webviewLogin
AppDelegate.reachfive().webviewLogin(WebviewLoginRequest(
presentationContextProvider
// optional
state,
nonce,
scope, (1)
origin,
prefersEphemeralWebBrowserSession, (2)
webSessionMode, (3)
loginUrlFragment, (4)
))
| 1 | Scope isn’t explicitly required. If not provided here, it defaults to the scopes set up in the client configuration which is picked up when you initialize the iOS SDK. |
| 2 | Available starting with version 7.1.3 |
| 3 | Optional; defaults to .customScheme, which also covers providers that hand the flow off to their own native app.
Use .universalLink only when the login must come back on a universal link intercepted in the sheet — see providerCreator.adoc#universal-link-web-providers and guides/apple-app-site-association.adoc#webcredentials. |
| 4 | Optional; requires request orchestration tokens to be enabled for the client. |
Description
Opens a secure webview through the authorization endpoint.
|
You must have configured a Login URL and enabled request orchestration tokens for your identity client. Orchestrated flows are supported from version |
-
If end-users have an active web SSO session, then the authorization endpoint immediately redirects to the application.
-
If end-users do not have an active web SSO session, they are redirected to the client’s Login URL for authentication.
When logging in with secure webview, a dialog pops up where you must select Continue and acknowledge that by continuing "This allows the app and the website to exchange information about you".
One web login at a time
webviewLogin and a login on a web provider share a single web session. A call made while another one is still in progress ends with AuthCanceled and leaves the login under way untouched.
To end a web login early, cancel the Task that started it: the sheet closes and the call returns AuthCanceled. A SwiftUI .task or any Task you cancel when tearing down your screen does this for you.
Usage
Build the request with presenting: Presentation(from: self) from the initiating UIViewController: the SDK derives the presentation context itself, as it does for provider.login.
Alternatively, pass your own presentationContextProvider — any object implementing ASWebAuthenticationPresentationContextProviding, for instance the view controller itself:
func presentationAnchor(for session: ASWebAuthenticationSession) -> ASPresentationAnchor {
view.window!
}
Examples
do {
let authToken = try await AppDelegate.reachfive().webviewLogin(WebviewLoginRequest(
state: "zf3ifjfmdkj",
nonce: "n-0S6_PzA3Ze",
scope: ["openid", "profile", "email"],
presenting: Presentation(from: self)
))
// Get the profile's authentication token
} catch {
// Return a ReachFive error
}
Parameters
| Parameter | Description | ||
|---|---|---|---|
A delegate that provides a display context whereby the system is able to present an authentication session to the user.
|
|||
The OAuth2 state value.
|
|||
An OIDC nonce value.
|
|||
The scopes granted to the profile. Make sure they are allowed by the client. Default scopes are the allowed scopes set up in the client’s configuration. |
|||
The origin of the call. |
|||
A Boolean value that indicates whether the session should ask the browser for a private authentication session. The value of this property is false by default.
|
|||
Controls the behavior of the Values
|
|||
Key/value pairs propagated in the fragment of the Intended for the token-orchestration flow:
|
Response
-
Type: AuthToken
-
Error: ReachFiveError
AuthToken
The authentication token.
idToken |
The ID token JSON Web Token (JWT) that contains the profile’s information. This is only available when the |
||||||||||||||||||||||||||||||||||
accessToken |
The authorization credential JSON Web Token (JWT) used to access the ReachFive API. |
||||||||||||||||||||||||||||||||||
refreshToken |
The refresh token JSON Web Token (JWT) used to obtain new access tokens once they expire. This is only available when the |
||||||||||||||||||||||||||||||||||
tokenType |
The type of token. Always equal to |
||||||||||||||||||||||||||||||||||
expiresIn |
The lifetime in seconds of the access token. If |
||||||||||||||||||||||||||||||||||
user OpenIDUser |
The user’s information contained in the ID token.
|
ReachFiveError
Based on the problem, the ReachFiveError will be:
-
AuthCanceled: Nothing happened, and nothing is expected of you — ignoring it is a valid way to handle it.
This can happen for any of the following reasons:-
The user canceled the request.
-
No passkey was saved for your app.
-
A web login was dropped because another one was already in progress. See webviewLogin.
-
The app is not associated with the host of an
WebProvider.universalLinkcallback. See guides/apple-app-site-association.adoc#webcredentials.
-
-
RequestError(apiError: ApiError)for a Bad Request (status 400) error. -
AuthFailure(reason: String, apiError: ApiError?)mainly for Unauthorized (status 401) error. -
TechnicalError(reason: String, apiError: ApiError?)if it’s an Internal Server Error (status 500) or other internal errors.
ApiError
error |
The main error message. |
||||||
errorId |
The identifier of the error. |
||||||
errorUserMsg |
The user-friendly error message.
|
||||||
errorMessageKey |
The error message key. |
||||||
errorDescription |
The technical error message. |
||||||
errorDetails FieldError[] |
|