{"_id":"@authok/express-openid-connect","_rev":"1-33200346034b7cccebc09ab101c65e94","name":"@authok/express-openid-connect","dist-tags":{"latest":"2.5.2"},"versions":{"2.5.2":{"name":"@authok/express-openid-connect","version":"2.5.2","description":"Express middleware to protect web applications using OpenID Connect.","homepage":"https://github.com/authok/express-openid-connect","license":"MIT","author":{"name":"Authok","email":"support@authok.com"},"main":"index.js","scripts":{"lint":"eslint .","start:example":"node ./examples/run_example.js","test":"mocha --max-http-header-size=16384","test:ci":"nyc --reporter=lcov npm test","docs":"typedoc --options typedoc.js index.d.ts","test:end-to-end":"mocha end-to-end"},"mocha":{"exit":true,"file":"./test/setup.js","timeout":10000},"dependencies":{"base64url":"^3.0.1","cb":"^0.1.0","clone":"^2.1.2","cookie":"^0.4.1","debug":"^4.3.2","futoin-hkdf":"^1.4.2","http-errors":"^1.8.0","joi":"^17.4.2","jose":"^2.0.5","on-headers":"^1.0.2","openid-client":"^4.9.1","p-memoize":"^4.0.2","url-join":"^4.0.1"},"devDependencies":{"@types/express":"^4.17.6","chai":"^4.2.0","chai-as-promised":"^7.1.1","connect-redis":"^5.1.0","dotenv":"^8.2.0","eslint":"^5.16.0","express":"^4.17.1","express-oauth2-bearer":"^0.4.0","husky":"^4.2.5","lodash":"^4.17.15","memorystore":"^1.6.4","mocha":"^7.2.0","nock":"^11.9.1","nyc":"^15.1.0","oidc-provider":"^6.27.0","prettier":"^2.0.5","pretty-quick":"^2.0.1","puppeteer":"^5.5.0","redis-mock":"^0.56.3","request":"^2.88.2","request-promise-native":"^1.0.8","sinon":"^7.5.0","typedoc":"^0.17.8","typescript":"^3.9.6"},"peerDependencies":{"express":">= 4.17.0"},"engines":{"node":"^10.19.0 || >=12.0.0 < 13 || >=13.7.0 < 14 || >= 14.2.0"},"husky":{"hooks":{"pre-commit":"pretty-quick --staged"}},"types":"./index.d.ts","gitHead":"746101f9f4e86c489172283e7e13c845bc7ea244","_id":"@authok/express-openid-connect@2.5.2","_nodeVersion":"16.13.1","_npmVersion":"8.1.2","dist":{"integrity":"sha512-aT5MNc8H8sPgfZy0Jr6+I7kW3x89diPG3UR1ZsvIsFx+8JVuTW3Gw+37zFXxjhdQE8dCdV7rafk1cxhIAWmkqg==","shasum":"237aa40e7b4d04283f1057899abfe6bbc46828e8","tarball":"https://registry.npmjs.org/@authok/express-openid-connect/-/express-openid-connect-2.5.2.tgz","fileCount":19,"unpackedSize":81746,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh5TPPCRA9TVsSAnZWagAAfqAQAJE3oGxak2y30tLquCMK\nnIkT6w0enkLfvfbupjcbYc9xHFlHNl5CdbsM/KrNBEaJfaEVbJdXlb2B96+r\n6P4KtTVoG5BGDRtIKce416t6Jz1ECUvWyCuyKTBhIgI1sdDS3oN1aENRsze6\n/bBjiU0d2r7P+jqmOeCilZUeTV84VGuQiEv1BmcCpLzUigIFYlkZF8XqGkWi\nAx6HWbmqTqc7lK6VsbHHPI9jvDvS8J9QEkSWZXP3KjwRGV9okg0iOrr57W0u\n+MQfK+KCULBkyjScXQ1Tv6eUjTR+B3ij4YlEIt+hsTNBE9vqJ7llgNkxRQ65\nlG52VLTWLsZK9y170XPkS4HbnIksUVCVKoq1EXKtc0guY/GPG15UzSvID/TG\nN0XezHlmoMjeIUa/nhcU4lsa/F2UbTk2SQMDMjAq5b/pk/Kd3wSSviZc5QDD\nlDHJS+BPL6KqBz/OYZlJ4brWeLnmVJr1a6rmZRGqCbCVt0/y6cTRgHqQ/RYh\nKNwsaW/17bhVGiJeO+LRvK059WNNNd2ZNualesNkXFhs6t3gii7A8Z8cZuS3\ndY26WFldzUX21NB2KSLOyUHBcR2JARc4IeATPSZNfNzi8LwRh6K19V0DDmkI\ngBTOZgBZo56jY8qrrQJlKp3tez9yBLp55APAwDln/3BwztRPS92xVAL8uP1u\nrmel\r\n=nP7v\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCdZwdIRJwwX2L6IcERTGGUrECw43eoItmMlgO2e2YSwAIhAImESlMvxdqk2G8u142p992ZYJOyIvu50rtzlUWCX5Gk"}]},"_npmUser":{"name":"newtalentxp","email":"newtalentxp@126.com"},"directories":{},"maintainers":[{"name":"newtalentxp","email":"newtalentxp@126.