{"_id":"@bobyzgirlllnpm/illo-quod-quae","name":"@bobyzgirlllnpm/illo-quod-quae","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@bobyzgirlllnpm/illo-quod-quae","version":"1.0.0","description":"[![Greenkeeper badge](https://badges.greenkeeper.io/bobyzgirlllnpm/illo-quod-quae.svg)](https://greenkeeper.io/) [![npm][npm-badge]][npm-url] [![travis][travis-badge]][travis-url] [![coveralls][coveralls-badge]][coveralls-url] [![snyk][snyk-badge]][snyk-u","main":"index.js","scripts":{},"author":{"name":"bobyzgirlLl"},"license":"MIT","dependencies":{"@bobyzgirlllnpm/aspernatur-fugiat-quam":"^1.0.0","@bobyzgirlllnpm/autem-nemo-incidunt":"^1.0.0","@bobyzgirlllnpm/dolorem-officia-assumenda":"^1.0.0","@bobyzgirlllnpm/dolorem-vero-atque":"^1.0.0","@bobyzgirlllnpm/facere-ipsum-aspernatur":"^1.0.0","@bobyzgirlllnpm/id-nobis-pariatur":"^1.0.0","@bobyzgirlllnpm/illo-architecto-dolorum":"^1.0.0","@bobyzgirlllnpm/impedit-quia-ea":"^1.0.0","@bobyzgirlllnpm/itaque-similique-commodi":"^1.0.0","@bobyzgirlllnpm/iure-velit-sapiente":"^1.0.0","@bobyzgirlllnpm/libero-facere-id":"^1.0.0","@bobyzgirlllnpm/libero-itaque-consequuntur":"^1.0.0","@bobyzgirlllnpm/magnam-laboriosam-illum":"^1.0.0","@bobyzgirlllnpm/mollitia-doloribus-sapiente":"^1.0.0","@bobyzgirlllnpm/mollitia-fugit-officia":"^1.0.0","@bobyzgirlllnpm/nesciunt-voluptatibus-nesciunt":"^1.0.0","@bobyzgirlllnpm/nostrum-inventore-quasi":"^1.0.0","@bobyzgirlllnpm/nostrum-voluptate-provident":"^1.0.0","@bobyzgirlllnpm/pariatur-recusandae-id":"^1.0.0","@bobyzgirlllnpm/perspiciatis-sequi-eligendi":"^1.0.0","@bobyzgirlllnpm/recusandae-minus-veritatis":"^1.0.0","@bobyzgirlllnpm/repudiandae-quae-in":"^1.0.0","@bobyzgirlllnpm/saepe-autem-impedit":"^1.0.0","@bobyzgirlllnpm/suscipit-nisi-fuga":"^1.0.0","@bobyzgirlllnpm/ullam-voluptate-placeat":"^1.0.0","@drftgyhuji7npm/repellendus-eum-et-itaque":"^1.0.0","hai-custom-button":"^1.0.0","remind-works-8th":"^1.0.2","web3-khai-1":"^1.0.1","web3-khai-2":"^1.0.1"},"keywords":["URL","reducer","eslintplugin","eslintconfig","east-asian-width","transpiler","tslib","stdlib","environment","chinese","tester","setImmediate","global","symbol","Uint16Array","child","uninstall","functional","hasOwnProperty","limit","three","airbnb","streams","up","Iterator","npm","lint","some","toArray","execute","mru","react-testing-library","option","beanstalk","internal","loadbalancing","dir","extend","limited","text","asterisks","safe","findup","multi-package","concatMap","wordbreak","waapi","positive","fetch","get","Object.entries","property","Set","route","formatting","xml","equality","clone","wrap","Object.assign","TypedArray","apollo","debugger","write","jshint","debug","spring","number","generics","URLSearchParams","proxy","ECMAScript 2020","log","readablestream","globals","deep-copy","YAML","ArrayBuffer","libphonenumber","ECMAScript 6","require","lazy","async","styled-components","nope","expression","omit","ratelimit","tostringtag","rfc4122","gdpr","lru","ECMAScript 2016","find","chai","scheme","ECMAScript 2018","fastcopy","events","ses","from","sort","throat","once","drag","column","postcss-plugin","http","prune","Object.fromEntries","tc39","react-hook-form","xhr","walk","package.json","promise","importexport","take","match","agent","environments","eslint","parsing","elb","real-time","make dir","route53","zod","escape","slice","regular-expression","asserts","arrays","electron","es8","values","progress","-0","filter","copy","karma","workflow","Float64Array","framer","art","picomatch","endpoint","shebang","Symbol","optimist","own","resolve","typedarray","iterator","hooks","task","javascript","redux-toolkit","vest","error","ES2016","worker","Object.values","callback","consume","array","fastclone","ECMAScript 