Skip to content

basalt / drives/src / CredentialsOptions

Interface: CredentialsOptions ​

Defined in: drives/src/credentials.ts:28

Properties ​

box ​

> box: DriveSecretBox

Defined in: drives/src/credentials.ts:30


fetchFor ​

> fetchFor: (connection) => GuardedFetch

Defined in: drives/src/credentials.ts:39

The guarded fetch a refresh call may use, per connection.

A refresh talks to the provider's token endpoint, which is as much an SSRF and timeout surface as a download is — so it goes through the same door. Required rather than optional: an implicit fallback to global fetch is exactly the kind of unguarded path that survives review by being invisible.

Parameters ​

connection ​

DriveConnection

Returns ​

GuardedFetch


now? ​

> optional now?: () => number

Defined in: drives/src/credentials.ts:40

Returns ​

number


onInvalidated? ​

> optional onInvalidated?: (info) => void | Promise<void>

Defined in: drives/src/credentials.ts:46

Called when the grant is terminally gone. Never receives a token.

Parameters ​

info ​
connection ​

DriveConnection

reason ​

string

Returns ​

void | Promise<void>


onRefreshed? ​

> optional onRefreshed?: (info) => void | Promise<void>

Defined in: drives/src/credentials.ts:44

Called after a successful refresh, for hooks/audit. Never receives a token.

Parameters ​

info ​
connection ​

DriveConnection

rotated ​

boolean

Returns ​

void | Promise<void>


refreshSkewMs? ​

> optional refreshSkewMs?: number

Defined in: drives/src/credentials.ts:42

How long before expiry a token counts as expired. Default 60 s.


store ​

> store: DriveConnectionStore

Defined in: drives/src/credentials.ts:29

Released under the MIT License.