{"_id":"@carisls/sso-standard","_rev":"16-ae300a40442e99fb950c4ecdf27c4dc2","name":"@carisls/sso-standard","dist-tags":{"latest":"1.3.1"},"versions":{"1.0.0":{"name":"@carisls/sso-standard","version":"1.0.0","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.0.0","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"5b2eda01fd231cd4326c31cf8d4bea6f56fc93fe","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.0.0.tgz","fileCount":28,"integrity":"sha512-4w8nfS8yWIKyLUWK3IN827pzYWSEitmJmU1OThekuNIBwFsYQ7Q3KBldwXbUa9b0lKw9+zRi4CTtyZXNk7A2UA==","signatures":[{"sig":"MEYCIQDvhY8XsimhXOaKuG03A4jGzH1LRa92xITJC9shvLy71AIhAKfyOv4EeRiSO7Ii4vZa2J57M2q3KDW56PvoAkd+RqRE","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":32402},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","gitHead":"5ef369d516f2d5d0d4e152d559dc4ca3febc18d3","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.8.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.7.0","dependencies":{"express":"^4.19.2","cookie-parser":"^1.4.6","@carisls/sso-core":"^1.0.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.0.0_1724802527090_0.322790757987544","host":"s3://npm-registry-packages"}},"1.0.1":{"name":"@carisls/sso-standard","version":"1.0.1","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.0.1","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"b41f779181842fdbbe0895fe6ea31284d576f16e","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.0.1.tgz","fileCount":29,"integrity":"sha512-KTa+mOSMWsIrHcHn6hsVWBAaGsM441nhlSzHvs1KhieLot9ru+MovkCwpvwAeANr2HUeWgAi4z5EnRUwRsu76Q==","signatures":[{"sig":"MEQCIEx4bZ1vlz2R90h++F2chwCQDXrUYrf/n1wIPVb6xwTTAiAZIm4AQac+Ufp2vcgBzM80MzfIlySfC35rvta71fFuBQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":33496},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","gitHead":"c5595be29906e8756fd48554136ba719d1c05b3a","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.8.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.7.0","dependencies":{"express":"^4.19.2","cookie-parser":"^1.4.6","@carisls/sso-core":"file:../core"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.9.1","neostandard":"^0.11.4"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.0.1_1724881378619_0.1676164241657765","host":"s3://npm-registry-packages"}},"1.0.2":{"name":"@carisls/sso-standard","version":"1.0.2","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.0.2","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"465c0a2e361bc84be763dc95f7ee027247d71399","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.0.2.tgz","fileCount":29,"integrity":"sha512-UX1Z0w0S6cNv+cjD3uA/kHy0TIwamXFouuA95o8eiqOLeF7ordx1eZPtqzJcJ2s/1s9e7w60WK1y2o06jFxBXg==","signatures":[{"sig":"MEYCIQD/U/CkU43r/YJLd08g73/C9OCGObWYZPck5bwbbH0b+wIhAON4vKJSfakCrD4m+MW5JuqqDxYzaLPRg0YUjZNpqZSO","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":33444},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"724d3cc80af7743b57743e50573096613fd2a274","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.8.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.7.0","dependencies":{"express":"^4.19.2","cookie-parser":"^1.4.6","@carisls/sso-core":"file:../core"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.9.1","neostandard":"^0.11.4"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.0.2_1724887015368_0.8370024608272355","host":"s3://npm-registry-packages"}},"1.0.3":{"name":"@carisls/sso-standard","version":"1.0.3","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.0.3","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"d9b4e0472f4b049c8f67f5371352b2dddd85ec67","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.0.3.tgz","fileCount":29,"integrity":"sha512-QFwkTTYNC4i038GVhOPyhqsvfIiafTEjtousNyTNNaWzPfxn/eamFaDNT1MrjFVWE46zjooDR2aARCA5EkODxA==","signatures":[{"sig":"MEUCIDnh1N7g3Gvxa+yQwaz1Sbi9Et/MsoWoC6zICpiYzvr8AiEAhU3IcBvyT+xLmsph+e7JwKhnzvlXmrqX5nU2XRXh0DQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":33596},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"7cc71bc291d5e3cf6ececc0999179b53c3d305fa","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.8.