@iron3io/sso
v0.1.0
Published
Client for the iron3 SSO hub: gate a Next.js app behind Google sign-in restricted to one email domain, with no database.
Readme
@iron3io/sso
Gate a Next.js app behind Google sign-in restricted to one email domain, with no database. The client half of iron3-sso; a deployed hub does the talking to Google.
pnpm add @iron3io/ssoFour exports, deliberately:
| Export | What it does |
|---|---|
| ssoProxy(config) | edge proxy that bounces signed-out browsers to the hub |
| createCallbackRoute(config) | route handler that turns a grant into a session cookie |
| getSessionUser(config) | verified session, or null — call it in every route |
| <SignInRedirect /> | an unstyled link into the hub's authorize endpoint |
import { ssoProxy, createCallbackRoute, getSessionUser, type SsoConfig } from "@iron3io/sso"
export const config: SsoConfig = {
hubUrl: process.env.SSO_HUB_URL!,
appId: "your-app-id",
appSecret: process.env.SSO_APP_SECRET!,
}getSessionUser is the security boundary, not the proxy. The proxy only checks that
a cookie is present, so every route and server component must handle null itself.
Sessions are stateless signed cookies with a 12-hour lifetime. There is no server-side session store, so sign-out is per-app and revocation takes effect at next sign-in — rotating an app's secret invalidates every session for that app at once.
See the repo README for the full adoption guide and how apps are registered with the hub.
