKEN_RESPONSE_KEY, JSON.stringify(token.toJson()));
|
|
||||||
this.notifyActionListers(AuthActionBuilder.RefreshSuccess(token));
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async internalLoadTokenFromStorage() {
|
|
||||||
let token: TokenResponse | undefined;
|
|
||||||
const tokenResponseString: string | null = await this.storage.getItem(TOKEN_RESPONSE_KEY);
|
|
||||||
|
|
||||||
if (tokenResponseString != undefined) {
|
|
||||||
token = new TokenResponse(JSON.parse(tokenResponseString));
|
|
||||||
|
|
||||||
if (token) {
|
|
||||||
return this.notifyActionListers(AuthActionBuilder.LoadTokenFromStorageSuccess(token));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
throw new Error('No Token In Storage');
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async requestTokenRevoke() {
|
|
||||||
const revokeRefreshJson: RevokeTokenRequestJson = {
|
|
||||||
token: (this._tokenSubject.value as TokenResponse).refreshToken as string,
|
|
||||||
token_type_hint: 'refresh_token',
|
|
||||||
client_id: this.authConfig.client_id,
|
|
||||||
};
|
|
||||||
|
|
||||||
const revokeAccessJson: RevokeTokenRequestJson = {
|
|
||||||
token: (this._tokenSubject.value as TokenResponse).accessToken,
|
|
||||||
token_type_hint: 'access_token',
|
|
||||||
client_id: this.authConfig.client_id,
|
|
||||||
};
|
|
||||||
|
|
||||||
await this.tokenHandler.performRevokeTokenRequest(
|
|
||||||
await this.configuration,
|
|
||||||
new RevokeTokenRequest(revokeRefreshJson),
|
|
||||||
);
|
|
||||||
await this.tokenHandler.performRevokeTokenRequest(
|
|
||||||
await this.configuration,
|
|
||||||
new RevokeTokenRequest(revokeAccessJson),
|
|
||||||
);
|
|
||||||
await this.storage.removeItem(TOKEN_RESPONSE_KEY);
|
|
||||||
this.notifyActionListers(AuthActionBuilder.RevokeTokensSuccess());
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async internalRequestUserInfo() {
|
|
||||||
if (this._tokenSubject.value) {
|
|
||||||
const userInfo = await this.userInfoHandler.performUserInfoRequest(
|
|
||||||
await this.configuration,
|
|
||||||
this._tokenSubject.value,
|
|
||||||
);
|
|
||||||
this.notifyActionListers(AuthActionBuilder.LoadUserInfoSuccess(userInfo));
|
|
||||||
} else {
|
|
||||||
throw new Error('No Token Available');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
public async loadTokenFromStorage() {
|
|
||||||
await this.internalLoadTokenFromStorage().catch(error => {
|
|
||||||
this.notifyActionListers(AuthActionBuilder.LoadTokenFromStorageFailed(error));
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
public async signIn(authExtras?: StringMap, state?: string) {
|
|
||||||
await this.performAuthorizationRequest(authExtras, state).catch(error => {
|
|
||||||
this.notifyActionListers(AuthActionBuilder.SignInFailed(error));
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
public async signOut(state?: string, revokeTokens?: boolean) {
|
|
||||||
if (revokeTokens) {
|
|
||||||
await this.revokeTokens();
|
|
||||||
}
|
|
||||||
|
|
||||||
await this.storage.removeItem(TOKEN_RESPONSE_KEY);
|
|
||||||
|
|
||||||
if ((await this.configuration).endSessionEndpoint) {
|
|
||||||
await this.performEndSessionRequest(state).catch(error => {
|
|
||||||
this.notifyActionListers(AuthActionBuilder.SignOutFailed(error));
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
public async revokeTokens() {
|
|
||||||
await this.requestTokenRevoke().catch(error => {
|
|
||||||
this.storage.removeItem(TOKEN_RESPONSE_KEY);
|
|
||||||
this.notifyActionListers(AuthActionBuilder.RevokeTokensFailed(error));
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
public async refreshToken() {
|
|
||||||
await this.requestTokenRefresh().catch(error => {
|
|
||||||
this.notifyActionListers(AuthActionBuilder.RefreshFailed(error));
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
public async loadUserInfo() {
|
|
||||||
await this.internalRequestUserInfo().catch(error => {
|
|
||||||
this.notifyActionListers(AuthActionBuilder.LoadUserInfoFailed(error));
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
public authorizationCallback(callbackUrl: string): void {
|
|
||||||
this.internalAuthorizationCallback(callbackUrl).catch(error => {
|
|
||||||
this.notifyActionListers(AuthActionBuilder.SignInFailed(error));
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
public endSessionCallback(): void {
|
|
||||||
this.internalEndSessionCallback().catch(error => {
|
|
||||||
this.notifyActionListers(AuthActionBuilder.SignOutFailed(error));
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
public async getValidToken(buffer: number = AUTH_EXPIRY_BUFFER): Promise<TokenResponse> {
|
|
||||||
if (this._tokenSubject.value) {
|
|
||||||
if (this._tokenSubject.value.isValid(buffer)) {
|
|
||||||
return this._tokenSubject.value;
|
|
||||||
} else {
|
|
||||||
await this.refreshToken();
|
|
||||||
if (this._tokenSubject.value) {
|
|
||||||
return this._tokenSubject.value;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
throw new Error('Unable To Obtain Valid Token');
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @deprecated independant observers have been replaced by Rxjs
|
|
||||||
* this will be removed in a future release
|
|
||||||
* please use $ suffixed observers in future
|
|
||||||
*/
|
|
||||||
public addActionListener(function_: (action: IAuthAction) => void): AuthObserver {
|
|
||||||
const observer: AuthObserver = AuthObserver.Create(function_);
|
|
||||||
this.addActionObserver(observer);
|
|
||||||
return observer;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @deprecated independant observers have been replaced by Rxjs
|
|
||||||
* this will be removed in a future release
|
|
||||||
* please use $ suffixed observers in future
|
|
||||||
*/
|
|
||||||
public addActionObserver(observer: BaseAuthObserver): void {
|
|
||||||
if (this._actionHistory.lastAction) {
|
|
||||||
observer.update(this._actionHistory.lastAction);
|
|
||||||
}
|
|
||||||
|
|
||||||
this._authSubject.attach(observer);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @deprecated independant observers have been replaced by Rxjs
|
|
||||||
* this will be removed in a future release
|
|
||||||
* please use $ suffixed observers in future
|
|
||||||
*/
|
|
||||||
public removeActionObserver(observer: BaseAuthObserver): void {
|
|
||||||
this._authSubject.detach(observer);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,270 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (C) 2026 StApps
|
||||||
|
* This program is free software: you can redistribute it and/or modify it
|
||||||
|
* under the terms of the GNU General Public License as published by the Free
|
||||||
|
* Software Foundation, version 3.
