{"_id":"@aller/openid-connect","_rev":"13-52ab6fa5b7896c4859cb85056c7762a8","name":"@aller/openid-connect","dist-tags":{"latest":"0.3.2"},"versions":{"0.0.1":{"name":"@aller/openid-connect","version":"0.0.1","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","_id":"@aller/openid-connect@0.0.1","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"homepage":"https://github.com/allermedia/openid-connect","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"c8237f69f43d5a537c2e76cd887028b68a3ba65b","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.0.1.tgz","fileCount":26,"integrity":"sha512-HlvATEB+XVnywroMCYMwBIFddNgbCzEzT6P7wp7PIGl2zEj5RV9gVKObSTT2Yn7FUY+blPQ7IP6zp94rQiJBmQ==","signatures":[{"sig":"MEQCIDKZSSOA7fym+Tc96Cs+v4Y+A9GCnr8TwUIqUhV9AVTxAiAoxpZOlDRfoH3Gs73uW9IO3xGiAm7cuA93795T3ecxrA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":192642},"main":"./lib/index.cjs","type":"module","types":"./types/index.d.ts","module":"./src/index.js","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js","require":"./lib/index.cjs"}},"gitHead":"b5fdf31820bfda45ec9a99a2bbff1c49bbeabbe4","scripts":{"lint":"eslint . --cache && prettier . -c","test":"mocha --max-http-header-size=16384","build":"rollup -c && dts-buddy","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run lint && npm run build","test:lcov":"c8 -n src -r lcov -r text mocha"},"_npmUser":{"name":"paed01","email":"pal.edman@outlook.com"},"deprecated":"encryption and signature deterioration","repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"10.9.4","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"joi":"^18.0.2","jose":"^6.1.3","debug":"^4.4.1","cookie":"^1.1.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^11.0.0","tsd":"^0.33.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","sinon":"^21.0.1","eslint":"^9.31.0","rollup":"^4.59.0","express":"^5.2.1","prettier":"^3.6.2","dts-buddy":"^0.7.0","supertest":"7.2.2","typescript":"^5.8.3","@types/node":"^22.19.10","@types/debug":"^4.1.12","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/on-headers":"^1.0.4","@rollup/plugin-json":"^6.1.0","eslint-plugin-import":"^2.32.0","@rollup/plugin-commonjs":"^29.0.0","@rollup/plugin-node-resolve":"^16.0.3"},"peerDependencies":{"express":">= 4.17.0","body-parser":"2.x","on-finished":"2.x"},"_npmOperationalInternal":{"tmp":"tmp/openid-connect_0.0.1_1773148608458_0.633397204685934","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"@aller/openid-connect","version":"0.0.2","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","_id":"@aller/openid-connect@0.0.2","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"homepage":"https://github.com/allermedia/openid-connect","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"47ab2afbd64dbc1970c40a30661db1ec5b71912e","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.0.2.tgz","fileCount":25,"integrity":"sha512-xQBf++t88KrncXGfQCMvt698mQyEEklnoZZnXKTsAy1/LSX7sDhy/wJ1/lmCZGCfzOr5+WrMuLS4ZZNctOAzpA==","signatures":[{"sig":"MEUCICFJPJ9DXuVnmt5iQP8VOtazjQY+HBag/CoBdJvtAIDdAiEAomUULnZw0ZL19e8y9XffNd6y2Dnc9cQbYaf63FRl5+U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aller%2fopenid-connect@0.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":190811},"main":"./lib/index.cjs","type":"module","types":"./types/index.d.ts","module":"./src/index.js","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js","require":"./lib/index.cjs"}},"gitHead":"829d8ecc42016edfc27c4e8bcd9847c8e66a09e8","scripts":{"lint":"eslint . --cache && prettier . -c","test":"mocha --max-http-header-size=16384","build":"rollup -c && dts-buddy","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run lint && npm run build","test:lcov":"c8 -n src -r lcov -r text mocha"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b8e4a41f-740a-45a3-a0f1-b00d29f2ac02"}},"deprecated":"encryption and signature deterioration","repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"11.11.0","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"joi":"^18.0.2","jose":"^6.1.3","debug":"^4.4.1","cookie":"^1.1.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^11.0.0","tsd":"^0.33.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","sinon":"^21.0.1","eslint":"^9.31.0","rollup":"^4.59.0","express":"^5.2.1","prettier":"^3.6.2","dts-buddy":"^0.7.0","supertest":"7.2.2","typescript":"^5.8.3","@types/node":"^22.19.10","@types/debug":"^4.1.12","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/on-headers":"^1.0.4","@rollup/plugin-json":"^6.1.0","eslint-plugin-import":"^2.32.0","@rollup/plugin-commonjs":"^29.0.0","@rollup/plugin-node-resolve":"^16.0.3"},"peerDependencies":{"express":">= 4.17.0","body-parser":"2.x","on-finished":"2.x"},"_npmOperationalInternal":{"tmp":"tmp/openid-connect_0.0.2_1773148952896_0.40964782654003273","host":"s3://npm-registry-packages-npm-production"}},"0.0.3":{"name":"@aller/openid-connect","version":"0.0.3","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","_id":"@aller/openid-connect@0.0.3","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"homepage":"https://github.com/allermedia/openid-connect","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"d2f24dc44b575d6a760afb653fc26b05b7bcf6b3","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.0.3.tgz","fileCount":25,"integrity":"sha512-AnVkEw/V9MqjeNKADNY8zZ2G4d6qhKazqxL2aYdDiARMFOpO9ZHKL67dsTliqq2guqDTCjGb+fmfr6q/HPK8Pg==","signatures":[{"sig":"MEYCIQCzlPmufIQtr3rT52qjW4WP9fQUIMdYl/gfiUGRKK1wOQIhAJT70FNvu/ReGNKgvYyFdi6z/HQYtOsNlf2wLY8F7hdU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aller%2fopenid-connect@0.0.