basalt / auth/src / OAuthRoutesOptions
Interface: OAuthRoutesOptions
Defined in: auth/src/oauth-plugin.ts:29
Properties
bindingCookie?
> optional bindingCookie?: object
Defined in: auth/src/oauth-plugin.ts:48
The HttpOnly cookie that binds a login to the browser that started it. secure defaults to true unless NODE_ENV is explicitly development or test (an unset NODE_ENV counts as production); when secure, the cookie is named __Host-basalt_oauth (host-only, so a sibling subdomain cannot plant it).
maxAgeSeconds?
> optional maxAgeSeconds?: number
secure?
> optional secure?: boolean
callbackBaseUrl
> callbackBaseUrl: string
Defined in: auth/src/oauth-plugin.ts:35
Base URL of your deployed app. The provider redirect_uri is built as ${callbackBaseUrl}/auth/oauth/:provider/callback and must be registered with each provider.
rateLimit?
> optional rateLimit?: false | { limit: number; windowMs: number; }
Defined in: auth/src/oauth-plugin.ts:55
meta.rateLimit on both routes (enforced by the http securityPlugin's rate limiter). Default 10 requests per minute per ip and route — each callback costs a token-endpoint and a profile round-trip to the provider. false removes it.
successRedirect?
> optional successRedirect?: string
Defined in: auth/src/oauth-plugin.ts:41
When set, the callback redirects the browser here after a successful login with #access_token=…&refresh_token=… in the fragment (for SPA flows). When omitted, the callback responds with JSON { user, accessToken, refreshToken }.