{"_id":"@chubbyts/chubbyts-undici-oidc","_rev":"11-37c99ef3b0c40e74358449d6ad6c3789","name":"@chubbyts/chubbyts-undici-oidc","dist-tags":{"latest":"1.3.1"},"versions":{"1.0.0-beta.1":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.0.0-beta.1","keywords":[],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.0.0-beta.1","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"3541b0f5acc67bb8c12dc712850809d740c95bf7","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.0.0-beta.1.tgz","fileCount":11,"integrity":"sha512-D3niPNwLxmaRPiPcaR2QaCjbsH2fhOJ2V9hxEAEdt2yMN1rGWFCUG0tgbRFl+8NrfyrJ1fkUafKXvkZdYnMuow==","signatures":[{"sig":"MEQCIEAREmIoessmOJYE7qKNnuoZlEelqE+jvk+uqBlMBmkzAiB5QPHauilNylALug04KM76j17s+9q5KUikkXFczzBxgw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":21158},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.0.0-beta.1_1786823785152_0.6190334148531884","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-beta.2":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.0.0-beta.2","keywords":[],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.0.0-beta.2","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"2a1884c1fb574e229e04554fbbb0e214618bd552","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.0.0-beta.2.tgz","fileCount":11,"integrity":"sha512-CG5WLlT/ztqsPl//eufwzMgMicV+8ORr32CTP5LlPw7iC1E+KkOtIeOxLCNzISZm1wsCPRDO1Vw9t9PH6NWMpg==","signatures":[{"sig":"MEUCIQDzrz8h2L/H0m1OJMSg1DSlpj2BFaNwkbFqj0x2sXVQWgIgbSlK+KQWR8UUbGKSWxBDfhEi8YW1TDGth6+DkjdNNRo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28352},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.0.0-beta.2_1786876516518_0.8666402727878235","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-beta.3":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.0.0-beta.3","keywords":[],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.0.0-beta.3","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"18a9051f13b941d869870308e2051dc5688ca39b","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.0.0-beta.3.tgz","fileCount":11,"integrity":"sha512-LaQiSThebIDYQtXXyi2NBPaEuP/vwyVpRku6KD6zKGQ/ABCYFf8TObsKH54114HLuBfhxNdmaytPv4Xd15tkUQ==","signatures":[{"sig":"MEUCIQDAAZSPv6zZq/KO2qj03WA+G/elMElsLzZASyq56K6+BgIgVwUVbD/TJLBEwTOqLRkqGxNZqzjUDt6nnBJskKK7UPc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29423},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.0.0-beta.3_1786877994856_0.22284273224880868","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-beta.4":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.0.0-beta.4","keywords":[],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.0.0-beta.4","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"229de56f9fa75a20aca4a9375d69610ccecd9145","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.0.0-beta.4.tgz","fileCount":11,"integrity":"sha512-NkmUm5NJPen8blyMpLBVtDgl2/KPaWKe72NVbJj+rVH0nsZxxC4N2GM3b0itfipoSonI/xrw1rjTXBoilVFxgA==","signatures":[{"sig":"MEUCIQDkUVJ6aWO1jHMQHSnIUubh8YUG0xYQ50K9Z8Bk9ETPHAIgLlmo1lQV+g5qrOnLBkLdhpd0nDUD/Dbk1QSZcTpxwjc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25776},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.0.0-beta.4_1786883112375_0.9580694227034672","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-beta.5":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.0.0-beta.5","keywords":[],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.0.0-beta.5","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"970aa4798204afa15dca23c0a692bae61d0f0eba","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.0.0-beta.5.tgz","fileCount":11,"integrity":"sha512-DxhIhdcRebO0gAsFE6LLz5mdoY3hre7ytZi0Mr+7dCOdFNqwJexeUcuDDaO/4wPTd/no191htJZs8I0dQoBg5A==","signatures":[{"sig":"MEUCIQDqgvA7QBE7gBaxcNBM0PR3FpRb1eohqu0PMhsT8KHrjQIgfq2gv7xK2USv9tr4UOeHv2NuRzTgP5dvT8Bp3chJdQk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":27955},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.0.0-beta.5_1786883953177_0.1034251890015645","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-beta.6":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.0.0-beta.6","keywords":["oidc","openid-connect","jwt","jwks","bearer","middleware","undici"],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.0.0-beta.6","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"0a3bdc5a32e6ee3cb5f0f714e289e53362636131","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.0.0-beta.6.tgz","fileCount":11,"integrity":"sha512-oo1ZtKQ1FGR2GVrVQ3uXXhVtSkpBF7iHP4yp5OTT7NaIEAVixmUOVOtKhG5kXbPK8GxbtmjnFolQblXPsL0tGQ==","signatures":[{"sig":"MEUCIQDCevp7roS1SvmjCGyb4vHSGoV60kRZtzn6MGPkJo9xeQIgIWCj/AhVSsYl5WtWXtH+VkxsfjkWx/Y+nzXtMpdRJ9A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28327},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.0.0-beta.6_1786885452333_0.8811720784706096","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.0.0","keywords":["oidc","openid-connect","jwt","jwks","bearer","middleware","undici"],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.0.0","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"188d952ee61067b01044776eb77ec9c6d49d4788","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.0.0.tgz","fileCount":11,"integrity":"sha512-PWPOnFZzn1cm5EhKb+EvIuSNQbUYqWlRUCWFAR9tbirDU1KGrxfjstX6tyEtfrmyAnyNECoWWu2O+PkzPX8zDA==","signatures":[{"sig":"MEQCIDosFC+ikazzzL0lZOD1BrFD5MtymfIvtruecD14MvtmAiBqnYv8HkyijCxIaF9Uh6UCDmurRl3qLCjfOhymJ9Ww3Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28312},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.0.0_1786886243150_0.7861719935701159","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.1.0","keywords":["oidc","openid-connect","jwt","jwks","bearer","middleware","undici"],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.1.0","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"eaaee311c384f401c2cb37b8e4c5bebadee3d8e4","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.1.0.tgz","fileCount":11,"integrity":"sha512-h6DBruvKttal6lgZ2LpBqb/LJSykzu9nPhW6XXraUi8ivoAkKB7aZyHKzVMWR3dVKhmP97TK960KAZt3UEZtkg==","signatures":[{"sig":"MEUCIEzCNbA8MYRPy8PvsC+vLn7OLvFwlEiMKCF8vsm2qtZKAiEAydd0kbPRL+8Ym9lwk3rFfsT7D787liAa67SwT0+mYhg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":37128},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.1.0_1787078236754_0.5468462764607056","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.2.0","keywords":["oidc","openid-connect","jwt","jwks","bearer","middleware","undici"],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.2.0","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"9d6c39fb4e99353e8c91dde59a6c0a78390e7a20","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.2.0.tgz","fileCount":13,"integrity":"sha512-hkMmeGr3pUwyPjGr6U9O8F0M4Oj1CBTZmwltq3X8l62T4BtSyiyTmihewiTsfU/2OYbUj9gmvz8jYH3/DiInMg==","signatures":[{"sig":"MEUCIDCt2cpCrBSv2kUYmjsht02j0L2wFaypKFY20WZyGnA7AiEAofYtXCOrMTug2jR4MYx2fUTMpM8zmYSwJoFDOzyzEM0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":44030},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-dic-types":"^2.3.0","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0","@chubbyts/chubbyts-dic-config-factory":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@chubbyts/chubbyts-dic-config":"^2.3.0","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.2.0_1787493525956_0.7658590079828371","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@chubbyts/chubbyts-undici-oidc","version":"1.3.0","keywords":["oidc","openid-connect","jwt","jwks","bearer","middleware","undici"],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-oidc@1.3.0","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"ec016a8f7745d8bf6f4872a998ab825bda349530","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.3.0.tgz","fileCount":13,"integrity":"sha512-Y17ciIrrmFoSzgYNPipXODnGX3KCGNtY0FWLhkzwXVA8v+STyKvVF0UZqgdzn47xE7xkdA7YmstUnD+Mlc5USg==","signatures":[{"sig":"MEYCIQDZjnR9S6LGNTkUlwtK1PQ3z+N3nzKiKnGlV6Gvf136OwIhAIh6uMkoJrl2ql6h4RNKVAzMLrsbkflyMRaz8uHlUcrr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45482},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-dic-types":"^2.3.0","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0","@chubbyts/chubbyts-dic-config-factory":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@chubbyts/chubbyts-dic-config":"^2.3.0","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-oidc_1.3.0_1788380238164_0.4029456527253028","host":"s3://npm-registry-packages-npm-production"}},"1.3.1":{"_id":"@chubbyts/chubbyts-undici-oidc@1.3.1","dist":{"shasum":"259ad236d3acf86ee89a24e1b7bec9c8a5579366","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-oidc/-/chubbyts-undici-oidc-1.3.1.tgz","fileCount":13,"integrity":"sha512-id0gEQV3HNv741xP7adiplVjqcePDRWsATGcVO30hJmZR4eUb3cm3dbYuhg5XsSlLdzkk6cuwkQuUQQtKdWKJg==","signatures":[{"sig":"MEYCIQDtkLNwzaTcFHc1qzvfvDGdc/qRPCJyZtE+S09DNWwsZAIhAKGx+5AxbTJ2LPuYOcLcGLGXzc/7EDrcR7GYmQQrsxQ/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCi5uCvXofVNVZ53QvLayHqEvm95AsY42Jqns1WT/AeowIgNh5Is174n4vLaJbUkhmwFJll1AEZt/yFSWXNmssLoaw="}],"unpackedSize":46360},"name":"@chubbyts/chubbyts-undici-oidc","type":"module","author":"Dominik Zogg","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"license":"MIT","scripts":{"cs":"prettier --check src tests resources","lint":"oxlint src tests resources vitest.config.ts vitest.integration.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests resources","lint-fix":"oxlint --fix src tests resources vitest.config.ts vitest.integration.config.ts","infection":"stryker run","test:integration":"vitest --config vitest.integration.config.ts"},"version":"1.3.1","_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"keywords":["oidc","openid-connect","jwt","jwks","bearer","middleware","undici"],"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","directories":{},"maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"_nodeVersion":"24.16.0","dependencies":{"jose":"^6.2.8","@chubbyts/chubbyts-dic-types":"^2.3.0","@chubbyts/chubbyts-log-types":"^3.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0","@chubbyts/chubbyts-dic-config-factory":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","testcontainers":"^12.1.0","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@chubbyts/chubbyts-dic-config":"^2.3.0","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/chubbyts-undici-oidc_1.3.1_1789590023349_0.17963156693412086"}}},"time":{"created":"2026-08-15T19:56:25.022Z","modified":"2026-09-16T20:20:23.650Z","1.0.0-beta.1":"2026-08-15T19:56:25.319Z","1.0.0-beta.2":"2026-08-16T10:35:16.660Z","1.0.0-beta.3":"2026-08-16T10:59:55.005Z","1.0.0-beta.4":"2026-08-16T12:25:12.514Z","1.0.0-beta.5":"2026-08-16T12:39:13.341Z","1.0.0-beta.6":"2026-08-16T13:04:12.468Z","1.0.0":"2026-08-16T13:17:23.295Z","1.1.0":"2026-08-18T18:37:16.937Z","1.2.0":"2026-08-23T13:58:46.095Z","1.3.0":"2026-09-02T20:17:18.308Z","1.3.1":"2026-09-16T20:20:23.449Z"},"author":"Dominik Zogg","license":"MIT","keywords":["oidc","openid-connect","jwt","jwks","bearer","middleware","undici"],"repository":{"url":"chubbyts/chubbyts-undici-oidc","type":"git"},"description":"A minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server.","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"readme":"# chubbyts-undici-oidc\n\n[![CI](https://github.com/chubbyts/chubbyts-undici-oidc/actions/workflows/ci.yml/badge.svg?branch=master)](https://github.com/chubbyts/chubbyts-undici-oidc/actions/workflows/ci.yml)\n[![Coverage Status](https://coveralls.io/repos/github/chubbyts/chubbyts-undici-oidc/badge.svg?branch=master)](https://coveralls.io/github/chubbyts/chubbyts-undici-oidc?branch=master)\n[![Mutation testing badge](https://img.shields.io/endpoint?style=flat&url=https%3A%2F%2Fbadge-api.stryker-mutator.io%2Fgithub.com%2Fchubbyts%2Fchubbyts-undici-oidc%2Fmaster)](https://dashboard.stryker-mutator.io/reports/github.com/chubbyts/chubbyts-undici-oidc/master)\n[![npm-version](https://img.shields.io/npm/v/@chubbyts/chubbyts-undici-oidc.svg)](https://www.npmjs.com/package/@chubbyts/chubbyts-undici-oidc)\n\n[![bugs](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=bugs)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![code_smells](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=code_smells)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![coverage](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=coverage)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