|
||||||
|
*
|
||||||
|
* This program is distributed in the hope that it will be useful, but WITHOUT
|
||||||
|
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||||
|
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
||||||
|
* more details.
|
||||||
|
*
|
||||||
|
* You should have received a copy of the GNU General Public License along with
|
||||||
|
* this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
|
*/
|
||||||
|
|
||||||
|
import {Browser} from '@capacitor/browser';
|
||||||
|
import {
|
||||||
|
AuthorizationError,
|
||||||
|
AuthorizationErrorJson,
|
||||||
|
AuthorizationRequest,
|
||||||
|
AuthorizationRequestHandler,
|
||||||
|
AuthorizationRequestJson,
|
||||||
|
AuthorizationRequestResponse,
|
||||||
|
AuthorizationResponse,
|
||||||
|
AuthorizationResponseJson,
|
||||||
|
AuthorizationServiceConfiguration,
|
||||||
|
BasicQueryStringUtils,
|
||||||
|
DefaultCrypto,
|
||||||
|
StorageBackend,
|
||||||
|
StringMap,
|
||||||
|
} from '@openid/appauth';
|
||||||
|
|
||||||
|
const AUTHORIZATION_REQUEST_KEY =
|
||||||
|
'appauth_capacitor_authorization_request';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* AppAuth authorization request handler for native Capacitor applications.
|
||||||
|
*
|
||||||
|
* AppAuth-JS handles:
|
||||||
|
* - state generation and validation data
|
||||||
|
* - PKCE code_verifier / code_challenge
|
||||||
|
* - authorization URL construction
|
||||||
|
* - AuthorizationNotifier
|
||||||
|
*
|
||||||
|
* This handler adds the Capacitor-specific parts:
|
||||||
|
* - persist the pending authorization request
|
||||||
|
* - open the authorization URL using @capacitor/browser
|
||||||
|
* - process the callback URL delivered through appUrlOpen
|
||||||
|
*/
|
||||||
|
export class CapacitorAuthorizationRequestHandler extends AuthorizationRequestHandler {
|
||||||
|
private callbackUrl?: string;
|
||||||
|
|
||||||
|
constructor(private readonly storage: StorageBackend) {
|
||||||
|
super(
|
||||||
|
new BasicQueryStringUtils(),
|
||||||
|
new DefaultCrypto(),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public async performAuthorizationRequest(
|
||||||
|
configuration: AuthorizationServiceConfiguration,
|
||||||
|
request: AuthorizationRequest,
|
||||||
|
): Promise<void> {
|
||||||
|
/*
|
||||||
|
* Important:
|
||||||
|
*
|
||||||
|
* toJson() calls setupCodeVerifier() internally.
|
||||||
|
* Therefore PKCE is initialized before buildRequestUrl()
|
||||||
|
* constructs the authorization URL.
|
||||||
|
*/
|
||||||
|
const requestJson =
|
||||||
|
await request.toJson();
|
||||||
|
|
||||||
|
await this.storage.setItem(
|
||||||
|
AUTHORIZATION_REQUEST_KEY,
|
||||||
|
JSON.stringify(requestJson),
|
||||||
|
);
|
||||||
|
|
||||||
|
const url =
|
||||||
|
this.buildRequestUrl(
|
||||||
|
configuration,
|
||||||
|
request,
|
||||||
|
);
|
||||||
|
|
||||||
|
await Browser.open({url});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Completes the authorization flow using the URL received from
|
||||||
|
* Capacitor's App.addListener('appUrlOpen', ...).
|
||||||
|
*/
|
||||||
|
public async completeAuthorizationRequestFromUrl(
|
||||||
|
callbackUrl: string,
|
||||||
|
): Promise<void> {
|
||||||
|
this.callbackUrl = callbackUrl;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The deep link has returned control to the application.
|
||||||
|
* Close the SFSafariViewController / Custom Tab if it is still open.
|
||||||
|
*/
|
||||||
|
try {
|
||||||
|
await Browser.close();
|
||||||
|
} catch {
|
||||||
|
// Browser might already have been closed by the platform.
|
||||||
|
}
|
||||||
|
|
||||||
|
await this.completeAuthorizationRequestIfPossible();
|
||||||
|
}
|
||||||
|
|
||||||
|
protected async completeAuthorizationRequest():
|
||||||
|
Promise<AuthorizationRequestResponse | null> {
|
||||||
|
if (!this.callbackUrl) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
const storedRequest =
|
||||||
|
await this.storage.getItem(
|
||||||
|
AUTHORIZATION_REQUEST_KEY,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!storedRequest) {
|
||||||
|
this.callbackUrl = undefined;
|
||||||
|
|
||||||
|
throw new Error(
|
||||||
|
'No pending authorization request found.',
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const requestJson =
|
||||||
|
JSON.parse(
|
||||||
|
storedRequest,
|
||||||
|
) as AuthorizationRequestJson;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The serialized request also contains `internal`, including
|
||||||
|
* AppAuth's PKCE code_verifier.
|
||||||
|
*/
|
||||||
|
const request =
|
||||||
|
new AuthorizationRequest(requestJson);
|
||||||
|
|
||||||
|
const parameters =
|
||||||
|
this.parseCallbackUrl(
|
||||||
|
this.callbackUrl,
|
||||||
|
);
|
||||||
|
|
||||||
|
const state =
|
||||||
|
parameters['state'];
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Never accept an authorization response for a different request.