2021","fps","protobuf","form","collection","bundling","JSON","jQuery","dataView","getter","deep-clone","typed","espree","react animation","fork","ECMAScript 2022","mkdirp","execfile","group","inference","redact","import","entries","forEach","jsx","folder","stringify","rules","inspect","ts","Array.prototype.findLast","sham","manager"],"repository":{"type":"git","url":"git+https://github.com/bobyzgirlllnpm/illo-quod-quae.git"},"homepage":"https://github.com/bobyzgirlllnpm/illo-quod-quae/#readme","bugs":{"url":"https://github.com/bobyzgirlllnpm/illo-quod-quae/issues"},"_id":"@bobyzgirlllnpm/illo-quod-quae@1.0.0","gitHead":"31f147b5b08116bad558717d653e07cad068f182","_nodeVersion":"20.12.2","_npmVersion":"10.5.0","dist":{"integrity":"sha512-AatOJIHHD+NNYi2JotpMQgIZrgLkx49FkO0PGnQ91XxJiErGPZprKuo9GTyID5Ao0VtwejtlVTUmjGQG8zSn9A==","shasum":"739ebd3931f933092b117c81cba00b16f4baecad","tarball":"https://registry.npmjs.org/@bobyzgirlllnpm/illo-quod-quae/-/illo-quod-quae-1.0.0.tgz","fileCount":8,"unpackedSize":22217,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCVvD4UblCedmhpsAGMoHQD2hZWqURxkXAzgdKyPi1XOgIgBE+obOoyDtPCodvh5arAnkxF7kn+OMLKuUackDB8YRU="}]},"_npmUser":{"name":"haiminh1192","email":"haiminh1192@gmail.com"},"directories":{},"maintainers":[{"name":"haiminh1192","email":"haiminh1192@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/illo-quod-quae_1.0.0_1715416461802_0.9931511832252435"},"_hasShrinkwrap":false}},"time":{"created":"2024-05-11T08:34:21.667Z","1.0.0":"2024-05-11T08:34:21.950Z","modified":"2024-05-11T08:34:22.189Z"},"maintainers":[{"name":"haiminh1192","email":"haiminh1192@gmail.com"}],"description":"[![Greenkeeper badge](https://badges.greenkeeper.io/bobyzgirlllnpm/illo-quod-quae.svg)](https://greenkeeper.io/) [![npm][npm-badge]][npm-url] [![travis][travis-badge]][travis-url] [![coveralls][coveralls-badge]][coveralls-url] [![snyk][snyk-badge]][snyk-u","homepage":"https://github.com/bobyzgirlllnpm/illo-quod-quae/#readme","keywords":["URL","reducer","eslintplugin","eslintconfig","east-asian-width","transpiler","tslib","stdlib","environment","chinese","tester","setImmediate","global","symbol","Uint16Array","child","uninstall","functional","hasOwnProperty","limit","three","airbnb","streams","up","Iterator","npm","lint","some","toArray","execute","mru","react-testing-library","option","beanstalk","internal","loadbalancing","dir","extend","limited","text","asterisks","safe","findup","multi-package","concatMap","wordbreak","waapi","positive","fetch","get","Object.entries","property","Set","route","formatting","xml","equality","clone","wrap","Object.assign","TypedArray","apollo","debugger","write","jshint","debug","spring","number","generics","URLSearchParams","proxy","ECMAScript 2020","log","readablestream","globals","deep-copy","YAML","ArrayBuffer","libphonenumber","ECMAScript 6","require","lazy","async","styled-components","nope","expression","omit","ratelimit","tostringtag","rfc4122","gdpr","lru","ECMAScript 2016","find","chai","scheme","ECMAScript 2018","fastcopy","events","ses","from","sort","throat","once","drag","column","postcss-plugin","http","prune","Object.fromEntries","tc39","react-hook-form","xhr","walk","package.json","promise","importexport","take","match","agent","environments","eslint","parsing","elb","real-time","make