Skip to content

basalt / drives/src / DriveAuthorizationFlow

Class: DriveAuthorizationFlow ​

Defined in: drives/src/authorization.ts:81

Signs, verifies and consumes authorization states, and derives the PKCE verifier.

The verifier is derived from the binding rather than stored, so the flow keeps no server-side session: there is nothing to garbage-collect, nothing to replicate between instances, and nothing an attacker can read out of a shared store. The binding lives only in the user's cookie.

Constructors ​

Constructor ​

> new DriveAuthorizationFlow(secret, options?): DriveAuthorizationFlow

Defined in: drives/src/authorization.ts:87

Parameters ​

secret ​

string

options? ​
now? ​

() => number

ttlMs? ​

number

Returns ​

DriveAuthorizationFlow

Methods ​

complete() ​

> complete(input): object

Defined in: drives/src/authorization.ts:117

Verifies the callback and consumes the state.

Every failure produces the same error type and a generic reason: telling a caller which check failed is free help for someone probing the flow.

Parameters ​

input ​

CompleteAuthorizationInput

Returns ​

object

codeVerifier ​

> codeVerifier: string


start() ​

> start(input): object

Defined in: drives/src/authorization.ts:99

Starts a flow: returns the state to put in the URL and the binding to put in a cookie.

Parameters ​

input ​

StartAuthorizationInput

Returns ​

object

binding ​

> binding: string

codeChallenge ​

> codeChallenge: string

state ​

> state: string

Released under the MIT License.