{"_id":"@access-tree/access-tree-express","_rev":"2-3a5c668ec5e6d56f53f904eb05c097c3","name":"@access-tree/access-tree-express","dist-tags":{"latest":"0.0.3"},"versions":{"0.0.1":{"name":"@access-tree/access-tree-express","version":"0.0.1","description":"middleware for endpoint access","main":"AccessTree.js","directories":{"example":"examples","test":"tests"},"scripts":{"test":"jest"},"repository":{"type":"git","url":"git+ssh://git@github.com/access-tree/access-tree-express.git"},"keywords":["endpoint","security","express","middleware"],"author":{"name":"John Powers"},"license":"MIT","bugs":{"url":"https://github.com/access-tree/access-tree-express/issues"},"homepage":"https://github.com/access-tree/access-tree-express#readme","dependencies":{"cookie-parser":"^1.4.6","express":"^4.18.2"},"gitHead":"5b29f0605eff32b206d83b2b1c48e0c4ea7b5b7c","_id":"@access-tree/access-tree-express@0.0.1","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-I/0OWP6PRkEgHrbItuqJUw8tjW4g5FYESIe7GBfEmg15CTHISpaD2/yE72vmarq8xJ81jX+gapXqH1LG8jfS6g==","shasum":"874adae81b406a76e476201a5cb23a5d232843ff","tarball":"https://registry.npmjs.org/@access-tree/access-tree-express/-/access-tree-express-0.0.1.tgz","fileCount":11,"unpackedSize":10824,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDcM4WOQvTYxOZuYLGM5DEKFfPoZC//BZjVCRBmhK7q4AiEAtZxMWdCfSWFKneVtJ/iLKCYZhVQCSNDBG0jIgAtOBeM="}]},"_npmUser":{"name":"jwpowers2","email":"john.powers070@gmail.com"},"maintainers":[{"name":"jwpowers2","email":"john.powers070@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/access-tree-express_0.0.1_1684548466582_0.7320407114979757"},"_hasShrinkwrap":false},"0.0.2":{"name":"@access-tree/access-tree-express","version":"0.0.2","description":"middleware for endpoint access","main":"AccessTree.js","directories":{"example":"examples","test":"tests"},"scripts":{"test":"jest"},"repository":{"type":"git","url":"git+ssh://git@github.com/access-tree/access-tree-express.git"},"keywords":["endpoint","security","express","middleware"],"author":{"name":"John Powers"},"license":"MIT","bugs":{"url":"https://github.com/access-tree/access-tree-express/issues"},"homepage":"https://github.com/access-tree/access-tree-express#readme","dependencies":{"cookie-parser":"^1.4.6"},"gitHead":"2bf7da9b3696dfaa0de7f7ff9a481cdce6dd91f1","_id":"@access-tree/access-tree-express@0.0.2","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-k27QD64n0jbncxwl+0p4xuWxFFyxjWGV1BtWlWPmSY0YOqkZ/0tlxLLz0DMVeSBHqv9EuJ8quu7+ZeTbV2QUaw==","shasum":"e75fa6e3253c197ed8a9b2d019571bd546a64a3e","tarball":"https://registry.npmjs.org/@access-tree/access-tree-express/-/access-tree-express-0.0.2.tgz","fileCount":8,"unpackedSize":9582,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBULTPPBZYxZDXIfTITUQ/YdGi2YG/cFzXRGRz+jtgqIAiEA3N18o5l+5w1MiCwhXP8f7ztJ/5JLdZPOmW3/Ttc3Ka4="}]},"_npmUser":{"name":"jwpowers2","email":"john.powers070@gmail.com"},"maintainers":[{"name":"jwpowers2","email":"john.powers070@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/access-tree-express_0.0.2_1685200617545_0.9974190204454179"},"_hasShrinkwrap":false},"0.0.3":{"name":"@access-tree/access-tree-express","version":"0.0.3","description":"middleware for endpoint access","main":"AccessTree.js","directories":{"example":"examples","test":"tests"},"scripts":{"test":"jest"},"repository":{"type":"git","url":"git+ssh://git@github.com/access-tree/access-tree-express.git"},"keywords":["endpoint","security","express","middleware"],"author":{"name":"John Powers"},"license":"MIT","bugs":{"url":"https://github.com/access-tree/access-tree-express/issues"},"homepage":"https://github.com/access-tree/access-tree-express#readme","dependencies":{"cookie-parser":"^1.4.6"},"gitHead":"a67f6a56ee908b7be5ba21cd61260195a2d65401","_id":"@access-tree/access-tree-express@0.0.3","_nodeVersion":"18.16.0","_npmVersion":"9.5.1","dist":{"integrity":"sha512-cWKVGsZhvzxdKsvTwsAPMLthz7+3uvZ9Wg0h3HzO+FM+KyXCS1kPdkweXpDdjEidQIE1NCBeY3kj4N+NWLJfOg==","shasum":"3d5de71da1c615da694817bd6e5f56e36a7e2e9f","tarball":"https://registry.npmjs.org/@access-tree/access-tree-express/-/access-tree-express-0.0.3.tgz","fileCount":8,"unpackedSize":9957,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHFVb9oltKxoml6MuS7G3iJHSDsjIBzvythAJCaokxAgAiB6nF7eNQqLjoP2psFC/aFEtocgCtfN9NMwtHE3h2LknA=="}]},"_npmUser":{"name":"jwpowers2","email":"john.powers070@gmail.com"},"maintainers":[{"name":"jwpowers2","email":"john.powers070@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/access-tree-express_0.0.3_1685201902153_0.5306315377394701"},"_hasShrinkwrap":false}},"time":{"created":"2023-05-20T02:07:46.511Z","0.0.1":"2023-05-20T02:07:46.770Z","modified":"2023-05-27T15:38:22.424Z","0.0.2":"2023-05-27T15:16:57.731Z","0.0.3":"2023-05-27T15:38:22.305Z"},"maintainers":[{"name":"jwpowers2","email":"john.powers070@gmail.com"}],"description":"middleware for endpoint access","homepage":"https://github.com/access-tree/access-tree-express#readme","keywords":["endpoint","security","express","middleware"],"repository":{"type":"git","url":"git+ssh://git@github.com/access-tree/access-tree-express.git"},"author":{"name":"John Powers"},"bugs":{"url":"https://github.com/access-tree/access-tree-express/issues"},"license":"MIT","readme":"# Access Tree Express\r\n\r\n### A library to provide access restrictions on express.js endpoints\r\n\r\n## How does it work ? \r\n\r\n1. User to endpoint mappings are ingested into a Tree data structure.