basalt / drives/src / DriveAuthorizationFlow
Class: DriveAuthorizationFlow
Defined in: drives/src/authorization.ts:81
Signs, verifies and consumes authorization states, and derives the PKCE verifier.
The verifier is derived from the binding rather than stored, so the flow keeps no server-side session: there is nothing to garbage-collect, nothing to replicate between instances, and nothing an attacker can read out of a shared store. The binding lives only in the user's cookie.
Constructors
Constructor
> new DriveAuthorizationFlow(secret, options?): DriveAuthorizationFlow
Defined in: drives/src/authorization.ts:87
Parameters
secret
string
options?
now?
() => number
ttlMs?
number
Returns
DriveAuthorizationFlow
Methods
complete()
> complete(input): object
Defined in: drives/src/authorization.ts:117
Verifies the callback and consumes the state.
Every failure produces the same error type and a generic reason: telling a caller which check failed is free help for someone probing the flow.
Parameters
input
Returns
object
codeVerifier
> codeVerifier: string
start()
> start(input): object
Defined in: drives/src/authorization.ts:99
Starts a flow: returns the state to put in the URL and the binding to put in a cookie.
Parameters
input
Returns
object
binding
> binding: string
codeChallenge
> codeChallenge: string
state
> state: string