{"_id":"@brandwacht/sso-auth","_rev":"9-8cc64c80b381849bce2ca3bdd7b495d8","name":"@brandwacht/sso-auth","dist-tags":{"latest":"0.0.19"},"versions":{"0.0.5":{"name":"@brandwacht/sso-auth","version":"0.0.5","_id":"@brandwacht/sso-auth@0.0.5","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"dist":{"shasum":"379911b96c6ceb5a678780562039279e588a3885","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.5.tgz","fileCount":5,"integrity":"sha512-/u/zEoA6+pY7cwq7SxAydI82VW9MlJvBfZ1HczaSQuQ8FbtHT+t8anA2SfZWdiY1GM1WvO9tNZchOvrfkdWuPg==","signatures":[{"sig":"MEUCIFd41pXsyTnzAUCE4b3jenPxKeitliU6mZ2s+P7fXmB2AiEAxfm6wXD0ThfneTaLH/4YoQFGC5+VAMtD+mgR4j7H9DM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":123097},"module":"fesm2022/brandwacht-sso-auth.mjs","exports":{".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"},"./package.json":{"default":"./package.json"}},"gitHead":"c02ba334b1b29859fe3beb52e50b962756a15348","typings":"types/brandwacht-sso-auth.d.ts","_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"_npmVersion":"10.9.4","description":"BWH SSO authentication library for Angular apps","directories":{},"lastUpdated":"25/03/26 11:14","sideEffects":false,"_nodeVersion":"22.22.1","dependencies":{"tslib":"^2.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"rxjs":"~7.8.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/common":"^21.0.0","@angular/router":"^21.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-auth_0.0.5_1774430096660_0.35945272527425876","host":"s3://npm-registry-packages-npm-production"}},"0.0.12":{"name":"@brandwacht/sso-auth","version":"0.0.12","_id":"@brandwacht/sso-auth@0.0.12","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"dist":{"shasum":"f57352801f3201fada5ef915dc83e71263bb2a5a","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.12.tgz","fileCount":5,"integrity":"sha512-3iwUytahSr3SFCG07oeDJ4UBn7aHkwoDw6sfWE3Ct3oX5RuetegqsIa3LD2OKIlNm689iR/ZEegiyoeYKW6yHQ==","signatures":[{"sig":"MEQCIGhzW2jpQoqzDqu7mglM6x0FxrMZ1Dr4Uv+pSJAjlkT2AiAtgkJE7h7cs0CRJrNjKa1wTqU5+/T3Dm2XxNl7r0ZQ3Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":123098},"module":"fesm2022/brandwacht-sso-auth.mjs","exports":{".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"},"./package.json":{"default":"./package.json"}},"gitHead":"27332318b9803c2bb6ecfc8906f48f52ed700b36","typings":"types/brandwacht-sso-auth.d.ts","_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"_npmVersion":"10.9.4","description":"BWH SSO authentication library for Angular apps","directories":{},"lastUpdated":"25/03/26 11:56","sideEffects":false,"_nodeVersion":"22.22.1","dependencies":{"tslib":"^2.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"rxjs":"~7.8.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/common":"^21.0.0","@angular/router":"^21.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-auth_0.0.12_1774432642012_0.4959668194632416","host":"s3://npm-registry-packages-npm-production"}},"0.0.13":{"name":"@brandwacht/sso-auth","version":"0.0.13","_id":"@brandwacht/sso-auth@0.0.13","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"dist":{"shasum":"03153ebe865e82c4a762005a56513a627d0d4776","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.13.tgz","fileCount":5,"integrity":"sha512-8RzGtdAit0BxW1lmeylxzlZhGKoFlIQlLR9LqdWEtdtFA/ztPN3/mbPewdfGX/SuBSCP+OCDKE4mHOP1T84qWg==","signatures":[{"sig":"MEYCIQCD/x8fWIF3jKgIxdwqzUgWsQDIV9PmB3ZmW1pP/cipTQIhAOtlygXwI+met5NgavsWPqJ0IRdJvFPOvE0ha8Bx6ynR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":123551},"module":"fesm2022/brandwacht-sso-auth.mjs","exports":{".