All files / server/src/features/kompassi-login KompassiLoginTypes.ts

100% Statements 2/2
100% Branches 0/0
100% Functions 0/0
100% Lines 2/2

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31          43x                         43x                        
import { z } from "zod";
 
// Only the access token is used: the claims are read from the userinfo
// endpoint, and Konsti never refreshes. The rest are present in Kompassi's
// response but optional here so an unused field can't fail a login
export const KompassiTokensSchema = z.object({
  access_token: z.string(),
  token_type: z.string(),
  expires_in: z.number().optional(),
  scope: z.string().optional(),
  refresh_token: z.string().optional(),
  id_token: z.string().optional(),
});
 
export type KompassiTokens = z.infer<typeof KompassiTokensSchema>;
 
// The full claim set Kompassi returns from /oidc/userinfo/. There is no
// username claim - Kompassi is removing usernames - so `sub` is the identity
export const KompassiUserinfoSchema = z.object({
  // Non-empty: "" is the local-account marker in `kompassiId`, so an empty sub
  // would look up and log in as an arbitrary local account
  sub: z.string().min(1),
  email: z.string(),
  name: z.string(),
  given_name: z.string(),
  family_name: z.string(),
  groups: z.array(z.string()),
});
 
export type KompassiUserinfo = z.infer<typeof KompassiUserinfoSchema>;