{"_id":"@667/express-jwt-authz","_rev":"2-748dd7f9fa4cc5bb0b268b22d576d03e","name":"@667/express-jwt-authz","dist-tags":{"latest":"2.4.1-1"},"versions":{"2.4.1-0":{"name":"@667/express-jwt-authz","version":"2.4.1-0","description":"Validate a JWTs scope to authorize access to an endpoint","main":"lib/index.js","types":"lib/index.d.ts","scripts":{"test":"mocha"},"repository":{"type":"git","url":"git+https://github.com/auth0/express-jwt-authz.git"},"keywords":["express","jwt","authorization"],"author":{"name":"Damian Schenkelman"},"license":"MIT","bugs":{"url":"https://github.com/auth0/express-jwt-authz/issues"},"homepage":"https://github.com/auth0/express-jwt-authz#readme","devDependencies":{"chai":"^4.2.0","husky":"^1.1.4","mocha":"^5.2.0","prettier":"^1.14.3","pretty-quick":"^1.8.0"},"husky":{"hooks":{"pre-commit":"pretty-quick --staged"}},"engines":{"node":">=6"},"peerDependencies":{"express":"^4.0.0","@types/express":"^4.0.0"},"gitHead":"4591867995181a4568fb38f9c4b00c658116a815","_id":"@667/express-jwt-authz@2.4.1-0","_nodeVersion":"14.15.4","_npmVersion":"7.5.4","dist":{"integrity":"sha512-vBwwZO2JUE2DioNe2I96zGcqAcoJNyKOOf9mbNOPn0MbgM1r+ZZlS1i0YA6KoBQRDK/ZaZqfZDDiCg4MyGijgw==","shasum":"f81c32bfb399359c337fd5d7026cfd05848240fe","tarball":"https://registry.npmjs.org/@667/express-jwt-authz/-/express-jwt-authz-2.4.1-0.tgz","fileCount":6,"unpackedSize":8034,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgUnoCCRA9TVsSAnZWagAARngQAJOnvSNZL4svKsFc8k79\nyLDr8HHzWTR77rotKVao+WKpZXEnRJaCNAoUGh7OzfxraNgDKxh9FQlbCJhg\n+EYJQfglV2g7BvbXG6wjzJo/7CNZ3e9PuASFW8dBDYGrwQ3zLN2hAMV2VUMR\nJxBg4j2VW7Piw4Vh3gfP9Nn6F+Raq4HkTY36ti6mQ2URitu866VVU+XEB+fQ\nQc65dq+SfyoXgLL/Cz86hw7tc3Zaf5XNCOccy7HcJKgeSF2NW9pQxzWOpXxw\ngWhIWDk3OohCxM4RttpdPN3yZXvSlZlpBArrsaF4wCCn9H8xkkj4qbyaOYQk\nOw+r88tc6aYcDOCrl7VqxYaq0Jfll1j5e9IVSQF6yaTXKf985ZRG2r9hMXE0\nMgCV2aPjxbGvy8BRexUmLPqMWF+oW7xW8tFFJuqAcisor+ntsXO6YJaNQCoQ\nEhWkn6S+OKlsw72IP1F/VLj82AGKqu43yGhs6oczZrHD+rWTUUtRH5sUM4A8\nJv+EWj7A0PMiLu+ye1TkmmZ/iQBzGo1f4C0w6yvAf8zuOb6qZ9vxYIu6LNk8\nVS/8sRShQ2YbXwE97+mCAkWi8ZcbFWsmqvyeVZePXTt9W57r9+xkWYzokpoQ\nY8j8XpMUvcVDariB3cSVkklpKc/J7Nl+h59rB2g7ErR1HN5Y3qnfZjQp/Egv\nmpaD\r\n=qjQl\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHufCQqnXpgJh97xWMK9Y4Fjqv44eNuIc5tmIXgChylvAiAPOoPOyDWzHOGnqRvl96o3T8qh3UxpqiPclD9sywTWNA=="}]},"_npmUser":{"name":"667","email":"667@june07.com"},"directories":{},"maintainers":[{"name":"667","email":"667@june07.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/express-jwt-authz_2.4.1-0_1616017921892_0.40201524154993007"},"_hasShrinkwrap":false},"2.4.1-1":{"name":"@667/express-jwt-authz","version":"2.4.1-1","description":"Validate a JWTs scope to authorize access to an