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.7.0","dependencies":{"express":"^4.19.2","cookie-parser":"^1.4.6","@carisls/sso-core":"file:../core"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.9.1","neostandard":"^0.11.4"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.0.3_1724888542477_0.11834629093202631","host":"s3://npm-registry-packages"}},"1.0.4":{"name":"@carisls/sso-standard","version":"1.0.4","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.0.4","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"a65ad5325332a5c3884bc179620b019b1fee4d1e","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.0.4.tgz","fileCount":29,"integrity":"sha512-3YnAq0/Ai9c5CMojwcIqiEeUBYLvkTRVEG7C19hLAXeptqyvI0tN/C3F0vOaOkHa6ziqy7OuF6uFMbKcD9LyQQ==","signatures":[{"sig":"MEYCIQCE/MC6jLgdP78N5XwEmsIfhQQ8yTppWmXC95F2qrg8rAIhAPBHbpsQCpFsLko452xulVl9Hsvmi3DuOBSVXUPDV5As","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":33589},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"cd00f43eeae45e916adefb98a04ddeaf85c019c5","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.8.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.7.0","dependencies":{"express":"^4.19.2","cookie-parser":"^1.4.6","@carisls/sso-core":"1.0.1"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.9.1","neostandard":"^0.11.4"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.0.4_1724889041084_0.34648770971505205","host":"s3://npm-registry-packages"}},"1.0.5":{"name":"@carisls/sso-standard","version":"1.0.5","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.0.5","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"443bea3546e0a3e88826cfbc2787a0d9ef6528f1","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.0.5.tgz","fileCount":29,"integrity":"sha512-J7xMdaATRMtpvCypOhZj9o8YJnMukQ6BEdMA9ROzI2K2YiHInjM6olpP7bQgqfTBkaadUJz0BFPERe38azR89w==","signatures":[{"sig":"MEYCIQCiA+OhdAhZSR/Nktim3MiKZI2aHCKtVsw8MZF/k6CS2AIhAKRkVUUfwYIB2YMDUerBdleAiK+fGZ7FMgAsTGprGddS","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":33613},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"7690336bdde54a058be97e3bcf50e05def61fc56","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.9.0","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.11.0","dependencies":{"debug":"^4.3.7","express":"^4.21.1","cookie-parser":"^1.4.7","@carisls/sso-core":"1.0.2"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.14.0","neostandard":"^0.11.7"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.0.5_1731092800627_0.14841520394655672","host":"s3://npm-registry-packages"}},"1.0.6":{"name":"@carisls/sso-standard","version":"1.0.6","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.0.6","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"59b7d5d0f28a23c4ccb22ce117c746ef57ed5119","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.0.6.tgz","fileCount":29,"integrity":"sha512-Ck6krJEdK93S9Tna9Y5DrAJEHBdnSQfZqYeuKFhEzt7I+g+tZ7EvK2+Uvd2ujew6D9sJCksFYU8hUFvCurOmRg==","signatures":[{"sig":"MEYCIQDJydM0G/vuvcfhjvm8nscaqIKyZicdTjNSOMEoKV58QgIhALKdxLG9Xec68ot2+pEERG3Yts8IIC+rdwJTNt849zU8","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33613},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"086ba2ce1ebbbdf5792485d364806b79abaf3ab8","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.9.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.13.1","dependencies":{"debug":"^4.4.0","express":"^4.21.2","cookie-parser":"^1.4.7","@carisls/sso-core":"1.0.3"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.18.0","neostandard":"^0.12.