diff --git a/.changeset/giant-nails-grow.md b/.changeset/giant-nails-grow.md
index bed8c422aa..be4d5793e7 100644
--- a/.changeset/giant-nails-grow.md
+++ b/.changeset/giant-nails-grow.md
@@ -9,3 +9,6 @@
Since the `IdentityClient` interface is marked as experimental, this is a
breaking change without a deprecation period.
+
+- Moved `BackstageSignInResult`, `BackstageIdentityResponse`, and
+ `BackstageUserIdentity` to `@backstage/plugin-auth-node`.
diff --git a/plugins/auth-backend/api-report.md b/plugins/auth-backend/api-report.md
index 6a77f1a7cf..e555eb4a36 100644
--- a/plugins/auth-backend/api-report.md
+++ b/plugins/auth-backend/api-report.md
@@ -5,9 +5,10 @@
```ts
///
+import { BackstageIdentityResponse } from '@backstage/plugin-auth-node';
+import { BackstageSignInResult } from '@backstage/plugin-auth-node';
import { CatalogApi } from '@backstage/catalog-client';
import { Config } from '@backstage/config';
-import { Entity } from '@backstage/catalog-model';
import express from 'express';
import { JsonValue } from '@backstage/types';
import { Logger as Logger_2 } from 'winston';
@@ -130,27 +131,6 @@ export type AwsAlbProviderOptions = {
// @public @deprecated
export type BackstageIdentity = BackstageSignInResult;
-// @public
-export interface BackstageIdentityResponse extends BackstageSignInResult {
- identity: BackstageUserIdentity;
-}
-
-// @public
-export interface BackstageSignInResult {
- // @deprecated
- entity?: Entity;
- // @deprecated
- id: string;
- token: string;
-}
-
-// @public
-export type BackstageUserIdentity = {
- type: 'user';
- userEntityRef: string;
- ownershipEntityRefs: string[];
-};
-
// Warning: (ae-missing-release-tag) "BitbucketOAuthResult" is exported by the package, but it is missing a release tag (@alpha, @beta, @public, or @internal)
//
// @public (undocumented)
diff --git a/plugins/auth-backend/src/identity/IdentityClient.ts b/plugins/auth-backend/src/identity/IdentityClient.ts
index 5fbd126cdf..6c6c2ca4b1 100644
--- a/plugins/auth-backend/src/identity/IdentityClient.ts
+++ b/plugins/auth-backend/src/identity/IdentityClient.ts
@@ -18,7 +18,7 @@ import fetch from 'node-fetch';
import { JWK, JWT, JWKS, JSONWebKey } from 'jose';
import { PluginEndpointDiscovery } from '@backstage/backend-common';
import { AuthenticationError } from '@backstage/errors';
-import { BackstageIdentityResponse } from '../providers/types';
+import { BackstageIdentityResponse } from '@backstage/plugin-auth-node';
const CLOCK_MARGIN_S = 10;
diff --git a/plugins/auth-backend/src/lib/oauth/OAuthAdapter.ts b/plugins/auth-backend/src/lib/oauth/OAuthAdapter.ts
index 82a43c7c64..75a3605483 100644
--- a/plugins/auth-backend/src/lib/oauth/OAuthAdapter.ts
+++ b/plugins/auth-backend/src/lib/oauth/OAuthAdapter.ts
@@ -23,10 +23,12 @@ import {
stringifyEntityRef,
} from '@backstage/catalog-model';
import {
- AuthProviderRouteHandlers,
- AuthProviderConfig,
BackstageIdentityResponse,
BackstageSignInResult,
+} from '@backstage/plugin-auth-node';
+import {
+ AuthProviderRouteHandlers,
+ AuthProviderConfig,
} from '../../providers/types';
import {
AuthenticationError,
diff --git a/plugins/auth-backend/src/lib/oauth/types.ts b/plugins/auth-backend/src/lib/oauth/types.ts
index 6973e99569..6e5fe19859 100644
--- a/plugins/auth-backend/src/lib/oauth/types.ts
+++ b/plugins/auth-backend/src/lib/oauth/types.ts
@@ -16,11 +16,8 @@
import express from 'express';
import { Profile as PassportProfile } from 'passport';
-import {
- RedirectInfo,
- BackstageSignInResult,
- ProfileInfo,
-} from '../../providers/types';
+import { BackstageSignInResult } from '@backstage/plugin-auth-node';
+import { RedirectInfo, ProfileInfo } from '../../providers/types';
/**
* Common options for passport.js-based OAuth providers
diff --git a/plugins/auth-backend/src/providers/index.ts b/plugins/auth-backend/src/providers/index.ts
index 1207254e11..37ce09978c 100644
--- a/plugins/auth-backend/src/providers/index.ts
+++ b/plugins/auth-backend/src/providers/index.ts
@@ -48,13 +48,6 @@ export type {
// These types are needed for a postMessage from the login pop-up
// to the frontend
-export type {
- AuthResponse,
- BackstageIdentity,
- BackstageUserIdentity,
- BackstageIdentityResponse,
- BackstageSignInResult,
- ProfileInfo,
-} from './types';
+export type { AuthResponse, BackstageIdentity, ProfileInfo } from './types';
export { prepareBackstageIdentityResponse } from './prepareBackstageIdentityResponse';
diff --git a/plugins/auth-backend/src/providers/oidc/provider.ts b/plugins/auth-backend/src/providers/oidc/provider.ts
index e77812e750..9ccdf25f74 100644
--- a/plugins/auth-backend/src/providers/oidc/provider.ts
+++ b/plugins/auth-backend/src/providers/oidc/provider.ts
@@ -234,7 +234,7 @@ export const oAuth2DefaultSignInResolver: SignInResolver<
* can be passed while creating a OIDC provider.
