{"_id":"@abramltd/jwt-oauth2-middleware","_rev":"1-db6250e8b4d175920b6a965725eb12e7","name":"@abramltd/jwt-oauth2-middleware","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@abramltd/jwt-oauth2-middleware","version":"0.1.0","description":"This project defines some middleware for the creation of OAuth Server using oauth2-node. An example is given using express as the intended server. Currently only password and refresh_token grants are supported.","main":"index.js","dependencies":{"auto-bind":"^1.2.1","jsonwebtoken":"^8.3.0","lodash":"^4.17.10","oauth2-server":"^3.0.0"},"devDependencies":{"eslint":"^5.3.0","eslint-config-airbnb-base":"^13.0.0","eslint-plugin-import":"^2.13.0","jest":"^23.4.2"},"scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"repository":{"type":"git","url":"git+https://github.com/AbramLtd/jwt-oauth2-middleware.git"},"keywords":[],"author":"","license":"ISC","bugs":{"url":"https://github.com/AbramLtd/jwt-oauth2-middleware/issues"},"homepage":"https://github.com/AbramLtd/jwt-oauth2-middleware#readme","gitHead":"3d67599de47ce43d83a24dd47a09c311f23a86f6","_id":"@abramltd/jwt-oauth2-middleware@0.1.0","_npmVersion":"5.6.0","_nodeVersion":"8.11.3","_npmUser":{"name":"david.abram","email":"david@abram.com"},"dist":{"integrity":"sha512-t+AWkUZa4RV5yvBVR8tJ+dPNQM598ZWEXuXBTA8EEXvtCoqT+VjXubCjnYucbNroPJhlYjsZVnKRXMowVjChpQ==","shasum":"e3b2fdded915fe00082adbe8ba166f85f15917ff","tarball":"https://registry.npmjs.org/@abramltd/jwt-oauth2-middleware/-/jwt-oauth2-middleware-0.1.0.tgz","fileCount":6,"unpackedSize":15498,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbbGg7CRA9TVsSAnZWagAAWBsQAJBTX7n+qSZW1dEohkE0\nHF8RfGQQVHjwJNK85dx9QYbyKTT79MABktrfA4SHolJHU9uP3s0uHBlS0Szx\nICQNYDEhRs5JBh3fTFbPFl1EZ0CZp8d6c08DVLDlHHZN3ZalF8CAHBrUO+e8\n9RycEyo0yhEai15H2Einw8fD134U4P7BEIUJuY7ow8geinrwiPJ//CQ71H3L\nOJNDkLEITtuABD5DxEYJop0wBxtpNmtv2P3CcQmrR8R7ylc8ALdwRVoaXr0l\n3ljdvsn8spt0iNVUHiF2kaSXzvTZtx5/cseC1ggmZwv6wTmFcPcl7AlSkYxr\nkKvr6+VD5RkBPGyrnXB4DcIOMG9W3IS+bRP4nbqLDmpLJt2sVZmYtfInBkVE\nsRs/7CEc6crdb2LkZu08ew9Y3EcSX//OgZmFjb/a+eT1b5k8RaazSmc64AQQ\n9BV68m73X/MhVm3DitCijYg6vmLR4gOofAarKp0yw8aJ3Ry/ETx3VdN8AJag\nrfyECubQK0Hmx+B/KQDD0nmteSdnYdKx9H6clLMk48ZQnoh/hFYWXE2lfZmk\nkDNqVeRXSdx3g31EWRtWxHJQNNRdseRkpH+EwPFCzJMGkTrxAmnLYGKfs50v\nBZMkFu8Aq20/vh1eg73FxNenb5uLwdcv7dBJOCVRHNMqJK1LxEtz9DsveIpi\nS6Hz\r\n=+4dy\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDoB6FZJvosZHKxMPwyv1aBao3HvqXuGpoMSgIbfz5wYgIgCl95vz7eK+DszGIx868uv5OXGui4XTCCbw1XbwArvPw="}]},"maintainers":[{"name":"david.abram","email":"david@abram.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/jwt-oauth2-middleware_0.1.0_1533831226775_0.13322432444985788"},"_hasShrinkwrap":false}},"time":{"created":"2018-08-09T16:13:46.651Z","0.1.0":"2018-08-09T16:13:46.851Z","modified":"2022-04-04T11:01:41.113Z"},"maintainers":[{"name":"david.abram","email":"david@abram.com"}],"description":"This project defines some middleware for the creation of OAuth Server using oauth2-node. An example is given using express as the intended server. Currently only password and refresh_token grants are supported.","homepage":"https://github.com/AbramLtd/jwt-oauth2-middleware#readme","keywords":[],"repository":{"type":"git","url":"git+https://github.com/AbramLtd/jwt-oauth2-middleware.git"},"bugs":{"url":"https://github.com/AbramLtd/jwt-oauth2-middleware/issues"},"license":"ISC","readme":"# JWT OAUTH Middleware\n\nThis project defines some middleware for the creation of OAuth Server using oauth2-node.\nAn example is given using express as the intended server.