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":190092},"main":"./lib/index.cjs","type":"module","types":"./types/index.d.ts","module":"./src/index.js","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js","require":"./lib/index.cjs"}},"gitHead":"48a8c4b9a4eefcaa5404da161443bb583fe1cabe","scripts":{"lint":"eslint . --cache && prettier . -c","test":"mocha --max-http-header-size=16384","build":"rollup -c && dts-buddy","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run lint && npm run build","test:lcov":"c8 -n src -r lcov -r text mocha"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b8e4a41f-740a-45a3-a0f1-b00d29f2ac02"}},"repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"11.11.1","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"joi":"^18.0.2","debug":"^4.4.1","cookie":"^1.1.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^11.0.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","eslint":"^9.31.0","rollup":"^4.59.0","express":"^5.2.1","jose-v2":"npm:jose@^2.0.7","prettier":"^3.6.2","dts-buddy":"^0.7.0","supertest":"7.2.2","typescript":"^5.8.3","@types/node":"^22.19.10","@types/debug":"^4.1.12","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/on-headers":"^1.0.4","@rollup/plugin-json":"^6.1.0","eslint-plugin-import":"^2.32.0","@rollup/plugin-commonjs":"^29.0.0","@rollup/plugin-node-resolve":"^16.0.3"},"peerDependencies":{"jose":"6.x","express":">= 4.17.0"},"_npmOperationalInternal":{"tmp":"tmp/openid-connect_0.0.3_1773743853968_0.9931863933966352","host":"s3://npm-registry-packages-npm-production"}},"0.0.4":{"name":"@aller/openid-connect","version":"0.0.4","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","_id":"@aller/openid-connect@0.0.4","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"homepage":"https://github.com/allermedia/openid-connect","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"50cd33efd408cf77305063d121ec8c3aa5930e74","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.0.4.tgz","fileCount":25,"integrity":"sha512-p3PrAowAS8WjFRzlGSow0nICkaLhL6S3sZ02SRxbgjqXN4MCdXLakYeKOh5J6LBNcAZGTwgaM+Hbxo+BGQ31nA==","signatures":[{"sig":"MEUCIQCEhK485Ytr+d4k85vntTHxSWDrhebJ2RUFO3pozJpyTAIgNsgZIFD6UvBTd/WvV7eNgKSeQ+fCtWd7a7bPbPI4X84=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aller%2fopenid-connect@0.0.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":191909},"main":"./lib/index.cjs","type":"module","types":"./types/index.d.ts","module":"./src/index.js","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js","require":"./lib/index.cjs"}},"gitHead":"b7ec1dbe51ca8eab1bdd2bf1314287bf96c2208f","scripts":{"lint":"eslint . --cache && prettier . -c && npm run test:md","test":"mocha --max-http-header-size=16384","build":"rollup -c && dts-buddy","test:md":"texample","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run lint && npm run build","test:lcov":"c8 -n src -r lcov -r text mocha"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b8e4a41f-740a-45a3-a0f1-b00d29f2ac02"}},"repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"11.12.0","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"joi":"^18.0.2","debug":"^4.4.1","cookie":"^1.1.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^11.0.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","eslint":"^9.31.0","rollup":"^4.59.0","express":"^5.2.1","jose-v2":"npm:jose@^2.0.7","prettier":"^3.6.2","texample":"^0.1.0","dts-buddy":"^0.7.0","supertest":"7.2.2","typescript":"^5.8.3","@types/node":"^22.19.10","@types/debug":"^4.1.12","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/on-headers":"^1.0.4","@rollup/plugin-json":"^6.1.0","eslint-plugin-import":"^2.32.0","@rollup/plugin-commonjs":"^29.0.0","@rollup/plugin-node-resolve":"^16.0.3"},"peerDependencies":{"jose":"6.x","express":">= 4.17.0"},"_npmOperationalInternal":{"tmp":"tmp/openid-connect_0.0.4_1774254367933_0.7949810126119294","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@aller/openid-connect","version":"0.1.0","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","_id":"@aller/openid-connect@0.1.0","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"vnorvik","email":"vnorvik@gmail.com"},{"name":"robinwa","email":"robin.wasjo@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"homepage":"https://github.com/allermedia/openid-connect","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"f2b34afffd376db8bb1b8431614b47ca522d7e0b","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.1.0.tgz","fileCount":25,"integrity":"sha512-DqVho3T2zo05zE0G4J4w5JIsRwrCmgB7yGTuemPLP5JY2r83yN/kATRm2Qr5Ve3iOvf/UsgSebd1dHADKnn7Qg==","signatures":[{"sig":"MEYCIQDkIG+vdjZmx3srC/xScdDvJdTCBRoBqnhM7+wBPjD8ywIhALo9rQ1WhFHff39YJCB3aeq5xFbIP8vN2MbsbntPdHav","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aller%2fopenid-connect@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":113965},"type":"module","types":"./types/index.d.ts","module":"./src/index.js","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js"}},"gitHead":"6851a0c399e628a6044c4babc23e8365b2d3b05d","scripts":{"lint":"eslint . --cache && prettier . -c && npm run test:md","test":"mocha --max-http-header-size=16384","build":"dts-buddy","test:md":"texample","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run lint && npm run build","test:lcov":"c8 -n src -r lcov -r text mocha"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b8e4a41f-740a-45a3-a0f1-b00d29f2ac02"}},"overrides":{"mocha":{"yargs":"^18.1.0"}},"repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"12.0.2","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"joi":"^18.0.2","debug":"^4.4.1","cookie":"^2.0.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^12.0.