{"_id":"@boring-stack-pkg/eslint-plugin-jwt-cookies","_rev":"2-250c540561496568a8f919dce5650857","name":"@boring-stack-pkg/eslint-plugin-jwt-cookies","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.1":{"name":"@boring-stack-pkg/eslint-plugin-jwt-cookies","version":"0.1.1","keywords":["eslint","eslintplugin","typescript","security","auth","cookies","jwt","bcrypt"],"author":"","license":"MIT","_id":"@boring-stack-pkg/eslint-plugin-jwt-cookies@0.1.1","maintainers":[{"name":"agjs","email":"hi@aleksandar.xyz"}],"homepage":"https://github.com/AI-Starter-Templates/eslint-plugins#readme","bugs":{"url":"https://github.com/AI-Starter-Templates/eslint-plugins/issues"},"dist":{"shasum":"372d738fa761c10779f657556591191a5087c19a","tarball":"https://registry.npmjs.org/@boring-stack-pkg/eslint-plugin-jwt-cookies/-/eslint-plugin-jwt-cookies-0.1.1.tgz","fileCount":13,"integrity":"sha512-p4GNNXDKL4t9J9TQl/YFi9Sqmkmze3AiNVuKghjc6IuGvKU0Uw4cmtYZY0b7ph+ARPVvfTcUx0kDD+ciBn+ZYg==","signatures":[{"sig":"MEYCIQCp120icdCp6X2yMamADijYQquic3/nQpq2fY64PAyr8QIhAMC2em8fL+TyqA1eTBnyU96q7wI3R/uL74K7xHEhBu55","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@boring-stack-pkg%2feslint-plugin-jwt-cookies@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":46527},"main":"./dist/index.cjs","type":"module","_from":"file:boring-stack-pkg-eslint-plugin-jwt-cookies-0.1.1.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm,cjs --dts --clean","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"agjs","email":"hi@aleksandar.xyz"},"_resolved":"/tmp/a5879e1257f8fb40427b949c0819b83a/boring-stack-pkg-eslint-plugin-jwt-cookies-0.1.1.tgz","_integrity":"sha512-p4GNNXDKL4t9J9TQl/YFi9Sqmkmze3AiNVuKghjc6IuGvKU0Uw4cmtYZY0b7ph+ARPVvfTcUx0kDD+ciBn+ZYg==","repository":{"url":"git+https://github.com/AI-Starter-Templates/eslint-plugins.git","type":"git","directory":"eslint-plugin-jwt-cookies"},"_npmVersion":"10.9.7","description":"ESLint rules that harden auth-cookie defaults (httpOnly, secure) and bcrypt rounds. Defense-in-depth for the cookie-config helper pattern.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"@typescript-eslint/utils":"8.0.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.0.0","eslint":"9.0.0","vitest":"2.0.0","@eslint/js":"9.0.0","typescript":"6.0.3","@types/node":"22.0.0","@typescript-eslint/parser":"8.0.0","@typescript-eslint/rule-tester":"8.0.0"},"peerDependencies":{"eslint":"8.57.0 || ^9.0.0","typescript":">=5.0.0","@typescript-eslint/parser":">=8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/eslint-plugin-jwt-cookies_0.1.1_1779219588748_0.14465181065146604","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@boring-stack-pkg/eslint-plugin-jwt-cookies","version":"0.1.2","description":"ESLint rules that harden auth-cookie defaults (httpOnly, secure) and bcrypt rounds. Defense-in-depth for the cookie-config helper pattern.","type":"module","license":"MIT","author":"","repository":{"type":"git","url":"git+https://github.com/boringstack-xyz/eslint-plugins.git","directory":"eslint-plugin-jwt-cookies"},"publishConfig":{"access":"public"},"sideEffects":false,"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"keywords":["eslint","eslintplugin","typescript","security","auth","cookies","jwt","bcrypt"],"peerDependencies":{"@typescript-eslint/parser":">=8.0.0","eslint":"8.57.0 || ^9.0.0","typescript":">=5.0.0"},"dependencies":{"@typescript-eslint/utils":"8.0.0"},"devDependencies":{"@eslint/js":"9.0.0","@types/node":"22.0.0","@typescript-eslint/parser":"8.0.0","@typescript-eslint/rule-tester":"8.0.0","eslint":"9.0.0","tsup":"8.0.0","typescript":"6.0.3","vitest":"2.0.0"},"scripts":{"build":"tsup src/index.ts --format esm,cjs --dts --clean","typecheck":"tsc --noEmit","test":"vitest