// Built-in Google provider (OAuth2 / OpenID Connect). Endpoints are hardcoded — // admins configure only Enabled + Client ID + Client Secret. Uses the OIDC // userinfo endpoint; `sub` is Google's stable per-user id. const OAuth2Provider = require('./oauth2.provider') class GoogleProvider extends OAuth2Provider { constructor(config = {}) { super({ kind: 'google', name: 'Google', ...config, id: config.id || 'google' }) } authEndpoint() { return 'https://accounts.google.com/o/oauth2/v2/auth' } tokenEndpoint() { return 'https://oauth2.googleapis.com/token' } userinfoEndpoint() { return 'https://openidconnect.googleapis.com/v1/userinfo' } scopeString() { return 'openid email profile' } authParams() { // Online access (no refresh token needed for login), and let the user pick // an account rather than silently reusing a signed-in one. return { access_type: 'online', prompt: 'select_account' } } normalizeProfile(p = {}) { return { subject: p.sub, email: p.email || null, // Google's OIDC userinfo carries the standard `email_verified` claim. Read // it rather than inferring verification from the mere presence of an // address, which is what this code used to do (ENGAGEMENT.md §0.6/1b). emailVerified: p.email_verified === true || p.email_verified === 'true', name: p.name || p.email || null, } } } module.exports = GoogleProvider