@salesforce/b2c-tooling-sdk / auth / UserAuthStrategy
Interface: UserAuthStrategy
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:83
An interactive, token-bearing OAuth strategy — the "user" auth flow (Authorization Code + PKCE, with the legacy implicit flow as fallback).
Unlike the base AuthStrategy, these always expose the access token / decoded JWT so callers like auth token can surface them. Implemented by PkceOAuthStrategy, ImplicitOAuthStrategy, and the transitional PkceWithImplicitFallbackStrategy.
Extends
Properties
authMethod
readonlyauthMethod:"user"|"implicit"
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:85
Browser auth method represented by this strategy.
Methods
fetch()
fetch(
url,init?):Promise<Response>
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:22
Performs a fetch request with authentication. Implementations MUST handle header injection and 401 retries (token refresh) internally.
Parameters
url
string
init?
Returns
Promise<Response>
Inherited from
getAccessTokenForCascade()?
optionalgetAccessTokenForCascade(candidates):Promise<string>
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:71
Optional: Resolves a scope cascade by trying each candidate scope set in order and returning the first that AM accepts.
Implementations should:
- Return any cached token whose scopes ⊇ a candidate (no AM call).
- Otherwise, call AM with each candidate in order until one survives; cache the result keyed by what was requested.
- Throw the last
invalid_scopeerror if all candidates fail.
Implementations MUST add any base scopes (e.g. tenant scope baked in via withAdditionalScopes) to each candidate before sending it to AM.
Used by the SCAPI auth middleware to pick the right scope tier (rw vs ro) per operation. Strategies without OAuth-style scope grants (basic, api-key) should leave this unset; the middleware falls through to getAuthorizationHeader in that case.
Parameters
candidates
string[][]
Outer array is cascade order; inner arrays are the scopes for each token request attempt. e.g. [['sfcc.jobs.rw'], ['sfcc.jobs']].
Returns
Promise<string>
The access token (Bearer value, no Bearer prefix).
Inherited from
AuthStrategy.getAccessTokenForCascade
getAuthorizationHeader()
getAuthorizationHeader():
Promise<string>
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:86
Optional: Helper for legacy clients (like a strict WebDAV lib) that need the raw header.
Returns
Promise<string>
Overrides
AuthStrategy.getAuthorizationHeader
getJWT()
getJWT():
Promise<DecodedJWT>
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:87
Returns
Promise<DecodedJWT>
getTokenResponse()
getTokenResponse():
Promise<AccessTokenResponse>
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:88
Returns
Promise<AccessTokenResponse>
invalidateToken()
invalidateToken():
void
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:89
Optional: Invalidates the cached token, forcing re-authentication on next request. Used by middleware to retry requests after receiving a 401 response.
Returns
void
Overrides
withAdditionalScopes()?
optionalwithAdditionalScopes(additionalScopes):AuthStrategy
Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:45
Optional: Returns a copy of this strategy with the given scopes merged into its requested scope set. SCAPI client factories use this to ensure the tenant scope is present on every token request.
Implemented by OAuthStrategy and JwtOAuthStrategy. Strategies that obtain tokens by other means (basic, api-key, implicit-via-stored-session) may not implement this; callers should treat them as "scopes already established at construction time."
Parameters
additionalScopes
string[]