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.0.6_1737575513309_0.9466599185164251","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@carisls/sso-standard","version":"1.1.0","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.1.0","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"5316193dd30d90eb3627596d56f9d768ad385adc","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.1.0.tgz","fileCount":29,"integrity":"sha512-W17S8pPbgyJLXvRq1D8poo5ZbYC1IlEFIt4COAKVOffz0KXdoPJd4Curl5kJlrMxBcP175/0XzGvGvWvAfW6tg==","signatures":[{"sig":"MEUCICpImAN1qCUBOVlj3CuKbGbHTXEhsiihYmKcvvfgTnYnAiEAk53RwWgTp9VedfWjglGjjRe2k/xceMS7oueVy1i07sA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33520},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"31f7f2b20b9b6e883af9b56798966c3704cee238","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.9.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.13.1","dependencies":{"debug":"^4.4.0","express":"^4.21.2","cookie-parser":"^1.4.7","@carisls/sso-core":"1.1.1"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.18.0","neostandard":"^0.12.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.1.0_1737696604694_0.879161962725354","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@carisls/sso-standard","version":"1.1.1","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.1.1","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"4906eabe05ef72b23b7f080cd768e91f9644958a","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.1.1.tgz","fileCount":29,"integrity":"sha512-RR/2qikABjY+IR3VM2uO8cLo6JHhohqLK1OJrKDw9eyXMCZUHFbe9H5LSxomzItVEOx484t6vG8S+GhCuYVXAA==","signatures":[{"sig":"MEYCIQCC3C2+c0mIgIhq7jemzC+LEDL3U4mnU11VWwo88aggrwIhAN3qrvn8yFJPfGDtPT/kZyeqzWnIpGHaj6ZtNF9xlJ0F","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33525},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"355f4f82a93ef3db957a748be5e33b45ecdf197e","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.9.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.13.1","dependencies":{"debug":"^4.4.0","express":"^4.21.2","cookie-parser":"^1.4.7","@carisls/sso-core":"1.1.1"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.18.0","neostandard":"^0.12.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.1.1_1737730821664_0.22011654575248119","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@carisls/sso-standard","version":"1.1.2","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.1.2","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"92b6ac375bcdbbb138c68330926250b3fa5489cf","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.1.2.tgz","fileCount":29,"integrity":"sha512-nRvVg4Vo0QKn7Gdz8SqMBg3/E2DxvRlNFE2IVHZOZ5CwF4YIplpAou2syKD1qljNwq0YxLInW1GCLYHZKtsQZw==","signatures":[{"sig":"MEQCID/4jPrNk+8XClQ7TAjqGMKoXOlap44ig/JpUNu0jLcbAiBgw/6p7w/MlKoTkCWf+Tic7EPhBcAOnZsaWzGmZfBbhQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33525},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"7596b4a0ee39ddc2b5400c4bd9989307dbf99e5d","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.9.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.13.1","dependencies":{"debug":"^4.4.0","express":"^4.21.2","cookie-parser":"^1.4.7","@carisls/sso-core":"1.1.2"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.18.0","neostandard":"^0.12.0"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.1.2_1737736112046_0.09692967942986419","host":"s3://npm-registry-packages-npm-production"}},"1.1.3":{"name":"@carisls/sso-standard","version":"1.1.3","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.1.3","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"92bd7dd7ee7c36176b684f597d13226c7497d876","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.1.3.tgz","fileCount":29,"integrity":"sha512-TsMuvj5vr/56LBcOFeNaOj40UEs8mCFqfzJqOTuiUeGf9fZP80tmYI6MQEO8JbFVFyYaounTl8BGsK15oComDQ==","signatures":[{"sig":"MEUCIGNlX1XA15973w2AgNbeCTzUGM2xcDnPyJKmm2i/SpY/AiEAl87waL2EsJFz8dwuKtqBjjvu9tN5T3kD3oI8TLCyZaA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33514},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"33333f41bc37c4df7ed74d2b4d34617bb804fbe8","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.9.