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","eslint":"^10.3.0","express":"^5.2.1","globals":"^17.6.0","jose-v2":"npm:jose@^2.0.7","prettier":"^3.6.2","texample":"^1.0.0","dts-buddy":"^0.8.0","supertest":"7.2.2","@eslint/js":"^10.0.1","@types/chai":"^5.2.3","@types/node":"^22.19.17","memorystore":"^1.6.8","@types/debug":"^4.1.12","@types/mocha":"^10.0.10","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/supertest":"^7.2.1","@types/on-headers":"^1.0.4","eslint-plugin-perfectionist":"^5.9.0"},"peerDependencies":{"jose":"6.x","express":">= 4.17.0"},"_npmOperationalInternal":{"tmp":"tmp/openid-connect_0.1.0_1785402253585_0.5728619887645534","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@aller/openid-connect","version":"0.2.0","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","_id":"@aller/openid-connect@0.2.0","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"vnorvik","email":"vnorvik@gmail.com"},{"name":"robinwa","email":"robin.wasjo@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"homepage":"https://github.com/allermedia/openid-connect","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"8d1bb847a28a343b510f6721bf8445e2050cf75e","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.2.0.tgz","fileCount":27,"integrity":"sha512-mCDh51pJY5ogXXA1Qp0D9PJ8V3mS26xeCO4xKi3AFzcF4Btvl66reXbiGaG8qh1AlZcko75CJHLb3y4V/9vQeA==","signatures":[{"sig":"MEUCIQCD022gWu3mSS1mBOTTXXITJDEVotnZXAWBTQUBiHbtXQIgK2+CwBnbifA4fvvNNOrnRUE+QCeIwg4p5Or1/VcaNSM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aller%2fopenid-connect@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":123894},"type":"module","types":"./types/index.d.ts","module":"./src/index.js","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js"}},"gitHead":"25a195a26c4548793ff8c04b39f0eaa3f756fc20","scripts":{"lint":"eslint . --cache && prettier . -c && npm run test:md","test":"mocha --max-http-header-size=16384","build":"dts-buddy","test:md":"texample","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run lint && npm run build","test:lcov":"c8 -n src -r lcov -r text mocha"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b8e4a41f-740a-45a3-a0f1-b00d29f2ac02"}},"overrides":{"mocha":{"yargs":"^18.1.0"}},"repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"12.0.2","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"joi":"^18.0.2","debug":"^4.4.1","cookie":"^2.0.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^12.0.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","eslint":"^10.3.0","express":"^5.2.1","globals":"^17.6.0","jose-v2":"npm:jose@^2.0.7","prettier":"^3.6.2","texample":"^1.0.0","dts-buddy":"^0.8.0","supertest":"7.2.2","@eslint/js":"^10.0.1","@types/chai":"^5.2.3","@types/node":"^22.19.17","memorystore":"^1.6.8","@types/debug":"^4.1.12","@types/mocha":"^10.0.10","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/supertest":"^7.2.1","@types/on-headers":"^1.0.4","eslint-plugin-perfectionist":"^5.9.0"},"peerDependencies":{"jose":"6.x","express":">= 4.17.0"},"_npmOperationalInternal":{"tmp":"tmp/openid-connect_0.2.0_1787558501078_0.9090519344249814","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aller/openid-connect","version":"0.3.0","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","_id":"@aller/openid-connect@0.3.0","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"vnorvik","email":"vnorvik@gmail.com"},{"name":"robinwa","email":"robin.wasjo@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"homepage":"https://github.com/allermedia/openid-connect","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"19a71d4318b1e96cd8ccf1cc30a1bcda80baba0d","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.3.0.tgz","fileCount":28,"integrity":"sha512-iDGZz1WYY4cc+w/O00xl0sB0ZaM0B7wzYJ5EgFtB7wqf36c3afu4za9sIy6uJ0UZuWc8l236zGxccHGsPM/EWg==","signatures":[{"sig":"MEUCIQCl2smlGlYGBddbHWkYy+DdxRGQ6zaTH0lbcNrAZftGswIgUtQ/UWPQ0t/iJN/pGZYSn1YywqIukFu6k89AGXBTwXw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aller%2fopenid-connect@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":139291},"type":"module","types":"./types/index.d.ts","module":"./src/index.js","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js"}},"gitHead":"2e34ef2b6806f2cf54ab062666dce29191c2b014","scripts":{"lint":"eslint . --cache && prettier . -c && npm run test:md","test":"mocha --max-http-header-size=16384","build":"dts-buddy","test:md":"texample","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run lint && npm run build","test:lcov":"c8 -n src -r lcov -r text mocha"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b8e4a41f-740a-45a3-a0f1-b00d29f2ac02"}},"overrides":{"mocha":{"yargs":"^18.1.0"}},"repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"12.0.2","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"joi":"^18.0.2","debug":"^4.4.1","cookie":"^2.0.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^12.0.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","eslint":"^10.3.0","express":"^5.2.1","globals":"^17.6.0","jose-v2":"npm:jose@^2.0.7","prettier":"^3.6.2","texample":"^1.0.0","dts-buddy":"^0.8.0","supertest":"7.2.2","@eslint/js":"^10.0.1","@types/chai":"^5.2.3","@types/node":"^22.19.17","memorystore":"^1.6.8","@types/debug":"^4.1.12","@types/mocha":"^10.0.10","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/supertest":"^7.2.1","@types/on-headers":"^1.0.4","eslint-plugin-perfectionist":"^5.9.0"},"peerDependencies":{"jose":"6.x","express":">= 4.17.0"},"_npmOperationalInternal":{"tmp":"tmp/openid-connect_0.3.0_1788337590540_0.4748697251201337","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@aller/openid-connect","version":"0.3.1","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","_id":"@aller/openid-connect@0.3.1","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"vnorvik","email":"vnorvik@gmail.com"},{"name":"robinwa","email":"robin.wasjo@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"homepage":"https://github.com/allermedia/openid-connect","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"1f2bf3af05d70c2359c1376d20ac1809bc251af8","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.3.1.tgz","fileCount":28,"integrity":"sha512-POquNLCvM5ZutwWFRtQDN9GDdYGcuu86/eQBOiLrTUM+/GSL6XoLjGageuuVjo4QT7EcXrdsfY3bGHO1odWy9w==","signatures":[{"sig":"MEUCIQCnNeeKpxSy2kTeoT0Fktk9clpFa8/J1tyOpgst4bMNDgIgdzS8Ycp6VSXaDADFU2nj8UfCuzTrZdFwlwXGIHU50BU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aller%2fopenid-connect@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":141069},"type":"module","types":"./types/index.d.ts","module":"./src/index.js","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js"}},"gitHead":"ccdc4c31586f7eb35c0ed618e6ce437cd031b9eb","scripts":{"lint":"eslint . --cache && prettier . -c && npm run test:md","test":"mocha --max-http-header-size=16384","build":"dts-buddy","test:md":"texample","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run lint && npm run build","test:lcov":"c8 -n src -r lcov -r text mocha"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b8e4a41f-740a-45a3-a0f1-b00d29f2ac02"}},"overrides":{"mocha":{"yargs":"^18.1.0"}},"repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"12.0.2","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"joi":"^18.0.2","debug":"^4.4.1","cookie":"^2.0.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^12.0.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","eslint":"^10.3.0","express":"^5.2.1","globals":"^17.6.0","jose-v2":"npm:jose@^2.0.7","prettier":"^3.6.2","texample":"^1.0.0","dts-buddy":"^0.8.0","supertest":"7.2.2","@eslint/js":"^10.0.1","@types/chai":"^5.2.3","@types/node":"^22.19.17","memorystore":"^1.6.8","@types/debug":"^4.1.12","@types/mocha":"^10.0.10","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/supertest":"^7.2.1","@types/on-headers":"^1.0.4","eslint-plugin-perfectionist":"^5.9.0"},"peerDependencies":{"jose":"6.x","express":">= 4.17.0"},"_npmOperationalInternal":{"tmp":"tmp/openid-connect_0.3.1_1788338617328_0.3369661224831795","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"_id":"@aller/openid-connect@0.3.2","bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"dist":{"shasum":"3b15a5a12f2c5ad07474f42f00ed7ca5255d97fd","tarball":"https://registry.npmjs.org/@aller/openid-connect/-/openid-connect-0.3.2.tgz","fileCount":29,"integrity":"sha512-VtkCX36QPVBclVmR3srpsk3JwL0yxIL/yW7/AkXuWQy6zPm7QkX+v0+TXmms5FrmgDAdLZKJsW58Eh6Y1JFdBA==","signatures":[{"sig":"MEQCIDOo/gqYEBwQuHF2/BLkfECtrYKyKh6mJRQ83uO56oqiAiAYxwZbkhFSUcXWHNWdNGS/3SuBABhRKighAiYH6EVK4g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICbH8zWuNbjmU3KSp+t1hvN3XXJ4NhI/hz9ZRatNkZn6AiBzhU9ooBl9DDJMw1DbVTLN5tO+Njw7dMFTdCKwuqWcRQ=="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aller%2fopenid-connect@0.3.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":158797},"name":"@aller/openid-connect","type":"module","types":"./types/index.d.ts","author":{"url":"https://github.com/allermedia","name":"Aller Media"},"module":"./src/index.js","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./types/index.d.ts","import":"./src/index.js"}},"gitHead":"5ab813f9868ccfc53156741eeb12e8c2f747c6c6","license":"MIT","scripts":{"toc":"toc README.md","lint":"eslint . --cache && prettier . -c","test":"mocha","build":"dts-buddy && npm run toc","prepack":"npm run build","test:md":"texample","cov:html":"c8 -n src -r html -r text mocha","posttest":"npm run build && npm run lint && npm run test:md","test:lcov":"c8 -n src -r lcov -r text mocha"},"version":"0.3.2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b8e4a41f-740a-45a3-a0f1-b00d29f2ac02"}},"homepage":"https://github.com/allermedia/openid-connect","overrides":{"mocha":{"yargs":"^18.1.0","serialize-javascript":"^7.1.0"}},"repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"_npmVersion":"12.0.2","description":"Express middleware to protect web applications using OpenID Connect.","directories":{},"maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"vnorvik","email":"vnorvik@gmail.com"},{"name":"robinwa","email":"robin.wasjo@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"_nodeVersion":"22.23.2","dependencies":{"joi":"^18.0.2","debug":"^4.4.1","cookie":"^2.0.1","on-headers":"^1.1.0","openid-client":"^6.8.1"},"_hasShrinkwrap":false,"devDependencies":{"c8":"^12.0.0","chai":"^6.2.2","nock":"^14.0.10","mocha":"^11.7.5","eslint":"^10.3.0","express":"^5.2.1","globals":"^17.6.0","jose-v2":"npm:jose@^2.0.7","prettier":"^3.6.2","texample":"^1.0.0","@0dep/toc":"^1.0.1","dts-buddy":"^0.8.0","supertest":"7.2.2","@eslint/js":"^10.0.1","@types/chai":"^5.2.3","@types/node":"^22.19.17","memorystore":"^1.6.8","@types/debug":"^4.1.12","@types/mocha":"^10.0.10","mocha-cakes-2":"^3.3.0","@types/express":"5.0.6","@types/supertest":"^7.2.1","@types/on-headers":"^1.0.4","eslint-plugin-perfectionist":"^5.9.0"},"peerDependencies":{"jose":"6.x","express":">= 4.17.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/openid-connect_0.3.2_1789567382605_0.38160186456124356"}}},"time":{"created":"2026-03-10T13:16:48.307Z","modified":"2026-09-16T14:03:03.187Z","0.0.1":"2026-03-10T13:16:48.592Z","0.0.2":"2026-03-10T13:22:33.044Z","0.0.3":"2026-03-17T10:37:34.108Z","0.0.4":"2026-03-23T08:26:08.086Z","0.1.0":"2026-07-30T09:04:13.731Z","0.2.0":"2026-08-24T08:01:41.236Z","0.3.0":"2026-09-02T08:26:30.689Z","0.3.1":"2026-09-02T08:43:37.478Z","0.3.2":"2026-09-16T14:03:02.683Z"},"bugs":{"url":"https://github.com/allermedia/openid-connect/issues"},"author":{"url":"https://github.com/allermedia","name":"Aller Media"},"license":"MIT","homepage":"https://github.com/allermedia/openid-connect","repository":{"url":"git+https://github.com/allermedia/openid-connect.git","type":"git"},"description":"Express middleware to protect web applications using OpenID Connect.","maintainers":[{"name":"jimoe","email":"jon3828@gmail.com"},{"name":"lobunto","email":"marius.ibsen@gmail.com"},{"name":"goodleby","email":"goodleby@gmail.com"},{"name":"konrad-j","email":"konrad.jorgensen@gmail.com"},{"name":"roninjc","email":"jesus.castanocandela@gmail.com"},{"name":"toremeek","email":"tore.meek@aller.com"},{"name":"vnorvik","email":"vnorvik@gmail.com"},{"name":"robinwa","email":"robin.wasjo@aller.com"},{"name":"paed01","email":"pal.edman@outlook.com"},{"name":"kuhanloh","email":"kuhanloh@gmail.com"}],"readme":"# @aller/openid-connect\n\nExpress middleware for apps using OpenID connect.