basalt / auth/src / OAuthOptions
Interface: OAuthOptions
Defined in: auth/src/oauth.ts:310
Properties
fetch?
> optional fetch?: (input, init?) => Promise<Response>
Defined in: auth/src/oauth.ts:314
Injected fetch (tests). Default: global fetch.
Parameters
input
string | URL | Request
init?
RequestInit
Returns
Promise<Response>
mfa?
> optional mfa?: "required" | "skip"
Defined in: auth/src/oauth.ts:325
MFA for an existing account that has it enabled. 'required' (default) refuses the social login with AUTH_MFA_REQUIRED — the callback cannot collect a code. 'skip' trusts the provider's own second factor; choose it only for an IdP that enforces MFA.
now?
> optional now?: () => number
Defined in: auth/src/oauth.ts:316
Clock in ms (tests). Default: Date.now.
Returns
number
secret
> secret: string
Defined in: auth/src/oauth.ts:312
Secret used to sign the CSRF state (typically your APP_SECRET).
stateTtlMs?
> optional stateTtlMs?: number
Defined in: auth/src/oauth.ts:318
How long a signed state stays valid, in ms. Default: 10 minutes.
subjectConflict?
> optional subjectConflict?: "refuse" | "link"
Defined in: auth/src/oauth.ts:340
An account already linked to one subject of a provider, and a login from a different subject of that provider asserting the same email: 'refuse' (default, AUTH_ACCOUNT_LINK_CONFLICT) or 'link' the new subject too. Choose 'link' only for an IdP that re-issues subjects (a directory migration) — otherwise it lets a second IdP account take the first one's place by email.
timeoutMs?
> optional timeoutMs?: number
Defined in: auth/src/oauth.ts:331
Timeout for every request to a provider (token endpoint, userinfo, …), ms. Default 10 s; a provider that hangs fails the login with AUTH_OAUTH_EXCHANGE_FAILED instead of holding the request open.