How can we share OAuth token between backend and frontend

Viewed 341

I have SPA app, backend is ruby on rails and frontend is React. Now I am developing new authentication feature; login with GitHub account with omuniauth gem.

However after authorization with GitHub we need to redirect to backend server as that is the server which is sending authorization request to GitHub authentication server. That means my frontend cannot receive response from GitHub which contains auth information such as user name, token, etc.

I understand we can redirect to frontend URL through backend API, but even in that case I believe auth information from GitHub is not passed to frontend.

Is there any way to share the auth info from GitHub after oauth2 authorization? Any help would be really appreciated. Thank you so much in advance!

1 Answers

For your use case (which is implicit grant flow) I think that's not possible, common pattern to solve this is token handler pattern

Basically, after your backend receive callback from the github & exchange it with access token, you can issue a cookie or token (not oauth token) to the frontend. This cookie is associated with the github's access token.

Later, after you redirected back to the frontend, you need to request the github's user profile proxied via backend

If you want to be able to access github api directly from the frontend, consider using client credential flow (typically used for SPA, without backend)

Related