Member Junction
    Preparing search index...

    Auth0 authentication provider implementation - v3.0.0

    Implements the abstract methods from MJAuthBase to hide Auth0-specific details. The key abstraction is that Auth0 stores the JWT in idTokenClaims.__raw, but consumers never need to know this detail.

    Hierarchy (View Summary)

    Index

    Constructors

    Properties

    auth: AuthService
    isAuthenticated$: BehaviorSubject<boolean> = ...
    type: "auth0" = MJAuth0Provider.PROVIDER_TYPE

    Provider type identifier Must be implemented by concrete providers

    userEmail$: BehaviorSubject<string> = ...
    userInfo$: BehaviorSubject<StandardUserInfo | null> = ...
    PROVIDER_TYPE: "auth0" = 'auth0'

    Accessors

    • get preservedLocalStorageKeys(): Set<string>

      localStorage keys that survive a logout (e.g. UI theme preference).

      Override this getter in a subclass to preserve additional keys specific to your provider or application.

      Returns Set<string>

    Methods

    • Get profile picture URL from auth provider

      Returns the user's profile picture URL if available from the auth provider. This abstracts away provider-specific logic:

      • Microsoft/MSAL: Fetches from Graph API
      • Auth0/Okta: Returns from user claims

      Returns Promise<string | null>

      Promise resolving to image URL or null if not available

      const pictureUrl = await this.authBase.getProfilePictureUrl();
      if (pictureUrl) {
      this.userAvatar = pictureUrl;
      }
    • Logout — clears all MJ client-side caches then delegates to the provider.

      Cache clearing happens universally regardless of auth provider so that a subsequent login as a different user never sees the previous user's data. Providers that need to clear additional caches should override logoutInternal() and call super.logoutInternal() if applicable.

      Returns Promise<void>

    • Refresh authentication token

      Attempts to obtain a fresh authentication token using the provider's refresh mechanism. If silent refresh fails due to session expiry, the provider will handle re-authentication automatically (which may involve redirecting to the auth provider's login page).

      Returns StandardAuthToken on success, or throws on complete failure.

      IMPORTANT: If the provider requires interactive re-authentication (redirect or popup), this method may never return. The app will reload after authentication completes and re-initialize with a fresh token.

      Returns Promise<StandardAuthToken>

      Promise resolving to StandardAuthToken or throws on failure

      const token = await this.authBase.refreshToken();
      return token.idToken; // Always succeeds or throws
    • Factory function to provide Angular dependencies required by Auth0 Stored as a static property for the factory to access without instantiation

      Parameters

      • environment: Record<string, unknown>

      Returns (
          | typeof AuthService
          | typeof AuthGuard
          | {
              deps?: undefined;
              provide: InjectionToken<AuthConfig>;
              useFactory?: undefined;
              useValue: {
                  authorizationParams: { redirect_uri: string; scope: string };
                  cacheLocation: string;
                  clientId: unknown;
                  domain: unknown;
                  skipRedirectCallback: boolean;
                  useRefreshTokens: boolean;
                  useRefreshTokensFallback: boolean;
              };
          }
          | {
              deps: typeof AuthClientConfig[];
              provide: InjectionToken<Auth0Client>;
              useFactory: (configFactory: AuthClientConfig) => Auth0Client;
              useValue?: undefined;
          }
      )[]