\nCurrently only password and refresh_token grants are supported.\n\n## Usage & routes\n\nShort usage version (example with **express.js** server):\n```javascript\n    var oauth = require('insert-package-name')(model, config); // creating server middleware\n    ... // express needed stuff\n\n    app.post('/oauth/token', oauth.token); // (1) and (2)\n\n    app.get('/validate', oauth.authenticate, function (req, res) { // (3)\n        res.json({ message: 'Secure data' });\n    });\n\n```\n\nAny OAuth server that implements password and refresh_token grant types, needs to have three routes:\n- one for generating access tokens (1) \n- one for generating new access tokens from unexpired refresh tokens (2)\n- one for token validation/gathering sensitive information (3)\n\n### Generating access tokens\n\nUsually, the route for acquiring an access token for a user is **/token**.\nThe request needs to be **HTTP/HTTPS POST** and required data is sent in the request's body. \n\n|Required data| Value|\n| ------------------ | ---------------- |\n|username| user's account username|\n|client_id| Id of the client (application) that is requesting the user's access token|\n|password| user's account password|\n|grant_type|**password** |\n|client_secret|client's secret used to sign token data|\n|scope|the scope the generated access token needs to have|\n\nThe return value example is shown below.\n\n```json\n    {\n        \"access_token\": \"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJjbGllbnRJZCI6IjEyMzUiLCJ1c2VySWQiOiI1OGVkMDUwYTczNGQxZDBlNjVmYzc3OTQiLCJ0eXBlIjoiYWNjZXNzVG9rZW4iLCJ1c2VybmFtZSI6IkRhbmEiLCJiYW5hbmEiOiJiYW5hbmEgd2hvIiwic2NvcGUiOiJiYW5hbmEiLCJleHBpcmVEYXRlIjoxNDk4MzI4MjY3NDc2LCJpYXQiOjE0OTgzMjgyMDcsImV4cCI6MTQ5ODMyODI2N30.KygbmACDVPYGoDpUg7YiyI5oAzQ5aUv8uqG0m9BDNg4\",\n        \"token_type\": \"Bearer\",\n        \"expires_in\": 59, // seconds \n        \"refresh_token\": \"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJjbGllbnRJZCI6IjEyMzUiLCJ1c2VySWQiOiI1OGVkMDUwYTczNGQxZDBlNjVmYzc3OTQiLCJ0eXBlIjoicmVmcmVzaFRva2VuIiwidXNlcm5hbWUiOiJEYW5hIiwiYmFuYW5hIjoiYmFuYW5hIHdobyIsInNjb3BlIjoiYmFuYW5hIiwiZXhwaXJlRGF0ZSI6MTQ5ODMyODI2NzQ3OCwiaWF0IjoxNDk4MzI4MjA3LCJleHAiOjE0OTgzMjgyNjd9.milncP0uopHUEU56ZqG1i9IDKDkP5ANfPQPFazMZLTE\",\n        \"scope\": \"banana\"\n    }\n```\n\n### Generating new access tokens from unexpired refresh tokens\n\nUsually, the route for acquiring an access token for a user is **/token**.\nThe request needs to be **HTTP/HTTPS POST** and required data is sent in the request's body. \n\n|Required data| Value|\n| ------------------ | ---------------- |\n|client_id| Id of the client (application) that is requesting the refresh of the user's access token|\n|grant_type|**refresh_token** |\n|client_secret|client's secret used to sign data, secret of the refresh token|\n|refresh_token|refresh token used to retrieve the new access and refresh token. Musn't be expired|\n\n**Remark:** if the token isn't expired, it will be revoked and a new pair accessToken/refreshToken will be issued.\nIn addition, the new generated tokens will have the same scope as the previously generated ones.\nAn example is shown below.