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"},"./package.json":{"default":"./package.json"}},"gitHead":"fe6ce86b5a717dd9c97020a17365fbfc01d4fb8e","typings":"types/brandwacht-sso-auth.d.ts","_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"_npmVersion":"10.9.4","description":"BWH SSO authentication library for Angular apps","directories":{},"lastUpdated":"25/03/26 12:13","sideEffects":false,"_nodeVersion":"22.22.1","dependencies":{"tslib":"^2.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"rxjs":"~7.8.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/common":"^21.0.0","@angular/router":"^21.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-auth_0.0.13_1774433653228_0.92406317907647","host":"s3://npm-registry-packages-npm-production"}},"0.0.14":{"name":"@brandwacht/sso-auth","version":"0.0.14","_id":"@brandwacht/sso-auth@0.0.14","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"dist":{"shasum":"97e0fadfcb216687704a1a4a732b6d626ef99268","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.14.tgz","fileCount":5,"integrity":"sha512-3qfzFp8HUWoLpu4APmydlBGXm4CMcQH6p1GUPLFaMpe8asAcFCGjyL6UdX57sKkgN6zSigPsZyJX1aIfvf1V0Q==","signatures":[{"sig":"MEUCIQC1W2IGT8Y4JMFJd6Unu8YY8ygZ2kq6AAUDsp5K7EjEiAIgZxmMAu+cfACWkEeUXaWNKyLBefz+tiCTWyprsz+ugmg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":127298},"module":"fesm2022/brandwacht-sso-auth.mjs","exports":{".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"},"./package.json":{"default":"./package.json"}},"gitHead":"346165a8a3a1b828b7bf56a77003bd589d83df05","typings":"types/brandwacht-sso-auth.d.ts","_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"_npmVersion":"10.9.4","description":"BWH SSO authentication library for Angular apps","directories":{},"lastUpdated":"25/03/26 12:52","sideEffects":false,"_nodeVersion":"22.22.1","dependencies":{"tslib":"^2.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"rxjs":"~7.8.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/common":"^21.0.0","@angular/router":"^21.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-auth_0.0.14_1774435979798_0.025708031114513474","host":"s3://npm-registry-packages-npm-production"}},"0.0.15":{"name":"@brandwacht/sso-auth","version":"0.0.15","_id":"@brandwacht/sso-auth@0.0.15","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"dist":{"shasum":"366e1f655d43db36d6334ccf32c4bf4f02f6342d","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.15.tgz","fileCount":5,"integrity":"sha512-M27ApuwuqZx4LzZOd9uTXZAnGvsnHQomzOpnDWpfJQaUIvMVVEKhBAfp8CbBB59kmurzLhEFxae4myBkhWSYLQ==","signatures":[{"sig":"MEUCICED2WZx17rk8N+csINf9xtRbcDLtkviTSrgp8iwg7FMAiEAg7yzPHSmP8Z0lmKANxJZzo6ayFstzoPlNZpj0OlWcz4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":131457},"module":"fesm2022/brandwacht-sso-auth.mjs","exports":{".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"},"./package.json":{"default":"./package.json"}},"gitHead":"9ab238ea5193bc0d9889f0e5d50cb5ea155b57b4","typings":"types/brandwacht-sso-auth.d.ts","_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"_npmVersion":"10.9.4","description":"BWH SSO authentication library for Angular apps","directories":{},"lastUpdated":"27/03/26 19:29","sideEffects":false,"_nodeVersion":"22.22.1","dependencies":{"tslib":"^2.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"rxjs":"~7.8.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/common":"^21.0.0","@angular/router":"^21.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-auth_0.0.15_1774632623028_0.4115031788024197","host":"s3://npm-registry-packages-npm-production"}},"0.0.16":{"name":"@brandwacht/sso-auth","version":"0.0.16","_id":"@brandwacht/sso-auth@0.0.16","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"dist":{"shasum":"304b81ad10a94fb624d9b4f57a2b9d4fb339f50f","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.16.tgz","fileCount":5,"integrity":"sha512-hx5fQFwEbDNgwMIvSk0xHl3SBw2hXfiYqJVxA09nohrMPZM3ybN9ryTCxF+hO87JceqHwsOm5mvrcUZSCDPvDw==","signatures":[{"sig":"MEYCIQDJlXHXPOuvuMLCiRqsFQ9UyWiamIBXto6WxuoWyEB+DgIhALCwshi281sLbYjqVPEiiaQxw100m0pYOmq54Tvw9e8o","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":141436},"module":"fesm2022/brandwacht-sso-auth.mjs","exports":{".