{"_id":"@benjamin_26/vehicle-auth-system","name":"@benjamin_26/vehicle-auth-system","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@benjamin_26/vehicle-auth-system","version":"1.0.0","description":"JWT-based Multi-Factor Authentication system for vehicle e-commerce platforms. Implements OWASP A07:2025 and NIST SP 800-63-4 standards with JWT refresh token rotation, Email OTP, TOTP, RBAC, rate limiting and audit logging.","main":"index.js","keywords":["jwt","mfa","authentication","totp","otp","vehicle","ecommerce","kenya","security","owasp","restful","express","bcrypt","speakeasy","rate-limiting","audit-log","rbac"],"author":{"name":"Benjamin Otieno Njoga","email":"njogabenjamin69@gmail.com"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/codeNjoga/vehicle-marketplace-auth.git"},"homepage":"https://github.com/codeNjoga/vehicle-marketplace-auth#readme","bugs":{"url":"https://github.com/codeNjoga/vehicle-marketplace-auth/issues"},"engines":{"node":">=18.0.0"},"dependencies":{"bcryptjs":"^2.4.3","jsonwebtoken":"^9.0.0","speakeasy":"^2.0.0","qrcode":"^1.5.0","express-rate-limit":"^7.0.0","resend":"^3.0.0","cookie-parser":"^1.4.6"},"peerDependencies":{"express":"^4.18.0","pg":"^8.0.0"},"gitHead":"2c9ff8429b39890178daba8e1ddc87bee7cc35c5","_id":"@benjamin_26/vehicle-auth-system@1.0.0","_nodeVersion":"25.4.0","_npmVersion":"11.7.0","dist":{"integrity":"sha512-NDtlNa9fZLVIIWaRsaHhNQMD7KiiyDi/ZQvQX2jv7ahDHIHcnqvdwf4ObcifXhBhF7Le11LSnPp8NdZqKZkQUQ==","shasum":"d54a0dd4670ae0e53d66e75868e10c6891b592aa","tarball":"https://registry.npmjs.org/@benjamin_26/vehicle-auth-system/-/vehicle-auth-system-1.0.0.tgz","fileCount":16,"unpackedSize":88693,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHMnE1mOUi4YiMvQDDyH/OTCceHTGj5MURHxUsWKPMuHAiEAq0X+RbSRn7WqDcX2oH/j37gCkMLHnsdowPN09H0dR2k="}]},"_npmUser":{"name":"benjamin_26","email":"njogabenjamin69@gmail.com"},"directories":{},"maintainers":[{"name":"benjamin_26","email":"njogabenjamin69@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vehicle-auth-system_1.0.0_1779044948266_0.3913272801784806"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-17T19:09:08.206Z","1.0.0":"2026-05-17T19:09:08.471Z","modified":"2026-05-17T19:09:08.756Z"},"maintainers":[{"name":"benjamin_26","email":"njogabenjamin69@gmail.com"}],"description":"JWT-based Multi-Factor Authentication system for vehicle e-commerce platforms. Implements OWASP A07:2025 and NIST SP 800-63-4 standards with JWT refresh token rotation, Email OTP, TOTP, RBAC, rate limiting and audit logging.","homepage":"https://github.com/codeNjoga/vehicle-marketplace-auth#readme","keywords":["jwt","mfa","authentication","totp","otp","vehicle","ecommerce","kenya","security","owasp","restful","express","bcrypt","speakeasy","rate-limiting","audit-log","rbac"],"repository":{"type":"git","url":"git+https://github.com/codeNjoga/vehicle-marketplace-auth.git"},"author":{"name":"Benjamin Otieno Njoga","email":"njogabenjamin69@gmail.com"},"bugs":{"url":"https://github.com/codeNjoga/vehicle-marketplace-auth/issues"},"license":"MIT","readme":"# @njoga/vehicle-auth-system\n\nA complete JWT-based Multi-Factor Authentication system for vehicle e-commerce platforms built with RESTful architecture.\n\nImplements **OWASP A07:2025** and **NIST SP 800-63-4** authentication standards.\n\n## Features\n\n- JWT authentication with refresh token rotation\n- Email OTP multi-factor authentication\n- TOTP (Google Authenticator) MFA — RFC 6238\n- Role-Based Access Control (Buyer, Seller, Admin)\n- Rate limiting and brute force protection\n- bcrypt password hashing (cost factor 12)\n- Immutable audit trail logging\n- Stateless RESTful API architecture\n\n## Demonstrated Through\n\nAutoKenya — a vehicle marketplace platform  \nLive: https://vehicle-marketplace-auth.vercel.app  \nAPI: https://vehicle-marketplace-auth-production.up.railway.app\n\n## Installation\n\n```bash\nnpm install @njoga/vehicle-auth-system\n```\n\n## Quick Start\n\n```javascript\nconst express = require('express');\nconst { \n  authRoutes, \n  mfaRoutes, \n  protect, \n  requireRole \n} = require('@njoga/vehicle-auth-system');\n\nconst app = express();\napp.use(express.json());\n\n// Mount auth routes\napp.use('/api/auth', authRoutes);\napp.use('/api/mfa', mfaRoutes);\n\n// Protect your routes\napp.get('/dashboard', protect, yourController);\napp.post('/listings', protect, requireRole('seller'), createListing);\napp.get('/admin', protect, requireRole('admin'), adminController);\n```\n\n## Environment Variables\n\n```env\nJWT_SECRET=your_jwt_secret\nJWT_REFRESH_SECRET=your_refresh_secret\nRESEND_API_KEY=your_resend_key\nEMAIL_FROM=auth@yourplatform.com\nTOTP_ISSUER=YourPlatformName\nDATABASE_URL=your_postgresql_url\n```\n\n## API Endpoints\n\n```text\nPOST /api/auth/register        Register new user\nPOST /api/auth/login           Login with email + password\nPOST /api/auth/logout          Logout and revoke token\nPOST /api/auth/refresh-token   Rotate refresh token\nPOST /api/auth/forgot-password Request password reset\nPOST /api/auth/reset-password  Reset password with token\n\nPOST /api/mfa/send-otp         Send email OTP\nPOST /api/mfa/verify-otp       Verify email OTP\nPOST /api/mfa/setup-totp       Generate TOTP QR code\nPOST /api/mfa/verify-totp-setup Confirm TOTP setup\nPOST /api/mfa/verify-totp-login Verify TOTP at login\nPOST /api/mfa/disable-totp     Disable TOTP\n```\n\n## Middleware\n\n```text\nprotect                    Requires valid JWT (401 if missing)\nrequireRole('admin')       Requires role (403 if wrong role)\nrateLimiter                5 attempts per 15 min per IP\n```\n\n## Security Standards\n\n- OWASP A07:2025 — Identification and Authentication Failures\n- NIST SP 800-63-4 — Digital Identity Guidelines\n- RFC 6238 — TOTP standard\n- RFC 7519 — JWT standard\n\n## Research\n\nThis package was developed as part of a BSc IT research project at Jomo Kenyatta University of Agriculture and Technology (JKUAT), Kenya.\n\nResearch Title: Implementation of a JWT-Based Multi-Factor Authentication System for Vehicle E-Commerce Platform Using RESTful Architecture\n\nAuthor: Benjamin Otieno Njoga (SCT221-0402/2022)\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-50262fecd32f8dfe757f2ec63c6bf273"}