{"_id":"@alphamatica/hub-sdk-nest","_rev":"2-0190349667374c667718dd186180986b","name":"@alphamatica/hub-sdk-nest","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@alphamatica/hub-sdk-nest","version":"0.1.0","_id":"@alphamatica/hub-sdk-nest@0.1.0","maintainers":[{"name":"simbik","email":"simbik@live.ru"}],"dist":{"shasum":"1ad8ca85f5821fed5ecd8c0aefed3abc81755a53","tarball":"https://registry.npmjs.org/@alphamatica/hub-sdk-nest/-/hub-sdk-nest-0.1.0.tgz","fileCount":29,"integrity":"sha512-lVzxsMBN9aSp99NYws2vqZBc4WC/CZnYsR7TK4WAiuZI30J2DzSulScffY5OKMNW8+IEL3vDWJ4Rglu8gwCLBQ==","signatures":[{"sig":"MEYCIQCaz4KraJxl+1RiOE/8E9X+5q3SN5K4qvXk0L3s7ohwEQIhAK37JRgLhQTUBv42J83SgRRZYMGZmSzOLlmInRsodJ86","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":50435},"main":"dist/index.js","_from":"file:alphamatica-hub-sdk-nest-0.1.0.tgz","types":"dist/index.d.ts","private":false,"scripts":{"lint":"eslint \"src/**/*.ts\"","build":"tsc -p tsconfig.json"},"_npmUser":{"name":"simbik","email":"simbik@live.ru"},"_resolved":"C:\\Users\\simbi\\AppData\\Local\\Temp\\ee9f980515894c4b553f4b510f8e7373\\alphamatica-hub-sdk-nest-0.1.0.tgz","_integrity":"sha512-lVzxsMBN9aSp99NYws2vqZBc4WC/CZnYsR7TK4WAiuZI30J2DzSulScffY5OKMNW8+IEL3vDWJ4Rglu8gwCLBQ==","_npmVersion":"8.19.3","description":"NestJS module, guards, and decorators for alpha-hub SDK","directories":{},"_nodeVersion":"24.15.0","dependencies":{"@alphamatica/hub-sdk-core":"0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^22.9.0","@nestjs/core":"^10.4.15","@nestjs/common":"^10.4.15","@types/express":"^5.0.0","reflect-metadata":"^0.2.2","@alpha/eslint-config":"0.0.0","@alpha/typescript-config":"0.0.0","@nestjs/platform-express":"^10.4.15"},"peerDependencies":{"@nestjs/core":"^10","@nestjs/common":"^10","reflect-metadata":"^0.1.14 || ^0.2.0","@nestjs/platform-express":"^10"},"_npmOperationalInternal":{"tmp":"tmp/hub-sdk-nest_0.1.0_1779711516767_0.9789338265581189","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@alphamatica/hub-sdk-nest","version":"0.2.0","private":false,"description":"NestJS guards and decorators for alpha-hub SDK trust-headers integration","main":"dist/index.js","types":"dist/index.d.ts","dependencies":{"@alphamatica/hub-sdk-core":"0.2.0"},"peerDependencies":{"@nestjs/common":"^10","@nestjs/core":"^10","@nestjs/platform-express":"^10","reflect-metadata":"^0.1.14 || ^0.2.0"},"devDependencies":{"@nestjs/common":"^10.4.15","@nestjs/core":"^10.4.15","@nestjs/platform-express":"^10.4.15","@types/express":"^5.0.0","@types/node":"^22.9.0","reflect-metadata":"^0.2.2","typescript":"^5.6.3","@alpha/eslint-config":"0.0.0","@alpha/typescript-config":"0.0.0"},"scripts":{"build":"tsc -p tsconfig.json","lint":"eslint \"src/**/*.ts\""},"_id":"@alphamatica/hub-sdk-nest@0.2.0","_integrity":"sha512-IAvok6Fz0Kal4l54nKqzziYUCENdjLvDgSAm29247YSpe2NCqogOdDmTM9eZGyNfAoXMleZNlMGCZ0pO23R5sA==","_resolved":"C:\\Users\\simbi\\AppData\\Local\\Temp\\984af1ad2782b4d2d603b678ec75b116\\alphamatica-hub-sdk-nest-0.2.0.tgz","_from":"file:alphamatica-hub-sdk-nest-0.2.0.tgz","_nodeVersion":"24.15.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-IAvok6Fz0Kal4l54nKqzziYUCENdjLvDgSAm29247YSpe2NCqogOdDmTM9eZGyNfAoXMleZNlMGCZ0pO23R5sA==","shasum":"d4f73c3cfa25de8e55d4628911a595e4e50140c6","tarball":"https://registry.npmjs.org/@alphamatica/hub-sdk-nest/-/hub-sdk-nest-0.2.0.tgz","fileCount":38,"unpackedSize":61817,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIB3SY1W6bUTyNGyFoMMBuO8Q0G9HLxR/AUJHRjpqt9L4AiAzSSWpkb/GVqeHxsC1shnelO5G4A4iKON7wf+12o6JxQ=="}]},"_npmUser":{"name":"simbik","email":"simbik@live.ru"},"directories":{},"maintainers":[{"name":"simbik","email":"simbik@live.ru"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/hub-sdk-nest_0.2.0_1779714420913_0.5643854530923986"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-25T12:18:36.587Z","modified":"2026-05-25T13:07:01.183Z","0.1.0":"2026-05-25T12:18:36.933Z","0.2.0":"2026-05-25T13:07:01.031Z"},"description":"NestJS guards and decorators for alpha-hub SDK trust-headers integration","maintainers":[{"name":"simbik","email":"simbik@live.ru"}],"readme":"# @alphamatica/hub-sdk-nest\n\nNestJS integration for alpha-hub trust-headers SDK.