Class: OAuth
Defined in: auth/src/oauth.ts:401
OAuth 2.0 authorization-code login. Server-side (confidential-client) flow: build an authorize URL with a signed, expiring state, then exchange the code for a token, fetch the profile, and log the user in via Auth.socialLogin.
The flow is bound to the browser that started it: authorize returns a random binding the caller stores in an HttpOnly cookie (oauthRoutes does). The signed state carries its hash, the PKCE verifier (S256) and the OIDC nonce are derived from it, and the callback requires it back — so an attacker's callback URL opened in a victim's browser (login CSRF) or an injected authorization code is refused. Each state is single-use.
Constructors
Constructor
> new OAuth(auth, providers, options): OAuth
Defined in: auth/src/oauth.ts:408
Parameters
auth
providers
options
Returns
OAuth
Methods
authorize()
> authorize(name, redirectUri): object
Defined in: auth/src/oauth.ts:452
Starts a login: returns the provider's authorization URL to redirect the browser to, and the binding to keep in an HttpOnly cookie until the callback (pass it back to callback).
Parameters
name
string
redirectUri
string
Returns
object
binding
> binding: string
url
> url: string
authorizeUrl()
> authorizeUrl(name, redirectUri, binding): string
Defined in: auth/src/oauth.ts:462
The provider's authorization URL for a caller-managed binding (at least 32 characters of randomness, stored where only the initiating browser can present it). Prefer authorize, which generates one.
Parameters
name
string
redirectUri
string
binding
string
Returns
string
callback()
> callback(name, input): Promise<{ created: boolean; tokens: TokenPair; user: PublicUser; }>
Defined in: auth/src/oauth.ts:488
Verifies state against the browser binding, consumes it (single-use), exchanges the code with the PKCE verifier, fetches the profile, and logs in.
Parameters
name
string
input
binding
string | undefined
code
string
redirectUri
string
state
string | undefined
Returns
Promise<{ created: boolean; tokens: TokenPair; user: PublicUser; }>
names()
> names(): string[]
Defined in: auth/src/oauth.ts:437
Returns
string[]