{"_id":"@0-auth/zero-auth-idp-mongodb","_rev":"2-e2c9181dd1c94f5955f5dfca852ccaa5","name":"@0-auth/zero-auth-idp-mongodb","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@0-auth/zero-auth-idp-mongodb","version":"0.1.0","keywords":["oauth","oauth2","authorization-server","mongodb","storage"],"author":{"name":"Darshan Kinge"},"license":"MIT","_id":"@0-auth/zero-auth-idp-mongodb@0.1.0","maintainers":[{"name":"wtfdrshn","email":"itsmedarshan8@gmail.com"}],"homepage":"https://zero-auth.netlify.app/","bugs":{"url":"https://github.com/0-auth/zero-auth/issues"},"dist":{"shasum":"7df803b7cae6009be8350809629ac99dc21277d3","tarball":"https://registry.npmjs.org/@0-auth/zero-auth-idp-mongodb/-/zero-auth-idp-mongodb-0.1.0.tgz","fileCount":10,"integrity":"sha512-5w3aCmbocrSARwlrcx8EtswqAVHUhqvDe5WS2rYYgFqeeSJzaeWc1rtFHH/udUohhNdWu9+BM+RmWZws6gxSvA==","signatures":[{"sig":"MEUCIAKZZHVpL/29mGQ6kC+0UWThx6hUeKmlMUd/YM9V0Jf/AiEA5MjJNyWf9fBTB0C7KepbiqOCdpr0z3COQzzRRbw7zTo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@0-auth%2fzero-auth-idp-mongodb@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":37145},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.mjs","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.ts","default":"./dist/index.js"}}},"gitHead":"50f5a31b8c058f977265979f58f294e681be424e","scripts":{"lint":"eslint src tests","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","test:coverage":"vitest run --coverage","prepublishOnly":"npm run lint && npm run typecheck && npm run test && npm run build","test:integration":"vitest run tests/mongodb.integration.test.ts"},"_npmUser":{"name":"wtfdrshn","email":"itsmedarshan8@gmail.com"},"repository":{"url":"git+https://github.com/0-auth/zero-auth.git","type":"git","directory":"packages/zero-auth-idp-mongodb"},"_npmVersion":"10.8.2","description":"MongoDB storage adapter for @0-auth/zero-auth-idp","directories":{},"sideEffects":false,"_nodeVersion":"20.20.2","_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","eslint":"^9.0.0","vitest":"^2.0.0","mongodb":"^6.20.0","prettier":"^3.3.3","typescript":"^5.6.0","@types/node":"^22.0.0","@vitest/coverage-v8":"^2.0.0","@0-auth/zero-auth-idp":"0.1.0","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^8.0.0","@typescript-eslint/eslint-plugin":"^8.0.0"},"peerDependencies":{"mongodb":"^6.20.0","@0-auth/zero-auth-idp":"^0.1.0"},"_npmOperationalInternal":{"tmp":"tmp/zero-auth-idp-mongodb_0.1.0_1788630675111_0.6376732341637403","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@0-auth/zero-auth-idp-mongodb","version":"0.2.0","description":"MongoDB storage adapter for @0-auth/zero-auth-idp","author":{"name":"Darshan Kinge"},"license":"MIT","keywords":["oauth","oauth2","authorization-server","mongodb","storage"],"homepage":"https://zero-auth.netlify.app/","repository":{"type":"git","url":"git+https://github.com/0-auth/zero-auth.git","directory":"packages/zero-auth-idp-mongodb"},"bugs":{"url":"https://github.com/0-auth/zero-auth/issues"},"main":"./dist/index.js","module":"./dist/index.mjs","types":"./dist/index.d.ts","exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.ts","default":"./dist/index.js"}}},"scripts":{"build":"tsup","test":"vitest run","test:integration":"vitest run tests/mongodb.integration.test.ts","test:coverage":"vitest run --coverage","lint":"eslint src tests","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","typecheck":"tsc --noEmit","prepublishOnly":"npm run lint && npm run typecheck && npm run test && npm run build"},"peerDependencies":{"@0-auth/zero-auth-idp":"^0.2.0","mongodb":"^6.20.0"},"devDependencies":{"@0-auth/zero-auth-idp":"0.2.0","@types/node":"^22.0.0","@typescript-eslint/eslint-plugin":"^8.0.0","@typescript-eslint/parser":"^8.0.0","@vitest/coverage-v8":"^2.0.0","eslint":"^9.0.0","eslint-config-prettier":"^9.1.0","mongodb":"^6.20.0","prettier":"^3.3.3","tsup":"^8.3.0","typescript":"^5.6.0","vitest":"^2.0.0"},"engines":{"node":">=18.0.0"},"sideEffects":false,"_id":"@0-auth/zero-auth-idp-mongodb@0.2.0","gitHead":"e1453bac578e6eefeb6b7f4685e0aa9540ab9d71","_nodeVersion":"22.18.0","_npmVersion":"10.2.5","dist":{"integrity":"sha512-4+RPUuNHuM0u4O8wTXEz34b0X3dwZhCxfbkTsExgU8cZVl4cAe0yOVRKx3Xh9YknKZXKsmojN9piCUToMlYl2Q==","shasum":"ffb0a6e13c4e35400da72f8803ae8531c48cd149","tarball":"https://registry.npmjs.org/@0-auth/zero-auth-idp-mongodb/-/zero-auth-idp-mongodb-0.2.0.tgz","fileCount":10,"unpackedSize":37250,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCICcUDH2dUi+lo/97gbDkS1XyZAVfUHwh34CWVPVKeLgIhAJYb7eIBWUEoIt6uW7q4tISnkI9VzqK7lml/Vh33v1aO"}]},"_npmUser":{"name":"wtfdrshn","email":"itsmedarshan8@gmail.com"},"directories":{},"maintainers":[{"name":"wtfdrshn","email":"itsmedarshan8@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/zero-auth-idp-mongodb_0.2.0_1788892737870_0.9028860917607293"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-05T17:51:14.930Z","modified":"2026-09-08T18:38:58.176Z","0.1.0":"2026-09-05T17:51:15.251Z","0.2.0":"2026-09-08T18:38:57.985Z"},"bugs":{"url":"https://github.com/0-auth/zero-auth/issues"},"author":{"name":"Darshan