{"_id":"@adobe/aio-app-actions-auth-passport","_rev":"133-c8b8e41d59eb8badb3496fefe00d4d9f","name":"@adobe/aio-app-actions-auth-passport","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@adobe/aio-app-actions-auth-passport","version":"1.0.0","keywords":["serverless, openwhisk, authentication, passportjs"],"author":{"name":"Dragos Dascalita Haut","email":"ddascal@adobe.com"},"license":"Apache-2.0","_id":"@adobe/aio-app-actions-auth-passport@1.0.0","maintainers":[{"name":"msavin99","email":"savin.mircea@gmail.com"},{"name":"natebaldwin","email":"natebaldwindesign@gmail.com"},{"name":"msagolj","email":"msagolj@adobe.com"},{"name":"richardhand","email":"pid90611@adobe.com"},{"name":"jckautzmann","email":"jkautzma@adobe.com"},{"name":"andreea_dracea","email":"andreeadracea@yahoo.com"},{"name":"bpauli","email":"mail@bpauli.de"},{"name":"vladbailescu","email":"vlad@bailescu.ro"},{"name":"mfrisbey","email":"mark_f79@hotmail.com"},{"name":"himar","email":"himar@adobe.com"},{"name":"bbythewa","email":"bbythewa@adobe.com"},{"name":"sanketra","email":"sanketra@gmail.com"},{"name":"dcpfsdk","email":"dcpfsdk@adobe.com"},{"name":"fmeschbe","email":"fmeschbe@adobe.com"},{"name":"jianliao79","email":"jian.liao@gmail.com"},{"name":"ibaratz","email":"ibaratz@adobe.com"},{"name":"conyu","email":"conyu@adobe.com"},{"name":"alexkli","email":"alexander@klimetschek.de"},{"name":"meryllblanchet","email":"meryll@adobeio.com"},{"name":"moritzraho","email":"raho.mr@gmail.com"},{"name":"justinedelson","email":"justin@justinedelson.com"},{"name":"icaraps","email":"icaraps@hotmail.com"},{"name":"dkstevekwak","email":"steveguac@gmail.com"},{"name":"ashryan","email":"sayhi@ashryan.io"},{"name":"korra","email":"npmjs.karo@cupdev.net"},{"name":"praschetan","email":"cprasad@adobe.com"},{"name":"nporter-adbe","email":"nporter@adobe.com"},{"name":"aaronius","email":"aaron@aaronhardy.com"},{"name":"hirenoble","email":"hirenanandshah@outlook.com"},{"name":"benjamind","email":"ben@delarre.net"},{"name":"yoshikinoko","email":"yoshikinoko@gmail.com"},{"name":"goya","email":"brettrudd@gmail.com"},{"name":"rofe","email":"npm@rofe.com"},{"name":"alexmirea","email":"alexandru.daniel.mirea@gmail.com"},{"name":"purplecabbage","email":"purplecabbage@gmail.com"},{"name":"krisnye","email":"krisnye@gmail.com"},{"name":"kerrishotts","email":"kerrishotts@gmail.com"},{"name":"dpfister","email":"dominique.pfister@gmail.com"},{"name":"kptdobe","email":"kptdobe@gmail.com"},{"name":"macdonst","email":"simon.macdonald@gmail.com"},{"name":"shazron","email":"shazron@gmail.com"},{"name":"abhinavsaraswat","email":"absarasw@adobe.com"},{"name":"aemsites","email":"meyer@adobe.com"},{"name":"stefan-guggisberg","email":"sg@adobe.com"},{"name":"jfkhoury","email":"jfkhoury@gmail.com"},{"name":"jileesh","email":"jileeshsathyan@gmail.com"},{"name":"marbec","email":"mabecker@adobe.com"},{"name":"tripod","email":"tripod@bocanegra.ch"},{"name":"asteed","email":"andrewsteed@gmail.com"},{"name":"garthdb","email":"garthdb@gmail.com"},{"name":"lazd","email":"lazdnet@gmail.com"},{"name":"adobe-admin","email":"grp-opensourceoffice@adobe.com"},{"name":"adobe-activation","email":"Engineering-Admins@adobe.com"},{"name":"target-admin","email":"ciocanu@adobe.com"},{"name":"adobe-behance","email":"sedunn@adobe.com"},{"name":"stevegill","email":"stevengill97@gmail.com"},{"name":"trieloff","email":"lars@trieloff.net"},{"name":"filmaj","email":"maj.fil@gmail.com"}],"dist":{"shasum":"a