Skip to content
View as Markdown
View as Markdown

@salesforce/b2c-tooling-sdk / auth / UserAuthStrategy

Interface: UserAuthStrategy

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:83

An interactive, token-bearing OAuth strategy — the "user" auth flow (Authorization Code + PKCE, with the legacy implicit flow as fallback).

Unlike the base AuthStrategy, these always expose the access token / decoded JWT so callers like auth token can surface them. Implemented by PkceOAuthStrategy, ImplicitOAuthStrategy, and the transitional PkceWithImplicitFallbackStrategy.

Extends

Properties

authMethod

readonly authMethod: "user" | "implicit"

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:85

Browser auth method represented by this strategy.

Methods

fetch()

fetch(url, init?): Promise<Response>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:22

Performs a fetch request with authentication. Implementations MUST handle header injection and 401 retries (token refresh) internally.

Parameters

url

string

init?

FetchInit

Returns

Promise<Response>

Inherited from

AuthStrategy.fetch


getAccessTokenForCascade()?

optional getAccessTokenForCascade(candidates): Promise<string>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:71

Optional: Resolves a scope cascade by trying each candidate scope set in order and returning the first that AM accepts.

Implementations should:

  1. Return any cached token whose scopes ⊇ a candidate (no AM call).
  2. Otherwise, call AM with each candidate in order until one survives; cache the result keyed by what was requested.
  3. Throw the last invalid_scope error if all candidates fail.

Implementations MUST add any base scopes (e.g. tenant scope baked in via withAdditionalScopes) to each candidate before sending it to AM.

Used by the SCAPI auth middleware to pick the right scope tier (rw vs ro) per operation. Strategies without OAuth-style scope grants (basic, api-key) should leave this unset; the middleware falls through to getAuthorizationHeader in that case.

Parameters

candidates

string[][]

Outer array is cascade order; inner arrays are the scopes for each token request attempt. e.g. [['sfcc.jobs.rw'], ['sfcc.jobs']].

Returns

Promise<string>

The access token (Bearer value, no Bearer prefix).

Inherited from

AuthStrategy.getAccessTokenForCascade


getAuthorizationHeader()

getAuthorizationHeader(): Promise<string>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:86

Optional: Helper for legacy clients (like a strict WebDAV lib) that need the raw header.

Returns

Promise<string>

Overrides

AuthStrategy.getAuthorizationHeader


getJWT()

getJWT(): Promise<DecodedJWT>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:87

Returns

Promise<DecodedJWT>


getTokenResponse()

getTokenResponse(): Promise<AccessTokenResponse>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:88

Returns

Promise<AccessTokenResponse>


invalidateToken()

invalidateToken(): void

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:89

Optional: Invalidates the cached token, forcing re-authentication on next request. Used by middleware to retry requests after receiving a 401 response.

Returns

void

Overrides

AuthStrategy.invalidateToken


withAdditionalScopes()?

optional withAdditionalScopes(additionalScopes): AuthStrategy

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:45

Optional: Returns a copy of this strategy with the given scopes merged into its requested scope set. SCAPI client factories use this to ensure the tenant scope is present on every token request.

Implemented by OAuthStrategy and JwtOAuthStrategy. Strategies that obtain tokens by other means (basic, api-key, implicit-via-stored-session) may not implement this; callers should treat them as "scopes already established at construction time."

Parameters

additionalScopes

string[]

Returns

AuthStrategy

Inherited from

AuthStrategy.withAdditionalScopes

Released under the Apache-2.0 License.