Member Junction
    Preparing search index...

    AWS Cognito authentication provider implementation - v3.0.0

    Implements the abstract methods from MJAuthBase to hide Cognito-specific details. Uses AWS Amplify v6 (tree-shakeable subpath imports) for authentication.

    Key abstraction: Cognito stores tokens in Amplify's internal storage, accessed via fetchAuthSession().tokens?.idToken?.toString(). Consumers never need to know this detail.

    This provider uses the Cognito Hosted UI for login via signInWithRedirect(). The flow is: redirect to Hosted UI -> user authenticates -> redirect back with authorization code -> Amplify exchanges code for tokens (PKCE).

    Hierarchy (View Summary)

    Index

    Constructors

    Properties

    isAuthenticated$: BehaviorSubject<boolean> = ...
    type: "cognito" = MJCognitoProvider.PROVIDER_TYPE

    Provider type identifier Must be implemented by concrete providers

    userEmail$: BehaviorSubject<string> = ...
    userInfo$: BehaviorSubject<StandardUserInfo | null> = ...
    PROVIDER_TYPE: "cognito" = 'cognito'

    Accessors

    • get preservedLocalStorageKeys(): Set<string>

      localStorage keys that survive a logout (e.g. UI theme preference).

      Override this getter in a subclass to preserve additional keys specific to your provider or application.

      Returns Set<string>

    Methods

    • Get profile picture URL from auth provider

      Returns the user's profile picture URL if available from the auth provider. This abstracts away provider-specific logic:

      • Microsoft/MSAL: Fetches from Graph API
      • Auth0/Okta: Returns from user claims

      Returns Promise<string | null>

      Promise resolving to image URL or null if not available

      const pictureUrl = await this.authBase.getProfilePictureUrl();
      if (pictureUrl) {
      this.userAvatar = pictureUrl;
      }
    • Logout — clears all MJ client-side caches then delegates to the provider.

      Cache clearing happens universally regardless of auth provider so that a subsequent login as a different user never sees the previous user's data. Providers that need to clear additional caches should override logoutInternal() and call super.logoutInternal() if applicable.

      Returns Promise<void>

    • Refresh authentication token

      Attempts to obtain a fresh authentication token using the provider's refresh mechanism. If silent refresh fails due to session expiry, the provider will handle re-authentication automatically (which may involve redirecting to the auth provider's login page).

      Returns StandardAuthToken on success, or throws on complete failure.

      IMPORTANT: If the provider requires interactive re-authentication (redirect or popup), this method may never return. The app will reload after authentication completes and re-initialize with a fresh token.

      Returns Promise<StandardAuthToken>

      Promise resolving to StandardAuthToken or throws on failure

      const token = await this.authBase.refreshToken();
      return token.idToken; // Always succeeds or throws
    • Factory function to provide Angular dependencies required by the Cognito provider. Returns a config injection token following the Okta provider pattern.

      Parameters

      • environment: Record<string, unknown>

      Returns { provide: string; useValue: CognitoConfig }[]