|
||||||
|
*/
|
||||||
|
if (!state || state !== request.state) {
|
||||||
|
this.callbackUrl = undefined;
|
||||||
|
|
||||||
|
throw new Error(
|
||||||
|
'Authorization response state does not match the authorization request.',
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const error =
|
||||||
|
parameters['error'];
|
||||||
|
|
||||||
|
let response:
|
||||||
|
AuthorizationResponse | null = null;
|
||||||
|
|
||||||
|
let authorizationError:
|
||||||
|
AuthorizationError | null = null;
|
||||||
|
|
||||||
|
if (error) {
|
||||||
|
const errorJson:
|
||||||
|
AuthorizationErrorJson = {
|
||||||
|
error,
|
||||||
|
|
||||||
|
error_description:
|
||||||
|
parameters[
|
||||||
|
'error_description'
|
||||||
|
],
|
||||||
|
|
||||||
|
error_uri:
|
||||||
|
parameters['error_uri'],
|
||||||
|
|
||||||
|
state,
|
||||||
|
};
|
||||||
|
|
||||||
|
authorizationError =
|
||||||
|
new AuthorizationError(
|
||||||
|
errorJson,
|
||||||
|
);
|
||||||
|
} else {
|
||||||
|
const code =
|
||||||
|
parameters['code'];
|
||||||
|
|
||||||
|
if (!code) {
|
||||||
|
this.callbackUrl = undefined;
|
||||||
|
|
||||||
|
throw new Error(
|
||||||
|
'Authorization callback contains neither an authorization code nor an error.',
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const responseJson:
|
||||||
|
AuthorizationResponseJson = {
|
||||||
|
code,
|
||||||
|
state,
|
||||||
|
};
|
||||||
|
|
||||||
|
response =
|
||||||
|
new AuthorizationResponse(
|
||||||
|
responseJson,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The response has been successfully associated with the
|
||||||
|
* pending request. It can now be consumed exactly once.
|
||||||
|
*/
|
||||||
|
await this.storage.removeItem(
|
||||||
|
AUTHORIZATION_REQUEST_KEY,
|
||||||
|
);
|
||||||
|
|
||||||
|
this.callbackUrl = undefined;
|
||||||
|
|
||||||
|
return {
|
||||||
|
request,
|
||||||
|
response,
|
||||||
|
error: authorizationError,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
private parseCallbackUrl(
|
||||||
|
callbackUrl: string,
|
||||||
|
): StringMap {
|
||||||
|
const result: StringMap = {};
|
||||||
|
|
||||||
|
const url = new URL(callbackUrl);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Authorization Code Flow normally returns code/state in
|
||||||
|
* the query string:
|
||||||
|
*
|
||||||
|
* openstapps:/callback?code=...&state=...
|
||||||
|
*/
|
||||||
|
url.searchParams.forEach(
|
||||||
|
(value, key) => {
|
||||||
|
result[key] = value;
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Also accept parameters in the fragment as a fallback.
|
||||||
|
*/
|
||||||
|
if (url.hash.length > 1) {
|
||||||
|
const hash =
|
||||||
|
url.hash.substring(1);
|
||||||
|
|
||||||
|
const hashParameters =
|
||||||
|
new URLSearchParams(hash);
|
||||||
|
|
||||||
|
hashParameters.forEach(
|
||||||
|
(value, key) => {
|
||||||
|
if (!(key in result)) {
|
||||||
|
result[key] = value;
|
||||||
|
}
|
||||||
|
},
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -13,61 +13,77 @@
|
|||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
* this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
import {Requestor} from '@openid/appauth';
|
import {
|
||||||
import {CapacitorHttp, HttpHeaders, HttpResponse} from '@capacitor/core';
|
AppAuthError,
|
||||||
import {XhrSettings} from 'ionic-appauth/lib/cordova';
|
Requestor,
|
||||||
|
} from '@openid/appauth';
|
||||||
|
import {
|
||||||
|
CapacitorHttp,
|
||||||
|
HttpHeaders,
|
||||||
|
HttpOptions,
|
||||||
|
} from '@capacitor/core';
|
||||||
|
|
||||||
// REQUIRES CAPACITOR PLUGIN
|
type XhrSettings = Parameters<Requestor['xhr']>[0];
|
||||||
// @capacitor-community/http
|
|
||||||
export class CapacitorRequestor extends Requestor {
|
|
||||||
constructor() {
|
|
||||||
super();
|
|
||||||
}
|
|
||||||
|
|
||||||
|
export class CapacitorRequestor implements Requestor {
|
||||||
public async xhr<T>(settings: XhrSettings): Promise<T> {
|
public async xhr<T>(settings: XhrSettings): Promise<T> {
|
||||||
if (!settings.method) settings.method = 'GET';
|
if (!settings.url) {
|
||||||
|
throw new AppAuthError('A URL must be provided.');
|
||||||
switch (settings.method) {
|
|
||||||
case 'GET': {
|
|
||||||
return this.get(settings.url, settings.headers);
|
|
||||||
}
|
|
||||||
case 'POST': {
|
|
||||||
return this.post(settings.url, settings.data, settings.headers);
|
|
||||||
}
|
|
||||||
case 'PUT': {
|
|
||||||
return this.put(settings.url, settings.data, settings.headers);
|
|
||||||
}
|
|
||||||
case 'DELETE': {
|
|
||||||
return this.delete(settings.url, settings.headers);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async get<T>(url: string, headers: HttpHeaders) {
|
const method = (settings.method ?? 'GET').toUpperCase();
|
||||||
return CapacitorHttp.get({url, headers}).then((response: HttpResponse) => response.data as T);
|
const url = new URL(settings.url);
|
||||||
}
|
|
||||||
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
let data: unknown;
|
||||||
private async post<T>(url: string, data: any, headers: HttpHeaders) {
|
|
||||||
return CapacitorHttp.post({
|
if (settings.data) {
|
||||||
url,
|
if (method === 'POST') {
|
||||||
data,
|
data = settings.data;
|
||||||
headers,
|
} else {
|
||||||
