{"_id":"@becklyn/deployment-protection","_rev":"10-0128d4cb21d622e23f9c2631e226ba98","name":"@becklyn/deployment-protection","dist-tags":{"latest":"0.4.4"},"versions":{"0.0.1":{"name":"@becklyn/deployment-protection","version":"0.0.1","license":"MIT","_id":"@becklyn/deployment-protection@0.0.1","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"ec77dfe2fd94aac937d4f46e647402252246c260","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.0.1.tgz","fileCount":81,"integrity":"sha512-rzB0fVYaoiFxZxLaAygtVajdbN8c0+gQfCgeslUuUeJLPd8xYLNjFQ3i1cL3PtByxlUn9X/2erqpzFJrrvkuvA==","signatures":[{"sig":"MEUCIGcQuys4WS7IbYvnMcs80LGJtNDE+8FVs5bQ8xYg5N3FAiEA3ClEHe0oZsA+lrL6+N6joli/IYDQc7Xoa3B/h/dZd4o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108967},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./package.json":"./package.json"},"gitHead":"0a0d628fd055cc0b5eaa2be8402df016d8655c96","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json}\"","test":"vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json","prepublishOnly":"npm run lint && npm run test && npm run build"},"_npmUser":{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.19.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.8.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.1","vitest":"^4.1.11","typescript":"^5.9.3","@types/node":"^26.2.0","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.0.1_1787128128864_0.5334636723309525","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@becklyn/deployment-protection","version":"0.1.0","license":"MIT","_id":"@becklyn/deployment-protection@0.1.0","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"977d58830e0a3032c2fa00b75c54878a6b822df4","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.1.0.tgz","fileCount":81,"integrity":"sha512-f5zLnH0ikUf0Kkv4MtG4YUvJo3snizy/Iy7O6lGR4AfdLLBJw6MjWAljQH9YI1KRaMayYhC8IB4Y15Hw0IYeuQ==","signatures":[{"sig":"MEUCIFoPPxOsNQ1cOMJcWAuk8NvajYXKz5KVAvxjR2DsQ86VAiEAyq3bLK6u06O21aC6p9PYtc5dDYaRqQ+Fn2B5VNCOqmo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@becklyn%2fdeployment-protection@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":111887},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./package.json":"./package.json"},"gitHead":"969a5816356cee9ca3d398eb2b2d855c330cf2d2","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json}\"","test":"vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json","prepublishOnly":"npm run lint && npm run test && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1f1ee962-eb48-444d-938a-cb28c071f84b"}},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.17.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.0","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^25.9.5","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.1.0_1787146580583_0.9926128355368076","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@becklyn/deployment-protection","version":"0.2.0","license":"MIT","_id":"@becklyn/deployment-protection@0.2.0","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"f10718357da71177701536a3e865de8fcfd3dde4","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.2.0.tgz","fileCount":81,"integrity":"sha512-O+u+yUBOvDJv3QTLgkF45WDUt0z59d7r87ibYtzrhMabiGBX3tc4AiE8C+oSXmxcYB6mvJxIAsMOOyStCJ0tvg==","signatures":[{"sig":"MEYCIQD7BnMzJUGbIYa1O8mctIm6njJJ1vG3pZheK0O/iCWHFwIhALVMAyUHB8Kcq9pX7GFXYcokvpAOXIszkZVJK9OSpDhy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@becklyn%2fdeployment-protection@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":112046},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./package.json":"./package.json"},"gitHead":"5d8fae3bc0564895862f920da286b913f3c2bc5f","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json}\"","test":"vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json","prepublishOnly":"npm run lint && npm run test && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1f1ee962-eb48-444d-938a-cb28c071f84b"}},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.17.