Compare commits

..
Author SHA1 Message Date
Rainer Killinger 0401ea06a3 ci: update app-builder image 2026-10-07 11:58:59 +02:00
Jovan Krunić c843e435a4 fix: translate service injection
Closes #250
2026-10-06 16:49:33 +02:00
Jovan Krunić d161d594a3 fix: replace deprecated sass import with use rules 2026-10-02 20:02:49 +02:00
38 changed files with 1826 additions and 2789 deletions
+13 -13
View File
@@ -13,23 +13,23 @@ const config = {
default: {
client: {
clientId: '1cac3f99-33fa-4234-8438-979f07e0cdab',
scopes: 'openid profile email offline_access',
url: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc',
scopes: '',
url: 'https://cas.rz.uni-frankfurt.de/cas/oauth2.0',
},
endpoints: {
authorization: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc/authorize',
endSession: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc/end-session',
authorization: 'https://cas.rz.uni-frankfurt.de/cas/oauth2.0/authorize',
endSession: 'https://cas.rz.uni-frankfurt.de/cas/logout',
mapping: {
id: '$.preferred_username',
email: '$.mailPrimaryAddress',
familyName: '$.family_name',
givenName: '$.given_name',
name: '$.name',
role: '$.eduPersonPrimaryAffiliation',
studentId: '$.employeeNumber',
id: '$.id',
email: '$.attributes.mailPrimaryAddress',
familyName: '$.attributes.sn',
givenName: '$.attributes.givenName',
name: '$.attributes.givenName',
role: '$.attributes.eduPersonPrimaryAffiliation',
studentId: '$.attributes.employeeNumber',
},
token: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc/token',
userinfo: 'https://idp.ub.uni-frankfurt.de/idp/profile/oidc/userinfo',
token: 'https://cas.rz.uni-frankfurt.de/cas/oauth2.0/accessToken',
userinfo: 'https://cas.rz.uni-frankfurt.de/cas/oauth2.0/profile',
},
},
},
+1 -1
View File
@@ -36,7 +36,7 @@
"format:fix": "prettier --write . --ignore-path ../../.gitignore",
"lint": "tsc --noEmit && eslint --ext .ts src/",
"lint:fix": "eslint --fix --ext .ts src/",
"start": "cross-env NODE_CONFIG_ENV=elasticsearch ALLOW_NO_TRANSPORT=true NODE_APP_INSTANCE=\"f-u\" node app.js",
"start": "cross-env NODE_CONFIG_ENV=elasticsearch ALLOW_NO_TRANSPORT=true node app.js",
"start:debug": "cross-env STAPPS_LOG_LEVEL=31 NODE_CONFIG_ENV=elasticsearch ALLOW_NO_TRANSPORT=true node app.js",
"test": "pnpm run test:unit",
"test:integration": "sh integration-test.sh",
+1 -1
View File
@@ -1,7 +1,7 @@
import {CapacitorConfig} from '@capacitor/cli';
const config: CapacitorConfig = {
appId: 'de.unifrankfurt.app',
appId: 'de.anyschool.app',
appName: 'StApps',
webDir: 'www/browser',
cordova: {
+1 -1
View File
@@ -29,7 +29,7 @@ def capacitor_pods
pod 'CapacitorShare', :path => '../../../../node_modules/.pnpm/@capacitor+share@8.0.1_@capacitor+core@8.2.0/node_modules/@capacitor/share'
pod 'CapacitorSplashScreen', :path => '../../../../node_modules/.pnpm/@capacitor+splash-screen@8.0.1_@capacitor+core@8.2.0/node_modules/@capacitor/splash-screen'
pod 'TransistorsoftCapacitorBackgroundFetch', :path => '../../../../node_modules/.pnpm/@transistorsoft+capacitor-background-fetch@8.0.0_@capacitor+core@8.2.0/node_modules/@transistorsoft/capacitor-background-fetch'
pod 'CapacitorSecureStoragePlugin', :path => '../../../../node_modules/.pnpm/capacitor-secure-storage-plugin@0.13.0_@capacitor+core@8.2.0/node_modules/capacitor-secure-storage-plugin'
pod 'CapacitorSecureStoragePlugin', :path => '../../../../node_modules/.pnpm/capacitor-secure-storage-plugin@0.12.0_@capacitor+core@8.2.0/node_modules/capacitor-secure-storage-plugin'
pod 'CordovaPlugins', :path => '../capacitor-cordova-ios-plugins'
end
+4 -3
View File
@@ -41,7 +41,7 @@
"resources:ios": "capacitor-assets generate --ios --iconBackgroundColor $(grep -oE \"^@include ion-color\\(primary, #[a-fA-F0-9]{3,6}\" src/theme/colors.scss | grep -oE \"#[a-fA-F0-9]{3,6}\") --splashBackgroundColor $(grep -oE \"^@include ion-color\\(primary, #[a-fA-F0-9]{3,6}\" src/theme/colors.scss | grep -oE \"#[a-fA-F0-9]{3,6}\")",
"run:android": "ionic capacitor run android --livereload --external",
"start": "ionic serve",
"start:external": "ionic serve --external --ssl=true",
"start:external": "ionic serve --external",
"start:prod": "ionic serve --prod",
"start:virtual-host": "ionic serve --public-host=mobile.app.uni-frankfurt.de --ssl=true --open=false",
"test": "ng test --code-coverage",
@@ -81,7 +81,7 @@
"@maplibre/ngx-maplibre-gl": "22.1.0",
"@ngx-translate/core": "15.0.0",
"@ngx-translate/http-loader": "8.0.0",
"@openid/appauth": "1.4.0",
"@openid/appauth": "1.3.2",
"@openstapps/api": "workspace:*",
"@openstapps/collection-utils": "workspace:*",
"@openstapps/core": "workspace:*",
@@ -93,7 +93,8 @@
"deepmerge": "4.3.1",
"form-data": "4.0.6",
"geojson": "0.5.0",
"ionicons": "8.0.13",
"ionic-appauth": "2.1.0",
"ionicons": "8.1.0",
"jsonpath-plus": "10.3.0",
"maplibre-gl": "6.4.1",
"material-symbols": "0.17.1",
+4 -6
View File
@@ -18,14 +18,13 @@ import {App, URLOpenListenerEvent} from '@capacitor/app';
import {Platform, ToastController} from '@ionic/angular/standalone';
import {SettingsProvider} from './modules/settings/settings.provider';
import {InAppReviewProvider} from './modules/settings/in-app-review/in-app-review.provider';
import {AuthProvider} from "./modules/auth/auth.provider";
import {AuthHelperService} from './modules/auth/auth-helper.service';
import {environment} from '../environments/environment';
import {Capacitor} from '@capacitor/core';
import {ScheduleSyncService} from './modules/background/schedule/schedule-sync.service';
import {Keyboard, KeyboardResize} from '@capacitor/keyboard';
import {AppVersionService} from './modules/about/app-version.service';
import {SplashScreen} from '@capacitor/splash-screen';
import {AuthHelperService} from "./modules/auth/auth-helper.service";
/**
* TODO
@@ -46,8 +45,6 @@ export class AppComponent implements AfterContentInit {
private readonly zone = inject(NgZone);
private readonly authProvider = inject(AuthProvider);
private readonly authHelper = inject(AuthHelperService);
private readonly toastController = inject(ToastController);
@@ -132,8 +129,9 @@ export class AppComponent implements AfterContentInit {
}
private async authNotificationsInit() {
this.authProvider
.events$.subscribe(action => this.showMessage(this.authHelper.getAuthMessage(action)));
this.authHelper
.getProvider()
.events$.subscribe(action => this.showMessage(this.authHelper.getAuthMessage('default', action)));
}
private async showMessage(message?: string) {
+4 -4
View File
@@ -57,6 +57,7 @@ import {AssessmentsModule} from './modules/assessments/assessments.module';
import {ServiceHandlerInterceptor} from './_helpers/service-handler.interceptor';
import {RoutingStackService} from './util/routing-stack.service';
import {SCLanguageCode, SCSettingValue} from '@openstapps/core';
import {DefaultAuthService} from './modules/auth/default-auth.service';
import {NavigationModule} from './modules/menu/navigation/navigation.module';
import {browserFactory, SimpleBrowser} from './util/browser.factory';
import {getDateFnsLocale} from './translation/dfns-locale';
@@ -66,7 +67,6 @@ import {Capacitor} from '@capacitor/core';
import {SplashScreen} from '@capacitor/splash-screen';
import * as maplibregl from 'maplibre-gl';
import {Protocol} from 'pmtiles';
import {AuthProvider} from "./modules/auth/auth.provider";
registerLocaleData(localeDe);
@@ -82,7 +82,7 @@ export function initializerFactory(
configProvider: ConfigProvider,
translateService: TranslateService,
_routingStackService: RoutingStackService,
authProvider: AuthProvider,
defaultAuthService: DefaultAuthService,
dateFnsConfigurationService: DateFnsConfigurationService,
) {
return async () => {
@@ -111,7 +111,7 @@ export function initializerFactory(
setDefaultOptions({locale: dateFnsLocale});
dateFnsConfigurationService.setLocale(dateFnsLocale);
await authProvider.init();
await defaultAuthService.init();
} catch (error) {
logger.warn(error);
}
@@ -201,7 +201,7 @@ export function createTranslateLoader(http: HttpClient) {
ConfigProvider,
TranslateService,
RoutingStackService,
AuthProvider,
DefaultAuthService,
DateFnsConfigurationService,
],
useFactory: initializerFactory,
@@ -15,9 +15,9 @@
import {Injectable, inject} from '@angular/core';
import {ConfigProvider} from '../config/config.provider';
import {SCAssessment, SCUuid} from '@openstapps/core';
import {DefaultAuthService} from '../auth/default-auth.service';
import {HttpClient} from '@angular/common/http';
import {uniqBy, keyBy} from '@openstapps/collection-utils';
import {AuthProvider} from "../auth/auth.provider";
/**
*
@@ -53,7 +53,7 @@ export function toAssessmentMap(data: SCAssessment[]): Record<SCUuid, SCAssessme
export class AssessmentsProvider {
readonly configProvider = inject(ConfigProvider);
readonly authProvider = inject(AuthProvider);
readonly defaultAuth = inject(DefaultAuthService);
readonly http = inject(HttpClient);
@@ -97,7 +97,7 @@ export class AssessmentsProvider {
this.cache = this.http
.get<{data: SCAssessment[]}>(`${url}/${this.assessmentPath}`, {
headers: {
Authorization: `Bearer ${accessToken ?? (await this.authProvider.getValidToken()).accessToken}`,
Authorization: `Bearer ${accessToken ?? (await this.defaultAuth.getValidToken()).accessToken}`,
},
})
.toPromise()
@@ -13,16 +13,13 @@
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {Component, inject} from '@angular/core';
import {Router} from '@angular/router';
import {takeUntilDestroyed} from '@angular/core/rxjs-interop';
import {NavController} from '@ionic/angular/standalone';
import {
AuthActions,
AuthProvider,
IAuthAction,
} from '../../auth.provider';
import {Router} from '@angular/router';
import {AuthActions, IAuthAction} from 'ionic-appauth';
import {AuthHelperService} from '../../auth-helper.service';
import {takeUntilDestroyed} from '@angular/core/rxjs-interop';
import {Observable} from 'rxjs';
import {DefaultAuthService} from '../../default-auth.service';
@Component({
templateUrl: 'auth-callback-page.component.html',
@@ -36,42 +33,23 @@ export class AuthCallbackPageComponent {
private authHelper = inject(AuthHelperService);
private authProvider = inject(AuthProvider);
private auth = inject(DefaultAuthService);
constructor() {
this.authProvider.events$
.pipe(takeUntilDestroyed())
.subscribe(action => {
void this.postCallback(action);
});
const events: Observable<IAuthAction> = this.auth.events$;
this.authProvider.authorizationCallback(
window.location.href,
);
events.pipe(takeUntilDestroyed()).subscribe((action: IAuthAction) => this.postCallback(action));
this.auth.authorizationCallback(window.location.origin + this.router.url);
}
private async postCallback(
action: IAuthAction,
): Promise<void> {
switch (action.action) {
case AuthActions.SignInSuccess: {
const originPath =
await this.authHelper.getOriginPath();
await this.authHelper.deleteOriginPath();
await this.navCtrl.navigateRoot(
originPath ?? 'profile',
);
break;
}
case AuthActions.SignInFailed: {
await this.navCtrl.navigateRoot('profile');
break;
}
async postCallback(action: IAuthAction) {
if (action.action === AuthActions.SignInSuccess) {
const originPath = await this.authHelper.getOriginPath();
this.navCtrl.navigateRoot(originPath ?? 'profile');
this.authHelper.deleteOriginPath();
}
if (action.action === AuthActions.SignInFailed) {
this.navCtrl.navigateRoot('profile');
}
}
}
@@ -16,13 +16,13 @@
import {Injectable, inject} from '@angular/core';
import {CanActivate, NavigationExtras, Router, RouterStateSnapshot} from '@angular/router';
import {ActivatedProtectedRouteSnapshot} from './protected.routes';
import {AuthProvider} from "./auth.provider";
import {AuthHelperService} from './auth-helper.service';
@Injectable({
providedIn: 'root',
})
export class AuthGuardService implements CanActivate {
private authProvider = inject(AuthProvider);
private authHelper = inject(AuthHelperService);
private router = inject(Router);
@@ -32,7 +32,7 @@ export class AuthGuardService implements CanActivate {
}
try {
await this.authProvider.getValidToken();
await this.authHelper.getProvider().getValidToken();
} catch {
const originNavigation = this.router.currentNavigation();
let extras: NavigationExtras = {};
@@ -41,7 +41,7 @@ export class AuthGuardService implements CanActivate {
extras = {queryParams: {origin_path: url}};
}
this.router.navigate(['profile'], extras);
await this.authProvider.signIn();
await this.authHelper.getProvider().signIn();
return false;
}
@@ -1,251 +1,118 @@
import {AuthActions, AuthProvider} from './auth.provider';
/*
* Copyright (C) 2023 StApps
* This program is free software: you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the Free
* Software Foundation, version 3.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
* more details.