endpoint","main":"lib/index.js","types":"lib/index.d.ts","scripts":{"test":"mocha"},"repository":{"type":"git","url":"git+https://github.com/june07/express-jwt-authz.git"},"keywords":["express","restify","jwt","authorization"],"author":{"name":"June07"},"license":"MIT","bugs":{"url":"https://github.com/june07/express-jwt-authz/issues"},"homepage":"https://github.com/june07/express-jwt-authz#readme","devDependencies":{"chai":"^4.2.0","husky":"^1.1.4","mocha":"^8.3.2","prettier":"^1.14.3","pretty-quick":"^1.8.0"},"husky":{"hooks":{"pre-commit":"pretty-quick --staged"}},"engines":{"node":">=6"},"peerDependencies":{"express":"^4.0.0","@types/express":"^4.0.0","restify":"^8.5.1"},"gitHead":"6352a92c3f63549b5867367baee0edd3d379e609","_id":"@667/express-jwt-authz@2.4.1-1","_nodeVersion":"12.21.0","_npmVersion":"6.14.11","dist":{"integrity":"sha512-0NNzoyMCSMVRd/lrz9Su4DsyV+1Ut1yiJcsXRvaa0C0udC/eVyWWtWvStQpGWn3es3mipMLXNF3MduNd1yQ7PA==","shasum":"d707cc29d540423ff7afb0494ea7a3345a457fef","tarball":"https://registry.npmjs.org/@667/express-jwt-authz/-/express-jwt-authz-2.4.1-1.tgz","fileCount":6,"unpackedSize":8511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgWg+HCRA9TVsSAnZWagAAsS0QAIn+IEJ8SVkHXk4ngD2L\n5v/Tuz0oNMhpCjsCZRGGkM1QysGpdjApy7qss5Pbrzw0WZbn21JN681tyT0R\nych509E0f/s5CNhWjutaK7oqHoYACTy2le6d+EpzNQck3guYxI41LuqpNtJc\nvyrkxoaRTm0m1R1msDr17eLfYsGYq32ndvVDvWdNGjicEIZs1S55YkoCtiIJ\n0DVZ4FwTZ5/fvyaxRrbdelZHbu63U2Mq0YtqDC8Tkp4sPci/4lua57/YA1uh\n4vSuEshtksaOOQITnj9B94kre+lkxOEIQyMYDlFXlA/6cLdD3alGmULAsMRd\noltIAnMW0MkgiZT60sBjW8pGnQKWvzgB8cja03jX4c/eCDAL997Pbuq44S6k\nREEGDcwhP3TrEMLFQOHV/HicJetRDUKiHt+b3AyWQ1nzBHovPpYLkuVKf47i\nFLcVoxPLW5WymZWe0SFurYpawREoZOkiKDVU/l4odW8wc2lhR7rHSYCULsi0\nL0wLSVpVvAt1aoIY/vU9IQ20iWELBDm595DToCFp6ftF7ZdeqOD0DGE4eo61\nRlWyA70rGUOE/xeBiya7WEytrbe3OT7+p57N/WAvA6LQsdoov3W+lmcrHMEC\nssh9S45S0GPqn3BOvOn6MkrHYy2YZkKDHlqJ2heRSKZ12iHu2/j3M7Pr2t/K\n72C2\r\n=khhw\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHwc4vcPyDvPhiVQxyAznr0RJy60XB2ZpVt5lov023bUAiBI/dWGfI/iL9inqcqO6h0+EEADygVECMSkbVgLIyApjQ=="}]},"_npmUser":{"name":"667","email":"667@june07.com"},"directories":{},"maintainers":[{"name":"667","email":"667@june07.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/express-jwt-authz_2.4.1-1_1616514951075_0.28951520464161407"},"_hasShrinkwrap":false}},"time":{"created":"2021-03-17T21:52:01.853Z","2.4.1-0":"2021-03-17T21:52:02.014Z","modified":"2022-04-04T10:48:48.655Z","2.4.1-1":"2021-03-23T15:55:51.209Z"},"maintainers":[{"name":"667","email":"667@june07.com"}],"description":"Validate a JWTs scope to authorize access to an endpoint","homepage":"https://github.com/june07/express-jwt-authz#readme","keywords":["express","restify","jwt","authorization"],"repository":{"type":"git","url":"git+https://github.com/june07/express-jwt-authz.git"},"author":{"name":"June07"},"bugs":{"url":"https://github.com/june07/express-jwt-authz/issues"},"license":"MIT","readme":"# express-jwt-authz\n\nThis fork of https://github.com/auth0/express-jwt-authz supports [restify](https://github.com/restify/node-restify) as well as express.\n\nValidate a JWTs `scope` to authorize access to an endpoint.\n\n## Install\n\n    $ npm install express-jwt-authz\n\n> `restify@^8.5.1` is a peer dependency.