{"_id":"@api-components/oauth-authorization","_rev":"14-803ad9783f5313df2fc2c2b5e63646b0","name":"@api-components/oauth-authorization","dist-tags":{"latest":"3.0.0-preview.2"},"versions":{"2.0.0":{"name":"@api-components/oauth-authorization","version":"2.0.0","author":{"name":"The Advanced REST client authors","email":"arc@mulesoft.com"},"license":"Apache-2.0","_id":"@api-components/oauth-authorization@2.0.0","maintainers":[{"name":"jarrodek","email":"jarrodek@gmail.com"}],"homepage":"https://github.com/advanced-rest-client/oauth-authorization#readme","bugs":{"url":"https://github.com/advanced-rest-client/oauth-authorization/issues","email":"arc@mulesoft.com"},"dist":{"shasum":"5794db8ad32ff5115cce95ed9ace6e02b9e6f019","tarball":"https://registry.npmjs.org/@api-components/oauth-authorization/-/oauth-authorization-2.0.0.tgz","fileCount":36,"integrity":"sha512-+teitl9LKEKxn0v7/b7QIHTAJkI2sqM/TWY2UV2mzJOVU8BndO0ZizER/rnPR/rZYMYuem8kx9v6de6cHafFmg==","signatures":[{"sig":"MEUCIDX+LlKRCQEZ7uwNUflotzosWqZV6fktiGrEj89dTGnjAiEApGVhRo0Fxe+q/TC0o3wTT51IG5CWxdx2rc/4BbHph14=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":499739},"main":"outh-authorization.html","gitHead":"15752838b149724a6844c00b0c02468b3113e925","private":false,"scripts":{"lint":"polymer lint oauth-authorization.html oauth1-authorization.html","test":"polymer test --plugin local","test-sauce":"polymer test --plugin sauce --job-name \"oauth-authorization:local-test\"","update-types":"gen-typescript-declarations --deleteExisting --outDir ."},"_npmUser":{"name":"jarrodek","email":"jarrodek@gmail.com"},"repository":{"url":"git://github.com/advanced-rest-client/oauth-authorization.git","type":"git"},"_npmVersion":"5.7.1","description":"A set of elements that perform oauth authorization","directories":{},"_nodeVersion":"8.1.3","_hasShrinkwrap":false,"devDependencies":{"bower":"^1.8.0","@polymer/gen-typescript-declarations":"^1.1.1"},"_npmOperationalInternal":{"tmp":"tmp/oauth-authorization_2.0.0_1521337914489_0.8344681645388776","host":"s3://npm-registry-packages"}},"3.0.0-preview.1":{"name":"@api-components/oauth-authorization","version":"3.0.0-preview.1","keywords":["web-components","polymer","oauth","oauth2","authorization"],"author":{"name":"The Advanced REST client authors","email":"arc@mulesoft.com"},"license":"Apache-2.0","_id":"@api-components/oauth-authorization@3.0.0-preview.1","maintainers":[{"name":"jarrodek","email":"jarrodek@gmail.com"}],"homepage":"https://github.com/advanced-rest-client/oauth-authorization#readme","bugs":{"url":"https://github.com/advanced-rest-client/oauth-authorization/issues","email":"arc@mulesoft.com"},"dist":{"shasum":"08b7ec07c849a876efd73f497c7461d4416536df","tarball":"https://registry.npmjs.org/@api-components/oauth-authorization/-/oauth-authorization-3.0.0-preview.1.tgz","fileCount":31,"integrity":"sha512-a44IIyzKEHFkye/K9m+0lK6BKFSLDfJs0QskzYbHGoO1+PWTDLPm0WcIupOO6ml6ifYTTTpiIB+eRere/WIY0A==","signatures":[{"sig":"MEUCIDLoGM7D7MRaffExqA6iVyi97hMqigKq0j9cETRpoQuRAiEArUu5JcgfCrYnE61BsoZvYuYcnCSFwvXD+Me+q0P4/OA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":272144,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJca0jzCRA9TVsSAnZWagAA8FEQAIH5Yltb24Pyl6CKfiE7\nTYNjrb97cV0irpagtPAl4CQsTQiT3KoduuDbgB9p087yH7rd+6I+5ylJCNrI\n0vCp+kfD8F8D3K78hTG6jRZNkjmqA0/QXr0VaYUO6oROUvmAoslPvsBfvxqM\nVauULSg0vjLpJJk9H/wGib1jVrXlbhUWR4HPqXHVJE7WDNx+sTkgcZe8jEUJ\nFH9Jy9h2+YimH+zZ3/oTSBYqlM5gM2fwXGOKoPtAO64iRuDdNinIVJmB9deu\nJMFc/ILLyKKJgU4k7tq/KndjyP9Sw/OmQG+gtwWsGdQerHBd1idFDnzrw3kL\nx3II/x64rXdQI/9E9EAY5ysVLJQj8WqDRJdMf+8vSQJPl1+Blkr17zBgfkaj\n17YgwScwBU4L27gbYiCbSQI+yi77Cx7pVN/r9UlpJeDOW3VYKoWDcoul6EQw\nEdWwLsyFwPJPFxvhW5482e8IwBeVoJDhickXwlVmR6Q7jpjY1RUJ6gUSLpEV\nrUGRG0RVNgbs5u7Orc5Kyg2PadbwzOOnAw+1KERyuYsB7ZAOGgPR07lRbK1m\nnIlhX4xJn22Se+gei8zoNil+n5niUFHbdRqZcaU8sBwHfRxSvpgFro0Az6LQ\nE6BFPjR0/r9EnJx05926DzxpB3YxHNHBSoKuH6UBfssy9i94DFfS2REl7XDl\ncwJF\r\n=ezFx\r\n-----END