*
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {TestBed} from '@angular/core/testing';
import {AuthHelperService} from './auth-helper.service';
const AUTH_ORIGIN_PATH = 'stapps.auth.origin_path';
const AUTH_MESSAGE_PREFIX = 'auth.messages.default';
const END_SESSION_ENDPOINT = 'https://idp.example.org/logout';
const USER_MAPPING = {
id: '$.sub',
givenName: '$.given_name',
familyName: '$.family_name',
email: '$.attributes.mail',
role: '$.role',
};
interface TestAlertButton {
text: string;
role?: string;
cssClass?: string;
handler?: () => Promise<void> | void;
}
import {ConfigProvider} from '../config/config.provider';
import {StorageProvider} from '../storage/storage.provider';
import {DefaultAuthService} from './default-auth.service';
import {Browser} from 'ionic-appauth';
import {Requestor, StorageBackend} from '@openid/appauth';
import {TranslateService} from '@ngx-translate/core';
import {StAppsWebHttpClient} from '../data/stapps-web-http-client.provider';
import {provideHttpClient, withInterceptorsFromDi} from '@angular/common/http';
import {SimpleBrowser} from '../../util/browser.factory';
import {LoggerTestingModule} from 'ngx-logger/testing';
describe('AuthHelperService', () => {
let service: AuthHelperService;
let translateService: jasmine.SpyObj<{instant(key: string): string}>;
let configProvider: jasmine.SpyObj<{getAnyValue(key: string): unknown}>;
let storageProvider: jasmine.SpyObj<{
get<T>(key: string): Promise<T>;
put(key: string, value: unknown): Promise<unknown>;
delete(key: string): Promise<unknown>;
}>;
let authProvider: jasmine.SpyObj<Pick<AuthProvider, 'getEndSessionEndpoint'>>;
let browser: jasmine.SpyObj<{open(url: string): Promise<void>}>;
let alertController: jasmine.SpyObj<{create(options: unknown): Promise<unknown>}>;
let alert: jasmine.SpyObj<{present(): Promise<void>}>;
function createService(authConfig: unknown = {default: {endpoints: {mapping: USER_MAPPING}}}) {
configProvider.getAnyValue.and.returnValue(authConfig);
return new AuthHelperService(
translateService as any,
configProvider as any,
storageProvider as any,
authProvider as any,
browser as any,
alertController as any,
);
}
/** Options passed to the most recent AlertController.create() call. */
function lastAlertOptions(): {header: string; message: string; buttons: TestAlertButton[]} {
return alertController.create.calls.mostRecent().args[0] as any;
}
function alertButton(role: string): TestAlertButton {
const button = lastAlertOptions().buttons.find(b => b.role === role);
if (!button) {
throw new Error(`No alert button with role "${role}"`);
}
return button;
}
let authHelperService: AuthHelperService;
const storageProviderSpy = jasmine.createSpyObj('StorageProvider', ['init', 'get', 'has', 'put', 'search']);
const translateServiceSpy = jasmine.createSpyObj('TranslateService', ['setDefaultLang', 'use']);
const defaultAuthServiceMock = jasmine.createSpyObj('DefaultAuthService', ['init', 'setupConfiguration']);
const authHelperServiceMock = jasmine.createSpyObj('AuthHelperService', ['constructor']);
const simpleBrowserMock = jasmine.createSpyObj('SimpleBrowser', ['open']);
const configProvider = jasmine.createSpyObj('ConfigProvider', {
getAnyValue: {
default: {
endpoints: {
mapping: {
id: '$.id',
email: '$.attributes.mailPrimaryAddress',
givenName: '$.attributes.givenName',
familyName: '$.attributes.sn',
name: '$.attributes.sn',
role: '$.attributes.eduPersonPrimaryAffiliation',
studentId: '$.attributes.employeeNumber',
},
},
},
},
});
beforeEach(() => {
translateService = jasmine.createSpyObj('TranslateService', ['instant']);
translateService.instant.and.callFake((key: string) => `translated:${key}`);
configProvider = jasmine.createSpyObj('ConfigProvider', ['getAnyValue']);
storageProvider = jasmine.createSpyObj('StorageProvider', ['get', 'put', 'delete']);
storageProvider.put.and.resolveTo();
storageProvider.delete.and.resolveTo();
authProvider = jasmine.createSpyObj('AuthProvider', ['getEndSessionEndpoint']);
authProvider.getEndSessionEndpoint.and.resolveTo(END_SESSION_ENDPOINT);
browser = jasmine.createSpyObj('SimpleBrowser', ['open']);
browser.open.and.resolveTo();
alert = jasmine.createSpyObj('HTMLIonAlertElement', ['present']);
alert.present.and.resolveTo();
alertController = jasmine.createSpyObj('AlertController', ['create']);
alertController.create.and.resolveTo(alert);
service = createService();
});
describe('userConfigurationMap', () => {
it('reads the user mapping from the default auth provider', () => {
expect(configProvider.getAnyValue).toHaveBeenCalledWith('auth');
expect(service.userConfigurationMap).toEqual(USER_MAPPING as any);
});
it('falls back to an empty mapping when no default auth provider is configured', () => {
service = createService({});
expect(service.userConfigurationMap).toEqual({} as any);
});
});
describe('getAuthMessage', () => {
it('returns the translated message for SignInSuccess', () => {
expect(service.getAuthMessage({action: AuthActions.SignInSuccess})).toBe(
`translated:${AUTH_MESSAGE_PREFIX}.logged_in_success`,
);
});
it('returns the translated message for SignOutSuccess', () => {
expect(service.getAuthMessage({action: AuthActions.SignOutSuccess})).toBe(
`translated:${AUTH_MESSAGE_PREFIX}.logged_out_success`,
);
});
it('returns undefined for all other actions without translating', () => {
const otherActions = Object.values(AuthActions).filter(
action => action !== AuthActions.SignInSuccess && action !== AuthActions.SignOutSuccess,
);
for (const action of otherActions) {
expect(service.getAuthMessage({action})).withContext(action).toBeUndefined();
}
expect(translateService.instant).not.toHaveBeenCalled();
TestBed.configureTestingModule({
imports: [LoggerTestingModule],
providers: [
StAppsWebHttpClient,
{
provide: TranslateService,
useValue: translateServiceSpy,
},
{
provide: StorageProvider,
useValue: storageProviderSpy,
},
{
provider: DefaultAuthService,
useValue: defaultAuthServiceMock,
},
{
provide: ConfigProvider,
useValue: configProvider,
},
Browser,
StorageBackend,
Requestor,
{
provider: AuthHelperService,
useValue: authHelperServiceMock,
},
{
provide: SimpleBrowser,
useValue: simpleBrowserMock,
},
provideHttpClient(withInterceptorsFromDi()),
],
});
authHelperService = TestBed.inject(AuthHelperService);
});
describe('getUserFromUserInfo', () => {
it('maps user info fields via the configured JSONPath mapping', () => {
const user = service.getUserFromUserInfo({
sub: 'user-123',
given_name: 'Erika',
family_name: 'Mustermann',
attributes: {mail: 'erika@example.org'},
role: 'employee',
});
expect(user).toEqual(
jasmine.objectContaining({
id: 'user-123',
it('should provide user configuration from userInfo', async () => {
const userConfiguration = authHelperService.getUserFromUserInfo({
attributes: {
eduPersonPrimaryAffiliation: 'student',
employeeNumber: '123456',
givenName: 'Erika',
familyName: 'Mustermann',
email: 'erika@example.org',
role: 'employee',
}),
);
});
it('builds the name from given name and family name', () => {
const user = service.getUserFromUserInfo({
sub: 'user-123',
given_name: 'Erika',
family_name: 'Mustermann',
role: 'student',
mailPrimaryAddress: 'emuster@anyschool.de',
oauthClientId: '123-abc-123',
sn: 'Musterfrau',
uid: 'emuster',
},
id: 'emuster',
client_id: '123-abc-123',
});
expect(user.name).toBe('Erika Mustermann');
});
it('keeps the default name when the family name is missing', () => {
const user = service.getUserFromUserInfo({
sub: 'user-123',
given_name: 'Erika',
expect(userConfiguration).toEqual({
id: 'emuster',
givenName: 'Erika',
familyName: 'Musterfrau',
name: 'Erika Musterfrau',
email: 'emuster@anyschool.de',
role: 'student',
studentId: '123456',
});
expect(user.name).toBe('');
});
it('returns the default user when no mapping is configured', () => {
service = createService({});
expect(service.getUserFromUserInfo({sub: 'user-123'})).toEqual({
id: '',
name: '',
role: 'student',
});
});
});
describe('origin path', () => {
it('stores the origin path', async () => {
await service.setOriginPath('/profile');
expect(storageProvider.put).toHaveBeenCalledOnceWith(AUTH_ORIGIN_PATH, '/profile');
});
it('returns the stored origin path', async () => {
storageProvider.get.and.resolveTo('/profile');
expect(await service.getOriginPath()).toBe('/profile');
expect(storageProvider.get).toHaveBeenCalledOnceWith(AUTH_ORIGIN_PATH);
});
it('returns undefined when reading the origin path fails', async () => {
storageProvider.get.and.rejectWith(new Error('Value not found'));
expect(await service.getOriginPath()).toBeUndefined();
});
it('deletes the origin path', async () => {
await service.deleteOriginPath();
expect(storageProvider.delete).toHaveBeenCalledOnceWith(AUTH_ORIGIN_PATH);
});
});
describe('endBrowserSession', () => {
it('does nothing when the provider has no end-session endpoint', async () => {
authProvider.getEndSessionEndpoint.and.resolveTo(undefined);
await service.endBrowserSession();
expect(alertController.create).not.toHaveBeenCalled();
expect(browser.open).not.toHaveBeenCalled();
});
it('presents a translated confirmation alert', async () => {
await service.endBrowserSession();
const options = lastAlertOptions();