1b303acaff821f8ff4e3e68c24eaac1e4948382","tarball":"https://registry.npmjs.org/@adobe/aio-app-actions-auth-passport/-/aio-app-actions-auth-passport-1.0.0.tgz","fileCount":19,"integrity":"sha512-XLdA40op8Zd4POxbke+pumEsbC64L+720miKusuoYUW0TjjNV3q0lt53uyi3lQt33nGqNN0eBJCm0OvZ4xvFOg==","signatures":[{"sig":"MEQCIELNbLaPxW9Si6leKVlA4UwKrXLflIomwkkNZe1Jx7F4AiAU8WY3SloUqLifxx5A2u6nlP4CZxeeui4NRkmWgseiPw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":21227052,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh1v4aCRA9TVsSAnZWagAA95YP/09MK0QFJH+pSqZn0FLI\nkzZnRgrUZxKtpxxeRABCnSz4EAY3frAflyp5ArE4zTEHTtn3JQ3cSsXVOCNq\nE3GaLfdJBGAM+fw3RxpTVecoCG6srBOW1XCl4uVeMYYggaxUnNzvdTfTwN8K\nRlr14/4pk94B8O6TjkKGQ9Guu+OdQy5VFUttAlvcKtZ3fnHRxipPYxL2mPOZ\nsSc7P/ljNsnHZzBbwmDSmuU1AZZvo4NyuMCq/YT1W2IuxVqE8PifR8R3MrAN\n/4WI4//vyONzJvn8GzIBdrZxcrE87OXEzBhwFPSRYOtEp+KYA8E/vmr7mkby\nNwuHt0m6s2rAYl7n3oBdnZOyFaEYq4aD2iZMqJlEfwTPb2xsG+f1o9UU9G5/\nBIAwoZevIB+AMve2PSx90VlmI+vf0k0MNEtoZlYitzf46r54A48zW1rexYJT\n+12dhoPs4fkXLjrRkXrR3Z737Hnh81QVeoU65MP3nQS1MBO+9lb+qHz45qUu\ngH9++voHB5XYixOMANKyq6/JP7EOsC20D0vDcDmmlAtkkB3CYcG14TxmgDpy\nsk/+YTXDd9Ppa9DKtOkcgjH1/b6xFR1YV7OdCNqigXE7232jeN+gzKQznm9f\nzkXazmBGD+BqAzxOVWIHIGw2Hh5HZO2VAfupQ1vX262RWsEsCPxWNmmEY+eM\nwg0I\r\n=k65n\r\n-----END PGP SIGNATURE-----\r\n"},"jest":{"reporters":["default","jest-junit"],"collectCoverage":true,"testEnvironment":"node","testPathIgnorePatterns":["<rootDir>/tests/fixtures/"],"coveragePathIgnorePatterns":["<rootDir>/tests/fixtures/"],"setupTestFrameworkScriptFile":"./jest.setup.js"},"main":"./src/action/auth.js","babel":{"presets":["latest"]},"gitHead":"3561c7476ee3528bc1953af0e360fc32bacf44c1","scripts":{"test":"npm run unit-tests","start":"babel-watch ./test/server/index.js","prepublish":"browserify -r ${npm_package_main}:main-action --node > aio-app-auth-passport.js && npm run remove_pkginfo && npm run whisk_wrapper","unit-tests":"jest --ci","prepublish_":"babel src --out-file aio-app-auth-passport.js --source-maps","whisk_wrapper":"echo \"var main = require('main-action').default;\" >> aio-app-auth-passport.js","remove_pkginfo":"replace '^require.*pkginfo' '// removed pkginfo ...' -r aio-app-auth-passport.js"},"_npmUser":{"name":"himar","email":"himar@adobe.com"},"browserify":{"transform":[["babelify"]]},"_npmVersion":"6.4.1","description":"An Openwhisk action that uses PassportJS for User Authentication Proxy","directories":{},"_nodeVersion":"10.13.0","dependencies":{"cookie":"^0.3.1","replace":"^1.1.0","passport":"^0.3.2","passport-github":"^1.1.0","passport-google":"^0.3.0","passport-twitter":"^1.0.4","passport-facebook":"^2.1.1","passport-adobe-oauth2":"^1.0.1","passport-google-oauth20":"^1.0.0","passport-oauth2-refresh":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^3.5.0","cors":"^2.7.1","jest":"^23.0.1","nock":"^9.0.2","eslint":"^4","isparta":"^4.0.0","request":"^2.79.0","babelify":"^7.3.0","babel-cli":"^6.18.0","babel-core":"^6.16.0","browserify":"^13.1.1","jest-junit":"^5.0.0","babel-watch":"^2.0.2","body-parser":"^1.15.2","compression":"^1.6.2","http-status":"^0.2.3","cls-bluebird":"^2.0.1","chai-as-promised":"^6.0.0","eslint-plugin-jest":"^22.1.2","babel-preset-babili":"0.0.9","babel-preset-es2015":"^6.16.0","babel-preset-latest":"^6.16.0","resource-router-middleware":"^0.6.0"},"_npmOperationalInternal":{"tmp":"tmp/aio-app-actions-auth-passport_1.0.0_1572874673736_0.12153868402871448","host":"s3://npm-registry-packages"}}},"time":{"created":"2019-11-04T13:37:53.509Z","modified":"2026-10-01T01:31:58.334Z","1.0.0":"2019-11-04T13:37:54.267Z"},"author":{"name":"Dragos