{"_id":"@asgardeo/auth-express","_rev":"2-a70148ddc4ec4a062b74f0290184b236","name":"@asgardeo/auth-express","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@asgardeo/auth-express","version":"0.1.0","description":"Asgardeo Auth Express JS SDK and Sample Apps","main":"dist/src/index.js","scripts":{"lint":"eslint --ext .js,.ts .","fix-lint":"eslint --ext .js,.ts . --fix","test":"echo \"Error: no test specified\" && exit 1","build":"cross-env NODE_ENV=production rimraf dist && rimraf umd && yarn run type-check","type-check":"tsc"},"keywords":[],"author":"","license":"Apache-2.0","devDependencies":{"@types/node":"^17.0.3","cross-env":"^7.0.3","typescript":"^4.5.2"},"dependencies":{"@asgardeo/auth-node":"^0.1.0","express":"^4.17.2","uuid":"^8.3.2"},"types":"./dist/src/index.d.ts","gitHead":"3bbd8270ffde0cc6f71af8fc00bebd99b4173de2","_id":"@asgardeo/auth-express@0.1.0","_nodeVersion":"16.14.2","_npmVersion":"8.5.0","dist":{"integrity":"sha512-ANcAjEaeXGqdEKctJ8BXmapXMn1tbMBdFmB4RZvaz99bPidn82HMoZsFvssURq8IqimCwlCC+B4ywnZh6VWI1A==","shasum":"f648139b8735a69e39ef16c7e7e5844e035b3305","tarball":"https://registry.npmjs.org/@asgardeo/auth-express/-/auth-express-0.1.0.tgz","fileCount":74,"unpackedSize":139529,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFlV7NjvfKIJIIpimckRN8qsAxOMj3vyhukJoMRUYV3hAiEA6HJOUcNdE+AE4Otp0tnrfSHpeK973+pEBBPF5+qkUAw="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJibAtdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr22A//f62o0INhGsLESSS95TAFDSuSdaIy3muMaJIo4fa4TLP7F5Lo\r\nQxySdsV71bUve+9nS//XpaKpw1ZAQ2mwSn5M4kIk28WfA1ReTWnzfTf/57Dv\r\n+1kTpVt+DPaJn4jXc09PfOpHPccpuxrN+pwgS7SwI7akJHPybYz2Yx67F5Dt\r\n10bntkqQY9oCMf78btbd5OJ4ZXJ8k+hVR5hwMOjMscvLIpOtPOdQHULb/KMc\r\nDa4T03YHSfyZdMR1O4ApUYfQT4GzWu1mdbvABdQqY6URCt0ghYYvvfF84NOv\r\nJhAWEiktA0C1ZdwZ75DMONfMZV7VybSPb3ei/RlWe+yFtxk+nO5GPwEQZ5o4\r\nvi29TjHYbRwL+OEie19rfnFFo2K8RJjs/nfJ8w8RJNlNpLFsZhddsTEpJihc\r\njg+Yog4VleqPHVj2IFnMpSyBbabmuwOcFzx1ednqlWOuM4aWdJzUJDuy3igd\r\ntEmKtxja/BSb5a7YCKOeaa9KYTBJ6Rnlsk3+mMXaWT/uTmFuC0ln8d/hJvmx\r\nDNo8JqobSwTUPpVuyL1O5j0FyftPM6u82UPJXBtJGEHHAjtLbQ7Zpw+CZb9z\r\n2ZkpT8l2aE/LLnaHC42WDMN8CRVDA5LFXvfZ8Zli4drb3jDhpYNSzM0CvVEh\r\n1D8QLHl23CoSuEVHxwHVQZ48U6IJd/JS0W0=\r\n=3fBE\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"wso2-org","email":"techops@wso2.com"},"directories":{},"maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/auth-express_0.1.0_1651247965437_0.9505898875015975"},"_hasShrinkwrap":false},"0.1.1":{"name":"@asgardeo/auth-express","version":"0.1.1","description":"Asgardeo Auth Express JS SDK and Sample Apps","main":"dist/src/index.js","scripts":{"lint":"eslint --ext .js,.ts .","fix-lint":"eslint --ext .js,.ts . --fix","test":"echo \"Error: no test specified\" && exit 1","build":"cross-env NODE_ENV=production rimraf dist && rimraf umd && yarn run type-check","type-check":"tsc"},"keywords":[],"author":"","license":"Apache-2.0","devDependencies":{"@types/node":"^17.0.3","cross-env":"^7.0.3","typescript":"^4.5.2"},"dependencies":{"@asgardeo/auth-node":"^0.1.1","express":"^4.17.2","uuid":"^8.3.2"},"types":"./dist/src/index.d.ts","gitHead":"fd34d0468d57b644e6bdffdff421f35d02904281","_id":"@asgardeo/auth-express@0.1.1","_nodeVersion":"16.17.0","_npmVersion":"8.15.0","dist":{"integrity":"sha512-iIaqMWwbrxP9h5fdF8e9c57I0EeeiMfhtg8rngqoslDrdxwVQWZAg7/YdRqu7x9SmnUhX8wJScpxBPf+Netbzw==","shasum":"dc5b57d46bfae3c6303f87c44731a3b83b3a208e","tarball":"https://registry.npmjs.org/@asgardeo/auth-express/-/auth-express-0.1.1.tgz","fileCount":79,"unpackedSize":146144,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFgXmnWMB/qJw5m5CN93uQqL3jUWAq0eZ0xrSfegLOmTAiEAt8n1aKi65Yzi2HjBBVvKfjgDG+FQsNd2fy360dwz7iQ="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjFhAQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo4YA//S37dVwMSiLRwQe7TYnbxpWyyjncep9lCP2mCPI5XczTdz5sR\r\nv4cFGbLqIksHMLNiH8gWahhArRyzPltmPjIOU6gfPiA0q3JPfTLZ0DPbORFE\r\nZeWRRtEa1EMVJfpcdWQPz6zqAMsjMBK82QfwAevAamZzuAkk9wv+j8gT2C87\r\nTj22G718mH48WjQnyLiIANwLxIfm+CPNV1009NLJpZRkbk1T39iUiQjRaz+m\r\nbB6d8Ph1I7lX1GafduI73KaQEurXmCwKlQWoHKogiqJFjdmO8XCSZcPP20r4\r\n+9pWJF6lhuNFWiDSk8EkPU5mPdfce9CtzZ4Ha5HsWmF4Kwxn2pAFPy5laO5r\r\ngO2WSZ5PmP4zDNP1XxG4GhvHJ1el/h6PLudhS/XxNJNKZiINTGcBdGrU8Hu8\r\nNa6+aooUDCDrwOLk+IIUQnqR3K3apr34GTIpLi87w1Jh+4MBU9d9z3Y4aOuL\r\n1XjZs1HhNTq+fw7IpM6iilHaQc2qoe2BhCJPpGNjdbphFnmO3qW9GFnENIgp\r\na8rsm3tje8oTHzwoHUb8h286loDroDsdPQM8gVifG1xpJRk4mRWCdYsP8z6N\r\nwX951ECXw0zE8JG5nQcN/j9XPrLzuXqy8g4YvSkIlCpT3AYt2EEYYIma+/j4\r\nK7MnoJQ58x+UMZnecKya7YdK3qe0ZJeveSA=\r\n=Vimu\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"wso2-org","email":"techops@wso2.com"},"directories":{},"maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/auth-express_0.1.1_1662390288066_0.599049298725653"},"_hasShrinkwrap":false},"0.1.2":{"name":"@asgardeo/auth-express","version":"0.1.2","description":"Asgardeo Auth Express JS SDK and Sample