Skip to content

basalt / auth/src / OAuth

Class: OAuth ​

Defined in: auth/src/oauth.ts:401

OAuth 2.0 authorization-code login. Server-side (confidential-client) flow: build an authorize URL with a signed, expiring state, then exchange the code for a token, fetch the profile, and log the user in via Auth.socialLogin.

The flow is bound to the browser that started it: authorize returns a random binding the caller stores in an HttpOnly cookie (oauthRoutes does). The signed state carries its hash, the PKCE verifier (S256) and the OIDC nonce are derived from it, and the callback requires it back — so an attacker's callback URL opened in a victim's browser (login CSRF) or an injected authorization code is refused. Each state is single-use.

Constructors ​

Constructor ​

> new OAuth(auth, providers, options): OAuth

Defined in: auth/src/oauth.ts:408

Parameters ​

auth ​

Auth

providers ​

OAuthProvider[]

options ​

OAuthOptions

Returns ​

OAuth

Methods ​

authorize() ​

> authorize(name, redirectUri): object

Defined in: auth/src/oauth.ts:452

Starts a login: returns the provider's authorization URL to redirect the browser to, and the binding to keep in an HttpOnly cookie until the callback (pass it back to callback).

Parameters ​

name ​

string

redirectUri ​

string

Returns ​

object

binding ​

> binding: string

url ​

> url: string


authorizeUrl() ​

> authorizeUrl(name, redirectUri, binding): string

Defined in: auth/src/oauth.ts:462

The provider's authorization URL for a caller-managed binding (at least 32 characters of randomness, stored where only the initiating browser can present it). Prefer authorize, which generates one.

Parameters ​

name ​

string

redirectUri ​

string

binding ​

string

Returns ​

string


callback() ​

> callback(name, input): Promise<{ created: boolean; tokens: TokenPair; user: PublicUser; }>

Defined in: auth/src/oauth.ts:488

Verifies state against the browser binding, consumes it (single-use), exchanges the code with the PKCE verifier, fetches the profile, and logs in.

Parameters ​

name ​

string

input ​
binding ​

string | undefined

code ​

string

redirectUri ​

string

state ​

string | undefined

Returns ​

Promise<{ created: boolean; tokens: TokenPair; user: PublicUser; }>


names() ​

> names(): string[]

Defined in: auth/src/oauth.ts:437

Returns ​

string[]

Released under the MIT License.