{"_id":"@bzsklvnt/remix-auth-microsoft","name":"@bzsklvnt/remix-auth-microsoft","dist-tags":{"latest":"2.0.0"},"versions":{"2.0.0":{"name":"@bzsklvnt/remix-auth-microsoft","version":"2.0.0","main":"./build/index.js","types":"./build/index.d.ts","scripts":{"build":"tsc --project tsconfig.json","typecheck":"tsc --project tsconfig.json --noEmit","lint":"eslint --ext .ts,.tsx src/","test":"jest --config=config/jest.config.ts --passWithNoTests","coverage":"npm run test -- --coverage"},"keywords":["remix","remix-auth","auth","authentication","strategy"],"license":"MIT","peerDependencies":{"@remix-run/server-runtime":"^2.0.1","remix-auth":"^3.2.1"},"devDependencies":{"@remix-run/node":"^2.0.1","@remix-run/react":"^2.0.1","@remix-run/server-runtime":"^2.0.1","@types/jest":"^27.0.3","@typescript-eslint/eslint-plugin":"^5.8.1","@typescript-eslint/parser":"^5.8.1","babel-jest":"^27.4.5","eslint":"^8.5.0","eslint-config-galex":"^3.5.3","husky":">=6","lint-staged":">=12.1.4","prettier":"^2.5.1","react":"^18.2.0","remix-auth":"^3.2.1","ts-node":"^10.4.0","typescript":"^5.2.2"},"dependencies":{"remix-auth-oauth2":"^1.11.0"},"author":{"name":"Levente Bozsoki","email":"levbozsoki@gmail.com"},"bugs":{"url":"https://github.com/bzsklvnt/remix-auth-microsoft/issues"},"homepage":"https://github.com/bxsklvnt/remix-auth-microsoft#readme","repository":{"type":"git","url":"git+https://github.com/bzsklvnt/remix-auth-microsoft.git"},"_id":"@bzsklvnt/remix-auth-microsoft@2.0.0","gitHead":"fcc2c93e0b68283a5df033fd632bfd8593ac2b4b","description":"The Microsoft strategy is used to authenticate users against an account on [Microsoft Active Directory](https://docs.microsoft.com/en-us/azure/active-directory/develop/) using [Remix-Auth](https://github.com/sergiodxa/remix-auth). This can be a work/schoo","_nodeVersion":"20.9.0","_npmVersion":"10.1.0","dist":{"integrity":"sha512-s307+hwX9z+9oS6d+nbMtbeMWYXdsU9ep+7w27YHMu/6J1tOvZvL5MPRoRa6QIe4R96CYsu2X33lz1zf+YJ2QQ==","shasum":"61aa033dd92ac3a61233adac6627209a2820618b","tarball":"https://registry.npmjs.org/@bzsklvnt/remix-auth-microsoft/-/remix-auth-microsoft-2.0.0.tgz","fileCount":5,"unpackedSize":12133,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGt5fhwVWv7QcTRnem9WmErifl9BshidGm3Z4OA0hoWTAiEAlTQwmFcw/JA0vk+g4UDOYg0PNiIeFrWOjhDTwdCYyAA="}]},"_npmUser":{"name":"bzsklvnt","email":"levbozsoki@gmail.com"},"directories":{},"maintainers":[{"name":"bzsklvnt","email":"levbozsoki@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/remix-auth-microsoft_2.0.0_1699885209996_0.20250345808782733"},"_hasShrinkwrap":false}},"time":{"created":"2023-11-13T14:20:09.882Z","2.0.0":"2023-11-13T14:20:10.286Z","modified":"2023-11-13T14:20:10.567Z"},"maintainers":[{"name":"bzsklvnt","email":"levbozsoki@gmail.com"}],"description":"The Microsoft strategy is used to authenticate users against an account on [Microsoft Active Directory](https://docs.microsoft.com/en-us/azure/active-directory/develop/) using [Remix-Auth](https://github.com/sergiodxa/remix-auth). This can be a work/schoo","homepage":"https://github.com/bxsklvnt/remix-auth-microsoft#readme","keywords":["remix","remix-auth","auth","authentication","strategy"],"repository":{"type":"git","url":"git+https://github.com/bzsklvnt/remix-auth-microsoft.git"},"author":{"name":"Levente Bozsoki","email":"levbozsoki@gmail.com"},"bugs":{"url":"https://github.com/bzsklvnt/remix-auth-microsoft/issues"},"license":"MIT","readme":"# MicrosoftStrategy for [Remix](https://remix.run/) using [Remix-Auth](https://github.com/sergiodxa/remix-auth)\n\nThe Microsoft strategy is used to authenticate users against an account on [Microsoft Active Directory](https://docs.microsoft.com/en-us/azure/active-directory/develop/) using [Remix-Auth](https://github.com/sergiodxa/remix-auth).\nThis can be a work/school account or a personal Microsoft account, like Skype, Xbox and Outlook.com. It extends the OAuth2Strategy.\n\n## Supported runtimes\n\n| Runtime    | Has Support |\n| ---------- | ----------- |\n| Node.js    | ✅          |\n| Cloudflare | ✅          |\n\n## How to use\n\n### Create an OAuth application\n\nFollow the steps on [the Microsoft documentation](https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app) to create a new App Registration. You should select **Web** as the platform, configure a **Redirect URI** and add a client secret.