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/express-openid-connect_2.5.2_1642410959169_0.09310681709334534"},"_hasShrinkwrap":false}},"time":{"created":"2022-01-17T09:15:59.117Z","2.5.2":"2022-01-17T09:15:59.312Z","modified":"2022-04-04T16:32:07.479Z"},"maintainers":[{"name":"newtalentxp","email":"newtalentxp@126.com"}],"description":"Express middleware to protect web applications using OpenID Connect.","homepage":"https://github.com/authok/express-openid-connect","author":{"name":"Authok","email":"support@authok.com"},"license":"MIT","readme":"# Express OpenID Connect\n\nExpress JS middleware implementing sign on for Express web apps using OpenID Connect.\n\n[![CircleCI](https://img.shields.io/circleci/build/github/authok/express-openid-connect/master?style=flat-square)](https://circleci.com/gh/authok/express-openid-connect/tree/master)\n[![codecov](https://img.shields.io/codecov/c/github/authok/express-openid-connect?style=flat-square)](https://codecov.io/gh/authok/express-openid-connect)\n[![NPM version](https://img.shields.io/npm/v/express-openid-connect.svg?style=flat-square)](https://npmjs.org/package/express-openid-connect)\n[![FOSSA Status](https://app.fossa.com/api/projects/git%2Bgithub.com%2Fauthok%2Fexpress-openid-connect.svg?type=shield)](https://app.fossa.com/projects/git%2Bgithub.com%2Fauthok%2Fexpress-openid-connect?ref=badge_shield)\n\n## Table of Contents\n\n- [Documentation](#documentation)\n- [Install](#install)\n- [Getting Started](#getting-started)\n- [Architecture](./ARCHITECTURE.md)\n- [Contributing](#contributing)\n- [Troubleshooting](./TROUBLESHOOTING.md)\n- [FAQs](./FAQ.md)\n- [Support + Feedback](#support--feedback)\n- [Vulnerability Reporting](#vulnerability-reporting)\n- [What is Authok](#what-is-authok)\n- [License](#license)\n\n## Documentation\n\n- Our [Express Quickstart](https://authok.com/docs/quickstart/webapp/express) is the quickest way to get up and running from scratch.\n- Use the [Examples for common configurations](https://github.com/authok/express-openid-connect/blob/master/EXAMPLES.md) for use cases beyond the basics.\n- The [API documentation](https://authok.github.io/express-openid-connect) details all configuration options, methods, and data that this library provides.\n- You can [run the sample application](https://github.com/authok-samples/authok-express-webapp-sample/tree/master) to see how this SDK functions without writing your own integration.\n\n## Install\n\nNode.js version **>=12.0.0** is recommended, but **^10.19.0** lts/dubnium is also supported.\n\n```bash\nnpm install express-openid-connect\n```\n\n## Getting Started\n\nFollow our [Secure Local Development guide](https://authok.com/docs/libraries/secure-local-development) to ensure that applications using this library are running over secure channels (HTTPS URLs). Applications using this library without HTTPS may experience \"invalid state\" errors.\n\nThe library needs [issuerBaseURL](https://authok.github.io/express-openid-connect/interfaces/configparams.html#issuerbaseurl), [baseURL](https://authok.github.io/express-openid-connect/interfaces/configparams.html#baseurl), [clientID](https://authok.github.io/express-openid-connect/interfaces/configparams.html#clientid) and [secret](https://authok.github.io/express-openid-connect/interfaces/configparams.html#secret) to request and accept authentication. These can be configured with environmental variables:\n\n```text\nISSUER_BASE_URL=https://YOUR_DOMAIN\nCLIENT_ID=YOUR_CLIENT_ID\nBASE_URL=https://YOUR_APPLICATION_ROOT_URL\nSECRET=LONG_RANDOM_VALUE\n```\n\n... or in the library initialization:\n\n```js\n// index.js\n\nconst { auth } = require('express-openid-connect');\napp.use(\n  auth({\n    issuerBaseURL: 'https://YOUR_DOMAIN',\n    baseURL: 'https://YOUR_APPLICATION_ROOT_URL',\n    clientID: 'YOUR_CLIENT_ID',\n    secret: 'LONG_RANDOM_STRING',\n    idpLogout: true,\n  })\n);\n```\n\nWith this basic configuration, your application will require authentication for all routes and store the user identity in an encrypted and signed cookie.