UNPKG

@esri/arcgis-rest-auth

Version:

Authentication helpers for @esri/arcgis-rest-js.

110 lines 4.28 kB
"use strict"; /* Copyright (c) 2018-2020 Environmental Systems Research Institute, Inc. * Apache-2.0 */ Object.defineProperty(exports, "__esModule", { value: true }); exports.platformSelf = exports.exchangeToken = void 0; var arcgis_rest_request_1 = require("@esri/arcgis-rest-request"); /** * Request app-specific token, passing in the token for the current app. * * This call returns a token after performing the same checks made by validateAppAccess. * It returns an app-specific token of the signed-in user only if the user has access * to the app and the encrypted platform cookie is valid. * * A scenario where an app would use this is if it is iframed into another platform app * and receives credentials via postMessage. Those credentials contain a token that is * specific to the host app, so the embedded app would use `exchangeToken` to get one * that is specific to itself. * * Note: This is only usable by Esri applications hosted on *arcgis.com, *esri.com or within * an ArcGIS Enterprise installation. Custom applications can not use this. * * @param token * @param clientId application * @param portal */ function exchangeToken(token, clientId, portal) { if (portal === void 0) { portal = "https://www.arcgis.com/sharing/rest"; } var url = portal + "/oauth2/exchangeToken"; var ro = { method: "POST", params: { f: "json", client_id: clientId, token: token, }, }; // make the request and return the token return arcgis_rest_request_1.request(url, ro).then(function (response) { return response.token; }); } exports.exchangeToken = exchangeToken; /** * @internal * Request a token for a specific application using the esri_aopc encrypted cookie * * When a client app boots up, it will know its clientId and the redirectUri for use * in the normal /oauth/authorize pop-out oAuth flow. * * If the app sees an `esri_aopc` cookie (only set if the app is hosted on *.arcgis.com), * it can call the /oauth2/platformSelf end-point passing in the clientId and redirectUri * in headers, and it will receive back an app-specific token, assuming the user has * access to the app. * * Since there are scenarios where an app can boot using credentials/token from localstorage * but those credentials are not for the same user as the esri_aopc cookie, it is recommended that * an app check the returned username against any existing identity they may have loaded. * * Note: This is only usable by Esri applications hosted on *arcgis.com, *esri.com or within * an ArcGIS Enterprise installation. Custom applications can not use this. * * ```js * // convert the encrypted platform cookie into a UserSession * import { platformSelf, UserSession } from '@esri/arcgis-rest-auth'; * * const portal = 'https://www.arcgis.com/sharing/rest'; * const clientId = 'YOURAPPCLIENTID'; * * // exchange esri_aopc cookie * return platformSelf(clientId, 'https://your-app-redirect-uri', portal) * .then((response) => { * const currentTimestamp = new Date().getTime(); * const tokenExpiresTimestamp = currentTimestamp + (response.expires_in * 1000); * // Construct the session and return it * return new UserSession({ * portal, * clientId, * username: response.username, * token: response.token, * tokenExpires: new Date(tokenExpiresTimestamp), * ssl: true * }); * }) * * ``` * * * @param clientId * @param redirectUri * @param portal */ function platformSelf(clientId, redirectUri, portal) { if (portal === void 0) { portal = "https://www.arcgis.com/sharing/rest"; } // TEMPORARY: the f=json should not be needed, but currently is var url = portal + "/oauth2/platformSelf?f=json"; var ro = { method: "POST", headers: { "X-Esri-Auth-Client-Id": clientId, "X-Esri-Auth-Redirect-Uri": redirectUri, }, // Note: request has logic to include the cookie // for platformSelf calls w/ the X-Esri-Auth-Client-Id header params: { f: "json", }, }; // make the request and return the token return arcgis_rest_request_1.request(url, ro); } exports.platformSelf = platformSelf; //# sourceMappingURL=app-tokens.js.map