import { OnDestroy, RendererFactory2 } from '@angular/core';
import { HttpClient } from '@angular/common/http';
import { Observable } from 'rxjs';
import { AuthConfig } from './auth.config';
import { TokenService } from './token.service';
export interface LoginOptions {
    [key: string]: string;
}
export interface User {
    uid: string;
    name: string;
    nickname: string;
    email: string;
    token: string;
}
export declare class AuthService implements OnDestroy {
    private _rendererFactory;
    private _tokenService;
    private _http;
    private config;
    private _user;
    private _currentState;
    private _loginCallbacks;
    private _logoutCallbacks;
    private _unlistenEvents;
    private _timeoutID;
    private readonly _domain;
    private readonly _appURL;
    private readonly _tokenURL;
    private readonly _authURL;
    private readonly _storageUpdater;
    private readonly _storageRemover;
    private readonly _commKeyName;
    private readonly _commKeyUpdater;
    constructor(_rendererFactory: RendererFactory2, _tokenService: TokenService, _http: HttpClient, config: AuthConfig);
    ngOnDestroy(): void;
    user(): Observable<User | null>;
    /**
     * Functions that opens a window instead of a tab.
     *
     * See method _filterLoginOptions regarding security risks of certain
     * LoginOptions.
     *
     * @param loginOptions Options passed as URL parameters to the SSO.
     * @param width Pixel width of the login window.
     * @param height Pixel height of the login window.
     * @param top Position of the top corners. If it is a negative
     *             number it centres the login window on the screen.
     * @param left Position of the left corners. If it is a negative
     *             number it centres the login window on the screen.
     */
    openLoginWindow(options?: LoginOptions, width?: number, height?: number, left?: number, top?: number): void;
    /**
     * @deprecated use openLoginWindow method instead (top and left arguments are inverted in the new method)
     * since version 1.0.0-beta.5.
     * windowOpen will be deleted in version 1.0.0
     */
    windowOpen(options?: LoginOptions, width?: number, height?: number, top?: number, left?: number): void;
    /**
     * Functions that opens a tab (in modern browser).
     *
     * See method _filterLoginOptions regarding security risks of certain
     * LoginOptions.
     *
     * @param loginOptions Options passed as URL parameters to the SSO.
     */
    openLoginTab(options?: LoginOptions): void;
    /**
     * @deprecated use openLoginTab method instead
     * since version 1.0.0-beta.5.
     * tabOpen will be deleted in version 1.0.0
     */
    tabOpen(options?: LoginOptions): void;
    /**
     * Produces a URL that allows logging into the single sign on (SSO) page.
     * The URL cans be opened in a new tab using target="_blank",
     * or in a new window using window.open().
     *
     * See method _filterLoginOptions regarding security risks of certain
     * LoginOptions.
     *
     * @param  loginOptions Options passed as URL parameters to the SSO.
     *
     * @returns The SSO URL.
     *
     */
    getSSOURL(options?: LoginOptions): string;
    /**
     * Functions that logs out the user.
     * It triggers the logout callbacks.
     * It is an arrow function (lambda) because in that way it has a reference
     * to 'this' when used in setTimeout call.
     */
    logOut(): void;
    /**
     * Create AAP account
     *
     * @returns uid of the new user
     */
    createAAPaccount(newUser: {
        name?: string;
        username: string;
        password: string;
        email?: string;
        organization?: string;
    }): Observable<string>;
    /**
     * Login directly through the AAP
     *
     * See method _filterLoginOptions regarding security risks of certain
     * LoginOptions.
     *
     * @returns true if the user successfully login, otherwise false
     */
    loginAAP(user: {
        username: string;
        password: string;
    }, options?: LoginOptions): Observable<boolean>;
    /**
     * Change password AAP account
     *
     * @returns true when password is successfully changed
     */
    changePasswordAAP({ username, oldPassword, newPassword }: {
        username: string;
        oldPassword: string;
        newPassword: string;
    }): Observable<boolean>;
    /**
     * Add a callback to the LogIn event.
     *
     * @param callback The Function called when the login event is triggered and the
     *    JWT token is received and accepted.
     *
     * @returns The event registration id (necessary to unregister the event).
     */
    addLogInEventListener(callback: Function): number;
    /**
     * Remove a callback from the LogIn event.
     *
     * @param id The id given when event listener was added.
     *
     * @returns true when remove successfully, false otherwise.
     */
    removeLogInEventListener(id: number): boolean;
    /**
     * Add a callback to the LogOut event.
     *
     * @param callback The Function called when the logout event is triggered and the
     *    JWT token is received and accepted.
     *
     * @returns The registration id (necessary to unregister the event).
     */
    addLogOutEventListener(callback: Function): number;
    /**
     * Remove a callback from the LogOut event.
     *
     * @param id The id given when event listener was added.
     *
     * @returns true when remove successfully, false otherwise.
     */
    removeLogOutEventListener(id: number): boolean;
    /**
     * Refresh token
     *
     * @returns true when token is successfully refreshed
     */
    refresh(): Observable<boolean>;
    /**
     * Format and filter fragment options
     *
     * @params options
     *
     * @returns fragment string
     */
    private _formatFragments;
    /**
     * Filters options that are unsecure.
     *
     * See the advance options that can be requested through the options parameter:
     * https://api.aai.ebi.ac.uk/docs/authentication/authentication.index.html#_common_attributes
     *
     * The time to live paramenter (ttl) default value is 60 minutes. It is a
     * big security risk to request longer ttl. If a third party gets hold of
     * such token, means that they could use it for a day, week, year
     * (essentially, like having the username/password).
     *
     * @param  loginOptions Options passed as URL parameters to the SSO.
     *
     *
     */
    private _filterLoginOptions;
    /**
     * Creates Authorization header
     *
     * @param object with username and password.
     *
     * @returns New authorization header
     */
    private _createAuthHeader;
    /**
     * Listen for login messages from other windows.
     * These messages contain the tokens from the AAP.
     * If a token is received then the callbacks are triggered.
     */
    private _listenLoginMessage;
    /** Listen to changes in the token from *other* windows.
     *
     * For inter-window communication messages are transmitted trough changes
     * on a dummy storage key property: '_commKeyName'.
     *
     * Notice that changes in the '_commKeyName' produced by this class doesn't
     * trigger this event.
     */
    private _listenChangesFromOtherWindows;
    /**
     * Check if the message is coming from the same domain we use to generate
     * the SSO URL, otherwise it's iffy and shouldn't trust it.
     */
    private _messageIsAcceptable;
    private _updateUser;
    private _getClaim;
    private _deprecationWarning;
}