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.0","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^25.9.5","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.2.0_1787148682760_0.400675227229939","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@becklyn/deployment-protection","version":"0.3.0","license":"MIT","_id":"@becklyn/deployment-protection@0.3.0","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"33892823b05839325af2243709a303f09d713d84","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.3.0.tgz","fileCount":93,"integrity":"sha512-cIRRuZMWicfCpqPYr58hQhw25nxvEqz8w4yDLV/qJWBbOzTaaTG/t30L/IEcpImupx5PwvcNbMGTilyRICzlzA==","signatures":[{"sig":"MEYCIQCVT4IZSi7dEo/Jvfy1Hy+M4CuanCF4/QRL4AUke1mquAIhAJwqlmvYwNMwqi32/wQaB4Pt/obr6oBkbNs11PiMRrPT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@becklyn%2fdeployment-protection@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":160937},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./package.json":"./package.json"},"gitHead":"a63b14cd57e18c6075f8101c41253b26e5873537","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json}\"","test":"vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json","prepublishOnly":"npm run lint && npm run test && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1f1ee962-eb48-444d-938a-cb28c071f84b"}},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.17.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.0","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^25.9.5","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.3.0_1787152525556_0.4046507929697263","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@becklyn/deployment-protection","version":"0.4.0","license":"MIT","_id":"@becklyn/deployment-protection@0.4.0","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"e2faaab2a32531999571f0f334f8b1c6aa908bda","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.4.0.tgz","fileCount":105,"integrity":"sha512-crCsZsW+PCV+3K+bipOQIT4ygMQ5hIZzjwgItRR+vamFvnWq31qfztqURlRm8c9E9qtKRaC9QT2/3Ra8SWYOlw==","signatures":[{"sig":"MEUCIESnXjaA+/ydX1uP+OQpZLIkqOPELZE4yveZPZAT4wwdAiEAghQVxCQMeWFo70P4Fab10Y+/BJNst5g1Zk9AAHrQ9jo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@becklyn%2fdeployment-protection@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":173437},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./edge":{"types":"./dist/cjs/edge.d.ts","import":"./dist/es/edge.js","default":"./dist/cjs/edge.js","require":"./dist/cjs/edge.js"},"./storybook":{"types":"./dist/cjs/storybook.d.ts","import":"./dist/es/storybook.js","default":"./dist/cjs/storybook.js","require":"./dist/cjs/storybook.js"},"./package.json":"./package.json"},"gitHead":"388739015ab04c0ff363bef42bb459011d0ed071","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json}\"","test":"vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json","prepublishOnly":"npm run lint && npm run test && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1f1ee962-eb48-444d-938a-cb28c071f84b"}},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.17.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js and Storybook deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.0","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^25.9.5","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.4.0_1787155210695_0.29730753708699464","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@becklyn/deployment-protection","version":"0.4.1","license":"MIT","_id":"@becklyn/deployment-protection@0.4.1","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"e55dd19c9074d70e29e80d5b87ddcce1f94b0697","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.4.1.tgz","fileCount":108,"integrity":"sha512-QD0Vhd33sthDdbS6/gAvVmvybJECei1AIG0UEz515nUNXrldF06q2TOIo08O836MEEcLQlcTS6Kd/x/Z3Oexag==","signatures":[{"sig":"MEUCIAGTWTOgFSrJ6Q+lNrOVaPhaNDmkBbV5SHXCL0f8AIe5AiEA2JxBz3JmR1RmXpE+VGuVfdt1Wujo+vJK9sOzDgiT//c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@becklyn%2fdeployment-protection@0.