\n\n[![Build](https://github.com/allermedia/openid-connect/actions/workflows/build.yaml/badge.svg)](https://github.com/allermedia/openid-connect/actions/workflows/build.yaml)\n[![Build Windows](https://github.com/allermedia/openid-connect/actions/workflows/build-windows.yaml/badge.svg)](https://github.com/allermedia/openid-connect/actions/workflows/build-windows.yaml)\n\nInspired and borrowed from [express-openid-connect](https://www.npmjs.com/package/express-openid-connect).\n\n<!-- toc -->\n\n- [Usage](#usage)\n- [Default routes](#default-routes)\n- [API](#api)\n  - [`auth(params)`](#authparams)\n  - [`requiresAuth([requiresLoginCheck], [options])`](#requiresauthrequireslogincheck-options)\n  - [`claimEquals(claim, value, [options])`](#claimequalsclaim-value-options)\n  - [`claimIncludes(claim, ...values, [options])`](#claimincludesclaim-values-options)\n  - [`claimIncludesAny(claim, ...values, [options])`](#claimincludesanyclaim-values-options)\n  - [`claimCheck(fn, [options])`](#claimcheckfn-options)\n  - [`requiresBearerAuth(params)`](#requiresbearerauthparams)\n  - [`attemptSilentLogin()`](#attemptsilentlogin)\n  - [`UnauthorizedError`](#unauthorizederror)\n  - [`ForbiddenError`](#forbiddenerror)\n  - [`Store`](#store)\n- [Protecting APIs with bearer tokens](#protecting-apis-with-bearer-tokens)\n- [Authorization with claim checks](#authorization-with-claim-checks)\n- [Differences from `express-openid-connect`](#differences-from-express-openid-connect)\n\n<!-- /toc -->\n\n## Usage\n\n```javascript\nimport express from 'express';\n\nimport { auth, requiresAuth } from '@aller/openid-connect';\n\nconst app = express();\n\napp.use(\n  auth({\n    baseURL: 'autodetect',\n    secret: 'supers3cret',\n    clientID: 'insecure-client-id',\n    issuerBaseURL: 'https://op.example.com',\n    authorizationParams: {\n      scope: 'openid email offline_access profile',\n      response_type: 'code',\n    },\n    discoveryCacheMaxAge: 24 * 3600 * 1000,\n    attemptSilentLogin: false,\n    authRequired: false,\n  })\n);\n\napp.get('/protected', requiresAuth, (req, res) => {\n  res.send('plus content');\n});\n```\n\n## Default routes\n\n`auth()` mounts these routes, relative to wherever the router is applied. Override the paths with `routes`, or set `login`, `logout` or `callback` to `false` to skip mounting that route.\n\n| `routes` option      | Default               | Method    | Behaviour                                                                              |\n| -------------------- | --------------------- | --------- | -------------------------------------------------------------------------------------- |\n| `login`              | `/login`              | GET       | Redirects to the issuer, returns to `/` after login                                    |\n| `logout`             | `/logout`             | GET       | Clears the session and redirects to the issuer end-session endpoint                    |\n| `callback`           | `/callback`           | GET, POST | Completes the login. POST serves `response_mode: 'form_post'`                          |\n| `backchannelLogout`  | `/backchannel-logout` | POST      | Receives issuer logout tokens. Only mounted when `backchannelLogout` is configured     |\n| `postLogoutRedirect` | `''`                  |           | Not a route. The `post_logout_redirect_uri` sent on logout unless `returnTo` is passed |\n\n```javascript\nimport express from 'express';\n\nimport { auth } from '@aller/openid-connect';\n\nconst app = express();\n\napp.use(\n  auth({\n    baseURL: 'https://app.example.com',\n    secret: 'supers3cret',\n    clientID: 'insecure-client-id',\n    issuerBaseURL: 'https://op.example.com',\n    routes: {\n      login: '/auth/login',\n      logout: '/auth/logout',\n      callback: '/auth/callback',\n      postLogoutRedirect: '/bye',\n    },\n  })\n);\n```\n\n## API\n\nAll named exports of `@aller/openid-connect`.\n\n### `auth(params)`\n\nReturns an `express.Router` that loads the session, attaches `req.oidc` and `res.oidc`, mounts the [default routes](#default-routes) and, unless `authRequired` is `false`, protects every route mounted after it.\n\nAll options are validated with a schema when `auth()` is called; an invalid or missing option throws a `TypeError` at startup. Defaults are the effective values from that schema. The list mirrors the shape of `params`.\n\n- `secret` **required**: string, `Buffer`, or array of either, at least 8 bytes. Derives the session cookie encryption key and signs transient cookies. With an array the first entry signs and encrypts, all entries verify and decrypt, which allows key rotation\n- `baseURL` **required**: public root URL of the app, e.g. `https://app.example.com/some/path`. When mounted under a path, mount `auth()` under the same path. `'autodetect'` builds it per request from `req.protocol` and `req.host`, so enable `trust proxy` behind a proxy\n- `clientID` **required**: the OIDC client id\n- `issuerBaseURL` **required**: issuer URL without trailing slash. Discovery is fetched from `<issuerBaseURL>/.well-known/openid-configuration`\n- `clientSecret`: required for the `client_secret_*` auth methods and for `HS*` id token algorithms\n- `clientAuthMethod`: `private_key_jwt` when `clientAssertionSigningKey` is set, else `client_secret_basic` when `clientSecret` is set, else `none`. Also accepts `client_secret_post` and `client_secret_jwt`. `none` is