Skip to content

basalt / auth/src / OAuthOptions

Interface: OAuthOptions ​

Defined in: auth/src/oauth.ts:310

Properties ​

fetch? ​

> optional fetch?: (input, init?) => Promise<Response>

Defined in: auth/src/oauth.ts:314

Injected fetch (tests). Default: global fetch.

Parameters ​

input ​

string | URL | Request

init? ​

RequestInit

Returns ​

Promise<Response>


mfa? ​

> optional mfa?: "required" | "skip"

Defined in: auth/src/oauth.ts:325

MFA for an existing account that has it enabled. 'required' (default) refuses the social login with AUTH_MFA_REQUIRED — the callback cannot collect a code. 'skip' trusts the provider's own second factor; choose it only for an IdP that enforces MFA.


now? ​

> optional now?: () => number

Defined in: auth/src/oauth.ts:316

Clock in ms (tests). Default: Date.now.

Returns ​

number


secret ​

> secret: string

Defined in: auth/src/oauth.ts:312

Secret used to sign the CSRF state (typically your APP_SECRET).


stateTtlMs? ​

> optional stateTtlMs?: number

Defined in: auth/src/oauth.ts:318

How long a signed state stays valid, in ms. Default: 10 minutes.


subjectConflict? ​

> optional subjectConflict?: "refuse" | "link"

Defined in: auth/src/oauth.ts:340

An account already linked to one subject of a provider, and a login from a different subject of that provider asserting the same email: 'refuse' (default, AUTH_ACCOUNT_LINK_CONFLICT) or 'link' the new subject too. Choose 'link' only for an IdP that re-issues subjects (a directory migration) — otherwise it lets a second IdP account take the first one's place by email.


timeoutMs? ​

> optional timeoutMs?: number

Defined in: auth/src/oauth.ts:331

Timeout for every request to a provider (token endpoint, userinfo, …), ms. Default 10 s; a provider that hangs fails the login with AUTH_OAUTH_EXCHANGE_FAILED instead of holding the request open.

Released under the MIT License.