}).then((response: HttpResponse) => {
|
const searchParams = new URLSearchParams(settings.data);
|
||||||
return response.data as T;
|
|
||||||
|
searchParams.forEach((value, key) => {
|
||||||
|
url.searchParams.append(key, value);
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
||||||
private async put<T>(url: string, data: any, headers: HttpHeaders) {
|
|
||||||
return CapacitorHttp.put({
|
|
||||||
url,
|
|
||||||
data,
|
|
||||||
headers,
|
|
||||||
}).then((response: HttpResponse) => response.data as T);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async delete<T>(url: string, headers: HttpHeaders) {
|
const options: HttpOptions = {
|
||||||
return CapacitorHttp.delete({url, headers}).then((response: HttpResponse) => response.data as T);
|
url: url.toString(),
|
||||||
|
method,
|
||||||
|
headers: this.getHeaders(settings.headers),
|
||||||
|
data,
|
||||||
|
};
|
||||||
|
|
||||||
|
if (settings.dataType?.toLowerCase() === 'json') {
|
||||||
|
options.responseType = 'json';
|
||||||
|
}
|
||||||
|
|
||||||
|
const response = await CapacitorHttp.request(options);
|
||||||
|
|
||||||
|
if (response.status < 200 || response.status >= 300) {
|
||||||
|
throw new AppAuthError(
|
||||||
|
`HTTP ${response.status}`,
|
||||||
|
response.data,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return response.data as T;
|
||||||
|
}
|
||||||
|
|
||||||
|
private getHeaders(headers: XhrSettings['headers']): HttpHeaders {
|
||||||
|
const result: HttpHeaders = {};
|
||||||
|
|
||||||
|
if (!headers) {
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const [key, value] of Object.entries(headers)) {
|
||||||
|
if (value !== undefined && value !== null) {
|
||||||
|
result[key] = String(value);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return result;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,104 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) 2023 StApps
|
|
||||||
* This program is free software: you can redistribute it and/or modify it
|
|
||||||
* under the terms of the GNU General Public License as published by the Free
|
|
||||||
* Software Foundation, version 3.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful, but WITHOUT
|
|
||||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
||||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
|
||||||
* more details.
|
|
||||||
*
|
|
||||||
* You should have received a copy of the GNU General Public License along with
|
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
|
||||||
*/
|
|
||||||
import {TestBed} from '@angular/core/testing';
|
|
||||||
import {ConfigProvider} from '../config/config.provider';
|
|
||||||
import {StorageProvider} from '../storage/storage.provider';
|
|
||||||
import {DefaultAuthService} from './default-auth.service';
|
|
||||||
import {Browser} from 'ionic-appauth';
|
|
||||||
import {nowInSeconds, Requestor, StorageBackend} from '@openid/appauth';
|
|
||||||
import {TranslateService} from '@ngx-translate/core';
|
|
||||||
import {StAppsWebHttpClient} from '../data/stapps-web-http-client.provider';
|
|
||||||
import {provideHttpClient, withInterceptorsFromDi} from '@angular/common/http';
|
|
||||||
import {IonicStorage} from 'ionic-appauth/lib';
|
|
||||||
import {RouterModule} from '@angular/router';
|
|
||||||
import {LoggerTestingModule} from 'ngx-logger/testing';
|
|
||||||
|
|
||||||
describe('AuthService', () => {
|
|
||||||
let defaultAuthService: DefaultAuthService;
|
|
||||||
let storageBackendSpy: jasmine.SpyObj<StorageBackend>;
|
|
||||||
const storageProviderSpy = jasmine.createSpyObj('StorageProvider', ['init', 'get', 'has', 'put', 'search']);
|
|
||||||
const translateServiceSpy = jasmine.createSpyObj('TranslateService', ['setDefaultLang', 'use']);
|
|
||||||
|
|
||||||
beforeEach(() => {
|
|
||||||
storageBackendSpy = jasmine.createSpyObj('StorageBackend', ['getItem']);
|
|
||||||
|
|
||||||
TestBed.configureTestingModule({
|
|
||||||
imports: [LoggerTestingModule, RouterModule.forRoot([])],
|
|
||||||
providers: [
|
|
||||||
StAppsWebHttpClient,
|
|
||||||
{
|
|
||||||
provide: TranslateService,
|
|
||||||
useValue: translateServiceSpy,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
provide: StorageProvider,
|
|
||||||
useValue: storageProviderSpy,
|
|
||||||
},
|
|
||||||
IonicStorage,
|
|
||||||
ConfigProvider,
|
|
||||||
Browser,
|
|
||||||
{
|
|
||||||
provide: StorageBackend,
|
|
||||||
useValue: storageBackendSpy,
|
|
||||||
},
|
|
||||||
Requestor,
|
|
||||||
provideHttpClient(withInterceptorsFromDi()),
|
|
||||||
],
|
|
||||||
});
|
|
||||||
defaultAuthService = TestBed.inject(DefaultAuthService);
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('loadTokenFromStorage', () => {
|
|
||||||
it('should provide false through isAuthenticated$ when there is no token response', async () => {
|
|
||||||
// eslint-disable-next-line unicorn/no-null
|
|
||||||
storageBackendSpy.getItem.and.returnValue(Promise.resolve(null));
|
|
||||||
let loggedInHolder;
|
|
||||||
defaultAuthService.isAuthenticated$.subscribe(loggedIn => {
|
|
||||||
loggedInHolder = loggedIn;
|
|
||||||
});
|
|
||||||
await defaultAuthService.loadTokenFromStorage();
|
|
||||||
|
|
||||||