\n> `express@^4.0.0` is a peer dependency.\n> Make sure one of them is installed in your project.\n\n## Usage\n\nUse together with [express-jwt](https://github.com/auth0/express-jwt) to both validate a JWT and make sure it has the correct permissions to call an endpoint.\n\n```javascript\nvar jwt = require('express-jwt');\nvar jwtAuthz = require('express-jwt-authz');\n\nvar options = {};\napp.get('/users',\n  jwt({ secret: 'shared_secret' }),\n  jwtAuthz([ 'read:users' ], options),\n  function(req, res) { ... });\n```\n\nIf multiple scopes are provided, the user must have _at least one_ of the specified scopes.\n\n```javascript\napp.post('/users',\n  jwt({ secret: 'shared_secret' }),\n  jwtAuthz([ 'read:users', 'write:users' ], {}),\n  function(req, res) { ... });\n\n// This user will be granted access\nvar authorizedUser = {\n  scope: 'read:users'\n};\n```\n\nTo check that the user has _all_ the scopes provided, use the `checkAllScopes: true` option:\n\n```javascript\napp.post('/users',\n  jwt({ secret: 'shared_secret' }),\n  jwtAuthz([ 'read:users', 'write:users' ], { checkAllScopes: true }),\n  function(req, res) { ... });\n\n// This user will have access\nvar authorizedUser = {\n  scope: 'read:users write:users'\n};\n\n// This user will NOT have access\nvar unauthorizedUser = {\n  scope: 'read:users'\n};\n```\n\nThe JWT must have a `scope` claim and it must either be a string of space-separated permissions or an array of strings. For example:\n\n```\n// String:\n\"write:users read:users\"\n\n// Array:\n[\"write:users\", \"read:users\"]\n```\n\n## Options\n\n- `failWithError`: When set to `true`, will forward errors to `next` instead of ending the response directly. Defaults to `false`.\n- `checkAllScopes`: When set to `true`, all the expected scopes will be checked against the user's scopes. Defaults to `false`.\n- `customUserKey`: The property name to check for the scope key. By default, permissions are checked against `req.user`, but you can change it to be `req.myCustomUserKey` with this option. Defaults to `user`.\n- `customScopeKey`: The property name to check for the actual scope. By default, permissions are checked against `user.scope`, but you can change it to be `user.myCustomScopeKey` with this option. Defaults to `scope`.\n\n\n## Issue Reporting\n\nFor issues directly related to restify support, please report them at this reposittory issues section.\n\nIf you have found a bug or if you have a feature request, please report them at https://github.com/auth0/express-jwt-authz/issues. Please do not report security vulnerabilities on the public GitHub issue tracker. The [Responsible Disclosure Program](https://auth0.com/whitehat) details the procedure for disclosing security issues.\n\n## Author\n\n[June07](https://june07.com)\n\n## License\n\nThis project is licensed under the MIT license. See the [LICENSE](LICENSE) file for more info.\n","readmeFilename":"README.md"}