MCPcopy Create free account
hub / github.com/UsefulSoftwareCo/executor / buildAuthorizationUrl

Function buildAuthorizationUrl

packages/core/sdk/src/oauth-helpers.ts:219–249  ·  view source on GitHub ↗
(input: BuildAuthorizationUrlInput)

Source from the content-addressed store, hash-verified

217/** Build an RFC 6749 §4.1.1 authorization URL. Sync; pre-computed
218 * challenge lets this stay out of the Promise world. */
219export const buildAuthorizationUrl = (input: BuildAuthorizationUrlInput): string => {
220 const url = new URL(
221 assertSupportedOAuthEndpointUrl(
222 input.authorizationUrl,
223 "Authorization URL",
224 input.endpointUrlPolicy,
225 ),
226 );
227 // Benign default kept by design: a single space is the RFC 6749 scope
228 // separator. Callers targeting a legacy comma-separated provider pass
229 // `scopeSeparator` explicitly (see the field's JSDoc).
230 const separator = input.scopeSeparator ?? " ";
231 url.searchParams.set("client_id", input.clientId);
232 url.searchParams.set("redirect_uri", input.redirectUrl);
233 url.searchParams.set("response_type", "code");
234 if (input.scopes.length > 0) {
235 url.searchParams.set("scope", input.scopes.join(separator));
236 }
237 url.searchParams.set("state", input.state);
238 url.searchParams.set("code_challenge_method", "S256");
239 url.searchParams.set("code_challenge", input.codeChallenge);
240 if (input.resource) {
241 url.searchParams.set("resource", input.resource);
242 }
243 if (input.extraParams) {
244 for (const [k, v] of Object.entries(input.extraParams)) {
245 url.searchParams.set(k, v);
246 }
247 }
248 return url.toString();
249};
250
251/** Provider-specific authorize-URL extras that are NOT RFC 6749 params, so the
252 * generic flow must add them per-provider (keyed off the authorization host).

Callers 3

startFunction · 0.90

Calls 3

toStringMethod · 0.80
setMethod · 0.65

Tested by

no test coverage detected