Files
databasus--databasus/docs/how-extrnal-oauth-works.md
wehub-resource-sync 75f3dd141c
CodeQL / Analyze (go) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
CodeQL / Analyze (javascript-typescript) (push) Has been cancelled
CI and Release / lint-frontend (push) Has been cancelled
CI and Release / dockerfile-scan (push) Has been cancelled
CI and Release / test-frontend (push) Has been cancelled
CI and Release / lint-verification-agent (push) Has been cancelled
CI and Release / test-verification-agent (push) Has been cancelled
CI and Release / e2e-verification-agent (push) Has been cancelled
CI and Release / test-backend (push) Has been cancelled
CI and Release / build-dev-image (push) Has been cancelled
CI and Release / push-dev-image (push) Has been cancelled
CI and Release / build-image (push) Has been cancelled
CI and Release / build-verification-image (push) Has been cancelled
CI and Release / determine-version (push) Has been cancelled
CI and Release / push-image (push) Has been cancelled
CI and Release / push-verification-image (12) (push) Has been cancelled
CI and Release / lint-backend (push) Has been cancelled
CI and Release / push-verification-image (17) (push) Has been cancelled
CI and Release / push-verification-image (18) (push) Has been cancelled
CI and Release / release (push) Has been cancelled
CI and Release / publish-helm-chart (push) Has been cancelled
CI and Release / push-verification-image (13) (push) Has been cancelled
CI and Release / push-verification-image (14) (push) Has been cancelled
CI and Release / push-verification-image (15) (push) Has been cancelled
CI and Release / push-verification-image (16) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 13:11:07 +08:00

1.1 KiB

Cloud storages usually require OAuth (Google Drive, Dropbox, OneDrive)

OAuth services usually need HTTPS domain for authorization. Self hosted Databasus can be hosted via HTTP or even without static IP so this way does not work. To make OAuth works even on localhost, we proxy requests via databasus.com domain

As permanent URL for authorization we use main Databasus domain. It forward responses to the self hosted domain so it can get access to the cloud

This is the sequence of requests (example for Google Drive):

sequenceDiagram
    participant SelfHosted as http://localhost:4005<br/>Self-hosted Databasus
    participant Proxy as https://databasus.com<br/>Proxy website
    participant Google as Google OAuth

    SelfHosted->>Google: Send auth request with DTO

    Google->>Proxy: Redirect with auth code<br/>to databasus.com/oauth

    Proxy->>SelfHosted: Redirect to self-hosted instance<br/>with DTO + auth code

    SelfHosted->>Google: Exchange auth code for tokens<br/>POST /oauth2/token
    Google->>SelfHosted: Return access & refresh tokens

    SelfHosted->>SelfHosted: Store Google Drive config for files exchange