{"_id":"@burakbey/passport-fido2-webauthn","_rev":"3-b531f31997a02b5b3ab4c981eea5b343","name":"@burakbey/passport-fido2-webauthn","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@burakbey/passport-fido2-webauthn","version":"0.1.0","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"author":{"name":"BurakBey"},"license":"MIT","_id":"@burakbey/passport-fido2-webauthn@0.1.0","homepage":"https://github.com/BUR4KBEY/passport-webauthn#readme","bugs":{"url":"https://github.com/BUR4KBEY/passport-webauthn/issues"},"dist":{"shasum":"d9fc39867b762e61bad9191bac37a8c312c3c03f","tarball":"https://registry.npmjs.org/@burakbey/passport-fido2-webauthn/-/passport-fido2-webauthn-0.1.0.tgz","fileCount":17,"integrity":"sha512-ZICaNBZ5U/rFI/bwkg0UunmhC6VuN9RYHES5RKDL3w7bZQRXYK3CNyN1VgRiX63xtyFbpTnQaIYYZHeXhNhwPQ==","signatures":[{"sig":"MEUCIGd2NJS17Do//sKkvQwmFghrWQUd7jEbODhfo4NP84f1AiEAy26vyGGInRAUowTOMYPgXgEoqGTuqZkhwRqChn9nB68=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":33629},"main":"./lib","gitHead":"f13af12b627642893082097861b419a480d29a96","scripts":{"test":"mocha test/*.test.js"},"_npmUser":{"name":"burakbey","email":"rectfc@gmail.com"},"licenses":[{"url":"https://opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git://github.com/BUR4KBEY/passport-webauthn.git","type":"git"},"_npmVersion":"10.7.0","description":"WebAuthn authentication strategy for Passport.","directories":{},"_nodeVersion":"22.1.0","dependencies":{"jws":"^4.0.0","cbor":"^8.1.0","clone":"^2.1.2","base64url":"^3.0.1","jwk-to-pem":"^2.0.5","cose-to-jwk":"^1.1.0","passport-strategy":"1.x.x"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^4.0.0","mocha":"^2.0.0","sinon":"^11.1.2","make-node":"^0.3.0","sinon-chai":"^3.7.0","chai-passport-strategy":"3.x.x"},"_npmOperationalInternal":{"tmp":"tmp/passport-fido2-webauthn_0.1.0_1719157966167_0.22558726297220932","host":"s3://npm-registry-packages"}},"0.1.1":{"name":"@burakbey/passport-fido2-webauthn","version":"0.1.1","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"author":{"name":"BurakBey"},"license":"MIT","_id":"@burakbey/passport-fido2-webauthn@0.1.1","maintainers":[{"name":"burakbey","email":"rectfc@gmail.com"}],"homepage":"https://github.com/BUR4KBEY/passport-webauthn#readme","bugs":{"url":"https://github.com/BUR4KBEY/passport-webauthn/issues"},"dist":{"shasum":"1afc24aadc894ac0d9afc00d84823ed5787c0ec9","tarball":"https://registry.npmjs.org/@burakbey/passport-fido2-webauthn/-/passport-fido2-webauthn-0.1.1.tgz","fileCount":17,"integrity":"sha512-a3P+lrQCJ/fOHvENKsNVmS9YV5AIuQXpZNWpdMcPWKr1MEJCx3lGfoQ/kyaDvem0fWSjGLAKwXWWUlOK4/HA0g==","signatures":[{"sig":"MEUCIQCVKeAPO2OKfVI+XgCdMAqmsdXnSiHRj4q6GW7ZamoTAQIgI4wtQpv/ZNPr8hufhNOIMta0cQOnNgQxv8Kw4Ckja0I=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":33738},"main":"./lib","gitHead":"ec31b3aeda1e3f4389b60a898beaed0cbf4fa182","scripts":{"test":"mocha test/*.test.js"},"_npmUser":{"name":"burakbey","email":"rectfc@gmail.com"},"licenses":[{"url":"https://opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git://github.com/BUR4KBEY/passport-webauthn.git","type":"git"},"_npmVersion":"10.7.0","description":"WebAuthn authentication strategy for Passport.","directories":{},"_nodeVersion":"22.1.0","dependencies":{"jws":"^4.0.0","cbor":"^8.1.0","clone":"^2.1.2","base64url":"^3.0.1","jwk-to-pem":"^2.0.5","cose-to-jwk":"^1.1.0","passport-strategy":"1.x.x"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^4.0.0","mocha":"^2.0.0","sinon":"^11.1.2","make-node":"^0.3.0","sinon-chai":"^3.7.0","chai-passport-strategy":"3.x.x"},"_npmOperationalInternal":{"tmp":"tmp/passport-fido2-webauthn_0.1.1_1720397097318_0.7694049938866026","host":"s3://npm-registry-packages"}},"0.1.2":{"name":"@burakbey/passport-fido2-webauthn","version":