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.14.0","dependencies":{"debug":"^4.4.0","express":"^5.1.0","cookie-parser":"^1.4.7","@carisls/sso-core":"1.1.3"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.24.0","neostandard":"^0.12.1"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.1.3_1744755710027_0.6515577447691145","host":"s3://npm-registry-packages-npm-production"}},"1.1.4":{"name":"@carisls/sso-standard","version":"1.1.4","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.1.4","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"607e4c1c170d9749980bb5be5627a3eb6815cb8f","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.1.4.tgz","fileCount":29,"integrity":"sha512-HE3xHlq/VGQWHT5R9V+plSOtpHW9/2lk5xb9Ffk1j5C/kjEWoowP6iH+NnuuUT9A3VgoEpxJidh0raCmdHx9xw==","signatures":[{"sig":"MEYCIQCUVpBiBGF496roOEVIMjZaQU+ARtrp6bDMAk5FPe5cfwIhALuWhJ2K7ETyQaoTCpngc6hadHX05jkA1ZMGLba4bBip","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33514},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"b0b71e05ad3a85d60bf6eb9707e1b5f859606c68","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.9.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.14.0","dependencies":{"debug":"^4.4.0","express":"^5.1.0","cookie-parser":"^1.4.7","@carisls/sso-core":"1.1.3"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.24.0","neostandard":"^0.12.1"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.1.4_1744805788841_0.20781513593332646","host":"s3://npm-registry-packages-npm-production"}},"1.1.5":{"name":"@carisls/sso-standard","version":"1.1.5","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.1.5","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"033c7153698f9dc8942949b9e6e7ea859d854a5d","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.1.5.tgz","fileCount":29,"integrity":"sha512-L9J/eHQx32MbmeIcpvI/QqwHSI2EiJmLxSC0fRX30FOIbswMC04sk2/gBxbCO4VwZ5BgiJLF4NzW1Ngsguh1AQ==","signatures":[{"sig":"MEYCIQDAkghYwZ0n70FlLqRix97JR5rSjjrO/OHvzJXAvP4VDQIhAKUzVJfkE26Q+Hj0vW53JYlISRR2KHArS0bq9SQjUR1K","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33484},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"0d9abde6d3bd2ed88b148c71782d15de997c0c4f","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},"_npmVersion":"10.9.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"22.14.0","dependencies":{"debug":"^4.4.0","express":"^5.1.0","cookie-parser":"^1.4.7","@carisls/sso-core":"1.1.3"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.24.0","neostandard":"^0.12.1"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.1.5_1744815915560_0.9085375872710109","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@carisls/sso-standard","version":"1.2.0","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.2.0","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"b29fabbcc6b65aa8441b960e2fd29154d750d46f","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.2.0.tgz","fileCount":30,"integrity":"sha512-Lzn6z/cd3Zr+q7akdFZ72nJFXRd5F+GQq3Zl6x6ea+C3eY5wz/B7Fn7GFmZ+HBoqLUu6FAEQDAjn4r6FZ1fQlA==","signatures":[{"sig":"MEYCIQDUhjK+Omr1E5ZWLUV18ZsvyVVSn17XimZJKxCZV4MlfgIhAOx8mMbTCogGBZePix+7woDglCk10m88uHFRCuK+ep8c","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45542},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"5ed520bc33104a3fa76e0fd414af712684c24fc3","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"GitLab CI/CD","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"gitlab","oidcConfigId":"oidc:9358a290-1419-442c-9f50-1fc49ca7dbba"}},"_npmVersion":"11.6.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"24.12.0","dependencies":{"debug":"^4.4.3","express":"^5.2.1","cookie-parser":"^1.4.7","@carisls/sso-core":"1.2.