-
Notifications
You must be signed in to change notification settings - Fork 0
/
auth.ts
102 lines (89 loc) · 3.11 KB
/
auth.ts
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
import NextAuth, { JWT } from "next-auth";
import Google from "next-auth/providers/google";
// const GOOGLE_AUTHORIZATION_URL =
// "https://accounts.google.com/o/oauth2/v2/auth?" +
// new URLSearchParams({
// prompt: "consent",
// access_type: "offline",
// response_type: "code",
// scope: "email profile openid https://www.googleapis.com/auth/userinfo.profile https://www.googleapis.com/auth/userinfo.email https://www.googleapis.com/auth/youtube.force-ssl",
// });
async function refreshGoogleAccessToken(token: any) {
console.log("refreshGoogleAccessToken");
try {
const url =
"https://oauth2.googleapis.com/token?" +
new URLSearchParams({
client_id: process.env.AUTH_GOOGLE_ID!,
client_secret: process.env.AUTH_GOOGLE_SECRET!,
grant_type: "refresh_token",
refresh_token: token.googleRefreshToken,
});
const response = await fetch(url, {
headers: {
"Content-Type": "application/x-www-form-urlencoded",
},
method: "POST",
});
const refreshedTokens = await response.json();
if (!response.ok) {
throw refreshedTokens;
}
return {
...token,
googleAccessToken: refreshedTokens.access_token,
googleAccessTokenExpiresAt: Date.now() + refreshedTokens.expires_in * 1000,
googleRefreshToken:
refreshedTokens.refresh_token ?? token.googleRefreshToken, // Fall back to old refresh token
};
} catch (error) {
console.log(error);
return {
...token,
error: "RefreshAccessTokenError",
};
}
}
export const { handlers, signIn, signOut, auth } = NextAuth({
providers: [
Google({
authorization: {
params: {
prompt: "consent",
access_type: "offline",
response_type: "code",
scope: "email profile openid https://www.googleapis.com/auth/userinfo.profile https://www.googleapis.com/auth/userinfo.email https://www.googleapis.com/auth/youtube.force-ssl",
},
},
}),
],
callbacks: {
jwt: async({account,token, user, }) => {
if(account && user) {
if (account.provider === "google") {
return {
...token,
googleAccessToken: account.access_token,
googleRefreshToken: account.refresh_token,
googleUsername: account.providerAccountId,
googleAccessTokenExpiresAt: (account.expires_at || 0) * 1000,
};
}
}
if (token.googleAccessTokenExpiresAt) {
//@ts-ignore
if (Date.now() > token.googleAccessTokenExpiresAt) {
return await refreshGoogleAccessToken(token);
}
}
return token;
},
session: async ({ session, token }) => {
session.user.googleAccessToken = token.googleAccessToken as string;
session.user.googleRefreshToken = token.googleRefreshToken as string;
session.user.googleUsername = token.googleUsername as string;
session.user.googleAccessTokenExpiresAt = token.googleAccessTokenExpiresAt as number;
return session;
},
},
});