expect(options.header).toBe(`translated:${AUTH_MESSAGE_PREFIX}.log_out_alert.header`);
expect(options.message).toBe(`translated:${AUTH_MESSAGE_PREFIX}.log_out_alert.message`);
expect(options.buttons.map(b => b.role)).toEqual(['cancel', 'confirm']);
expect(alert.present).toHaveBeenCalledTimes(1);
});
it('does not open the end-session endpoint before confirmation', async () => {
await service.endBrowserSession();
expect(browser.open).not.toHaveBeenCalled();
});
it('opens the end-session endpoint when the user confirms', async () => {
await service.endBrowserSession();
await alertButton('confirm').handler?.();
expect(browser.open).toHaveBeenCalledOnceWith(END_SESSION_ENDPOINT);
});
it('does not open the end-session endpoint when the user cancels', async () => {
await service.endBrowserSession();
const cancelButton = alertButton('cancel');
await cancelButton.handler?.();
expect(cancelButton.handler).toBeUndefined();
expect(browser.open).not.toHaveBeenCalled();
});
});
});
@@ -14,38 +14,35 @@
*/
import {Injectable, inject} from '@angular/core';
import {AlertController} from '@ionic/angular/standalone';
import {AuthActions, IAuthAction} from 'ionic-appauth';
import {TranslateService} from '@ngx-translate/core';
import {JSONPath} from 'jsonpath-plus';
import {
SCAuthorizationProvider,
SCAuthorizationProviderType,
SCUserConfiguration,
SCUserConfigurationMap,
} from '@openstapps/core';
import {JSONPath} from 'jsonpath-plus';
import {SimpleBrowser} from '../../util/browser.factory';
import {ConfigProvider} from '../config/config.provider';
import {StorageProvider} from '../storage/storage.provider';
import {
AuthActions, AuthProvider,
IAuthAction,
} from './auth.provider';
import {DefaultAuthService} from './default-auth.service';
import {SimpleBrowser} from '../../util/browser.factory';
import {AlertController} from '@ionic/angular/standalone';
const AUTH_ORIGIN_PATH = 'stapps.auth.origin_path';
const AUTH_MESSAGE_PREFIX = 'auth.messages.default';
@Injectable({
providedIn: 'root',
})
export class AuthHelperService {
private authProvider = inject(AuthProvider);
private translateService = inject(TranslateService);
private configProvider = inject(ConfigProvider);
private storageProvider = inject(StorageProvider);
private defaultAuth = inject(DefaultAuthService);
private browser = inject(SimpleBrowser);
private alertController = inject(AlertController);
@@ -61,139 +58,93 @@ export class AuthHelperService {
).default?.endpoints.mapping ?? {};
}
public getAuthMessage(
action: IAuthAction,
): string | undefined {
public getAuthMessage(provider: SCAuthorizationProviderType, action: IAuthAction) {
let message: string | undefined;
switch (action.action) {
case AuthActions.SignInSuccess:
return this.translateService.instant(
`${AUTH_MESSAGE_PREFIX}.logged_in_success`,
);
case AuthActions.SignOutSuccess:
return this.translateService.instant(
`${AUTH_MESSAGE_PREFIX}.logged_out_success`,
);
default:
return undefined;
case AuthActions.SignInSuccess: {
message = this.translateService.instant(`auth.messages.${provider}.logged_in_success`);
break;
}
case AuthActions.SignOutSuccess: {
message = this.translateService.instant(`auth.messages.${provider}.logged_out_success`);
break;
}
}
return message;
}
public getUserFromUserInfo(
userInfo: object,
): SCUserConfiguration {
getUserFromUserInfo(userInfo: object) {
const user: SCUserConfiguration = {
id: '',
name: '',
role: 'student',
};
for (const key in this.userConfigurationMap) {
const userKey =
key as keyof SCUserConfiguration;
user[userKey] = JSONPath({
path:
this.userConfigurationMap[
userKey
] as string,
user[key as keyof SCUserConfiguration] = JSONPath({
path: this.userConfigurationMap[key as keyof SCUserConfiguration] as string,
json: userInfo,
})[0];
}
if (
user.givenName &&
user.familyName
) {
user.name =
`${user.givenName} ${user.familyName}`;
if (user.givenName && user.givenName.length > 0 && user.familyName && user.familyName.length > 0) {
user.name = `${user.givenName} ${user.familyName}`;
}
return user;
}
public async deleteOriginPath():
Promise<void> {
await this.storageProvider.delete(
AUTH_ORIGIN_PATH,
);
async deleteOriginPath() {
return this.storageProvider.delete(AUTH_ORIGIN_PATH);
}
public async setOriginPath(
path: string,
): Promise<void> {
await this.storageProvider.put(
AUTH_ORIGIN_PATH,
path,
);
async setOriginPath(path: string) {
return this.storageProvider.put<string>(AUTH_ORIGIN_PATH, path);
}
public async getOriginPath():
Promise<string | undefined> {
async getOriginPath() {
let originPath: string;
try {
return await this.storageProvider.get<string>(
AUTH_ORIGIN_PATH,
);
originPath = await this.storageProvider.get<string>(AUTH_ORIGIN_PATH);
} catch {
return undefined;
}
}
public async endBrowserSession():
Promise<void> {
const endSessionEndpoint =
await this.authProvider
.getEndSessionEndpoint();
if (!endSessionEndpoint) {
return;
}
return originPath;
}
const alert =
await this.alertController.create({
header:
this.translateService.instant(
`${AUTH_MESSAGE_PREFIX}.log_out_alert.header`,
),
/**
* Provides appropriate auth service instance based on type (string) parameter
*/
getProvider(): DefaultAuthService {
return this.defaultAuth;
}
message:
this.translateService.instant(
`${AUTH_MESSAGE_PREFIX}.log_out_alert.message`,
),
/**
* Ends browser session by opening endSessionEndpoint URL of the provider
* @param providerType Type of the provider (e.g. 'default' or 'paia')
*/
async endBrowserSession(providerType: SCAuthorizationProviderType) {
const endSessionEndpoint = (await this.getProvider().configuration).endSessionEndpoint;
if (endSessionEndpoint) {
const alert: HTMLIonAlertElement = await this.alertController.create({
header: this.translateService.instant(`auth.messages.${providerType}.log_out_alert.header`),
message: this.translateService.instant(`auth.messages.${providerType}.log_out_alert.message`),
buttons: [
{
text:
this.translateService.instant(
'no',
),
role: 'cancel',
text: this.translateService.instant('no'),
cssClass: 'default',
},
{
text:
this.translateService.instant(
'yes',
),
text: this.translateService.instant('yes'),
role: 'confirm',
cssClass: 'preferred',
handler: async () => {
/*
* Only now, after explicit confirmation,
* open the IdP end-session endpoint.
*/
await this.browser.open(
endSessionEndpoint,
);
handler: () => {
this.browser.open(new URL(endSessionEndpoint).href);
},
},
],
});
await alert.present();
await alert.present();
}
}
}
@@ -12,5 +12,15 @@
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {SCAuthorizationProviderType} from '@openstapps/core';
export const AUTH_REDIRECT_PATH = 'auth/callback';
export const authPaths: {
[key in SCAuthorizationProviderType]: {redirect_path: string};
} = {
default: {
redirect_path: 'auth/callback',
},
paia: {
redirect_path: 'auth/paia/callback',
},
};
@@ -15,12 +15,12 @@
import {RouterModule, Routes} from '@angular/router';
import {NgModule} from '@angular/core';
import {AUTH_REDIRECT_PATH} from './auth-paths';
import {authPaths} from './auth-paths';
import {AuthCallbackPageComponent} from './auth-callback/page/auth-callback-page.component';
const authRoutes: Routes = [
{
path: AUTH_REDIRECT_PATH,
path: authPaths.default.redirect_path,
component: AuthCallbackPageComponent,
},
];
@@ -3,12 +3,14 @@ import {CommonModule} from '@angular/common';
import {Platform} from '@ionic/angular/standalone';
import {Requestor, StorageBackend} from '@openid/appauth';
import {storageFactory} from './factories';
import {requestorFactory} from './factories/requestor.factory';
import {Browser} from 'ionic-appauth';
import {CapacitorBrowser} from 'ionic-appauth/lib/capacitor';
import {httpFactory} from './factories/http.factory';
import {HttpClient} from '@angular/common/http';
import {AuthRoutingModule} from './auth-routing.module';
import {TranslateModule} from '@ngx-translate/core';
import {AuthCallbackPageComponent} from './auth-callback/page/auth-callback-page.component';
import {AuthProvider} from "./auth.provider";
import {DefaultAuthService} from './default-auth.service';
@NgModule({
declarations: [AuthCallbackPageComponent],
@@ -21,10 +23,14 @@ import {AuthProvider} from "./auth.provider";
},
{
provide: Requestor,
useFactory: requestorFactory,
useFactory: httpFactory,
deps: [Platform, HttpClient],
},
AuthProvider,
{
provide: Browser,
useClass: CapacitorBrowser,
},
DefaultAuthService,
],
})
export class AuthModule {}
@@ -13,90 +13,69 @@
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {AuthorizationServiceConfigurationJson} from '@openid/appauth';
import {IAuthConfig} from 'ionic-appauth';
import {SCAuthorizationProvider, SCAuthorizationProviderType} from '@openstapps/core';
import {Capacitor} from '@capacitor/core';
import {SCAuthorizationProvider} from '@openstapps/core';
import {
AuthorizationServiceConfiguration,
} from '@openid/appauth';
import {authPaths} from './auth-paths';
import {environment} from '../../../environments/environment';
import {AUTH_REDIRECT_PATH} from './auth-paths';
import type {AuthConfig} from './auth.provider';
export interface OidcEndpoints {
userinfo?: string;
endSession?: string;
}
/**
* Returns the configuration of the OIDC client.