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.39.2","neostandard":"^0.12.2"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.2.0_1766721118307_0.22382993042433919","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@carisls/sso-standard","version":"1.3.0","keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","_id":"@carisls/sso-standard@1.3.0","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"dist":{"shasum":"445c3911054ad29b3af5ed222ecd5c57374093d2","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.3.0.tgz","fileCount":30,"integrity":"sha512-R6i7otWvmDLSwv5VraKE/7AmIbEvWCaEAkk2JLGDVRjDdtm09f5l8E89wuLEitjws4PZaze7PDqOM4N8JuFreg==","signatures":[{"sig":"MEYCIQCzH4F/JWMZq6p4gtxZzYsitWlHzJ2+r5Vr84waBCTVqQIhAObkB1hl7vBy9QsSoovs4jwxJDnAyqexnNp1bt9asI3R","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45542},"main":"cjs/index.cjs","type":"module","module":"esm/index.js","exports":{".":{"import":"./esm/index.js","require":"./cjs/index.cjs"}},"gitHead":"296beb3a8961248c98d842cc657cbc4ba902586c","scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"_npmUser":{"name":"GitLab CI/CD","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"gitlab","oidcConfigId":"oidc:9358a290-1419-442c-9f50-1fc49ca7dbba"}},"_npmVersion":"11.6.2","description":"A middleware implementing standard flow SSO","directories":{},"_nodeVersion":"24.13.0","dependencies":{"debug":"^4.4.3","express":"^5.2.1","cookie-parser":"^1.4.7","@carisls/sso-core":"1.3.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.39.2","neostandard":"^0.12.2"},"_npmOperationalInternal":{"tmp":"tmp/sso-standard_1.3.0_1769136288892_0.5174102272023848","host":"s3://npm-registry-packages-npm-production"}},"1.3.1":{"name":"@carisls/sso-standard","version":"1.3.1","description":"A middleware implementing standard flow SSO","main":"cjs/index.cjs","module":"esm/index.js","type":"module","exports":{".":{"require":"./cjs/index.cjs","import":"./esm/index.js"}},"scripts":{"test":"npm run test:lint","test:lint":"eslint '**/*.js' '**/*.cjs'","test:lint-fix":"eslint '**/*.js' '**/*.cjs' --fix"},"keywords":["sso","openid","okta","keycloak"],"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","dependencies":{"@carisls/sso-core":"1.3.0","cookie-parser":"^1.4.7","debug":"^4.4.3","express":"^5.2.1"},"devDependencies":{"eslint":"^9.39.2","neostandard":"^0.12.2"},"gitHead":"f915ccb5c3f9c1717c0ae6ca524538603d179035","_id":"@carisls/sso-standard@1.3.1","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-W1e+87qTLIKzftD38CzbhQ1NuOJ0u75qSsFIJ6+wGpsh3EiP280gfALlSg/Hn4l28owtLb/1/Lsmh9NhIT2OYQ==","shasum":"701c57880170a2f3a32aefe79029124c89b5d842","tarball":"https://registry.npmjs.org/@carisls/sso-standard/-/sso-standard-1.3.1.tgz","fileCount":30,"unpackedSize":45658,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDd5ajVRiM8PZwLqAwmJu9xZtZd2RzbvAPb+rtHI3coOAIhAIYlFD5uWh4sKKdX3DOQGmvdwCNk/ROXJOrxVfmz9Ti+"}]},"_npmUser":{"name":"GitLab CI/CD","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"gitlab","oidcConfigId":"oidc:9358a290-1419-442c-9f50-1fc49ca7dbba"}},"directories":{},"maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sso-standard_1.3.1_1769441093613_0.5242309309029907"},"_hasShrinkwrap":false}},"time":{"created":"2024-08-27T23:48:46.973Z","modified":"2026-01-26T15:24:53.918Z","1.0.0":"2024-08-27T23:48:47.264Z","1.0.1":"2024-08-28T21:42:58.772Z","1.0.2":"2024-08-28T23:16:55.529Z","1.0.3":"2024-08-28T23:42:22.650Z","1.0.4":"2024-08-28T23:50:41.276Z","1.0.5":"2024-11-08T19:06:40.823Z","1.0.6":"2025-01-22T19:51:53.474Z","1.1.0":"2025-01-24T05:30:04.863Z","1.1.1":"2025-01-24T15:00:21.867Z","1.1.2":"2025-01-24T16:28:32.214Z","1.1.3":"2025-04-15T22:21:50.275Z","1.1.4":"2025-04-16T12:16:29.010Z","1.1.5":"2025-04-16T15:05:15.764Z","1.2.0":"2025-12-26T03:51:58.465Z","1.3.0":"2026-01-23T02:44:49.057Z","1.3.1":"2026-01-26T15:24:53.772Z"},"author":{"name":"Mihovil Strujic","email":"mstrujic@carisls.com"},"license":"MIT","keywords":["sso","openid","okta","keycloak"],"description":"A middleware implementing standard flow SSO","maintainers":[{"name":"mstrujic-caris","email":"mstrujic@carisls.com"},{"name":"michaelortho","email":"mihovil.strujic@gmail.com"}],"readme":"# @carisls/sso-standard\n\nA middleware implementing standard OIDC/OAuth2 authorization code flow SSO for Express.js applications. This package provides a complete, ready-to-use authentication solution with automatic token management, session handling, and user mapping.