expect(loggedInHolder).toBeFalse();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('should provide true through isAuthenticated$ when access token is valid', async () => {
|
|
||||||
const validToken = `{"access_token":"AT-XXXX","refresh_token":"RT-XXXX","scope":"","token_type":"bearer","issued_at":${nowInSeconds()},"expires_in":"${
|
|
||||||
8 * 60 * 60
|
|
||||||
}"}`;
|
|
||||||
storageBackendSpy.getItem.and.returnValue(Promise.resolve(validToken));
|
|
||||||
let loggedInHolder;
|
|
||||||
defaultAuthService.isAuthenticated$.subscribe(loggedIn => {
|
|
||||||
loggedInHolder = loggedIn;
|
|
||||||
});
|
|
||||||
await defaultAuthService.loadTokenFromStorage();
|
|
||||||
|
|
||||||
expect(loggedInHolder).toBeTrue();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('should provide false through isAuthenticated$ when access token is invalid', async () => {
|
|
||||||
const invalidToken = `{"access_token":"AT-INVALID-XXXX","refresh_token":"RT-XXXX","scope":"","token_type":"bearer","issued_at":${
|
|
||||||
nowInSeconds() - 9 * 60 * 60
|
|
||||||
},"expires_in":"${8 * 60 * 60}"}`;
|
|
||||||
storageBackendSpy.getItem.and.returnValue(Promise.resolve(invalidToken));
|
|
||||||
let loggedInHolder;
|
|
||||||
defaultAuthService.isAuthenticated$.subscribe(loggedIn => {
|
|
||||||
loggedInHolder = loggedIn;
|
|
||||||
});
|
|
||||||
await defaultAuthService.loadTokenFromStorage();
|
|
||||||
|
|
||||||
expect(loggedInHolder).toBeFalse();
|
|
||||||
});
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,102 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) 2023 StApps
|
|
||||||
* This program is free software: you can redistribute it and/or modify it
|
|
||||||
* under the terms of the GNU General Public License as published by the Free
|
|
||||||
* Software Foundation, version 3.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful, but WITHOUT
|
|
||||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
||||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
|
||||||
* more details.
|
|
||||||
*
|
|
||||||
* You should have received a copy of the GNU General Public License along with
|
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
|
||||||
*/
|
|
||||||
|
|
||||||
import {
|
|
||||||
AuthorizationRequestHandler,
|
|
||||||
AuthorizationServiceConfiguration,
|
|
||||||
JQueryRequestor,
|
|
||||||
LocalStorageBackend,
|
|
||||||
Requestor,
|
|
||||||
StorageBackend,
|
|
||||||
TokenRequestHandler,
|
|
||||||
} from '@openid/appauth';
|
|
||||||
import {AuthActionBuilder, Browser, DefaultBrowser, EndSessionHandler, UserInfoHandler} from 'ionic-appauth';
|
|
||||||
import {ConfigProvider} from '../config/config.provider';
|
|
||||||
import {SCAuthorizationProvider} from '@openstapps/core';
|
|
||||||
import {getClientConfig, getEndpointsConfig} from './auth.provider.methods';
|
|
||||||
import {Injectable, inject} from '@angular/core';
|
|
||||||
import {AuthService} from './auth.service';
|
|
||||||
|
|
||||||
const TOKEN_RESPONSE_KEY = 'token_response';
|
|
||||||
|
|
||||||
@Injectable({
|
|
||||||
providedIn: 'root',
|
|
||||||
})
|
|
||||||
export class DefaultAuthService extends AuthService {
|
|
||||||
protected browser: Browser;
|
|
||||||
|
|
||||||
protected storage: StorageBackend;
|
|
||||||
|
|
||||||
protected requestor: Requestor;
|
|
||||||
|
|
||||||
private readonly configProvider = inject(ConfigProvider);
|
|
||||||
|
|
||||||
public localConfiguration: AuthorizationServiceConfiguration;
|
|
||||||
|
|
||||||
protected tokenHandler: TokenRequestHandler;
|
|
||||||
|
|
||||||
protected userInfoHandler: UserInfoHandler;
|
|
||||||
|
|
||||||
protected requestHandler: AuthorizationRequestHandler;
|
|
||||||
|
|
||||||
protected endSessionHandler: EndSessionHandler;
|
|
||||||
|
|
||||||
constructor() {
|
|
||||||
const browser = inject(Browser) ?? new DefaultBrowser();
|
|
||||||
const storage = inject(StorageBackend) ?? new LocalStorageBackend();
|
|
||||||
const requestor = inject(Requestor) ?? new JQueryRequestor();
|
|
||||||
|
|
||||||
super(browser, storage, requestor);
|
|
||||||
|
|
||||||
this.browser = browser;
|
|
||||||
this.storage = storage;
|
|
||||||
this.requestor = requestor;
|
|
||||||
}
|
|
||||||
|
|
||||||
get configuration(): Promise<AuthorizationServiceConfiguration> {
|
|
||||||
if (!this.localConfiguration) throw new Error('Local Configuration Not Defined');
|
|
||||||
|
|
||||||
return Promise.resolve(this.localConfiguration);
|
|
||||||
}
|
|
||||||
|
|
||||||
public async init() {
|
|
||||||
this.setupConfiguration();
|
|
||||||
this.setupAuthorizationNotifier();
|
|
||||||
await this.loadTokenFromStorage();
|
|
||||||
}
|
|
||||||
|
|
||||||
setupConfiguration() {
|
|
||||||
const authConfig = this.configProvider.getAnyValue('auth') as {
|
|
||||||
default: SCAuthorizationProvider;
|
|
||||||
};
|
|
||||||
this.authConfig = getClientConfig('default', authConfig);
|
|
||||||
this.localConfiguration = new AuthorizationServiceConfiguration(
|
|
||||||
getEndpointsConfig('default', authConfig),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
public async signOut() {
|
|
||||||
await this.revokeTokens().catch(error => {
|
|
||||||
this.notifyActionListers(AuthActionBuilder.SignOutFailed(error));
|
|
||||||
});
|
|
||||||
this.notifyActionListers(AuthActionBuilder.SignOutSuccess());
