{"_id":"@aopslabs/host-auth","_rev":"4-504cbee7a498d37e5c21678b12b207f0","name":"@aopslabs/host-auth","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@aopslabs/host-auth","version":"0.1.0","license":"SEE LICENSE IN LICENSE","_id":"@aopslabs/host-auth@0.1.0","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"homepage":"https://github.com/eeemzs/xf-packages#readme","bugs":{"url":"https://github.com/eeemzs/xf-packages/issues"},"dist":{"shasum":"bcb57a575c0904543b08b5d7ff9aa97906957f04","tarball":"https://registry.npmjs.org/@aopslabs/host-auth/-/host-auth-0.1.0.tgz","fileCount":6,"integrity":"sha512-yUNnklBZt3joiEOedw5llMtzB7MLb+g+5yYmFKMgJ2Biwp0BAdq0sCFwj+/3yoVY4m99bz+cFAQlfXnGqXpbkQ==","signatures":[{"sig":"MEYCIQC1l5Xtl0b0ISNQj78lCImgmKtcpqVq5N31dBtPnOuXMwIhAO+9CxS492jpC8hYKHCoDWcYqoR1HtKcY2n1vaZEplL5","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":18962},"main":"./dist/index.js","type":"module","_from":"file:C:/Users/mzs/AppData/Local/Temp/xf-private-release-FeUJyJ/aopslabs-host-auth-0.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./package.json":"./package.json"},"private":false,"scripts":{"build":"tsc -p tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit"},"_npmUser":{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"},"_resolved":"C:\\Users\\mzs\\AppData\\Local\\Temp\\xf-private-release-FeUJyJ\\aopslabs-host-auth-0.1.0.tgz","_integrity":"sha512-yUNnklBZt3joiEOedw5llMtzB7MLb+g+5yYmFKMgJ2Biwp0BAdq0sCFwj+/3yoVY4m99bz+cFAQlfXnGqXpbkQ==","repository":{"url":"git+https://github.com/eeemzs/xf-packages.git","type":"git"},"_npmVersion":"11.6.4","description":"Principal-authority providers for trusted-local and South-oracle AOPS Labs plugin hosts.","directories":{},"_nodeVersion":"22.18.0","dependencies":{"@aopslabs/host-core":"^0.2.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^25.3.0"},"_npmOperationalInternal":{"tmp":"tmp/host-auth_0.1.0_1785957408245_0.1699521874632095","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@aopslabs/host-auth","version":"0.1.1","license":"SEE LICENSE IN LICENSE","_id":"@aopslabs/host-auth@0.1.1","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"homepage":"https://github.com/eeemzs/xf-packages#readme","bugs":{"url":"https://github.com/eeemzs/xf-packages/issues"},"dist":{"shasum":"113beb47d4b0319841dcacc8b48db449555034b8","tarball":"https://registry.npmjs.org/@aopslabs/host-auth/-/host-auth-0.1.1.tgz","fileCount":6,"integrity":"sha512-NacnVpf/sSNbeVmUQhf9hS9uFX6WmK4EuVrbPm1zQ5XEQDwb+R6C3HCR/xAj1wz9+Kz83KJ2qyAVmOQj9LrL5w==","signatures":[{"sig":"MEUCIFZmHOkrNrgkSKffkU+IH5g8Zawhz6uUJSDdHVmNIlzQAiEA0hnCkcJHP+ghj8flZ7thHY13GFyp14u3/kDIT+NL13U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24682},"main":"./dist/index.js","type":"module","_from":"file:/tmp/xf-private-release-AEkjXG/aopslabs-host-auth-0.1.1.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./package.json":"./package.json"},"private":false,"scripts":{"test":"pnpm run build && node --test test/*.test.mjs","build":"tsc -p tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c89d0b8b-712c-4884-ae87-3fc78bbc94c2"}},"_resolved":"/tmp/xf-private-release-AEkjXG/aopslabs-host-auth-0.1.1.tgz","_integrity":"sha512-NacnVpf/sSNbeVmUQhf9hS9uFX6WmK4EuVrbPm1zQ5XEQDwb+R6C3HCR/xAj1wz9+Kz83KJ2qyAVmOQj9LrL5w==","repository":{"url":"git+https://github.com/eeemzs/xf-packages.git","type":"git"},"_npmVersion":"11.9.0","description":"Principal-authority providers for trusted-local and South-oracle AOPS Labs plugin hosts.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@aopslabs/host-core":"0.3.