* Get configuration of an OAuth2 client
*/
export function getClientConfig(
providerType: SCAuthorizationProviderType,
authConfig: {
default: SCAuthorizationProvider;
default?: SCAuthorizationProvider;
paia?: SCAuthorizationProvider;
},
): AuthConfig {
const provider =
authConfig.default;
): IAuthConfig {
const providerConfig = authConfig[providerType] as SCAuthorizationProvider;
return {
server_host: provider.client.url,
client_id: provider.client.clientId,
scopes: provider.client.scopes,
redirect_url: getRedirectUrl(),
end_session_redirect_url: '',
pkce: true,
scopes: providerConfig.client.scopes,
server_host: providerConfig.client.url,
client_id: providerConfig.client.clientId,
redirect_url: getRedirectUrl(authPaths[providerType].redirect_path),
};
}
/**
* Returns the AppAuth OAuth/OIDC service configuration.
* Get configuration about endpoints of an OAuth2 server
*/
export function getServiceConfiguration(
export function getEndpointsConfig(
providerType: SCAuthorizationProviderType,
authConfig: {
default: SCAuthorizationProvider;
default?: SCAuthorizationProvider;
paia?: SCAuthorizationProvider;
},
): AuthorizationServiceConfiguration {
const endpoints =
authConfig.default.endpoints;
return new AuthorizationServiceConfiguration({
authorization_endpoint: endpoints.authorization,
token_endpoint: endpoints.token,
revocation_endpoint: endpoints.revoke || '',
});
}
/**
* Returns the additional OIDC endpoints that AppAuth-JS does not expose
* through AuthorizationServiceConfiguration.
*/
export function getOidcEndpoints(
authConfig: {
default: SCAuthorizationProvider;
},
): OidcEndpoints {
const endpoints = authConfig.default.endpoints;
): AuthorizationServiceConfigurationJson {
const providerConfig = authConfig[providerType] as SCAuthorizationProvider;
return {
userinfo:
endpoints.userinfo,
endSession:
endpoints.endSession,
authorization_endpoint: providerConfig.endpoints.authorization,
end_session_endpoint: providerConfig.endpoints.endSession,
revocation_endpoint: providerConfig.endpoints.revoke ?? '',
token_endpoint: providerConfig.endpoints.token,
userinfo_endpoint: providerConfig.endpoints.userinfo,
};
}
/**
* Returns the OIDC redirect URL depending on the current platform.
* Return a URL of the app, depending on the platform where it is running
*/
function getRedirectUrl(): string {
if (Capacitor.isNativePlatform()) {
return `${environment.custom_url_scheme}://${environment.app_host}/${AUTH_REDIRECT_PATH}`;
}
function getRedirectUrl(routePath: string): string {
let appHost: string;
let appSchema: string;
if (environment.production) {
return `https://${environment.app_host}/${AUTH_REDIRECT_PATH}`;
}
appSchema = Capacitor.isNativePlatform() ? environment.custom_url_scheme : 'https';
appHost = environment.app_host;
} else {
appSchema = Capacitor.isNativePlatform()
? environment.custom_url_scheme
: window.location.protocol.split(':')[0];
return `${window.location.origin}/${AUTH_REDIRECT_PATH}`;
appHost = Capacitor.isNativePlatform() ? environment.app_host : window.location.host;
}
return `${appSchema}://${appHost}/${routePath}`;
}
@@ -1,239 +0,0 @@
import {
AppAuthError,
AuthorizationServiceConfiguration,
StorageBackend,
TokenRequestHandler,
TokenResponse,
} from '@openid/appauth';
import {BehaviorSubject, firstValueFrom} from 'rxjs';
import {AuthProvider, IAuthAction, INVALID_GRANT} from './auth.provider';
const TOKEN_RESPONSE_KEY = 'token_response';
const TOKEN_LIFETIME = 3600;
const NOW_MS = Date.parse('2026-01-01T12:00:00Z');
const NOW = NOW_MS / 1000;
/**
* Creates a token with a real lifetime instead of spying on isValid().
*
* remainingSeconds > 0 → still valid for that long
* remainingSeconds < 0 → expired that many seconds ago
* refreshToken: null → token without refresh token
*/
function makeToken(
opts: {accessToken?: string; refreshToken?: string | null; remainingSeconds?: number} = {},
): TokenResponse {
const remaining = opts.remainingSeconds ?? TOKEN_LIFETIME;
return new TokenResponse({
access_token: opts.accessToken ?? 'access-token',
refresh_token: opts.refreshToken === null ? undefined : (opts.refreshToken ?? 'refresh-token'),
token_type: 'bearer',
expires_in: String(TOKEN_LIFETIME),
issued_at: NOW - (TOKEN_LIFETIME - remaining),
});
}
/** Typed access to the private members the tests depend on. */
interface AuthProviderInternals {
storage: StorageBackend;
tokenHandler: TokenRequestHandler;
tokenSubject: BehaviorSubject<TokenResponse | undefined>;
notify(action: IAuthAction): void;
}
describe('AuthProvider', () => {
let provider: AuthProvider;
let internals: AuthProviderInternals;
let storageGetItem: jasmine.Spy;
let storageSetItem: jasmine.Spy;
let storageRemoveItem: jasmine.Spy;
let tokenRequest: jasmine.Spy;
/** Seeds storage with the given token and loads it through the public API. */
async function givenLoadedToken(token: TokenResponse | null): Promise<void> {
storageGetItem.and.resolveTo(token ? JSON.stringify(token.toJson()) : null);
await provider.loadTokenFromStorage();
}
const isAuthenticated = () => firstValueFrom(provider.isAuthenticated$);
const isLoggedIn = () => firstValueFrom(provider.isLoggedIn$);
beforeEach(() => {
jasmine.clock().install();
jasmine.clock().mockDate(new Date(NOW_MS));
const platform = {is: () => false} as any;
const configProvider = {} as any;
provider = new AuthProvider(platform, configProvider);
internals = provider as unknown as AuthProviderInternals;
(provider as any).authConfigValue = {
server_host: 'https://idp.example.org',
client_id: 'test-client',
redirect_url: 'https://app.example.org/callback',
scopes: 'openid profile',
pkce: true,
};
(provider as any).localConfiguration = new AuthorizationServiceConfiguration({
authorization_endpoint: 'https://idp.example.org/authorize',
token_endpoint: 'https://idp.example.org/token',
revocation_endpoint: 'https://idp.example.org/revoke',
});
// Never touch real storage or the network.
storageGetItem = spyOn(internals.storage, 'getItem').and.resolveTo(null);
storageSetItem = spyOn(internals.storage, 'setItem').and.resolveTo();
storageRemoveItem = spyOn(internals.storage, 'removeItem').and.resolveTo();
tokenRequest = spyOn(internals.tokenHandler, 'performTokenRequest').and.rejectWith(
new Error('Unexpected token request'),
);
});
afterEach(() => {
jasmine.clock().uninstall();
});
describe('isAuthenticated$', () => {
it('should provide false through isAuthenticated$ when there is no token response', async () => {
// Start authenticated so the test cannot pass on the initial value alone.
await givenLoadedToken(makeToken());
expect(await isAuthenticated()).toBeTrue();
await givenLoadedToken(null);
expect(internals.tokenSubject.value).toBeUndefined();
expect(await isAuthenticated()).toBeFalse();
});
it('should provide true through isAuthenticated$ when access token is valid', async () => {
await givenLoadedToken(makeToken());
expect(await isAuthenticated()).toBeTrue();
});
it('should provide false through isAuthenticated$ when access token is invalid', async () => {
await givenLoadedToken(makeToken({remainingSeconds: -TOKEN_LIFETIME}));
expect(await isAuthenticated()).toBeFalse();
// Still logged in: a refresh token is available.
expect(await isLoggedIn()).toBeTrue();
});
it('should provide true through isAuthenticated$ after an expired token was refreshed', async () => {
await givenLoadedToken(makeToken({remainingSeconds: -60}));
expect(await isAuthenticated()).toBeFalse();
tokenRequest.and.resolveTo(makeToken({accessToken: 'new-access-token'}));
await provider.getValidToken();
expect(await isAuthenticated()).toBeTrue();
});
});
describe('getValidToken', () => {
it('returns the current token without refreshing when it is valid', async () => {
await givenLoadedToken(makeToken({accessToken: 'current-access-token'}));
const token = await provider.getValidToken();
expect(tokenRequest).not.toHaveBeenCalled();
expect(token.accessToken).toBe('current-access-token');
});
it('refreshes the token when the access token is expired', async () => {
await givenLoadedToken(makeToken({remainingSeconds: -60}));
tokenRequest.and.resolveTo(
makeToken({accessToken: 'new-access-token', refreshToken: 'new-refresh-token'}),
);
const token = await provider.getValidToken();
expect(tokenRequest).toHaveBeenCalledTimes(1);
expect(token.accessToken).toBe('new-access-token');
expect(token.refreshToken).toBe('new-refresh-token');
expect(storageSetItem).toHaveBeenCalledOnceWith(TOKEN_RESPONSE_KEY, jasmine.any(String));
});
it('refreshes the token when the access token expires within the buffer', async () => {
// 5 minutes left, default buffer requires more than 10.
await givenLoadedToken(makeToken({remainingSeconds: 5 * 60}));
tokenRequest.and.resolveTo(makeToken({accessToken: 'new-access-token'}));
const token = await provider.getValidToken();
expect(tokenRequest).toHaveBeenCalledTimes(1);
expect(token.accessToken).toBe('new-access-token');
});
it('keeps the previous refresh token when the refresh response contains none', async () => {
await givenLoadedToken(makeToken({remainingSeconds: -60, refreshToken: 'old-refresh-token'}));
tokenRequest.and.resolveTo(makeToken({accessToken: 'new-access-token', refreshToken: null}));
const token = await provider.getValidToken();
expect(token.accessToken).toBe('new-access-token');
expect(token.refreshToken).toBe('old-refresh-token');
});
it('rejects without a request when the token is expired and has no refresh token', async () => {
await givenLoadedToken(makeToken({remainingSeconds: -60, refreshToken: null}));
await expectAsync(provider.getValidToken()).toBeRejectedWithError(/No Refresh Token Available/);
expect(tokenRequest).not.toHaveBeenCalled();
});
describe('when refresh fails with invalid_grant', () => {
const refreshError = new AppAuthError(INVALID_GRANT);
beforeEach(async () => {
await givenLoadedToken(makeToken({remainingSeconds: -60, refreshToken: 'invalid-refresh-token'}));
expect(await isLoggedIn()).toBeTrue();
tokenRequest.and.rejectWith(refreshError);
await expectAsync(provider.getValidToken()).toBeRejectedWith(refreshError);
});
it('changes isLoggedIn to false', async () => {
expect(await isLoggedIn()).toBeFalse();
});
it('removes the token from storage', () => {
expect(storageRemoveItem).toHaveBeenCalledOnceWith(TOKEN_RESPONSE_KEY);
});
it('clears the current token', () => {
expect(internals.tokenSubject.value).toBeUndefined();
});
});
describe('when refresh fails with a temporary error', () => {
// An AppAuthError that is not invalid_grant, e.g. a network failure.
const refreshError = new AppAuthError('Network Error');
beforeEach(async () => {
await givenLoadedToken(makeToken({remainingSeconds: -60}));
tokenRequest.and.rejectWith(refreshError);
await expectAsync(provider.getValidToken()).toBeRejectedWith(refreshError);
});
it('keeps the user logged in', async () => {
expect(await isLoggedIn()).toBeTrue();
});
it('does not remove the token from storage', () => {
expect(storageRemoveItem).not.toHaveBeenCalled();
});
it('keeps the current token for a later retry', () => {
expect(internals.tokenSubject.value?.refreshToken).toBe('refresh-token');
});
});
});
});
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,526 @@
/*
* Copyright (C) 2023 StApps
* This program is free software: you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the Free
* Software Foundation, version 3.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
* more details.