Dascalita Haut","email":"ddascal@adobe.com"},"license":"Apache-2.0","keywords":["serverless, openwhisk, authentication, passportjs"],"description":"An Openwhisk action that uses PassportJS for User Authentication Proxy","maintainers":[{"email":"mabecker@adobe.com","name":"marbec"},{"email":"tripod@bocanegra.ch","name":"tripod"},{"email":"garthdb@gmail.com","name":"garthdb"},{"email":"lazdnet@gmail.com","name":"lazd"},{"email":"grp-opensourceoffice@adobe.com","name":"adobe-admin"},{"email":"patrickfulton@gmail.com","name":"patrickfulton"},{"email":"lars@trieloff.net","name":"trieloff"},{"email":"krisnye@gmail.com","name":"krisnye"},{"email":"dcpfsdk@adobe.com","name":"dcpfsdk"},{"email":"natebaldwindesign@gmail.com","name":"natebaldwin"},{"email":"devongovett@gmail.com","name":"devongovett"},{"email":"danniintheus@gmail.com","name":"aspro83"},{"email":"symanovi@adobe.com","name":"symanovi"},{"email":"dominique.pfister@gmail.com","name":"dpfister"},{"email":"sg@adobe.com","name":"stefan-guggisberg"},{"email":"npm@rofe.com","name":"rofe"},{"email":"kptdobe@gmail.com","name":"kptdobe"},{"email":"halls@adobe.com","name":"adobehalls"},{"email":"bradjohn@adobe.com","name":"fullcolorcoder"},{"email":"djaeggi@adobe.com","name":"djaeggi"},{"email":"dylandepass@gmail.com","name":"dylandepass"},{"email":"mhaack@adobe.com","name":"mhaack"},{"email":"amol@adobe.com","name":"amol-anand"},{"email":"stopp@adobe.com","name":"stopp-adobe"},{"email":"namarora@adobe.com","name":"namarora"},{"email":"doten@adobe.com","name":"doten"},{"email":"schmidt@adobe.com","name":"duh_schmidt"},{"email":"astha.bhargava23@gmail.com","name":"asthabh23"},{"email":"aljoseph@adobe.com","name":"aljoseph"},{"email":"zouhir.dahbi@outlook.com","name":"zdahbi"},{"email":"tuicu@adobe.com","name":"tuicu"},{"email":"fmeschbe@adobe.com","name":"fmeschbe"}],"readme":"[![Build Status](https://travis-ci.com/adobe/adobeio-cna-actions-auth-passport.svg?branch=master)](https://travis-ci.com/adobe/adobeio-cna-actions-auth-passport)\n[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n\n\n# actions-auth-passport\nAn Openwhisk action that uses [PassportJS](http://passportjs.org/) for User Authentication Proxy.\n\nThe scope of this action is to authenticate users, returning an Access Token, a Refresh Token, and the Profile of the user.\nThe output of this action should be cached, encrypted with Openwhisk's namespace credentials or other means;\nactions belonging to the same package should be able to access this cache, retrieve a valid token, in order to be able to execute actions on behalf of the users.\n\n<img src=\"./docs/auth-demo.gif\" alt=\"Demo\" width=\"500px\"/>\n\n## Quick start\n\n1. Run `npm install`\n2. Create a [webaction](https://github.com/openwhisk/openwhisk/blob/master/docs/webactions.md) for an authentication provider.\n\n    ```bash\n    # (optional) place the action in a package\n    $ wsk package create oauth\n\n    $ wsk action create oauth/<action_name> ./openwhisk-passport-auth-0.0.1.js  --web true \\\n        --param auth_provider <authentication_provider> \\\n        --param client_id <client_id> \\\n        --param client_secret <client_secret> \\\n        --param scopes <comma_sepparated_scopes> \\\n        --param callback_url https://<openwhisk_hostname>/api/v1/web/<openwhisk_namespace>/oauth/<action_name>.json\n    ```\n\n    Configure the default action parameters:\n    * `auth_provider` - the name of the authentication provider ( i.e. `facebook`, `github`, etc ).