|
|
||||||
}
|
|
||||||
|
|
||||||
public async revokeTokens() {
|
|
||||||
// Note: only locally
|
|
||||||
await this.storage.removeItem(TOKEN_RESPONSE_KEY);
|
|
||||||
this.notifyActionListers(AuthActionBuilder.RevokeTokensSuccess());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
+5
-3
@@ -14,9 +14,11 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
import {Platform} from '@ionic/angular/standalone';
|
import {Platform} from '@ionic/angular/standalone';
|
||||||
|
import {FetchRequestor, Requestor} from '@openid/appauth';
|
||||||
import {CapacitorRequestor} from '../capacitor-requestor';
|
import {CapacitorRequestor} from '../capacitor-requestor';
|
||||||
import {NgHttpService} from '../ng-http.service';
|
|
||||||
|
|
||||||
export const httpFactory = (platform: Platform) => {
|
export const requestorFactory = (platform: Platform): Requestor => {
|
||||||
return platform.is('capacitor') ? new CapacitorRequestor() : new NgHttpService();
|
return platform.is('capacitor')
|
||||||
|
? new CapacitorRequestor()
|
||||||
|
: new FetchRequestor();
|
||||||
};
|
};
|
||||||
@@ -14,9 +14,11 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
import {Platform} from '@ionic/angular/standalone';
|
import {Platform} from '@ionic/angular/standalone';
|
||||||
import {IonicStorage} from 'ionic-appauth/lib';
|
import {LocalStorageBackend, StorageBackend} from '@openid/appauth';
|
||||||
import {SafeCapacitorSecureStorage} from '../../storage/capacitor-secure-storage';
|
import {SafeCapacitorSecureStorage} from '../../storage/capacitor-secure-storage';
|
||||||
|
|
||||||
export const storageFactory = (platform: Platform) => {
|
export const storageFactory = (platform: Platform): StorageBackend => {
|
||||||
return platform.is('capacitor') ? new SafeCapacitorSecureStorage() : new IonicStorage();
|
return platform.is('capacitor')
|
||||||
|
? new SafeCapacitorSecureStorage()
|
||||||
|
: new LocalStorageBackend();
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,77 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) 2023 StApps
|
|
||||||
* This program is free software: you can redistribute it and/or modify it
|
|
||||||
* under the terms of the GNU General Public License as published by the Free
|
|
||||||
* Software Foundation, version 3.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful, but WITHOUT
|
|
||||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
||||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
|
||||||
* more details.
|
|
||||||
*
|
|
||||||
* You should have received a copy of the GNU General Public License along with
|
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
|
||||||
*/
|
|
||||||
|
|
||||||
import {Injectable, inject} from '@angular/core';
|
|
||||||
import {Requestor} from '@openid/appauth';
|
|
||||||
import {HttpClient, HttpHeaders} from '@angular/common/http';
|
|
||||||
import {XhrSettings} from 'ionic-appauth/lib/cordova';
|
|
||||||
import {firstValueFrom, Observable} from 'rxjs';
|
|
||||||
|
|
||||||
@Injectable({
|
|
||||||
providedIn: 'root',
|
|
||||||
})
|
|
||||||
export class NgHttpService implements Requestor {
|
|
||||||
private http = inject(HttpClient);
|
|
||||||
|
|
||||||
public async xhr<T>(settings: XhrSettings): Promise<T> {
|
|
||||||
if (!settings.method) {
|
|
||||||
settings.method = 'GET';
|
|
||||||
}
|
|
||||||
|
|
||||||
let observable: Observable<T>;
|
|
||||||
|
|
||||||
switch (settings.method) {
|
|
||||||
case 'GET': {
|
|
||||||
observable = this.http.get<T>(settings.url, {
|
|
||||||
headers: this.getHeaders(settings.headers),
|
|
||||||
});
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case 'POST': {
|
|
||||||
observable = this.http.post<T>(settings.url, settings.data, {
|
|
||||||
headers: this.getHeaders(settings.headers),
|
|
||||||
});
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case 'PUT': {
|
|
||||||
observable = this.http.put<T>(settings.url, settings.data, {
|
|
||||||
headers: this.getHeaders(settings.headers),
|
|
||||||
});
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
case 'DELETE': {
|
|
||||||
observable = this.http.delete<T>(settings.url, {
|
|
||||||
headers: this.getHeaders(settings.headers),
|
|
||||||
});
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return firstValueFrom(observable);
|
|
||||||
}
|
|
||||||
|
|
||||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
||||||
private getHeaders(headers: any): HttpHeaders {
|
|
||||||
let httpHeaders: HttpHeaders = new HttpHeaders();
|
|
||||||
|
|
||||||
if (headers !== undefined) {
|
|
||||||
for (const key of Object.keys(headers)) {
|
|
||||||
httpHeaders = httpHeaders.append(key, headers[key]);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return httpHeaders;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright (C) 2022 StApps
|
|
||||||
* This program is free software: you can redistribute it and/or modify it
|
|
||||||
* under the terms of the GNU General Public License as published by the Free
|
|
||||||
* Software Foundation, version 3.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful, but WITHOUT
|
|
||||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
||||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
|
|
||||||
* more details.
