seahaven-ap/packages/api/openapi/paths/auth-callback.yaml

33 lines
836 B
YAML
Raw Permalink Normal View History

get:
tags:
- Session
summary: Complete hosted UI sign-in
description: Exchanges the authorization code, sets HttpOnly session cookies, and redirects to returnTo.
operationId: get-api-auth-callback
security: []
parameters:
- name: code
in: query
required: false
description: Authorization code from Cognito.
schema:
type: string
example: abcdef
- name: state
in: query
required: false
description: PKCE state echoed from login.
schema:
type: string
example: state-token
- name: error
in: query
required: false
description: Cognito error code when sign-in failed.
schema:
type: string
example: access_denied
responses:
"302":
description: Redirect to the SPA or the login error page.