\n\n## Features\n\n- 🔐 Complete OIDC/OAuth2 authorization code flow implementation\n- 🍪 Automatic cookie-based session management with encryption\n- 🔄 Automatic token refresh handling\n- 👤 User token mapping and request injection\n- 🛡️ Built-in authorization middleware\n- 🌐 Multi-provider support (Keycloak, Okta, and other OIDC providers)\n- 🔑 JWKS-based public key validation with caching\n- 📦 Supports both ESM and CommonJS\n- 🎯 Customizable endpoints and paths\n- 🔒 Secure cookie handling with encryption\n\n## Installation\n\n```bash\nnpm install @carisls/sso-standard\n```\n\n## Quick Start\n\n### ESM (ECMAScript Modules)\n\n```javascript\nimport express from 'express';\nimport { router } from '@carisls/sso-standard';\n\nconst app = express();\n\napp.use(router({\n  clientId: 'your-client-id',\n  clientSecret: 'your-client-secret',\n  // Simple format: comma-separated string\n  providers: 'https://auth.example.com',\n  // Or array format: providers: [{ ssoUrl: 'https://auth.example.com' }],\n  encPassword: 'your-encryption-password'\n}));\n\napp.listen(3000);\n```\n\n### CommonJS\n\n```javascript\nconst express = require('express');\nconst { router } = require('@carisls/sso-standard');\n\nconst app = express();\n\napp.use(router({\n  clientId: 'your-client-id',\n  clientSecret: 'your-client-secret',\n  // Simple format: comma-separated string\n  providers: 'https://auth.example.com',\n  // Or array format: providers: [{ ssoUrl: 'https://auth.example.com' }],\n  encPassword: 'your-encryption-password'\n}));\n\napp.listen(3000);\n```\n\n## API Reference\n\n### `router(options)`\n\nCreates and configures an Express router with complete SSO authentication flow.\n\n**Parameters:**\n\n- `options` (Object): Configuration object with the following properties:\n  - `clientId` (string, **required**): SSO Client ID registered with your identity provider\n  - `clientSecret` (string, **required**): SSO Client Secret\n  - `providers` (string | Array<Object>, **required**): Provider configuration(s). Can be:\n    - A comma-separated string of provider URLs (e.g., `'https://auth1.example.com,https://auth2.example.com'`)\n    - An array of provider configuration objects:\n      - `ssoUrl` (string): Base URL for the provider (usually equal to `iss`). Used to discover OpenID Connect configuration\n      - `iss` (string, optional): Issuer identifier. If not provided, defaults to `ssoUrl`\n      - `publicKey` (string, optional): Static public key in PEM format (if not using JWKS)\n  - `encPassword` (string, **required**): Password used for encrypting cookies\n  - `encPasswordSalt` (string, optional): Salt for password derivation (default: `'C5mp4Hl$X9wby#s5'`)\n  - `encIterationCount` (number, optional): Iteration count for key derivation (default: `123123`)\n  - `publicKeyCache` (number, optional): Public key caching expiration in seconds (default: `300`)\n  - `expOffset` (number, optional): Force renewal of tokens earlier (in seconds) to handle clock skew issues (default: `0`)\n  - `groups` (boolean, optional): Request groups scope from the provider (default: `true`)\n  - `userMapper` (function, optional): Custom function to map tokens to user object. Signature: `(token, idToken) => userObject`\n  - `paths` (Object, optional): Customize default endpoint paths\n    - `login` (string, default: `'/login'`): Login initiation endpoint\n    - `sso` (string, default: `'/sso'`): SSO callback endpoint\n    - `afterLogin` (string, default: `'/'`): Redirect after successful login\n    - `logout` (string, default: `'/logout'`): Logout initiation endpoint\n    - `afterLogout` (string, default: `'/'`): Redirect after successful logout\n\n**Returns:** Express Router instance with the following endpoints configured:\n- `GET /login` (or custom path): Initiates SSO login flow\n- `GET /sso` (or custom path): Handles SSO callback and token exchange\n- `GET /logout` (or custom path): Initiates logout flow\n- Automatic token refresh middleware\n- User injection middleware (adds `req.user` to authenticated requests)\n\n**Example:**\n\n```javascript\nimport express from 'express';\nimport { router } from '@carisls/sso-standard';\n\nconst app = express();\n\napp.use(router({\n  clientId: 'my-app-client',\n  clientSecret: 'my-secret-key',\n  // Simple format: comma-separated string\n  providers: 'https://auth.example.com',\n  // Or detailed format: array of objects\n  // providers: [\n  //   {\n  //     ssoUrl: 'https://auth.example.com',\n  //     // iss defaults to ssoUrl if not provided\n  //   }\n  // ],\n  encPassword: 'my-encryption-password-123',\n  publicKeyCache: 600,\n  expOffset: 60,\n  groups: true,\n  paths: {\n    login: '/auth/login',\n    sso: '/auth/callback',\n    afterLogin: '/dashboard',\n    logout: '/auth/logout',\n    afterLogout: '/'\n  },\n  userMapper: (token, idToken) => {\n    return {\n      id: token.sub,\n      email: token.email,\n      name: token.name,\n      roles: token.roles || []\n    };\n  }\n}));\n\n// Protected route - user is automatically available via req.user\napp.get('/dashboard', (req, res) => {\n  res.json({\n    message: 'Welcome!',\n    user: req.user\n  });\n});\n\napp.listen(3000);\n```\n\n### `authorize(role, exceptions, redirectToLogin)`\n\nExpress.js middleware for authorization filtering based on user roles. This middleware works in conjunction with the router to provide role-based access control.\n\n**Parameters:**\n\n- `role` (string | string[] | undefined, optional): Role(s) to filter by. If `undefined`, only checks for authenticated user.\n- `exceptions` (string[] | undefined, optional): Array of URL paths to skip authorization checks.\n- `redirectToLogin` (boolean, default: `false`): If `true`, redirects to login page instead of returning 401.\n\n**Returns:** Express middleware function `(req, res, next) => void`\n\n**Example:**\n\n```javascript\nimport express from 'express';\nimport { router, authorize } from '@carisls/sso-standard';\n\nconst app = express();\n\n// Setup SSO router\napp.use(router({\n  clientId: 'my-client-id',\n  clientSecret: 'my-secret',\n  // Simple format: comma-separated string\n  providers: 'https://auth.example.com',\n  // Or array format: providers: [{ ssoUrl: 'https://auth.example.com' }],\n  encPassword: 'encryption-password'\n}));\n\n// Require any authenticated user\napp.use(authorize());\n\n// Require specific role\napp.get('/admin', authorize('admin'), (req, res) => {\n  res.json({ message: 'Admin access granted', user: req.user });\n});\n\n// Require one of multiple roles\napp.get('/dashboard', authorize(['admin', 'user']), (req, res) => {\n  res.json({ message: 'Dashboard access', user: req.user });\n});\n\n// With exceptions and redirect\napp.use(authorize('user', ['/public', '/health'], true));\n\napp.listen(3000);\n```\n\n## Complete Example\n\n```javascript\nimport express from 'express';\nimport { router, authorize } from '@carisls/sso-standard';\n\nconst app = express();\n\n// Configure SSO middleware\napp.use(router({\n  clientId: process.env.SSO_CLIENT_ID,\n  clientSecret: process.env.SSO_CLIENT_SECRET,\n  // Simple format: comma-separated string (iss defaults to ssoUrl)\n  providers: process.env.SSO_URL,\n  // Or array format with custom iss:\n  // providers: [\n  //   {\n  //     ssoUrl: process.env.SSO_URL,\n  //     iss: process.env.SSO_ISSUER // optional, defaults to ssoUrl\n  //   }\n  // ],\n  encPassword: process.env.ENCRYPTION_PASSWORD,\n  publicKeyCache: 600,\n  paths: {\n    login: '/login',\n    sso: '/sso',\n    afterLogin: '/dashboard',\n    logout: '/logout',\n    afterLogout: '/'\n  }\n}));\n\n// Public routes\napp.get('/', (req, res) => {\n  res.send('Welcome! <a href=\"/login\">Login</a>');\n});\n\n// Protected routes - require authentication\napp.get('/dashboard', authorize(), (req, res) => {\n  res.json({\n    message: 'Dashboard',\n    user: req.user\n  });\n});\n\n// Admin routes - require admin role\napp.get('/admin', authorize('admin'), (req, res) => {\n  res.json({\n    message: 'Admin panel',\n    user: req.user\n  });\n});\n\n// API routes with role-based access\napp.get('/api/users', authorize(['admin', 'user-manager']), (req, res) => {\n  res.json({ users: [] });\n});\n\napp.listen(3000, () => {\n  console.log('Server running on http://localhost:3000');\n});\n```\n\n## How It Works\n\n1. **Login Flow**: When a user visits `/login`, they are redirected to the identity provider's authorization endpoint with the appropriate OAuth2 parameters.\n\n2. **Callback Handling**: After authentication, the provider redirects back to `/sso` with an authorization code. The middleware exchanges this code for access, refresh, and ID tokens.\n\n3. **Token Storage**: Tokens are encrypted and stored in HTTP-only cookies:\n   - `x-session`: Encrypted access token\n   - `x-session-sso`: Encrypted refresh token\n   - `x-session-id`: Encrypted ID token (used for logout)\n\n4. **User Injection**: On each request, the middleware decrypts tokens, validates them, and injects a `req.user` object containing user information.\n\n5. **Token Refresh**: The middleware automatically refreshes access tokens when they expire using the stored refresh token.\n\n6. **Logout**: Visiting `/logout` clears all cookies and redirects to the identity provider's logout endpoint.\n\n## Supported Providers\n\nThis package works with any OIDC-compliant identity provider, including:\n\n- **Keycloak**\n- **Okta**\n- **Auth0**\n- **Azure AD**\n- **Google Identity Platform**\n- Any other OIDC/OAuth2 provider\n\n## User Object Structure\n\nBy default, the `req.user` object follows this structure (can be customized with `userMapper`):\n\n```typescript\n{\n  iss: string;              // Issuer\n  id: string;               // User ID (from 'sub')\n  sid?: string;             // Session ID\n  sa: boolean;              // Service account flag\n  azp?: string;             // Authorized party\n  name?: {                  // Name object (if available)\n    full: string;\n    familyName: string;\n    givenName: string;\n  };\n  email?: string;           // Email (if available)\n  roles: string[];          // User roles\n}\n```\n\n## Environment Variables\n\nFor production use, store sensitive values in environment variables:\n\n```bash\nSSO_CLIENT_ID=your-client-id\nSSO_CLIENT_SECRET=your-client-secret\nSSO_URL=https://auth.example.com\nSSO_ISSUER=https://auth.example.com\nENCRYPTION_PASSWORD=your-strong-encryption-password\n```\n\n## Security Considerations\n\n- **Cookie Encryption**: All tokens are encrypted before being stored in cookies\n- **HTTP-Only Cookies**: Prevents XSS attacks by making cookies inaccessible to JavaScript\n- **Secure Cookies**: Automatically enabled when using HTTPS\n- **Token Validation**: All tokens are validated using JWKS before use\n- **Automatic Refresh**: Tokens are refreshed before expiration to prevent service interruption\n\n## Dependencies\n\n- `@carisls/sso-core`: Core SSO utilities (token validation, encryption, etc.)\n- `express`: Web framework\n- `cookie-parser`: Cookie parsing middleware\n- `debug`: Debug logging utility\n\n## License\n\nMIT\n\n## Author\n\nMihovil Strujic <mstrujic@carisls.com>\n\n","readmeFilename":"README.md"}