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":235724},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./edge":{"types":"./dist/cjs/edge.d.ts","import":"./dist/edge.mjs","worker":"./dist/edge.mjs","browser":"./dist/edge.mjs","default":"./dist/edge.mjs","require":"./dist/cjs/edge.js","edge-light":"./dist/edge.mjs"},"./storybook":{"types":"./dist/cjs/storybook.d.ts","import":"./dist/storybook.mjs","worker":"./dist/storybook.mjs","browser":"./dist/storybook.mjs","default":"./dist/storybook.mjs","require":"./dist/cjs/storybook.js","edge-light":"./dist/storybook.mjs"},"./package.json":"./package.json"},"gitHead":"8bf4a073f69002487462d7218de0b47fbaf1cf44","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json,mjs}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json,mjs}\"","test":"npm run build && vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json && node ./scripts/build-edge-bundles.mjs","prepublishOnly":"npm run lint && npm run test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1f1ee962-eb48-444d-938a-cb28c071f84b"}},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.17.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js and Storybook deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.0","vitest":"^3.2.4","esbuild":"^0.25.12","typescript":"^5.9.3","@types/node":"^25.9.5","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.4.1_1787311173645_0.993848262259657","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"@becklyn/deployment-protection","version":"0.4.2","license":"MIT","_id":"@becklyn/deployment-protection@0.4.2","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"7955f55258f43d539e8d59a72f52e8707d7b696e","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.4.2.tgz","fileCount":108,"integrity":"sha512-k5xzFT/IwM7GTIXUthvgfVK5Ia0lVLbBSNscv4tPt7urI3TvnRFQa2D7GWRSLQBkF/Qrpuqzz7bUUZZn/iFmAw==","signatures":[{"sig":"MEUCIEOsGFu/ke9Y2U4YhGUYQYsDoWuUpYMpH6juEmGBIQIHAiEA6U6wxiGG1kR/ZGsj/b5lkD6FM24a6VBRM6EvkgSWl98=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@becklyn%2fdeployment-protection@0.4.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":241912},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./edge":{"types":"./dist/cjs/edge.d.ts","import":"./dist/edge.mjs","worker":"./dist/edge.mjs","browser":"./dist/edge.mjs","default":"./dist/edge.mjs","require":"./dist/cjs/edge.js","edge-light":"./dist/edge.mjs"},"./storybook":{"types":"./dist/cjs/storybook.d.ts","import":"./dist/storybook.mjs","worker":"./dist/storybook.mjs","browser":"./dist/storybook.mjs","default":"./dist/storybook.mjs","require":"./dist/cjs/storybook.js","edge-light":"./dist/storybook.mjs"},"./package.json":"./package.json"},"gitHead":"e73543ac218a9fdcf6bd59679a794a912763b8bc","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json,mjs}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json,mjs}\"","test":"vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json && node ./scripts/build-edge-bundles.mjs","prepublishOnly":"npm run lint && npm run build && npm run test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1f1ee962-eb48-444d-938a-cb28c071f84b"}},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.17.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js and Storybook deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.0","vitest":"^3.2.4","esbuild":"^0.25.12","typescript":"^5.9.3","@types/node":"^25.9.5","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.4.2_1787641041309_0.3218058587663508","host":"s3://npm-registry-packages-npm-production"}},"0.4.3":{"name":"@becklyn/deployment-protection","version":"0.4.3","license":"MIT","_id":"@becklyn/deployment-protection@0.4.3","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"9266cf21ab100303fa87d2c104fabddb39f73c76","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.4.3.tgz","fileCount":108,"integrity":"sha512-jpnGP12sk2zAD0cJWFk3vHsZiPhOW8ZRXA+Qn4ngP8F226WNsdHPPbkQtG2e/UX+izjkfLANif96VOEMDXOT/Q==","signatures":[{"sig":"MEUCIQC8Tx7jnNUtpZhKtoypampkZK8P+Y3qzkv5WZkXcwJzbwIgPAgVyBcqKTcY/m1lEQ7y3jvaAqDfZNCd8DaxkCnxNSo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@becklyn%2fdeployment-protection@0.4.