{"_id":"@biowiki/auth-sdk","name":"@biowiki/auth-sdk","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@biowiki/auth-sdk","version":"0.1.0","description":"Browser OAuth 2.0 Authorization Code + PKCE client for BioWiki applications.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsup","typecheck":"tsc --noEmit","prepack":"npm run typecheck && npm run build","prepublishOnly":"npm run typecheck && npm run build"},"publishConfig":{"access":"restricted"},"engines":{"node":">=24 <25"},"devDependencies":{"tsup":"^8.5.1","typescript":"^5.7.3"},"gitHead":"b22d018e917d73d2a92d2ca254a1703891672cf9","_id":"@biowiki/auth-sdk@0.1.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-Miw7LcoPCG3cUW3KFbET9o2efFGP1eh8f6zU9NiVUYnVfqMWGacx8c61uKE5DdbCg7PmqQso0eHtoEXfQ9nZ7g==","shasum":"89a13c8994d37da135d12edbc854790341285ee1","tarball":"https://registry.npmjs.org/@biowiki/auth-sdk/-/auth-sdk-0.1.0.tgz","fileCount":6,"unpackedSize":33634,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCnSMmBjx1Hhq/UowHi5SA3KgtMCk3Y+MUmS3YUN6e9jwIgJ6pBxnIMxGwPatT3Hw9EsCS2kPVcHQIlr/XRuThYxbs="}]},"_npmUser":{"name":"liuzcbiowiki","email":"liuzc@biowiki.com.hk"},"directories":{},"maintainers":[{"name":"liuzcbiowiki","email":"liuzc@biowiki.com.hk"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth-sdk_0.1.0_1787879875534_0.34065924735299835"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-28T01:17:55.285Z","0.1.0":"2026-08-28T01:17:55.687Z","modified":"2026-08-28T01:17:55.969Z"},"maintainers":[{"name":"liuzcbiowiki","email":"liuzc@biowiki.com.hk"}],"description":"Browser OAuth 2.0 Authorization Code + PKCE client for BioWiki applications.","readme":"# @biowiki/auth-sdk\n\nBrowser OAuth 2.0 Authorization Code + PKCE (`S256`) client for BioWiki Web applications. It keeps only the short-lived access token in `sessionStorage`; the refresh token remains an Identity-managed HttpOnly Cookie.\nIt also maintains a stable per-application browser device ID in `localStorage` and sends it when exchanging or refreshing tokens.\n\n## Install\n\nThe package is published only to the company private npm Registry. Configure the scope registry in the consuming project's `.npmrc`:\n\n```ini\n@biowiki:registry=https://npm.company.example/repository/npm-private/\n```\n\nThen install a pinned version:\n\n```bash\nnpm install @biowiki/auth-sdk@0.1.0\n```\n\n## Use\n\n```ts\nimport { BioWikiAuthClient } from '@biowiki/auth-sdk';\n\nexport const auth = new BioWikiAuthClient({\n  authUrl: import.meta.env.VITE_AUTH_URL,\n  clientId: import.meta.env.VITE_SSO_CLIENT_ID,\n  redirectUri: `${window.location.origin}/auth/callback`\n});\n\nexport async function login() {\n  await auth.login(window.location.pathname + window.location.search);\n}\n\nexport async function completeLogin() {\n  const { returnTo } = await auth.completeLogin();\n  window.location.replace(returnTo.startsWith('/') ? returnTo : '/');\n}\n```\n\nIn the callback route, call `completeLogin()` exactly once. For protected pages, use `getSession()` or `requireAuth()`.\n\n## Logout\n\nFirst revoke the application's current API session through its same-origin BFF,\nthen call `logout()`. The SDK clears its local access token and navigates to\nthe Identity Service logout endpoint to clear the SSO session before returning\nto the registered application origin.\n\n```ts\ntry {\n  await fetch('/api/bff/auth/logout', { method: 'POST' });\n} finally {\n  await auth.logout();\n}\n```\n\n## Registration\n\nThe SDK also provides browser registration helpers:\n\n```ts\nawait auth.requestRegistrationCode({\n  email: 'user@example.com',\n  botToken: '<turnstile-token>'\n});\n\nawait auth.register({\n  email: 'user@example.com',\n  password: 'StrongPassword',\n  verificationCode: '381624'\n});\n```\n\n## Publish\n\nPackage maintainers publish from `packages/auth-sdk`:\n\n```bash\nnpm ci\nnpm run typecheck\nnpm run build\nnpm pack --dry-run\nnpm publish --registry=\"$NPM_REGISTRY\"\n```\n\nSet `NPM_REGISTRY` and `NPM_TOKEN` in CI secrets. Copy `.npmrc.example` to a user-level or CI-generated `.npmrc`, replacing the Registry URL. Never commit an npm token.\n\n`prepublishOnly` rebuilds and typechecks the package before publication. Only `dist/`, `README.md`, and `LICENSE` are included in the published tarball.\n\n## Security\n\n- Do not place `app_secret`, service tokens, JWT signing keys, or npm tokens in frontend environment variables.\n- Register the exact callback URL for each environment in Platform Console.\n- Configure Identity Service `CORS_ORIGIN` to include the application Origin.\n- The SDK does not create Tenants, Applications, OAuth Clients, or API credentials. Use `getSession()`, `isAuthenticated()`, and `requireAuth()` for browser session checks.\n","readmeFilename":"README.md","_rev":"1-f869f93a3be38da40ff43260d2b84e7b"}