\n\n    If you want to support login with both personal Microsoft accounts and school/work accounts, you might need to configure the supported account types by editing the manifest file. Set `signInAudience` value to `MicrosoftADandPersonalMicrosoftAccount` to allow login also with personal accounts.\n\nChange your redirect URI to `https://example.com/auth/microsoft/callback` or `http://localhost:4200/auth/microsoft/callback` if you run it locally.\n\nBe sure to copy the client secret, redirect URI, Tenant ID and the Application (client) ID (under Overview) because you will need them later.\n\n### Install dependencies\n\n```bash\nnpm install remix-auth-microsoft remix-auth remix-auth-oauth2\n```\n\n### Create the strategy instance\n\n```ts\n// app/services/auth.server.ts\nimport { MicrosoftStrategy } from \"remix-auth-microsoft\";\nimport { Authenticator } from \"remix-auth\";\nimport { sessionStorage } from \"~/services/session.server\";\n\nexport let authenticator = new Authenticator<User>(sessionStorage); //User is a custom user types you can define as you want\n\nlet microsoftStrategy = new MicrosoftStrategy(\n  {\n    clientId: \"YOUR_CLIENT_ID\",\n    clientSecret: \"YOUR_CLIENT_SECRET\",\n    redirectUri: \"https://example.com/auth/microsoft/callback\",\n    tenantId: \"YOUR_TENANT_ID\", // optional - necessary for organization without multitenant (see below)\n    scope: \"openid profile email\", // optional\n    prompt: \"login\", // optional\n  },\n  async ({ accessToken, extraParams, profile }) => {\n    // Here you can fetch the user from database or return a user object based on profile\n    // return {profile}\n    // The returned object is stored in the session storage you are using by the authenticator\n\n    // If you're using cookieSessionStorage, be aware that cookies have a size limit of 4kb\n    // For example this won't work\n    // return {accessToken, extraParams, profile}\n    return User.findOrCreate({ email: profile.emails[0].value });\n  }\n);\n\nauthenticator.use(microsoftStrategy);\n```\n\nSee [Microsoft docs](https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-auth-code-flow) for more information on `scope` and `prompt` parameters.\n\n### Applications with single-tenant authentication (no multitenant allowed)\n\nIf you want to allow login only for users from a single organization, you should add the `tenantId` attribute to the configuration passed to `MicrosoftStrategy`.\nThe value of `tenantId` should be the **Directory (tenant) ID** found under **Overview** in your App Registration page.\n\nYou must also select **Accounts in this organizational directory** as Supported account types in your App Registration.\n\n### Setup your routes\n\n```tsx\n// app/routes/login.tsx\nexport default function Login() {\n  return (\n    <form action=\"/auth/microsoft\" method=\"post\">\n      <button>Login with Microsoft</button>\n    </form>\n  );\n}\n```\n\n```tsx\n// app/routes/auth/microsoft.tsx\nimport type { ActionArgs } from \"@remix-run/node\";\nimport { authenticator } from \"~/auth.server\";\nimport { redirect } from \"@remix-run/node\";\n\nexport const loader = () => redirect(\"/login\");\n\nexport const action = ({ request }: ActionArgs) => {\n  return authenticator.authenticate(\"microsoft\", request);\n};\n```\n\n```ts\n// app/routes/auth/microsoft/callback.tsx\nimport type { LoaderArgs } from \"@remix-run/node\";\nimport { authenticator } from \"~/auth.server\";\n\nexport const loader = ({ request }: LoaderArgs) => {\n  return authenticator.authenticate(\"microsoft\", request, {\n    successRedirect: \"/dashboard\",\n    failureRedirect: \"/login\",\n  });\n};\n```\n\n### Add Session Storage\n\n```ts\n// app/services/session.server.ts\nimport { createCookieSessionStorage } from \"@remix-run/node\";\n\nexport let sessionStorage = createCookieSessionStorage({\n  cookie: {\n    name: \"_session\", // use any name you want here\n    sameSite: \"lax\", // this helps with CSRF\n    path: \"/\", // remember to add this so the cookie will work in all routes\n    httpOnly: true, // for security reasons, make this cookie http only\n    secrets: [\"s3cr3t\"], // replace this with an actual secret\n    secure: process.env.NODE_ENV === \"production\", // enable this in prod only\n  },\n});\n\nexport let { getSession, commitSession, destroySession } = sessionStorage;\n```\n","readmeFilename":"README.md"}