PGP SIGNATURE-----\r\n"},"main":"outh-authorization.js","gitHead":"839267c5e327e508025a3a5c903c73e7302f6392","scripts":{"lint":"polymer lint oauth-authorization.html oauth1-authorization.html","test":"polymer test --module-resolution=node --npm --plugin local","test-sauce":"polymer test --module-resolution=node --npm --plugin sauce --job-name \"oauth-authorization:local-test\"","update-types":"gen-typescript-declarations --deleteExisting --outDir ."},"_npmUser":{"name":"jarrodek","email":"jarrodek@gmail.com"},"deprecated":"this version has been deprecated","repository":{"url":"git://github.com/advanced-rest-client/oauth-authorization.git","type":"git"},"_npmVersion":"6.8.0","description":"A set of elements that perform oauth authorization","directories":{},"_nodeVersion":"8.11.2","dependencies":{"@polymer/polymer":"^3.0.0","@polymer/iron-meta":"^3.0.0","@advanced-rest-client/url-parser":"^3.0.0-preview.1","@advanced-rest-client/headers-parser-mixin":"^3.0.0-preview.1"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^4.2.0","mocha":"^5.2.0","sinon":"^7.2.3","jsrsasign":"^8.0.12","wct-mocha":"^1.0.0","cryptojslib":"^3.1.2","@polymer/test-fixture":"^4.0.2","@polymer/iron-test-helpers":"^3.0.0","@polymer/iron-component-page":"^4.0.0","@webcomponents/webcomponentsjs":"^2.0.0","@polymer/gen-typescript-declarations":"^1.6.1"},"_npmOperationalInternal":{"tmp":"tmp/oauth-authorization_3.0.0-preview.1_1550534899209_0.4585192136300653","host":"s3://npm-registry-packages"}},"3.0.0-preview.2":{"name":"@api-components/oauth-authorization","version":"3.0.0-preview.2","keywords":["web-components","polymer","oauth","oauth2","authorization"],"author":{"name":"The Advanced REST client authors","email":"arc@mulesoft.com"},"license":"Apache-2.0","_id":"@api-components/oauth-authorization@3.0.0-preview.2","maintainers":[{"name":"jarrodek","email":"jarrodek@gmail.com"}],"homepage":"https://github.com/advanced-rest-client/oauth-authorization#readme","bugs":{"url":"https://github.com/advanced-rest-client/oauth-authorization/issues","email":"arc@mulesoft.com"},"dist":{"shasum":"347233aa6ca010cedbfb9c6b2c92ef7995e5d31d","tarball":"https://registry.npmjs.org/@api-components/oauth-authorization/-/oauth-authorization-3.0.0-preview.2.tgz","fileCount":31,"integrity":"sha512-wVmnUULa2vvyFY3Axz5KgySVqGfjccBGU6iMARsX2tRx+9DyJp0qP8SIYoIyDRNsHU74soGycgNk37ysPYsbrg==","signatures":[{"sig":"MEUCIQC3VE1E7lOX/rQcwF6jpTgsPPO+X1OGQ9S2Kwv2OG8NaQIgGeFtgQZ2WM3U9kP1NYWU1bkKIcSJmtjscOeX9upKubc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":276908,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJccH3HCRA9TVsSAnZWagAA/2AP/35q0WzJX7kCAFHmgOVa\nDVtSaiQkrJb8swf7xaYaWG3lR1r+v3N/shT5LQu40W6fhf/c2fsA4QcHL+dk\n1YabcbzbBwP7UlLWx/ig8UZxvV8n5c4DKn8+N9XaaZEMFfn7MlgmSpJSuErW\nX4x3tYsKKyux0lztkLzFbsve1jI3y7syNSPQHueAWegPv+spzi9Hg4XIREIt\nlniEt75I/FkRHZ9EoS2xkaiOrfOtkiqB15jGEkexjxc4pyo1HLxGaFfaYnIO\noZbwa+wSjJqPQGBsZdTM2h3ctW3DTUwIgh+7agjoci91aA84JPxqbECTjhi8\nH4zBa36gzr+C+x3NZYq/oNmid3MwwSMDrnu+TIcVLfDUdGgqU/0iMsOAihhb\nZff/Am4OjxM7rGtRsDjX2aOqJw/LzwKAeXQtWOWCCwJP4mqPhp3IQXfqB35E\nV/uKm95o8ZLz7OfFv7RBTkkY1EOr/pU+Xpj+nNSzFm0vIVtmjRIFgqQ7Ow7N\nYLrl6nltqDW6jaQIp3bOgKAqTadsXF4XL0QVz++lV7ScB3CIdyulJELcdOwH\nSRyL9hoee8zX5Y+U3dDsqJW2uuMs1AblGz3YFgz7ffgod6klZ1saZyHu6VNR\nVBXwU7kxgqJLGOxjgg7iOUrmdo0BG8xkXXHgxptT/AMV3sTGLDlcJP9r+JWc\nlFrW\r\n=Ejyv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"outh-authorization.js","gitHead":"839267c5e327e508025a3a5c903c73e7302f6392","scripts":{"lint":"polymer lint oauth-authorization.html oauth1-authorization.html","test":"polymer test --module-resolution=node --npm --plugin local","test-sauce":"polymer test --module-resolution=node --npm --plugin sauce --job-name \"oauth-authorization:local-test\"","update-types":"gen-typescript-declarations --deleteExisting --outDir ."