*
* authHandler : called after sign in was successful, a new object must be returned which includes a profile
- * signInResolver: called after sign in was successful, expects to return a new {@link BackstageSignInResult}
+ * signInResolver: called after sign in was successful, expects to return a new {@link @backstage/plugin-auth-node#BackstageSignInResult}
*
* Both options are optional. There is fallback for authHandler where the default handler expect an e-mail explicitly
* otherwise it throws an error
diff --git a/plugins/auth-backend/src/providers/prepareBackstageIdentityResponse.ts b/plugins/auth-backend/src/providers/prepareBackstageIdentityResponse.ts
index bb99cb3487..f3b234c08e 100644
--- a/plugins/auth-backend/src/providers/prepareBackstageIdentityResponse.ts
+++ b/plugins/auth-backend/src/providers/prepareBackstageIdentityResponse.ts
@@ -19,7 +19,10 @@ import {
parseEntityRef,
stringifyEntityRef,
} from '@backstage/catalog-model';
-import { BackstageIdentityResponse, BackstageSignInResult } from './types';
+import {
+ BackstageIdentityResponse,
+ BackstageSignInResult,
+} from '@backstage/plugin-auth-node';
function parseJwtPayload(token: string) {
const [_header, payload, _signature] = token.split('.');
@@ -28,7 +31,7 @@ function parseJwtPayload(token: string) {
/**
* Parses a Backstage-issued token and decorates the
- * {@link BackstageIdentityResponse} with identity information sourced from the
+ * {@link @backstage/plugin-auth-node#BackstageIdentityResponse} with identity information sourced from the
* token.
*
* @public
diff --git a/plugins/auth-backend/src/providers/types.ts b/plugins/auth-backend/src/providers/types.ts
index f3a1a95919..6bef80fd4c 100644
--- a/plugins/auth-backend/src/providers/types.ts
+++ b/plugins/auth-backend/src/providers/types.ts
@@ -19,8 +19,11 @@ import {
TokenManager,
} from '@backstage/backend-common';
import { CatalogApi } from '@backstage/catalog-client';
-import { Entity } from '@backstage/catalog-model';
import { Config } from '@backstage/config';
+import {
+ BackstageIdentityResponse,
+ BackstageSignInResult,
+} from '@backstage/plugin-auth-node';
import express from 'express';
import { Logger } from 'winston';
import { TokenIssuer } from '../identity/types';
@@ -162,84 +165,13 @@ export type AuthResponse = {
};
/**
- * User identity information within Backstage.
+ * The old exported symbol for {@link @backstage/plugin-auth-node#BackstageSignInResult}.
*
* @public
- */
-export type BackstageUserIdentity = {
- /**
- * The type of identity that this structure represents. In the frontend app
- * this will currently always be 'user'.
- */
- type: 'user';
-
- /**
- * The entityRef of the user in the catalog.
- * For example User:default/sandra
- */
- userEntityRef: string;
-
- /**
- * The user and group entities that the user claims ownership through
- */
- ownershipEntityRefs: string[];
-};
-
-/**
- * A representation of a successful Backstage sign-in.
- *
- * Compared to the {@link BackstageIdentityResponse} this type omits
- * the decoded identity information embedded in the token.
