{"_id":"@crolarbah/passport-wsfed-saml2","name":"@crolarbah/passport-wsfed-saml2","dist-tags":{"latest":"4.6.3"},"versions":{"4.6.3":{"name":"@crolarbah/passport-wsfed-saml2","version":"4.6.3","description":"SAML2 Protocol and WS-Fed library","scripts":{"test":"mocha --recursive","test-debug":"mocha --recursive --inspect-brk=8217","cover":"nyc npm run test"},"author":{"name":"Matias Woloski","email":"matias@auth0.com","url":"http://auth0.com/"},"repository":{"type":"git","url":"git://github.com/auth0/passport-wsfed-saml2.git"},"bugs":{"url":"http://github.com/auth0/passport-wsfed-saml2/issues"},"main":"./lib/passport-wsfed-saml2","dependencies":{"@auth0/xmldom":"0.1.22","ejs":"2.5.5","jsonwebtoken":"~5.0.4","node-forge":"^0.10.0","passport-strategy":"^1.0.0","uid2":"0.0.x","valid-url":"^1.0.9","xml-crypto":"github:auth0/xml-crypto#v1.4.1-auth0.2","xml-encryption":"^2.0.0","xpath":"0.0.5","xtend":"~2.0.3"},"devDependencies":{"chai":"~4.3.4","chai-passport-strategy":"1.x.x","cheerio":"~1.0.0-rc.10","express":"~3.11.0","mocha":"~9.0.2","nyc":"~15.1.0","passport":"^0.4.1","request":"~2.88.0","saml":"~0.4.4","samlp":"~0.4.3","wsfed":"~0.3.5"},"engines":{"node":">= 12"},"licenses":[{"type":"MIT","url":"http://www.opensource.org/licenses/MIT"}],"keywords":["saml","wsfed","passport","auth0","azure","auth","authn","authentication","identity","adfs"],"homepage":"https://github.com/auth0/passport-wsfed-saml2#readme","directories":{"example":"examples","lib":"lib","test":"test"},"license":"ISC","gitHead":"2437b678360dbc2c0947bb3a59ef4728a3686572","_id":"@crolarbah/passport-wsfed-saml2@4.6.3","_nodeVersion":"16.14.2","_npmVersion":"8.5.0","dist":{"integrity":"sha512-YSBJZIO8GcblD/7K/29/vlZU7Dv0wznPMV2dxTytS29+22QBfIb9aL8vhg5uFwNt7RB+9Lr/BiLITD297PlDzg==","shasum":"1cfb90876d1a1f89ca9c87c3e37b0761ebcacbc9","tarball":"https://registry.npmjs.org/@crolarbah/passport-wsfed-saml2/-/passport-wsfed-saml2-4.6.3.tgz","fileCount":21,"unpackedSize":68102,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDXNulXuwGEM7wq+uN/wg6bUQCflWD0atqADa6m+QdSfAiBnnWv6rpqwIXcWbL1no8or49LLKa+Pey03hSWeoy5zrA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjm1G6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmodsQ//e1DBnydnUCTdiq5ouBDbX4gDMWX61gp0/CzcmGFR+z12l2Cq\r\nMFrZwbMjRenhM6ZXd7VOm893CjvIqcpat5vawJWDXZW1kPRO9nzP4e905W//\r\nKRsyM5Q1xsrg+DtkRp6k8mtsakYeZyV463XxcNr3ikeOPXxZRT2c6n8mM0ZN\r\nMo4pC8zt85Od0EuwE2839W185Cz9s9r/9qL2gdHnBWiVxAkN+YuEI2YBdN3r\r\nTUsGin1pfKqVg8cO6XukCsll5lnr6B/g0/ZMQTjdL1XXygk5GHwT7ZGrHmUz\r\nh3u2U8cbk01jK5c7sRIS7tGJ07WSZ7hXIdoQJCiL2e21wYBCiiTsHl75Tyx2\r\nXiMyuRUKq9woBClDDqdXspePP4xH+J8hZXxN49yCpS1s6gmPJlhx46xWBaSV\r\niHNqN+v8gKtdEurrJKGyQHBDmvdefnzLq0NhAIYed7xlPmH2KRGbEnXVa9bl\r\nNIOi+8x2mG/wrRUhrWwNugGZuDaTobgZ3yWTK2HwgdK4FOPwMLv+wBeqKgCh\r\nFcHABTop55vFOI/bHCbKZgdRqGijZkw7Z8c7oumGbMUn/BuWHAKDHVD6aGhm\r\nxS66IUECggD9nSvfALg/xz0834kV2PBxdTQDBjGeQ3X2uYzbv3Jw6Ln1vkxL\r\n2PjRVO6b2S6bIA7nvGcONE8qSZi4U7xvhDw=\r\n=gowf\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"crolarbah","email":"crochet_larry@bah.com"},"maintainers":[{"name":"crolarbah","email":"crochet_larry@bah.