{"_id":"@apsu/express-fido","name":"@apsu/express-fido","dist-tags":{"latest":"0.0.0"},"versions":{"0.0.0":{"name":"@apsu/express-fido","version":"0.0.0","description":"simple FIDO authentication for express apps","type":"module","exports":"./express-fido.js","dependencies":{"fido2-lib":"^3.4.3"},"gitHead":"b415d09767ee95e7d985aaada3ad73d360e0747f","_id":"@apsu/express-fido@0.0.0","_nodeVersion":"16.20.0","_npmVersion":"8.19.4","dist":{"integrity":"sha512-XSa5TIsUEQBg8ZmY9TX2U1zvyCpUI8QACtWI5uO2EEXhGocinnBeyokUGj9B16kqKUUzQWKBaNICct003TTljQ==","shasum":"9677dada512517b38be4ca3d60ddd0bb09487b78","tarball":"https://registry.npmjs.org/@apsu/express-fido/-/express-fido-0.0.0.tgz","fileCount":8,"unpackedSize":14424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCVO+CmbX3y/J8fW7iToKTUqMMx/xO7BiM6lJasbBJRpwIgNJMLMj5x8REVjJNcCLzzPTf8Jl3axnuVKJf+aITf93o="}]},"_npmUser":{"name":"rremer","email":"reanjr@gmail.com"},"directories":{},"maintainers":[{"name":"rremer","email":"reanjr@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/express-fido_0.0.0_1701803825882_0.6172568426347247"},"_hasShrinkwrap":false}},"time":{"created":"2023-12-05T19:17:05.789Z","0.0.0":"2023-12-05T19:17:06.105Z","modified":"2023-12-05T19:17:06.408Z"},"maintainers":[{"name":"rremer","email":"reanjr@gmail.com"}],"description":"simple FIDO authentication for express apps","readme":"Simple FIDO public key implementation for Express.js.\n\nexpress-fido\n============\n\nServer Example\n--------------\n```js\nimport http from \"http\";\nimport express from \"express\";\nimport session from \"express-session\";\nimport bodyParser from \"body-parser\";\nimport {FIDO} from \"@apsu/express-fido\";\n\nconst app = express();\nconst server = http.createServer(app);  // example expects TLS proxy\nconst users = new Map();                // mock users DB\nconst rpId = \"localhost\";               // identifies FIDO server\nconst fido = new FIDO({rpId});\n\napp.set(\"trust proxy\", 1);              // example expects TLS proxy\napp.use(session({secret: \"secret\"}));   // sessions must be enabled\napp.use(bodyParser.json());             // middleware expects parsed body\n\napp.use(fido.init({\n  // implement load function to get user key from DB\n  async load(id) {\n    return users.get(id);\n  },\n\n  // implement save function to save registered user\n  async save(id, name, displayName, publicKey, counter) {\n    const user = {id, name, displayName, publicKey, counter};\n    users.set(id, user);\n  }\n}));\n\n// endpoint to send attestation options to client (for registering)\napp.get(\"/register/:fidoName\", fido.attestationOptions());\n\n// endpoint to send assertion options to client (for login)\napp.get(\"/login/challenge\", fido.assertionOptions());\n\n// endpoint to save credential sent from client\napp.post(\"/register\", fido.attestation());\n\n// endpoint to verify credential sent from client\napp.post(\"/login\", fido.assertion());\n\nserver.listen(process.env.LISTEN_PORT, process.env.LISTEN_ADDR);\n```\n\nClient Example\n--------------\nThis client example makes use of the [client library](lib/fido-client.js)\nprovided by this package.  This example assumes you have copied the library\ninto the same directory as the example code.\n\n**index.html**  \n```html\n<!doctype html>\n<html>\n  <head>\n    <script type=\"module\" src=\"client.js\"></script>\n  </head>\n  <body>\n    <section class=\"register\">\n      <label for=\"fidoName\">Username</label>\n      <input id=\"fidoName\" autocomplete=\"webauthn username\">\n      <button id=\"register\" type=\"button\">Register</button>\n    </section>\n    <section class=\"login\">\n      <button id=\"login\" type=\"button\">Login</button>\n    </section>\n  </body>\n</html>\n```\n\n**client.js**  \n```js\nimport * as fido from \"./fido-client.js\";\n\nconst {href} = window.location;\n\ndocument.addEventListener(\"DOMContentLoaded\", () => {\n  const register = document.getElementById(\"register\");\n  const login = document.getElementById(\"login\");\n  const fidoName = document.getElementById(\"fidoName\");\n\n  register.addEventListener(\"click\", async () => {\n    const name = fidoName.value;\n    const opt = {url: new URL(`/register/${name}`, href)};\n    const cred = {url: new URL(\"/register\", href)};\n    const user = await fido.create({opt, cred});\n\n    console.info(\"logged in as\", user.name);\n  });\n\n  login.addEventListener(\"click\", async () => {\n    const opt = {url: new URL(\"/login/challenge\", href)};\n    const cred = {url: new URL(\"/login\", href)};\n    const user = await fido.get({opt, cred});\n\n    console.info(\"logged in as\", user.name);\n  });\n});\n```\n","readmeFilename":"README.md"}