I am trying to properly implement an authentication with next.js/next-auth.js. Following the documentation I implemented the Providers authentication. The code below calls my api (in php), the api returns a token and the token is stored in a httpOnly cookie.
import NextAuth from "next-auth"
import Providers from "next-auth/providers";
const https = require('https');
export default NextAuth({
providers: [
Providers.Credentials({
name: 'Credentials',
credentials: {
email: { label: "Email", type: "email" },
password: { label: "Password", type: "password" }
},
async authorize(credentials) {
const url = process.env.NEXT_PUBLIC_API_PLATFORM_BASE_URL + '/auth';
const httpsAgent = new https.Agent({
rejectUnauthorized: false,
});
const response = await fetch(url, {
method: 'POST',
body: JSON.stringify(credentials),
agent: httpsAgent,
headers: {
"Content-Type": "application/json"
}
})
const user = await response.json();
if (response.ok && user) {
return user;
} else {
return null;
}
}
}),
// ...add more providers here
],
callbacks: {
async jwt(token, user, account, profile, isNewUser) {
if (user?.token) {
token = { accessToken: user.token };
}
return token;
},
async session(session, token) {
session.accessToken = token.accessToken;
return session;
}
}
})
I'd need to know how to retrieve the jwt token in the httpOnly cookie for future calls (tipically passing it to the api like Bearer <MYTOKEN>, using fetch), but I know JS does not have access to httpOnly cookies. In that case what is the best way to proceed?