- *
- * @public
- */
-export interface BackstageSignInResult {
- /**
- * An opaque ID that uniquely identifies the user within Backstage.
- *
- * This is typically the same as the user entity `metadata.name`.
- *
- * @deprecated Use the `identity` field instead
- */
- id: string;
-
- /**
- * The entity that the user is represented by within Backstage.
- *
- * This entity may or may not exist within the Catalog, and it can be used
- * to read and store additional metadata about the user.
- *
- * @deprecated Use the `identity` field instead.
- */
- entity?: Entity;
-
- /**
- * The token used to authenticate the user within Backstage.
- */
- token: string;
-}
-
-/**
- * The old exported symbol for {@link BackstageSignInResult}.
- *
- * @public
- * @deprecated Use the {@link BackstageSignInResult} instead.
+ * @deprecated Use the {@link @backstage/plugin-auth-node#BackstageSignInResult} instead.
*/
export type BackstageIdentity = BackstageSignInResult;
-/**
- * Response object containing the {@link BackstageUserIdentity} and the token
- * from the authentication provider.
- *
- * @public
- */
-export interface BackstageIdentityResponse extends BackstageSignInResult {
- /**
- * A plaintext description of the identity that is encapsulated within the token.
- */
- identity: BackstageUserIdentity;
-}
-
/**
* Used to display login information to user, i.e. sidebar popup.
*
@@ -286,7 +218,7 @@ export type SignInInfo = {
/**
* Describes the function which handles the result of a successful
- * authentication. Must return a valid {@link BackstageSignInResult}.
+ * authentication. Must return a valid {@link @backstage/plugin-auth-node#BackstageSignInResult}.
*
* @public
*/
diff --git a/plugins/auth-node/api-report.md b/plugins/auth-node/api-report.md
index e32a35880b..7795cae2ca 100644
--- a/plugins/auth-node/api-report.md
+++ b/plugins/auth-node/api-report.md
@@ -3,6 +3,29 @@
> Do not edit this file. It is a report generated by [API Extractor](https://api-extractor.com/).
```ts
+import { Entity } from '@backstage/catalog-model';
+
+// @public
+export interface BackstageIdentityResponse extends BackstageSignInResult {
+ identity: BackstageUserIdentity;
+}
+
+// @public
+export interface BackstageSignInResult {
+ // @deprecated
+ entity?: Entity;
+ // @deprecated
+ id: string;
+ token: string;
+}
+
+// @public
+export type BackstageUserIdentity = {
+ type: 'user';
+ userEntityRef: string;
+ ownershipEntityRefs: string[];
+};
+
// @public
export function getBearerTokenFromAuthorizationHeader(
authorizationHeader: unknown,
diff --git a/plugins/auth-node/package.json b/plugins/auth-node/package.json
index 7e4b4bfe77..6b66f37c6a 100644
--- a/plugins/auth-node/package.json
+++ b/plugins/auth-node/package.json
@@ -20,6 +20,7 @@
},
"dependencies": {
"@backstage/backend-common": "^0.10.7-next.0",
+ "@backstage/catalog-model": "^0.9.10",
"@backstage/config": "^0.1.13",
"winston": "^3.2.1"
},
diff --git a/plugins/auth-node/src/index.ts b/plugins/auth-node/src/index.ts
index 83037f75be..0ecee97e40 100644
--- a/plugins/auth-node/src/index.ts
+++ b/plugins/auth-node/src/index.ts
@@ -21,3 +21,8 @@
*/
export { getBearerTokenFromAuthorizationHeader } from './getBearerTokenFromAuthorizationHeader';
+export type {
+ BackstageIdentityResponse,
+ BackstageSignInResult,
+ BackstageUserIdentity,
+} from './types';
diff --git a/plugins/auth-node/src/types.ts b/plugins/auth-node/src/types.ts
new file mode 100644
index 0000000000..b574c2204d
--- /dev/null
+++ b/plugins/auth-node/src/types.ts
@@ -0,0 +1,88 @@
+/*
+ * Copyright 2022 The Backstage Authors
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+import { Entity } from '@backstage/catalog-model';
+
+/**
+ * A representation of a successful Backstage sign-in.
+ *
+ * Compared to the {@link BackstageIdentityResponse} this type omits
+ * the decoded identity information embedded in the token.
+ *
+ * @public
+ */
+export interface BackstageSignInResult {
+ /**
+ * An opaque ID that uniquely identifies the user within Backstage.