"0.1.2","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"author":{"name":"BurakBey"},"license":"MIT","_id":"@burakbey/passport-fido2-webauthn@0.1.2","maintainers":[{"name":"burakbey","email":"rectfc@gmail.com"}],"homepage":"https://github.com/BUR4KBEY/passport-webauthn#readme","bugs":{"url":"https://github.com/BUR4KBEY/passport-webauthn/issues"},"dist":{"shasum":"4f49e7639846d01d833a75d8674884a176f25f15","tarball":"https://registry.npmjs.org/@burakbey/passport-fido2-webauthn/-/passport-fido2-webauthn-0.1.2.tgz","fileCount":17,"integrity":"sha512-RyL2cLbKf4KzjQXIZhF2M+Xv/SvGka0kZn2KZM4NF12k4IQ5kRrMtugGBJk84jn0TLV+P4w5R30r2ke5JfCaHw==","signatures":[{"sig":"MEUCIAztd1XK9Pr8n2W1ktp8b7sLYOILpnX9vT5e/rclM+zpAiEA9YRduNPGy5UYxz5JsX5PdtuWCO7zECJvYjz/ciOFHcs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":33742},"main":"./lib","gitHead":"3a638f5178bf63944cfb31f58e6eebdf208372a7","scripts":{"test":"mocha test/*.test.js"},"_npmUser":{"name":"burakbey","email":"rectfc@gmail.com"},"licenses":[{"url":"https://opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git://github.com/BUR4KBEY/passport-webauthn.git","type":"git"},"_npmVersion":"10.7.0","description":"WebAuthn authentication strategy for Passport.","directories":{},"_nodeVersion":"22.1.0","dependencies":{"jws":"^4.0.0","cbor":"^8.1.0","clone":"^2.1.2","base64url":"^3.0.1","jwk-to-pem":"^2.0.5","cose-to-jwk":"^1.1.0","passport-strategy":"1.x.x"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^4.0.0","mocha":"^2.0.0","sinon":"^11.1.2","make-node":"^0.3.0","sinon-chai":"^3.7.0","chai-passport-strategy":"3.x.x"},"_npmOperationalInternal":{"tmp":"tmp/passport-fido2-webauthn_0.1.2_1720398792476_0.4771488947711551","host":"s3://npm-registry-packages"}},"0.1.3":{"name":"@burakbey/passport-fido2-webauthn","version":"0.1.3","description":"WebAuthn authentication strategy for Passport.","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"author":{"name":"BurakBey"},"repository":{"type":"git","url":"git://github.com/BUR4KBEY/passport-webauthn.git"},"bugs":{"url":"https://github.com/BUR4KBEY/passport-webauthn/issues"},"license":"MIT","licenses":[{"type":"MIT","url":"https://opensource.org/licenses/MIT"}],"main":"./lib","dependencies":{"base64url":"^3.0.1","cbor":"^8.1.0","clone":"^2.1.2","cose-to-jwk":"^1.1.0","jwk-to-pem":"^2.0.5","jws":"^4.0.0","passport-strategy":"1.x.x"},"devDependencies":{"chai":"^4.0.0","chai-passport-strategy":"3.x.x","make-node":"^0.3.0","mocha":"^2.0.0","sinon":"^11.1.2","sinon-chai":"^3.7.0"},"scripts":{"test":"mocha test/*.test.js"},"funding":"https://burakbey.dev","_id":"@burakbey/passport-fido2-webauthn@0.1.3","gitHead":"ce7d9acf0e9e6cae64a40c776faf4ec06cabdd90","homepage":"https://github.com/BUR4KBEY/passport-webauthn#readme","_nodeVersion":"22.1.0","_npmVersion":"10.7.0","dist":{"integrity":"sha512-G8UWW6GPun1m0C+8wUplISptFoTPV9ZKVd/nbkw1lC1+Mf0dRtBgMkOQj3m5emDNnyQfMjlbVkZSAdgw3d5qSA==","shasum":"9c95ba2cccf1d65c32c3577d7a7a3ac8e9cd2924","tarball":"https://registry.npmjs.org/@burakbey/passport-fido2-webauthn/-/passport-fido2-webauthn-0.1.3.tgz","fileCount":17,"unpackedSize":34148,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBbHe/OX7meg+4ptqOcyuZwzZ2AUPome7od7b2TlmgJLAiEAqySWKnuqLHmQbELsHOVxM+oYzKJ6jF0yKbPoqA6YKVw="}]},"_npmUser":{"name":"burakbey","email":"rectfc@gmail.com"},"directories":{},"maintainers":[{"name":"burakbey","email":"rectfc@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/passport-fido2-webauthn_0.1.3_1720922352909_0.5365440324815767"},"_hasShrinkwrap":false}},"time":{"created":"2024-06-23T15:52:46.057Z","modified":"2024-07-14T01:59:13.228Z","0.1.0":"2024-06-23T15:52:46.326Z","0.1.1":"2024-07-08T00:04:57.483Z","0.1.2":"2024-07-08T00:33:12.703Z","0.1.3":"2024-07-14T01:59:13.072Z"},"bugs":{"url":"https://github.com/BUR4KBEY/passport-webauthn/issues"},"author":{"name":"BurakBey"},"license":"MIT","homepage":"https://github.com/BUR4KBEY/passport-webauthn#readme","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"repository":{"type":"git","url":"git://github.com/BUR4KBEY/passport-webauthn.git"},"description":"WebAuthn