The ESPRMNeoAuth class provides authentication functionality via the RainMaker User Auth API. Key features include:

  • Sign-Up Process: Methods to send sign-up codes and confirm user registration.
  • Password Management: Support for password recovery, setting new passwords, and login with credentials.
  • Session Management: Provides functionality to fetch details of the currently logged-in user.

Constructors

Methods

  • Changes the password for the currently authenticated user.

    Calls POST /v1/user/auth/password (CognitoAuthorizer Bearer token).

    Parameters

    • oldPassword: string

      The user's current password.

    • newPassword: string

      The new password to set.

    Returns Promise<ChangePasswordResponse>

    A promise that resolves to a ChangePasswordResponse on success.

    If not logged in or the API request fails.

  • Confirms a user's sign-up using the verification code sent by Cognito.

    Calls POST /v1/user/auth/signup/verify.

    Parameters

    • username: string

      The username (typically the user's email or phone).

    • verificationCode: string

      The verification code received by the user.

    Returns Promise<ConfirmSignUpResponse>

    The API response.

    If confirmation fails.

  • Initiates the password recovery process for a user.

    Calls POST /v1/user/auth/password-recovery.

    Parameters

    • username: string

      The username (email or phone number) for password recovery.

    Returns Promise<ForgotPasswordResponse>

    The server response with an optional message field — the only field the backend returns (verified against the backend source).

    If recovery initiation fails.

  • Retrieves the currently logged-in user.

    Reads tokens from storage. If the access token is expired, refreshes the session using the refresh token, then reloads. Returns null when no tokens are stored.

    Returns Promise<null | ESPRMNeoUser>

    An ESPRMNeoUser if a session is active, or null when no tokens are stored.

    If the session refresh fails.

  • Logs in a user with username and password.

    Calls POST /v1/user/auth/token.

    Parameters

    • username: string

      The username (email or phone number) for authentication.

    • password: string

      The user's password.

    Returns Promise<ESPRMNeoUser>

    A promise that resolves to an ESPRMNeoUser instance on successful login.

    If authentication fails or credentials are invalid.

  • Sends a verification code to the user's email during the sign-up process.

    Calls POST /v1/user/auth/signup.

    Parameters

    • username: string

      The email address of the user signing up

    • password: string

      The password for the new account

    • OptionaluserAttributes: Record<string, string>

      Optional additional user attributes

    Returns Promise<ESPAPIResponse>

    A promise that resolves with the API response when the verification code is sent successfully

    If the sign-up code request fails.

  • Sets a new password for a user during password recovery flow.

    Calls POST /v1/user/auth/password-recovery/confirmation.

    Parameters

    • username: string

      The username (email or phone number) for password recovery.

    • newPassword: string

      The new password to set.

    • verificationCode: string

      The verification code received by the user.

    Returns Promise<SetNewPasswordResponse>

    A promise that resolves to a SetNewPasswordResponse on success.

    If the verification code is invalid or password setting fails.

  • Gets refreshed tokens using a refresh token without persisting them.

    Calls POST /v1/user/auth/token/refresh (unauthenticated; the backend validates refresh_token in the body only).

    The backend rotates the refresh token on every redemption: the presented token is spent and the response carries its replacement. Presenting a spent token again is treated as reuse and kills the login, so the rotated token from the response is returned here (and must be persisted by the caller). Falls back to the presented token only when the backend does not return one.

    Parameters

    • refreshToken: string

    Returns Promise<UserTokensData>