basalt / drives/src / CredentialsOptions
Interface: CredentialsOptions
Defined in: drives/src/credentials.ts:28
Properties
box
> box: DriveSecretBox
Defined in: drives/src/credentials.ts:30
fetchFor
> fetchFor: (connection) => GuardedFetch
Defined in: drives/src/credentials.ts:39
The guarded fetch a refresh call may use, per connection.
A refresh talks to the provider's token endpoint, which is as much an SSRF and timeout surface as a download is — so it goes through the same door. Required rather than optional: an implicit fallback to global fetch is exactly the kind of unguarded path that survives review by being invisible.
Parameters
connection
Returns
now?
> optional now?: () => number
Defined in: drives/src/credentials.ts:40
Returns
number
onInvalidated?
> optional onInvalidated?: (info) => void | Promise<void>
Defined in: drives/src/credentials.ts:46
Called when the grant is terminally gone. Never receives a token.
Parameters
info
connection
reason
string
Returns
void | Promise<void>
onRefreshed?
> optional onRefreshed?: (info) => void | Promise<void>
Defined in: drives/src/credentials.ts:44
Called after a successful refresh, for hooks/audit. Never receives a token.
Parameters
info
connection
rotated
boolean
Returns
void | Promise<void>
refreshSkewMs?
> optional refreshSkewMs?: number
Defined in: drives/src/credentials.ts:42
How long before expiry a token counts as expired. Default 60 s.
store
> store: DriveConnectionStore
Defined in: drives/src/credentials.ts:29