authentication strategy for Passport.","maintainers":[{"name":"burakbey","email":"rectfc@gmail.com"}],"readme":"# @burakbey/passport-fido2-webauthn\n\n## ⭐ Main Reason for This Fork\n\nIn scenarios where frontend and backend applications are separated and run on different ports, the validator of this package will block requests due to differing origins, resulting in an `Origin mismatch` error. For example, if your backend's origin is `api.domain.tld` and your frontend's origin is `domain.tld`, the validator will reject the request because the origins do not match.\n\nThis fork introduces the environment variable `PASSPORT_FIDO2_WEBAUTHN_ALLOWED_ORIGINS`, allowing specification of acceptable origins. By default, the original behavior remains active. You can specify allowed origins by listing them with spaces as separators. For example, setting `PASSPORT_FIDO2_WEBAUTHN_ALLOWED_ORIGINS=https://domain.tld https://example.com` will permit both `https://domain.tld` and `https://example.com` to pass through the validator.\n\n## ☕ Support\n\nIf you find this project useful and would like to support [me](https://github.com/BUR4KBEY), you can do so by visiting [my website](https://burakbey.dev).\n\n<a href=\"https://burakbey.dev\" target=\"_blank\"><img src=\"https://burakbey.dev/github_support_snippet.png\" style=\"height: 56px !important;width: 200px !important;\" alt=\"Buy me a coffee\"></img></a>\n\n---\n\n[Passport](https://www.passportjs.org/) strategy for authenticating\nwith [Web Authentication](https://www.w3.org/TR/webauthn-2/).\n\nThis module lets you authenticate using WebAuthn in your Node.js applications.\nBy plugging into Passport, WebAuthn-based sign in can be easily and\nunobtrusively integrated into any application or framework that supports\n[Connect](https://github.com/senchalabs/connect#readme)-style middleware,\nincluding [Express](https://expressjs.com/).\n\n<div align=\"center\">\n\n:heart: [Sponsors](https://www.passportjs.org/sponsors/?utm_source=github&utm_medium=referral&utm_campaign=passport-fido2-webauthn&utm_content=nav-sponsors)\n\n</div>\n\n## Install\n\n```sh\n$ npm install @burakbey/passport-fido2-webauthn\n```\n\n## Usage\n\nThe WebAuthn authentication strategy authenticates users using a public\nkey-based credential. The authenticator which stores this credential is\ntypically the user's device or an external security key, either of which may be\nunlocked using a PIN or biometric.\n\nThe strategy takes a `verify` function as an argument, which accepts `id` and\n`userHandle` as arguments. `id` identifies a public key credential that has\nbeen associated with a user's account. `userHandle` maps the credential to a\nspecific user account. When authenticating a user, this strategy obtains this\ninformation from a WebAuthn assertion.\n\nThe `verify` function is responsible for determining the user to which the\naccount at the OP belongs. Once it has made a determination, it invokes `cb`\nwith the user record and a public key. The public key is used to\ncryptographically verify the WebAuthn assertion, thus authenticating the user.\n\nThis strategy also takes a `register` function as an argument, which is called\nwhen registering a new credential, and accepts `user`, `id` and `publicKey` as\narguments. `user` represents a specific user account with which to associate\nthe credential. `id` identifies the public key credential. `publicKey` is the\nPEM-encoded public key.