{"_id":"@akashnetwork/fastify-mtls-proxy","_rev":"10-c599b7a5f791e15562e9241fd40c2fca","name":"@akashnetwork/fastify-mtls-proxy","dist-tags":{"latest":"1.1.2"},"versions":{"1.1.0":{"name":"@akashnetwork/fastify-mtls-proxy","version":"1.1.0","license":"MIT","_id":"@akashnetwork/fastify-mtls-proxy@1.1.0","maintainers":[{"name":"corysturtevant","email":"cory@akash.network"},{"name":"jtary","email":"joseph.tary@gmail.com"}],"dist":{"shasum":"a01c6e88a8322168e673e60714f19051fa0ea1f0","tarball":"https://registry.npmjs.org/@akashnetwork/fastify-mtls-proxy/-/fastify-mtls-proxy-1.1.0.tgz","fileCount":12,"integrity":"sha512-6esAFzWNTcenVSc7Ga76QczCJc2NmnZNCgZPwc+5amBwkzcZQSn8YI2F0SaNmrsUJgrf8Px+rCmBeF7zBLEKDA==","signatures":[{"sig":"MEQCIFdrFo0H1LEJJ53ChYhZ2VEMLB0qK/1HVJWPAvUFwinWAiATBgPWCXpTIZRBzSFYZwTANu+FtS1ae3vkwr7uQJb50w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":62818,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi/SwqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoyHA//R4N9i2VtxCnky4mc9qfK0MDCMeOdt4YYDodLRYfie0fT1bNO\r\nmHjdJqTiN5NzRDx+eYKDDP6K307d2dgQpVueNzzc8vTuR8tb3VPcz0jWy7Js\r\nQ7enp9yE+7QIjf0oeQrAkjnmjHXXslYY4Wuobs4s6/22LOqjOkU9S2AlSCRF\r\n89W/hjOs+ws4KvsySa95bdCZz90NDgQm0laQY5KXz9v6u0dNAxEvBQ6k8L++\r\nF37Rllh3hAfPc0Zl+Jp1D0NSqaW/SB84OCGruhi+lH/FCsEyDmBZePV4g07g\r\nb6vShQS35GlFwuJivnAIyfGuE5GdWhOTwirHjVA0a9zt22Ax6toSme7x4j9c\r\nuhrVOXXtEUpxhZ1HrADA6P8Nt/YC0ZXpQdiLdpjtVmbtVZ8aqPUVnu9o4BvG\r\n0EpyRk7uKrY05BZfHA6IqNIemr5rt0dhUCRgMCGLgPHxgG+gprVvS9FsxyTS\r\nm82KjbsBb9n/p9HXC+VBul6X7Lg1m4+IhJ8uhccOfF+BqERnDYDdI6Jj7Y29\r\nKgWrimdxzXUt56pVrjuu5uFqkEJfMchc2W2hapS6r2NKa/NKHv2yvk86kmEr\r\nMQ2DSTeS6eLIjQZibxLRRkQON3TG9mcJoWabLxHK13rgeI1w1aouRbLSEtaK\r\nh14rJfF+9S17FfJTSpZwJ6KhbItvADdYMCo=\r\n=SApJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"src/index.js","gitHead":"9a9e8e0de4575d2aaa7be36c0572c96f159e0ecf","scripts":{"test":"jest","start":"ts-node sample-server.ts","prepublishOnly":"tsc"},"_npmUser":{"name":"jtary","email":"joseph.tary@gmail.com"},"_npmVersion":"8.8.0","description":"This proxy server seamlessly accepts client certificates and keys to forward upstream.","directories":{},"_nodeVersion":"18.1.0","dependencies":{"ws":"^8.7.0","jest":"^28.1.0","pump":"^3.0.0","axios":"^0.27.2","http2":"^3.3.7","semver":"^7.3.7","undici":"^5.4.0","fastify":"^3.29.0","ts-jest":"^28.0.3","ts-node":"^10.8.0","typescript":"^4.7.4","@types/jest":"^27.5.1","end-of-stream":"^1.4.4","fastify-plugin":"^3.0.1","@fastify/reply-from":"^7.0.1"},"_hasShrinkwrap":false,"devDependencies":{"@types/ws":"^8.5.3","@types/pump":"^1.1.1","@types/semver":"^7.3.9","@types/end-of-stream":"^1.4.1"},"_npmOperationalInternal":{"tmp":"tmp/fastify-mtls-proxy_1.1.0_1660759082650_0.18628830482472236","host":"s3://npm-registry-packages"}},"1.1.1":{"name":"@akashnetwork/fastify-mtls-proxy","version":"1.1.1","license":"MIT","_id":"@akashnetwork