{"_id":"@blue-cloud/oauth2-server","_rev":"3-6a0236185a05075f6a834269739842eb","name":"@blue-cloud/oauth2-server","dist-tags":{"latest":"2.4.7"},"versions":{"2.4.5":{"name":"@blue-cloud/oauth2-server","description":"Complete, compliant and well tested module for implementing an OAuth2 Server/Provider with express in node.js","version":"2.4.5","keywords":["oauth","oauth2"],"author":{"name":"Thom Seddon","email":"thom@seddonmedia.co.uk"},"contributors":[{"name":"Thom Seddon","email":"thom@seddonmedia.co.uk"},{"name":"Dhurv Prajapati","email":"dhruva.prajapati@gmail.com"}],"main":"lib/oauth2server.js","dependencies":{"basic-auth":"~0.0.1"},"devDependencies":{"body-parser":"^1.19.0","express":"^4.17.1","mocha":"~1.20.1","should":"~4.0.4","supertest":"~0.13.0"},"licenses":[{"type":"Apache 2.0","url":"http://www.apache.org/licenses/LICENSE-2.0.html"}],"engines":{"node":">=0.8"},"scripts":{"test":"mocha"},"repository":{"type":"git","url":"git+https://github.com/bluecloudtechnologies/node-oauth2-server.git"},"gitHead":"26c9f0f1385edf064ea36fb8a03f00376909dfbb","bugs":{"url":"https://github.com/bluecloudtechnologies/node-oauth2-server/issues"},"homepage":"https://github.com/bluecloudtechnologies/node-oauth2-server#readme","_id":"@blue-cloud/oauth2-server@2.4.5","_nodeVersion":"12.16.1","_npmVersion":"6.14.4","dist":{"integrity":"sha512-wrBhGyLIets8OVuMYOsnp7AjLqrcjFgrRWEfWF8nZi7GWUJJp6rTnHDUtw5K7MlqQeZcciR0YIw2LkuE/rDo3g==","shasum":"9e1dc8d178eaa139a0a2ad11ddaf1fbe71a9bdc4","tarball":"https://registry.npmjs.org/@blue-cloud/oauth2-server/-/oauth2-server-2.4.5.tgz","fileCount":41,"unpackedSize":162016,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJemakNCRA9TVsSAnZWagAAV9sP/R3RH96TfsW0IEFZ+rdc\nNe/lhGoYaV+jjnWwEeChsl7UqroplD/N7W0LzHL+Rb0lOcZpdyPZ3+aoVsFF\nUwITWQarLXGxqA3mi8eyg0Lykbnc6/o+7NmQtVVMh+nmZ4rxEtdqdIMptj0T\ncEY8TllBs33OILy6mmhvch0wpsVUXGazpcombQFU19YviA3WbbaBKGZ1K4jv\nHg2bmi0Qd1dFykzVvU+KYedCPKZ+w4TIcD2KHJOL55iHa6uie0j+KRK94KMG\naNceClwJfspGlzasFdYcPtJ5fxSrhg0vkPjYGZnT7Fyen+QNBi/IkDnaH2rC\n9JdRkaqBb3Tmt6nFcqzLiOvaQdaE8j6fUzagENThWoPHTGcmGcjelXryZg3A\n5FS9O39xz2Bf9sO3TgC92RfHNhXreTnDWEj6DsYtgKV1szTHrVDW6Zo3I/7E\n4/qtQozbutfVBDoYxhLe3q7ifWMgH+BS491NlAi6Enc9DcnF8uH+C0kNRV3c\nln4fQnEIFlHaLjko9OKkOPgQ3rRG++4oysf4cGdprEc0YJ7RetzlYSwuen5/\n0/4kkZeYzlmROp3Mx7+1VTxt5IrZzqhwO84rKrG7b9laeop3J1SPILxWxl0c\n+UEC+fGKC2SFYwHgkgopN6IQRAIWQZKQtVIP09fZAcOYxEiS4dmiTdIf571J\neDFr\r\n=19NP\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDiZ73AfJS93iRGLx5LRdD0C4NSHPwDSc0ZvkqnP6P7FwIhAKYqClAB6nqkP+oFsAl99Ayrr9T1gF0UskTtKtf7LByL"}]},"maintainers":[{"name":"blue-cloud","email":"vphpltechnology@gmail.com"}],"_npmUser":{"name":"blue-cloud","email":"vphpltechnology@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/oauth2-server_2.4.5_1587128588989_0.2627302796977895"},"_hasShrinkwrap":false},"2.4.6":{"name":"@blue-cloud/oauth2-server","description":"Complete, compliant and well tested module for implementing an OAuth2 Server/Provider with express in node.js","version":"2.4.6","keywords":["oauth","oauth2"],"author":{"name":"Thom Seddon","email":"thom@seddonmedia.co.uk"},"contributors":[{"name":"Thom Seddon","email":"thom@seddonmedia.co.uk"},{"name":"Dhurv Prajapati","email":"dhruva.prajapati@gmail.com"}],"main":"lib/oauth2server.js","dependencies":{"basic-auth":"~0.0.1"},"devDependencies":{"body-parser":"^1.19.0","express":"^4.17.1","mocha":"~1.20.1","should":"~4.0.4","supertest":"~0.13.0"},"licenses":[{"type":"Apache 