*
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
// Temporary use of direct file until the version with bug fix is released
// https://github.com/wi3land/ionic-appauth/blob/3716f4fc6b5491b0b75e049be0a47a5af8c4da6f/src/auth-service.ts
// Bug: https://github.com/wi3land/ionic-appauth/issues/154
import {
AuthorizationError,
AuthorizationNotifier,
AuthorizationRequest,
AuthorizationRequestHandler,
AuthorizationRequestJson,
AuthorizationResponse,
AuthorizationServiceConfiguration,
BaseTokenRequestHandler,
DefaultCrypto,
GRANT_TYPE_AUTHORIZATION_CODE,
GRANT_TYPE_REFRESH_TOKEN,
JQueryRequestor,
LocalStorageBackend,
Requestor,
RevokeTokenRequest,
RevokeTokenRequestJson,
StorageBackend,
StringMap,
TokenRequest,
TokenRequestHandler,
TokenRequestJson,
TokenResponse,
} from '@openid/appauth';
import {
ActionHistoryObserver,
AuthActionBuilder,
AuthActions,
AuthObserver,
AUTHORIZATION_RESPONSE_KEY,
AuthSubject,
BaseAuthObserver,
Browser,
DefaultBrowser,
EndSessionHandler,
EndSessionRequest,
EndSessionRequestJson,
IAuthAction,
IAuthConfig,
IAuthService,
IonicAuthorizationRequestHandler,
IonicEndSessionHandler,
IonicUserInfoHandler,
SessionObserver,
UserInfoHandler,
} from 'ionic-appauth';
import {BehaviorSubject, Observable} from 'rxjs';
const TOKEN_RESPONSE_KEY = 'token_response';
const AUTH_EXPIRY_BUFFER = 10 * 60 * -1; // 10 mins in seconds
export abstract class AuthService implements IAuthService {
private _configuration?: AuthorizationServiceConfiguration;
private _authConfig?: IAuthConfig;
private _authSubject: AuthSubject = new AuthSubject();
private _actionHistory: ActionHistoryObserver = new ActionHistoryObserver();
private _session: SessionObserver = new SessionObserver();
private _authSubjectV2 = new BehaviorSubject<IAuthAction>(AuthActionBuilder.Init());
private _tokenSubject = new BehaviorSubject<TokenResponse | undefined>(undefined);
// eslint-disable-next-line @typescript-eslint/no-explicit-any
private _userSubject = new BehaviorSubject<any>(undefined);
private _authenticatedSubject = new BehaviorSubject<boolean>(false);
private _loggedInSubject = new BehaviorSubject<boolean>(false);
private _initComplete = new BehaviorSubject<boolean>(false);
protected tokenHandler: TokenRequestHandler;
protected userInfoHandler: UserInfoHandler;
protected requestHandler: AuthorizationRequestHandler;
protected endSessionHandler: EndSessionHandler;
constructor(
protected browser: Browser = new DefaultBrowser(),
protected storage: StorageBackend = new LocalStorageBackend(),
protected requestor: Requestor = new JQueryRequestor(),
) {
this.tokenHandler = new BaseTokenRequestHandler(requestor);
this.userInfoHandler = new IonicUserInfoHandler(requestor);
this.requestHandler = new IonicAuthorizationRequestHandler(browser, storage);
this.endSessionHandler = new IonicEndSessionHandler(browser);
}
/**
* @deprecated independant observers have been replaced by Rxjs
* this will be removed in a future release
* please use $ suffixed observers in future
*/
get history(): IAuthAction[] {
return [...this._actionHistory.history];
}
/**
* @deprecated independant observers have been replaced by Rxjs
* this will be removed in a future release
* please use $ suffixed observers in future
*/
get session() {
return this._session.session;
}
get token$(): Observable<TokenResponse | undefined> {
return this._tokenSubject.asObservable();
}
get isAuthenticated$(): Observable<boolean> {
return this._authenticatedSubject.asObservable();
}
/**
* Similar to isAuthenticated$, but will also return true if the token is expired
*/
get isLoggedIn$(): Observable<boolean> {
return this._loggedInSubject.asObservable();
}
get initComplete$(): Observable<boolean> {
return this._initComplete.asObservable();
}
// eslint-disable-next-line @typescript-eslint/no-explicit-any
get user$(): Observable<any> {
return this._userSubject.asObservable();
}
get events$(): Observable<IAuthAction> {
return this._authSubjectV2.asObservable();
}
get authConfig(): IAuthConfig {
if (!this._authConfig) throw new Error('AuthConfig Not Defined');
return this._authConfig;
}
set authConfig(value: IAuthConfig) {
this._authConfig = value;
}
get configuration(): Promise<AuthorizationServiceConfiguration> {
if (!this._configuration) {
return AuthorizationServiceConfiguration.fetchFromIssuer(
this.authConfig.server_host,
this.requestor,
).catch(() => {
throw new Error('Unable To Obtain Server Configuration');
});
}
if (this._configuration == undefined) {
throw new Error('Unable To Obtain Server Configuration');
} else {
return Promise.resolve(this._configuration);
}
}
public async init() {
this.setupAuthorizationNotifier();
this.loadTokenFromStorage();
this.addActionObserver(this._actionHistory);
this.addActionObserver(this._session);
}
protected notifyActionListers(action: IAuthAction) {
/* eslint-disable unicorn/no-useless-undefined */
switch (action.action) {
case AuthActions.SignInFailed:
case AuthActions.SignOutSuccess:
case AuthActions.SignOutFailed: {
this._tokenSubject.next(undefined);
this._userSubject.next(undefined);
this._authenticatedSubject.next(false);
this._loggedInSubject.next(false);
break;
}
case AuthActions.LoadTokenFromStorageFailed: {
this._tokenSubject.next(undefined);
this._userSubject.next(undefined);
this._authenticatedSubject.next(false);
this._loggedInSubject.next(false);
this._initComplete.next(true);
break;
}
case AuthActions.SignInSuccess:
case AuthActions.RefreshSuccess: {
this._tokenSubject.next(action.tokenResponse);
this._authenticatedSubject.next(true);
this._loggedInSubject.next(true);
break;
}
case AuthActions.LoadTokenFromStorageSuccess: {
this._tokenSubject.next(action.tokenResponse);
this._authenticatedSubject.next((action.tokenResponse as TokenResponse).isValid(0));
this._loggedInSubject.next(true);
this._initComplete.next(true);
break;
}
case AuthActions.RevokeTokensSuccess: {
this._tokenSubject.next(undefined);
break;
}
case AuthActions.LoadUserInfoSuccess: {
this._userSubject.next(action.user);
break;
}
case AuthActions.LoadUserInfoFailed: {
this._userSubject.next(undefined);
break;
}
}
this._authSubjectV2.next(action);
this._authSubject.notify(action);
}
protected setupAuthorizationNotifier() {
const notifier = new AuthorizationNotifier();
this.requestHandler.setAuthorizationNotifier(notifier);
notifier.setAuthorizationListener((request, response, error) =>
this.onAuthorizationNotification(request, response, error),
);
}
protected onAuthorizationNotification(
request: AuthorizationRequest,
response: AuthorizationResponse | null,
error: AuthorizationError | null,
) {
const codeVerifier: string | undefined =
request.internal != undefined && this.authConfig.pkce ? request.internal.code_verifier : undefined;
if (response != undefined) {
this.requestAccessToken(response.code, codeVerifier);
} else if (error == undefined) {
throw new Error('Unknown Error With Authentication');
} else {
throw new Error(error.errorDescription);
}
}
protected async internalAuthorizationCallback(url: string) {
this.browser.closeWindow();
await this.storage.setItem(AUTHORIZATION_RESPONSE_KEY, url);
return this.requestHandler.completeAuthorizationRequestIfPossible();
}
protected async internalEndSessionCallback() {
this.browser.closeWindow();
this._actionHistory.clear();
this.notifyActionListers(AuthActionBuilder.SignOutSuccess());
}
protected async performEndSessionRequest(state?: string): Promise<void> {
if (this._tokenSubject.value == undefined) {
//if user has no token they should not be logged in in the first place
this.endSessionCallback();
} else {
const requestJson: EndSessionRequestJson = {
postLogoutRedirectURI: this.authConfig.end_session_redirect_url,
idTokenHint: this._tokenSubject.value.idToken || '',
state: state || undefined,
};
const request: EndSessionRequest = new EndSessionRequest(requestJson);
const returnedUrl: string | undefined = await this.endSessionHandler.performEndSessionRequest(
await this.configuration,
request,
);
//callback may come from showWindow or via another method
if (returnedUrl != undefined) {
this.endSessionCallback();
}
}
}
protected async performAuthorizationRequest(authExtras?: StringMap, state?: string): Promise<void> {
const requestJson: AuthorizationRequestJson = {
response_type: AuthorizationRequest.RESPONSE_TYPE_CODE,
client_id: this.authConfig.client_id,
redirect_uri: this.authConfig.redirect_url,
scope: this.authConfig.scopes,
extras: authExtras,
state: state || undefined,
};
const request = new AuthorizationRequest(requestJson, new DefaultCrypto(), this.authConfig.pkce);
if (this.authConfig.pkce) await request.setupCodeVerifier();
return this.requestHandler.performAuthorizationRequest(await this.configuration, request);
}
protected async requestAccessToken(code: string, codeVerifier?: string): Promise<void> {
const requestJSON: TokenRequestJson = {
grant_type: GRANT_TYPE_AUTHORIZATION_CODE,
code: code,
refresh_token: undefined,
redirect_uri: this.authConfig.redirect_url,
client_id: this.authConfig.client_id,
extras: codeVerifier
? {
code_verifier: codeVerifier,
client_secret: this.authConfig.client_secret as string,
}
: {
client_secret: this.authConfig.client_secret as string,
},
};
const token: TokenResponse = await this.tokenHandler.performTokenRequest(
await this.configuration,
new TokenRequest(requestJSON),
);
await this.storage.setItem(TOKEN_RESPONSE_KEY, JSON.stringify(token.toJson()));
this.notifyActionListers(AuthActionBuilder.SignInSuccess(token));
}
protected async requestTokenRefresh() {
if (!this._tokenSubject.value) {
throw new Error('No Token Defined!');
}
const requestJSON: TokenRequestJson = {
grant_type: GRANT_TYPE_REFRESH_TOKEN,
refresh_token: this._tokenSubject.value?.refreshToken,
