Skip to content
View as Markdown
View as Markdown

@salesforce/b2c-tooling-sdk / auth / UserAuthStrategy

Interface: UserAuthStrategy

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:45

An interactive, token-bearing OAuth strategy — the "user" auth flow (Authorization Code + PKCE, with the legacy implicit flow as fallback).

Unlike the base AuthStrategy, these always expose the access token / decoded JWT so callers like auth token can surface them. Implemented by PkceOAuthStrategy, ImplicitOAuthStrategy, and the transitional PkceWithImplicitFallbackStrategy.

Extends

Methods

fetch()

fetch(url, init?): Promise<Response>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:22

Performs a fetch request with authentication. Implementations MUST handle header injection and 401 retries (token refresh) internally.

Parameters

url

string

init?

FetchInit

Returns

Promise<Response>

Inherited from

AuthStrategy.fetch


getAuthorizationHeader()

getAuthorizationHeader(): Promise<string>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:46

Optional: Helper for legacy clients (like a strict WebDAV lib) that need the raw header.

Returns

Promise<string>

Overrides

AuthStrategy.getAuthorizationHeader


getJWT()

getJWT(): Promise<DecodedJWT>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:47

Returns

Promise<DecodedJWT>


getTokenResponse()

getTokenResponse(): Promise<AccessTokenResponse>

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:48

Returns

Promise<AccessTokenResponse>


invalidateToken()

invalidateToken(): void

Defined in: packages/b2c-tooling-sdk/src/auth/types.ts:49

Optional: Invalidates the cached token, forcing re-authentication on next request. Used by middleware to retry requests after receiving a 401 response.

Returns

void

Overrides

AuthStrategy.invalidateToken

Released under the Apache-2.0 License.