{"_id":"@ash0080/hasura-oauth-service","_rev":"1-1d79ac5c0ab33cb4219deb415a14e0fb","name":"@ash0080/hasura-oauth-service","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@ash0080/hasura-oauth-service","version":"1.0.0","description":"This is a full-featured OAuth proxy service, It works with hasura to provide users with login, logout and authentication features","repository":{"type":"git","url":"git+https://github.com/ash0080/hasura-oauth-service.git"},"main":"src/index.js","scripts":{"test":"tap -j1 -R=specy -o report.tap --no-cov --comments test/controllers/metadata.js","start":"nodemon src/index.js","debug":"node --inspect src/index.js"},"keywords":[],"author":{"name":"ash0080"},"license":"MIT","dependencies":{"@ash0080/fastify-hasura":"link:../fastify-hasura","@ash0080/one-char-hash":"^1.0.4","@mgcrea/fastify-request-logger":"^0.5.2","@mgcrea/pino-pretty-compact":"^0.5.0","delay":"^5.0.0","dotenv":"^10.0.0","fastify":"^3.25.3","fastify-autoload":"^3.10.0","fastify-cron":"^1.2.0","fastify-jwt":"^4.1.3","fastify-oauth2":"^4.4.1","fastify-plugin":"^3.0.0","fastify-rate-limit":"^5.7.0","fastify-redis":"^4.3.3","fastify-secure-session":"^3.0.0","fastify-sensible":"^3.1.2","get-jwks":"^5.0.0","grant":"^5.4.19","gravatar":"^1.8.2","ioredis":"^4.28.3","lodash":"^4.17.21","ms":"^2.1.3","nanoid":"^3.2.0","phin":"^3.6.1","plur":"^4.0.0","ratelimiter":"^3.4.1","simple-get":"^4.0.0"},"devDependencies":{"tap":"^15.1.6"},"gitHead":"c4902dbde1ceec592d1d6dfe6c2acc4a6933ab10","bugs":{"url":"https://github.com/ash0080/hasura-oauth-service/issues"},"homepage":"https://github.com/ash0080/hasura-oauth-service#readme","_id":"@ash0080/hasura-oauth-service@1.0.0","_nodeVersion":"14.18.2","_npmVersion":"8.3.0","dist":{"integrity":"sha512-xqA0ZSMqrX02/0lW+eM4TGvRPWl6nuamh7wsKaFF3l1Nz5GvRf7Q/CPv9Q41V5sNdXXcVGqXGw7p8JWiKgVChQ==","shasum":"302ee74259959c28127b3996ad3b38bd360be36f","tarball":"https://registry.npmjs.org/@ash0080/hasura-oauth-service/-/hasura-oauth-service-1.0.0.tgz","fileCount":38,"unpackedSize":236333,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh6DRZCRA9TVsSAnZWagAAtzAQAIrkeCuSQROZ/LRFHtfU\n/pTHJsI9hwsVnE34tMxu0iYz75Y0jTy5sWKig/vyO03Nhe3MmyotmhDdiz7R\nQym/pClhDv4K7kYOmTZEdfW6n1RIKPF1JBVOVCsAqyDMajPefkb+04h/d3zQ\ncA+m6d6z9wjuhxBuIqEUOKKSMxLEIaWxjwyOmPR9BKXThyjKPVpWzs3wzQoE\nKHwMi3LBe9nYd9SiiA+YGXTOFJi1zYLQzSv/L38Oi4aICePNVMiLYiQNDwZ3\nhqZRHg+RF/zPOpMVnDnEMfxT6cbQ4rzWxdpi7uxA3XHx1wG6HL9xXHlVdzSP\ngeJU8//6YR+qh//+TzciOVOnPFubL8rodrQHTaeMWjfUg3l4+zHdfOwB3uXE\n2/QIN3lHGfj6165Q/v/NvolCt8oMkWprQEbJpmnQd3lw0GKSYcMmjelosgsp\naxWENPkjAVL/3osSCNijvJKLUGfkurIEf/c/Ct8vmTb3pbI360iY+WHROGkn\nyXOFC7OjciHfxersk5hZCM8ojPMisED0eIIpMadyA3QC/dykUm6Pl1UCUFVM\nVblJU68daOgEfIPunTUmVcR8QExj/eSFcWD3FKGVvJVfbfY9IzsPso5d0vqX\nPPpwiJUhD0WWrpaf4xw7WF6yuvBN1FJsnWu87fI9/LPBptIkQNYG4tzTRMTY\ndm/U\r\n=7wJ3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCJ+5Q5L31mt+SrEcVxDq7ZUot32KPcb51Q7d1DUtzLdgIhANM7VAXf1bLrGT+xIHfbBkvpErsBEpR0FlHmsNvrcImo"}]},"_npmUser":{"name":"ash0080","email":"ash0080@gmail.com"},"directories":{},"maintainers":[{"name":"ash0080","email":"ash0080@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/hasura-oauth-service_1.0.0_1642607705045_0.6459124611546632"},"_hasShrinkwrap":false}},"time":{"created":"2022-01-19T15:55:04.979Z","1.0.0":"2022-01-19T15:55:05.196Z","modified":"2022-04-04T15:45:15.381Z"},"maintainers":[{"name":"ash0080","email":"ash0080@gmail.com"}],"description":"This is a full-featured OAuth proxy service, It works with hasura to provide users with login, logout and authentication features","homepage":"https://github.com/ash0080/hasura-oauth-service#readme","keywords":[],"repository":{"type":"git","url":"git+https://github.com/ash0080/hasura-oauth-service.git"},"author":{"name":"ash0080"},"bugs":{"url":"https://github.com/ash0080/hasura-oauth-service/issues"},"license":"MIT","readme":"# @ash0080/hasura-oauth-service\n\nThis is a full-featured OAuth proxy service, It works with hasura to provide users with login, logout and authentication features.\n\nFor now, it's OAuth proxy only, does not provide local registration, the biggest reason is that I do not need it, in addition to the \nimplementation of registration also involves email/SMS verification, etc., which will make the size and complexity of the project greatly increased, however, this does not mean that you do not own the user data, the service still provides the basic user data, including, id, email, bio, avatar_url, etc., and the user can update these data through hasura.\n\n## Changelog\n1.0.0 - A full-featured oauth service used to extend [HASURA]()\n\n## Architecture\n![](image/architecture.png)\n\n## Features\n\n`OAuth:` Based on [grant](https://www.npmjs.com/package/grant), so it is easy to add 200+ OAuth Providers through a single configuration\nfile. without adding any new dependencies.