basalt / auth/src / OAuthProvider
Interface: OAuthProvider
Defined in: auth/src/oauth.ts:57
Properties
allowAnyEmailDomain?
> optional allowAnyEmailDomain?: true
Defined in: auth/src/oauth.ts:83
Explicit opt-out of allowedEmailDomains for an enterprise provider when several providers are configured: this IdP may assert any email. Only for an IdP you fully control.
allowedEmailDomains?
> optional allowedEmailDomains?: string[]
Defined in: auth/src/oauth.ts:77
Email domains this provider is trusted to assert (exact, case-insensitive match on the part after @; list subdomains explicitly). A login for any other domain is refused with AUTH_OAUTH_EXCHANGE_FAILED before any account is looked up.
authorizeUrl
> authorizeUrl: string
Defined in: auth/src/oauth.ts:59
clientId
> clientId: string
Defined in: auth/src/oauth.ts:61
clientSecret
> clientSecret: string
Defined in: auth/src/oauth.ts:62
enterprise?
> optional enterprise?: boolean
Defined in: auth/src/oauth.ts:91
The provider is an enterprise IdP administered by someone else — typically a customer's Okta / Entra / Keycloak (oidcProvider sets it). Its admin decides which emails it asserts as verified, so when more than one provider is configured it must declare allowedEmailDomains (or allowAnyEmailDomain) or the OAuth service refuses to start.
issuer?
> optional issuer?: string | string[]
Defined in: auth/src/oauth.ts:70
Expected iss of the id_token (OpenID Connect). When set, an id_token issued by anyone else is refused.
name
> name: string
Defined in: auth/src/oauth.ts:58
scopes
> scopes: string[]
Defined in: auth/src/oauth.ts:63
tokenUrl
> tokenUrl: string
Defined in: auth/src/oauth.ts:60
Methods
fetchProfile()
> fetchProfile(accessToken, doFetch): Promise<OAuthProfile>
Defined in: auth/src/oauth.ts:65
Fetches and normalizes the user profile from an access token.
Parameters
accessToken
string
doFetch
(input, init?) => Promise<Response>
Returns
Promise<OAuthProfile>