\n      The action will try importing `passport-<provider>` lib. You can also add your own authentication provider.\n    * `auth_provider_name` - optional; defaults to `auth_provider`; it defines an alternate name for the authorization to be used with Passport.\n    * `client_id` - consumer key\n    * `client_secret` - consumer secret\n    * `scopes` - optional; the list of scopes to request\n    * `callback_url` - this parameter should point to this action\n    * `success_redirect` - a URL to redirect after a successful login. This value is cached in a cookie  named `__Secure-auth_context` in order to be retrieved when the authentication provider invokes the `callback_url`.\n\n3. To test the action browse to `https://<openwhisk_hostname>/api/v1/web/<openwhisk_namespace>/oauth/<action_name>`\n\n### Using the built-in OAuth providers\n\nThe examples bellow assume there is a local OpenWhisk deployment, accessible on `localhost`,\nand an `oauth` package already created in OpenWhisk.\n\n```bash\n$ wsk package create oauth\n```\n\n#### GitHub\n\nVisit https://github.com/settings/developers to create a new application, or to retrieve the `Client ID` and `Client Secret` for an existing application.\n\n > NOTE: When configuring the application in GitHub make sure the `Authorization callback URL`\n is set to `https://localhost/api/v1/web/guest/oauth/github.json`\n\nCreate a new action called `github` inside the `oauth` package.\n\n```bash\n$ wsk action create oauth/github ./openwhisk-passport-auth-0.0.1.js --web true \\\n        --param auth_provider github \\\n        --param client_id --client-id-- \\\n        --param client_secret --client-secret-- \\\n        --param callback_url https://localhost/api/v1/web/guest/oauth/github.json -i\n```\n\nThen browse to https://localhost/api/v1/web/guest/oauth/github in order to test the action.\n\n\n#### Facebook\nVisit https://developers.facebook.com to create a new application, or to retrieve the `App ID` and the `App secret` for an existing app.\n\nCreate a new action called `fb` inside the `oauth` package.\n\n```bash\n$ wsk action create oauth/fb ./openwhisk-passport-auth-0.0.1.js --web true \\\n        --param auth_provider facebook \\\n        --param client_id --app-id-- \\\n        --param client_secret --app-secret-- \\\n        --param callback_url https://localhost/api/v1/web/guest/oauth/fb.json -i\n```\n\nThen browse to https://localhost/api/v1/web/guest/oauth/fb in order to test the action.\n\n#### Twitter\nVisit https://apps.twitter.com/ to create an application, or to retrieve the `Consumer Key` and `Consumer Secret` for an existing app.\n\nCreate a new action called `twitter` inside the `oauth` package.\n\n```bash\n$ wsk action create oauth/twitter ./openwhisk-passport-auth-0.0.1.js --web true \\\n        --param auth_provider twitter \\\n        --param client_id --consumer-key-- \\\n        --param client_secret --consumer-secret-- \\\n        --param callback_url https://localhost/api/v1/web/guest/oauth/twitter.json -i\n```\n\nThen browse to https://localhost/api/v1/web/guest/oauth/twitter in order to test the action.\n\n#### Google OAuth\n\nVisit https://console.developers.google.com to create a project, or to retrieve the `Client ID ` and `Client Secret` of an existing application.