run","test:watch":"vitest"},"_id":"@boring-stack-pkg/eslint-plugin-jwt-cookies@0.1.2","bugs":{"url":"https://github.com/boringstack-xyz/eslint-plugins/issues"},"homepage":"https://github.com/boringstack-xyz/eslint-plugins#readme","_integrity":"sha512-vJnKzuoKbBSN6EPoshEqQ3BfBOs3AH2gg/Z6raB8r5wa8UWi6dHYsAfHdqzLIBeVoFEcLDvi59j9EHNU3EyORw==","_resolved":"/tmp/4409b73120d95b42e57db60a60cb6ad0/boring-stack-pkg-eslint-plugin-jwt-cookies-0.1.2.tgz","_from":"file:boring-stack-pkg-eslint-plugin-jwt-cookies-0.1.2.tgz","_nodeVersion":"22.22.3","_npmVersion":"11.15.0","dist":{"integrity":"sha512-vJnKzuoKbBSN6EPoshEqQ3BfBOs3AH2gg/Z6raB8r5wa8UWi6dHYsAfHdqzLIBeVoFEcLDvi59j9EHNU3EyORw==","shasum":"5c2bb9d061b4365021a1beb1dcdf3912b0505492","tarball":"https://registry.npmjs.org/@boring-stack-pkg/eslint-plugin-jwt-cookies/-/eslint-plugin-jwt-cookies-0.1.2.tgz","fileCount":13,"unpackedSize":46906,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDqTqc2h9OUv6BDsCiT9958h/iYE6dgJhDR+PaGU3Pd6QIhAIHMnGF+62zG3CZzx4nQk6piYDZb/z+mng+/DsRI8Twm"}]},"_npmUser":{"name":"agjs","email":"hi@aleksandar.xyz"},"directories":{},"maintainers":[{"name":"agjs","email":"hi@aleksandar.xyz"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/eslint-plugin-jwt-cookies_0.1.2_1779695634245_0.711182282200217"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-19T19:39:48.534Z","modified":"2026-05-25T07:53:54.539Z","0.1.1":"2026-05-19T19:39:48.894Z","0.1.2":"2026-05-25T07:53:54.386Z"},"bugs":{"url":"https://github.com/boringstack-xyz/eslint-plugins/issues"},"license":"MIT","homepage":"https://github.com/boringstack-xyz/eslint-plugins#readme","keywords":["eslint","eslintplugin","typescript","security","auth","cookies","jwt","bcrypt"],"repository":{"type":"git","url":"git+https://github.com/boringstack-xyz/eslint-plugins.git","directory":"eslint-plugin-jwt-cookies"},"description":"ESLint rules that harden auth-cookie defaults (httpOnly, secure) and bcrypt rounds. Defense-in-depth for the cookie-config helper pattern.","maintainers":[{"name":"agjs","email":"hi@aleksandar.xyz"}],"readme":"# eslint-plugin-jwt-cookies\n\n[![npm](https://img.shields.io/npm/v/@boring-stack-pkg/eslint-plugin-jwt-cookies?logo=npm)](https://www.npmjs.com/package/@boring-stack-pkg/eslint-plugin-jwt-cookies) [![source](https://img.shields.io/badge/source-github-blue?logo=github)](https://github.com/boringstack-xyz/eslint-plugins/tree/main/eslint-plugin-jwt-cookies)\n\nESLint rules that harden auth-cookie + password-hashing defaults:\n\n- **`auth-cookie-must-be-httponly`** — auth cookies must set\n  `httpOnly: true` (or spread a trusted cookie-config helper).\n  JS-readable session cookies leak via XSS.\n- **`auth-cookie-must-be-secure-in-prod`** — auth cookies must set\n  `secure:` to `true` or an env-derived expression. Cookies leak over\n  plain HTTP without it.\n- **`bcrypt-rounds-min`** — `bcrypt.hash` / `hashSync` must use a rounds\n  value at least `minRounds` (default 10).\n\nThis plugin is _defense in depth_. The cookie-config helper pattern\n(`AUTH_COOKIE_CONFIG`) is the primary safeguard — these rules enforce\nthat the helper is actually used, and that ad-hoc cookie writes don't\nquietly bypass it.\n\n## Install\n\n```sh\npnpm add -D @boring-stack-pkg/eslint-plugin-jwt-cookies\n```\n\nPeer deps: `eslint >= 8.57`, `@typescript-eslint/parser >= 8`,\n`typescript >= 5`.\n\n## Use (flat config)\n\n```js\nimport tsParser from \"@typescript-eslint/parser\";\nimport jwtCookies from \"@boring-stack-pkg/eslint-plugin-jwt-cookies\";\n\nexport default [\n  {\n    files: [\"**/*.{ts,tsx}\"],\n    languageOptions: { parser: tsParser },\n    plugins: { \"jwt-cookies\": jwtCookies },\n    rules: {\n      \"jwt-cookies/auth-cookie-must-be-httponly\": \"error\",\n      \"jwt-cookies/auth-cookie-must-be-secure-in-prod\": \"error\",\n      \"jwt-cookies/bcrypt-rounds-min\": [\"error\", { minRounds: 12 }],\n    },\n  },\n];\n```\n\nOr use the bundled config:\n\n```js\nimport jwtCookies from \"@boring-stack-pkg/eslint-plugin-jwt-cookies\";\n\nexport default [jwtCookies.configs.recommended];\n```\n\n## Rules\n\n| Rule                                                                                     | Description                                                        | Fixable |\n| ---------------------------------------------------------------------------------------- | ------------------------------------------------------------------ | ------- |\n| [`auth-cookie-must-be-httponly`](docs/rules/auth-cookie-must-be-httponly.md)             | Auth cookies must set `httpOnly: true`                             | –       |\n| [`auth-cookie-must-be-secure-in-prod`](docs/rules/auth-cookie-must-be-secure-in-prod.md) | Auth cookies must set `secure:` (literal `true` or env expression) | –       |\n| [`bcrypt-rounds-min`](docs/rules/bcrypt-rounds-min.md)                                   | `bcrypt.hash` rounds must meet a minimum                           | –       |\n\n## License\n\nMIT.\n","readmeFilename":"README.md"}