Apps","main":"dist/src/index.js","scripts":{"lint":"eslint --ext .js,.ts .","fix-lint":"eslint --ext .js,.ts . --fix","test":"echo \"Error: no test specified\" && exit 1","build":"cross-env NODE_ENV=production rimraf dist && rimraf umd && yarn run type-check","type-check":"tsc"},"keywords":[],"author":"","license":"Apache-2.0","devDependencies":{"@types/node":"^17.0.3","cross-env":"^7.0.3","typescript":"^4.5.2"},"dependencies":{"@asgardeo/auth-node":"^0.1.1","express":"^4.17.2","uuid":"^8.3.2"},"types":"./dist/src/index.d.ts","gitHead":"4a18423c3f8a732b1944350e38e1c483d9dcd4e9","_id":"@asgardeo/auth-express@0.1.2","_nodeVersion":"16.17.1","_npmVersion":"8.15.0","dist":{"integrity":"sha512-CW9CDdQb3sMRbgDGfwprb8nfSDEQOIsUII8fgUa7XHWZ02vkwifySINYU0w3+22ndF7mWv+ZV07hFPxh7uvP+A==","shasum":"e1a60c25336be2e8b414bc9f39806737c805b7da","tarball":"https://registry.npmjs.org/@asgardeo/auth-express/-/auth-express-0.1.2.tgz","fileCount":79,"unpackedSize":145886,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBdQd7Ec4jToibtlgJ4Vy4YNDi6GCgP9ZamQ/x3xj1isAiEA6QFh1xbylQsQrY+gNKF/QJo43Y3UJSDVqe0MX1+SdyU="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjR35ZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq4BBAAiNHg1hPK8VajEueOUk3hyavRUSuuthXDPOyBJKqfe4DiNM0K\r\nIZyHa3LgMrJpWFYhLMQrHufTZvll19hkxQJnayayWTzigFO74ETLMk6rgwv+\r\npuapgwVtxuYK8dxvJK1+p78fJZAjFDPLeSkMXnJbdEstdEIuADVeWVtmVfkY\r\nHkoTkbLRwM9bHeDTFeg/EqIThWdC8jYvwJYRYjtmefyMjKb2eZnJ4q0q+eAT\r\nNnRZNC9w0nMcWtLw9pkkKegiaW4WyBI4wpzWDS8eXTLFMDplnHmD2zJ3Lvho\r\nc48bX5CXg1wd7xnNxpOS+XL1vNnW7oL4m0VVq/TYk6BGzvAMaTvyMHvfgvWz\r\nZzX0ggX1DJJPq5CV2MnOXiHihpNBrO/LEdEMXDTmnBVPb9HrlhsOkRv0jDYj\r\nLe/wbkXyscEpv1AYI6WLi7Hj7+sJeU/SQWwLcbe2eJw5y8GIWjc7u9eP/Yao\r\nj6fJcU6p2upmR3o11uZCeoWA9Ss6U1dyOGD/lfMqNffKJboV2BH6fkIkjC5G\r\nkgV2tNYhSEFmC8xkUwBsFzB6s2G2tJolaytQpRFAPkeQcb1GsJRV14AvPmq2\r\nG6PQDV1WA6R0Iw6M7Kk0Ba4NDaQEZfx7B7hp+23rIYnwMVrwLG5GRYkgjVI7\r\ns6nnuirPoLsU0GNzIDduoAdAed3kjsKQODM=\r\n=im46\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"wso2-org","email":"techops@wso2.com"},"directories":{},"maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/auth-express_0.1.2_1665629785605_0.9392470167565323"},"_hasShrinkwrap":false}},"time":{"created":"2022-04-29T15:59:25.395Z","0.1.0":"2022-04-29T15:59:25.614Z","modified":"2022-10-13T02:56:25.914Z","0.1.1":"2022-09-05T15:04:48.262Z","0.1.2":"2022-10-13T02:56:25.794Z"},"maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"description":"Asgardeo Auth Express JS SDK and Sample Apps","keywords":[],"license":"Apache-2.0","readme":"# Asgardeo Auth Express SDK\n\n![Builder](https://github.com/asgardeo/asgardeo-auth-js-sdk/workflows/Builder/badge.svg)\n[![Stackoverflow](https://img.shields.io/badge/Ask%20for%20help%20on-Stackoverflow-orange)](https://stackoverflow.com/questions/tagged/wso2is)\n[![Join the chat at https://discord.gg/wso2](https://img.shields.io/badge/Join%20us%20on-Discord-%23e01563.svg)](https://discord.gg/wso2)\n[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://github.com/wso2/product-is/blob/master/LICENSE)\n[![Twitter](https://img.shields.io/twitter/follow/wso2.svg?style=social&label=Follow)](https://twitter.com/intent/follow?screen_name=wso2)\n\n\n## Table of Content\n\n- [Asgardeo Auth Express SDK](#asgardeo-auth-express-sdk)\n  - [Table of Content](#table-of-content)\n  - [Introduction](#introduction)\n  - [Prerequisite](#prerequisite)\n  - [Install](#install)\n  - [Getting Started](#getting-started)\n  - [Middleware](#middleware)\n    - [asgardeoExpressAuth](#asgardeoexpressauth)\n      - [Arguments](#arguments)\n      - [Example](#example)\n      - [Description](#description)\n      - [Example Usage](#example-usage)\n    - [protectRoute](#protectRoute)\n      - [Description](#description-1)\n      - [Example Usage](#example-usage-1)\n  - [APIs](#apis)\n    - [getIDToken](#getIDToken)\n    - [getBasicUserInfo](#getBasicUserInfo)\n    - [getOIDCServiceEndpoints](#getOIDCServiceEndpoints)\n    - [getDecodedIDToken](#getdecodedidtoken)\n    - [getAccessToken](#getAccessToken)\n    - [revokeAccessToken](#revokeAccessToken)\n    - [requestCustomGrant](#requestCustomGrant)\n    - [updateConfig](#updateConfig)\n    - [isSignOutSuccessful](#isSignOutSuccessful)\n    - [isSignOutSuccessful](#isSignOutSuccessful) \n  - [Data Storage](#data-storage)\n  - [Models](#models)\n    - [ExpressClientConfig](#expressclientconfig)\n    - [Store](#store)\n    - [cookieConfig](#cookieconfig)\n    - [UnauthenticatedCallback](#UnauthenticatedCallback)\n  - [Develop](#develop)\n    - [Prerequisites](#prerequisites)\n    - [Installing Dependencies](#installing-dependencies)\n  - [Contribute](#contribute)\n    - [Reporting issues](#reporting-issues)\n  - [License](#license)\n\n## Introduction\n\nAsgardeo Auth Express SDK implements OIDC authentication in JavaScript/TypeScript-based server-side apps written with Express Framework. This SDK wraps around the `@asgardeo/auth-node` to provide framework-specific functionalities for Express enabling the developers to use OIDC authentication in the applications with minimum effort.