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":243418},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./edge":{"types":"./dist/cjs/edge.d.ts","import":"./dist/edge.mjs","worker":"./dist/edge.mjs","browser":"./dist/edge.mjs","default":"./dist/edge.mjs","require":"./dist/cjs/edge.js","edge-light":"./dist/edge.mjs"},"./storybook":{"types":"./dist/cjs/storybook.d.ts","import":"./dist/storybook.mjs","worker":"./dist/storybook.mjs","browser":"./dist/storybook.mjs","default":"./dist/storybook.mjs","require":"./dist/cjs/storybook.js","edge-light":"./dist/storybook.mjs"},"./package.json":"./package.json"},"gitHead":"8a0e71f6356f4d66c63424810a5394e500200141","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json,mjs}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json,mjs}\"","test":"vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json && node ./scripts/build-edge-bundles.mjs","prepublishOnly":"npm run lint && npm run build && npm run test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1f1ee962-eb48-444d-938a-cb28c071f84b"}},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.17.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js and Storybook deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.0","vitest":"^3.2.4","esbuild":"^0.25.12","typescript":"^5.9.3","@types/node":"^25.9.5","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.4.3_1787643164945_0.7289649657278825","host":"s3://npm-registry-packages-npm-production"}},"0.4.4":{"name":"@becklyn/deployment-protection","version":"0.4.4","license":"MIT","_id":"@becklyn/deployment-protection@0.4.4","maintainers":[{"name":"jesko-plitt","email":"jesko.plitt@unic.com"},{"name":"msvujnovic-becklyn","email":"mv@becklyn.com"},{"name":"hautzi","email":"ch@becklyn.com"},{"name":"dsmoosh-becklyn","email":"david.smusz@unic.com"},{"name":"msc-at-becklyn","email":"msc@becklyn.com"},{"name":"mangoischke","email":"mg@becklyn.com"},{"name":"jj_becklyn","email":"jj@becklyn.com"},{"name":"svenja-haas","email":"svenja.haas@unic.com"},{"name":"d4lister","email":"Jakob.Haag@gmx.de"}],"homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"dist":{"shasum":"398b1b1f758e54b5fee6c5b31409c50b479a61b4","tarball":"https://registry.npmjs.org/@becklyn/deployment-protection/-/deployment-protection-0.4.4.tgz","fileCount":108,"integrity":"sha512-2xYeswGA+uCm+rI1hMJS7AhXL9kZIDx/uCYyzVT0G6tPo+L/zk83dAc1kklCC9QI9uppDlxJToQ4ohd2Hfspmw==","signatures":[{"sig":"MEQCICXkRoyCHxQFraRrYtpQ6G+h1orBCVG2s5Yf8QfRPyXQAiBkR4qfltbfTJ2q8pMhH8IHFDpZvjHgAGM8iyvrfT9R1Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@becklyn%2fdeployment-protection@0.4.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":243417},"main":"dist/cjs/index.js","types":"dist/cjs/index.d.ts","module":"dist/es/index.js","exports":{".":{"types":"./dist/cjs/index.d.ts","import":"./dist/es/index.js","default":"./dist/cjs/index.js","require":"./dist/cjs/index.js"},"./edge":{"types":"./dist/cjs/edge.d.ts","import":"./dist/edge.mjs","worker":"./dist/edge.mjs","browser":"./dist/edge.mjs","default":"./dist/edge.mjs","require":"./dist/cjs/edge.js","edge-light":"./dist/edge.mjs"},"./storybook":{"types":"./dist/cjs/storybook.d.ts","import":"./dist/storybook.mjs","worker":"./dist/storybook.mjs","browser":"./dist/storybook.mjs","default":"./dist/storybook.mjs","require":"./dist/cjs/storybook.js","edge-light":"./dist/storybook.mjs"},"./package.json":"./package.json"},"gitHead":"5a9de71aee84c249811203d61467144b4c2ee0c3","scripts":{"fix":"eslint . --fix && prettier --write \"./**/*.