* feat: add personal access tokens * feat: replace MCP tokens with OAuth foundation * fix: keep OAuth constants private in auth foundation * fix: clean up mcp oauth branch scope * fix: expose oauth metadata endpoints * fix: trim mcp oauth config to non-default options Drop OIDC scopes, the org-id JWT claim, and the openid-configuration metadata endpoint since the MCP integration is OAuth-only and the org gets resolved server-side. Also remove options that just duplicated better-auth defaults. * fix: drop redundant oauth metadata helpers Remove `session.storeSessionInDatabase: true` since better-auth only enforces it when secondaryStorage is configured. Inline the `getHostedBaseUrlForOAuthMetadata` alias and skip the async `getOAuthServerConfig()` call in the protected-resource metadata handler — the issuer is just `baseURL` without a custom jwt.issuer override. * docs: explain cache headers on mcp metadata response * Use escaped file routes for OAuth metadata * save
32 lines
949 B
TypeScript
32 lines
949 B
TypeScript
import { oauthProviderAuthServerMetadata } from "@better-auth/oauth-provider";
|
|
import { createFileRoute } from "@tanstack/react-router";
|
|
import { env } from "cloudflare:workers";
|
|
import { getAuth, hasHostedAuthConfig } from "@/lib/auth";
|
|
import { isHostedAuthMode } from "@/lib/auth-mode";
|
|
|
|
function unavailableMetadataResponse() {
|
|
if (!isHostedAuthMode(env.AUTH_MODE)) {
|
|
return new Response("Not found", { status: 404 });
|
|
}
|
|
|
|
return new Response("Missing Better Auth hosted configuration", {
|
|
status: 500,
|
|
});
|
|
}
|
|
|
|
export const Route = createFileRoute("/.well-known/oauth-authorization-server")(
|
|
{
|
|
server: {
|
|
handlers: {
|
|
GET: async ({ request }: { request: Request }) => {
|
|
if (!isHostedAuthMode(env.AUTH_MODE) || !hasHostedAuthConfig()) {
|
|
return unavailableMetadataResponse();
|
|
}
|
|
|
|
return oauthProviderAuthServerMetadata(getAuth())(request);
|
|
},
|
|
},
|
|
},
|
|
},
|
|
);
|