\n\n`Automatic Setup:` Based on my [@ash0080/fastify-hasura](https://www.npmjs.com/package/@ash0080/fastify-hasura) When the service starts and\nconnects to hasura, it automatically sets up the database and metadata. Hands free.\n\n`Roles:` public, user, subscriber\n\n`Redis Cache:` The actual use is [keyDB](https://keydb.dev) (an enhanced version of redis), which includes out-of-the-box data persistence\nand some other features. It is used to cache basic user data and tokens. Reduce the time of token exchanging and the pressure on the\ndatabase from frequent exchanges.\n\n`Finger Print:` A simple back-end user fingerprint verification based on\nmy [@ash0080/one-char-hash](https://www.npmjs.com/package/@ash0080/one-char-hash)\n\n`Rate Limiting:` Based on [fastify-rate-limiter](https://www.npmjs.com/package/fastify-rate-limiter).\n\n`Multi-device login:` Supports multiple device login for the same account, and the local Redis database keeps track of the user's tokens;\n\n`Protected Hooks:` A built-in hooks endpoint validation.\n\n`Internal Event Triggers:` Out of the box, you don't have to worry much about it, for synchronizing basic user data and roles, still for a\nfaster token exchange mechanism.\n\n`Remote Cron Jobs:` Currently there are two,\n\n* Auto-downgrade expired subscribers\n* Auto-clean processed events and events logs. These take up a lot of space in hasura, and I saw someone say that he has 1.8G events_logs in\n  the database.\n\n`Unified endpoints:` Unified OAuth callback endpoint at `/token` and unified event webhook endpoint at `/events`, In fact, I actually don't\nreally like mixing Graphql and REST, so I want to expose as few endpoints as possible if I have to use them, This also has the advantage\nthat when you need to extend this project, you only need to extend these few endpoints, and the code is clearer and easier to understand.\n\n| Features     | Highlights                                            |\n|--------------|:------------------------------------------------------|\n| OAuth        | Based on grant, Easy to expand to 200+ providers;     |\n| Auto         | Auto set up, Hands free;                              |\n| Cache        | keyDB for jwt and basic user profile caching;         |\n| Rate-Limit   | Rate limiting;                                        |\n| Multi-Device | Supports multiple device login;                       |\n| Security     | Fingerprint & Protected Hooks;                        |\n| Cron         | Roles cleaning and logs cleaning;                     |\n| Unified      | Few exposed endpoints, easier to maintain and extend; |\n\n## Prepare\n\nStep 1: rename .example.env as .env and configure it with your data;\n\nStep 2: run src/config/key/jwtRS256.sh to generate keys, 1 pair for jwt, the other for session;\n\nStep 3: copy .jwt.example.json as .env to HASURA's path, fill it with the public_key you generated in step 2;\n\nStep 4: config and restart your hasura with this new HASURA_GRAPHQL_JWT_SECRET environment variable;\n\n## Run Service\n\nStep 5: ```yarn i```\n\nStep 6: ```yarn start```\n\nStep 7: This service will config your hasura and database automatically, if no exception is thrown, The service will be started and exposed\nat 0.0.0.0:${port} DONE!\n\n## Routers\n\n/- healthz check return 'ok'::string\n\n/$ROUTE_PREFIX/:provider_name - the entry point user start login (eg: /oauth/github)\n\n/$ROUTE_PREFIX/:provider_name/callback - the oauth callback url  (eg: /oauth/github/callback)\n\n/token - the final redirect url after oauth callback, you GET {access_token, refresh_token}::json\n\n/refresh - refresh token, you POST {refresh_token}, GET {access_token, refresh_token?}::json\n\n/revoke - revoke token, you POST {refresh_token}, GET {success}::json\n\n/events - the hasura events webhook endpoint\n\n## Q&A\n\n1. Why REST but not Remote Schema?  \n   The oauth process is a series of redirects but nothing; All necessary basic user data is redis cached, there is no need to forward it\n   through hasura;\n\n\n2. Can I use Redis replace keyDB?  \n   For now, Yes, you can. But in the future I may add some features unique to keydb, which may only be available in the Redis enterprise version\n\n## Todo\n\n1. Rewrite with typescript;\n2. Add a function to limit the number of devices for multi-device login;\n3. More Tests;\n\n## Thanks\nThanks all people who helped develop this project, especially,\n\n@simov - Author of [Grant](https://github.com/simov/grant)\n\n@Johan Eliasson - Author of [nhost/hasura-auth](https://github.com/nhost/hasura-auth) \n\n## Contributing\n\nEveryone is welcome to contribute. Please take a moment to review the [contributing guidelines](Contributing.md).\n\n## Authors and license\n\n[ash0080](Eldarion) and [contributors](/graphs/contributors).\n\nMIT License, see the included [License.md](License.md) file.\n","readmeFilename":"Readme.md"}