Skip to content

Repository files navigation

React Router Auth Starter

React Router full-stack authentication starter for Tuurio ID with protected routes and standards-based OpenID Connect.

Verify template

React Router Auth Starter social preview

Generated from Tuurio/auth_samples/auth_samples_react_router. Submit implementation fixes upstream so they are not replaced by the next synchronized release.

What you get

  • Standards-based OpenID Connect authentication with framework-native integration.
  • Exact redirect and post-logout redirect handling.
  • Protected-route and logout examples.
  • A reviewed, pinned Tuurio provisioning workflow.

Quickstart

  1. Create a repository with Use this template or clone this repository.
  2. Follow the framework-specific prerequisites below.
  3. Review and run this pinned provisioning command:
npx manage-tuurio-id@1.1.6 init --framework react-router --project-dir . --auth browser --yes --output json --campaign github_react_router --no-open --no-wait
  1. Approve the exact command, then complete the secure browser handoff yourself.
  2. Run the build and verify one real sign-in and sign-out.

Never paste credentials, client secrets, authorization codes, tokens, session cookies, or environment-file contents into an agent chat. Browser and native applications are public clients and must not contain a client secret.

Runtime and verification

  • Runtime: Node.js 24.11+
  • Package manager: npm
  • Verification: npm ci && npm run typecheck && npm run build

Security model

This starter uses OpenID Connect Authorization Code flow. Browser and native clients use PKCE S256 and contain no client secret. Redirect and post-logout redirect URIs must match exactly. Identity comes from the established OIDC integration or an authenticated UserInfo request; decoded JWT payloads are never treated as validation. Keep generated local environment files ignored and never commit tokens or credentials.

Framework instructions

React Router full-stack OIDC authentication with Tuurio ID

Runnable React Router + Vite + Express starter with one application origin, Authorization Code + PKCE S256, validated ID tokens, UserInfo subject binding, opaque server-side sessions, a protected API/route, and RP-initiated logout.

npx manage-tuurio-id@1.1.6 init --framework react-router --project-dir . --auth browser --yes --output json --campaign github_react_router --no-open --no-wait
npm install
npm run dev

The in-memory transaction/session stores are intentionally simple. Replace them with a shared server-side store before horizontal scaling. Never expose TUURIO_CLIENT_SECRET or tokens to the React bundle.

License

Licensed under the Apache License, Version 2.0. See LICENSE.

About

React Router full-stack authentication starter for Tuurio ID with protected routes and standards-based OpenID Connect.

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages