{"_id":"@4pp-io/verdaccio-entra","_rev":"2-4cdbe399b409cbafa353b90ae0c5f9c2","name":"@4pp-io/verdaccio-entra","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@4pp-io/verdaccio-entra","version":"0.1.0","keywords":["verdaccio","verdaccio-plugin","verdaccio-auth","verdaccio-auth-plugin","plugin","auth","authentication","entra","entra-id","microsoft-entra","azure-ad","azure","active-directory","oidc","oauth","npm","registry","enterprise","sso"],"author":{"name":"primeinc","email":"vincit.omnia.veritas@lellirose.com"},"license":"MIT","_id":"@4pp-io/verdaccio-entra@0.1.0","maintainers":[{"name":"primeinc","email":"will.peters@gmail.com"}],"homepage":"https://github.com/4pp-io/verdaccio-entra#readme","bugs":{"url":"https://github.com/4pp-io/verdaccio-entra/issues"},"dist":{"shasum":"290fef592ae868d2925e0a1030040965be96a5d8","tarball":"https://registry.npmjs.org/@4pp-io/verdaccio-entra/-/verdaccio-entra-0.1.0.tgz","fileCount":38,"integrity":"sha512-vnD7ARjqi9AGuKk8JbydAS3L1peePXvFOPz19cjtZbUK7S8mRseMrqKZMM6OFJZguSTAP3ZiEYyiGmOSmgkKbA==","signatures":[{"sig":"MEYCIQCiGQFTHumQaCVgt1KIB7+0Qa2FyvK8Guu74McRJGw/IwIhAP5sWJBh6W23H63bGWAAs+1GG5Ge2/9GKWKk05tr/Fv5","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":242855},"main":"lib/src/index.js","types":"lib/src/index.d.ts","engines":{"node":">=22"},"gitHead":"53f256442f57e798c079589211c05c3cb459b233","scripts":{"lint":"eslint --max-warnings=0 --no-inline-config src/ types/","test":"vitest run --exclude src/__tests__/e2e.test.ts","build":"tsc","release":"npm run build && changeset publish --provenance","test:e2e":"vitest run src/__tests__/e2e.test.ts","changeset":"changeset","test:watch":"vitest","check-config":"tsx scripts/check-config.ts","test:coverage":"vitest run --coverage","test:e2e:debug":"cross-env DEBUG='testcontainers*' vitest run src/__tests__/e2e.test.ts","version-packages":"changeset version && npm install"},"_npmUser":{"name":"primeinc","email":"will.peters@gmail.com"},"repository":{"url":"git+https://github.com/4pp-io/verdaccio-entra.git","type":"git"},"_npmVersion":"10.9.4","description":"Microsoft Entra ID (Azure AD) auth plugin for Verdaccio — validates access tokens via JWKS","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.2.1","debug":"4.4.3","@verdaccio/core":"6.0.0-6-next.76"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","eslint":"^10.0.0","vitest":"^3.2.1","cross-env":"^10.1.0","typescript":"5.9.3","@types/node":"^22.19.15","@types/debug":"4.1.12","@types/express":"4.17.25","testcontainers":"^11.12.0","@changesets/cli":"^2.30.0","@verdaccio/auth":"6.0.0-6-next.55","@verdaccio/types":"11.0.0-6-next.25","typescript-eslint":"^8.57.0","@vitest/coverage-v8":"^3.2.1","@changesets/changelog-github":"^0.6.0"},"_npmOperationalInternal":{"tmp":"tmp/verdaccio-entra_0.1.0_1773719403093_0.08450866239262123","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@4pp-io/verdaccio-entra","version":"0.2.0","description":"Microsoft Entra ID (Azure AD) auth plugin for Verdaccio — validates access tokens via JWKS","main":"lib/src/index.js","types":"lib/src/index.d.ts","bin":{"verdaccio-entra-check":"lib/src/cli.js"},"engines":{"node":">=22"},"dependencies":{"@verdaccio/core":"6.0.0-6-next.76","debug":"4.4.3","jose":"^6.2.1","valibot":"^1.3.0"},"devDependencies":{"@changesets/changelog-github":"^0.6.0","@changesets/cli":"^2.30.0","@types/debug":"4.1.12","@types/node":"^22.19.15","@verdaccio/types":"11.0.0-6-next.25","@vitest/coverage-v8":"^4.1.0","cross-env":"^10.1.0","eslint":"^10.0.0","eslint-config-prettier":"10.1.8","prettier":"3.8.1","testcontainers":"^11.12.0","typescript":"5.9.3","typescript-eslint":"^8.57.0","vitest":"^4.1.0"},"keywords":["verdaccio","verdaccio-plugin","verdaccio-auth","verdaccio-auth-plugin","plugin","auth","authentication","entra","entra-id","microsoft-entra","azure-ad","azure","active-directory","oidc","oauth","npm","registry","enterprise","sso"],"license":"MIT","repository":{"type":"git","url":"git+https://github.com/4pp-io/verdaccio-entra.git"},"publishConfig":{"access":"public"},"author":{"name":"primeinc","email":"vincit.omnia.veritas@lellirose.com"},"scripts":{"build":"tsc","prepublishOnly":"npm run build","lint":"eslint --max-warnings=0 --no-inline-config src/ types/","test":"vitest run --exclude src/__tests__/e2e.test.ts","test:e2e":"vitest run src/__tests__/e2e.test.ts","test:e2e:debug":"cross-env DEBUG='testcontainers*' vitest run src/__tests__/e2e.test.ts","test:coverage":"vitest run --coverage --exclude src/__tests__/e2e.test.ts","test:watch":"vitest","format":"prettier --write .","format:check":"prettier --check .","check-config":"npm run build && node lib/src/cli.js","changeset":"changeset","version-packages":"changeset version && npm install && npm run format","release":"npm run build && changeset publish --provenance"},"gitHead":"a85019aa1d9a751250d7fbba90bbd96f3d698cd2","_id":"@4pp-io/verdaccio-entra@0.2.0","bugs":{"url":"https://github.com/4pp-io/verdaccio-entra/issues"},"homepage":"https://github.com/4pp-io/verdaccio-entra#readme","_nodeVersion":"24.14.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-c+yimQQdlAod504Veoo2+49LjmAn8oBY8kqlvoSvEfHyC4hbxPzB93DXGhcN4keKAtkMkUgkJqmWcywY0r+2hg==","shasum":"dc5163bafa5ccf2993ed0465c00ff1466685fe72","tarball":"https://registry.npmjs.org/@4pp-io/verdaccio-entra/-/verdaccio-entra-0.2.0.tgz","fileCount":15,"unpackedSize":49194,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@4pp-io%2fverdaccio-entra@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCGrIWHUyO+2s6hHFi+fUqJJlYRxNPygQMCG8INqLvEoQIhAOMDD1OmjA90kqA0p8HTHsUodi8y829a03V8dysenJ4g"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:692da868-bc1e-40c7-b6c9-90c17940c388"}},"directories":{},"maintainers":[{"name":"primeinc","email":"will.peters@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/verdaccio-entra_0.2.0_1773756368890_0.5176745223934933"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-17T03:50:03.021Z","modified":"2026-03-17T14:06:09.393Z","0.1.0":"2026-03-17T03:50:03.280Z","0.2.0":"2026-03-17T14:06:09.051Z"},"bugs":{"url":"https://github.com/4pp-io/verdaccio-entra/issues"},"author":{"name":"primeinc","email":"vincit.omnia.veritas@lellirose.com"},"license":"MIT","homepage":"https://github.com/4pp-io/verdaccio-entra#readme","keywords":["verdaccio","verdaccio-plugin","verdaccio-auth","verdaccio-auth-plugin","plugin","auth","authentication","entra","entra-id","microsoft-entra","azure-ad","azure","active-directory","oidc","oauth","npm","registry","enterprise","sso"],"repository":{"type":"git","url":"git+https://github.com/4pp-io/verdaccio-entra.git"},"description":"Microsoft Entra ID (Azure AD) auth plugin for Verdaccio — validates access tokens via JWKS","maintainers":[{"name":"primeinc","email":"will.peters@gmail.com"}],"readme":"# verdaccio-entra\n\nMicrosoft Entra ID (Azure AD) auth plugin for [Verdaccio](https://verdaccio.org/) — validates access tokens via JWKS.\n\n## Features\n\n- Validates Entra ID access tokens (RS256) with automatic JWKS key caching and rotation via [jose](https://github.com/panva/jose)\n- Sovereign cloud support (US Government, China) via configurable `authority`\n- Username enforcement — npm login username must match Entra identity\n- Group and role-based access control from JWT claims\n- Environment variable override for all config values\n- Pre-flight config validation CLI: `npx verdaccio-entra-check --client-id <guid> --tenant-id <guid>`\n\n## Install\n\n```bash\nnpm install verdaccio-entra\n```\n\nRequires Node.js >= 22 and Verdaccio 6.x.\n\n## Configuration\n\nAdd to your Verdaccio `config.yaml`:\n\n```yaml\nauth:\n  entra:\n    clientId: \"your-client-id\" # or ENTRA_CLIENT_ID env var\n    tenantId: \"your-tenant-id\" # or ENTRA_TENANT_ID env var\n```\n\n### Environment Variables\n\nAll config values can be overridden via environment variables (takes precedence over config.yaml):\n\n| Env Variable                    | Config Key              | Default                             | Description                     |\n| ------------------------------- | ----------------------- | ----------------------------------- | ------------------------------- |\n| `ENTRA_CLIENT_ID`               | `clientId`              | —                                   | Application (client) ID         |\n| `ENTRA_TENANT_ID`               | `tenantId`              | —                                   | Directory (tenant) ID           |\n| `ENTRA_AUDIENCE`                | `audience`              | `api://{clientId}`                  | Expected token audience         |\n| `ENTRA_AUTHORITY`               | `authority`             | `https://login.microsoftonline.com` | Entra authority URL             |\n| `ENTRA_FAIL_CLOSED`             | `failClosed`            | `false`                             | Kill process on config error    |\n| `ENTRA_ALLOW_GROUP_OVERAGE`     | `allowGroupOverage`     | `false`                             | Allow auth when >200 groups     |\n| `ENTRA_MAX_TOKEN_BYTES`         | `maxTokenBytes`         | `256000`                            | Max token size before rejecting |\n| `ENTRA_CLOCK_TOLERANCE_SECONDS` | `clockToleranceSeconds` | `300`                               | Clock skew tolerance (seconds)  |\n\nSet `NODE_USE_ENV_PROXY=1` to enable `HTTPS_PROXY` support for JWKS fetching. See [Node.js proxy docs](https://nodejs.org/en/learn/http/enterprise-network-configuration).\n\n## Docker\n\n```bash\ndocker build -t verdaccio-entra .\ndocker run -p 4873:4873 \\\n  -e ENTRA_CLIENT_ID=your-client-id \\\n  -e ENTRA_TENANT_ID=your-tenant-id \\\n  verdaccio-entra\n```\n\n## Client Setup\n\nFor the easiest client-side setup, use [`@4pp-io/r`](https://www.npmjs.com/package/@4pp-io/r):\n\n```bash\nnpx @4pp-io/r\n```\n\nThis auto-detects your package manager, configures scoped registries, and authenticates via Windows SSO (WAM) or browser.\n\n## Security\n\nSee [docs/SECURITY.md](docs/SECURITY.md) for security considerations, including fail-closed mode, username mutability, and group overage handling.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}