jargonsdev/jargons.dev

Auth Feature - Fourth Iteration

Open

#30 opened on Apr 4, 2024

 (1 comment) (0 reactions) (0 assignees)MDX (45 forks)auto 404
:arrow_upper_right: medium priority:sparkles: enhancementhacktoberfest

Repository metrics

Stars
 (54 stars)
PR merge metrics
 (PR metrics pending)

Description

The third iteration of the auth feature should focus on enhancing the OAuth flow and adding a signout/disconnect feature.

This is a follow up to the initial iterations...

Tasks

  1. Store OAuth Flow State Object in Cookies: Implement the todo that suggests storing the OAuth flow state object to cookies. This stored state should be compared with the state param returned from the GitHub OAuth flow in the github/oauth/callback handler to prevent CSRF attacks.

Related Files

  • github/oauth/callback.js
  • lib/actions/do-auth.js

Acceptance Criteria

  • OAuth flow state object is stored in cookies and compared with the state param.
  • Signout/disconnect feature is implemented and accessible through the doAuth action

Additional Notes

  • Nothing much... just ask a question or share ideas, if you've got any 😉

Contributor guide