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"},"./package.json":{"default":"./package.json"}},"gitHead":"3752cd03792dfae922a31ac3fa9911c5b37d09b8","typings":"types/brandwacht-sso-auth.d.ts","_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"_npmVersion":"10.9.4","description":"BWH SSO authentication library for Angular apps","directories":{},"lastUpdated":"30/03/26 10:38","sideEffects":false,"_nodeVersion":"22.22.1","dependencies":{"tslib":"^2.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"rxjs":"~7.8.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/common":"^21.0.0","@angular/router":"^21.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-auth_0.0.16_1774856383012_0.12948915931117844","host":"s3://npm-registry-packages-npm-production"}},"0.0.17":{"name":"@brandwacht/sso-auth","version":"0.0.17","_id":"@brandwacht/sso-auth@0.0.17","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"dist":{"shasum":"7d9d556f8120858694861985082123806230a1ec","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.17.tgz","fileCount":5,"integrity":"sha512-fvCovFrT/WvYjjxirINmJS/cDsnnGQVbJXwT5HVDgxxd/W2VZJh7DQiBPiT1w8YVjS7Y72z4aOJDIWg/9KLaGQ==","signatures":[{"sig":"MEUCIDWyclpr/b4T6FJFd6OtgeAmh+Tw1LTBLmD7nHV74e54AiEAils5a3adQNc8mElT+0EV9wmaRjvTzZ5u0i4737DRVCA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":142300},"module":"fesm2022/brandwacht-sso-auth.mjs","exports":{".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"},"./package.json":{"default":"./package.json"}},"gitHead":"d4fa8f8f3cfb2aea04054b632c4f65dd94b62ce3","typings":"types/brandwacht-sso-auth.d.ts","_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"_npmVersion":"10.9.4","description":"BWH SSO authentication library for Angular apps","directories":{},"lastUpdated":"30/03/26 11:35","sideEffects":false,"_nodeVersion":"22.22.1","dependencies":{"tslib":"^2.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"rxjs":"~7.8.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/common":"^21.0.0","@angular/router":"^21.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-auth_0.0.17_1774859749640_0.10768543085182736","host":"s3://npm-registry-packages-npm-production"}},"0.0.18":{"name":"@brandwacht/sso-auth","version":"0.0.18","_id":"@brandwacht/sso-auth@0.0.18","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"dist":{"shasum":"7ced8fb410e0039302cf20b55b1dcf94bae30e50","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.18.tgz","fileCount":5,"integrity":"sha512-+TvXHikfyneFt6rV+PImhHM6FiUTBPL53CfUBLONudOrHRyEc3VPmWJ4J14C4+v0NmDrCxV91Yc+E9IR9rRTXw==","signatures":[{"sig":"MEYCIQDbymBUaAKc4pZri3eHlO/n1/z53yDmv+nUgC+d+vMw2AIhAPiDeP/5pnhrltEauE9V/D8B6lxXoKbsYpj3ygMkmYB0","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":146088},"module":"fesm2022/brandwacht-sso-auth.mjs","exports":{".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"},"./package.json":{"default":"./package.json"}},"gitHead":"eb7b0e9cf4b0c1aa83810ed4363ef0f8b6e396e5","typings":"types/brandwacht-sso-auth.d.ts","_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"_npmVersion":"10.9.4","description":"BWH SSO authentication library for Angular apps","directories":{},"lastUpdated":"30/03/26 16:10","sideEffects":false,"_nodeVersion":"22.22.1","dependencies":{"tslib":"^2.3.0"},"_hasShrinkwrap":false,"peerDependencies":{"rxjs":"~7.8.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/common":"^21.0.0","@angular/router":"^21.