@better-auth-ui/core
Version:
Authentication components and data utilities for [Better Auth](https://better-auth.com), available for React and Solid.
201 lines (200 loc) • 6.76 kB
TypeScript
import { OAuthClientManager } from './oauth-client-manager';
import { OAuthProviderLocalization } from './oauth-provider-localization';
import { OAuthScopeMetadataSource } from './oauth-scope-metadata';
declare module "../../lib/view-paths" {
/** Widens `AuthViewPaths` with the OAuth paths when this plugin is imported. */
interface AuthViewPaths {
/** @default "oauth-consent" */
oauthConsent?: string;
/** @default "oauth-sign-up" */
oauthSignUp?: string;
/** @default "select-account" */
oauthSelectAccount?: string;
}
interface SettingsViewPaths {
/** @default "oauth-clients" */
oauthClients?: string;
}
}
/**
* The display-safe parts of Better Auth's signed authorization query.
*/
export type OAuthAuthorizationRequest = {
clientId?: string;
scopes: string[];
prompts: string[];
};
/**
* Variables accepted by Better Auth's `oauth2.continue` endpoint.
*
* Exactly one flag is set per call, matching the redirect screen that just
* finished: signup (`created`), account selection (`selected`), or an
* application-owned post-login screen (`postLogin`).
*/
export interface OAuthContinueVariables {
created?: true;
selected?: true;
postLogin?: true;
}
/**
* Keep client-controlled links and images on browser-safe web protocols.
*/
export declare function sanitizeOAuthClientUrl(value: string | null | undefined): string | undefined;
/**
* Read the display-safe parts of Better Auth's signed authorization query.
*
* The complete query string must remain in the browser URL so
* `oauthProviderClient()` can forward and verify it during consent.
*/
export declare function parseOAuthAuthorizationRequest(search: string): OAuthAuthorizationRequest;
/**
* Check whether the authorization request asked for a specific prompt.
*
* OAuth sends `prompt` as a space-separated set, so `prompt=login consent`
* matches both `"login"` and `"consent"`.
*/
export declare function hasOAuthPrompt(request: OAuthAuthorizationRequest, prompt: string): boolean;
export type OAuthProviderPluginOptions = {
/**
* Override the plugin's default localization strings.
* @remarks `OAuthProviderLocalization`
*/
localization?: Partial<OAuthProviderLocalization>;
/**
* URL segment for the OAuth consent view.
* @remarks `string`
* @default "oauth-consent"
*/
path?: string;
/**
* URL segment for the OAuth-aware sign-up view.
*
* This is a route of its own rather than an override of the built-in
* `signUp` view, so ordinary sign-up stays untouched. Point Better Auth's
* `signup.page` at it.
* @remarks `string`
* @default "oauth-sign-up"
*/
signUpPath?: string;
/**
* URL segment for the OAuth account selection view.
* @remarks `string`
* @default "select-account"
*/
selectAccountPath?: string;
/**
* Labels and descriptions for OAuth scopes, as a keyed record, a static
* list, or a synchronous resolver.
*
* Entries override the built-in metadata for `openid`, `profile`, `email`,
* and `offline_access`. Unresolved scopes remain visible using their raw
* value.
* @remarks `OAuthScopeMetadataSource`
*/
scopeMetadata?: OAuthScopeMetadataSource;
/**
* Register the connected applications card in security settings.
* @remarks `boolean`
* @default true
*/
showConnectedApplications?: boolean;
/**
* Add personal OAuth client developer settings backed by Better Auth.
* @default false
*/
clientManagement?: boolean;
/**
* Replace the personal Better Auth browser adapter with an application-owned
* manager. Use this for server-only operations such as enable or disable.
*/
clientManager?: OAuthClientManager;
/**
* Add organization developer settings backed by an application-owned
* manager. The UI passes the organization ID and slug on every operation.
*/
organizationClientManager?: OAuthClientManager;
/** @default "oauth-clients" */
clientManagementPath?: string;
};
export declare const oauthProviderPlugin: ((options?: OAuthProviderPluginOptions | undefined) => {
localization: {
authorize: string;
authorizationDescription: string;
requestedPermissions: string;
signedInAs: string;
allow: string;
cancel: string;
privacyPolicy: string;
termsOfService: string;
invalidRequest: string;
invalidRequestDescription: string;
application: string;
selectAccount: string;
selectAccountDescription: string;
currentAccount: string;
continue: string;
noAccounts: string;
noAccountsDescription: string;
accountCreated: string;
continuing: string;
continueFailed: string;
tryAgain: string;
connectedApplications: string;
noConnectedApplications: string;
connectedApplicationsDescription: string;
lastAuthorized: string;
removeAuthorization: string;
removeAuthorizationTitle: string;
removeAuthorizationDescription: string;
remove: string;
oauthClients: string;
oauthClientsDescription: string;
noOAuthClients: string;
noOAuthClientsDescription: string;
createClient: string;
editClient: string;
clientName: string;
applicationType: string;
webApplication: string;
nativeApplication: string;
redirectUrls: string;
redirectUrlsDescription: string;
invalidUrl: string;
applicationUrl: string;
logoUrl: string;
scopes: string;
saveChanges: string;
clientId: string;
clientSecret: string;
clientSecretWarning: string;
rotateSecret: string;
rotateSecretTitle: string;
rotateSecretDescription: string;
deleteClient: string;
deleteClientTitle: string;
deleteClientDescription: string;
enabled: string;
disabled: string;
clientCreated: string;
secretRotated: string;
};
scopeMetadata: OAuthScopeMetadataSource | undefined;
showConnectedApplications: boolean;
clientManagement: boolean;
clientManager: OAuthClientManager | undefined;
organizationClientManager: OAuthClientManager | undefined;
viewPaths: {
auth: {
oauthConsent: string;
oauthSignUp: string;
oauthSelectAccount: string;
};
settings: {
oauthClients: string;
};
};
} & {
id: "oauthProvider";
}) & {
id: "oauthProvider";
};