crouter

Signing people in

The OAuth client that connects a person to the app, where connections are stored, and how a refused refresh is read.

Exports of @crouter/sdk, read from the TypeScript compiler at build time. Types re-exported from @crouter/api are documented with that package.

AuthorizeNonce

type declared in oauth/index.ts

authorizeUrl's nonce: string when the scopes are known to include openid, undefined when known not to, else either.

string extends S[number] ? string | undefined : "openid" extends S[number] ? string : undefined

Connection

interface declared in oauth/index.ts

Prop

Type

ConnectionStore

interface declared in oauth/index.ts

Prop

Type

generateKeyPair

function declared in oauth/keygen.ts

Make an app signing key and the public JWK to register in the directory.

() => Promise<{ privateJwk: JWK; publicJwk: JWK; kid: string; }>

Identity

interface declared in oauth/index.ts

A person's crouter cloud identity from a sign-in-only (openid, openid email, openid profile, or openid email profile) request, read from an ID token the SDK verified: ES256 signature against the directory's JWKS, iss, aud = the client id, exp, and the nonce from authorizeUrl. It is not a connection: it holds no runtime URL, refresh token, or grant, and nothing can be called on the person's runtime with it.

Prop

Type

MemoryConnectionStore

class declared in oauth/index.ts

Prop

Type

OAuth2Client

class declared in oauth/index.ts

Prop

Type

OAuth2Options

interface declared in oauth/index.ts

Prop

Type

parsePrivateJwk

function declared in oauth/keygen.ts

Check that value (a JWK object or its JSON text) is a private signing key with a kid, and return it as OAuth2Options.privateKey takes it. source names where it came from in the error, e.g. a file path.

(value: string | JWK, source?: string) => JWK & { d: string; kid: string; }

privateKeyFromFile

function declared in oauth/keygen.ts

Read a private JWK file, such as the one crouter-sdk keygen writes, and check it as parsePrivateJwk does. Node only.

(path: string) => Promise<JWK & { d: string; kid: string; }>

profileFromClaims

function declared in oauth/index.ts

The profile claims a verified ID token carries, each only when present: use it on Connection.idToken after verifyIdToken for a sign-in that requested runtime scopes (exchangeCode), as exchangeIdentity does for a sign-in-only one.

(claims: IdTokenClaims) => Pick<Identity, 'name' | 'givenName' | 'familyName' | 'picture'>

RefreshFailure

interface declared in oauth/index.ts

One connection refreshIdleConnections could not refresh. reason is refreshRefusal(error).

Prop

Type

refreshRefusal

function declared in oauth/index.ts

What a refused refresh means (RefreshRefusal), or null when error is not the directory refusing one. Takes any error a connected client or refresh threw; only APIError with origin: 'directory' counts.

(error: unknown) => RefreshRefusal | null

RefreshRefusal

type declared in oauth/index.ts

Why the directory refused a connection's refresh token, and what it means for the app's data: - removed (grant_removed): the person removed the app or deleted their account. The runtime has deleted the app's runs; delete what the app stores for them. - paused (grant_suspended): the grant is suspended or expired. Nothing was deleted; keep the person's data and show the app paused until they sign in again. - reconnect (refresh_token_expired, refresh_token_reused, or grant_revoked with no reason given): the grant still exists. Nothing was deleted; drop the dead connection and ask them to sign in again.

"paused" | "reconnect" | "removed"

On this page