|
|
||||||
*
|
|
||||||
* You should have received a copy of the GNU General Public License along with
|
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
|
||||||
*/
|
|
||||||
|
|
||||||
export interface IUserInfo {
|
|
||||||
display_name: string;
|
|
||||||
role: string;
|
|
||||||
email: string;
|
|
||||||
user_name: string;
|
|
||||||
}
|
|
||||||
@@ -1,16 +1,19 @@
|
|||||||
import {Injectable, inject} from '@angular/core';
|
import {Injectable, inject} from '@angular/core';
|
||||||
import {SCIdCard, SCThingOriginType, SCThingType, SCUserConfiguration} from '@openstapps/core';
|
import {SCIdCard, SCThingOriginType, SCThingType, SCUserConfiguration} from '@openstapps/core';
|
||||||
import {from, of, Observable} from 'rxjs';
|
import {from, of, Observable} from 'rxjs';
|
||||||
import {AuthHelperService} from '../auth/auth-helper.service';
|
|
||||||
import {mergeMap, concatWith, filter, map, startWith, catchError, tap} from 'rxjs/operators';
|
import {mergeMap, concatWith, filter, map, startWith, catchError, tap} from 'rxjs/operators';
|
||||||
import {ConfigProvider} from '../config/config.provider';
|
import {ConfigProvider} from '../config/config.provider';
|
||||||
import {HttpClient} from '@angular/common/http';
|
import {HttpClient} from '@angular/common/http';
|
||||||
import {EncryptedStorageProvider} from '../storage/encrypted-storage.provider';
|
import {EncryptedStorageProvider} from '../storage/encrypted-storage.provider';
|
||||||
|
import {AuthProvider} from "../auth/auth.provider";
|
||||||
|
import {AuthHelperService} from "../auth/auth-helper.service";
|
||||||
|
|
||||||
@Injectable({providedIn: 'root'})
|
@Injectable({providedIn: 'root'})
|
||||||
export class IdCardsProvider {
|
export class IdCardsProvider {
|
||||||
private authHelper = inject(AuthHelperService);
|
private authHelper = inject(AuthHelperService);
|
||||||
|
|
||||||
|
private authProvider = inject(AuthProvider);
|
||||||
|
|
||||||
private config = inject(ConfigProvider);
|
private config = inject(ConfigProvider);
|
||||||
|
|
||||||
private httpClient = inject(HttpClient);
|
private httpClient = inject(HttpClient);
|
||||||
@@ -19,7 +22,7 @@ export class IdCardsProvider {
|
|||||||
|
|
||||||
getIdCards(): Observable<SCIdCard[]> {
|
getIdCards(): Observable<SCIdCard[]> {
|
||||||
const feature = this.config.config.app.features.extern?.['idCards'];
|
const feature = this.config.config.app.features.extern?.['idCards'];
|
||||||
const auth = this.authHelper.getProvider();
|
const auth = this.authProvider;
|
||||||
const storedIdCards = from(
|
const storedIdCards = from(
|
||||||
this.encryptedStorageProvider.get<SCIdCard[]>('id-cards') as Promise<SCIdCard[]>,
|
this.encryptedStorageProvider.get<SCIdCard[]>('id-cards') as Promise<SCIdCard[]>,
|
||||||
).pipe(filter(it => it !== undefined));
|
).pipe(filter(it => it !== undefined));
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ import {EncryptedStorageProvider} from '../storage/encrypted-storage.provider';
|
|||||||
import {TestBed} from '@angular/core/testing';
|
import {TestBed} from '@angular/core/testing';
|
||||||
import {TranslateService} from '@ngx-translate/core';
|
import {TranslateService} from '@ngx-translate/core';
|
||||||
import {StorageBackend, Requestor} from '@openid/appauth';
|
import {StorageBackend, Requestor} from '@openid/appauth';
|
||||||
import {IonicStorage, Browser} from 'ionic-appauth';
|
|
||||||
import {LoggerTestingModule} from 'ngx-logger/testing';
|
import {LoggerTestingModule} from 'ngx-logger/testing';
|
||||||
import {StAppsWebHttpClient} from '../data/stapps-web-http-client.provider';
|
import {StAppsWebHttpClient} from '../data/stapps-web-http-client.provider';
|
||||||
import {SimpleBrowser} from '../../util/browser.factory';
|
import {SimpleBrowser} from '../../util/browser.factory';
|
||||||
|
|||||||
@@ -19,6 +19,7 @@ import {AuthHelperService} from '../../auth/auth-helper.service';
|
|||||||
import {mergeMap, of} from 'rxjs';
|
import {mergeMap, of} from 'rxjs';
|
||||||
import Swiper from 'swiper';
|
import Swiper from 'swiper';
|
||||||
import {toObservable, toSignal} from '@angular/core/rxjs-interop';
|
import {toObservable, toSignal} from '@angular/core/rxjs-interop';
|
||||||
|
import {AuthProvider} from "../../auth/auth.provider";
|
||||||
|
|
||||||
@Component({
|
@Component({
|
||||||
selector: 'stapps-profile-page-section',
|
selector: 'stapps-profile-page-section',
|
||||||
@@ -32,10 +33,11 @@ export class ProfilePageSectionComponent {
|
|||||||
minSlideWidth = input(110);
|
minSlideWidth = input(110);
|
||||||
|
|
||||||
authHelper = inject(AuthHelperService);
|
authHelper = inject(AuthHelperService);
|
||||||
|
authProvider = inject(AuthProvider);
|
||||||
|
|
||||||
loggedIn = toSignal(
|
loggedIn = toSignal(
|
||||||
toObservable(this.item).pipe(
|
toObservable(this.item).pipe(
|
||||||
mergeMap(item => (item.authProvider ? this.authHelper.getProvider().isLoggedIn$ : of(false))),
|
mergeMap(item => (item.authProvider ? this.authProvider.isLoggedIn$ : of(false))),
|
||||||
),
|
),
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -66,13 +68,11 @@ export class ProfilePageSectionComponent {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async toggleLogIn() {
|
async toggleLogIn() {
|
||||||
const providerType = this.item().authProvider;
|
|
||||||
if (!providerType) return;
|
|
||||||
if (this.loggedIn()) {
|
if (this.loggedIn()) {
|
||||||
await this.authHelper.getProvider().signOut();
|
await this.authProvider.signOut();
|
||||||
await this.authHelper.endBrowserSession(providerType);
|
await this.authHelper.endBrowserSession();
|
||||||
} else {
|
} else {
|
||||||
await this.authHelper.getProvider().signIn();
|
await this.authProvider.signIn();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