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"5.9.3","@types/node":"25.9.5"},"_npmOperationalInternal":{"tmp":"tmp/host-auth_0.1.1_1787263387564_0.8649805259832068","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@aopslabs/host-auth","version":"0.1.2","license":"SEE LICENSE IN LICENSE","_id":"@aopslabs/host-auth@0.1.2","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"homepage":"https://github.com/eeemzs/tsapps#readme","bugs":{"url":"https://github.com/eeemzs/tsapps/issues"},"dist":{"shasum":"6d313f912b61ec8678444f40ddd4e5433c0a6637","tarball":"https://registry.npmjs.org/@aopslabs/host-auth/-/host-auth-0.1.2.tgz","fileCount":6,"integrity":"sha512-g06pkxUl9X4IK4T/Wt1pRmL83yxbxcaU0NZkkHRrmQCD+6OiIRD+rWcuxD5qzmDLXQJNotG0nENiE8gasvfXJA==","signatures":[{"sig":"MEUCIG6QKtL1etPwuqrAO0KQe2NUYXPUqERfcioktG3RH+oRAiEAz1TfjGNpulNllihe5cbADDV/kjxRQw//biIzhZQ5gXg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":37721},"main":"./dist/index.js","type":"module","_from":"file:/home/runner/work/_temp/release-candidates/aopslabs-host-auth-0.1.2.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./package.json":"./package.json"},"private":false,"scripts":{"lint":"eslint . --max-warnings=0","test":"node --test test/*.test.mjs","build":"tsc -p tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit --incremental false"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c5fb0b5f-5536-45eb-baf1-581bafd20d8c"}},"_resolved":"/home/runner/work/_temp/release-candidates/aopslabs-host-auth-0.1.2.tgz","_integrity":"sha512-g06pkxUl9X4IK4T/Wt1pRmL83yxbxcaU0NZkkHRrmQCD+6OiIRD+rWcuxD5qzmDLXQJNotG0nENiE8gasvfXJA==","repository":{"url":"git+https://github.com/eeemzs/tsapps.git","type":"git","directory":"packages/xf-packages/xf-host-auth"},"_npmVersion":"11.9.0","description":"Principal-authority providers for trusted-local and South-oracle AOPS Labs plugin hosts.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"@aopslabs/host-core":"0.3.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"9.39.5","typescript":"5.9.3","@types/node":"25.3.0","@aopslabs/eslint-config":"0.0.0","@aopslabs/typescript-config":"0.0.0"},"_npmOperationalInternal":{"tmp":"tmp/host-auth_0.1.2_1788791279197_0.8640977671461172","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@aopslabs/host-auth","version":"0.1.3","private":false,"type":"module","description":"Principal-authority providers for trusted-local and South-oracle AOPS Labs plugin hosts.","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{"./package.json":"./package.json",".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"dependencies":{"@aopslabs/host-core":"0.3.3"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"repository":{"type":"git","url":"git+https://github.com/eeemzs/tsapps.git","directory":"packages/xf-packages/xf-host-auth"},"license":"SEE LICENSE IN LICENSE","devDependencies":{"@types/node":"25.3.0","eslint":"9.39.5","typescript":"5.9.3","@aopslabs/eslint-config":"0.0.0","@aopslabs/typescript-config":"0.0.0"},"scripts":{"build":"tsc -p tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit --incremental false","test":"node --test test/*.test.mjs","lint":"eslint . --max-warnings=0"},"_id":"@aopslabs/host-auth@0.1.3","bugs":{"url":"https://github.com/eeemzs/tsapps/issues"},"homepage":"https://github.com/eeemzs/tsapps#readme","_integrity":"sha512-6C+pQ1/Ce018f61eT0WsOo1oqf28HlavzxuEl0psw1NwN7bvSi74tn/gkFLjV/e1EAg8l1i4/X+L9ASVT3GKrQ==","_resolved":"/home/runner/work/_temp/release-candidates/aopslabs-host-auth-0.1.3.tgz","_from":"file:/home/runner/work/_temp/release-candidates/aopslabs-host-auth-0.1.3.tgz","_nodeVersion":"24.20.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-6C+pQ1/Ce018f61eT0WsOo1oqf28HlavzxuEl0psw1NwN7bvSi74tn/gkFLjV/e1EAg8l1i4/X+L9ASVT3GKrQ==","shasum":"0181966962e1f8d3871e97d03818b8e7ffb41207","tarball":"https://registry.npmjs.org/@aopslabs/host-auth/-/host-auth-0.1.3.tgz","fileCount":6,"unpackedSize":54929,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDFFUB4vbWIh4+mXnCsjcrFX/4zoV90xFrOkwORag0dbQIhAL2EkBBHh0YU7NsQHIgTn8gr5SsBtAHvsPBhfQWyvqmY"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c5fb0b5f-5536-45eb-baf1-581bafd20d8c"}},"directories":{},"maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/host-auth_0.1.3_1789257757435_0.18755199999430494"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-05T19:16:48.056Z","modified":"2026-09-13T00:02:37.732Z","0.1.0":"2026-08-05T19:16:48.399Z","0.1.1":"2026-08-20T22:03:07.706Z","0.1.2":"2026-09-07T14:27:59.324Z","0.1.3":"2026-09-13T00:02:37.569Z"},"bugs":{"url":"https://github.com/eeemzs/tsapps/issues"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/eeemzs/tsapps#readme","repository":{"type":"git","url":"git+https://github.com/eeemzs/tsapps.git","directory":"packages/xf-packages/xf-host-auth"},"description":"Principal-authority providers for trusted-local and South-oracle AOPS Labs plugin hosts.","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"readme":"# @aopslabs/host-auth\n\nPrincipal-authority providers for AOPS Labs plugin hosts.\n\nTrusted-local authority is loopback-only by default. Hosts may attach an\nexplicit, bounded role/capability list to the local operator; wildcard and\nmalformed authority values are rejected during provider construction. The\ncaller address must come from the server adapter rather than forwarded client\nheaders. The trusted-local tenant is also host-configured; an `x-tenant-id`\nheader cannot replace it.\n\n## Installation\n\n\\`\\`\\`bash\nnpm install @aopslabs/host-auth\n\\`\\`\\`\n\nThe public surface provides trusted-local development authority and a production\nSouth \\`/api/auth/authority-projection\\` oracle. South credentials are forwarded\nnarrowly, Auth and verified South tenant identities remain distinct, and\nbounded token-hash/authority caches expose only statistics and explicit\ninvalidation.\n\n\\`authorityMode: 'projection-v1'\\` is the default. The legacy\n\\`'auth-me-compat'\\` mode must be selected explicitly, never probes or silently\nfalls back, and is not production-grade South tenant proof.\n\nApplication-bound authority is an explicit opt-in:\n\nUse the application slug and resource audience registered in South; names are\nnot a fixed product list. The retired `integrationKey` configuration option is\nrejected even when empty or combined with a slug. Human v2 requests send only\n`x-south-application` and `x-south-audience`; South rejects the presence of the\nretired `x-south-integration` header. Service authority uses the same explicit\nslug/audience expectations without forwarding caller authority selectors.\nHuman and service authority responses and host contexts omit profile metadata;\nthe former `SouthIntegrationKey` output type is no longer exported. Registered\napplication/resource identities, audiences and current grants remain authoritative.\n\n\\`\\`\\`ts\ncreateSouthOracleAuthorityProvider({\n  baseUrl: 'https://south.example.com',\n  authorityMode: 'projection-v2',\n  applicationSlug: 'meridian-storefront',\n  audience: 'urn:meridian:catalog',\n})\n\\`\\`\\`\n\nBoth application and audience are mandatory in v2 and invalid in the other\nmodes, preventing an incomplete configuration from silently using v1. The\nprovider calls only \\`/api/auth/authority-projection/v2\\`, verifies the exact\ntenant/application/client/resource/authorization-space boundary, rejects\nwildcards, and forwards or creates a correlation id surfaced on the returned\nrequest context. Its positive cache key is\nthe bearer hash plus tenant, application, and audience; its TTL is bounded by\nthe token, session, grant-neutral application-session binding, South\nrevalidation hint, and 60 seconds. The verified expiry and revalidation bounds\nare carried on the returned request context.\nOnly 401/403 decisions are negative-cached, for at most 10 seconds; malformed\nresponses and outages fail closed and are never cached.\n\n`createSouthTokenFamilyAuthorityProvider` performs a no-fallback bearer-family\nselection: an exact `south_sat_` access token reaches only the service oracle;\nmalformed South service material and raw `south_svc_` credentials are rejected\nlocally; all other bearer forms reach only the configured human oracle. Route\nadapters remain responsible for rejecting cookies, PATs, and mixed credential\nfamilies before invoking this provider.\n\n## License\n\nCopyright (c) 2026 Mehmet Zeki Sönmez. Licensed under the PolyForm Strict License 1.0.0; see LICENSE.\n","readmeFilename":"README.md"}