\n\n```json\n    {\n        \"access_token\": \"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJjbGllbnRJZCI6IjEyMzUiLCJ1c2VySWQiOiI1OGVkMDUwYTczNGQxZDBlNjVmYzc3OTQiLCJ0eXBlIjoiYWNjZXNzVG9rZW4iLCJ1c2VybmFtZSI6IkRhbmEiLCJiYW5hbmEiOiJiYW5hbmEgd2hvIiwic2NvcGUiOiJiYW5hbmEiLCJleHBpcmVEYXRlIjoxNDk4MzI5MTY3OTkxLCJpYXQiOjE0OTgzMjkxMDcsImV4cCI6MTQ5ODMyOTE2N30._vbYF3f1DIcuiG_nX-8clYX6IgckIqY9n75NoLzw3tE\",\n        \"token_type\": \"Bearer\",\n        \"expires_in\": 59, // seconds\n        \"refresh_token\": \"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJjbGllbnRJZCI6IjEyMzUiLCJ1c2VySWQiOiI1OGVkMDUwYTczNGQxZDBlNjVmYzc3OTQiLCJ0eXBlIjoicmVmcmVzaFRva2VuIiwidXNlcm5hbWUiOiJEYW5hIiwiYmFuYW5hIjoiYmFuYW5hIHdobyIsInNjb3BlIjoiYmFuYW5hIiwiZXhwaXJlRGF0ZSI6MTQ5ODMyOTE2Nzk5MywiaWF0IjoxNDk4MzI5MTA3LCJleHAiOjE0OTgzMjkxNjd9.GQU0bCFlu_qCuQgZtdTXTie6SPA08xVIv5Zv93ELFig\",\n        \"scope\": \"banana\"\n    }\n```\n\n### Token validation/gathering sensitive information\n\nFor validating the token or gathering sensitive information one must issue a **HTTP GET** request on a desired route.\nIf scope should be validated, the request should have scope specified in the URL query.\nQuery parameter's name is **scope**.\n\n\n\n## Model\n\nIn order to create the middleware object one must supply the model object and configuration.\nHowever, not all model functions need to be provided - partial functionality is provided.\nThe following table shows which grant_types require which methods as well as show if the method is used in (1), (2) or (3).\n\n|Model function name| Declaration| Description | Grant types | Needed for (1)? |  Needed for (2)? | Needed for (3)? |\n| ------------------ | ---------------- | ------------------ | ---------------- | ------------------ | ---------------- |---------------- |\n|**generateTokenData**| (client, user, scope) => data directly saved into the token | Same for access token and refresh token| Both | yes | yes| no|\n|**getClientById**|(id) => Client : {id: string, refreshTokenSecret: string, accessTokenSecret: string} | Returns client object | Both | yes| yes| yes|\n|**getUserData**|(username, password) => either (User : {id: string}) or false| Returns user object | password | yes | yes | no |\n|**revokeRefreshToken**| (data) => boolean | Revokes the supplied refresh token and returns whether the operation was successful | refresh_token | no | yes | no|\n|**saveToken**| (token, user, client) => Token with user and client data attached as follows {user: {id: string}, client: {id: string}} | Saves both refresh and access tokens | Both | yes | yes| no |\n|**validateScopeUser**| (user, client, scope)=> either scope  or false| Used to see whether the user/client combination should/can have certain scope | password| yes | no | no|\n|**verifyScopeAccessToken**|(data, scope) => boolean | Used to see whether the supplied access token can be used for the supplied scope| Authenticate method | no | no| yes|\n\n\n**revokeRefreshToken data type**\n```javascript\n \n  data = { \n      user: {id: string},\n      client: {id: string},\n      token: {\n                    refreshToken: string, // token\n                    expires: Date,\n                    client: Client,\n                    scope: string\n      },\n      scope: string\n    };\n```\n**verifyScopeAccessToken data type**\n```javascript\n \n  data = {\n            user: { id: string},\n            token: {\n                accessToken: string, //bearerToken,\n                expires: Date,\n                client: Client,\n                scope: string\n            },\n            scope: string\n };\n```\n ## Config\n\n Config needs to define expiration in seconds for both access and refresh token.\n Example is provided below.\n ```javascript\n \n  var config = {\n    accessTokenExpiry: 60,             // seconds\n    refreshTokenExpiry: 60,          // seconds\n  };\n```","readmeFilename":"README.md"}