basalt / drives/src / DriveAuthorizationStart
Interface: DriveAuthorizationStart
Defined in: drives/src/authorization.ts:31
What the caller must carry through the flow.
Properties
binding
> binding: string
Defined in: drives/src/authorization.ts:40
Store in an HttpOnly, SameSite=Lax, Secure cookie and hand back at the callback. This is what binds the flow to one browser: a state alone is replayable into a victim's session (login CSRF), a state that only verifies against a value held in the victim's own cookie jar is not.
state
> state: string
Defined in: drives/src/authorization.ts:42
Opaque value echoed by the provider; also carried in the URL.
url
> url: string
Defined in: drives/src/authorization.ts:33
Send the browser here.