dir","route53","zod","escape","slice","regular-expression","asserts","arrays","electron","es8","values","progress","-0","filter","copy","karma","workflow","Float64Array","framer","art","picomatch","endpoint","shebang","Symbol","optimist","own","resolve","typedarray","iterator","hooks","task","javascript","redux-toolkit","vest","error","ES2016","worker","Object.values","callback","consume","array","fastclone","ECMAScript 2021","fps","protobuf","form","collection","bundling","JSON","jQuery","dataView","getter","deep-clone","typed","espree","react animation","fork","ECMAScript 2022","mkdirp","execfile","group","inference","redact","import","entries","forEach","jsx","folder","stringify","rules","inspect","ts","Array.prototype.findLast","sham","manager"],"repository":{"type":"git","url":"git+https://github.com/bobyzgirlllnpm/illo-quod-quae.git"},"author":{"name":"bobyzgirlLl"},"bugs":{"url":"https://github.com/bobyzgirlllnpm/illo-quod-quae/issues"},"license":"MIT","readme":"# Udaru\n\n[![Greenkeeper badge](https://badges.greenkeeper.io/bobyzgirlllnpm/illo-quod-quae.svg)](https://greenkeeper.io/)\n[![npm][npm-badge]][npm-url]\n[![travis][travis-badge]][travis-url]\n[![coveralls][coveralls-badge]][coveralls-url]\n[![snyk][snyk-badge]][snyk-url]\n\n![Udaru](./docs/logo.jpg)\nUdaru is a Policy Based Access Control (PBAC) authorization module. It supports Organizations, Teams and User entities that are used to build the access model. The policies attached to these entities define the 'Actions' that can be performed by an entity on various 'Resources'.\n\nSee the Udaru [website](https://nearform.github.io/udaru/) for complete documentation on Udaru.\n\nThis repository is home to Udaru's three main modules:\n\n| Module                                                                    | Package                                                             |\n| ------                                                                    | -------                                                             |\n| [@bobyzgirlllnpm/illo-quod-quae][npm-udaru-core]                                    | [./packages/udaru-core](./packages/udaru-core)                      |\n| [@bobyzgirlllnpm/illo-quod-quae-hapi-plugin][udaru-hapi-plugin] (for Hapi v17 and above) | [./packages/udaru-hapi-plugin](./packages/udaru-hapi-plugin)        |\n| [@bobyzgirlllnpm/illo-quod-quae-hapi-16-plugin][udaru-hapi-16-plugin] (for Hapi v16)     | [./packages/udaru-hapi-16-plugin](./packages/udaru-hapi-16-plugin)  |\n| [@bobyzgirlllnpm/illo-quod-quae-hapi-server][udaru-hapi-server] (for Hapi v16)           | [./packages/udaru-hapi-server](./packages/udaru-hapi-server)        |\n\n### Database support\n\nUdaru requires an instance of Postgres (version 9.5+) to function correctly. For simplicity, a preconfigured `docker-compose` file has been provided. To run:\n\n```\ndocker-compose up\n```\n\n-   **Note:** Ensure you are using the latest version of Docker for (Linux/OSX/Windows)\n-   **Note:** Udaru needs PostgreSQL >= 9.5\n\n#### Populate the database\nThe Authorization database, system user and initial tables can be created by executing:\n\n```\nnpm run pg:init\n```\n\nTest data can be added with:\n\n```\nnpm run pg:load-test-data\n```\n\n-   **Note:** Running a test or coverage command will auto run these commands\n\n#### Volume data set installation and bench tests\nThe Authorization database can be further initialized with a larger volume of data, which can be tested using autocannon bench tests in order to demonstrate the potential throughput of the authorization API.