/fastify-mtls-proxy@1.1.1","maintainers":[{"name":"corysturtevant","email":"cory@akash.network"},{"name":"jtary","email":"joseph.tary@gmail.com"}],"dist":{"shasum":"84fd1a84fe2f9e5313b3505fb0d01938dc4574f8","tarball":"https://registry.npmjs.org/@akashnetwork/fastify-mtls-proxy/-/fastify-mtls-proxy-1.1.1.tgz","fileCount":10,"integrity":"sha512-qdhnVSpwmxfQLS9RmTj59g7ne5OSR3QbqzOM2A2qRB0P3qEjeFO81u5C12xX/HUQ+SPQFY9cDBI6JCJHpr7GxQ==","signatures":[{"sig":"MEYCIQDFsi6O633bZv7+WJvPnXG+/Z0Zjkj9Hh65unr1Kgmz4wIhAOMSRVi3FnMFBERrkBLiWUib4taSkr94VRWxpv25jxzd","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":168814,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi/TlTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmotBg//VDzcHBKulf8gt+FjqAUv58F4uoyOoQnQai8w+zACItnmb4+O\r\n+7+st5r26wP/PaLsGnTGTFenf16oE0E2icpbrQsAtFvfcBDkMfvBR+JQfZQR\r\n58ZsBoWrLRx9p8k+NoBNZ6yaau4V1gbvHnsBihngGZL1zYuEOH8NY2T8WUcO\r\ngkhP7EbYbb02zZvsGtThGN0lubb6ZecARxRLWxSZkwnS2Tj4CKwoHAnnpiDn\r\n4mURNjoNzBaNHr6JBek2MjRltx1SH9Ci5/MrcmveDNapMvJhJ7mMbdCpVr1T\r\nG2Q09YuOeBA+B9igSP5BKkGvExCklC0bQgFjn+Kh7Ij/Yqky20ZWDkSxsT99\r\nh5pb6+bUXJIuFiPDiTBlXSmjqRr5L6cGJO3nzEHDj1o0fZ/UE7E/a1aIxfjH\r\n19ae8EJlFTwB4FAksuoJFaUL3r1zomjOJsohsb6zibUaoltdLkTydMl2xP5u\r\nmC84K0ZdP9BvObeT0UwQpf/oJQdtQSyAq+Wrw08JtZyXRr0HZjMHTpi/IN6C\r\nc6BOQLGDDLHQdQeumExQnHP9PnbZejvAtkNAkjKb1FjD1nEElxpE/IA03QpC\r\n+A/bSki0YM2FKtFpFalWReZ+muCZp9JwfVZqp677nEhWzgYcUd8LgbqcjnI4\r\njK+dZt7pRTsXJcZLRcUUQ5cu7/vCqipmt5k=\r\n=vc8L\r\n-----END PGP SIGNATURE-----\r\n"},"main":"src/index.js","scripts":{"test":"jest","start":"ts-node sample-server.ts","prepublishOnly":"tsc"},"_npmUser":{"name":"jtary","email":"joseph.tary@gmail.com"},"description":"This proxy server seamlessly accepts client certificates and keys to forward upstream.","directories":{},"dependencies":{"ws":"^8.7.0","jest":"^28.1.0","pump":"^3.0.0","axios":"^0.27.2","http2":"^3.3.7","semver":"^7.3.7","undici":"^5.4.0","fastify":"^3.29.0","ts-jest":"^28.0.3","ts-node":"^10.8.0","typescript":"^4.7.4","@types/jest":"^27.5.1","end-of-stream":"^1.4.4","fastify-plugin":"^3.0.1","@fastify/reply-from":"^7.0.1"},"_hasShrinkwrap":false,"devDependencies":{"@types/ws":"^8.5.3","@types/pump":"^1.1.1","@types/semver":"^7.3.9","@types/end-of-stream":"^1.4.1"},"_npmOperationalInternal":{"tmp":"tmp/fastify-mtls-proxy_1.1.1_1660762451294_0.7209340323305267","host":"s3://npm-registry-packages"}},"1.1.2":{"name":"@akashnetwork/fastify-mtls-proxy","version":"1.1.2","license":"MIT","_id":"@akashnetwork/fastify-mtls-proxy@1.1.2","maintainers":[{"name":"corysturtevant","email":"cory@akash.network"},{"name":"jtary","email":"joseph.tary@gmail.com"}],"dist":{"shasum":"84c2d7be1a1fbb501a704f7d3410cfacac8dd9d5","tarball":"https://registry.npmjs.org/@akashnetwork/fastify-mtls-proxy/-/fastify-mtls-proxy-1.1.2.tgz","fileCount":10,"integrity":"sha512-WYvWZ40Bw70TKKBUw85y3SGtsJLvKoxOK45Pn5V6XjOlpPiLXUfSmyw7Io97UgGtx1x0Nrrz1Ziiw1iLv6lGQA==","signatures":[{"sig":"MEYCIQC1d/cxqlorNR8cDf/tsBPsiYn7sdMx7YaCB7fd1n2u0QIhAL86gXyisXRqWw2bZcTEw1u6KtEf2v1UC9zqHQPBxdww","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":168809,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi/VNaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmosFQ//XPq6eVdQQdt2ZwxOFTqrxH+WIKGdYJzIl0HMA2Yl9q2d7V5j\r\nR8VYk+qX8wNAFddrunCcGd6PFLWsNLHJGWCmwf2g+FaTxzCT4BUF2JyM3j1t\r\nIgIdrmgJCEvjwGynzmMwrLqfFpWxO9e8MrxmjMah8m1YwcppZtQCIsv5ZVms\r\ni4OGXr3mNf0rQjyM6MXxRAtGRBfHvmJf+oAhmtKxV8MHXEnSyoz5/T+RitK9\r\nXAA8uXbpjLaWk2qy0tueLAeit73r46iTNN+QENa8sNjahGHXNmoP5BhHBAge\r\nXA8oxDrlqu/ude5JqB0caBsF+cikMLHPlgy0ohg2WZbzT/g/vqfki48YRKjV\r\nEGlHqeuFwuhadcEqklL+zTcs3z/uFwkcd4RiylO5jK5b0Bdoq08z00VsC43C\r\nb8QEDslslwmvSNFlJDWwuqVsjZqF2KUbcVQ6DX9Hc8nDq3Rf/RgH4WsKtrCi\r\nsxQdDT9uU3gYo5SRamKfYUBrPpoiXokI3gTYZyFWO2BZAHQ1vf3/20ZI5YT7\r\n3xMPU5qxlRCdwa4oY7y1tVi8te74iu26LvuvaBOODc+FXxLQCJSej65zO/WU\r\nGznvP1wHePVVYvozZqQf42CwTN8INg/E9nAmpfClDQZVa21Nkko9PLWpkjBp\r\nNTpWaHrYPC6r9cLotooMXwGq14TkU0J9/5A=\r\n=llm6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"src/index.js","scripts":{"test":"jest","start":"ts-node sample-server.ts","prepublishOnly":"tsc"},"_npmUser":{"name":"jtary","email":"joseph.tary@gmail.com"},"description":"This proxy server seamlessly accepts client certificates and keys to forward upstream.","directories":{},"dependencies":{"ws":"^8.7.0","jest":"^28.1.0","pump":"^3.0.0","axios":"^0.27.2","http2":"^3.3.7","semver":"^7.3.7","undici":"^5.4.0","fastify":"^3.29.0","ts-jest":"^28.0.3","ts-node":"^10.8.0","typescript":"^4.7.4","@types/jest":"^27.5.1","end-of-stream":"^1.4.4","fastify-plugin":"^3.0.1","@fastify/reply-from":"^7.0.1"},"_hasShrinkwrap":false,"devDependencies":{"@types/ws":"^8.5.3","@types/pump":"^1.1.1","@types/semver":"^7.3.9","@types/end-of-stream":"^1.4.1"},"_npmOperationalInternal":{"tmp":"tmp/fastify-mtls-proxy_1.1.2_1660769114453_0.0909720045717557","host":"s3://npm-registry-packages"}}},"time":{"created":"2022-08-17T17:58:02.591Z","modified":"2025-09-30T13:29:17.511Z","1.1.0":"2022-08-17T17:58:02.849Z","1.1.1":"2022-08-17T18:54:11.461Z","1.1.2":"2022-08-17T20:45:14.693Z"},"license":"MIT","description":"This proxy server seamlessly accepts client certificates and keys to forward upstream.","maintainers":[{"email":"cory@akash.network","name":"corysturtevant"},{"email":"yaroslav.grishajev@akash.network","name":"ygrishajev.akash"},{"email":"maxime.beauchamp@akash.network","name":"baktun14"},{"email":"serhii@akash.network","name":"serhii_akash"}],"readme":"# @akashnetwork/fastify-mtls-proxy\n\nThis proxy server seamlessly accepts client certificates and keys to forward upstream.\n\n## why?\n\nIn secure environments such as browsers, self signed certificates are not honored to ensure that certificate authorities are vetted and thus ideally those using certificates are subject to some form of regulation.