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-auth_0.0.18_1774876282202_0.4400414874772469","host":"s3://npm-registry-packages-npm-production"}},"0.0.19":{"name":"@brandwacht/sso-auth","version":"0.0.19","description":"BWH SSO authentication library for Angular apps","peerDependencies":{"@angular/common":"^21.0.0","@angular/core":"^21.0.0","@angular/forms":"^21.0.0","@angular/router":"^21.0.0","rxjs":"~7.8.0"},"lastUpdated":"30/03/26 18:03","module":"fesm2022/brandwacht-sso-auth.mjs","typings":"types/brandwacht-sso-auth.d.ts","exports":{"./package.json":{"default":"./package.json"},".":{"types":"./types/brandwacht-sso-auth.d.ts","default":"./fesm2022/brandwacht-sso-auth.mjs"}},"sideEffects":false,"dependencies":{"tslib":"^2.3.0"},"_id":"@brandwacht/sso-auth@0.0.19","gitHead":"ea79cfe7eaf5ac7ca39183acfd433ebc13fd64e5","_nodeVersion":"22.22.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-vviJCb83CK8k3lIPeLSRgUbM8YzAt21avj8thfsaSvuhtNw8Q/+zoGJc9EamTi0GwybdFoxnOIsOJBbicWTIsw==","shasum":"879d375751183fec52663b3ae1f412536e221708","tarball":"https://registry.npmjs.org/@brandwacht/sso-auth/-/sso-auth-0.0.19.tgz","fileCount":5,"unpackedSize":146812,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDp7cfgj+NbZQhc6FIB3AhRDMbDHUIhnabdQCDvMs5l3QIgYX3CV+aykiKCtFDDrYQDt0lUlXEgHGZuae1t0cJrbXc="}]},"_npmUser":{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"},"directories":{},"maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sso-auth_0.0.19_1774883020592_0.26484901140273576"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-25T09:14:56.573Z","modified":"2026-03-30T15:03:40.902Z","0.0.5":"2026-03-25T09:14:56.845Z","0.0.12":"2026-03-25T09:57:22.219Z","0.0.13":"2026-03-25T10:14:13.388Z","0.0.14":"2026-03-25T10:52:59.961Z","0.0.15":"2026-03-27T17:30:23.191Z","0.0.16":"2026-03-30T07:39:43.167Z","0.0.17":"2026-03-30T08:35:49.782Z","0.0.18":"2026-03-30T13:11:22.354Z","0.0.19":"2026-03-30T15:03:40.752Z"},"description":"BWH SSO authentication library for Angular apps","maintainers":[{"name":"bwh-ciprian","email":"ciprian.dragoste@brandwachthuren.nl"}],"readme":"# @brandwacht/sso-auth\n\nDrop-in SSO authentication library for Angular apps in the Brandwacht Huren B.V. ecosystem.\n\nProvides the full login flow — SSO redirect, code exchange, JWT management — plus a ready-made login page with dark/light theme and EN/NL language switching.\n\n## Installation\n\n```bash\nnpm install @brandwacht/sso-auth\n```\n\n> **Local development (within the monorepo):** The library is already wired via tsconfig paths. Build it with `npm run build` — consuming apps resolve `@brandwacht/sso-auth` from source automatically.\n\n## Quick start\n\n### 1. Configure providers\n\n```typescript\n// app.config.ts\nimport { ApplicationConfig, provideZoneChangeDetection } from '@angular/core';\nimport { provideRouter } from '@angular/router';\nimport { provideHttpClient, withInterceptors } from '@angular/common/http';\nimport { provideBwhSsoAuth, bwhJwtInterceptor } from '@brandwacht/sso-auth';\nimport { routes } from './app.routes';\nimport { environment } from '../environments/environment';\n\nexport const appConfig: ApplicationConfig = {\n  providers: [\n    provideZoneChangeDetection({ eventCoalescing: true }),\n    provideRouter(routes),\n    provideHttpClient(withInterceptors([bwhJwtInterceptor])),\n    provideBwhSsoAuth({\n      ssoAuthPortalUri: environment.ssoAuthPortalUri,\n      apiBaseUrl: environment.apiBaseUrl,\n      appBaseUrl: environment.appBaseUrl,\n      appId: 'my-app',\n      resolveLanding: (user) => '/dashboard',\n    }),\n  ],\n};\n```\n\n### 2. Set up routes\n\n```typescript\n// app.routes.ts\nimport { Routes } from '@angular/router';\nimport { BwhSsoLoginPage, ssoAuthGuard } from '@brandwacht/sso-auth';\n\nexport const routes: Routes = [\n  { path: 'login', component: BwhSsoLoginPage },\n  {\n    path: '',\n    canActivate: [ssoAuthGuard],\n    children: [\n      { path: 'dashboard', loadComponent: () => import('./dashboard/dashboard') },\n      { path: '', redirectTo: 'dashboard', pathMatch: 'full' },\n    ],\n  },\n];\n```\n\nThat's it. You now have a fully working SSO login with JWT auth.