\n\n## Prerequisite\n\nCreate an organization in Asgardeo if you don't already have one. The organization name you choose will be referred to as `<org_name>` throughout this documentation.\n\nIf you are using [Asgardeo Cloud](https://wso2.com/asgardeo/) as the identity server, \n1. Create a **Standard-Based Application** in the console.\n2. In the Protocol section in Asgardeo console,\n    1. Change **Allowed grant types** to **Code** and **Refresh Token**.\n    2. Specify the login and logout URLs under **Authorized redirect URLs**.\n          ```\n           # default login url:\n          https://<host>:<port>/login\n            \n          # default logout url:\n          https://<host>:<port>/logout            \n          ```\n    3. Add the HTTP origin under the Allowed Origin.\n\n## Install\n\nInstall the library from the npm registry.\n\n```\nnpm install @asgardeo/auth-express\n```\n\n## Getting Started\n\n```javascript\n//Import Express\nconst express = require('express');\n\n// Import Cookie Parser to access request cookies.\nconst cookieParser = require('cookie-parser');\n\n// The SDK provides a client middleware that can be used to carry out the authentication.\nconst { AsgardeoExpressClient } = require(\"@asgardeo/auth-express\");\n\n\n// Create a config object containing the necessary configurations.\nconst config = {\n  clientID: \"<YOUR_CLIENT_ID>\",\n  clientSecret: \"<YOUR_CLIENT_SECRET>\",\n  baseUrl: \"https://api.asgardeo.io/t/<org_name>\",\n  appURL: \"http://localhost:3000\",\n  scope: [\"openid\", \"profile\"]\n};\n\n//Initialize an Express App\nconst app = express();\n\n// Use cookie parser in the Express App.\napp.use(cookieParser())\n\n//Initialize Asgardeo Express Client\nconst authClient = AsgardeoExpressClient.getInstance(config);\n\n//Define onSignIn method to handle successful sign in\nconst onSignIn = (res, response) => {\n  if (response) {\n    res.status(200).send(response);\n  }\n};\n\n//Define onSignOut method to handle successful sign out\nconst onSignOut = (res) => {\n  res.status(200).send(\"Sign out successful\");\n};\n\n//Define onError method to handle errors\nconst onError = (res, error) => {\n  if(error){\n    res.status(400).send(error);\n  }\n};\n\n//Use the Asgardeo Auth Client\napp.use(\n  AsgardeoExpressClient.asgardeoExpressAuth(onSignIn, onSignOut, onError)\n);\n\n//At this point the default /login and /logout routes should be available.\n//Users can use these two routes for authentication.\n\n//A regular route\napp.get(\"/\", (req, res) => {\n    res.status(200).send(\"Hello World\");\n});\n\n//A Protected Route\n\n//Define the callback function to handle unauthenticated requests\nconst authCallback = (res, error) => {\n  if(error){\n    res.status(400).send(error);\n  }\n  // Return true to end the flow at the middleware.\n  return true;\n};\n\n//Create a new middleware to protect the route\nconst isAuthenticated = AsgardeoExpressClient.protectRoute(authCallback);\n\napp.get(\"/protected\", isAuthenticated, (req, res) => {\n    res.status(200).send(\"Hello from Protected Route\");\n});\n\n//Start the express app on PORT 3000\napp.listen(3000, () => { console.log(`Server Started at PORT 3000`);});\n\n```\n\n---\n## Middleware\n\n### asgardeoExpressAuth\n```TypeScript\nasgardeoAuth(\n  onSignIn: (res: express.Response, response: TokenResponse) => void,\n  onSignOut: (res: express.Response) => void,\n  onError: (res: express.Response, exception: AsgardeoAuthException) => void\n): any;\n```\n\n#### Arguments\n\n1. onSignIn: `(res: express.Response, response: TokenResponse) => void`\n\n   This method will be called when the user successfully signs in. \n\n   ##### Arguments\n   - res: `express.Response`\n   The res object represents the HTTP response that an Express app sends when it gets an HTTP request.\n\n   - response: `TokenResponse`\n   This object will have the token response from the `signIn` method. To know more about the [`TokenResponse`](#TokenResponse), refer to the [TokenResponse](#TokenResponse) section.\n\n2.  onSignOut: `(res: express.Response) => void`\n\n    This method will be called when the user signs out successfully. \n\n    ##### Arguments\n    - res: `express.Response`\n    The res object represents the HTTP response that an Express app sends when it gets an HTTP request.\n\n3. onError: `(res: express.Response, exception: AsgardeoAuthException) => void`\n\n    This method will be called if an error occurs.\n\n    ##### Arguments\n    - res: `express.Response`\n    The res object represents the HTTP response that an Express app sends when it gets an HTTP request.\n\n    - exception: `AsgardeoAuthException`\n    The exception object of the error occurred.