\n\n> NOTE: When configuring credentials in Google select `OAuth Client ID`, `Application Type = Other`.\n\nCreate a new action called `google` inside the `oauth` package.\n\n```bash\n$ wsk action create oauth/google ./openwhisk-passport-auth-0.0.1.js --web true \\\n        --param auth_provider google-oauth20 --param auth_provider_name google \\\n        --param client_id --client-id-- \\\n        --param client_secret --client-secret-- \\\n        --param scopes https://www.googleapis.com/auth/plus.login \\\n        --param callback_url https://localhost/api/v1/web/guest/oauth/google.json -i\n```\n\nThen browse to https://localhost/api/v1/web/guest/oauth/google in order to test the action.\n\n\n### Adding a custom authentication provider\n\n1. Install the Node module that supports a new provider\n2. Import it in the main action [auth.js](src/action/auth.js)\n3. Follow the [quick start](#quick-start) steps\n\n## Using Package Bindings\n\nThe [quick-start](#quick-start) method it's easy to setup, but the disadvantage is that the code is uploaded\nfor each individual action/authentication provider. This makes it more difficult to apply changes.\nOpenWhisk provides a solution for this: [package bindings](https://github.com/openwhisk/openwhisk/blob/master/docs/packages.md#creating-and-using-package-bindings).\n\nWith package bindings the action is uploaded and maintained in a single package. Developers may use package binding\nin order to set custom `client_id`, `client_secret`, `scope` for each authentication provider.\n\nTo set this up, start by creating a shared package:\n```bash\nwsk -i package create oauth --shared yes\n```\n\nThen install this action without specifying any default parameters:\n\n```bash\nwsk -i action create oauth/user ./openwhisk-passport-auth-0.0.1.js  --web true\n```\n\nThen define one or more authentication providers by using package bindings:\n\n```bash\nwsk -i package bind oauth/user my-oauth-provider \\\n--param auth_provider <authentication_provider> \\\n--param client_id <client_id> \\\n--param client_secret <client_secret> \\\n--param scopes <comma_sepparated_scopes> \\\n--param callback_url https://<openwhisk_hostname>/api/v1/web/<openwhisk_namespace>/oauth/fb.json\n```\n\n## Linking multiple social IDs together\n\nThis action can also be invoked in a sequence with other authentication actions,\nso that a user can authenticate with multiple providers and at the end to link those identities together.\nThis action is not concerned with persisting user information,\nbut since it receives the HTTP Request first, it does something to help: it creates a `context` object.\n\nThe purpose of the `context` object is to persist a list with the linked identities during the login process:\nFor example:\n\n```json\n{\"identities\":[\n  {\"provider\":\"facebook\",\"user_id\":\"1234\"},\n  {\"provider\": \"twitter\", \"user_id\": \"999\"}\n]}\n```\n\nThis information is assumed to be stored in a cookie named `__Secure-auth_context`. This cookie can be easily set by an action that is invoked as the last step for the login sequence. See [src/action/redirect.js](src/action/redirect.js) action for an example.\n\n### Contributing\n\nContributions are welcomed! Read the [Contributing Guide](./.github/CONTRIBUTING.md) for more information.\n\n### Licensing\n\nThis project is licensed under the Apache V2 License. See [LICENSE](LICENSE) for more information.\n","readmeFilename":"README.md"}