\n\n## Multi-app SSO (single sign-on across multiple Angular apps)\n\nThis library supports automatic cross-app authentication. When a user logs in to **any** app, they are silently authenticated in all other apps that share the same SSO portal — no extra clicks needed.\n\n### How it works\n\nEach app maintains its own JWT (stored in `localStorage`, scoped to its domain). Cross-app SSO works through the **SSO portal's session**:\n\n```\nApp A (user logs in)                SSO Portal                    App B (user visits later)\n─────────────────                   ──────────                    ────────────────────────\n1. Redirect to portal  ──────────►  2. User authenticates\n                                    3. Portal creates session\n                       ◄──────────  4. Redirect back with code\n5. Exchange code → JWT\n   (user is now logged\n    in to App A)\n                                                                  6. User opens App B\n                                                                  7. Guard → /login\n                                                                  8. Silent redirect ──────►  9. Session exists → return code\n                                                                                     ◄──────  10. Redirect back with code\n                                                                  11. Exchange code → JWT\n                                                                      (auto-logged in!)\n```\n\nSteps 6–11 happen automatically with no user interaction. The `BwhSsoLoginPage` component detects that the user isn't authenticated and performs a **silent SSO redirect** (`prompt=none`) to the portal. If the portal has an active session, it returns a code immediately, and the app completes the login flow.\n\n### Setup checklist (repeat for each app)\n\nEvery app that participates in cross-app SSO needs **all four** of the following:\n\n#### 1. Same `ssoAuthPortalUri`\n\nAll apps must point to the **same** SSO portal so they share one session:\n\n```typescript\n// App A\nprovideBwhSsoAuth({ ssoAuthPortalUri: 'https://oauth-portal.bwh.nl', ... })\n\n// App B\nprovideBwhSsoAuth({ ssoAuthPortalUri: 'https://oauth-portal.bwh.nl', ... })\n\n// App C\nprovideBwhSsoAuth({ ssoAuthPortalUri: 'https://oauth-portal.bwh.nl', ... })\n```\n\n#### 2. Unique `appId` and correct `appBaseUrl` per app\n\nEach app has its own identity. The `appBaseUrl` must match the public URL exactly (including protocol and port) — the SSO portal uses it to validate redirect callbacks:\n\n```typescript\n// App A\nprovideBwhSsoAuth({\n  appId: 'inventory',\n  appBaseUrl: 'https://inventory.bwh.nl',\n  ...\n})\n\n// App B\nprovideBwhSsoAuth({\n  appId: 'crm',\n  appBaseUrl: 'https://crm.bwh.nl',\n  ...\n})\n```\n\n> Each `appId` must be **registered in the SSO portal** and its `appBaseUrl` must be listed as an allowed redirect URI.\n\n#### 3. `BwhSsoLoginPage` on the login route\n\nThe login page component handles the silent SSO attempt. Without it, cross-app auto-login won't trigger:\n\n```typescript\n// app.routes.ts — this route is REQUIRED\n{ path: 'login', component: BwhSsoLoginPage }\n```\n\nThe route path must match the `loginRoute` config (defaults to `'/login'`).