Replies: 2 comments
|
The The If you actually need access to the authorization server metadata inside the hook, you would need to either:
app.use("/*", async (c, next) => {
const oidcAuth = oidcAuthMiddleware({
oidcClaimsHook: async (orig, claims, response) => {
// Access c here via closure
const server = c.get("oidcAuthorizationServer");
const userInfo = await fetch(server.userinfo_endpoint, {
headers: { Authorization: `Bearer ${response.access_token}` },
}).then((res) => res.json());
return { ...orig, ...userInfo };
},
});
return oidcAuth(c, next);
});
Worth opening an issue or PR to fix that README snippet — it is misleading as-is. |
|
You didn't miss anything — To resolve and use Option 1: Factory Function / Closure (Recommended)Define the hook inside your route or middleware so import { processOAuthCallback } from '@hono/oidc-auth';
import type { Context, OidcAuthClaims } from 'hono';
app.get('/callback', async (c) => {
// `c` is captured from the route handler's lexical scope
const oidcClaimsHook = async (
orig: OidcAuth | undefined,
claims: IDToken | undefined,
response: TokenEndpointResponses
): Promise<OidcAuthClaims> => {
// Safely retrieve the authorization server config stored by the middleware
const authServer = c.get('oidcAuthorizationServer');
let extraUserInfo = {};
if (authServer?.userinfo_endpoint && response.access_token) {
const res = await fetch(authServer.userinfo_endpoint, {
headers: {
Authorization: `Bearer ${response.access_token}`,
},
});
extraUserInfo = await res.json();
}
return {
name: claims?.name as string ?? orig?.name ?? '',
sub: claims?.sub ?? orig?.sub ?? '',
...extraUserInfo,
};
};
c.set('oidcClaimsHook', oidcClaimsHook);
return processOAuthCallback(c);
});Option 2: Middleware-level Hook (for Automatic Refresh)Because app.use('*', async (c, next) => {
c.set('oidcClaimsHook', async (orig, claims, response) => {
const authServer = c.get('oidcAuthorizationServer');
if (authServer?.userinfo_endpoint && response.access_token) {
// fetch userinfo...
}
return {
name: claims?.name as string ?? orig?.name ?? '',
sub: claims?.sub ?? orig?.sub ?? '',
};
});
await next();
});(Note also that in standard |
Uh oh!
There was an error while loading. Please reload this page.
In the README of
oidc-auth, under the section "Using original response or additional claims", there is the following code:However, I can't find where
cis defined or how it should be resolved in this context.Am I missing something?
All reactions