basalt / drives/src / DriveRoutesOptions
Interface: DriveRoutesOptions
Defined in: drives/src/routes.ts:123
Properties
basePath?
> optional basePath?: string
Defined in: drives/src/routes.ts:125
Mount prefix. Default /drives.
cookie?
> optional cookie?: object
Defined in: drives/src/routes.ts:151
name?
> optional name?: string
sameSite?
> optional sameSite?: "Strict" | "Lax"
secure?
> optional secure?: boolean
Force Secure off. Only honoured for a http://localhost redirect URI.
drives?
> optional drives?: Drives | (() => Drives)
Defined in: drives/src/routes.ts:160
The instance to use. Defaults to DRIVES from the request's container.
meta?
> optional meta?: Record<string, unknown>
Defined in: drives/src/routes.ts:150
Guard metadata for the connect and callback routes. Default { auth: true }: starting an authorization on behalf of a tenant is not an anonymous action, and defaulting it open is how a connect endpoint becomes a way to attach an attacker's drive to someone else's tenant.
The notification routes never get this — the provider has no session.
notifications?
> optional notifications?: DriveNotificationRoutes
Defined in: drives/src/routes.ts:158
Mount the notification endpoint. Omit it and only the connect flow is served.
redirectUri
> redirectUri: string | ((provider) => string)
Defined in: drives/src/routes.ts:134
The redirect URI registered with the provider. A function when it differs per provider, which it usually does.
It must match the provider's registration byte for byte; it is validated (absolute, https: except on localhost, no credentials, no fragment) before it ever reaches a URL the browser follows.
scopes?
> optional scopes?: (provider) => readonly string[] | undefined
Defined in: drives/src/routes.ts:136
Scopes to request, when they differ from the adapter's defaults.
Parameters
provider
string
Returns
readonly string[] | undefined
successRedirect?
> optional successRedirect?: string | ((connection) => string)
Defined in: drives/src/routes.ts:141
Where to send the browser after a successful connect. Omit to answer with the connection as JSON — useful for an SPA that opened a popup.