* this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
*/
|
*/
|
||||||
import {Component, inject} from '@angular/core';
|
import {Component, inject} from '@angular/core';
|
||||||
import {AuthHelperService} from '../../auth/auth-helper.service';
|
import {AuthProvider} from '../../auth/auth.provider';
|
||||||
import {ActivatedRoute} from '@angular/router';
|
import {ActivatedRoute} from '@angular/router';
|
||||||
import {ScheduleProvider} from '../../calendar/schedule.provider';
|
import {ScheduleProvider} from '../../calendar/schedule.provider';
|
||||||
import {profilePageSections} from '../../../../config/profile-page-sections';
|
import {profilePageSections} from '../../../../config/profile-page-sections';
|
||||||
@@ -25,7 +25,7 @@ import {profilePageSections} from '../../../../config/profile-page-sections';
|
|||||||
standalone: false,
|
standalone: false,
|
||||||
})
|
})
|
||||||
export class ProfilePageComponent {
|
export class ProfilePageComponent {
|
||||||
readonly authHelper = inject(AuthHelperService);
|
readonly authProvider = inject(AuthProvider);
|
||||||
|
|
||||||
readonly activatedRoute = inject(ActivatedRoute);
|
readonly activatedRoute = inject(ActivatedRoute);
|
||||||
|
|
||||||
@@ -33,23 +33,7 @@ export class ProfilePageComponent {
|
|||||||
|
|
||||||
sections = profilePageSections;
|
sections = profilePageSections;
|
||||||
|
|
||||||
async signIn() {
|
ionViewWillEnter(): void {
|
||||||
const originPath = this.activatedRoute.snapshot.queryParamMap.get('origin_path');
|
void this.authProvider.loadUserInfo();
|
||||||
await (originPath ? this.authHelper.setOriginPath(originPath) : this.authHelper.deleteOriginPath());
|
|
||||||
await this.authHelper.getProvider().signIn();
|
|
||||||
}
|
|
||||||
|
|
||||||
async signOut() {
|
|
||||||
await this.authHelper.getProvider().signOut();
|
|
||||||
}
|
|
||||||
|
|
||||||
ionViewWillEnter() {
|
|
||||||
this.authHelper
|
|
||||||
.getProvider()
|
|
||||||
.getValidToken()
|
|
||||||
.then(() => void this.authHelper.getProvider().loadUserInfo())
|
|
||||||
.catch(() => {
|
|
||||||
// noop
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -12,19 +12,58 @@
|
|||||||
* You should have received a copy of the GNU General Public License along with
|
* You should have received a copy of the GNU General Public License along with
|
||||||
* this program. If not, see <https://www.gnu.org/licenses/>.
|
* this program. If not, see <https://www.gnu.org/licenses/>.
|
||||||
*/
|
*/
|
||||||
import {CapacitorSecureStorage} from 'ionic-appauth/lib/capacitor';
|
|
||||||
|
|
||||||
/*
|
import {StorageBackend} from '@openid/appauth';
|
||||||
* Removes an item from storage before entering the new one to avoid issues
|
import {SecureStoragePlugin} from 'capacitor-secure-storage-plugin';
|
||||||
* after iOS upgrade (iOS 16)
|
|
||||||
|
/**
|
||||||
|
* Secure storage backend for AppAuth on native Capacitor platforms.
|
||||||
|
*
|
||||||
|
* Removes an existing item before writing it again to avoid issues
|
||||||
|
* observed after iOS upgrades.
|
||||||
*/
|
*/
|
||||||
export class SafeCapacitorSecureStorage extends CapacitorSecureStorage {
|
export class SafeCapacitorSecureStorage implements StorageBackend {
|
||||||
async setItem(name: string, value: string): Promise<void> {
|
public async getItem(name: string): Promise<string | null> {
|
||||||
if (!Storage) throw new Error('Capacitor Storage Is Undefined!');
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
await super.removeItem(name);
|
const {value} = await SecureStoragePlugin.get({
|
||||||
} catch {}
|
key: name,
|
||||||
return super.setItem(name, value);
|
});
|
||||||
|
|
||||||
|
return value;
|
||||||
|
} catch {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async setItem(
|
||||||
|
name: string,
|
||||||
|
value: string,
|
||||||
|
): Promise<void> {
|
||||||
|
try {
|
||||||
|
await SecureStoragePlugin.remove({
|
||||||
|
key: name,
|
||||||
|
});
|
||||||
|
} catch {
|
||||||
|
// Item does not exist yet.
|
||||||
|
}
|
||||||
|
|
||||||
|
await SecureStoragePlugin.set({
|
||||||
|
key: name,
|
||||||
|
value,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public async removeItem(name: string): Promise<void> {
|
||||||
|
try {
|
||||||
|
await SecureStoragePlugin.remove({
|
||||||
|
key: name,
|
||||||
|
});
|
||||||
|
} catch {
|
||||||
|
// Removing a non-existing item is fine.
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public async clear(): Promise<void> {
|
||||||
|
await SecureStoragePlugin.clear();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -19,9 +19,9 @@
|
|||||||
|
|
||||||
export const environment = {
|
export const environment = {
|
||||||
backend_url: 'https://mobile.server.uni-frankfurt.de',
|
backend_url: 'https://mobile.server.uni-frankfurt.de',
|
||||||
app_host: 'mobile.app.uni-frankfurt.de',
|
app_host: 'dev.app.uni-frankfurt.de',
|
||||||
custom_url_scheme: 'de.anyschool.app',
|
custom_url_scheme: 'de.anyschool.app',
|
||||||
backend_version: '4.0.0',
|
backend_version: '999.0.0',
|
||||||
production: true,
|
production: true,
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -19,8 +19,9 @@
|
|||||||
|
|
||||||
export const environment = {
|
export const environment = {
|
||||||
backend_url: 'https://mobile.server.uni-frankfurt.de',
|
backend_url: 'https://mobile.server.uni-frankfurt.de',
|
||||||
|
// backend_url: 'http://localhost:3000',
|
||||||
app_host: 'mobile.app.uni-frankfurt.de',
|
app_host: 'mobile.app.uni-frankfurt.de',
|
||||||
custom_url_scheme: 'de.anyschool.app',
|
custom_url_scheme: 'de.unifrankfurt.app',
|
||||||
backend_version: '999.0.0',
|
backend_version: '999.0.0',
|
||||||
production: false,
|
production: false,
|
||||||
};
|
};
|
||||||
|
|||||||
Generated
+517
-616
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user