{"_id":"@alex-bl/next-authentication","_rev":"1-5b2021475bde2492c856c064e8a0509c","name":"@alex-bl/next-authentication","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@alex-bl/next-authentication","version":"1.0.0","description":"An authentication library for Next.js","repository":{"type":"git","url":"git+https://github.com/iaincollins/next-auth.git"},"main":"index.js","scripts":{"build":"rollup --config","prepare":"rollup --config"},"author":{"name":"Alex"},"license":"ISC","sideEffects":false,"dependencies":{"babel-core":"^6.26.3","babel-polyfill":"^6.26.0","body-parser":"^1.18.2","express":"^4.16.3","express-session":"^1.15.6","isomorphic-fetch":"^2.2.1","lusca":"^1.6.0","passport":"^0.4.0","rollup-plugin-babel":"^3.0.7","uuid":"^3.2.1"},"devDependencies":{"babel-plugin-external-helpers":"^6.22.0","babel-preset-env":"^1.7.0","bl":"^2.1.2","rollup":"^0.67.4","rollup-plugin-commonjs":"^9.1.3","rollup-plugin-json":"^3.0.0","rollup-plugin-node-builtins":"^2.1.2","rollup-plugin-node-resolve":"^3.3.0","semver":"^5.6.0"},"gitHead":"7ce94fe3481c8e0edb231951ae7464cda0c1347e","bugs":{"url":"https://github.com/iaincollins/next-auth/issues"},"homepage":"https://github.com/iaincollins/next-auth#readme","_id":"@alex-bl/next-authentication@1.0.0","_nodeVersion":"11.13.0","_npmVersion":"6.9.0","dist":{"integrity":"sha512-plKYS+uZCsPGn+7dZb3V7/T+/21R7c7eMT6W4Q8sd0y3d05FdwvjwaHj63YhEDeJcvb+gTLE2DmkXZ+4b/DDDg==","shasum":"546aa1cdc0ae46221771e45610fce3eeb6647954","tarball":"https://registry.npmjs.org/@alex-bl/next-authentication/-/next-authentication-1.0.0.tgz","fileCount":29,"unpackedSize":398857,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJc83tjCRA9TVsSAnZWagAAYwIP/RZc65jMnZRGPtblpsac\nfHRtHOvFWNlXTLV8Wm4KJiPOjklpyUc9A3LgET7gvNTFog8qHTEaSUndKnby\npHuaKhurKqDvrofPNwKYKDnLQVoXlzL6azxsuD009AFEWkXFTw0RRJk3nLkx\nMak0TpPYfo3lBMgAaYt9aLkc6Z+jeDm566G/OVCqLI43hmBYzkuCFIPq/9tW\nyYO5TUBXg/LFU+/qfW6Xl+++++FskH0HxcoJ4fwJ3pw+A1Ei13d1vRZfDVH3\ndoIPuAapAFk55Yvr7r8Px6bVm4eVVaX7NZL4JtTdBgSkD9VClnvllxyFeyvk\nkK++L9EqGLdEzdx2hFPiag4R8bjq9gBHHRWwWhefYjwHLDR8UZwJ8NuEGakm\nxKq+JCiLVKHm7hLOwARO76UXhDhYiHjFyFkdiygbrC/2ciWlSbL2KgknWeEq\nptt1Lnex3o7aQDFRU09kuLraPsyucLm08Ybf/nU0n7enB99fnQi4QcWuaRU0\nTwQ8I+cN8ZnqmdDS73tAwZ/9XRzjwJdmGnlTS+GY3LDeHWzBu/LRMx55Tjed\nS5kxv9/KRX0cj959waH/HTasNZNqRKy00Ua9nLiqeN6/kqe1WK5EyYC5GQCh\nT58GdCeapmnj8penPV8F3AdPOiu7XJvbA9xX/T32wdThdKJ7R9Vv8LCDME4p\njAsY\r\n=7YZx\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGRHJu9YpCUhibDZN7vl4R2xPJrUe8sLr42v4gYQAbHqAiAJmoosTAU9uuqpTY3i9bLmBxS+CUN7ZLwWemvyi7xisA=="}]},"maintainers":[{"name":"alex-bl","email":"ialexi.jhc@gmail.com"}],"_npmUser":{"name":"alex-bl","email":"ialexi.jhc@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/next-authentication_1.0.0_1559460706405_0.15103862266902301"},"_hasShrinkwrap":false}},"time":{"created":"2019-06-02T07:31:46.372Z","1.0.0":"2019-06-02T07:31:46.525Z","modified":"2022-04-04T12:38:19.509Z"},"maintainers":[{"name":"alex-bl","email":"ialexi.jhc@gmail.com"}],"description":"An authentication library for Next.js","homepage":"https://github.com/iaincollins/next-auth#readme","repository":{"type":"git","url":"git+https://github.com/iaincollins/next-auth.git"},"author":{"name":"Alex"},"bugs":{"url":"https://github.com/iaincollins/next-auth/issues"},"license":"ISC","readme":"# NextAuth\r\n\r\n## About NextAuth\r\n\r\nNextAuth is an authentication library for Next.js projects.\r\n\r\nThe NextAuth library uses Express and Passport, the most commonly used authentication library for Node.js, to provide support for signing in with email and with services like Facebook, Google and Twitter.\r\n\r\nNextAuth adds Cross Site Request Forgery (CSRF) tokens and HTTP Only cookies, supports universal rendering and does not require client side JavaScript.\r\n\r\nIt adds session support without using client side accessible session tokens, providing protection against Cross Site Scripting (XSS) and session hijacking, while leveraging localStorage where available to cache non-critical session state for optimal performance in Single Page Apps.