redirect_uri: this.authConfig.redirect_url,
client_id: this.authConfig.client_id,
};
const token: TokenResponse = await this.tokenHandler.performTokenRequest(
await this.configuration,
new TokenRequest(requestJSON),
);
if (!token.accessToken) {
throw new Error('No Access Token Defined In Refresh Response');
}
await this.storage.setItem(TOKEN_RESPONSE_KEY, JSON.stringify(token.toJson()));
this.notifyActionListers(AuthActionBuilder.RefreshSuccess(token));
}
protected async internalLoadTokenFromStorage() {
let token: TokenResponse | undefined;
const tokenResponseString: string | null = await this.storage.getItem(TOKEN_RESPONSE_KEY);
if (tokenResponseString != undefined) {
token = new TokenResponse(JSON.parse(tokenResponseString));
if (token) {
return this.notifyActionListers(AuthActionBuilder.LoadTokenFromStorageSuccess(token));
}
}
throw new Error('No Token In Storage');
}
protected async requestTokenRevoke() {
const revokeRefreshJson: RevokeTokenRequestJson = {
token: (this._tokenSubject.value as TokenResponse).refreshToken as string,
token_type_hint: 'refresh_token',
client_id: this.authConfig.client_id,
};
const revokeAccessJson: RevokeTokenRequestJson = {
token: (this._tokenSubject.value as TokenResponse).accessToken,
token_type_hint: 'access_token',
client_id: this.authConfig.client_id,
};
await this.tokenHandler.performRevokeTokenRequest(
await this.configuration,
new RevokeTokenRequest(revokeRefreshJson),
);
await this.tokenHandler.performRevokeTokenRequest(
await this.configuration,
new RevokeTokenRequest(revokeAccessJson),
);
await this.storage.removeItem(TOKEN_RESPONSE_KEY);
this.notifyActionListers(AuthActionBuilder.RevokeTokensSuccess());
}
protected async internalRequestUserInfo() {
if (this._tokenSubject.value) {
const userInfo = await this.userInfoHandler.performUserInfoRequest(
await this.configuration,
this._tokenSubject.value,
);
this.notifyActionListers(AuthActionBuilder.LoadUserInfoSuccess(userInfo));
} else {
throw new Error('No Token Available');
}
}
public async loadTokenFromStorage() {
await this.internalLoadTokenFromStorage().catch(error => {
this.notifyActionListers(AuthActionBuilder.LoadTokenFromStorageFailed(error));
});
}
public async signIn(authExtras?: StringMap, state?: string) {
await this.performAuthorizationRequest(authExtras, state).catch(error => {
this.notifyActionListers(AuthActionBuilder.SignInFailed(error));
});
}
public async signOut(state?: string, revokeTokens?: boolean) {
if (revokeTokens) {
await this.revokeTokens();
}
await this.storage.removeItem(TOKEN_RESPONSE_KEY);
if ((await this.configuration).endSessionEndpoint) {
await this.performEndSessionRequest(state).catch(error => {
this.notifyActionListers(AuthActionBuilder.SignOutFailed(error));
});
}
}
public async revokeTokens() {
await this.requestTokenRevoke().catch(error => {
this.storage.removeItem(TOKEN_RESPONSE_KEY);
this.notifyActionListers(AuthActionBuilder.RevokeTokensFailed(error));
});
}
public async refreshToken() {
await this.requestTokenRefresh().catch(error => {
this.notifyActionListers(AuthActionBuilder.RefreshFailed(error));
});
}
public async loadUserInfo() {
await this.internalRequestUserInfo().catch(error => {
this.notifyActionListers(AuthActionBuilder.LoadUserInfoFailed(error));
});
}
public authorizationCallback(callbackUrl: string): void {
this.internalAuthorizationCallback(callbackUrl).catch(error => {
this.notifyActionListers(AuthActionBuilder.SignInFailed(error));
});
}
public endSessionCallback(): void {
this.internalEndSessionCallback().catch(error => {
this.notifyActionListers(AuthActionBuilder.SignOutFailed(error));
});
}
public async getValidToken(buffer: number = AUTH_EXPIRY_BUFFER): Promise<TokenResponse> {
if (this._tokenSubject.value) {
if (this._tokenSubject.value.isValid(buffer)) {
return this._tokenSubject.value;
} else {
await this.refreshToken();
if (this._tokenSubject.value) {
return this._tokenSubject.value;
}
}
}
throw new Error('Unable To Obtain Valid Token');
}
/**
* @deprecated independant observers have been replaced by Rxjs
* this will be removed in a future release
* please use $ suffixed observers in future
*/
public addActionListener(function_: (action: IAuthAction) => void): AuthObserver {
const observer: AuthObserver = AuthObserver.Create(function_);
this.addActionObserver(observer);
return observer;
}
/**
* @deprecated independant observers have been replaced by Rxjs
* this will be removed in a future release
* please use $ suffixed observers in future
*/
public addActionObserver(observer: BaseAuthObserver): void {
if (this._actionHistory.lastAction) {
observer.update(this._actionHistory.lastAction);
}
this._authSubject.attach(observer);
}
/**
* @deprecated independant observers have been replaced by Rxjs
* this will be removed in a future release
* please use $ suffixed observers in future
*/
public removeActionObserver(observer: BaseAuthObserver): void {
this._authSubject.detach(observer);
}
}
@@ -1,270 +0,0 @@
/*
* Copyright (C) 2026 StApps
* This program is free software: you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the Free
* Software Foundation, version 3.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
* more details.
*
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {Browser} from '@capacitor/browser';
import {
AuthorizationError,
AuthorizationErrorJson,
AuthorizationRequest,
AuthorizationRequestHandler,
AuthorizationRequestJson,
AuthorizationRequestResponse,
AuthorizationResponse,
AuthorizationResponseJson,
AuthorizationServiceConfiguration,
BasicQueryStringUtils,
DefaultCrypto,
StorageBackend,
StringMap,
} from '@openid/appauth';
const AUTHORIZATION_REQUEST_KEY =
'appauth_capacitor_authorization_request';
/**
* AppAuth authorization request handler for native Capacitor applications.
*
* AppAuth-JS handles:
* - state generation and validation data
* - PKCE code_verifier / code_challenge
* - authorization URL construction
* - AuthorizationNotifier
*
* This handler adds the Capacitor-specific parts:
* - persist the pending authorization request
* - open the authorization URL using @capacitor/browser
* - process the callback URL delivered through appUrlOpen
*/
export class CapacitorAuthorizationRequestHandler extends AuthorizationRequestHandler {
private callbackUrl?: string;
constructor(private readonly storage: StorageBackend) {
super(
new BasicQueryStringUtils(),
new DefaultCrypto(),
);
}
public async performAuthorizationRequest(
configuration: AuthorizationServiceConfiguration,
request: AuthorizationRequest,
): Promise<void> {
/*
* Important:
*
* toJson() calls setupCodeVerifier() internally.
* Therefore PKCE is initialized before buildRequestUrl()
* constructs the authorization URL.
*/
const requestJson =
await request.toJson();
await this.storage.setItem(
AUTHORIZATION_REQUEST_KEY,
JSON.stringify(requestJson),
);
const url =
this.buildRequestUrl(
configuration,
request,
);
await Browser.open({url});
}
/**
* Completes the authorization flow using the URL received from
* Capacitor's App.addListener('appUrlOpen', ...).
*/
public async completeAuthorizationRequestFromUrl(
callbackUrl: string,
): Promise<void> {
this.callbackUrl = callbackUrl;
/*
* The deep link has returned control to the application.
* Close the SFSafariViewController / Custom Tab if it is still open.
*/
try {
await Browser.close();
} catch {
// Browser might already have been closed by the platform.
}
await this.completeAuthorizationRequestIfPossible();
}
protected async completeAuthorizationRequest():
Promise<AuthorizationRequestResponse | null> {
if (!this.callbackUrl) {
return null;
}
const storedRequest =
await this.storage.getItem(
AUTHORIZATION_REQUEST_KEY,
);
if (!storedRequest) {
this.callbackUrl = undefined;
throw new Error(
'No pending authorization request found.',
);
}
const requestJson =
JSON.parse(
storedRequest,
) as AuthorizationRequestJson;
/*
* The serialized request also contains `internal`, including
* AppAuth's PKCE code_verifier.
*/
const request =
new AuthorizationRequest(requestJson);
const parameters =
this.parseCallbackUrl(
this.callbackUrl,
);
const state =
parameters['state'];
/*
* Never accept an authorization response for a different request.
*/
if (!state || state !== request.state) {
this.callbackUrl = undefined;
throw new Error(
'Authorization response state does not match the authorization request.',
);
}
const error =
parameters['error'];
let response:
AuthorizationResponse | null = null;
let authorizationError:
AuthorizationError | null = null;
if (error) {
const errorJson:
AuthorizationErrorJson = {
error,
error_description:
parameters[
'error_description'
],
error_uri:
parameters['error_uri'],
state,
};
authorizationError =
new AuthorizationError(
errorJson,
);
} else {
const code =
parameters['code'];
if (!code) {
this.callbackUrl = undefined;
throw new Error(
'Authorization callback contains neither an authorization code nor an error.',
);
}
const responseJson:
AuthorizationResponseJson = {
code,
state,
};
response =
new AuthorizationResponse(
responseJson,
);
}
/*
* The response has been successfully associated with the
* pending request. It can now be consumed exactly once.
*/
await this.storage.removeItem(
AUTHORIZATION_REQUEST_KEY,
);
this.callbackUrl = undefined;
return {
request,
response,
error: authorizationError,
};
}
private parseCallbackUrl(
callbackUrl: string,
): StringMap {
const result: StringMap = {};
const url = new URL(callbackUrl);
/*
* Authorization Code Flow normally returns code/state in
* the query string:
*
* openstapps:/callback?code=...&state=...
*/
url.searchParams.forEach(
(value, key) => {
result[key] = value;
},
);
/*
* Also accept parameters in the fragment as a fallback.