2.0","url":"http://www.apache.org/licenses/LICENSE-2.0.html"}],"engines":{"node":">=0.8"},"scripts":{"test":"mocha"},"repository":{"type":"git","url":"git+https://github.com/bluecloudtechnologies/node-oauth2-server.git"},"gitHead":"7d0cb38c604d17c5fd0741707abe38100abfc10e","bugs":{"url":"https://github.com/bluecloudtechnologies/node-oauth2-server/issues"},"homepage":"https://github.com/bluecloudtechnologies/node-oauth2-server#readme","_id":"@blue-cloud/oauth2-server@2.4.6","_nodeVersion":"12.16.1","_npmVersion":"6.14.4","dist":{"integrity":"sha512-ft3ky/TIYxaMPAUlAN6OpLt/ZRNhg8u48mOhSswWgrZz1JlTEnRmUV0Fk+qXGQjk67RUGc5uAHmUhpuXc/Mz+A==","shasum":"58b149082d127071a137f54c7d51458196b40e32","tarball":"https://registry.npmjs.org/@blue-cloud/oauth2-server/-/oauth2-server-2.4.6.tgz","fileCount":41,"unpackedSize":162017,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJemap3CRA9TVsSAnZWagAAmD0P/3PuXKw5ezrG6+ZCPTe3\nP9CVRhMGD/BLlygBEfn662V8M+jzDLsay+FmrcN2ze+SjQf+TtgcAJDWrBdP\n8Y9G2QwEj3B5U+thWNUBUYVmVY5qyzw2oQdWN09rHOxMa/NuYbRphnXOI3Up\ndgR9h5sNjXV90UNw1nu2s8r3Vb1psn9w2NxbZdb1a4toEhVtU1FVS2Nog8d7\nfuFs1OsJKfW+CeqJ4KhcI1JyL6mT56gvB9QDSF97T4OlPCDnnMRs8BBmsfuc\nkprlqftS1QA+Rz/wlhTYfr8T6D4WOsaOYvJhCrZ9VIudtHVq8tkYdN61JNC8\nlCMUBeS4VGUzKPyOLdlrOdUPjYWWxhNNfdBS6ljYff9sQrbeCVjqPYaN1ovL\nl3th5tya6L5HeDXuA5UCkR8mK0vMRhi81HIWLnIGuSjD1IWVzXIYDZzkeIhB\nVpbbfUNokamkRTqb19TDE/4fWUFALcEzyDy1/FGup81rZ+2/lyWrQFobIO3G\nRtRZs1ogyJuLL4VLplBFe9QUVAlRS8AHBvRV70yrrzZLZBMrkNjn2MGA8fdc\nb05wQ3VQ1nMXOOnt7DSIAt/1RQQsik/ws6kTLDzbJR5JTKuk86qorcKbtn9J\nvrJ6+hy/iFdLjz2dZkBg4VQ70JjEu7EldvZdqCZs8juEnTqB5fDMytFidVeK\nz0V4\r\n=tcv3\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGDH14usKaq7th17V5kFJz6fR/ir1vMNvkH6/czRfB8PAiAROAVgboKNHO4sJiEKiiXn3aVN2aheDgU7gyxOk0d+cQ=="}]},"maintainers":[{"name":"blue-cloud","email":"vphpltechnology@gmail.com"}],"_npmUser":{"name":"blue-cloud","email":"vphpltechnology@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/oauth2-server_2.4.6_1587128950874_0.4140011714184584"},"_hasShrinkwrap":false},"2.4.7":{"name":"@blue-cloud/oauth2-server","description":"Complete, compliant and well tested module for implementing an OAuth2 Server/Provider with express in node.js","version":"2.4.7","keywords":["oauth","oauth2"],"author":{"name":"Thom Seddon","email":"thom@seddonmedia.co.uk"},"contributors":[{"name":"Thom Seddon","email":"thom@seddonmedia.co.uk"},{"name":"Dhurv Prajapati","email":"dhruva.prajapati@gmail.com"}],"main":"lib/oauth2server.js","dependencies":{"basic-auth":"~0.0.1"},"devDependencies":{"body-parser":"^1.19.0","express":"^4.17.1","mocha":"~1.20.1","should":"~4.0.4","supertest":"~0.13.0"},"licenses":[{"type":"Apache 2.0","url":"http://www.apache.org/licenses/LICENSE-2.0.html"}],"engines":{"node":">=0.8"},"scripts":{"test":"mocha"},"repository":{"type":"git","url":"git+https://github.com/bluecloudtechnologies/node-oauth2-server.git"},"gitHead":"4356eace5122c9e7bcea7e1cb18c6badc63901f4","bugs":{"url":"https://github.com/bluecloudtechnologies/node-oauth2-server/issues"},"homepage":"https://github.com/bluecloudtechnologies/node-oauth2-server#readme","_id":"@blue-cloud/oauth2-server@2.4.7","_nodeVersion":"12.16.1","_npmVersion":"6.14.4","dist":{"integrity":"sha512-FKq5BNAC6TkKhekfKYhU4hn4TFh2YoOGdy1PApcZzHLUCNOXJgLVTxLYSVvvOdJ4VRiQuI8x6UCtnF30nr9UqA==","shasum":"70582e69d54a729db259a60ea4dd3157039525ab","tarball":"https://registry.npmjs.org/@blue-cloud/oauth2-server/-/oauth2-server-2.4.7.tgz","fileCount":41,"unpackedSize":162018,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJemarkCRA9TVsSAnZWagAAS2IP/13CLufptaFH9yOjcZ8u\nyYp2IaLKigIEm/cAGeO1PfB/txaQHtOYyX8P5cs88sJ7GZVsdoPKneBsyMwJ\nMDkJT5sUeHiAN/8rmOVj3SutMtXpfgmqBH+A85b83YyVfsgA47dSWnNeyg5f\ncqNhMs7kvRgoRQt4q1WGg+Wh0s8HC1L9v8XSmtsFF82jzhR54TojoK81l4tF\nUoTHnjQWhgYAngWL2HXhpAG8+RoKM3hdBMhZ/eZbQjxTNMuA96xuUBZkf92x\nyw1CATFn+mKuuVTzcdzq9HOAIyG1WW744VdP64nDW4faclBQQTmF4KwV2aig\nG8Oz8wpiidHiWY6ew9KNVlKPqU/k8c7NAEV0istyMp98+n2RrKJkqFQBLkLy\n1JLZz5sVB5YFf1XpMgd6A6fX0qML2zGMzZ6xK2ERRiOLNUgzE0l82n8uADS/\nRnzqPZGcrWhm4iQ3WhAZsMOKCg+Tt7nVE5SS0cFULoZe6gLQeAI4VQG2Px2J\nap030+CBwjrD4Lw5YtBaPLU5F4qrM4AlwKMKhgesPWgKMe1aYftw9Y733seN\nNqmp3JLMCSJPw2mjoxoGX9494ByLVc//aUGblCGheMgCRDrbEfw98Fvy/zot\nkKRFl3jhbVz/d30/3OcXMICYz8oErPpm1UQYUgEXHfipgW5TZ//PnsI2pKMO\nrKq8\r\n=a85G\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICT04wOWm79vMgQ3bQckzpOpf1cLEOjQN2WwgsLtM4zMAiAz7NM4nd3hsU6SWUaUzQt43x2clVTuRsTwcTJ8dspAkw=="}]},"maintainers":[{"name":"blue-cloud","email":"vphpltechnology@gmail.com"}],"_npmUser":{"name":"blue-cloud","email":"vphpltechnology@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/oauth2-server_2.4.7_1587129059908_0.7931253051987814"},"_hasShrinkwrap":false}},"time":{"created":"2020-04-17T13:03:08.951Z","2.4.5":"2020-04-17T13:03:09.149Z","modified":"2022-04-04T19:43:47.662Z","2.4.6":"2020-04-17T13:09:11.058Z","2.4.7":"2020-04-17T13:11:00.036Z"},"maintainers":[{"name":"blue-cloud","email":"vphpltechnology@gmail.com"}],"description":"Complete, compliant and well tested module for implementing an OAuth2 Server/Provider with express in node.js","homepage":"https://github.com/bluecloudtechnologies/node-oauth2-server#readme","keywords":["oauth","oauth2"],"repository":{"type":"git","url":"git+https://github.com/bluecloudtechnologies/node-oauth2-server.git"},"contributors":[{"name":"Thom Seddon","email":"thom@seddonmedia.co.uk"},{"name":"Dhurv Prajapati","email":"dhruva.prajapati@gmail.com"}],"author":{"name":"Thom Seddon","email":"thom@seddonmedia.co.uk"},"bugs":{"url":"https://github.com/bluecloudtechnologies/node-oauth2-server/issues"},"readme":"# Node OAuth2 Server [![Build Status](https://travis-ci.org/thomseddon/node-oauth2-server.png?branch=2.0)](https://travis-ci.org/thomseddon/node-oauth2-server) \n\nComplete, compliant and well tested module for implementing an OAuth2 Server/Provider with [express](http://expressjs.com/) in [node.js](http://nodejs.org/)\n\n## Installation\n\n```\nnpm i @blue-cloud/oauth2-server\n```\n\n## Quick Start\n\nThe module provides two middlewares, one for authorization and routing, another for error handling, use them as you would any other middleware:\n\n```js\nvar express = require('express'),\n    bodyParser = require('body-parser'),\n    oauthserver = require('@blue-cloud/oauth2-server');\n\nvar app = express();\n\napp.use(bodyParser.urlencoded({ extended: true }));\n\napp.use(bodyParser.json());\n\napp.oauth = oauthserver({\n  model: {}, // See below for specification\n  grants: ['password'],\n  debug: true\n});\n\napp.all('/oauth/token', app.oauth.grant());\n\napp.get('/', app.oauth.authorise(), function (req, res) {\n  res.send('Secret area');\n});\n\napp.use(app.oauth.errorHandler());\n\napp.listen(3000);\n```\n\nAfter running with node, visting http://127.0.0.1:3000 should present you with a json response saying your access token could not be found.\n\nNote: As no model was actually implemented here, delving any deeper, i.e. passing an access token, will just cause a server error. See below for the specification of what's required from the model.