Skip to main content

ResourceOwnerFlow

An authentication flow that implements the OAuth2 Resource Owner flow, also known as the Password Grant.

This enables developers to sign users in using a simple username and password.

The OAuth2 Security Best Practices recommends that the password grant should not be used since it exposes user credentials to the client. Furthermore, this authentication flow does not support the use of multifactor authentication, so caution should be used when implementing applications using this flow.

Implements

Index

Constructors

Properties

Methods

Constructors

constructor

  • new ResourceOwnerFlow(issuer: URL, clientId: string, scopes: string): ResourceOwnerFlow
  • Constructor that creates the authentication flow with the given client options.


    Parameters

    • issuer: URL

      The issuer URL for the client.

    • clientId: string

      The client ID for this client.

    • scopes: string

      The scopes the client is requesting.

    Returns ResourceOwnerFlow

Properties

readonlyclient

client: OAuth2Client

The OAuth2Client this authentication flow will use.

readonlyisAuthenticating

isAuthenticating: boolean

Indicates whether or not this flow is currently in the process of authenticating a user.

Methods

reset

  • reset(): void
  • Resets the authentication session.


    Returns void

start

  • start(username: string, password: string): Promise<Token>
  • Authenticates using the supplied username and password.

    @throws

    Error indicating a problem with signing in.


    Parameters

    • username: string

      Username

    • password: string

      Password

    Returns Promise<Token>

    A token for the user, if authentication is successful.