mirror of
https://github.com/nestriness/nestri.git
synced 2026-09-19 09:15:19 +03:00
A program with no browser — the desktop app — had a client for RFC 8628 and nothing to point it at. This serves the other half: a device authorization request that hands back a code, a page a person enters that code on, and a token endpoint that answers the poll. Both of the paths the client already implements are now reachable. Polling faster than the advertised interval gets slow_down, and each warning widens the interval so ignoring one costs more than the last; refusing gets access_denied, so a request nobody started stops instead of being polled until it ages out. The interval is capped, because it only ever grows and a code has to stay pollable for the whole of its life. The codes live in the same storage as the other short-lived grants rather than in a table, since that is what they are. User codes are drawn from an alphabet with no vowels and no look-alike pairs, and are accepted back in whatever case and spacing a person retyped them in.
packages/auth (@nestri/auth)
Framework-agnostic OpenAuth implementation for Nestri — the OAuth/OIDC issuer, client, subjects, and the login UI. A vendored/forked build of OpenAuth.
What it does
Everything needed to run your own authentication provider:
issuer.ts— the authorization server: routes for/authorize,/callback,/token,/userinfo,.well-known/*, plus the login UI (React renderer).client.ts—createClientto verify JWTs against the issuer ("who is this token?").subject.ts— typed JWT subjects (zodschemas for the token payload).provider/*— drop-in OAuth/OIDC providers (steam, discord, github, google, apple, microsoft, slack, spotify, twitch, x, yahoo, facebook, linkedin, cognito, keycloak, jumpcloud, oauth2, oidc, password, ssh, code, arctic).storage/*— persistence adapters for keys/sessions/codes:memory,cloudflare(KV),aws,dynamo.ui/*— the login page components (forms, password, code, theme, CSS).jwt.ts,keys.ts,pkce.ts,random.ts— signing, keypair management, PKCE, randomness.
Usage
Consumed by the apps/auth worker, e.g.:
import { issuer } from '@nestri/auth/index';
import { CloudflareStorage } from '@nestri/auth/storage/cloudflare';
import { SteamProvider } from '@nestri/auth/provider/steam';
The API uses createClient (from @openauth/openauth/client) or the bundled client.ts to verify
tokens against the issuer URL.
Scripts
bun test # run tests
bun run build # build (see script/build.ts)
Note
@openauthjs is the upstream project; this package's exports are meant to be API-compatible with a
pinned preference toward tree-shaking-friendly imports. Prefer importing subpaths over the barrel
(@nestri/auth/index).