+ *
+ * This is typically the same as the user entity `metadata.name`.
+ *
+ * @deprecated Use the `identity` field instead
+ */
+ id: string;
+
+ /**
+ * The entity that the user is represented by within Backstage.
+ *
+ * This entity may or may not exist within the Catalog, and it can be used
+ * to read and store additional metadata about the user.
+ *
+ * @deprecated Use the `identity` field instead.
+ */
+ entity?: Entity;
+
+ /**
+ * The token used to authenticate the user within Backstage.
+ */
+ token: string;
+}
+
+/**
+ * Response object containing the {@link BackstageUserIdentity} and the token
+ * from the authentication provider.
+ *
+ * @public
+ */
+export interface BackstageIdentityResponse extends BackstageSignInResult {
+ /**
+ * A plaintext description of the identity that is encapsulated within the token.
+ */
+ identity: BackstageUserIdentity;
+}
+
+/**
+ * User identity information within Backstage.
+ *
+ * @public
+ */
+export type BackstageUserIdentity = {
+ /**
+ * The type of identity that this structure represents. In the frontend app
+ * this will currently always be 'user'.
+ */
+ type: 'user';
+
+ /**
+ * The entityRef of the user in the catalog.
+ * For example User:default/sandra
+ */
+ userEntityRef: string;
+
+ /**
+ * The user and group entities that the user claims ownership through
+ */
+ ownershipEntityRefs: string[];
+};
diff --git a/plugins/permission-backend/src/service/router.ts b/plugins/permission-backend/src/service/router.ts
index 10a70b01db..e68f2497e4 100644
--- a/plugins/permission-backend/src/service/router.ts
+++ b/plugins/permission-backend/src/service/router.ts
@@ -23,11 +23,11 @@ import {
PluginEndpointDiscovery,
} from '@backstage/backend-common';
import { InputError } from '@backstage/errors';
+import { IdentityClient } from '@backstage/plugin-auth-backend';
import {
+ getBearerTokenFromAuthorizationHeader,
BackstageIdentityResponse,
- IdentityClient,
-} from '@backstage/plugin-auth-backend';
-import { getBearerTokenFromAuthorizationHeader } from '@backstage/plugin-auth-node';
+} from '@backstage/plugin-auth-node';
import {
AuthorizeResult,
AuthorizeDecision,
diff --git a/plugins/permission-node/api-report.md b/plugins/permission-node/api-report.md
index 43bb548a06..534ad45110 100644
--- a/plugins/permission-node/api-report.md
+++ b/plugins/permission-node/api-report.md
@@ -7,7 +7,7 @@ import { AuthorizeDecision } from '@backstage/plugin-permission-common';
import { AuthorizeQuery } from '@backstage/plugin-permission-common';
import { AuthorizeRequestOptions } from '@backstage/plugin-permission-common';
import { AuthorizeResult } from '@backstage/plugin-permission-common';
-import { BackstageIdentityResponse } from '@backstage/plugin-auth-backend';
+import { BackstageIdentityResponse } from '@backstage/plugin-auth-node';
import { Config } from '@backstage/config';
import express from 'express';
import { Identified } from '@backstage/plugin-permission-common';
diff --git a/plugins/permission-node/package.json b/plugins/permission-node/package.json
index 6fb58251e3..7977e9057f 100644
--- a/plugins/permission-node/package.json
+++ b/plugins/permission-node/package.json
@@ -32,7 +32,7 @@
"@backstage/backend-common": "^0.10.7-next.0",
"@backstage/config": "^0.1.13",
"@backstage/errors": "^0.2.0",
- "@backstage/plugin-auth-backend": "^0.10.0-next.0",
+ "@backstage/plugin-auth-node": "^0.0.0",
"@backstage/plugin-permission-common": "^0.4.0",
"@types/express": "^4.17.6",
"express": "^4.17.1",
diff --git a/plugins/permission-node/src/policy/types.ts b/plugins/permission-node/src/policy/types.ts
index 2e344d6d96..19b12b8f28 100644
--- a/plugins/permission-node/src/policy/types.ts
+++ b/plugins/permission-node/src/policy/types.ts
@@ -20,7 +20,7 @@ import {
PermissionCondition,
PermissionCriteria,
} from '@backstage/plugin-permission-common';
-import { BackstageIdentityResponse } from '@backstage/plugin-auth-backend';
+import { BackstageIdentityResponse } from '@backstage/plugin-auth-node';
/**
* An authorization request to be evaluated by the {@link PermissionPolicy}.