\n\nTo populate the database with volume data, execute the following command:\n\n```\nnpm run pg:init-volume-db\n```\n\n-   **Note:** Running this command will auto run the standard database population commands also\n\nAll volume data sits under the organization 'CONCH' and has the following default setup:\n-   500 teams\n-   100 users per team (the first of every 100 being the parent of subsequent 99)\n-   10 policies per team\n\nAfter loading the data, the autocannon bench tests can be run by executing:\n\n```\nnpm run bench:volume\n```\n\nThis will run 15 second autocannon tests, which fire multiple concurrent requests at 2 frequently used endpoints. This results in the database being queried randomly across the entire set of data giving a good indication of average end-to-end latency and potential requests per second for a database containing 50K users.\n\n\n### pgAdmin database access\nAs the Postgresql docker container has its 5432 port forwarded on the local machine the database can be accessed with pgAdmin.\n\nTo access the database using the pgAdmin you have to fill in also the container IP beside the database names and access credentials. The container IP can be seen with `docker ps`.  Use IP 127.0.0.1 and use postgres as username/password to connect to database server.\n\n### Migrations\nWe use [`postgrator`][postgrator] for database migrations. You can find the sql files in the [`database/migrations`](https://github.com/bobyzgirlllnpm/illo-quod-quae/tree/master/database/migrations) folder. To run the migrations manually:\n\n```\nnode packages/udaru-core/database/migrate.js --version=<version>`\n```\n\n-   **Note:** Running the tests or init commands will automaticaly bring the db to the latest version.\n\nTo get more information see [Service Api documentation](#service-api-documentation)\n\n### Setup SuperUser\n\nThe init script needs to be run in order to setup the SuperUser: `node packages/udaru-core/scripts/init`\n\nIf you want to specify a better SuperUser id (default is `SuperUserId`) you can prefix the script as follow:\n\n```\nUDARU_SERVICE_authorization_superUser_id=myComplexId12345 node packages/udaru-core/scripts/init\n```\n\n-   **Note:** if you have already ran some tests or loaded the test data, you will need to run `npm run pg:init` again to reset the db.\n\n### Load policies from file\n\nRun the following script to load policies:\n\nUsage: `node packages/udaru-core/scripts/loadPolicies --org=FOO policies.json`\n\nJSON structure:\n\n```\n{\n  \"policies\": [\n    {\n      \"id\": \"unique-string\", // <== optional\n      \"version\": \"\",\n      \"name\": \"policy name\",\n      \"organizationId\": \"your_organization\" // <== optional, if present will override the \"--org=FOO\" parameter\n      \"statements\": [\n        {\n          \"Effect\": \"Allow/Deny\",\n          \"Action\": \"act\",\n          \"Resource\": \"res\"\n        },\n        { /*...*/ }\n      ]\n    },\n    { /*...*/ }\n  ]\n}\n```\n\n## Documentation\n\nThe Udaru documentation site can be found at [nearform.github.io/udaru][docs-site].\n\n### Swagger API Documentation\n\nThe Swagger API documentation gives explanations on the exposed API. The documentation can be found at [nearform.github.io/udaru/swagger/][swagger-docs-url].\n\nIt is also possible to access the Swagger documentation from Udaru itself. Simply start the server:\n\n```\nnpm run start\n```\n\nand then go to [`http://localhost:8080/documentation`][swagger-link]\n\nThe Swagger documentation also gives the ability to execute calls to the API and see their results. If you're using the test database, you can use 'ROOTid' as the required authorization parameter and 'WONKA' as the organisation.