\r\n\r\nThe NextAuth comes with a client library, designed to work with React pages powered by Next.js to easily add universal session support to sites.\r\n\r\nIt contains an [example site](https://github.com/iaincollins/next-auth/tree/master/example) that shows how to use it in a simple project. It's also used in the [nextjs-starter.now.sh](https://nextjs-starter.now.sh) project, which provides a more complete example with a live demo.\r\n\r\nNote: As of version 1.5 NextAuth is also compatible non-Next.js React projects, just pass `null` instead of a nextApp instance when calling `nextAuth()`.\r\n\r\nYou will need to handle setting up routes before and after initialising NextAuth if you are not using Next.js. NextAuth lets you pass an instance of express as 'expressApp' option (and returns it in the response).\r\n\r\n## Example Client Usage\r\n\r\n````javascript\r\nimport React from 'react'\r\nimport { NextAuth } from 'next-auth/client'\r\n\r\nexport default class extends React.Component {\r\n  static async getInitialProps({req}) {\r\n    return {\r\n      session: await NextAuth.init({req})\r\n    }\r\n  }\r\n  render() {\r\n    if (this.props.session.user) {\r\n      return(\r\n        <div>\r\n          <p>You are logged in as {this.props.session.user.name || this.props.session.user.email}.</p>\r\n        </div>\r\n        )\r\n    } else {\r\n      return(\r\n        <div>\r\n          <p>You are not logged in.</p>\r\n        </div>\r\n      )\r\n    }\r\n  }\r\n}\r\n````\r\n\r\nSee [Documentation for the NextAuth Client](https://github.com/iaincollins/next-auth/blob/master/README-CLIENT.md) for more information on how to interact with the client.\r\n\r\n## Routes\r\n\r\nNextAuth adds a number of routes under `/auth':\r\n\r\n* POST `/auth/email/signin` - Request Sign In Token\r\n* GET `/auth/email/signin/:token` - Validate Sign In Token\r\n* POST `/auth/signout` - Sign Out\r\n* GET `/auth/csrf` - CSRF endpoint for Single Page Apps\r\n* GET `/auth/session` - Session endpoint for Single Page Apps\r\n* GET `/auth/linked` - View linked accounts for Single Page Apps\r\n\r\nAll POST routes request must include a CSRF token.\r\n\r\nCSRF, Session and Linked Account endpoints are provided for Single Page Apps.\r\n\r\nNote: Session Tokens are stored in HTTP Only cookies to prevent session hijacking and protect against Cross Site Scripting (XSS) attacks. Only HTTP requests that originate from the original domain are able to read from them.\r\n\r\nIn addition, it will add the following routes for each oAuth provider currently configured:\r\n\r\n* GET `/auth/oauth/${provider}`\r\n* GET `/auth/oauth/${provider}/callback`\r\n* POST `/auth/oauth/${provider}/unlink`\r\n\r\nYou can see which routes are configured and the callback URLs defined for them via this route:\r\n\r\n* GET `/auth/providers`\r\n\r\nIt will return a JSON object with the current oAuth provider configuration:\r\n\r\n````json\r\n{\r\n  \"Facebook\": {\r\n    \"signin\": \"/auth/oauth/facebook\",\r\n    \"callback\": \"/auth/oauth/facebook/callback\"\r\n  },\r\n  \"Google\": {\r\n    \"signin\": \"/auth/oauth/google\",\r\n    \"callback\": \"/auth/oauth/google/callback\"\r\n  },\r\n  \"Twitter\": {\r\n    \"signin\": \"/auth/oauth/twitter\",\r\n    \"callback\": \"/auth/oauth/twitter/callback\"\r\n  }\r\n}\r\n````\r\n\r\nNote: The `/auth` prefix is configurable via an option in the module, but it is currently hard coded in the client component, so you probably don't want to change it. It will be configurable in future releases.