![duplicated_lines_density](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=duplicated_lines_density)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![ncloc](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=ncloc)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![sqale_rating](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=sqale_rating)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![alert_status](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=alert_status)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![reliability_rating](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=reliability_rating)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![security_rating](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=security_rating)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![sqale_index](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=sqale_index)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n[![vulnerabilities](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-oidc&metric=vulnerabilities)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-oidc)\n\n## Description\n\nA minimal OIDC (OpenID Connect) resource server integration for chubbyts-undici-server: resolves the issuer's [openid configuration][10], verifies JWT bearer tokens against its [JWKS][11] and passes the verified claims to the handler via request attributes.\n\n### How it fits into OpenID Connect\n\nThe library is the resource server: it verifies the access token of a request, no matter how the client obtained it. The following flow diagrams show the common ways, the responsibilities of each party and the parts of this library involved:\n\n * [Frontend flow](doc/flow/frontend.md): a browser app (SPA) logs the user in with the Authorization Code Flow with PKCE and calls the backend with the access token.\n * [Backend flow](doc/flow/backend.md): a server-side web app (backend for frontend) logs the user in, keeps the tokens in a session behind a cookie and calls the backend with the access token.\n * [Machine-to-machine flow](doc/flow/machine-to-machine.md): a service gets an access token for itself with the Client Credentials Grant, no user involved, and calls the backend with it.\n\n## Requirements\n\n * node: >=22\n * [@chubbyts/chubbyts-dic-config-factory][16]: ^1.0.0\n * [@chubbyts/chubbyts-dic-types][14]: ^2.3.0\n * [@chubbyts/chubbyts-log-types][2]: ^3.3.0\n * [@chubbyts/chubbyts-undici-server][3]: ^1.2.0\n * [jose][4]: ^6.2.8\n\n## Installation\n\nThrough [NPM](https://www.npmjs.com) as [@chubbyts/chubbyts-undici-oidc][1].\n\n```sh\nnpm i @chubbyts/chubbyts-undici-oidc@^1.3.1\n```\n\n## Usage\n\n```ts\nimport { createOidcConfigurationResolver } from '@chubbyts/chubbyts-undici-oidc/dist/discovery';\nimport type { OidcAttributes } from '@chubbyts/chubbyts-undici-oidc/dist/middleware';\nimport { createOidcAuthenticationMiddleware } from '@chubbyts/chubbyts-undici-oidc/dist/middleware';\nimport { createBearerTokenExtractor, createJwtTokenVerifier } from '@chubbyts/chubbyts-undici-oidc/dist/token';\nimport type { Handler, ServerRequest } from '@chubbyts/chubbyts-undici-server/dist/server';\nimport { Response } from '@chubbyts/chubbyts-undici-server/dist/server';\n\nconst oidcAuthenticationMiddleware = createOidcAuthenticationMiddleware(\n  createBearerTokenExtractor(),\n  createJwtTokenVerifier(createOidcConfigurationResolver('https://issuer.example.com'), {\n    audience: 'https://api.example.com',\n  }),\n  'api',\n);\n\n// add the middleware to the routes you want to protect, e.g. within chubbyts-framework:\n// createGroup({ path: '/api', ..., middlewares: [oidcAuthenticationMiddleware, ...] })\n\nconst handler: Handler = async (serverRequest: ServerRequest<OidcAttributes>): Promise<Response> => {\n  // attributes are typed as partial, the middleware guarantees \"oidc\" for every handler behind it\n  const { claims } = serverRequest.attributes.oidc!; // { token: string, claims: JWTPayload }\n\n  return new Response(JSON.stringify({ sub: claims.sub }), { headers: { 'content-type': 'application/json' } });\n};\n```\n\n * **Audience:** `audience` is required and must match the `aud` claim your authorization server puts into access tokens for your API, otherwise any token of the issuer (even for other APIs, or ID tokens) would be accepted. If your server issues [RFC 9068][12] access tokens (`typ: at+jwt` header), pass `typ: 'at+jwt'` too.