\n\nSee the [examples](EXAMPLES.md) for route-specific authentication, custom application session handling, requesting and using access tokens for external APIs, and more.\n\nSee the [API documentation](https://authok.github.io/express-openid-connect) for [additional configuration possibilities](https://authok.github.io/express-openid-connect/interfaces/configparams.html) and [provided methods](https://authok.github.io/express-openid-connect/globals.html#attemptsilentlogin).\n\n## A note on error handling\n\nErrors raised by this library are handled by the [default Express error handler](https://expressjs.com/en/guide/error-handling.html#the-default-error-handler) which, in the interests of security, does not include the stack trace or error message in the production environment. If you write your own error handler, you should not render the error message without using a templating engine that will properly escape it first.\n\nTo write your own error handler, see the Express documentation on writing [Custom error handlers](https://expressjs.com/en/guide/error-handling.html#writing-error-handlers). \n\n## Contributing\n\nWe appreciate feedback and contribution to this repo! Before you get started, please see the following:\n\n- [Authok's general contribution guidelines](https://github.com/authok/.github/blob/master/CONTRIBUTING.md)\n- [Authok's code of conduct guidelines](https://github.com/authok/open-source-template/blob/master/CODE-OF-CONDUCT.md)\n\nContributions can be made to this library through PRs to fix issues, improve documentation or add features. Please fork this repo, create a well-named branch, and submit a PR with a complete template filled out.\n\nCode changes in PRs should be accompanied by tests covering the changed or added functionality. Tests can be run for this library with:\n\n```bash\nnpm install\nnpm test\n```\n\nWhen you're ready to push your changes, please run the lint command first:\n\n```bash\nnpm run lint\n```\n\n## Support + Feedback\n\nPlease use the [Issues queue](https://github.com/authok/express-openid-connect/issues) in this repo for questions and feedback.\n\n## Vulnerability Reporting\n\nPlease do not report security vulnerabilities on the public GitHub issue tracker. The [Responsible Disclosure Program](https://authok.com/whitehat) details the procedure for disclosing security issues.\n\n## What is Authok?\n\nAuthok helps you to easily:\n\n- implement authentication with multiple identity providers, including social (e.g., Google, Facebook, Microsoft, LinkedIn, GitHub, Twitter, etc), or enterprise (e.g., Windows Azure AD, Google Apps, Active Directory, ADFS, SAML, etc.)\n- log in users with username/password databases, passwordless, or multi-factor authentication\n- link multiple user accounts together\n- generate signed JSON Web Tokens to authorize your API calls and flow the user identity securely\n- access demographics and analytics detailing how, when, and where users are logging in\n- enrich user profiles from other data sources using customizable JavaScript rules\n\n[Why Authok?](https://authok.com/why-authok)\n\n## License\n\nThis project is licensed under the MIT license. See the [LICENSE](LICENSE) file for more info.\n\n[![FOSSA Status](https://app.fossa.com/api/projects/git%2Bgithub.com%2Fauthok%2Fexpress-openid-connect.svg?type=large)](https://app.fossa.com/projects/git%2Bgithub.com%2Fauthok%2Fexpress-openid-connect?ref=badge_large)\n","readmeFilename":"README.md"}