},"_npmUser":{"name":"jarrodek","email":"jarrodek@gmail.com"},"deprecated":"this version has been deprecated","repository":{"url":"git://github.com/advanced-rest-client/oauth-authorization.git","type":"git"},"_npmVersion":"6.8.0","description":"A set of elements that perform oauth authorization","directories":{},"_nodeVersion":"10.14.0","dependencies":{"@polymer/polymer":"^3.0.0","@polymer/iron-meta":"^3.0.0","@advanced-rest-client/url-parser":"^3.0.0-preview.1","@advanced-rest-client/headers-parser-mixin":"^3.0.0-preview.1"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^4.2.0","mocha":"^5.2.0","sinon":"^7.2.3","jsrsasign":"^8.0.12","wct-mocha":"^1.0.0","cryptojslib":"^3.1.2","@polymer/test-fixture":"^4.0.2","@polymer/iron-test-helpers":"^3.0.0","@polymer/iron-component-page":"^4.0.0","@webcomponents/webcomponentsjs":"^2.0.0","@polymer/gen-typescript-declarations":"^1.6.1"},"_npmOperationalInternal":{"tmp":"tmp/oauth-authorization_3.0.0-preview.2_1550876102666_0.8275886836379074","host":"s3://npm-registry-packages"}}},"time":{"created":"2018-03-18T01:51:54.425Z","modified":"2026-04-07T19:29:56.659Z","2.0.0":"2018-03-18T01:51:54.601Z","3.0.0-preview.1":"2019-02-19T00:08:19.376Z","3.0.0-preview.2":"2019-02-22T22:55:02.884Z"},"bugs":{"url":"https://github.com/advanced-rest-client/oauth-authorization/issues","email":"arc@mulesoft.com"},"author":{"name":"The Advanced REST client authors","email":"arc@mulesoft.com"},"license":"Apache-2.0","homepage":"https://github.com/advanced-rest-client/oauth-authorization#readme","keywords":["web-components","polymer","oauth","oauth2","authorization"],"repository":{"url":"git://github.com/advanced-rest-client/oauth-authorization.git","type":"git"},"description":"A set of elements that perform oauth authorization","maintainers":[{"email":"jarrodek@gmail.com","name":"jarrodek"},{"email":"alexperez@mulesoft.com","name":"alexperez_march_2024"},{"email":"elmellidiego@gmail.com","name":"dmacias"}],"readme":"[![Build Status](https://travis-ci.org/advanced-rest-client/oauth-authorization.svg?branch=stage)](https://travis-ci.org/advanced-rest-client/oauth-authorization)\n\n\n==================\n\nThis version is deprecated. Please, migate to `@advanced-rest-client/oauth-authorization`.\n\nNot further releases are planned in here.\n\n==================\n\n# OAuth authorization\n\nProvides components to authorize the user using OAuth 1 and OAuth 2 standards.\n\n## OAuth 2\n\nThere are 4 basic token requests flows:\n- Authorization Code for apps running on a web server (`authorization_code` type)\n- Implicit for browser-based or mobile apps (`implicit` type)\n- Password for logging in with a username and password (`password` type)\n- Client credentials for application access (`client_credentials` type)\n\nThis element uses them all.\n\nMain function is the `authorize()` function that can be also used via event system.\nThis function accepts different set of parameters depending on request type. However it will\nnot perform a validation on the settings. It will try to perform the request for given set of\nparameters. If it fails, than it fail on the server side.\n\n### Example\n\n```\n<outh2-authorization></outh2-authorization>\n```\n```\nconst settings = {\n  type: 'implicit',\n  clientId: 'CLIENT ID',\n  redirectUri: 'https://example.com/auth-popup.html',\n  authorizationUri: 'https://auth.example.com/token'\n  scopes: ['email'],\n  state: 'Optional string'\n};\nconst factory = document.querySelector('outh2-authorization');\nfactory.authorize(settings)\n\n// or event based\nconst event = new CustomEvent('oauth2-token-requested', { 'detail': settings, bubbles: true });\ndocument.dispatchEvent(event);\n```\n\nThere is one difference for from using event based approach. When the token has been received\nthis will set `tokenValue` property on the target of the event.\nThe event will be cancelled one it reach this element so other elements will not double the action.\n\nAn element or app that requesting the token should observe the `oauth2-token-response` and\n`oauth2-error` events to get back the response.\n\n## Popup in authorization flow\n\nThis element contain a `oauth-popup.html` that can be used to exchange token / code data with\nhosting page. Other page can be used as well. But in must `window.postMessage` back to the\n`window.opener`. The structure of the message if the parsed query or has string to the map\nof parameters. Furthermore it must camel case the parameters. Example script is source code\nof the `oauth-popup.html` page.\nPopup should be served over the SSL.\n\n## The state parameter and security\n\nThis element is intened to be used in debug applications where confidentialy is already\ncompromised because users may be asked to provide client secret parameter (depending on the flow).\n**It should not be used in client applications** that don't serve debugging purposes.\nClient secret should never be used on the client side.\n\nTo have at least minimum of protection (in already compromised environment) this library generates\na `state` parameter as a series of alphanumeric characters and append them to the request.\nIt is expected to return the same string in the response (as defined in rfc6749). Though this\nparameter is optional, it will reject the response if the `state` parameter is not the same as the\none generated before the request.\n\nThe state parameter is generated automatically by the element if non provided in\nsettings. It is a good idea to use this property to check if the event response\n(either token or error) are coming from your request for token. The app can\nsupport different OAuth clients so you can check later with the token response if\nthis is a response for the same client.\n\n## Non-interactive authorization (experimental)\n\nFor `implicit` and `code` token requests you can set `interactive` property\nof the settings object to `false` to request the token in the background without\ndisplaying any UI related to authorization to the user.\nIt can be used to request an access token after the user authorized the application.\nServer should return the token which will be passed back to the application.\n\nWhen using `interactive = false` mode then the response event is always\n`oauth2-token-response`, even when there was authorization error or user never\nauthorized the application. In this case the response object will not carry\n`accessToken` property and always have `interactive` set to `false` and `code`\nto determine cause of unsuccessful request.\n\n### Example\n\n```\nconst settings = {\n  interactive: false,\n  type: 'implicit',\n  clientId: 'CLIENT ID',\n  redirectUri: 'https://example.com/auth-popup.html',\n  authorizationUri: 'https://auth.example.com/token'\n  state: '1234'\n};\nconst event = new CustomEvent('oauth2-token-requested', { 'detail': settings, bubbles: true });\ndocument.dispatchEvent(event);\n\ndocument.body.addEventListener('oauth2-token-response', (e) => {\n  let info = e.detail;\n  if (info.state !== '1234') {\n    return;\n  }\n  if (info.interactive === false && info.code) {\n    // unsuccessful request\n    return;\n  }\n  let token = info.accessToken;\n});\n```\n\n## OAuth 1\nAn element to perform OAuth1 authorization and to sign auth requests.\n\nNote that the OAuth1 authorization wasn't designed for browser. Most existing\nOAuth1 implementation disallow browsers to perform the authorization by\nnot allowing POST requests to authorization server. Therefore receiving token\nmay not be possible without using browser extensions to alter HTTP request to\nenable CORS.\nIf the server disallow obtaining authorization token and secret from clients\nthen your application has to listen for `oauth1-token-requested` custom event\nand perform authorization on the server side.\n\nWhen auth token and secret is available and the user is to perform a HTTP request,\nthe request panel sends `before-request` custom event. This element handles the event\nand applies authorization header with generated signature to the request.\n\n## OAuth 1 configuration object\n\nBoth authorization or request signing requires detailed configuration object.\nThis is handled by the request panel. It sets OAuth1 configuration in the `request.auth`\nproperty.\n\n| Property | Type | Description |\n| ----------------|-------------|---------- |\n| `signatureMethod` | `String` | One of `PLAINTEXT`, `HMAC-SHA1`, `RSA-SHA1` |\n| `requestTokenUrl` | `String` | Token request URI. Optional for before request. Required for authorization |\n| `accessTokenUri` | `String` | Access token request URI. Optional for before request. Required for authorization |\n| `authorizationUri` | `String` | User dialog URL. |\n| `consumerKey` | `String` | Consumer key to be used to generate the signature. Optional for before request. |\n| `consumerSecret` | `String` | Consumer secret to be used to generate the signature. Optional for before request. |\n| `redirectUri` | `String` | Redirect URI for the authorization. Optional for before request. |\n| `authParamsLocation` | `String` | Location of the authorization parameters. Default to `authorization` header |\n| `authTokenMethod` | `String` | Token request HTTP method. Default to `POST`. Optional for before request. |\n| `version` | `String` | Oauth1 protocol version. Default to `1.0` |\n| `nonceSize` | `Number` | Size of the nonce word to generate. Default to 32. Unused if `nonce` is set. |\n| `nonce` | `String` | Nonce to be used to generate signature. |\n| `timestamp` | `Number` | Request timestamp. If not set it sets current timestamp |\n| `customHeaders` | `Object` | Map of custom headers to set with authorization request |\n| `type` | `String` | Must be set to `oauth1` or during before-request this object will be ignored. |\n| `token` | `String` | Required for signing requests. Received OAuth token |\n| `tokenSecret` | `String` | Required for signing requests. Received OAuth token secret |\n\n## Error codes\n\n-  `params-error` Oauth1 parameters are invalid\n-  `oauth1-error` OAuth popup is blocked.\n-  `token-request-error` HTTP request to the authorization server failed\n-  `no-response` No response recorded.\n\n## Acknowledgements\n\n- This element uses [jsrsasign](https://github.com/kjur/jsrsasign) library distributed\nunder MIT licence.\n- This element uses [crypto-js](https://code.google.com/archive/p/crypto-js/) library\ndistributed under BSD license.\n\n## Required dependencies\n\nThe `CryptoJS` and `RSAKey` libraries are not included into the element sources.\nIf your project do not use this libraries already include it into your project.\n\n```\nnpm i cryptojslib jsrsasign\n```\n\n```html\n<script src=\"../../../cryptojslib/components/core.js\"></script>\n<script src=\"../../../cryptojslib/rollups/sha1.js\"></script>\n<script src=\"../../../cryptojslib/components/enc-base64-min.js\"></script>\n<script src=\"../../../cryptojslib/rollups/md5.js\"></script>\n<script src=\"../../../cryptojslib/rollups/hmac-sha1.js\"></script>\n<script src=\"../../../jsrsasign/lib/jsrsasign-rsa-min.js\"></script>\n```\n","readmeFilename":"README.md"}