not allowed with pushed authorization requests\n- `clientAssertionSigningKey`: private key for `private_key_jwt`: PEM string or `Buffer`, JWK object, `KeyObject`, or `CryptoKey`\n- `clientAssertionSigningAlg`: algorithm for the client assertion JWT, sent as `token_endpoint_auth_signing_alg`. Defaults to `RS256` when `clientAssertionSigningKey` is a PEM string or `Buffer`, otherwise `openid-client` derives it from the key, or uses `HS256` for `client_secret_jwt`\n- `idTokenSigningAlg`: expected id token algorithm, default `RS256`. `none` is rejected\n- `clockTolerance`: clock skew tolerance in seconds for token verification, default `60`\n- `pushedAuthorizationRequests`: send a pushed authorization request to the issuer before redirecting the user, default `false`\n- `authRequired`: apply `requiresAuth()` to every route after `auth()`, default `true`. Set to `false` and protect routes individually\n- `errorOnRequiredAuth`: answer an anonymous request with a 401 `UnauthorizedError` instead of redirecting to login, default `false`. Can be overridden per `requiresAuth` middleware\n- `attemptSilentLogin`: try a `prompt=none` login on the first unauthenticated HTML request, default `false`\n- `authorizationParams`: parameters for the authorization request, default `{ response_type: 'code', scope: 'openid profile email' }`. Extra keys such as `audience` or `acr_values` pass through\n  - `response_type`: `code` or `code id_token`\n  - `scope`: must contain `openid`\n  - `response_mode`: `query` or `form_post`, forced to `form_post` for `code id_token`\n- `tokenEndpointParams`: extra body parameters for the token endpoint on code exchange and refresh\n- `logoutParams`: extra query parameters for the issuer end-session endpoint\n- `idpLogout`: also log the user out at the issuer on `/logout`, default `false`\n- `identityClaimFilter`: claims stripped from the id token before it is exposed as `req.oidc.user`, default `['aud', 'iss', 'iat', 'exp', 'nbf', 'nonce', 'azp', 'auth_time', 's_hash', 'at_hash', 'c_hash']`\n- `legacySameSiteCookie`: set a fallback transaction cookie without `SameSite` when `response_mode` is `form_post`, for browsers that reject `SameSite=None`, default `true`\n- `routes`: paths relative to where the router is mounted, see [Default routes](#default-routes)\n  - `login`: default `/login`, `false` skips mounting it\n  - `logout`: default `/logout`, `false` skips mounting it\n  - `callback`: default `/callback`, `false` skips mounting it\n  - `backchannelLogout`: default `/backchannel-logout`, only mounted when `backchannelLogout` is configured\n  - `postLogoutRedirect`: the `post_logout_redirect_uri` sent on logout unless `returnTo` is passed, default `''`\n- `getLoginState`: `(req, options) => object` hook returning the state object encoded into the `state` parameter. The default returns `{ returnTo }`. May be async\n- `afterCallback`: `(req, res, session, decodedState) => session` hook run after the id token is validated and before the redirect. Return the session object to store, so token storage, userinfo calls or extra claim validation can happen here. May be async\n- `session`: the session is stored in an encrypted cookie unless `store` is set\n  - `name`: cookie name, also the property on `req` that exposes the session data, default `appSession`. Letters, digits, `_`, `.` and `-` only\n  - `rolling`: extend the session on every request, default `true`. `false` gives an absolute session that ends a fixed time after login\n  - `rollingDuration`: idle time in seconds before the user is logged out, default `86400` (1 day). Must be `false` when `rolling` is `false`\n  - `absoluteDuration`: seconds after login when the user is logged out regardless of activity, default `604800` (7 days). `false` disables it, but only when `rolling` is `true`\n  - `store`: custom session store with `get`, `set` and `destroy`. Callback based express-session stores and promise based stores both work. The cookie then only holds the session id\n  - `genid`: `(req) => string` generating the session id for a custom store, default 16 random bytes as hex. Use a cryptographically strong value or enable `signSessionStoreCookie`\n  - `signSessionStoreCookie`: HMAC sign the session id cookie used with a custom store, default `false`\n  - `requireSignedSessionStoreCookie`: reject unsigned session id cookies, defaults to `signSessionStoreCookie`. Set to `false` temporarily when turning on signing, so existing sessions can roll over\n  - `cookie`: attributes passed to `res.cookie()`\n    - `domain`: cookie domain\n    - `path`: cookie path, relative\n    - `transient`: omit the cookie expiry so the browser drops it when closed, default `false`\n    - `httpOnly`: hide the cookie from client side scripts, default `true`\n    - `sameSite`: `lax`, `strict` or `none`, default `Lax`. With `none` you need your own CSRF protection\n    - `secure`: default `true` for an `https` `baseURL`. Must be `false` for an `http` `baseURL`, since secure cookies are not sent over plain http. Setting it to `false` over https logs a warning\n- `transactionCookie`: the short lived cookie that carries `state`, `nonce` and the PKCE verifier between the login redirect and the callback\n  - `name`: cookie name, default `auth_verification`\n  - `sameSite`: `Lax`, `Strict` or `None`, defaults to `session.cookie.sameSite`. `response_mode: 'form_post'` forces `None` on this cookie\n- `backchannelLogout`: default `false`. `true` enables the `POST /backchannel-logout` route with the default hooks, an object configures them. Enabling it requires a `backchannelLogout.store`, or a `session.store` to reuse, or custom `isLoggedOut` and `onLogoutToken` hooks\n  - `store`: store for logout entries with `get`, `set` and `destroy`. Falls back to `session.store`\n  - `onLogoutToken`: `(decodedToken, config) => void`. Default stores an entry per `sid` and per `sub` from the logout token\n  - `isLoggedOut`: `(req, config) => boolean`, checked on every authenticated request. Default looks up the session's `sid` and `sub` in the store. `false` disables the check\n  - `onLogin`: `(req, config) => void`. Default removes stale logout entries for the `sub` on successful login. `false` disables it\n  - `isInsecure`: skip logout token signature verification. Tests only\n- `discoveryCacheMaxAge`: milliseconds to cache the issuer discovery document, default `600000` (10 min)\n- `httpTimeout`: timeout in milliseconds for requests to the issuer, default `5000`, at least `500`\n- `httpUserAgent`: `User-Agent` header for requests to the issuer\n- `allowInsecureRequests`: allow an `http` issuer, for local development, default `false`\n- `customFetch`: custom `fetch` implementation handed to `openid-client`, e.g. for a proxy or for testing, default `globalThis.fetch`\n\n### `requiresAuth([requiresLoginCheck], [options])`\n\nReturns a middleware that triggers a login redirect for anonymous HTML requests, or calls `next()` with a 401 `UnauthorizedError` when the request does not accept HTML or `errorOnRequiredAuth` is set. Mounted automatically by `auth()` when `authRequired` is `true`. The optional `requiresLoginCheck`, `(req) => boolean`, returns `true` when the request must log in; the default is `!req.oidc.isAuthenticated()`, satisfied by a bearer authenticated request as well.\n\n- `errorOnRequiredAuth`: answer anonymous requests with 401 instead of a login redirect, defaults to the `auth()` option\n\n### `claimEquals(claim, value, [options])`\n\nReturns a middleware that requires authentication as `requiresAuth` does, then requires the id token claim to strictly equal `value`, a string, number, boolean or `null`. A failing check calls `next()` with a 403 `ForbiddenError`, see [Authorization with claim checks](#authorization-with-claim-checks).\n\n- `errorOnRequiredAuth`: answer anonymous requests with 401 instead of a login redirect, defaults to the `auth()` option\n- `ignoreCase`: compare string claim values case insensitively, default `false`\n- `trim`: trim string values and split space separated claims on whitespace, default `false`\n\n### `claimIncludes(claim, ...values, [options])`\n\nAs `claimEquals`, but every listed value must be present in the claim, which may be an array or a space separated string. Takes the same options as `claimEquals`.\n\n### `claimIncludesAny(claim, ...values, [options])`\n\nAs `claimIncludes`, but at least one listed value must be present. Takes the same options as `claimEquals`.\n\n### `claimCheck(fn, [options])`\n\nAs `claimEquals`, but with a custom predicate `(req, claims) => unknown`, only called for authenticated requests. Return a truthy value to allow the request, a falsy value to reject it with a generic `ForbiddenError`, or an `Error` to reject it with that error. Takes the `errorOnRequiredAuth` option only.\n\n### `requiresBearerAuth(params)`\n\nReturns a middleware that verifies an OAuth2 bearer access token against the issuer JWKS and exposes it as `req.bearerAuth`, see [Protecting APIs with bearer tokens](#protecting-apis-with-bearer-tokens).\n\n- `issuerBaseURL` **required**: issuer that signs the access tokens; JWKS is resolved through discovery\n- `audience` **required**: expected `aud` claim, a string or an array where any match is accepted\n- `clockTolerance`: clock skew tolerance in seconds, default `60`\n- `fallthrough`: let requests without a bearer token continue unauthenticated, default `false`. Invalid tokens are still rejected\n\n### `attemptSilentLogin()`\n\nReturns a middleware that runs `res.oidc.silentLogin()` for unauthenticated requests, i.e. the same behaviour the `attemptSilentLogin` option of `auth()` mounts at the end of the router, for use on individual routes when the global option is off. Takes no options.\n\n### `UnauthorizedError`\n\nError with `statusCode: 401` passed to `next()` when authentication is required and missing. `headers` holds response headers the error handler should apply, e.g. the `WWW-Authenticate` challenge set by `requiresBearerAuth`.\n\n### `ForbiddenError`\n\nError with `statusCode: 403` passed to `next()` when an authenticated request fails a claim check. `reason` describes what failed, `{ claim, expected, actual }` for the built in checks. Construct it yourself in a `claimCheck` predicate to reject with a custom reason.\n\n### `Store`\n\nBase class for express-session compatible, callback based, session stores. Store factories that expect the express-session module can be instantiated with `auth`, which exposes this class as `auth.Store`, e.g. `memorystore(auth)`. Stores extending `Store` are promisified internally; other stores are assumed to be promise based.\n\n## Protecting APIs with bearer tokens\n\n`requiresBearerAuth` guards JSON API routes with an OAuth2 bearer access token (JWT), independent of the cookie session `auth()` maintains — for cross-origin AJAX callers or other services. Tokens are verified against the issuer's JWKS (resolved via OIDC discovery on first use and cached) and must match the configured audience. The verified token is exposed as `req.bearerAuth = { payload, protectedHeader, token }`; failures call `next()` with an `UnauthorizedError` (`statusCode: 401`) whose `headers` carry an RFC 6750 `WWW-Authenticate` challenge, so pair it with a JSON error handler that applies `err.headers`. With `fallthrough: true` a request without a bearer token continues to the next handler unauthenticated (`req.bearerAuth` unset) instead of failing, so other auth methods can be chained after this one — a presented-but-invalid token is still rejected.