feat(auth): sync OAuth provider tokens to backend via NextAuth session
Wire the Google/Facebook OAuth callback flow end-to-end so the provider's id_token (Google) and access_token (Facebook) captured by NextAuth are forwarded to the backend in exchange for business tokens: - Extend the NextAuth config with jwt/session callbacks that surface `account.id_token` / `account.access_token` to the client during first sign-in - Add an `OAuthSessionSync` bridge mounted inside `RootProviders` that listens to `useSession()` and dispatches new `AuthGoogleSyncSubmitted` / `AuthFacebookSyncSubmitted` events - Add corresponding actors in the auth XState machine that call `authRepository.googleLogin` / `facebookLogin`, persisting the backend's `LoginResponse` through the existing repository path This keeps all authentication orchestrated by the auth state machine while preserving NextAuth's OAuth redirect UX.
This commit is contained in:
@@ -25,4 +25,8 @@ export type AuthEvent =
|
||||
// 社交登录 —— 状态机内部调 next-auth/react 的 signIn(provider)
|
||||
| { type: "AuthGoogleLoginSubmitted"; provider: AuthProvider }
|
||||
| { type: "AuthFacebookLoginSubmitted"; provider: AuthProvider }
|
||||
| { type: "AuthAppleLoginSubmitted" };
|
||||
| { type: "AuthAppleLoginSubmitted" }
|
||||
// OAuth 回调后:把 OAuth provider token 转交后端换业务 token
|
||||
// 由 <OAuthSessionSync /> 监听 useSession() 派发
|
||||
| { type: "AuthGoogleSyncSubmitted"; idToken: string }
|
||||
| { type: "AuthFacebookSyncSubmitted"; accessToken: string };
|
||||
|
||||
Reference in New Issue
Block a user