-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathgithub-auth.ts
More file actions
57 lines (49 loc) · 1.82 KB
/
Copy pathgithub-auth.ts
File metadata and controls
57 lines (49 loc) · 1.82 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
import { env } from '$env/dynamic/private';
export function githubAuthConfigured(): boolean {
return Boolean(env.GITHUB_CLIENT_ID && env.GITHUB_CLIENT_SECRET && env.SESSION_SECRET);
}
export function buildAuthorizeUrl(state: string, redirectUri: string): string {
const params = new URLSearchParams({
client_id: env.GITHUB_CLIENT_ID ?? '',
redirect_uri: redirectUri,
scope: 'read:user',
state
});
return `https://github.com/login/oauth/authorize?${params}`;
}
export async function exchangeCodeForToken(code: string, redirectUri: string): Promise<string> {
const res = await fetch('https://github.com/login/oauth/access_token', {
method: 'POST',
headers: {
Accept: 'application/json',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({
client_id: env.GITHUB_CLIENT_ID ?? '',
client_secret: env.GITHUB_CLIENT_SECRET ?? '',
code,
redirect_uri: redirectUri
}),
signal: AbortSignal.timeout(10_000)
});
if (!res.ok) throw new Error(`GitHub token exchange failed: ${res.status}`);
const data = await res.json();
if (!data.access_token) throw new Error(`GitHub token exchange failed: ${JSON.stringify(data)}`);
return data.access_token;
}
export async function fetchGithubUser(accessToken: string): Promise<{ id: number; login: string }> {
const res = await fetch('https://api.github.com/user', {
headers: {
Authorization: `Bearer ${accessToken}`,
// GitHub's API rejects unauthenticated-looking requests without one.
'User-Agent': 'ghostbase'
},
signal: AbortSignal.timeout(10_000)
});
if (!res.ok) throw new Error(`GitHub user fetch failed: ${res.status}`);
const data = await res.json();
if (typeof data.id !== 'number' || typeof data.login !== 'string') {
throw new Error('GitHub user fetch: missing id/login');
}
return { id: data.id, login: data.login };
}