\n\n#### 4. `ssoAuthGuard` on all protected routes\n\nThe guard redirects unauthenticated users to the login page, which then triggers silent SSO. It also preserves the original URL so users land on the page they intended to visit:\n\n```typescript\n{\n  path: '',\n  canActivate: [ssoAuthGuard],\n  children: [\n    { path: 'dashboard', ... },\n    { path: 'settings', ... },\n  ],\n}\n```\n\n#### 5. `bwhJwtInterceptor` in `provideHttpClient`\n\nAttaches the JWT to all outgoing HTTP requests:\n\n```typescript\nprovideHttpClient(withInterceptors([bwhJwtInterceptor]))\n```\n\n### Return URL preservation\n\nWhen a user navigates to a deep link (e.g. `https://crm.bwh.nl/clients/42`) and isn't authenticated yet, the guard stores the intended URL. After silent SSO completes, the user lands on `/clients/42` — not the default landing page. This works automatically.\n\n### Backend requirements for each app\n\nEach app's backend must implement the SSO token exchange endpoint (see [Backend contract](#backend-contract)). The backend validates the SSO tokens with the portal and returns an app-specific JWT.\n\n### Example: three-app setup\n\n```typescript\n// === inventory/app.config.ts ===\nprovideBwhSsoAuth({\n  ssoAuthPortalUri: 'https://oauth-portal.bwh.nl',\n  apiBaseUrl: '/api',\n  appBaseUrl: 'https://inventory.bwh.nl',\n  appId: 'inventory',\n  resolveLanding: () => '/stock',\n})\n\n// === crm/app.config.ts ===\nprovideBwhSsoAuth({\n  ssoAuthPortalUri: 'https://oauth-portal.bwh.nl',\n  apiBaseUrl: '/api',\n  appBaseUrl: 'https://crm.bwh.nl',\n  appId: 'crm',\n  resolveLanding: () => '/clients',\n})\n\n// === admin/app.config.ts ===\nprovideBwhSsoAuth({\n  ssoAuthPortalUri: 'https://oauth-portal.bwh.nl',\n  apiBaseUrl: '/api',\n  appBaseUrl: 'https://admin.bwh.nl',\n  appId: 'admin',\n  resolveLanding: () => '/overview',\n})\n```\n\nEach app also needs **the same route setup** (login page + guard) shown in [Quick start](#quick-start).\n\n## Configuration reference\n\n`provideBwhSsoAuth()` accepts a `BwhSsoAuthConfig` object:\n\n| Property | Type | Required | Default | Description |\n|---|---|---|---|---|\n| `ssoAuthPortalUri` | `string` | yes | — | URL of the BWH SSO portal (e.g. `https://oauth-portal.bwh.nl`) |\n| `apiBaseUrl` | `string` | yes | — | Base URL for the app's API (e.g. `/api`) |\n| `appBaseUrl` | `string` | yes | — | Public URL of this app, used for SSO redirect callback |\n| `appId` | `string` | yes | — | Unique app identifier registered in the SSO portal |\n| `resolveLanding` | `(user: SsoAuthUser) => string \\| Observable<string>` | yes | — | Returns the URL to navigate to after login |\n| `storageKey` | `string` | no | `'BWH_SSO_AUTH_STATE'` | localStorage key for persisted auth state |\n| `loginRoute` | `string` | no | `'/login'` | Route path for the login page |\n| `ssoCodeParam` | `string` | no | `'sso_code'` | Query parameter name for the SSO code |\n| `ssoEndpoint` | `string` | no | `'/auth/sso'` | Backend endpoint path appended to `apiBaseUrl` |\n\n## Exports\n\n### Core auth\n\n| Export | Description |\n|---|---|\n| `SsoAuthService` | Injectable service — `user()`, `token()`, `isAuthenticated()` signals, `startSsoLogin()`, `ssoLogin(code)`, `logout()` |\n| `bwhJwtInterceptor` | HTTP interceptor that attaches `Authorization: Bearer <token>` to all requests |\n| `ssoAuthGuard` | Route guard — redirects unauthenticated users to the login page, preserves return URL |\n| `BwhSsoLoginPage` | Standalone login page component with SSO button, silent auto-login, theme toggle, language switcher |\n| `provideBwhSsoAuth(config)` | Provider helper — call once in `app.config.ts` |\n\n### I18n\n\n| Export | Description |\n|---|---|\n| `BwhI18nService` | Lightweight i18n service (EN/NL). Use `lang()` signal, `setLanguage()`, `t(key)` |\n| `BwhTranslatePipe` | Template pipe: `{{ 'Hello' \\| bwhT }}` |\n| `registerTranslations(locale, map)` | Extend the built-in translations with your own keys |\n\n```typescript\n// Extend translations for your app\nconst i18n = inject(BwhI18nService);\ni18n.registerTranslations('nl', {\n  