{ts,tsx,md,json,mjs}\"","lint":"eslint . --max-warnings 0 && prettier --check \"./**/*.{ts,tsx,md,json,mjs}\"","test":"vitest run","build":"rm -rf dist && tsc -p tsconfig-es.json && tsc -p tsconfig-cjs.json && node ./scripts/build-edge-bundles.mjs","prepublishOnly":"npm run lint && npm run build && npm run test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1f1ee962-eb48-444d-938a-cb28c071f84b"}},"prettier":"@becklyn/prettier","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"_npmVersion":"11.19.0","description":"Simple shared username/password + Sign in with Vercel gate for Next.js and Storybook deployments","directories":{},"sideEffects":false,"_nodeVersion":"24.20.0","_hasShrinkwrap":false,"devDependencies":{"next":"^16.3.5","vitest":"^3.2.7","esbuild":"^0.28.2","typescript":"^5.9.3","@types/node":"^25.9.6","@becklyn/eslint":"*","@becklyn/tsconfig":"*"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/deployment-protection_0.4.4_1789368749673_0.9096047873790272","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-08-19T08:28:48.701Z","modified":"2026-09-15T07:07:23.196Z","0.0.1":"2026-08-19T08:28:49.003Z","0.1.0":"2026-08-19T13:36:20.728Z","0.2.0":"2026-08-19T14:11:22.914Z","0.3.0":"2026-08-19T15:15:25.721Z","0.4.0":"2026-08-19T16:00:10.855Z","0.4.1":"2026-08-21T11:19:33.828Z","0.4.2":"2026-08-25T06:57:21.434Z","0.4.3":"2026-08-25T07:32:45.086Z","0.4.4":"2026-09-14T06:52:29.797Z"},"bugs":{"url":"https://github.com/Becklyn-Studios/ts-libs/issues"},"license":"MIT","homepage":"https://github.com/Becklyn-Studios/ts-libs/tree/main/packages/deployment-protection","repository":{"url":"git+https://github.com/Becklyn-Studios/ts-libs.git","type":"git"},"description":"Simple shared username/password + Sign in with Vercel gate for Next.js and Storybook deployments","maintainers":[{"email":"jesko.plitt@unic.com","name":"jesko-plitt"},{"email":"mv@becklyn.com","name":"msvujnovic-becklyn"},{"email":"ch@becklyn.com","name":"hautzi"},{"email":"david.smusz@unic.com","name":"dsmoosh-becklyn"},{"email":"msc@becklyn.com","name":"msc-at-becklyn"},{"email":"mg@becklyn.com","name":"mangoischke"},{"email":"jj@becklyn.com","name":"jj_becklyn"},{"email":"svenja.haas@unic.com","name":"svenja-haas"},{"email":"Jakob.Haag@gmx.de","name":"d4lister"},{"email":"info@glassp.dev","name":"glassp"}],"readme":"# `@becklyn/deployment-protection`\n\nSimple, shared deployment gate for Next.js apps and static Storybook deploys on Vercel.\n\nUse this instead of (or after disabling) Vercel platform Deployment Protection when you need:\n\n- a **shared username/password** from env vars\n- optional **Sign in with Vercel** for team members\n- always-on **automation bypass** via `x-vercel-protection-bypass` / `VERCEL_AUTOMATION_BYPASS_SECRET`\n- a kill switch (`DEPLOYMENT_PROTECTION_ENABLED`, on by default)\n\nProtection runs in:\n\n- Next.js **middleware** (Next ≤15) or **proxy** (Next 16+)\n- **Vercel Edge Middleware** for static Storybook (`@becklyn/deployment-protection/storybook`)\n\n> **Note:** Vercel Connect is unrelated (third-party API tokens). Platform Vercel Authentication cookies are not visible to your app once platform protection is off — team members use the **Sign in with Vercel** button instead.\n\n## Install\n\n```bash\nnpm i @becklyn/deployment-protection\n```\n\n## Quick setup\n\n### Storybook (static on Vercel)\n\nBuilt Storybook is static (`storybook-static`), so protection is **Vercel Routing Middleware** — not a Storybook addon.\n\n1. Install the package in the project that deploys Storybook (published build, or workspace package after `npm run build`).\n2. Add `middleware.ts` at the **Vercel project root** (same level Vercel uses for `vercel.json` / output):\n\n```ts\nimport { withStorybookDeploymentProtection } from \"@becklyn/deployment-protection/storybook\";\n\nexport default withStorybookDeploymentProtection();\n\nexport const config = {\n    matcher: [\"/((?!.