@sap-cloud-sdk/connectivity
Version:
SAP Cloud SDK for JavaScript connectivity
53 lines (52 loc) • 3.66 kB
TypeScript
import type { IasTokenOptions, IasTokenResult } from './destination/ias-types';
import type { Destination } from './destination/destination-service-types';
import type { Service, ServiceCredentials } from './environment-accessor';
import type { CachingOptions } from './cache';
import type { JwtPayload } from './jsonwebtoken-type';
/**
* Returns an access token that can be used to call the given service. The token is fetched via a client credentials grant with the credentials of the given service.
* If multiple instances of the provided service exist, the first instance will be selected.
* When a JWT is passed, the tenant of the JWT will be used when performing the grant.
* When no JWT is passed, the grant will be performed using the provider tenant.
*
* Throws an error if there is no instance of the given service type or the XSUAA service, or if the request to the XSUAA service fails.
* @param service - The type of the service or an instance of {@link Service}.
* @param options - Options to influence caching behavior (see {@link CachingOptions}) and a JWT. By default, caching and usage of a circuit breaker are enabled.
* @returns Access token.
*/
export declare function serviceToken(service: string | Service, options?: CachingOptions & {
jwt?: string | JwtPayload;
}): Promise<string>;
/**
* Returns a JWT bearer token that can be used to call the given service.
* The token is fetched via a JWT bearer token grant using the user token + client credentials.
*
* Throws an error if there is no instance of the given service type.
* @param jwt - The JWT of the user for whom the access token should be fetched.
* @param service - The type of the service or an instance of {@link Service}.
* @returns A JWT bearer token.
*/
export declare function jwtBearerToken(jwt: string, service: string | Service): Promise<string>;
/**
* Returns an IAS token from the Identity Authentication Service.
* Supports both technical user (OAuth2ClientCredentials) and business user (OAuth2JWTBearer) flows.
* @remarks
* Prefer using `'identity'` (default) for the `service` parameter.
* Passing raw ServiceCredentials or Service directly is only recommended for environments where service bindings are unavailable as they hardcode the credentials.
* @param service - Service credentials {@link ServiceCredentials}, the service type (always 'identity' for IAS), or a {@link Service} binding.
* @param options - Options for IAS token retrieval. See {@link IasTokenOptions}.
* @returns An {@link IasTokenResult} containing the access token, expiration, and optional refresh token.
*/
export declare function getIasToken(service?: ServiceCredentials | 'identity' | Service, options?: IasTokenOptions): Promise<IasTokenResult>;
/**
* Creates an {@link Destination} from IAS service credentials.
* Fetches an IAS token and builds a destination with the token, mTLS key pair (if available),
* and the target URL.
* @remarks
* Prefer using `'identity'` (default) for the `service` parameter.
* Passing raw ServiceCredentials or Service directly is only recommended for environments where service bindings are unavailable as they hardcode the credentials.
* @param service - Service credentials {@link ServiceCredentials}, the service type (always 'identity' for IAS), or a {@link Service} binding.
* @param options - Options for IAS token retrieval and destination configuration. See {@link IasTokenOptions}.
* @returns A promise that resolves to an HTTP destination.
*/
export declare function createDestinationFromIasService(service?: ServiceCredentials | 'identity' | Service, options?: IasTokenOptions): Promise<Destination>;