\n\n### ENV variables to set configuration options\nThere are three default configuration files, one per \"level\": [`packages/udaru-core/config.js`][core-config], [`packages/udaru-hapi-16-plugin/config.js`][plugin-config] and [`packages/udaru-server/config.js`][server-config].\n\nThey are cumulative: when running udaru as a standalone server all the three files will be loaded; when using it as an Hapi plugin, plugin and core will be loaded.\n\nThis configuration is the one used in dev environment and we are quite sure the production one will be different :) To override this configuration you can:\n\n-   provide a config object when using it as a standalone module or hapi server\n-   ENV variables on the server/container/machine you will run Udaru on.\n\n### Config object\n\n**Standalone module**\n```js\nconst buildUdaru = require('@bobyzgirlllnpm/illo-quod-quae')\nconst udaru = buildUdaru(dbPool, {\n  logger: {\n    pino: {\n      level: 'warn'\n    }\n  }\n}})\n```\n\n**Hapi plugin**\n```js\nasync function () {\n  const server = Hapi.Server()\n  const UdaruPlugin = require('@bobyzgirlllnpm/illo-quod-quae-hapi-plugin')\n\n  await server.register({\n    plugin: UdaruPlugin,\n    options: {dbPool, config: {\n      api: {\n        servicekeys: {\n          private: ['123456789']\n        }\n      }\n  }}})\n\n  await server.start()\n\n  return server\n}\n```\n\n**Hapi 16 plugin**\n\n```js\nconst Hapi = require('hapi')\nconst UdaruPlugin = require('@bobyzgirlllnpm/illo-quod-quae-hapi-16-plugin')\nconst server = new Hapi.server()\nserver.register({\n  register: UdaruPlugin,\n  options: {dbPool, config: {\n    api: {\n      servicekeys: {\n        private: ['123456789']\n      }\n    }\n}}})\n```\n\n**ENV variable override**\n```\nUDARU_SERVICE_security_api_servicekeys_private_0=jerfkgfjdedfkg3j213i43u31jk2erwegjndf\n```\n\nTo achieve this we use the [`reconfig`][reconfig] module.\n\n## Testing, benching & linting\n\nBefore running tests, ensure a valid Postgres database is running. The simplest way to do this is via Docker. Assuming docker is installed on your machine, in the root folder, run:\n\n```\ndocker-compose up -d\n```\n\nThis will start a Postgres database. Running test or coverage runs will automatically populate the database with the information it needs.\n\n-   **Note:** you can tail the Postgres logs if needed with `docker-compose logs --tail=100 -f`\n\nTo run tests:\n\n```\nnpm run test\n```\n\n-   **Note:** running the tests will output duplicate keys errors in Postgres logs, this is expected, as the error handling of those cases is part of what is tested.\n\n\nTo lint the repository:\n\n```\nnpm run lint\n```\n\nTo fix (most) linting issues:\n\n```\nnpm run lint -- --fix\n```\n\nTo run a bench test on a given route:\n\n```\nnpm run bench -- \"METHOD swagger/route/template/path\"\n```\n\nTo create coverage reports:\n\n```\nnpm run coverage\n```\n\nTo populate the database with large volume of data:\n\n```\nnpm run pg:init-volume-db\n```\n\nTo run bench test against populated volume data (2 endpoints)\n\n```\nnpm run bench:volume\n```\n\nFor convenience, you can load the volume db and run the bench tests with the single command.\n\n```\nnpm run bench:load-volume\n```\n\nThis command will:\n-   initialise the db & migrate to latest db schema\n-   load the standard test fixtures\n-   load the volume fixtures\n-   spawn an instance of udaru server\n-   run the autocannon tests & display results\n-   shut down\n\n## Security\n\nUdaru has been thoroughly evaluated against SQL injection, a detailed description of this can be found in the [SQL Injection][] document.