Dashboard: 'Dashboard',\n  Settings: 'Instellingen',\n});\n```\n\n### Theme\n\n| Export | Description |\n|---|---|\n| `BwhThemeService` | Dark/light theme service. `isDark$` observable, `toggle()`, `setDark(boolean)` |\n\n## SSO flow\n\n```\nUser clicks \"SSO Corporate Authentication\"\n    │\n    ▼\nBrowser redirects to SSO portal\n  {ssoAuthPortalUri}?redirectUri={appBaseUrl}{loginRoute}&appId={appId}\n    │\n    ▼\nUser authenticates on SSO portal\n    │\n    ▼\nSSO portal redirects back to\n  {appBaseUrl}{loginRoute}?sso_code=<code>\n    │\n    ▼\nLibrary exchanges code for tokens (two-step):\n  1. POST {ssoAuthPortalUri}/api/sso/exchange  { code }        → SSO tokens\n  2. POST {apiBaseUrl}{ssoEndpoint}             { authToken, refreshToken } → app JWT + user\n    │\n    ▼\nJWT + user stored in localStorage\n    │\n    ▼\nresolveLanding(user) called → navigate to result\n```\n\n## Backend contract\n\nThe library expects the app's backend to expose a single endpoint:\n\n```\nPOST {apiBaseUrl}/auth/sso\nContent-Type: application/json\n\n{\n  \"authToken\": \"<access_token from SSO portal>\",\n  \"refreshToken\": \"<refresh_token from SSO portal>\"\n}\n\n→ 200 OK\n{\n  \"token\": \"<app JWT>\",\n  \"user\": {\n    \"id\": \"...\",\n    \"email\": \"...\",\n    \"name\": \"...\",\n    \"role\": \"...\",\n    \"tenantId\": \"...\",\n    ...\n  }\n}\n```\n\nThe endpoint path is configurable via `ssoEndpoint`.\n\n## Troubleshooting cross-app SSO\n\n### Silent login doesn't fire — user always sees the login button\n\n1. **Missing `BwhSsoLoginPage`** on the login route. The silent SSO logic lives in this component's `ngOnInit`. Without it, nothing triggers the auto-login.\n2. **Missing `ssoAuthGuard`** on protected routes. If the guard isn't there, unauthenticated users stay on the page instead of being redirected to login.\n3. **`loginRoute` mismatch.** If you set `loginRoute: '/auth/login'` in config but the component is at `path: 'login'`, the redirects won't match.\n\n### Silent login redirects but comes back without logging in\n\n1. **SSO portal doesn't support `prompt=none`.** The portal must handle this parameter: return a code if the user has an active session, or redirect back with `?sso_error=...` if not.\n2. **SSO portal session cookie is restricted.** The portal's session cookie must be accessible when the browser navigates to the portal domain. Check that the cookie's `Domain`, `SameSite`, and `Secure` attributes are correct.\n3. **`appId` not registered in the portal.** Each app's `appId` must be registered, with its `appBaseUrl` as an allowed redirect URI.\n\n### Code exchange fails (network error or 4xx)\n\n1. **CORS not configured on the SSO portal.** The library makes a `POST` to `{ssoAuthPortalUri}/api/sso/exchange` from the app's domain. The portal must allow cross-origin requests from all app domains.\n2. **Backend `/auth/sso` endpoint not implemented.** Each app's backend must implement the token exchange endpoint (see [Backend contract](#backend-contract)).\n3. **`apiBaseUrl` is wrong.** Verify it points to the correct backend. Open browser DevTools → Network tab and check for failed requests.\n\n### User lands on the wrong page after auto-login\n\nThe `ssoAuthGuard` preserves the original URL via a `returnUrl` query parameter. After authentication, the user is redirected to the page they originally requested. If this isn't working, make sure you're using `ssoAuthGuard` (not a custom guard) on your protected routes.\n\n## Build and publish\n\n```bash\n# Build the library\nnpm run build\n\n# Publish to private registry\ncd dist/sso-auth\nnpm publish\n```\n\n## Requirements\n\n- Angular 21+\n- RxJS 7.8+\n- Tailwind CSS 4 (for the login page component's utility classes)\n","readmeFilename":"README.md"}