\n\n#### Description\n\nThe SDK provides a client middleware called asgardeoAuth that provides you with the necessary methods to implement authentication. You can use this middleware to initiate the AsgardeoAuth for your application. By default, the SDK implements the `/login` and `/logout` routes so as soon as you use asgardeoAuth middleware, the /login and /logout routes will be available out of the box for the users to authenticate.\n\n_Note: The default `/login` and `/logout` route names can be customized.To learn more, refer to the [`ExpressClientConfig`](#ExpressClientConfig) section._\n\n#### Example Usage\n\n  ```TypeScript\n  app.use(\n    AsgardeoExpressClient.asgardeoExpressAuth(onSignIn, onSignOut, onError)\n  );\n   ```\n\n---\n\n### protectRoute\n```TypeScript\nprotectRoute(callback: UnauthenticatedCallback): (req: express.Request, res: express.Response, next: express.nextFunction);\n```\n#### Arguments\n\n1. callback: [`UnauthenticatedCallback`](#UnauthenticatedCallback)\n\n   This function handles the callback for the unauthenticated users. To know more about implementing the [`UnauthenticatedCallback`](#UnauthenticatedCallback) type, refer to the [UnauthenticatedCallback](#UnauthenticatedCallback) section.\n\n#### Description\n\nThis middleware function can be used to protect a route. When this function is passed down to a route, it will check if the session cookie exists on the request and if not it will call the callback function and if the cookie is there, the request will proceed as usual.\n\n#### Example Usage\n\n```TypeScript\nconst authCallback = (res, error) => {\n  res.redirect(`/?message=${ error }`);\n  return true;\n};\n\nconst isAuthenticated = protectRoute(authCallback);\n\napp.get(\"/protected\", isAuthenticated, (req, res) => {\n    res.status(200).send(\"Hello from Protected Route\");\n});\n```\n---\n\n## APIs\n\nThe SDK provides a singleton client class called `AsgardeoExpressClient` that provides you with the necessary methods to implement authentication. \nYou can instantiate the class and use `req.asgardeoAuth` inside a request to access this class in order to use the provided methods. \n\n### constructor\n\n```typescript\nAsgardeoExpressClient.getInstance(config: ExpressClientConfig, store?: Store);\n```\n#### Arguments\n\n1. config: [`ExpressClientConfig`](#ExpressClientConfig)\n\n   This contains the configuration information needed to implement authentication such as the client ID, server origin etc. Additional configuration information that is needed to configure the client, can be passed down from this object (Eg: A custom login path). To learn more about what attributes can be passed into this object, refer to the [`ExpressClientConfig`](#ExpressClientConfig) section.\n\n   #### Example\n\n   ```TypeScript\n   const config = {\n       clientID: \"<YOUR_CLIENT_ID>\",\n       clientSecret: \"<YOUR_CLIENT_SECRET>\",\n       baseUrl: \"<YOUR_BASE_URL>\",\n       appURL: \"http://localhost:3000\",\n       scope: [\"openid\", \"profile\"]\n   };\n   ```\n2. store: [`Store`](#Store) (optional)\n\n   This is the object of interface [`Store`](#Store) that is used by the SDK to store all the necessary data used ranging from the configuration data to the access token. By default, the SDK is packed with a built-in Memory Cache Store. If needed, you can implement the Store to create a class with your own implementation logic and pass an instance of the class as the second argument. This way, you will be able to get the data stored in your preferred place. To know more about implementing the [`Store`](#Store) interface, refer to the [Data Storage](#data-storage) section.\n\n#### Description\nThis returns an instance of the `AsgardeoExpressClient` class and if the class is not instantiated already, it will create a new instance and return it.\n\n#### Example Usage\n\n```TypeScript\napp.use(AsgardeoExpressClient.getInstance(config, store););\n```\n\n---\n\n### getIDToken\n\n```TypeScript\ngetIDToken(userId: string): Promise<string>\n```\n\n#### Returns\n\nidToken: `Promise<string>`\nA Promise that resolves with the ID Token.\n\n#### Description\n\nThis method returns the id token.\n\n#### Example\n\n```TypeScript\nconst idToken = await authClient.getIDToken(\"a2a2972c-51cd-5e9d-a9ae-058fae9f7927\");\n```\n\n---\n\n### getBasicUserInfo\n\n```TypeScript\ngetBasicUserInfo(userId: string): Promise<BasicUserInfo>\n```\n\n#### Arguments\n\n1. userId: `string` (optional)\n\n   If you want to use the SDK to manage multiple user sessions, you can pass a unique ID here to generate an authorization URL specific to that user. This can be useful when this SDK is used in backend applications.\n\n#### Returns\n\nbasicUserInfo: Promise<[BasicUserInfo](#BasicUserInfo)>\nAn object containing basic user information obtained from the id token.\n\n#### Description\n\nThis method returns the basic user information obtained from the payload. To learn more about what information is returned, checkout the DecodedIDTokenPayload model.\n\n#### Example\n\n```TypeScript\n// This should be within an async function.\nconst basicUserInfo = await authClient.getBasicUserInfo(\"a2a2972c-51cd-5e9d-a9ae-058fae9f7927\");\n```\n\n---\n\n### getOIDCServiceEndpoints\n\n```TypeScript\ngetOIDCServiceEndpoints(): Promise<OIDCEndpoints>\n```\n\n#### Returns\n\noidcEndpoints: Promise<[OIDCEndpoints](#OIDCEndpoints)>\nAn object containing the OIDC service endpoints returned by the `.well-known` endpoint.\n\n#### Description\n\nThis method returns the OIDC service endpoints obtained from the `.well-known` endpoint. To learn more about what endpoints are returned, checkout the OIDCEndpoints section.\n\n#### Example\n\n```TypeScript\n// This should be within an async function.\nconst oidcEndpoints = await authClient.getOIDCServiceEndpoints();\n```\n\n---\n\n### getDecodedIDToken\n\n```TypeScript\ngetDecodedIDToken(userId?: string): Promise<DecodedIDTokenPayload>\n```\n\n#### Arguments\n\n1. userId: `string` (optional)\n\n   If you want to use the SDK to manage multiple user sessions, you can pass a unique ID here to generate an authorization URL specific to that user. This can be useful when this SDK is used in backend applications.\n\n#### Returns\n\ndecodedIDTokenPayload: Promise<[DecodedIDTokenPayload](#DecodedIDTokenPayload)>\nThe decoded ID token payload.\n\n#### Description\n\nThis method decodes the payload of the id token and returns the decoded values.\n\n#### Example\n\n```TypeScript\n// This should be within an async function.\nconst decodedIDTokenPayload = await authClient.getDecodedIDToken(\"a2a2972c-51cd-5e9d-a9ae-058fae9f7927\");\n```\n\n---\n\n### getAccessToken\n\n```TypeScript\ngetAccessToken(userId?: string): Promise<string>\n```\n\n#### Arguments\n\n1. userId: `string` (optional)\n\n   If you want to use the SDK to manage multiple user sessions, you can pass a unique ID here to generate an authorization URL specific to that user. This can be useful when this SDK is used in backend applications.\n\n#### Returns\n\naccessToken: `Promise<string>` The access token.\n\n#### Description\n\nThis method returns the access token.\n\n#### Example\n\n```TypeScript\n// This should be within an async function.\nconst accessToken = await authClient.getAccessToken(\"a2a2972c-51cd-5e9d-a9ae-058fae9f7927\");\n```\n\n---\n\n### revokeAccessToken\n\n```TypeScript\nrevokeAccessToken(userId?: string): Promise<FetchResponse>\n```\n\n#### Arguments\n\n1. userId: `string` (optional)\n\n   If you want to use the SDK to manage multiple user sessions, you can pass a unique ID here to generate an authorization URL specific to that user. This can be useful when this SDK is used in backend applications.\n\n#### Returns\n\nA Promise that resolves with the response returned by the server.\n\n#### Description\n\nThis method clears the authentication data and sends a request to revoke the access token. You can use this method if you want to sign the user out of your application but not from the server.\n\n#### Example\n\n```TypeScript\n// This should be within an async function.\nconst revokeToken = await auth.revokeAccessToken(\"a2a2972c-51cd-5e9d-a9ae-058fae9f7927\");\n```\n\n---\n\n### requestCustomGrant\n\n```TypeScript\nrequestCustomGrant(config: CustomGrantConfig, userId?: string): Promise<TokenResponse | FetchResponse>\n```\n\n#### Arguments\n\n1. config: [CustomGrantConfig](#CustomGrantConfig)\n\n   The config object contains attributes that would be used to configure the custom grant request. To learn more about the different configurations available, checkout the CustomGrantConfig model.\n\n1. userId: `string` (optional)\n\n   If you want to use the SDK to manage multiple user sessions, you can pass a unique ID here to generate an authorization URL specific to that user. This can be useful when this SDK is used in backend applications.\n\n#### Returns\n\nA Promise that resolves with the token information or the response returned by the server depending on the configuration passed.\n\n#### Description\n\nThis method can be used to send custom-grant requests to Asgardeo.\n\n#### Example\n\n```TypeScript\nconst config = {\n    attachToken: false,\n    data: {\n        client_id: \"{{clientID}}\",\n        grant_type: \"account_switch\",\n        scope: \"{{scope}}\",\n        token: \"{{token}}\",\n    },\n    id: \"account-switch\",\n    returnResponse: true,\n    returnsSession: true,\n    signInRequired: true\n}\n\nauth.requestCustomGrant(config).then((response) => {\n    console.log(response);\n}).catch((error) => {\n    console.error(error);\n});\n```\n\n---\n\n### updateConfig\n\n```TypeScript\nupdateConfig(config: Partial<AuthClientConfig<T>>): Promise<void>\n```\n\n#### Arguments\n\n1. config: `AuthClientConfig<T>`\n\n   The config object containing the attributes that can be used to configure the SDK. To learn more about the available attributes, refer to the[ AuthClientConfig<T>](# AuthClientConfig<T>) model.