\n\nThe `requiresAuth` family (`requiresAuth`, `claimEquals`, `claimIncludes`, `claimCheck`) recognizes a bearer-authenticated request, so claim checks can be chained after `requiresBearerAuth` — they then operate on the verified token claims, which take precedence over a session identity when both are present.\n\n```javascript\nimport express from 'express';\n\nimport { claimEquals, requiresBearerAuth } from '@aller/openid-connect';\n\nconst api = express();\n\napi.get('/api/things', requiresBearerAuth({ issuerBaseURL: 'https://op.example.com', audience: 'api://my-api' }), (req, res) => {\n  res.json({ sub: req.bearerAuth.payload.sub });\n});\n\napi.get(\n  '/api/admin/things',\n  requiresBearerAuth({ issuerBaseURL: 'https://op.example.com', audience: 'api://my-api' }),\n  claimEquals('role', 'admin'),\n  (req, res) => {\n    res.json({ role: req.bearerAuth.payload.role });\n  }\n);\n\napi.use((err, req, res, next) => {\n  if (res.headersSent) return next(err);\n  res\n    .set(err.headers)\n    .status(err.statusCode || 500)\n    .json({ message: err.message });\n});\n```\n\n## Authorization with claim checks\n\n`claimEquals`, `claimIncludes` and `claimCheck` separate authentication from authorization. An anonymous request is handled as by `requiresAuth` — a login redirect, or a 401 `UnauthorizedError` with `errorOnRequiredAuth`. An authenticated request that fails the claim check calls `next()` with a `ForbiddenError` (`statusCode: 403`) — never a login redirect, since the identity provider would just send the user straight back with the same claims. `err.reason` carries what failed as `{ claim, expected, actual }`, where `actual` is `undefined` when the claim is missing altogether, so a \"no role assigned\" page can be told apart from a \"wrong role\" one.\n\n`claimIncludes(claim, ...values)` has AND semantics: every listed value must be present in the claim, which may be an array or a space separated string. `claimIncludesAny(claim, ...values)` is the OR variant: at least one listed value must be present. Anything more involved goes in a `claimCheck` predicate.\n\nClaim values are matched exactly, including case, since scopes and roles are opaque strings to the identity provider. For claims where case does not matter, e.g. email addresses, pass `{ ignoreCase: true }` to `claimEquals`, `claimIncludes` or `claimIncludesAny` — string values are then compared case insensitively. `{ trim: true }` strips surrounding whitespace from string values and splits a space separated claim on runs of whitespace. Both flags leave numbers, booleans and null strict, and `err.reason` still reports the original values.\n\nA `claimCheck` predicate is only called for authenticated requests. It returns a truthy value to allow the request, a falsy value to reject it with a generic `ForbiddenError`, or an `Error` — e.g. a `ForbiddenError` with a custom `reason` — to reject it with that error.\n\n`errorOnRequiredAuth` can also be set per middleware, so a single route can answer 401 instead of redirecting without flipping the global option for `requiresAuth`.\n\n```javascript\nimport express from 'express';\n\nimport { auth, requiresAuth, claimIncludes, claimIncludesAny, claimCheck, ForbiddenError } from '@aller/openid-connect';\n\nconst app = express();\n\napp.use(\n  auth({\n    baseURL: 'autodetect',\n    secret: 'supers3cret',\n    clientID: 'insecure-client-id',\n    issuerBaseURL: 'https://op.example.com',\n    authRequired: false,\n  })\n);\n\napp.use(requiresAuth()); // anonymous → login redirect\n\napp.get('/admin', claimIncludes('roles', 'Admin'), (req, res) => {\n  res.send('admin content'); // signed in without the role → 403\n});\n\napp.get('/audit', claimIncludes('roles', 'Admin', 'Auditor'), (req, res) => {\n  res.send('audit content'); // AND: both roles are required\n});\n\napp.get('/billing', claimIncludesAny('roles', 'Admin', 'Finance'), (req, res) => {\n  res.send('billing content'); // OR: either role is enough\n});\n\napp.get(\n  '/support',\n  claimCheck((req, claims) => {\n    if (Array.isArray(claims.roles) && claims.roles.includes('Support')) return true;\n    return new ForbiddenError('Support role required', { claim: 'roles', expected: ['Support'], actual: claims.roles });\n  }),\n  (req, res) => {\n    res.send('support content');\n  }\n);\n\napp.get('/staff', claimIncludes('email', 'jane@example.org', { ignoreCase: true, trim: true }), (req, res) => {\n  res.send('staff content'); // \" Jane@Example.org \" is fine too\n});\n\napp.get('/api/me', requiresAuth({ errorOnRequiredAuth: true }), (req, res) => {\n  res.json(req.oidc.user); // anonymous → 401 instead of a redirect\n});\n\napp.use((err, req, res, next) => {\n  if (res.headersSent) return next(err);\n  if (err.statusCode === 403) return res.status(403).send(`Forbidden: ${err.message} ${JSON.stringify(err.reason)}`);\n  res.status(err.statusCode || 500).send(err.message);\n});\n```\n\n## Differences from `express-openid-connect`\n\nCompared against `express-openid-connect` v3, which is built on the same `openid-client` v6 / `jose` v6 stack:\n\n- ESM only (upstream is CommonJS). Express 5 compatible, Node ≥ 22.\n- `baseURL: 'autodetect'` resolves from the request at runtime — no need to hard-code the public URL or set a `BASE_URL` env var.\n- `session.store` accepts promise based stores in addition to callback based express-session compatible stores (instantiated with `auth`, e.g. `memorystore(auth)`).\n- `requiresBearerAuth` protects JSON APIs with issuer/JWKS-verified bearer access tokens (the [express-oauth2-jwt-bearer](https://www.npmjs.com/package/express-oauth2-jwt-bearer) use case) without a second package — and the `requiresAuth` family recognizes bearer-authenticated requests, so cookie and bearer auth compose on the same routes.\n- No Auth0-specific defaults, env vars, or helpers — generic OIDC only.\n","readmeFilename":"README.md"}