*\\\\.(?:svg|png|jpg|jpeg|gif|webp|ico|css|js|map|txt|xml|woff2?|mjs)$).*)\"],\n};\n```\n\n3. Set the same environment variables as for Next.js (below).\n4. `vercel.json` for a Storybook-only project — **`framework` must be `null`** (Other). Do **not** use the Vercel “Storybook” framework preset; it sets `disableRootMiddleware` and skips middleware entirely:\n\n```json\n{\n    \"buildCommand\": \"npm run build-storybook\",\n    \"outputDirectory\": \"storybook-static\",\n    \"framework\": null\n}\n```\n\n`withStorybookDeploymentProtection` does **not** require the `next` package. The matcher must stay a **string literal** in `middleware.ts` (same static-analysis rule as Next.js).\n\nPrefer the default **edge** runtime. `runtime: \"nodejs\"` is supported as well — both resolve to a self-contained ESM bundle (`dist/storybook.mjs` / `dist/edge.mjs`) so Vercel does not need to trace the multi-file tsc graph.\n\nFramework-agnostic alias (same implementation):\n\n```ts\nimport { withEdgeDeploymentProtection } from \"@becklyn/deployment-protection/edge\";\n\nexport default withEdgeDeploymentProtection();\n```\n\n### 1. Next.js middleware / proxy\n\nNext.js requires `config.matcher` to be a **string literal in the local middleware/proxy file**.\nIt cannot be imported from a package (Next analyzes the matcher statically at build time).\n\n**Next.js 16+ (`proxy.ts`):**\n\n```ts\nimport { withDeploymentProtection } from \"@becklyn/deployment-protection\";\n\nexport const proxy = withDeploymentProtection();\n\nexport const config = {\n    matcher: [\n        \"/((?!_next/static|_next/image|favicon.ico|.*\\\\.(?:svg|png|jpg|jpeg|gif|webp|ico|css|js|map|txt|xml|woff2?)$).*)\",\n    ],\n};\n```\n\n**Next.js ≤15 (`middleware.ts`):**\n\n```ts\nimport { withDeploymentProtection } from \"@becklyn/deployment-protection\";\n\nexport default withDeploymentProtection();\n\nexport const config = {\n    matcher: [\n        \"/((?!_next/static|_next/image|favicon.ico|.*\\\\.(?:svg|png|jpg|jpeg|gif|webp|ico|css|js|map|txt|xml|woff2?)$).*)\",\n    ],\n};\n```\n\nCompose with existing middleware:\n\n```ts\nexport default withDeploymentProtection(async request => {\n    // your logic…\n    return NextResponse.next();\n});\n```\n\n### 2. Environment variables\n\n| Variable                                     | Required          | Default                   | Description                                            |\n| -------------------------------------------- | ----------------- | ------------------------- | ------------------------------------------------------ |\n| `DEPLOYMENT_PROTECTION_ENABLED`              | no                | `true`                    | Set `false` / `0` / `off` to disable                   |\n| `DEPLOYMENT_PROTECTION_USERNAME`             | for password auth | —                         | Shared username                                        |\n| `DEPLOYMENT_PROTECTION_PASSWORD`             | for password auth | —                         | Shared password                                        |\n| `DEPLOYMENT_PROTECTION_SECRET`               | recommended       | derived from user+pass    | HMAC secret for session cookies (+ handoff fallback)   |\n| `DEPLOYMENT_PROTECTION_AUTH_PROXY_URL`       | for proxy SSO     | —                         | Base URL of the central auth-proxy app                 |\n| `DEPLOYMENT_PROTECTION_HANDOFF_SECRET`       | no                | same as `…_SECRET`        | Shared secret between apps and the auth-proxy          |\n| `VERCEL_AUTOMATION_BYPASS_SECRET`            | no                | —                         | Same secret as Vercel Protection Bypass for Automation |\n| `DEPLOYMENT_PROTECTION_VERCEL_CLIENT_ID`     | direct Vercel SSO | —                         | Or `NEXT_PUBLIC_VERCEL_APP_CLIENT_ID` (legacy)         |\n| `DEPLOYMENT_PROTECTION_VERCEL_CLIENT_SECRET` | direct