\n\n#### Description\n\nThis method can be used to update the configurations passed into the constructor of the [AsgardeoAuthClient](#AsgardeoAuthClient). Please note that every attribute in the config object passed as the argument here is optional. Use this method if you want to update certain attributes after instantiating the class.\n\n#### Example\n\n```TypeScript\nconst pkce = auth.updateConfig({\n    signOutRedirectURL: \"http://localhost:3000/sign-out\"\n});\n```\n\n---\n\n### isSignOutSuccessful\n\n```TypeScript\nstatic isSignOutSuccessful(signOutRedirectURL: string): boolean\n```\n**This is a static method.**\n\n#### Arguments\n\n1. signOutRedirectURL: `string`\n\n   The URL to which the user is redirected to after signing out from the server.\n\n#### Returns\n\nisSignedOut: `boolean`\nA boolean value indicating if the user has been signed out or not.\n\n#### Description\n\nThis method returns if the user has been successfully signed out or not. When a user signs out from the server, the user is redirected to the URL specified by the [signOutRedirectURL](#signOutRedirectURL) in the config object passed into the constructor of the [AsgardeoAuthClient](#AsgardeoAuthClient). The server appends path parameters indicating if the sign-out is successful. This method reads the URL and returns if the sign-out is successful or not. So, make sure you pass as the argument the URL to which the user has been redirected to after signing out from the server.\n\n#### Example\n\n```TypeScript\nconst isSignedOut = auth.isSignOutSuccessful(<signout_redirect_url>);\n```\n\n---\n\n### didSignOutFail\n\n```TypeScript\nstatic didSignOutFail(signOutRedirectURL: string): boolean\n```\n**This is a static method.**\n\n#### Arguments\n\n1. signOutRedirectURL: `string`\n\n   The URL to which the user is redirected to after signing out from the server.\n\n#### Returns\n\ndidSignOutFail: `boolean`\nA boolean value indicating if sign-out failed or not.\n\n#### Description\n\nThis method returns if sign-out failed or not. When a user signs out from the server, the user is redirected to the URL specified by the [signOutRedirectURL](#signOutRedirectURL) in the config object passed into the constructor of the [AsgardeoAuthClient](#AsgardeoAuthClient). The server appends path parameters indicating if the sign-out is successful. This method reads the URL and returns if the sign-out failed or not. So, make sure you pass as the argument the URL to which the user has been redirected to after signing out from the server.\n\n#### Example\n\n```TypeScript\nconst isSignedOutFailed = auth.isSignOutSuccessful(<signout_redirect_url>);\n```\n\n\n\n---\n\n## Data Storage\n\nSince the SDK was developed with the view of being able to support various storage approaches, the SDK allows developers to use their preferred mode of storage. To that end, the SDK allows you to pass a store object when using the `asgardeoAuth` middleware. This store object contains methods that can be used to store, retrieve and delete data. The SDK provides a Store interface that you can implement to create your own Store class. You can refer to the [`Store`](#store) section to learn mire about the `Store` interface.\n\nThere are three methods that are to be implemented by the developer. They are\n\n1. `setData`\n2. `getData`\n3. `removeData`\n\nThe `setData` method is used to store data. The `getData` method is used to retrieve data. The `removeData` method is used to delete data. The SDK converts the data to be stored into a JSON string internally and then calls the `setData` method to store the data. The data is represented as a key-value pairs in the SDK. The SDK uses four keys internally, and you can learn about them by referring to the [Data Layer](#data-layer) section. So, every JSON stringified data value is supposed to be stored against the passed key in the data store. A sample implementation of the `Store` class using the browser session storage is given here.\n\n```TypeScript\nclass NodeStore implements Store {\n    public setData(key: string, value: string): void {\n        sessionStorage.setItem(key, value);\n    }\n\n    public getData(key: string): string {\n        return sessionStorage.getItem(key);\n    }\n\n    public removeData(key: string): void {\n        sessionStorage.removeItem(key);\n    }\n}\n```\n\n---\n\n## Models\n\n### ExpressClientConfig\n\nThis model has the following attributes.