*/
if (url.hash.length > 1) {
const hash =
url.hash.substring(1);
const hashParameters =
new URLSearchParams(hash);
hashParameters.forEach(
(value, key) => {
if (!(key in result)) {
result[key] = value;
}
},
);
}
return result;
}
}
@@ -13,77 +13,61 @@
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {
AppAuthError,
Requestor,
} from '@openid/appauth';
import {
CapacitorHttp,
HttpHeaders,
HttpOptions,
} from '@capacitor/core';
import {Requestor} from '@openid/appauth';
import {CapacitorHttp, HttpHeaders, HttpResponse} from '@capacitor/core';
import {XhrSettings} from 'ionic-appauth/lib/cordova';
type XhrSettings = Parameters<Requestor['xhr']>[0];
export class CapacitorRequestor implements Requestor {
public async xhr<T>(settings: XhrSettings): Promise<T> {
if (!settings.url) {
throw new AppAuthError('A URL must be provided.');
}
const method = (settings.method ?? 'GET').toUpperCase();
const url = new URL(settings.url);
let data: unknown;
if (settings.data) {
if (method === 'POST') {
data = settings.data;
} else {
const searchParams = new URLSearchParams(settings.data);
searchParams.forEach((value, key) => {
url.searchParams.append(key, value);
});
}
}
const options: HttpOptions = {
url: url.toString(),
method,
headers: this.getHeaders(settings.headers),
data,
};
if (settings.dataType?.toLowerCase() === 'json') {
options.responseType = 'json';
}
const response = await CapacitorHttp.request(options);
if (response.status < 200 || response.status >= 300) {
throw new AppAuthError(
`HTTP ${response.status}`,
response.data,
);
}
return response.data as T;
// REQUIRES CAPACITOR PLUGIN
// @capacitor-community/http
export class CapacitorRequestor extends Requestor {
constructor() {
super();
}
private getHeaders(headers: XhrSettings['headers']): HttpHeaders {
const result: HttpHeaders = {};
public async xhr<T>(settings: XhrSettings): Promise<T> {
if (!settings.method) settings.method = 'GET';
if (!headers) {
return result;
}
for (const [key, value] of Object.entries(headers)) {
if (value !== undefined && value !== null) {
result[key] = String(value);
switch (settings.method) {
case 'GET': {
return this.get(settings.url, settings.headers);
}
case 'POST': {
return this.post(settings.url, settings.data, settings.headers);
}
case 'PUT': {
return this.put(settings.url, settings.data, settings.headers);
}
case 'DELETE': {
return this.delete(settings.url, settings.headers);
}
}
}
return result;
private async get<T>(url: string, headers: HttpHeaders) {
return CapacitorHttp.get({url, headers}).then((response: HttpResponse) => response.data as T);
}
// eslint-disable-next-line @typescript-eslint/no-explicit-any
private async post<T>(url: string, data: any, headers: HttpHeaders) {
return CapacitorHttp.post({
url,
data,
headers,
}).then((response: HttpResponse) => {
return response.data as T;
});
}
// eslint-disable-next-line @typescript-eslint/no-explicit-any
private async put<T>(url: string, data: any, headers: HttpHeaders) {
return CapacitorHttp.put({
url,
data,
headers,
}).then((response: HttpResponse) => response.data as T);
}
private async delete<T>(url: string, headers: HttpHeaders) {
return CapacitorHttp.delete({url, headers}).then((response: HttpResponse) => response.data as T);
}
}
@@ -0,0 +1,104 @@
/*
* Copyright (C) 2023 StApps
* This program is free software: you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the Free
* Software Foundation, version 3.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
* more details.
*
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {TestBed} from '@angular/core/testing';
import {ConfigProvider} from '../config/config.provider';
import {StorageProvider} from '../storage/storage.provider';
import {DefaultAuthService} from './default-auth.service';
import {Browser} from 'ionic-appauth';
import {nowInSeconds, Requestor, StorageBackend} from '@openid/appauth';
import {TranslateService} from '@ngx-translate/core';
import {StAppsWebHttpClient} from '../data/stapps-web-http-client.provider';
import {provideHttpClient, withInterceptorsFromDi} from '@angular/common/http';
import {IonicStorage} from 'ionic-appauth/lib';
import {RouterModule} from '@angular/router';
import {LoggerTestingModule} from 'ngx-logger/testing';
describe('AuthService', () => {
let defaultAuthService: DefaultAuthService;
let storageBackendSpy: jasmine.SpyObj<StorageBackend>;
const storageProviderSpy = jasmine.createSpyObj('StorageProvider', ['init', 'get', 'has', 'put', 'search']);
const translateServiceSpy = jasmine.createSpyObj('TranslateService', ['setDefaultLang', 'use']);
beforeEach(() => {
storageBackendSpy = jasmine.createSpyObj('StorageBackend', ['getItem']);
TestBed.configureTestingModule({
imports: [LoggerTestingModule, RouterModule.forRoot([])],
providers: [
StAppsWebHttpClient,
{
provide: TranslateService,
useValue: translateServiceSpy,
},
{
provide: StorageProvider,
useValue: storageProviderSpy,
},
IonicStorage,
ConfigProvider,
Browser,
{
provide: StorageBackend,
useValue: storageBackendSpy,
},
Requestor,
provideHttpClient(withInterceptorsFromDi()),
],
});
defaultAuthService = TestBed.inject(DefaultAuthService);
});
describe('loadTokenFromStorage', () => {
it('should provide false through isAuthenticated$ when there is no token response', async () => {
// eslint-disable-next-line unicorn/no-null
storageBackendSpy.getItem.and.returnValue(Promise.resolve(null));
let loggedInHolder;
defaultAuthService.isAuthenticated$.subscribe(loggedIn => {
loggedInHolder = loggedIn;
});
await defaultAuthService.loadTokenFromStorage();
expect(loggedInHolder).toBeFalse();
});
it('should provide true through isAuthenticated$ when access token is valid', async () => {
const validToken = `{"access_token":"AT-XXXX","refresh_token":"RT-XXXX","scope":"","token_type":"bearer","issued_at":${nowInSeconds()},"expires_in":"${
8 * 60 * 60
}"}`;
storageBackendSpy.getItem.and.returnValue(Promise.resolve(validToken));
let loggedInHolder;
defaultAuthService.isAuthenticated$.subscribe(loggedIn => {
loggedInHolder = loggedIn;
});
await defaultAuthService.loadTokenFromStorage();
expect(loggedInHolder).toBeTrue();
});
it('should provide false through isAuthenticated$ when access token is invalid', async () => {
const invalidToken = `{"access_token":"AT-INVALID-XXXX","refresh_token":"RT-XXXX","scope":"","token_type":"bearer","issued_at":${
nowInSeconds() - 9 * 60 * 60
},"expires_in":"${8 * 60 * 60}"}`;
storageBackendSpy.getItem.and.returnValue(Promise.resolve(invalidToken));
let loggedInHolder;
defaultAuthService.isAuthenticated$.subscribe(loggedIn => {
loggedInHolder = loggedIn;
});
await defaultAuthService.loadTokenFromStorage();
expect(loggedInHolder).toBeFalse();
});
});
});
@@ -0,0 +1,102 @@
/*
* Copyright (C) 2023 StApps
* This program is free software: you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the Free
* Software Foundation, version 3.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
* more details.
*
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {
AuthorizationRequestHandler,
AuthorizationServiceConfiguration,
JQueryRequestor,
LocalStorageBackend,
Requestor,
StorageBackend,
TokenRequestHandler,
} from '@openid/appauth';
import {AuthActionBuilder, Browser, DefaultBrowser, EndSessionHandler, UserInfoHandler} from 'ionic-appauth';
import {ConfigProvider} from '../config/config.provider';
import {SCAuthorizationProvider} from '@openstapps/core';
import {getClientConfig, getEndpointsConfig} from './auth.provider.methods';
import {Injectable, inject} from '@angular/core';
import {AuthService} from './auth.service';
const TOKEN_RESPONSE_KEY = 'token_response';
@Injectable({
providedIn: 'root',
})
export class DefaultAuthService extends AuthService {
protected browser: Browser;
protected storage: StorageBackend;
protected requestor: Requestor;
private readonly configProvider = inject(ConfigProvider);
public localConfiguration: AuthorizationServiceConfiguration;
protected tokenHandler: TokenRequestHandler;
protected userInfoHandler: UserInfoHandler;
protected requestHandler: AuthorizationRequestHandler;
protected endSessionHandler: EndSessionHandler;
constructor() {
const browser = inject(Browser) ?? new DefaultBrowser();
const storage = inject(StorageBackend) ?? new LocalStorageBackend();
const requestor = inject(Requestor) ?? new JQueryRequestor();
super(browser, storage, requestor);
this.browser = browser;
this.storage = storage;
this.requestor = requestor;
}
get configuration(): Promise<AuthorizationServiceConfiguration> {
if (!this.localConfiguration) throw new Error('Local Configuration Not Defined');
return Promise.resolve(this.localConfiguration);
}
public async init() {
this.setupConfiguration();
this.setupAuthorizationNotifier();
await this.loadTokenFromStorage();
}
setupConfiguration() {
const authConfig = this.configProvider.getAnyValue('auth') as {
default: SCAuthorizationProvider;
};
this.authConfig = getClientConfig('default', authConfig);
this.localConfiguration = new AuthorizationServiceConfiguration(
getEndpointsConfig('default', authConfig),
);
}
public async signOut() {
await this.revokeTokens().catch(error => {
this.notifyActionListers(AuthActionBuilder.SignOutFailed(error));
});
this.notifyActionListers(AuthActionBuilder.SignOutSuccess());
}
public async revokeTokens() {
// Note: only locally
await this.storage.removeItem(TOKEN_RESPONSE_KEY);
this.notifyActionListers(AuthActionBuilder.RevokeTokensSuccess());
}
}
@@ -14,11 +14,9 @@
*/
import {Platform} from '@ionic/angular/standalone';
import {FetchRequestor, Requestor} from '@openid/appauth';
import {CapacitorRequestor} from '../capacitor-requestor';
import {NgHttpService} from '../ng-http.service';
export const requestorFactory = (platform: Platform): Requestor => {
return platform.is('capacitor')
? new CapacitorRequestor()
: new FetchRequestor();
export const httpFactory = (platform: Platform) => {
return platform.is('capacitor') ? new CapacitorRequestor() : new NgHttpService();
};
@@ -14,11 +14,9 @@
*/
import {Platform} from '@ionic/angular/standalone';
import {LocalStorageBackend, StorageBackend} from '@openid/appauth';
import {IonicStorage} from 'ionic-appauth/lib';
import {SafeCapacitorSecureStorage} from '../../storage/capacitor-secure-storage';
export const storageFactory = (platform: Platform): StorageBackend => {
return platform.is('capacitor')
? new SafeCapacitorSecureStorage()
: new LocalStorageBackend();
export const storageFactory = (platform: Platform) => {
return platform.is('capacitor') ? new SafeCapacitorSecureStorage() : new IonicStorage();
};
@@ -0,0 +1,77 @@
/*
* Copyright (C) 2023 StApps
* This program is free software: you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the Free
* Software Foundation, version 3.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
* more details.