\n\n## Features\n\n- Supports authorization_code, password, refresh_token, client_credentials and extension (custom) grant types\n- Implicitly supports any form of storage e.g. PostgreSQL, MySQL, Mongo, Redis...\n- Full test suite\n\n## Options\n\n- *string* **model**\n - Model object (see below)\n- *array* **grants**\n - grant types you wish to support, currently the module supports `authorization_code`, `password`, `refresh_token` and `client_credentials`\n  - Default: `[]`\n- *function|boolean* **debug**\n - If `true` errors will be  logged to console. You may also pass a custom function, in which case that function will be called with the error as its first argument\n  - Default: `false`\n- *number* **accessTokenLifetime**\n - Life of access tokens in seconds\n - If `null`, tokens will considered to never expire\n  - Default: `3600`\n- *number* **refreshTokenLifetime**\n - Life of refresh tokens in seconds\n - If `null`, tokens will considered to never expire\n  - Default: `1209600`\n- *number* **authCodeLifetime**\n - Life of auth codes in seconds\n  - Default: `30`\n- *regexp* **clientIdRegex**\n - Regex to sanity check client id against before checking model. Note: the default just matches common `client_id` structures, change as needed \n  - Default: `/^[a-z0-9-_]{3,40}$/i`\n- *boolean* **passthroughErrors**\n - If true, **non grant** errors will not be handled internally (so you can ensure a consistent format with the rest of your api)\n- *boolean* **continueAfterResponse**\n - If true, `next` will be called even if a response has been sent (you probably don't want this)\n\n## Model Specification\n\nThe module requires a model object through which some aspects or storage, retrieval and custom validation are abstracted.\nThe last parameter of all methods is a callback of which the first parameter is always used to indicate an error.\n\nNote: see https://github.com/thomseddon/node-oauth2-server/tree/master/examples/postgresql for a full model example using postgres.\n\n### Always Required\n\n#### getAccessToken (bearerToken, callback)\n- *string* **bearerToken**\n - The bearer token (access token) that has been provided\n- *function* **callback (error, accessToken)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *object* **accessToken**\n     - The access token retrieved form storage or falsey to indicate invalid access token\n     - Must contain the following keys:\n         - *date* **expires**\n             - The date when it expires\n             - `null` to indicate the token **never expires**\n         - *mixed* **user** *or* *string|number* **userId**\n             - If a `user` key exists, this is saved as `req.user`\n             - Otherwise a `userId` key must exist, which is saved in `req.user.id`\n\n#### getClient (clientId, clientSecret, callback)\n- *string* **clientId**\n- *string|null* **clientSecret**\n - If null, omit from search query (only search by clientId)\n- *function* **callback (error, client)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *object* **client**\n     - The client retrieved from storage or falsey to indicate an invalid client\n     - Saved in `req.client`\n     - Must contain the following keys:\n         - *string* **clientId**\n         - *string* **redirectUri** (`authorization_code` grant type only)\n\n#### grantTypeAllowed (clientId, grantType, callback)\n- *string* **clientId**\n- *string* **grantType**\n- *function* **callback (error, allowed)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *boolean* **allowed**\n     - Indicates whether the grantType is allowed for this clientId\n\n#### saveAccessToken (accessToken, client, expires, user, callback)\n- *string* **accessToken**\n- *mixed* **client**\n   - Whatever was passed to getClient callback\n- *date* **expires**\n- *object* **user**\n- *function* **callback (error)**\n - *mixed* **error**\n     - Truthy to indicate an error\n\n\n### Required for `authorization_code` grant type\n\n#### getAuthCode (authCode, callback)\n- *string* **authCode**\n- *function* **callback (error, authCode)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *object* **authCode**\n     - The authorization code retrieved form storage or falsey to indicate invalid code\n     - Must contain the following keys:\n         - *string|number* **clientId**\n             - client id associated with this auth code\n         - *date* **expires**\n             - The date when it expires\n         - *string|number* **userId**\n             - The userId\n\n#### saveAuthCode (authCode, client, expires, user, callback)\n- *string* **authCode**\n- *mixed* **client**\n   - Whatever was passed to getClient callback\n- *date* **expires**\n- *mixed* **user**\n   - Whatever was passed as `user` to the codeGrant function (see example)\n- *function* **callback (error)**\n - *mixed* **error**\n     - Truthy to indicate an error\n\n\n### Required for `password` grant type\n\n#### getUser (username, password, callback)\n- *string* **username**\n- *string* **password**\n- *function* **callback (error, user)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *object* **user**\n     - The user retrieved from storage or falsey to indicate an invalid user\n     - Saved in `req.user`\n     - Must contain the following keys:\n         - *string|number* **id**\n\n### Required for `refresh_token` grant type\n\n#### saveRefreshToken (refreshToken, client, expires, user, callback)\n- *string* **refreshToken**\n- *mixed* **client**\n   - Whatever was passed to getClient callback\n- *date* **expires**\n- *object* **user**\n- *function* **callback (error)**\n - *mixed* **error**\n     - Truthy to indicate an error\n\n#### getRefreshToken (refreshToken, callback)\n- *string* **refreshToken**\n - The bearer token (refresh token) that has been provided\n- *function* **callback (error, refreshToken)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *object* **refreshToken**\n     - The refresh token retrieved form storage or falsey to indicate invalid refresh token\n     - Must contain the following keys:\n         - *string|number* **clientId**\n             - client id associated with this token\n         - *date* **expires**\n             - The date when it expires\n             - `null` to indicate the token **never expires**\n         - *string|number* **userId**\n             - The userId\n\n\n### Optional for Refresh Token grant type\n\n#### revokeRefreshToken (refreshToken, callback)\nThe spec does not actually require that you revoke the old token - hence this is optional (Last paragraph: http://tools.ietf.org/html/rfc6749#section-6)\n- *string* **refreshToken**\n- *function* **callback (error)**\n - *mixed* **error**\n     - Truthy to indicate an error\n\n### Required for [extension grant](#extension-grants) grant type\n\n#### extendedGrant (grantType, req, callback)\n- *string* **grantType**\n - The (custom) grant type\n- *object* **req**\n - The raw request\n- *function* **callback (error, supported, user)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *boolean* **supported**\n     - Whether you support the grant type\n - *object* **user**\n     - The user retrieved from storage or falsey to indicate an invalid user\n     - Saved in `req.user`\n     - Must contain the following keys:\n         - *string|number* **id**\n\n### Required for `client_credentials` grant type\n\n#### getUserFromClient (clientId, clientSecret, callback)\n- *string* **clientId**\n- *string* **clientSecret**\n- *function* **callback (error, user)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *object* **user**\n     - The user retrieved from storage or falsey to indicate an invalid user\n     - Saved in `req.user`\n     - Must contain the following keys:\n         - *string|number* **id**\n\n\n### Optional\n\n#### generateToken (type, req, callback)\n- *string* **type**\n - `accessToken` or `refreshToken`\n- *object* **req**\n - The current express request\n- *function* **callback (error, token)**\n - *mixed* **error**\n     - Truthy to indicate an error\n - *string|object|null* **token**\n     - *string* indicates success\n     - *null* indicates to revert to the default token generator\n     - *object* indicates a reissue (i.e. will not be passed to saveAccessToken/saveRefreshToken)\n         - Must contain the following keys (if object):\n           - *string* **accessToken** OR **refreshToken** dependant on type\n\n## Extension Grants\nYou can support extension/custom grants by implementing the extendedGrant method as outlined above.\nAny grant type that is a valid URI will be passed to it for you to handle (as [defined in the spec](http://tools.ietf.org/html/rfc6749#section-4.5)).\nYou can access the grant type via the first argument and you should pass back supported as `false` if you do not support it to ensure a consistent (and compliant) response.\n\n## Example using the `password` grant type\n\nFirst you must insert client id/secret and user into storage. This is out of the scope of this example.\n\nTo obtain a token you should POST to `/oauth/token`. You should include your client credentials in\nthe Authorization header (\"Basic \" + client_id:client_secret base64'd), and then grant_type (\"password\"),\nusername and password in the request body, for example:\n\n```\nPOST /oauth/token HTTP/1.1\nHost: server.example.com\nAuthorization: Basic czZCaGRSa3F0MzpnWDFmQmF0M2JW\nContent-Type: application/x-www-form-urlencoded\n\ngrant_type=password&username=johndoe&password=A3ddj3w\n```\nThis will then call the following on your model (in this order):\n - getClient (clientId, clientSecret, callback)\n - grantTypeAllowed (clientId, grantType, callback)\n - getUser (username, password, callback)\n - saveAccessToken (accessToken, clientId, expires, user, callback)\n - saveRefreshToken (refreshToken, clientId, expires, user, callback) **(if using)**\n\nProvided there weren't any errors, this will return the following (excluding the `refresh_token` if you've not enabled the refresh_token grant type):\n\n```\nHTTP/1.1 200 OK\nContent-Type: application/json;charset=UTF-8\nCache-Control: no-store\nPragma: no-cache\n\n{\n  \"access_token\":\"2YotnFZFEjr1zCsicMWpAA\",\n  \"token_type\":\"bearer\",\n  \"expires_in\":3600,\n  \"refresh_token\":\"tGzv3JOkF0XG5Qx2TlKWIA\"\n}\n```\n\n## Changelog\n\nSee: https://github.com/thomseddon/node-oauth2-server/blob/master/Changelog.md\n\n## Credits\n\nCopyright (c) 2013 Thom Seddon\n\n## License\n\n[Apache, Version 2.0](https://github.com/thomseddon/node-oauth2-server/blob/master/LICENSE)\n","readmeFilename":"Readme.md"}