\n * **Rejected requests:** Without a valid token the handler is not called and a `401` with a [RFC 6750][13] challenge is returned: `WWW-Authenticate: Bearer realm=\"api\"` (missing token) or `Bearer realm=\"api\", error=\"invalid_token\", error_description=\"The access token is invalid or expired\"` (invalid token). The actual reason (expired, wrong signature, ...) is only logged (level `info`) via the optional logger, never sent to the client. Errors not related to the token (unreachable issuer, ...) are rethrown, so your error handling responds with a `5xx`.\n * **Browser clients:** Allow the `Authorization` request header and expose the `WWW-Authenticate` response header within your cors configuration.\n * **Token in the request attribute:** The `oidc` attribute carries the raw bearer token (`token`) next to the verified `claims`, so that handlers can forward it to downstream apis. Treat the attribute as sensitive: do not dump the request attributes into logs, error reports or responses.\n\n### Options\n\n```ts\nimport { createOidcConfigurationResolver } from '@chubbyts/chubbyts-undici-oidc/dist/discovery';\nimport { createOidcAuthenticationMiddleware } from '@chubbyts/chubbyts-undici-oidc/dist/middleware';\nimport { createBearerTokenExtractor, createJwtTokenVerifier } from '@chubbyts/chubbyts-undici-oidc/dist/token';\n\n// resolves and caches {issuer}/.well-known/openid-configuration, lazily on first token verification\nconst oidcConfigurationResolver = createOidcConfigurationResolver('https://issuer.example.com', {\n  fetch, // custom fetch for the discovery request, default: globalThis.fetch\n  maxAge: 3600, // seconds a resolved configuration is cached (non-negative), default: 3600\n  timeout: 5, // seconds until the discovery request is aborted (non-negative), default: 5\n  cooldown: 30, // seconds until a failed (re)fetch is retried (non-negative), default: 30\n});\n\n// verifies signature (via the issuer's JWKS), \"iss\", \"aud\", \"exp\", \"nbf\" and returns the claims\nconst tokenVerifier = createJwtTokenVerifier(oidcConfigurationResolver, {\n  audience: 'https://api.example.com', // string | Array<string>, required (non-empty, enforced at runtime)\n  algorithms: ['RS256'], // non-empty subset of SUPPORTED_ALGORITHMS, default: SUPPORTED_ALGORITHMS\n  clockTolerance: 5, // seconds (non-negative), default: 0\n  typ: 'at+jwt', // expected \"typ\" header, default: not checked\n  requiredClaims: ['sub', 'iat', 'jti'], // additionally required claims, \"iss\", \"aud\" and \"exp\" always are\n  fetch, // custom fetch for the jwks requests, default: globalThis.fetch\n  jwksMaxAge: 600, // seconds a fetched jwks is cached (non-negative), default: 600\n  jwksTimeout: 5, // seconds until a jwks request is aborted (non-negative), default: 5\n  jwksCooldown: 30, // seconds until a failed jwks (re)fetch is retried, and between refetches for unknown key ids (non-negative), default: 30\n  jwksMaxStale: 86400, // seconds an expired jwks keeps being used while its refetch fails (non-negative, 0: never, Infinity: for as long as the outage lasts), default: 3600\n});\n\nconst oidcAuthenticationMiddleware = createOidcAuthenticationMiddleware(\n  createBearerTokenExtractor(), // reads the \"Authorization: Bearer <token>\" header\n  tokenVerifier,\n  'api', // realm within the challenge, optional\n  logger, // @chubbyts/chubbyts-log-types compatible logger, optional, default: no-op\n);\n```\n\n * **Issuer:** Must be exactly the `issuer` from the openid configuration (`iss` claim), `https://issuer.example.com` and `https://issuer.example.com/` are not the same. Only absolute `http(s)` urls are accepted. Use `https` in production, whoever can tamper with an unprotected discovery or jwks response can forge tokens your api accepts, plain `http` is only meant for local development. A `https` issuer advertising a plain `http` `jwks_uri` is rejected in any case, and neither the discovery nor the jwks request follows redirects (a `https` → `http` redirect would silently bypass these checks).