The App SDK provides an interface to integrate FIDO authentication into an existing OIDC Federation infrastructure. Use this interface as an OIDC Federation client. After an end user authenticates and your app receives the AuthenticationData object from the App SDK, initiate the OIDC flow:
if let jwt = (authData?.sessionData.object(forKey: "sessionKey")) {
let params = NNLOidcFederationParams(authFlow: URL(string: "<OIDC_AUTH_URL>"), jwToken: jwt)
params.federationResumeUrl = URL(string: "<OIDC_RESUME_URL>")
params.tokenUrl = URL(string: "<OIDC_TOKEN_URL>")
let fedClient = NNLOidcFederationClient(params: params)
let promise = fedClient.performCodeGrantFlow()
promise.then({ result in
if let result = result as? NNLOidcResult {
print("ID Token = \(result.id_token ?? "nil")")
print("Refresh Token = \(result.refresh_token ?? "nil")")
return NSNull()
}).error({ error in
print("Code grant flow operation failed with an error. Reason: \((error as? NSError)?.localizedDescription ?? "unknown")")
return NSNull()
})
}
}Class NNLOidcFederationClient contains methods that support the following OIDC flows:
Authorization code grant
Implicit
Token refresh
Working example in Tutorial App
AppDelegate.swift shows how to initiate OIDC flows.