Skip to content

basalt / auth/src / OAuthRoutesOptions

Interface: OAuthRoutesOptions ​

Defined in: auth/src/oauth-plugin.ts:29

Properties ​

bindingCookie? ​

> optional bindingCookie?: object

Defined in: auth/src/oauth-plugin.ts:48

The HttpOnly cookie that binds a login to the browser that started it. secure defaults to true unless NODE_ENV is explicitly development or test (an unset NODE_ENV counts as production); when secure, the cookie is named __Host-basalt_oauth (host-only, so a sibling subdomain cannot plant it).

maxAgeSeconds? ​

> optional maxAgeSeconds?: number

secure? ​

> optional secure?: boolean


callbackBaseUrl ​

> callbackBaseUrl: string

Defined in: auth/src/oauth-plugin.ts:35

Base URL of your deployed app. The provider redirect_uri is built as ${callbackBaseUrl}/auth/oauth/:provider/callback and must be registered with each provider.


rateLimit? ​

> optional rateLimit?: false | { limit: number; windowMs: number; }

Defined in: auth/src/oauth-plugin.ts:55

meta.rateLimit on both routes (enforced by the http securityPlugin's rate limiter). Default 10 requests per minute per ip and route — each callback costs a token-endpoint and a profile round-trip to the provider. false removes it.


successRedirect? ​

> optional successRedirect?: string

Defined in: auth/src/oauth-plugin.ts:41

When set, the callback redirects the browser here after a successful login with #access_token=…&refresh_token=… in the fragment (for SPA flows). When omitted, the callback responds with JSON { user, accessToken, refreshToken }.

Released under the MIT License.