Vercel SSO | —                         | Or `VERCEL_APP_CLIENT_SECRET` (legacy)                 |\n| `DEPLOYMENT_PROTECTION_FORM_TITLE`           | no                | `Authentication required` | Login heading                                          |\n| `DEPLOYMENT_PROTECTION_FORM_DESCRIPTION`     | no                | …                         | Login description                                      |\n\nAt least one of password auth, Vercel OAuth (proxy or direct), or a bypass secret must be configured while enabled. If nothing is configured, the gate stays inactive (fail-open) so local dev is not bricked.\n\n### 3. Sign in with Vercel via auth-proxy (recommended)\n\nRegister **one** OAuth callback URL on a shared [Sign in with Vercel](https://vercel.com/docs/sign-in-with-vercel) app:\n\n```text\nhttps://<auth-proxy-host>/callback\n```\n\nDeploy the `deployment-protection-auth-proxy` app from this monorepo (or any tiny Next app that wires the handlers below) and set:\n\n**On the auth-proxy**\n\n| Variable                                             | Description                            |\n| ---------------------------------------------------- | -------------------------------------- |\n| `DEPLOYMENT_PROTECTION_VERCEL_CLIENT_ID`             | Vercel OAuth client id                 |\n| `DEPLOYMENT_PROTECTION_VERCEL_CLIENT_SECRET`         | Vercel OAuth client secret             |\n| `DEPLOYMENT_PROTECTION_SECRET` or `…_HANDOFF_SECRET` | Shared HMAC secret with protected apps |\n| `DEPLOYMENT_PROTECTION_ALLOWED_ORIGINS`              | Optional allowlist (see below)         |\n\n**On every protected app**\n\n| Variable                               | Description                            |\n| -------------------------------------- | -------------------------------------- |\n| `DEPLOYMENT_PROTECTION_AUTH_PROXY_URL` | e.g. `https://dp-auth.example.com`     |\n| `DEPLOYMENT_PROTECTION_SECRET`         | Session cookie secret                  |\n| `DEPLOYMENT_PROTECTION_HANDOFF_SECRET` | Same as proxy (defaults to `…_SECRET`) |\n\nNo per-project / per-preview callback URLs.\n\n#### Flow\n\n1. App redirects to `{AUTH_PROXY_URL}/start` with a **signed** `return_origin` + `return_path`.\n2. Proxy runs Vercel OAuth against its fixed `/callback`.\n3. Proxy redirects to  \n   `{return_origin}/_becklyn/deployment-protection/vercel/callback?handoff=…&return_to=…`\n4. App verifies the short-lived handoff token (`aud` must match its origin), sets `__becklyn_dp_session`, continues.\n\n#### Allowlist (proxy)\n\n`DEPLOYMENT_PROTECTION_ALLOWED_ORIGINS` is a comma-separated list:\n\n- full origins: `https://app.example.com`\n- host suffixes: `.vercel.app`, `example.com`\n- `localhost` (http(s) localhost / 127.0.0.1)\n\nEmpty allowlist → any origin that passes https (or local http) validation. Prefer an allowlist in production.\n\n#### Minimal proxy route handlers\n\n```ts\n// app/start/route.ts\nimport { handleAuthProxyStart } from \"@becklyn/deployment-protection\";\n\nexport const GET = (request: Request) => handleAuthProxyStart(request);\n\n// app/callback/route.ts\nimport { handleAuthProxyCallback } from \"@becklyn/deployment-protection\";\n\nexport const GET = (request: Request) => handleAuthProxyCallback(request);\n```\n\n### 4. Sign in with Vercel (legacy direct mode)\n\nStill supported when `DEPLOYMENT_PROTECTION_AUTH_PROXY_URL` is unset:\n\n1. Create a Sign in with Vercel app.\n2. Add authorization callback URLs for **each** project host:\n\n    ```text\n    https://<your-host>/_becklyn/deployment-protection/vercel/callback\n    http://localhost:3000/_becklyn/deployment-protection/vercel/callback\n    ```\n\n3. Set client id/secret on the project(s).\n\nWhen both proxy URL and direct client credentials are set, **proxy mode wins** for the authorize step.\n\nScopes used: `openid email profile`.