@mechta-dev/mechta-id-js
v0.2.1
Published
Browser SDK for Mechta ID OpenID Connect authentication
Maintainers
Readme
@mechta-dev/mechta-id-js
Browser SDK for Mechta ID authentication. It uses Authorization Code Flow with PKCE,
keeps OAuth tokens in memory and stores only transient OIDC state in
sessionStorage.
Installation
pnpm add @mechta-dev/mechta-id-jsApplications do not need to install or import oidc-client-ts directly.
Usage
Initialize Mechta ID before mounting the application router:
import { MechtaID } from '@mechta-dev/mechta-id-js';
export const mechtaID = new MechtaID({
authority: import.meta.env.VITE_MECHTA_ID_URL,
clientId: import.meta.env.VITE_MECHTA_ID_CLIENT_ID,
redirectUri: `${window.location.origin}/auth/callback`,
});
await mechtaID.init({
onLoad: 'login-required',
});The SDK detects code and state on the callback URL, performs exactly one token
exchange, loads UserInfo and restores the relative path supplied to login().
Use a current token for API calls:
const token = await mechtaID.getToken();
const response = await fetch('/api/employee', {
headers: token ? { Authorization: `Bearer ${token}` } : {},
});Login, logout and authorization helpers:
await mechtaID.login({ returnTo: '/employee' });
await mechtaID.logout();
mechtaID.hasRole('admin');
mechtaID.hasPermission('employee.read');
const utpID = mechtaID.profile?.attributes?.utp_id;profile.attributes содержит только ключи, разрешённые администратором для текущего
OIDC-клиента. Приложение не должно ожидать остальные динамические атрибуты пользователя.
Active-session controls:
const sessions = await mechtaID.getSessions();
await mechtaID.revokeSession(sessions[0].id);
await mechtaID.revokeOtherSessions();Sessions are client-scoped device slots. Check clientId and
selfTerminationAllowed before showing a self-service termination action. A
normal OIDC logout revokes credentials but intentionally keeps a limited
client's device slot; the same browser may sign in again, while another device
must wait for an authorized manager to terminate the slot or for it to expire.
An administrator with iam:session:manage (or global-admin) may pass a user
ID to getSessions, revokeSession, and revokeAllSessions. Mechta ID enforces
this permission server-side; hiding controls in the UI is not sufficient.
Role and permission checks in a browser are only UI hints. Backend services must still validate the access token and enforce authorization.
Security defaults
- public OIDC client; no client secret is accepted;
- Authorization Code Flow with PKCE S256;
- tokens are stored only in memory;
- callback and refresh operations are single-flight;
- automatic and on-demand refreshes share the same single-flight operation;
returnToaccepts only same-origin relative paths;- discovery is loaded from
/.well-known/openid-configuration; - refresh and logout use the endpoints advertised by Mechta ID.
