Skip to content

basalt / drives/src / DriveAuthorizationStart

Interface: DriveAuthorizationStart ​

Defined in: drives/src/authorization.ts:31

What the caller must carry through the flow.

Properties ​

binding ​

> binding: string

Defined in: drives/src/authorization.ts:40

Store in an HttpOnly, SameSite=Lax, Secure cookie and hand back at the callback. This is what binds the flow to one browser: a state alone is replayable into a victim's session (login CSRF), a state that only verifies against a value held in the victim's own cookie jar is not.


state ​

> state: string

Defined in: drives/src/authorization.ts:42

Opaque value echoed by the provider; also carried in the URL.


url ​

> url: string

Defined in: drives/src/authorization.ts:33

Send the browser here.

Released under the MIT License.