\n\nHowever with-in self managed `mTLS` environments, self signed certificates make much sense to validate the client application's commands are under control of the client party and not snarfed by a `mitm`. The ability to generate `x509` certificates through `Subtle.crypto` means the progression of continued security at the user custody level.\n\nThis server allows that communication to easily facilitate. Using natural `proxy forwarding` requests can use a traditional proxy model, supported by libraries like `Axios`, `curl` and others.\n\n### quick setup\n\ninstall the package\n\n```bash\nyarn add @akashnetwork/fastify-mtls-proxy\n```\n\nsetup the server to receive mTLS requests to forward.\n\n```typescript\nimport fastify from \"fastify\";\nimport mTLSProxyPlugin, { Options } from \"@dmikey/fastify-mtls-proxy\";\n\nconst app = fastify();\napp.register(mTLSProxyPlugin, {} as Options);\n```\n\n### how to use\n\nSend a request to your server as you would to the original upstream. Specify `proxy_cert` and `proxy_key` in the post body.\n\nbash using `curl`\n\n```bash\ncurl --proxy \"http://localhost:3000\" \"http://www.httpbin.org/ip\"\n```\n\nor to make a secure request over the insecure proxy\n\n```bash\ncurl --proxy-insecure \"http://localhost:3000\" \"https://www.google.com\"\n```\n\ntypescript using the `axios` library\n\n```typescript\nimport axios from \"axios\";\n\naxios\n  .post(\"http://localhost:3000/ip\", {\n    headers: {\n      host: \"http://www.httpbin.org/\",\n    },\n  })\n  .then(function (response) {\n    console.log(response);\n  })\n  .catch(function (error) {\n    console.log(error);\n  });\n```\n\nIf you can not modify the headers, and can only modify the host of the platform you are trying to proxy through, using a `query string` parameter is available.\n\n```bash\ncurl \"http://localhost:3000/ip?upstream=http://httpbin.org/ip\"\ncurl \"http://localhost:3000/ip?upstream=https://www.httpbin.org\"\n```\n\nSending `mTLS` connection information along with the upstream request.\n\n```javascript\nimport axios from \"axios\";\n\naxios\n  .post(\"http://localhost:3000/\", {\n    headers: {\n      host: \"https://certauth.cryptomix.com\",\n    },\n  })\n  .then(function (response) {\n    console.log(response);\n  })\n  .catch(function (error) {\n    console.log(error);\n  });\n```\n\n### how pathing works\n\nWhen using a requesting a resource, the pathing should be requested from the proxy.\n\nExample a resource that is available at `http://foo.com/my-resource` would be requested as `http://proxy.com/my-resource?upstream=http://foo.com/my-resource`\n\n### advanced configuration\n\nusing the `Options` type, you can define\n\n### thanks\n\nto the original work by all the contributors to the original modules.\n","readmeFilename":"README.md"}