\n\nIn the alpha-hub architecture all browser→service traffic is proxied through\nalpha-hub core. The hub validates JWT and resolves permissions at edge, then\nforwards the request to your service with `X-Alpha-User-*` headers and a\nshared `X-Alpha-Proxy-Secret`. This package verifies the proxy secret and\nparses the user headers into `req.alphaUser`.\n\n**Your service does NOT need to know about hub URL, JWT public key, or\ncatalog endpoints.** Only the shared proxy secret.\n\n## Install\n\n```bash\npnpm add @alphamatica/hub-sdk-nest\n```\n\n## Quick wire-up\n\n```ts\n// app.module.ts\nimport { Module } from '@nestjs/common';\nimport { AlphaTrustModule, AlphaTrustGuard, RequirePermissionGuard } from '@alphamatica/hub-sdk-nest';\nimport { APP_GUARD } from '@nestjs/core';\n\n@Module({\n  imports: [\n    AlphaTrustModule.forRoot({\n      proxySecret: process.env.ALPHA_PROXY_SECRET!,\n    }),\n  ],\n  providers: [\n    // Apply globally so every route is trust-checked + permission-checked.\n    // Routes without @RequirePermission just need a valid proxy secret + user headers.\n    { provide: APP_GUARD, useClass: AlphaTrustGuard },\n    { provide: APP_GUARD, useClass: RequirePermissionGuard },\n  ],\n})\nexport class AppModule {}\n```\n\nThen on controllers:\n\n```ts\nimport { Controller, Get } from '@nestjs/common';\nimport { RequirePermission, AlphaUser } from '@alphamatica/hub-sdk-nest';\nimport type { AlphaUserShape } from '@alphamatica/hub-sdk-nest';\n\n@Controller('playlists')\nexport class PlaylistsController {\n  @Get()\n  @RequirePermission('asur.playlists.read')\n  list(@AlphaUser() user: AlphaUserShape) {\n    // user.id, user.email, user.scopes available\n    return this.svc.list({ scopes: user.scopes });\n  }\n}\n```\n\n## Environment\n\nOnly one variable needed:\n\n| Variable | Description |\n|---|---|\n| `ALPHA_PROXY_SECRET` | Shared secret with alpha-hub. The hub sets this in its env and includes it as `X-Alpha-Proxy-Secret` on every forwarded request. Generate with `openssl rand -hex 32`. |\n\nNo `ALPHA_HUB_URL`, no public key, no sync secret.\n\n## Architecture note\n\nRequests reach your service ONLY through alpha-hub's `/proxy/:serviceId/*`\nforwarder. The hub does:\n\n1. JWT validation\n2. Permission resolution (role → permissions catalog)\n3. Audit logging\n4. Forward request + headers to your service\n\nYour service trusts the forwarded headers (verified via `X-Alpha-Proxy-Secret`)\nand applies `@RequirePermission` checks against the already-resolved permission\nset in the header.\n\nFor defense-in-depth, also restrict your service to internal network so it's\nunreachable bypassing hub. The proxy secret is the auth-header-level guarantee;\nnetwork isolation is the topology-level guarantee.\n\n## Migrating from v0.1.x\n\nv0.1.x had `AlphaAuthModule.forRoot({ coreUrl, serviceId, publicKey, syncSecret, ... })`.\nv0.2.0 collapses all that to:\n\n```ts\nAlphaTrustModule.forRoot({ proxySecret: ... })\n```\n\n`AlphaAuthGuard` → `AlphaTrustGuard`. `@RequirePermission` and `@AlphaUser`\nkeep the same name and semantics. Sync endpoints (`/alpha-sync/*`) and SSO\nbridge are gone — hub proxy handles those flows now.\n","readmeFilename":"README.md"}