*
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {Injectable, inject} from '@angular/core';
import {Requestor} from '@openid/appauth';
import {HttpClient, HttpHeaders} from '@angular/common/http';
import {XhrSettings} from 'ionic-appauth/lib/cordova';
import {firstValueFrom, Observable} from 'rxjs';
@Injectable({
providedIn: 'root',
})
export class NgHttpService implements Requestor {
private http = inject(HttpClient);
public async xhr<T>(settings: XhrSettings): Promise<T> {
if (!settings.method) {
settings.method = 'GET';
}
let observable: Observable<T>;
switch (settings.method) {
case 'GET': {
observable = this.http.get<T>(settings.url, {
headers: this.getHeaders(settings.headers),
});
break;
}
case 'POST': {
observable = this.http.post<T>(settings.url, settings.data, {
headers: this.getHeaders(settings.headers),
});
break;
}
case 'PUT': {
observable = this.http.put<T>(settings.url, settings.data, {
headers: this.getHeaders(settings.headers),
});
break;
}
case 'DELETE': {
observable = this.http.delete<T>(settings.url, {
headers: this.getHeaders(settings.headers),
});
break;
}
}
return firstValueFrom(observable);
}
// eslint-disable-next-line @typescript-eslint/no-explicit-any
private getHeaders(headers: any): HttpHeaders {
let httpHeaders: HttpHeaders = new HttpHeaders();
if (headers !== undefined) {
for (const key of Object.keys(headers)) {
httpHeaders = httpHeaders.append(key, headers[key]);
}
}
return httpHeaders;
}
}
@@ -0,0 +1,21 @@
/*
* Copyright (C) 2022 StApps
* This program is free software: you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the Free
* Software Foundation, version 3.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
* more details.
*
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
export interface IUserInfo {
display_name: string;
role: string;
email: string;
user_name: string;
}
@@ -1,19 +1,16 @@
import {Injectable, inject} from '@angular/core';
import {SCIdCard, SCThingOriginType, SCThingType, SCUserConfiguration} from '@openstapps/core';
import {from, of, Observable} from 'rxjs';
import {AuthHelperService} from '../auth/auth-helper.service';
import {mergeMap, concatWith, filter, map, startWith, catchError, tap} from 'rxjs/operators';
import {ConfigProvider} from '../config/config.provider';
import {HttpClient} from '@angular/common/http';
import {EncryptedStorageProvider} from '../storage/encrypted-storage.provider';
import {AuthProvider} from "../auth/auth.provider";
import {AuthHelperService} from "../auth/auth-helper.service";
@Injectable({providedIn: 'root'})
export class IdCardsProvider {
private authHelper = inject(AuthHelperService);
private authProvider = inject(AuthProvider);
private config = inject(ConfigProvider);
private httpClient = inject(HttpClient);
@@ -22,7 +19,7 @@ export class IdCardsProvider {
getIdCards(): Observable<SCIdCard[]> {
const feature = this.config.config.app.features.extern?.['idCards'];
const auth = this.authProvider;
const auth = this.authHelper.getProvider();
const storedIdCards = from(
this.encryptedStorageProvider.get<SCIdCard[]>('id-cards') as Promise<SCIdCard[]>,
).pipe(filter(it => it !== undefined));
@@ -7,6 +7,7 @@ import {EncryptedStorageProvider} from '../storage/encrypted-storage.provider';
import {TestBed} from '@angular/core/testing';
import {TranslateService} from '@ngx-translate/core';
import {StorageBackend, Requestor} from '@openid/appauth';
import {IonicStorage, Browser} from 'ionic-appauth';
import {LoggerTestingModule} from 'ngx-logger/testing';
import {StAppsWebHttpClient} from '../data/stapps-web-http-client.provider';
import {SimpleBrowser} from '../../util/browser.factory';
@@ -19,7 +19,6 @@ import {AuthHelperService} from '../../auth/auth-helper.service';
import {mergeMap, of} from 'rxjs';
import Swiper from 'swiper';
import {toObservable, toSignal} from '@angular/core/rxjs-interop';
import {AuthProvider} from "../../auth/auth.provider";
@Component({
selector: 'stapps-profile-page-section',
@@ -33,11 +32,10 @@ export class ProfilePageSectionComponent {
minSlideWidth = input(110);
authHelper = inject(AuthHelperService);
authProvider = inject(AuthProvider);
loggedIn = toSignal(
toObservable(this.item).pipe(
mergeMap(item => (item.authProvider ? this.authProvider.isLoggedIn$ : of(false))),
mergeMap(item => (item.authProvider ? this.authHelper.getProvider().isLoggedIn$ : of(false))),
),
);
@@ -68,11 +66,13 @@ export class ProfilePageSectionComponent {
}
async toggleLogIn() {
const providerType = this.item().authProvider;
if (!providerType) return;
if (this.loggedIn()) {
await this.authProvider.signOut();
await this.authHelper.endBrowserSession();
await this.authHelper.getProvider().signOut();
await this.authHelper.endBrowserSession(providerType);
} else {
await this.authProvider.signIn();
await this.authHelper.getProvider().signIn();
}
}
@@ -13,7 +13,7 @@
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {Component, inject} from '@angular/core';
import {AuthProvider} from '../../auth/auth.provider';
import {AuthHelperService} from '../../auth/auth-helper.service';
import {ActivatedRoute} from '@angular/router';
import {ScheduleProvider} from '../../calendar/schedule.provider';
import {profilePageSections} from '../../../../config/profile-page-sections';
@@ -25,7 +25,7 @@ import {profilePageSections} from '../../../../config/profile-page-sections';
standalone: false,
})
export class ProfilePageComponent {
readonly authProvider = inject(AuthProvider);
readonly authHelper = inject(AuthHelperService);
readonly activatedRoute = inject(ActivatedRoute);
@@ -33,7 +33,23 @@ export class ProfilePageComponent {
sections = profilePageSections;
ionViewWillEnter(): void {
void this.authProvider.loadUserInfo();
async signIn() {
const originPath = this.activatedRoute.snapshot.queryParamMap.get('origin_path');
await (originPath ? this.authHelper.setOriginPath(originPath) : this.authHelper.deleteOriginPath());
await this.authHelper.getProvider().signIn();
}
async signOut() {
await this.authHelper.getProvider().signOut();
}
ionViewWillEnter() {
this.authHelper
.getProvider()
.getValidToken()
.then(() => void this.authHelper.getProvider().loadUserInfo())
.catch(() => {
// noop
});
}
}
@@ -13,11 +13,9 @@
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {Pipe, PipeTransform, inject} from '@angular/core';
import {TranslateService} from '@ngx-translate/core';
import {Pipe, PipeTransform} from '@angular/core';
import {SCSetting} from '@openstapps/core';
import {ThingTranslatePipe} from '../../translation/thing-translate.pipe';
import {ThingTranslateService} from '../../translation/thing-translate.service';
/**
* Translates a setting value (into the display value in current language)
@@ -28,13 +26,10 @@ import {ThingTranslateService} from '../../translation/thing-translate.service';
standalone: false,
})
export class SettingTranslatePipe implements PipeTransform {
private readonly translate = inject(TranslateService);
private readonly thingTranslate = inject(ThingTranslateService);
private readonly thingTranslatePipe = new ThingTranslatePipe();
transform(setting: SCSetting): string | undefined {
const thingTranslatePipe = new ThingTranslatePipe();
const translatedSettingValues = thingTranslatePipe.transform('values', setting);
const translatedSettingValues = this.thingTranslatePipe.transform('values', setting);
return translatedSettingValues
? String(translatedSettingValues[setting.values?.indexOf(setting.value as string) as number])
@@ -12,58 +12,19 @@
* You should have received a copy of the GNU General Public License along with
* this program. If not, see <https://www.gnu.org/licenses/>.
*/
import {CapacitorSecureStorage} from 'ionic-appauth/lib/capacitor';
import {StorageBackend} from '@openid/appauth';
import {SecureStoragePlugin} from 'capacitor-secure-storage-plugin';
/**
* Secure storage backend for AppAuth on native Capacitor platforms.
*
* Removes an existing item before writing it again to avoid issues
* observed after iOS upgrades.
/*
* Removes an item from storage before entering the new one to avoid issues
* after iOS upgrade (iOS 16)
*/
export class SafeCapacitorSecureStorage implements StorageBackend {
public async getItem(name: string): Promise<string | null> {
export class SafeCapacitorSecureStorage extends CapacitorSecureStorage {
async setItem(name: string, value: string): Promise<void> {
if (!Storage) throw new Error('Capacitor Storage Is Undefined!');
try {
const {value} = await SecureStoragePlugin.get({
key: name,
});
return value;
} catch {
return null;
}
}
public async setItem(
name: string,
value: string,
): Promise<void> {
try {
await SecureStoragePlugin.remove({
key: name,
});
} catch {
// Item does not exist yet.
}
await SecureStoragePlugin.set({
key: name,
value,
});
}
public async removeItem(name: string): Promise<void> {
try {
await SecureStoragePlugin.remove({
key: name,
});
} catch {
// Removing a non-existing item is fine.
}
}
public async clear(): Promise<void> {
await SecureStoragePlugin.clear();
await super.removeItem(name);
} catch {}
return super.setItem(name, value);
}
}
@@ -19,9 +19,9 @@
export const environment = {
backend_url: 'https://mobile.server.uni-frankfurt.de',
app_host: 'dev.app.uni-frankfurt.de',
app_host: 'mobile.app.uni-frankfurt.de',
custom_url_scheme: 'de.anyschool.app',
backend_version: '999.0.0',
backend_version: '4.0.0',
production: true,
};
+1 -2
View File
@@ -19,9 +19,8 @@
export const environment = {
backend_url: 'https://mobile.server.uni-frankfurt.de',
// backend_url: 'http://localhost:3000',
app_host: 'mobile.app.uni-frankfurt.de',
custom_url_scheme: 'de.unifrankfurt.app',
custom_url_scheme: 'de.anyschool.app',
backend_version: '999.0.0',
production: false,
};
+4 -4
View File
@@ -15,6 +15,10 @@
// http://ionicframework.com/docs/theming/
@use 'swiper/scss';
@use 'swiper/scss/controller';
@use 'swiper/scss/navigation';
@use 'theme/common/helper';
@use 'theme/common/ion-alert';
@use 'theme/common/ion-button';
@@ -56,10 +60,6 @@
@import 'maplibre-gl/dist/maplibre-gl.css';
@import 'swiper/scss';
@import 'swiper/scss/controller';
@import 'swiper/scss/navigation';
.add-event-popover {
--width: fit-content;
--max-width: 95%;
+4 -4
View File
@@ -1,17 +1,17 @@
### Set base image
FROM ubuntu:22.04
FROM ubuntu:24.04
LABEL version="2.0.0" \
description="Build environment for the StApps app." \
maintainer="Jovan Krunić <krunic@uni-frankfurt.de>"
### Configure versions to install
ENV ANDROID_APIS="android-34" \
ANDROID_BUILD_TOOLS_VERSION="34.0.0" \
ENV ANDROID_APIS="android-36" \
ANDROID_BUILD_TOOLS_VERSION="36.0.0" \
NODE_VERSION="22.x" \
NPM_VERSION="^10.0.0" \
IONIC_VERSION="^7.0.0" \
CAPACITOR_VERSION="^7.0.0" \
CAPACITOR_VERSION="^8.0.0" \
CORDOVA_RES_VERSION="latest" \
### Configure download URLs
ANDROID_SDK_TOOLS_DOWNLOAD_URL="https://dl.google.com/android/repository/commandlinetools-linux-13114758_latest.zip" \
+616 -517
View File
File diff suppressed because it is too large Load Diff