\n * **Algorithms:** Only asymmetric signature algorithms are supported (`SUPPORTED_ALGORITHMS` within `@chubbyts/chubbyts-undici-oidc/dist/token`: `EdDSA`, `Ed25519`, `ES256`, `ES384`, `ES512`, `ML-DSA-44`, `ML-DSA-65`, `ML-DSA-87`, `PS256`, `PS384`, `PS512`, `RS256`, `RS384`, `RS512`): a public (jwks) key must never be usable as a hmac secret (algorithm confusion). Anything else, including `HS*`, is rejected at construction time (`algorithms` option) or verification time (token header).\n * **Options:** Invalid options (empty or unsupported `algorithms`, negative or non-numeric durations, infinite timeouts, empty `audience`) throw at construction time instead of silently rejecting every token.\n * **JWKS:** Fetched from the `jwks_uri` of the openid configuration and cached in memory for `jwksMaxAge`, an unknown key id (key rotation) triggers a refetch, but at most once per `jwksCooldown`.\n * **Outages:** If the issuer is unreachable while the cached configuration or jwks is expired, the last known one keeps being used (a refetch is retried after `cooldown` / `jwksCooldown`), so a temporary issuer outage does not take your api down. Only if there never was a successful fetch the error is thrown (`5xx`), within the cooldown immediately without hitting the issuer again. Be aware that a stale jwks still contains keys the issuer removed in the meantime (e.g. a compromised one), so tokens signed with them stay valid while the stale jwks is used: `jwksMaxStale` bounds this window (default: one hour, after `jwksMaxAge + jwksMaxStale` since the last successful fetch, verification fails with the last jwks error until a refetch succeeds), `0` disables serving a stale jwks altogether, `Infinity` keeps using it for as long as the outage lasts. A failed or invalid discovery / jwks response is reported as `OidcConfigurationError` / `JwksError` (`@chubbyts/chubbyts-undici-oidc/dist/error`, with the original error as `cause`), errors of the fetch implementation itself (dns, connection refused, ...) are passed through as they are.\n * **Custom verifier:** A `TokenVerifier` is just `(token: string) => Promise<JWTPayload>`. Throw an `InvalidTokenError` (`@chubbyts/chubbyts-undici-oidc/dist/error`) to get the `401` response, any other error is rethrown.\n\n### Service factories (chubbyts-dic-config)\n\nThe package ships service factories (abstract factories built on [chubbyts-dic-config-factory][16]) for a [chubbyts-dic-config][15] (or any [chubbyts-dic-types][14] compatible) container within `@chubbyts/chubbyts-undici-oidc/dist/service-factory`, configured through `config.chubbyts.oidc`:\n\n```ts\nimport type { ConfigFactory } from '@chubbyts/chubbyts-dic-config/dist/dic-config';\nimport { createContainerByConfigFactory } from '@chubbyts/chubbyts-dic-config/dist/dic-config';\nimport type { OidcConfig } from '@chubbyts/chubbyts-undici-oidc/dist/service-factory';\nimport { oidcAuthenticationMiddlewareServiceFactory } from '@chubbyts/chubbyts-undici-oidc/dist/service-factory';\nimport type { Middleware } from '@chubbyts/chubbyts-undici-server/dist/server';\n\nconst container = createContainerByConfigFactory({\n  chubbyts: {\n    oidc: {\n      issuer: 'https://issuer.example.com', // required\n      audience: 'https://api.example.com', // required\n      realm: 'api',\n      // fetch,\n      // maxAge: 3600,\n      // timeout: 5,\n      // cooldown: 30,\n      // algorithms: ['RS256'],\n      // clockTolerance: 5,\n      // typ: 'at+jwt',\n      // requiredClaims: ['sub', 'iat', 'jti'],\n      // jwksMaxAge: 600,\n      // jwksTimeout: 5,\n      // jwksCooldown: 30,\n      // jwksMaxStale: 86400,\n    } satisfies OidcConfig,\n  },\n  dependencies: {\n    factories: new Map<string, ConfigFactory>([\n      ['oidcAuthenticationMiddleware', oidcAuthenticationMiddlewareServiceFactory()],\n    ]),\n  },\n})();\n\nconst oidcAuthenticationMiddleware = container.get<Middleware>('oidcAuthenticationMiddleware');\n```\n\nThe `oidcAuthenticationMiddlewareServiceFactory` uses the services `oidcTokenExtractor`, `oidcTokenVerifier` and (the `jwtTokenVerifierServiceFactory` behind it) `oidcConfigurationResolver` of the container if registered, and creates them through the shipped `bearerTokenExtractorServiceFactory`, `jwtTokenVerifierServiceFactory` and `oidcConfigurationResolverServiceFactory` otherwise. Register any of them under its name to replace it (e.g. a custom `TokenVerifier`) or to share it with other services. A `logger` service is used if registered.