\n| Attribute                    | Required/Optional | Type            | Default Value                                               | Description                                                                                   |\n| ---------------------------- | ----------------- | --------------- | ----------------------------------------------------------- | --------------------------------------------------------------------------------------------- |\n| `appURL`                    | Required*         | `string`        | \"\"                                                          | The base URL of the application. eg: `https//localhost:3000`                                  |\n| `clientID`                   | Required*         | `string`        | \"\"                                                          | The client ID of the OIDC application hosted in the Asgardeo.                                 |\n| `baseUrl`               | Required*         | `string`        | \"\"                                                          | The origin of the Identity Provider. eg: `https://api.asgardeo.io/t/<org_name>`               |\n| `clientHost`                 | Optional          | `string`        | The origin of the client app obtained using `window.origin` | The hostname of the client app. eg: `https://localhost:3000`                                  |\n| `clientSecret`               | Optional          | `string`        | \"\"                                                          | The client secret of the OIDC application                                                     |\n| `enablePKCE`                 | Optional          | `boolean`       | `true`                                                      | Specifies if a PKCE should be sent with the request for the authorization code.               |\n| `prompt`                     | Optional          | `string`        | \"\"                                                          | Specifies the prompt type of an OIDC request                                                  |\n| `responseMode`               | Optional          | `ResponseMode`  | `\"query\"`                                                   | Specifies the response mode. The value can either be `query` or `form_post`                   |\n| `scope`                      | Optional          | `string[]`      | `[\"openid\"]`                                                | Specifies the requested scopes.                                                               |\n| `endpoints`                  | Optional          | `OIDCEndpoints` | [OIDC Endpoints Default Values](#oidc-endpoints)            | The OIDC endpoint URLs. The SDK will try to obtain the endpoint URLS                          | using the `.well-known` endpoint. If this fails, the SDK will use these endpoint URLs. If this attribute is not set, then the default endpoint URLs will be | used. However, if the `overrideWellEndpointConfig` is set to `true`, then this will override the endpoints obtained from the `.well-known` endpoint. |\n| `overrideWellEndpointConfig` | Optional          | `boolean`       | `false`                                                     | If this option is set to `true`, then the `endpoints` object will override endpoints obtained | from the `.well-known` endpoint. If this is set to `false`, then this will be used as a fallback if the request to the `.well-known` endpoint fails.        |\n| `wellKnownEndpoint`          | Optional          | `string`        | `\"/oauth2/token/.well-known/openid-configuration\"`          | The URL of the `.well-known` endpoint.                                                        |\n| `validateIDToken`            | Optional          | `boolean`       | `true`                                                      | Allows you to enable/disable JWT ID token validation after obtaining the ID token.            |\n| `clockTolerance`             | Optional          | `number`        | `60`                                                        | Allows you to configure the leeway when validating the id_token.                              |\n| `sendCookiesInRequests`      | Optional          | `boolean`       | `true`                                                      | Specifies if cookies should be sent in the requests.                                          |\n| `cookieConfig`               | Optional          | `cookieConfig`  | [cookieConfig Default Values](cookieConfig)                 | Specifies the `maxAge`, `httpOnly` and `sameSite` values for the cookie configuration.        |\n| `loginPath`                  | Optional          | `string`        | `/login`                                                    | Specifies the default login path.                                                             |\n| `logoutPath`                 | Optional          | `string`        | `/logout`                                                   | Specifies the default logout path.                                                            |\n| `globalAuth`                 | Optional          | `boolean`       | `false`                                                     | Specifies if all the routes should be protected or not.                                       |\n\n**Important:**\nWhen specifying a custom login and logout path using `loginPath` and `logoutPath` attributes, make sure you add these URLs in the `Authorized redirect URLs` section in the Asgardeo Console. Also make sure you add the `baseURL` in the `Allowed origins`section as well.\n\n---\n\n### Store\n\n| Method       | Required/Optional | Arguments                      | Returns         | Description                                                                                                                                                                     |\n|--------------|-------------------|--------------------------------|-----------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|\n| `setData`    | Required          | key: `string`, value: `string` | `Promise<void>` | This method saves the passed value to the store. The data to be saved is JSON stringified so will be passed by the SDK as a string.                                             |\n| `getData`    | Required          | key: `string`\\                 | `string`        | This method retrieves the data from the store and returns a Promise that resolves with it. Since the SDK stores the data as a JSON string, the returned value will be a string. |\n| `removeData` | Required          | key: `string`                  | `Promise<void>` | Removes the data with the specified key from the store.                                                                                                                         |\n\n---\n\n### cookieConfig\n\n| Method     | Required/Optional | Type      | Default Value | Description                                                                                            |\n|------------|-------------------|-----------|---------------|--------------------------------------------------------------------------------------------------------|\n| `maxAge`   | Optional          | `number`  | 90000         | The maximum age of the cookie.                                                                         |\n| `httpOnly` | Optional          | `boolean` | `true`        | Setting this true will make sure that the cookie inaccessible to the JavaScript `Document.cooki`e API. |\n| `sameSite` | Optional          | `string` | `lax`        | Specifies the value for sameSite (Lax / Strict / None) attribute.                               |\n| `secure` | Optional          | `boolean` | `false`        | Specifies whether the cookie is secure or not. This will be needed to set to true when `sameSite` attribute is set to `None`.                               |\n\n---\n### TokenResponse\n\n| Method         | Type     | Description                 |\n|----------------|----------|-----------------------------|\n| `accessToken`  | `string` | The access token.           |\n| `idToken`      | `string` | The id token.               |\n| `expiresIn`    | `string` | The expiry time in seconds. |\n| `scope`        | `string` | The scope of the token.     |\n| `refreshToken` | `string` | The refresh token.          |\n| `tokenType`    | `string` | The token type.             |\n| `session`      | `string` | The session ID.             |\n\n\n\n---\n\n### UnauthenticatedCallback\n\n```TypeScript\n(res: express.Response, error: string) => boolean;\n```\n\n#### Description\n\nThis method is used to handle the callback from a protected route. You may use this function to get the request object and the error message to redirect the user to the desired error page or to redirect to the login page and authenticate the user.\n\n\n#### Example\n\n```TypeScript\nconst authCallback = (res, error) => {\n  res.redirect(`/?message=${ error }`);\n  return true;\n};\n```\n\n\n## Develop\n\n### Prerequisites\n\n- `Node.js` (version 10 or above).\n- `npm` package manager.\n\n### Installing Dependencies\n\nThe repository is a mono repository. The SDK repository is found in the [lib](https://github.com/asgardeo/asgardeo-express-sdk/tree/master/lib) directory. You can install the dependencies by running the following command at the root.\n\n```\nnpm run build\n```\n---\n## Contribute\n\nPlease read [Contributing to the Code Base](http://wso2.github.io/) for details on our code of conduct, and the process for submitting pull requests to us.\n\n### Reporting issues\n\nWe encourage you to report issues, improvements, and feature requests creating [Github Issues](https://github.com/asgardeo/asgardeo-auth-js-sdk/issues).\n\nImportant: And please be advised that security issues must be reported to security@wso2com, not as GitHub issues, in order to reach the proper audience. We strongly advise following the WSO2 Security Vulnerability Reporting Guidelines when reporting the security issues.\n\n---\n\n## License\n\nThis project is licensed under the Apache License 2.0. See the [LICENSE](LICENSE) file for details.\n","readmeFilename":"README.md"}