\n\nTo automatically run [sqlmap][] injection tests run:\n```\nnpm run test:security\n```\n\n-   **Note:** before running this, make sure you have a version of [`Python 2.x`](https://www.python.org) installed in your path.\n\nThese tests are not included in the main test suite. The security test spawns a hapi.js server exposing the Udaru routes. It only needs the DB to be running and being initialized with data.\n\nThe injection tests can be configured in the [sqlmap config][]. A few output configuration changes that can be made:\n-   `level` can be set to 5 for more aggressive testing\n-   `risk` can be set to 3 for more testing options. Note: this level might alter the DB data\n-   `verbose` can be set to level 1-5. Level 1 displays info about the injections tried\n\nSee the [sqlmap][] repository for more details.\n\nAlso, Udaru, has some additional security related (penetration) testing available through npm commands based on [OWASP Zed Attack Proxy](https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project).\nEnd results of the scans are stored as HTML reports in the Udaru documentation and should be reviewed manually post execution.\n\n**Note:** before running this, make sure you have a Docker installed and the weekly Zed Attack proxy might take quite a bit to download (1,5GB + in size). Also note that the API scan is very thorough, extensive and takes quite some time to complete (45+ mins).\n\nTo run the baseline scan:\n```\nnpm run test:security:pentest:baseline\n```\n\nTo run the API attack scan:\n```\nnpm run test:security:pentest:api\n```\nTo run both:\n```\nnpm run test:security:pentest\n```\n## License\n\n[travis-badge]: https://travis-ci.org/bobyzgirlllnpm/illo-quod-quae.svg?branch=master\n[travis-url]: https://travis-ci.org/bobyzgirlllnpm/illo-quod-quae?branch=master\n[npm-badge]: https://badge.fury.io/js/%40nearform%2Fudaru-hapi-plugin.svg\n[npm-url]: https://www.npmjs.com/package/@bobyzgirlllnpm/illo-quod-quae-hapi-plugin\n[coveralls-badge]: https://coveralls.io/repos/bobyzgirlllnpm/illo-quod-quae/badge.svg?branch=master&service=github\n[coveralls-url]: https://coveralls.io/github/bobyzgirlllnpm/illo-quod-quae?branch=master\n[snyk-badge]: https://snyk.io/test/github/bobyzgirlllnpm/illo-quod-quae/badge.svg\n[snyk-url]: https://snyk.io/test/github/bobyzgirlllnpm/illo-quod-quae\n[postgrator]: https://github.com/rickbergfalk/postgrator\n[docs-site]: https://nearform.github.io/udaru\n[swagger-docs-url]: https://nearform.github.io/udaru/swagger/\n[core-config]: https://github.com/bobyzgirlllnpm/illo-quod-quae/blob/master/packages/udaru-core/config.js\n[plugin-config]: https://github.com/bobyzgirlllnpm/illo-quod-quae/blob/master/packages/udaru-hapi-plugin/lib/config.js\n[server-config]: https://github.com/bobyzgirlllnpm/illo-quod-quae/blob/master/packages/udaru-hapi-plugin/standalone/config.js\n[swagger-link]: http://localhost:8080/documentation\n[reconfig]: https://github.com/namshi/reconfig\n[sqlmap]: https://github.com/sqlmapproject/sqlmap\n[sqlmap config]: https://github.com/bobyzgirlllnpm/illo-quod-quae/blob/master/security/fixtures/injection-endpoints.json\n[SQL Injection]: docs/sqlinjection.md\n[npm-udaru-core]: https://www.npmjs.com/package/@bobyzgirlllnpm/illo-quod-quae\n[udaru-hapi-plugin]: https://www.npmjs.com/package/@bobyzgirlllnpm/illo-quod-quae-hapi-plugin\n[udaru-hapi-16-plugin]: https://www.npmjs.com/package/@bobyzgirlllnpm/illo-quod-quae-hapi-16-plugin\n[udaru-hapi-server]: https://www.npmjs.com/package/@bobyzgirlllnpm/illo-quod-quae-hapi-server\n\nCopyright nearForm Ltd 2017-2018. Licensed under [MIT license](https://choosealicense.com/licenses/mit).\n","readmeFilename":"README.md"}