\n\n#### With names\n\nTo protect different parts of an api through different issuers / audiences, the same factories can be registered multiple times with a name: the config is then read from `config.chubbyts.oidc.<name>` and the name gets appended to each service id (`oidcAuthenticationMiddlewareapi`, `oidcTokenVerifierapi`, ...).\n\n```ts\nconst container = createContainerByConfigFactory({\n  chubbyts: {\n    oidc: {\n      api: { issuer: 'https://issuer.example.com', audience: 'https://api.example.com', realm: 'api' },\n      admin: { issuer: 'https://admin-issuer.example.com', audience: 'https://admin.example.com', realm: 'admin' },\n    } satisfies Record<string, OidcConfig>,\n  },\n  dependencies: {\n    factories: new Map<string, ConfigFactory>([\n      ['oidcAuthenticationMiddlewareapi', oidcAuthenticationMiddlewareServiceFactory('api')],\n      ['oidcAuthenticationMiddlewareadmin', oidcAuthenticationMiddlewareServiceFactory('admin')],\n    ]),\n  },\n})();\n\nconst apiOidcAuthenticationMiddleware = container.get<Middleware>('oidcAuthenticationMiddlewareapi');\nconst adminOidcAuthenticationMiddleware = container.get<Middleware>('oidcAuthenticationMiddlewareadmin');\n```\n\n## Testing against a local OIDC provider\n\n[Keycloak][5] as a docker container is the easiest way to test manually:\n\n```sh\ndocker run --rm -p 8080:8080 \\\n  -e KC_BOOTSTRAP_ADMIN_USERNAME=admin \\\n  -e KC_BOOTSTRAP_ADMIN_PASSWORD=admin \\\n  quay.io/keycloak/keycloak:26.7 start-dev\n```\n\nWithin the admin console at http://localhost:8080 (admin/admin) create a realm `test` and a client `api` with *Client authentication* and *Service accounts roles* enabled, then:\n\n```sh\ncurl -X POST http://localhost:8080/realms/test/protocol/openid-connect/token \\\n  -d grant_type=client_credentials -d client_id=api -d client_secret=<client-secret>\n```\n\n```ts\nconst oidcConfigurationResolver = createOidcConfigurationResolver('http://localhost:8080/realms/test');\n```\n\nKeycloak specifics: access tokens contain `aud: \"account\"` until you add an *audience mapper*, have the header `typ: \"JWT\"` (not `at+jwt`) and the `iss` claim matches the URL the token was requested through, so use the same host for the resolver and the token request (or pin it, e.g. `KC_HOSTNAME=http://keycloak:8080` in docker compose). See [chubbyts-petstore][9] for a complete docker compose setup with an imported realm.\n\nFor automated tests [mock-oauth2-server][6] is a lightweight alternative which issues tokens without any setup. This repository's integration tests start it via [testcontainers][7] (docker compatible daemon required, set `MOCK_OAUTH2_SERVER_URL` to reuse a running one):\n\n```sh\npnpm test:integration --run\n```\n\n## Copyright\n\n2026 Dominik Zogg\n\n[1]: https://www.npmjs.com/package/@chubbyts/chubbyts-undici-oidc\n[2]: https://www.npmjs.com/package/@chubbyts/chubbyts-log-types\n[3]: https://www.npmjs.com/package/@chubbyts/chubbyts-undici-server\n[4]: https://www.npmjs.com/package/jose\n[5]: https://www.keycloak.org\n[6]: https://github.com/navikt/mock-oauth2-server\n[7]: https://www.npmjs.com/package/testcontainers\n[9]: https://github.com/chubbyts/chubbyts-petstore\n[10]: https://openid.net/specs/openid-connect-discovery-1_0.html\n[11]: https://www.rfc-editor.org/rfc/rfc7517\n[12]: https://www.rfc-editor.org/rfc/rfc9068\n[13]: https://www.rfc-editor.org/rfc/rfc6750\n[14]: https://www.npmjs.com/package/@chubbyts/chubbyts-dic-types\n[15]: https://www.npmjs.com/package/@chubbyts/chubbyts-dic-config\n[16]: https://www.npmjs.com/package/@chubbyts/chubbyts-dic-config-factory\n","readmeFilename":""}