// Invisible host for the OAuth client during sign-in. BrowserOAuthClient // needs window/localStorage, which the MV3 worker lacks, so the worker opens // this document and asks it to build the authorization URL and, later, to // exchange the callback redirect for a session (see src/signin.ts). import { completeAuthorization, revokeSession, startAuthorization } from '../lib/oauth' import type { OffscreenMsg } from '../lib/types' chrome.runtime.onMessage.addListener( (msg: OffscreenMsg | { target?: undefined }, _sender, sendResponse) => { if (msg.target !== 'offscreen') return false dispatch(msg) .then(sendResponse) .catch((err: unknown) => { sendResponse({ __error: err instanceof Error ? err.message : String(err) }) }) return true }, ) async function dispatch(msg: OffscreenMsg): Promise { switch (msg.type) { case 'oauth-authorize': return startAuthorization(msg.handle) case 'oauth-callback': return completeAuthorization(msg.url) case 'oauth-revoke': return revokeSession(msg.sub) } }