* feat: add personal access tokens * feat: replace MCP tokens with OAuth foundation * fix: keep OAuth constants private in auth foundation * fix: clean up mcp oauth branch scope * fix: expose oauth metadata endpoints * fix: trim mcp oauth config to non-default options Drop OIDC scopes, the org-id JWT claim, and the openid-configuration metadata endpoint since the MCP integration is OAuth-only and the org gets resolved server-side. Also remove options that just duplicated better-auth defaults. * fix: drop redundant oauth metadata helpers Remove `session.storeSessionInDatabase: true` since better-auth only enforces it when secondaryStorage is configured. Inline the `getHostedBaseUrlForOAuthMetadata` alias and skip the async `getOAuthServerConfig()` call in the protected-resource metadata handler — the issuer is just `baseURL` without a custom jwt.issuer override. * docs: explain cache headers on mcp metadata response * Use escaped file routes for OAuth metadata * save
13 lines
414 B
TypeScript
13 lines
414 B
TypeScript
import { randomUUID } from "node:crypto";
|
|
import { betterAuth } from "better-auth";
|
|
import { createBaseAuthConfig } from "./src/lib/auth-config";
|
|
|
|
const CLI_DEV_BASE_URL = "http://localhost:3000";
|
|
const baseUrl = process.env.BETTER_AUTH_URL ?? CLI_DEV_BASE_URL;
|
|
|
|
export const auth = betterAuth({
|
|
baseURL: baseUrl,
|
|
secret: process.env.BETTER_AUTH_SECRET ?? randomUUID(),
|
|
...createBaseAuthConfig(baseUrl),
|
|
});
|