CLASS
OAuthTokenManager
Contents
- Properties
oauthTokenConfiguration
- Methods
init(oauthTokenConfiguration:)fetchAccessToken(with:dpop:additionalParameters:)refreshAccessToken(with:additionalParameters:)revokeAccessToken(with:)revokeRefreshToken(with:)dpop(forAccessToken:)
@objcMembers public final class OAuthTokenManager: NSObject, Sendable
OAuthTokenManager instances are used to fetch or refresh an access token.
Properties
oauthTokenConfiguration
public let oauthTokenConfiguration: OAuthTokenConfigurable
The configuration used to build this instance.
Methods
init(oauthTokenConfiguration:)
@objc public convenience init(oauthTokenConfiguration: OAuthTokenConfigurable)
Creates an OAuthTokenManager instance.
- Parameters:
- oauthTokenConfiguration: The configuration used to build this instance.
Parameters
| Name | Description |
|---|---|
| oauthTokenConfiguration | The configuration used to build this instance. |
fetchAccessToken(with:dpop:additionalParameters:)
public func fetchAccessToken(
with authorizationCode: String,
dpop: Dpop? = nil,
additionalParameters: [String: String]? = nil
) async -> TokenResponse
Fetches an access token using an authorization code grant.
If it succeeds then a SuccessfulTokenResponse with the access token is returned.
If it fails either a ErrorTokenResponse with the error reason is returned or the result has an Error.
- Parameters:
- authorizationCode: The authorization code.
- dpop: The Dpop that was used during the Haapi flow. When it is required, this value has to be used via HaapiManager.dpop.
- additionalParameters: The additional parameters for the request body. The default value is nil.
- Returns: A TokenResponse.
Parameters
| Name | Description |
|---|---|
| authorizationCode | The authorization code. |
| dpop | The Dpop that was used during the Haapi flow. When it is required, this value has to be used via HaapiManager.dpop. |
| additionalParameters | The additional parameters for the request body. The default value is nil. |
refreshAccessToken(with:additionalParameters:)
public func refreshAccessToken(
with refreshToken: String,
additionalParameters: [String: String]? = nil
) async -> TokenResponse
Refresh an access token by providing a refresh token.
If it succeeds then a SuccessfulTokenResponse with the access token is returned.
If it fails either an ErrorTokenResponse with the error reason is returned or the result has an Error.
- Parameters:
- refreshToken: The refresh token.
- additionalParameters: The additional parameters for the request body. The default value is nil.
- Returns: A TokenResponse.
Parameters
| Name | Description |
|---|---|
| refreshToken | The refresh token. |
| additionalParameters | The additional parameters for the request body. The default value is nil. |
revokeAccessToken(with:)
public func revokeAccessToken(with token: String) async -> TokenRevocationResponse
Revokes an access token.
If it succeeds then a successfulRevocation is returned.
If it fails an error response is returned containing an Error.
- Parameters:
- token: The token to be revoked.
- Returns: A TokenRevocationResponse.
Parameters
| Name | Description |
|---|---|
| token | The token to be revoked. |
revokeRefreshToken(with:)
public func revokeRefreshToken(with token: String) async -> TokenRevocationResponse
Revokes a refresh token.
If it succeeds then a success is returned.
If it fails an error response is returned containing an Error.
- Parameters:
- token: The token to be revoked.
- Returns: A TokenRevocationResponse.
Parameters
| Name | Description |
|---|---|
| token | The token to be revoked. |
dpop(forAccessToken:)
public func dpop(forAccessToken accessToken: String) throws -> Dpop?
Returns the Dpop the given access token is bound to, for presenting that token to a resource server.
- Parameters:
- accessToken: The access token whose bound
Dpopis requested. A refresh token is not accepted here and yieldsnil.
- accessToken: The access token whose bound
- Returns: The
Dpopbound toaccessToken, ornilwhen none is — an unbound client, a superseded or revoked token, or a token that is not an access token. - Throws:
HaapiError.dpopProofFailurewhen the storage could not be read, so a recoverable failure such as a locked keychain can be told apart from a token that has no DPoP. - Note: An app upgrading from 5.6.0 gets
nilfor an access token it already held, until its next successful token response re-stores the entry.
Parameters
| Name | Description |
|---|---|
| accessToken | The access token whose bound Dpop is requested. A refresh token is not accepted here and yields nil. |