Skip to content

Instantly share code, notes, and snippets.


simonw/OAuth.js Secret

Created November 28, 2024 15:49
Show Gist options
  • Save simonw/4097d9f1901c498753ca82aa5b4aa174 to your computer and use it in GitHub Desktop.
Save simonw/4097d9f1901c498753ca82aa5b4aa174 to your computer and use it in GitHub Desktop.
export default {
async fetch(request, env) {
const url = new URL(request.url);
const clientId = env.GITHUB_CLIENT_ID;
const clientSecret = env.GITHUB_CLIENT_SECRET;
const redirectUri = url.origin;
// If we have a code, exchange it for an access token
if (url.searchParams.has('code')) {
const code = url.searchParams.get('code');
// Exchange the code for an access token
const tokenResponse = await fetch('', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Accept': 'application/json'
body: JSON.stringify({
client_id: clientId,
client_secret: clientSecret,
code: code,
redirect_uri: redirectUri
const tokenData = await tokenResponse.json();
// Return HTML that stores the token and closes the window
return new Response(`
<!DOCTYPE html>
<title>GitHub OAuth Success</title>
localStorage.setItem('github_token', '${tokenData.access_token}');
document.body.innerHTML = 'Authentication successful! You can close this window.';
`, {
headers: {
'Content-Type': 'text/html'
// If no code, redirect to GitHub OAuth
const githubAuthUrl = new URL('');
githubAuthUrl.searchParams.set('client_id', clientId);
githubAuthUrl.searchParams.set('redirect_uri', redirectUri);
githubAuthUrl.searchParams.set('scope', 'gist');
githubAuthUrl.searchParams.set('state', crypto.randomUUID());
return Response.redirect(githubAuthUrl.toString(), 302);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment