{"_id":"@arthit75420/socketio-jwt-pos","_rev":"2-057354d93d647ab19bc3187d960d1bfc","name":"@arthit75420/socketio-jwt-pos","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@arthit75420/socketio-jwt-pos","version":"1.0.0","description":"authenticate socket.io connections using JWTs","main":"lib/index.js","types":"./types/index.d.ts","keywords":["socket","socket.io","jwt"],"author":{"name":"SAN","email":"arthit75420@gmail.com"},"repository":{"type":"git","url":"git+https://github.com/arthit75420/socketio-jwt-pos.git"},"scripts":{"test":"mocha"},"license":"MIT","dependencies":{"jsonwebtoken":"^8.3.0","xtend":"~2.1.2"},"devDependencies":{"@types/socket.io":"~1.4.29","body-parser":"~1.17.1","express":"~4.15.2","mocha":"~3.2.0","request":"~2.81.0","serve-static":"^1.13.2","q":"^1.5.1","server-destroy":"~1.0.1","should":"~11.2.1","socket.io":"^1.7.3","socket.io-client":"^1.7.3"},"bugs":{"url":"https://github.com/arthit75420/socketio-jwt-pos/issues"},"homepage":"https://github.com/arthit75420/socketio-jwt-pos#readme","directories":{"example":"example","lib":"lib","test":"test"},"gitHead":"04294c69c5172a315d9e013bdf146ffbd2d83cfe","_id":"@arthit75420/socketio-jwt-pos@1.0.0","_nodeVersion":"12.18.3","_npmVersion":"6.14.8","dist":{"integrity":"sha512-8zM6LHAe6Se07SODWVP+rEpSdf4Peo9m2Z/1qPTi/dYrNbP4u//jixSgEbGgH5A/GbvhBwAIbpj1bjc6pV0CBA==","shasum":"b054c5e700be477cf3ead53944c9a7704c838da9","tarball":"https://registry.npmjs.org/@arthit75420/socketio-jwt-pos/-/socketio-jwt-pos-1.0.0.tgz","fileCount":22,"unpackedSize":61205,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfc6Y9CRA9TVsSAnZWagAA2qUP/jYd2JFUdtZ5pe6NqzWy\n/mzeZDMvu5J1Zm66NVGEIbNFN/EBxZawLsiEZgxfMvfyPm3iBLRZiMGLPQ6b\nPTPfNIOuKzlTuglVWn/7YlPNJ0xiOTQW0nsg12NS1+3TMzEbp1zLbrbUvQ1U\n+FdTJaHU6Zbt9NHSNpEoERRpRktRaKLXr0KBs0kxNdeKOcgxpGiqk/XoQf7M\nlx5aEJMCjjZ6kf3JiYSzHhtRH1f7u8ccoFJdlpxehVVD4xVD9U1w6Jgih8dg\nTl8J7FKqz42sg6bE2zAjQV/z6hqWvz7aTPvcyc1nvrcbpqNTu73TZJ1PQQhC\n0fZag+E7XQWdKe2Jiqv9t0gApvKq3Cac40r3DabLn+xq5N+nzkAWYeCOVEy7\n6P9BSz0V8pcpn2LOjf/vBnUYA9LrzjGHhG4WFr/B828n7D5qeaGWMT9ZTtVW\ntJwvCa5lCBd/jXUYWaxVJQ703cRmEl4P7016TCuSDhgkNE5O013QBWmd0Iqt\nWDM9//u9nkJkhPhjuSTzCyy0P3nLb5QANJF0tsXABXZvtgqaaU/l1kkxQz79\nffhG/9TdVBNi2oyOxKCGsvzGAR1eI2/63udtvJ3k/9bUPBwcmUUQGpv0y7vG\niBTgKiucfohd7VsQVmLRByKrBz21Hl9Do7hmSlecLKF+jnBEXgYhFxm0CKfI\n89r8\r\n=vbpE\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDxHoT0atEevcHCIjn03dGDDsX/Ck8kbX92p6P9NRFfjwIgUc/gqxyMkQpqTwM/uHejVsB2mJZ28XURTs+XvfeJhoc="}]},"maintainers":[{"name":"arthit75420","email":"arthit75420@gmail.com"}],"_npmUser":{"name":"arthit75420","email":"arthit75420@gmail.com"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/socketio-jwt-pos_1.0.0_1601414716420_0.25790809058040676"},"_hasShrinkwrap":false},"1.0.1":{"name":"@arthit75420/socketio-jwt-pos","version":"1.0.1","description":"authenticate socket.io connections using JWTs","main":"lib/index.js","types":"./types/index.d.ts","keywords":["socket","socket.io","jwt"],"author":{"name":"SAN","email":"arthit75420@gmail.com"},"repository":{"type":"git","url":"git+https://github.com/arthit75420/socketio-jwt-pos.git"},"scripts":{"test":"mocha"},"license":"MIT","dependencies":{"jsonwebtoken":"^8.3.0","xtend":"~2.1.2"},"devDependencies":{"@types/socket.io":"~1.4.29","body-parser":"~1.17.1","express":"~4.15.2","mocha":"~3.2.0","request":"~2.81.0","serve-static":"^1.13.2","q":"^1.5.1","server-destroy":"~1.0.1","should":"~11.2.1","socket.io":"^1.7.3","socket.io-client":"^1.7.3"},"bugs":{"url":"https://github.com/arthit75420/socketio-jwt-pos/issues"},"homepage":"https://github.com/arthit75420/socketio-jwt-pos#readme","directories":{"example":"example","lib":"lib","test":"test"},"gitHead":"a2bba53cf5151c721404a36198a17db835bc614b","_id":"@arthit75420/socketio-jwt-pos@1.0.1","_nodeVersion":"12.18.3","_npmVersion":"6.14.8","dist":{"integrity":"sha512-a1Bq/O2LsMLMS1zZ9vSzNmzSkBbHqqIY96HKrSdwjXsfCXGzOWhhByrzyUiZkH7a0ALPsfkum03ZLdeCRk1QXg==","shasum":"c763a375e38f2711bd5bd827d1b5cb64354aaa0e","tarball":"https://registry.npmjs.org/@arthit75420/socketio-jwt-pos/-/socketio-jwt-pos-1.0.1.tgz","fileCount":22,"unpackedSize":58259,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfc6iACRA9TVsSAnZWagAAHjgP/jr/m/UGc9Y9ECa/mzJV\nkRuByKodszGpksiXUHTMfv2RIV3eYn+W2fnmiZcPD4/3LgTHibnVQ40Fd3s8\nKlJOQWqgnUX2lxA2oK8km9p2wYUpPrh2rAjAsUHitsQwoEnKDI+3F+h4bo3b\n/kbdwfDUzeOP6O9Hft6VgVlNNlOendXUK1uCI9IPEIHgKYmhMaX8WkIpgFAt\nY02icxrnRnjQ2t8xiDBBCrMjQ8UKMHLREempPIYDYR+RZ3y7m/cpzGwgG8BA\nZoirMgayvfJg4Ow6K9wnLUiXMbGUZPLFaUP2o4clyc4Not1zo/0FWLyBfWik\nrkLFTnLhiGQGKLO7/iTLP2sj+o1uWwpc8V28Mmi+4SKkame/qDGHcYGOHbwG\ni9cp7siiFBmCgpuxcWBV1oDp82HNZ/CSlrTb/YadBLWmfq6c9pDMaSwH3t+0\nRlAGAC5GTsOZuEjB3zyFrnzgTZ3kWgCJvy1zpuGZQ1es0IERdNOjMef4gZnE\nIgcj/SM1XTQetPzGxZqetc6CJ2vO6UTatvKJAIoIZ7wXu6xNiAmUCq+mQabV\nIpNE/inq/wWGpvaBbUOIJEmUosAdZRQfxNL8DiwaHluBhEM3clMzV7qU4/nR\nE5e23u2EsvA1SIajrfLxndUMk8hYGkv+pXh4etkPxnIeQN/zpmSF2WVw3jHT\nBOvw\r\n=6wfr\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIF4rYqs/q3+kTAdSq3L1G40KbaT9xrX7FkqAXeINNtIkAiB2We3GkRXOBey2j6uJJ9GxQ7G+/XeuK5nX3PRaqprg5w=="}]},"maintainers":[{"name":"arthit75420","email":"arthit75420@gmail.com"}],"_npmUser":{"name":"arthit75420","email":"arthit75420@gmail.com"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/socketio-jwt-pos_1.0.1_1601415295757_0.6750005463394813"},"_hasShrinkwrap":false}},"time":{"created":"2020-09-29T21:25:16.372Z","1.0.0":"2020-09-29T21:25:16.598Z","modified":"2022-04-04T15:37:25.718Z","1.0.1":"2020-09-29T21:34:55.907Z"},"maintainers":[{"name":"arthit75420","email":"arthit75420@gmail.com"}],"description":"authenticate socket.io connections using JWTs","homepage":"https://github.com/arthit75420/socketio-jwt-pos#readme","keywords":["socket","socket.io","jwt"],"repository":{"type":"git","url":"git+https://github.com/arthit75420/socketio-jwt-pos.git"},"author":{"name":"SAN","email":"arthit75420@gmail.com"},"bugs":{"url":"https://github.com/arthit75420/socketio-jwt-pos/issues"},"license":"MIT","readme":"# socketio-jwt-pos\r\n\r\n[![All Contributors](https://img.shields.io/badge/all_contributors-5-orange.svg?style=flat-square)](#contributors)\r\n <img src=\"https://img.shields.io/badge/community-driven-brightgreen.svg\"/> <br>\r\n\r\n## Installation\r\n\r\n```bash\r\nnpm install socketio-jwt-pos\r\n```\r\n\r\n## Usage\r\n\r\n```javascript\r\n// set authorization for socket.io\r\nio.sockets\r\n  .on('connection', socketioJwt.authorize({\r\n    secret: 'your secret or public key',\r\n    timeout: 15000 // 15 seconds to send the authentication message\r\n  }))\r\n  .on('authenticated', (socket) => {\r\n    //this socket is authenticated, we are good to handle more events from it.\r\n    console.log(`hello! ${socket.decoded_token.name}`);\r\n  });\r\n```\r\n\r\n**Note:** If you are using a base64-encoded secret (e.g. your Auth0 secret key), you need to convert it to a Buffer: `Buffer('your secret key', 'base64')`\r\n\r\n**Client side**\r\n\r\n```javascript\r\nconst socket = io.connect('http://localhost:9000');\r\nsocket.on('connect', () => {\r\n  socket\r\n    .emit('authenticate', { token: jwt }) //send the jwt\r\n    .on('authenticated', () => {\r\n      //do other things\r\n    })\r\n    .on('unauthorized', (msg) => {\r\n      console.log(`unauthorized: ${JSON.stringify(msg.data)}`);\r\n      throw new Error(msg.data.type);\r\n    })\r\n});\r\n```\r\n\r\n### One roundtrip\r\n\r\nThe previous approach uses a second roundtrip to send the jwt. There is a way you can authenticate on the handshake by sending the JWT as a query string, the caveat is that intermediary HTTP servers can log the url.\r\n\r\n```javascript\r\nconst io            = require('socket.io')(server);\r\nconst socketioJwt   = require('socketio-jwt');\r\n```\r\n\r\nWith socket.io < 1.0:\r\n\r\n```javascript\r\nio.set('authorization', socketioJwt.authorize({\r\n  secret: 'your secret or public key',\r\n  handshake: true\r\n}));\r\n\r\nio.on('connection', (socket) => {\r\n  console.log('hello!', socket.handshake.decoded_token.name);\r\n});\r\n```\r\n\r\nWith socket.io >= 1.0:\r\n\r\n```javascript\r\nio.use(socketioJwt.authorize({\r\n  secret: 'your secret or public key',\r\n  handshake: true\r\n}));\r\n\r\nio.on('connection', (socket) => {\r\n  console.log('hello!', socket.decoded_token.name);\r\n});\r\n```\r\n\r\nFor more validation options see [auth0/jsonwebtoken](https://github.com/auth0/node-jsonwebtoken).\r\n\r\n**Client side**\r\n\r\nAppend the jwt token using query string:\r\n\r\n```javascript\r\nconst socket = io.connect('http://localhost:9000', {\r\n  query: `token=${your_jwt}`\r\n});\r\n```\r\n\r\nAppend the jwt token using 'Authorization Header' (Bearer Token):\r\n\r\n```javascript\r\nconst socket = io.connect('http://localhost:9000', {\r\n  extraHeaders: { Authorization: `Bearer ${your_jwt}` }\r\n});\r\n```\r\n\r\nBoth options can be combined or used optionally.\r\n\r\n### Authorization Header Requirement\r\n\r\nRequire Bearer Tokens to be passed in as an Authorization Header\r\n\r\n**Server side**:\r\n\r\n```javascript\r\nio.use(socketioJwt.authorize({\r\n  secret: 'your secret or public key',\r\n  handshake: true,\r\n  auth_header_required: true\r\n}));\r\n```\r\n\r\n### Handling token expiration\r\n\r\n**Server side**\r\n\r\nWhen you sign the token with an expiration time (example: 60 minutes):\r\n\r\n```javascript\r\nconst token = jwt.sign(user_profile, jwt_secret, { expiresIn: 60*60 });\r\n```\r\n\r\nYour client-side code should handle it as below:\r\n\r\n**Client side**\r\n\r\n```javascript\r\nsocket.on('unauthorized', (error) => {\r\n  if (error.data.type == 'UnauthorizedError' || error.data.code == 'invalid_token') {\r\n    // redirect user to login page perhaps?\r\n    console.log('User token has expired');\r\n  }\r\n});\r\n```\r\n\r\n### Handling invalid token\r\n\r\nToken sent by client is invalid.\r\n\r\n**Server side**:\r\n\r\nNo further configuration needed.\r\n\r\n**Client side**\r\n\r\nAdd a callback client-side to execute socket disconnect server-side.\r\n\r\n```javascript\r\nsocket.on('unauthorized', (error, callback) => {\r\n  if (error.data.type == 'UnauthorizedError' || error.data.code == 'invalid_token') {\r\n    // redirect user to login page perhaps or execute callback:\r\n    callback();\r\n    console.log('User token has expired');\r\n  }\r\n});\r\n```\r\n\r\n**Server side**\r\n\r\nTo disconnect socket server-side without client-side callback:\r\n\r\n```javascript\r\nio.sockets.on('connection', socketioJwt.authorize({\r\n  secret: 'secret goes here',\r\n  // No client-side callback, terminate connection server-side\r\n  callback: false\r\n}))\r\n```\r\n\r\n**Client side**\r\n\r\nNothing needs to be changed client-side if callback is false.\r\n\r\n**Server side**\r\n\r\nTo disconnect socket server-side while giving client-side 15 seconds to execute callback:\r\n\r\n```javascript\r\nio.sockets.on('connection', socketioJwt.authorize({\r\n  secret: 'secret goes here',\r\n  // Delay server-side socket disconnect to wait for client-side callback\r\n  callback: 15000\r\n}))\r\n```\r\n\r\nYour client-side code should handle it as below:\r\n\r\n**Client side**\r\n\r\n```javascript\r\nsocket.on('unauthorized', (error, callback) => {\r\n  if (error.data.type == 'UnauthorizedError' || error.data.code == 'invalid_token') {\r\n    // redirect user to login page perhaps or execute callback:\r\n    callback();\r\n    console.log('User token has expired');\r\n  }\r\n});\r\n```\r\n\r\n### Getting the secret dynamically\r\n\r\nYou can pass a function instead of a string when configuring secret.\r\nThis function receives the request, the decoded token and a callback. This\r\nway, you are allowed to use a different secret based on the request and / or\r\nthe provided token.\r\n\r\n**Server side**\r\n\r\n```javascript\r\nconst SECRETS = {\r\n  'user1': 'secret 1',\r\n  'user2': 'secret 2'\r\n}\r\n\r\nio.use(socketioJwt.authorize({\r\n  secret: (request, decodedToken, callback) => {\r\n    // SECRETS[decodedToken.userId] will be used as a secret or\r\n    // public key for connection user.\r\n\r\n    callback(null, SECRETS[decodedToken.userId]);\r\n  },\r\n  handshake: false\r\n}));\r\n```\r\n\r\n### Altering the value of the decoded token\r\n\r\nYou can pass a function to change the value of the decoded token\r\n\r\n```javascript\r\n\r\nio.on(\r\n  'connection',\r\n  socketIOJwt.authorize({\r\n    customDecoded: (decoded) => {\r\n      return \"new decoded token\";\r\n    },\r\n    secret: 'my_secret_key',\r\n    decodedPropertyName: 'my_decoded_token',\r\n  }),\r\n);\r\n\r\nio.on('authenticated', (socket) => {\r\n  console.log(socket.my_decoded_token); // new decoded token\r\n});\r\n\r\n```\r\n\r\n## Contribute\r\n\r\nFeel like contributing to this repo? We're glad to hear that! Before you start contributing please visit our [Contributing Guideline](https://github.com/auth0-community/getting-started/blob/master/CONTRIBUTION.md).\r\n\r\nHere you can also find the [PR template](https://github.com/auth0-community/socketio-jwt/blob/master/PULL_REQUEST_TEMPLATE.md) to fill once creating a PR. It will automatically appear once you open a pull request.\r\n\r\nYou might run the unit tests, before creating a PR:\r\n```bash\r\nnpm test\r\n```\r\n\r\n## Repo Community\r\n\r\nFeel like PRs and issues are not enough? Want to dive into further discussion about the tool? We created topics for each Auth0 Community repo so that you can join discussion on stack available on our repos. Here it is for this one: [socketio-jwt](https://community.auth0.com/t/auth0-community-oss-socketio-jwt/20024)\r\n\r\n<a href=\"https://community.auth0.com/\">\r\n<img src=\"/assets/join_auth0_community_badge.png\"/>\r\n</a>\r\n\r\n## License\r\n\r\nThis project is licensed under the MIT license. See the [LICENSE](https://github.com/auth0-community/socketio-jwt/blob/master/LICENSE) file for more info.\r\n\r\n## What is Auth0?\r\n\r\nAuth0 helps you to:\r\n\r\n* Add authentication with [multiple authentication sources](https://docs.auth0.com/identityproviders), either social like\r\n  * Google\r\n  * Facebook\r\n  * Microsoft\r\n  * Linkedin\r\n  * GitHub\r\n  * Twitter\r\n  * Box\r\n  * Salesforce\r\n  * etc.\r\n\r\n  **or** enterprise identity systems like:\r\n  * Windows Azure AD\r\n  * Google Apps\r\n  * Active Directory\r\n  * ADFS\r\n  * Any SAML Identity Provider\r\n\r\n* Add authentication through more traditional [username/password databases](https://docs.auth0.com/mysql-connection-tutorial)\r\n* Add support for [linking different user accounts](https://docs.auth0.com/link-accounts) with the same user\r\n* Support for generating signed [JSON Web Tokens](https://docs.auth0.com/jwt) to call your APIs and create user identity flow securely\r\n* Analytics of how, when and where users are logging in\r\n* Pull data from other sources and add it to user profile, through [JavaScript rules](https://docs.auth0.com/rules)\r\n\r\n## Create a free Auth0 account\r\n\r\n* Go to [Auth0 website](https://auth0.com/signup)\r\n* Hit the **SIGN UP** button in the upper-right corner\r\n","readmeFilename":"README.md"}