\n\n### 5. Automation bypass\n\nMatches Vercel’s Protection Bypass for Automation:\n\n```http\nGET /api/health\nx-vercel-protection-bypass: <VERCEL_AUTOMATION_BYPASS_SECRET>\n```\n\nOr query:\n\n```text\nhttps://app.example/?x-vercel-protection-bypass=<secret>\n```\n\nA valid bypass query param redirects to the same path without the secret and sets the signed `__becklyn_dp_session` cookie, so later requests stay authenticated. You do not need `x-vercel-set-bypass-cookie` for that.\n\nOptional Vercel-compatible helper — also persist the raw bypass secret as `__becklyn_dp_bypass`:\n\n```text\nhttps://app.example/?x-vercel-protection-bypass=<secret>&x-vercel-set-bypass-cookie=true\n```\n\nThe header form stays one-shot (no cookies) so CI/Playwright can send it on each request.\n\nWhen platform Deployment Protection is disabled, **this package** enforces the bypass secret so CI/Playwright keep working the same way.\n\n## Behaviour\n\n1. Disabled / misconfigured → pass through\n2. Internal Vercel OAuth routes → handled by the package (proxy start or direct OAuth / handoff)\n3. Login form `POST` → validate username/password, set signed HttpOnly session cookie\n4. Valid bypass header → allow this request\n5. Valid bypass query param → set `__becklyn_dp_session`, redirect to the cleaned URL\n6. Valid session or bypass cookie → allow\n7. Else → HTML login page (password and/or Sign in with Vercel)\n\nSession cookie: `__becklyn_dp_session` (HMAC-SHA256, 14 days by default). On HTTPS it is `HttpOnly; Secure; SameSite=None` so a logged-in session is sent when the preview is embedded in a third-party iframe (e.g. Contentful live preview). On HTTP (localhost) it stays `SameSite=Lax` because browsers reject `SameSite=None` without `Secure`.\n\n## Disable without code changes\n\n```bash\nDEPLOYMENT_PROTECTION_ENABLED=false\n```\n\nRedeploy. Middleware stays installed but is a no-op.\n\n## API\n\n```ts\nimport {\n    handleAuthProxyCallback,\n    handleAuthProxyStart,\n    handleDeploymentProtection,\n    resolveConfig,\n    withDeploymentProtection,\n    withEdgeDeploymentProtection,\n} from \"@becklyn/deployment-protection\";\nimport { withStorybookDeploymentProtection } from \"@becklyn/deployment-protection/storybook\";\n```\n\n- `withDeploymentProtection(options?)` / `withDeploymentProtection(next, options?)` — Next.js middleware/proxy factory\n- `withStorybookDeploymentProtection(options?)` / `withEdgeDeploymentProtection(options?)` — Vercel Edge Middleware for Storybook / static deploys (no Next.js)\n- `handleDeploymentProtection(request, options?)` — framework-agnostic core (`null` = continue)\n- `handleAuthProxyStart` / `handleAuthProxyCallback` — central auth-proxy routes\n\nRecommended matcher (must be pasted as a string literal in your middleware/proxy file — see above):\n\n```ts\n\"/((?!_next/static|_next/image|favicon.ico|.*\\\\.(?:svg|png|jpg|jpeg|gif|webp|ico|css|js|map|txt|xml|woff2?)$).*)\";\n```\n\n## Security notes\n\n- This is a **shared-secret gate**, not per-user product auth.\n- Prefer a dedicated `DEPLOYMENT_PROTECTION_SECRET` in production.\n- Auth-proxy start requests are HMAC-signed; handoff tokens are short-lived and audience-bound.\n- Do not put the raw handoff secret in query strings — only signatures/tokens.\n- Turn off paid Vercel Password Protection / seat-heavy sharing once this is live; keep `VERCEL_AUTOMATION_BYPASS_SECRET` configured for tooling.\n- Middleware is a convenience edge check — do not treat it as the only control for highly sensitive data.\n- `__becklyn_dp_session` is `SameSite=None` on HTTPS so third-party iframes can send it. That cookie only decides whether the preview may load; apps must still CSRF-protect their own state-changing endpoints. OAuth state/PKCE cookies stay `SameSite=Lax`.\n- Safari (and some Chrome third-party-cookie settings) may still block unpartitioned third-party cookies even with `SameSite=None`.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}