\r\n\r\n## Getting Started\r\n\r\nCreate an `index.js` file in the root of your Next.js project containing the following:\r\n\r\n````javascript\r\nconst next = require('next')\r\nconst nextAuth = require('next-auth')\r\nconst nextAuthConfig = require('./next-auth.config')\r\n\r\nrequire('dotenv').load()\r\n\r\nconst nextApp = next({\r\n  dir: '.',\r\n  dev: (process.env.NODE_ENV === 'development')\r\n})\r\n\r\nnextApp.prepare()\r\n.then(async () => {\r\n  const nextAuthOptions = await nextAuthConfig()\r\n  const nextAuthApp = await nextAuth(nextApp, nextAuthOptions)  \r\n  console.log(`Ready on http://localhost:${process.env.PORT || 3000}`)\r\n})\r\n.catch(err => {\r\n  console.log('An error occurred, unable to start the server')\r\n  console.log(err)\r\n})\r\n````\r\n\r\nYou can add the following to your `package.json` file to start the project:\r\n\r\n````json\r\n\"scripts\": {\r\n  \"dev\": \"NODE_ENV=development node index.js\",\r\n  \"build\": \"next build\",\r\n  \"start\": \"node index.js\"\r\n}\r\n````\r\n\r\n## Pages\r\n\r\nYou will need to create following pages under `./pages/auth` in your project:\r\n\r\n* index.js – Sign In and Link/Unlink accounts\r\n* error.js – If an authentication error occurs\r\n* check-email.js – 'Check your email' messsage\r\n* callback.js – Callback page; updates local session on sign in / sign out\r\n\r\nYou can [find examples of these](https://github.com/iaincollins/next-auth/tree/master/example) included which you can copy and paste into your project.\r\n\r\n## Configuration\r\n\r\nConfiguration can be split across three files to make it easier to understand and manage.\r\n\r\nYou can copy over the following configuration files into the root of your project to get started:\r\n\r\n* [next-auth.config.js](https://github.com/iaincollins/next-auth/tree/master/example/next-auth.config.js)\r\n* [next-auth.functions.js](https://github.com/iaincollins/next-auth/tree/master/example/next-auth.functions.js)\r\n* [next-auth.providers.js](https://github.com/iaincollins/next-auth/tree/master/example/next-auth.providers.js)\r\n\r\n\r\nYou can also add a **.env** file to the root of the project as a place to specify configuration options. The provided example files for NextAuth will use one if there is is one.\r\n\r\n````\r\nSERVER_URL=http://localhost:3000\r\nMONGO_URI=mongodb://localhost:27017/my-database\r\nFACEBOOK_ID=\r\nFACEBOOK_SECRET=\r\nGOOGLE_ID=\r\nGOOGLE_SECRET=\r\nTWITTER_KEY=\r\nTWITTER_SECRET=\r\nEMAIL_FROM=username@gmail.com\r\nEMAIL_SERVER=smtp.gmail.com\r\nEMAIL_PORT=465\r\nEMAIL_USERNAME=username@gmail.com\r\nEMAIL_PASSWORD=\r\n````\r\n\r\n### next-auth.config.js\r\n\r\nBasic configuration of NextAuth is handled in **next-auth.config.js**.\r\n\r\nIt is also where the **next-auth.functions.js** and **next-auth.providers.js** files are loaded.\r\n\r\n### next-auth.functions.js\r\n\r\nMethods for user management and sending email are defined in **next-auth.functions.js**\r\n\r\nThe example configuration provided is for Mongo DB. By defining the behaviour in these functions you can use NextAuth with any database, including a relational database that uses SQL.\r\n\r\n#### Required\r\n\r\n* find({id,email,emailToken,provider})\r\n* insert(user, oAuthProfile, providerParams)\r\n* update(user, oAuthProfile, providerParams)\r\n* remove(id)\r\n* serialize(user)\r\n* deserialize(id)\r\n\r\n#### Optional\r\n\r\n* sendSigninEmail({email, url, req})\r\n* signIn({form, req})\r\n\r\nThe `sendSigninEmail()` method is used to send an email for email token based sign in (one time use passwords). Omit it or set it to null to disable email based sign in.\r\n\r\nThe `signIn()` method is used to handle authenticating with custom credentials (e.g. username and password, 2FA token, etc). Omit it or leave it undefined unless you need it.\r\n\r\nYou can use any combination of authentication methods (email, credentials, oAuth providers).\r\n\r\n### next-auth.providers.js \r\n\r\nConfiguration for oAuth providers are defined in **next-auth.functions.js**\r\n\r\nIt includes configuration examples for Facebook, Google and Twitter oAuth, which can easily be copied and replicated to add support for signing in other oAuth providers.\r\n\r\nFor tips on configuring oAuth see [AUTHENTICATION.md](https://github.com/iaincollins/next-auth/tree/master/AUTHENTICATION.md).\r\n\r\n---- \r\n\r\nSee the included [example site](https://github.com/iaincollins/next-auth/tree/master/example) and the expanded example at [nextjs-starter.now.sh](https://nextjs-starter.now.sh/examples/authentication).\r\n","readmeFilename":"README.md"}