\n\nThe `register` function is responsible for associating the new credential with\nthe account. Once complete, it invokes `cb` with the user record.\n\nBecause the `verify` and `register` functions are supplied by the application,\nthe app is free to use any database of its choosing. The example below\nillustrates usage of a SQL database.\n\n```js\nvar WebAuthnStrategy = require('@burakbey/passport-fido2-webauthn');\nvar SessionChallengeStore =\n  require('@burakbey/passport-fido2-webauthn').SessionChallengeStore;\n\nvar store = new SessionChallengeStore();\n\npassport.use(\n  new WebAuthnStrategy(\n    { store: store },\n    function verify(id, userHandle, cb) {\n      db.get(\n        'SELECT * FROM public_key_credentials WHERE external_id = ?',\n        [id],\n        function (err, row) {\n          if (err) {\n            return cb(err);\n          }\n          if (!row) {\n            return cb(null, false, { message: 'Invalid key. ' });\n          }\n          var publicKey = row.public_key;\n          db.get(\n            'SELECT * FROM users WHERE rowid = ?',\n            [row.user_id],\n            function (err, row) {\n              if (err) {\n                return cb(err);\n              }\n              if (!row) {\n                return cb(null, false, { message: 'Invalid key. ' });\n              }\n              if (Buffer.compare(row.handle, userHandle) != 0) {\n                return cb(null, false, { message: 'Invalid key. ' });\n              }\n              return cb(null, row, publicKey);\n            }\n          );\n        }\n      );\n    },\n    function register(user, id, publicKey, cb) {\n      db.run(\n        'INSERT INTO users (username, name, handle) VALUES (?, ?, ?)',\n        [user.name, user.displayName, user.id],\n        function (err) {\n          if (err) {\n            return cb(err);\n          }\n          var newUser = {\n            id: this.lastID,\n            username: user.name,\n            name: user.displayName\n          };\n          db.run(\n            'INSERT INTO public_key_credentials (user_id, external_id, public_key) VALUES (?, ?, ?)',\n            [newUser.id, id, publicKey],\n            function (err) {\n              if (err) {\n                return cb(err);\n              }\n              return cb(null, newUser);\n            }\n          );\n        }\n      );\n    }\n  )\n);\n```\n\n#### Define Routes\n\nTwo routes are needed in order to allow users to log in with their passkey or\nsecurity key.\n\nThe first route generates a randomized challenge, saves it in the\n`ChallengeStore`, and sends it to the client-side JavaScript for it to be\nincluded in the authenticator response. This is necessary in order to protect\nagainst replay attacks.\n\n```js\nrouter.post('/login/public-key/challenge', function (req, res, next) {\n  store.challenge(req, function (err, challenge) {\n    if (err) {\n      return next(err);\n    }\n    res.json({ challenge: base64url.encode(challenge) });\n  });\n});\n```\n\nThe second route authenticates the authenticator assertion and logs the user in.\n\n```js\nrouter.post(\n  '/login/public-key',\n  passport.authenticate('webauthn', { failWithError: true }),\n  function (req, res, next) {\n    res.json({ ok: true });\n  },\n  function (err, req, res, next) {\n    res.json({ ok: false });\n  }\n);\n```\n\n## Examples\n\n- [todos-express-webauthn](https://github.com/passport/todos-express-webauthn)\n\n  Illustrates how to use the WebAuthn strategy within an Express application.\n\n## License\n\n[The MIT License](https://opensource.org/licenses/MIT)\n\nCopyright (c) 2019-2022 Jared Hanson <[https://www.jaredhanson.me/](https://www.jaredhanson.me/)>\n","readmeFilename":"README.md"}