Kinge"},"license":"MIT","homepage":"https://zero-auth.netlify.app/","keywords":["oauth","oauth2","authorization-server","mongodb","storage"],"repository":{"type":"git","url":"git+https://github.com/0-auth/zero-auth.git","directory":"packages/zero-auth-idp-mongodb"},"description":"MongoDB storage adapter for @0-auth/zero-auth-idp","maintainers":[{"name":"wtfdrshn","email":"itsmedarshan8@gmail.com"}],"readme":"# @0-auth/zero-auth-idp-mongodb\n\n> [!NOTE]\n> This package only provides storage for `@0-auth/zero-auth-idp`. It does not\n> create users, hash passwords, or expose a MongoDB user model.\n> Migration from the unreleased scaffold: `expiresAt` is stored as a BSON date.\n> Convert earlier numeric records before reusing that development data. No\n> automatic database migration runs on startup.\n\nMongoDB storage for the self-hosted OAuth authorization server. The core IdP\npackage stays database-independent; this adapter persists sessions, temporary\nOAuth transactions, authorization codes, and access tokens.\n\n## Install\n\n```bash\nnpm install @0-auth/zero-auth-idp @0-auth/zero-auth-idp-mongodb mongodb@6\n```\n\n## Usage\n\n```ts\nimport express from \"express\";\nimport { MongoClient } from \"mongodb\";\nimport { createIdentityProvider } from \"@0-auth/zero-auth-idp\";\nimport { createMongoOAuthStorage } from \"@0-auth/zero-auth-idp-mongodb\";\nimport { authenticateUser } from \"./users.js\"; // Your application's password verification.\n\nconst client = new MongoClient(process.env.MONGODB_URI!);\nawait client.connect();\n\nconst storage = createMongoOAuthStorage(client.db(\"my-app\"));\nawait storage.ensureIndexes();\n\nconst idp = createIdentityProvider({\n  issuer: \"https://example.com/auth\",\n  storage,\n  clients: [\n    {\n      clientId: \"my-app\",\n      clientType: \"public\",\n      redirectUris: [\"https://example.com/callback\"],\n      allowedScopes: [\"profile\"],\n    },\n  ],\n  authenticateUser,\n});\n\nconst app = express();\napp.use(\"/auth\", idp.router());\napp.listen(3000);\n```\n\nThe application-provided `authenticateUser({ email, password })` must verify a\npassword hash and return `{ id, email }`, or `null` for invalid credentials.\nThe runnable example below includes a complete implementation.\n\n## Collections\n\nThe adapter creates four collections using the `zero_auth_idp_` prefix:\n\n- `zero_auth_idp_sessions`\n- `zero_auth_idp_transactions`\n- `zero_auth_idp_authorization_codes`\n- `zero_auth_idp_access_tokens`\n\nPass `{ collectionPrefix: \"my_prefix\" }` to change the prefix. Call\n`ensureIndexes()` during application startup. Each collection receives a TTL\nindex on `expiresAt`. The adapter writes this field as a BSON date and converts it\nback to milliseconds on reads, preserving the core package's storage interface.\nMongoDB cleanup is asynchronous; session, transaction, and code queries reject\nexpired records immediately. The core checks access-token expiration.\n\nThe earlier unreleased scaffold stored numeric dates, which MongoDB TTL indexes\ncannot clean. Existing development records from that scaffold need their\n`expiresAt` converted to BSON dates before using this adapter; no automatic\ndatabase migration runs on startup.\n\nSee the [runnable MongoDB example](https://github.com/0-auth/zero-auth/tree/master/examples/express-idp) for Docker\nCompose, hashed user authentication, a complete PKCE client, and restart testing.\n\n## Integration tests\n\nSet `MONGODB_URI` to a disposable/test MongoDB instance and run\n`npm run test:integration --workspace @0-auth/zero-auth-idp-mongodb` from the\nrepository root. Tests use a uniquely named database and delete it afterward.\nThey verify actual TTL deletion in all four collections, numeric API round trips,\nconcurrent code consumption, and revocation across connections. The TTL test waits\nup to 90 seconds for background cleanup. Without `MONGODB_URI`, regular unit tests\nskip integration.\n\n## Security behavior\n\n- Session, authorization-code, and access-token values are stored by their\n  hashes supplied by the core package.\n- Authorization-code consumption uses MongoDB `findOneAndDelete`, so only one\n  concurrent token exchange can consume a valid code.\n- Client, redirect URI, PKCE, scope, and user validation remain in the core\n  IdP package.\n- The adapter does not store passwords or application business data.\n\nThe adapter requires MongoDB driver 6.x so it remains compatible with Node.js 18. Use a database with appropriate TLS, authentication, backups, and network\naccess controls in production.\n\n## License\n\n[MIT](./LICENSE)\n","readmeFilename":"README.md"}