Skip to content

basalt / auth/src / OAuthPluginOptions

Interface: OAuthPluginOptions ​

Defined in: auth/src/oauth-plugin.ts:10

Extends ​

Properties ​

fetch? ​

> optional fetch?: (input, init?) => Promise<Response>

Defined in: auth/src/oauth.ts:314

Injected fetch (tests). Default: global fetch.

Parameters ​

input ​

string | URL | Request

init? ​

RequestInit

Returns ​

Promise<Response>

Inherited from ​

OAuthOptions.fetch


mfa? ​

> optional mfa?: "required" | "skip"

Defined in: auth/src/oauth.ts:325

MFA for an existing account that has it enabled. 'required' (default) refuses the social login with AUTH_MFA_REQUIRED — the callback cannot collect a code. 'skip' trusts the provider's own second factor; choose it only for an IdP that enforces MFA.

Inherited from ​

OAuthOptions.mfa


now? ​

> optional now?: () => number

Defined in: auth/src/oauth.ts:316

Clock in ms (tests). Default: Date.now.

Returns ​

number

Inherited from ​

OAuthOptions.now


providers ​

> providers: OAuthProvider[]

Defined in: auth/src/oauth-plugin.ts:11


secret ​

> secret: string

Defined in: auth/src/oauth.ts:312

Secret used to sign the CSRF state (typically your APP_SECRET).

Inherited from ​

OAuthOptions.secret


stateTtlMs? ​

> optional stateTtlMs?: number

Defined in: auth/src/oauth.ts:318

How long a signed state stays valid, in ms. Default: 10 minutes.

Inherited from ​

OAuthOptions.stateTtlMs


subjectConflict? ​

> optional subjectConflict?: "refuse" | "link"

Defined in: auth/src/oauth.ts:340

An account already linked to one subject of a provider, and a login from a different subject of that provider asserting the same email: 'refuse' (default, AUTH_ACCOUNT_LINK_CONFLICT) or 'link' the new subject too. Choose 'link' only for an IdP that re-issues subjects (a directory migration) — otherwise it lets a second IdP account take the first one's place by email.

Inherited from ​

OAuthOptions.subjectConflict


timeoutMs? ​

> optional timeoutMs?: number

Defined in: auth/src/oauth.ts:331

Timeout for every request to a provider (token endpoint, userinfo, …), ms. Default 10 s; a provider that hangs fails the login with AUTH_OAUTH_EXCHANGE_FAILED instead of holding the request open.

Inherited from ​

OAuthOptions.timeoutMs

Released under the MIT License.