\r\n\r\n2. Endpoint access middleware is designed to be applied to an Express.js endpoint.\r\n\r\n3. A username cookie is read to match up the user permissions with the endpoints + HTTP Verb they have access to.  \r\n\r\n## Setup\r\n\r\n1. install the access-tree-express package and the cookie-parser package\r\n\r\n    `npm install @access-tree/access-tree-express cookie-parser`\r\n\r\n2. require access-tree-express in your express server and cookie-parser\r\n```javascript\r\n    let AccessTree = require('@access-tree/access-tree-express');\r\n    const cookieParser = require('cookie-parser');\r\n```\r\n3. instantiate the tree and apply the cookie parser middleware globally, as well as apply a body-parser type middleware\r\n```javascript\r\n    let tree = new AccessTree('root');\r\n    app.use(cookieParser());\r\n    // express native body parser\r\n    app.use(express.json());\r\n```\r\n4. read the initial user to endpoint mappings into the tree (imported from a file, first)\r\n```javascript\r\n    // in your initial dependency imports\r\n    const userData = require('./userData.json');\r\n    tree.readUserFile(userData)\r\n```\r\n## Examples: loading the initial user to endpoint mappings\r\n\r\n* here are some example user to endpoint mappings\r\n* this is the format for data to be read and loaded by readUserFile method\r\n\r\n```javascript\r\n{\r\n    \"paths\": [\r\n        \"/john/api/home/data/chicken/legs/raw/GET/6\",\r\n        \"/john/api/home/data/chicken/legs/raw/POST/0\",\r\n        \"/john/api/home/data/chicken/legs/cooked/GET/4\",\r\n        \"/bob/api/users/dogs/names/GET/4\",\r\n        \"/alice/api/data/people/things/шеллы/POST/6\",\r\n        \"/alice/api/両/乓/乶/POST/6\",\r\n        \"/admin/api/add-endpoint/POST/6\",\r\n        \"/admin/api/remove-user/DELETE/6\"\r\n    ]\r\n}\r\n```\r\n\r\n## Examples: Applying Access-Tree to Express Endpoints\r\n\r\n_Here is an example of endpoint access for a read endpoint (bob has access):_\r\n\r\n```javascript\r\n// user to endpoint mapping is:\r\n//      /bob/api/users/dogs/names/GET/4\r\napp.get(\r\n    \"/api/users/dogs/names\",\r\n    tree.endpointAccess(tree, \"read\"),\r\n    (req, res) => {\r\n        res.json({ message: \"hello data\" });\r\n    }\r\n);\r\n```\r\n\r\n_Here is an endpoint access example with utf-8 non-ascii characters_\r\n\r\n```javascript\r\n// user to endpoint mapping is:\r\n//      /alice/api/両/乓/乶/POST/6\r\napp.post(\"/api/%E4%B8%A1/%E4%B9%93/%E4%B9%B6\",\r\n    tree.endpointAccess(tree, \"write\"),\r\n    (req, res) => {\r\n        res.json({ message: \"hello there\" })\r\n    }\r\n);\r\n```\r\n\r\n_Here is an example where endpoint validation is done and then the access tree is modified:_\r\n\r\n```javascript\r\n// user to endpoint mapping is:\r\n//     /admin/api/remove-user/DELETE/6\r\napp.delete(\"/api/remove-user/:username\",\r\n    tree.endpointAccess(tree, \"write\"),\r\n    (req, res) => {\r\n        tree.removeUser(req.params.username);\r\n        res.json({ message: \"you just removed a user and their endpoints\" })\r\n    }\r\n);\r\n```\r\n_Here is an example of endpoint access for admin, who will list the users in the tree:_\r\n\r\n```javascript\r\n// user to endpoint mapping for admin user is:\r\n//   /admin/api/list-users/GET/4\r\napp.get(\r\n    \"/api/list-users\",\r\n    tree.endpointAccess(tree, \"read\"),\r\n    (req, res) => {\r\n        const users = tree.listUsers();\r\n        res.json({ message: users });\r\n    }\r\n);\r\n```\r\n## Why is Access Tree worth using ? \r\n\r\n1. The Tree is a Trie, optimized for string completion with O^1 time complexity for searching.\r\n\r\n2. The Tree uses references, non-contiguous memory, so it can scale big for large organizations.\r\n\r\n3. The Tree can be mutated in real-time so an administrator can modify permissions without rebooting a server\r\n\r\n* A User tree can be pruned or an endpoint can be added.  \r\n\r\n* To add a new user, you add all their endpoints.\r\n\r\n\r\n### FAQ:\r\n\r\n* can't a user just say they are admin and then get access to admin utilities ? \r\n\r\n _Authentication is not Access Tree's job.  Authorization is.  So, it should be used in conjuction with a system for authenticating a user._ \r\n\r\n\r\n","readmeFilename":"README.md"}