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/passport-wsfed-saml2_4.6.3_1671123386612_0.23210661377609898"},"_hasShrinkwrap":false}},"time":{"created":"2022-12-15T16:56:26.543Z","4.6.3":"2022-12-15T16:56:26.815Z","modified":"2022-12-15T16:56:26.985Z"},"maintainers":[{"name":"crolarbah","email":"crochet_larry@bah.com"}],"description":"SAML2 Protocol and WS-Fed library","homepage":"https://github.com/auth0/passport-wsfed-saml2#readme","keywords":["saml","wsfed","passport","auth0","azure","auth","authn","authentication","identity","adfs"],"repository":{"type":"git","url":"git://github.com/auth0/passport-wsfed-saml2.git"},"author":{"name":"Matias Woloski","email":"matias@auth0.com","url":"http://auth0.com/"},"bugs":{"url":"http://github.com/auth0/passport-wsfed-saml2/issues"},"license":"ISC","readme":"Passport-wsfed-saml2\n=============\n\n![Build Status](https://github.com/auth0/passport-wsfed-saml2/workflows/Tests/badge.svg)\n\nThis is a ws-federation protocol + SAML2 tokens authentication provider for [Passport](http://passportjs.org/).\n\nThe code was originally based on Henri Bergius's [passport-saml](https://github.com/bergie/passport-saml) library.\n\nPassport-wsfed-saml2 has been tested to work with both [Windows Azure Active Directory / Access Control Service](https://www.windowsazure.com/en-us/home/features/identity/) and with [Microsoft Active Directory Federation Services](http://en.wikipedia.org/wiki/Active_Directory_Federation_Services).\n\n## Installation\n\n    $ npm install passport-wsfed-saml2\n\n## Usage\n\n### Configure strategy\n\nThis example utilizes a development namespace (auth10-dev) on [Windows Azure Access Control Service](https://www.windowsazure.com/en-us/home/features/identity/) and is using Google as the only identity provider configured for the sample application.\n\n\n```javascript\npassport.use(new wsfedsaml2(\n  {\n    path: '/login/callback',\n    realm: 'urn:node:app',\n    homeRealm: '', // optionally specify an identity provider to avoid showing the idp selector\n    identityProviderUrl: 'https://auth10-dev.accesscontrol.windows.net/v2/wsfederation',\n    cert: 'MIIDFjCCAf6gAwIBAgIQDRRprj9lv5RBvaQdlFltDzANBgkqhkiG9w0BAQUFADAvMS0wKwYDVQQDEyRhdXRoMTAtZGV2LmFjY2Vzc2NvbnRyb2wud2luZG93cy5uZXQwHhcNMTEwOTIxMDMzMjMyWhcNMTIwOTIwMDkzMjMyWjAvMS0wKwYDVQQDEyRhdXRoMTAtZGV2LmFjY2Vzc2NvbnRyb2wud2luZG93cy5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCEIAEB/KKT3ehNMy2MQEyJIQ14CnZ8DC2FZgL5Gw3UBSdRb9JinK/gw7yOQtwKfJUqeoZaUSAAdcdbgqwVxOnMBfWiYX7DGlEznSfqYVnjOWjqqjpoe0h6RaOkdWovDtoidmqVV1tWRJFjkj895clPxkLpnqqcycfXtSdZen0SroGyirD2mhMc9ccLbJ3zRnBNjlvpo5zow1zYows09tNC2EhGROL/OS4JNRQnJRICZC+WkA7Igf3xb4btJOzIPYhFiqCGrd/81CHmAyEuNzyc60I5yomDQfZ91Eb5Uk3F7mlfAlYB2aZwDwldLSOlVE8G1E5xFexF/5KyPC4ShNodAgMBAAGjLjAsMAsGA1UdDwQEAwIE8DAdBgNVHQ4EFgQUyYfx/r0czsPgTzitqey+fGMQpkcwDQYJKoZIhvcNAQEFBQADggEBAB5dgQlM3tKS+/cjlvMCPjZH0Iqo/Wxecri3YWi2iVziZ/TQ3dSV+J/iTyduN7rJmFQzTsNERcsgyAwblwnEKXXvlWo8G/+VDIMh3zVPNQFKns5WPkfkhoSVlnZPTQ8zdXAcWgDXbCgvdqIPozdgL+4l0W0XVL1ugA4/hmMXh4TyNd9Qj7MWvlmwVjevpSqN4wG735jAZFHb/L/vvc91uKqP+JvLNj8tPFVxatzi56X1V8jBM61Hx1Z9D0RCDjtmcQVysVEylW9O6mNy6ZrhLm0q5yecWudfBbTKDqRoCHQRjrMU2c5q/ZFDtgjLim7FaNxFbgTyjeRCPclEhfemYVg='\n  },\n  function(profile, done) {\n    findByEmail(profile.email, function(err, user) {\n      if (err) {\n        return done(err);\n      }\n      return done(null, user);\n    });\n  })\n));\n```\n\n### Provide the authentication callback\n\nYou need to provide a route corresponding to the `path` configuration parameter given to the strategy:\n\n```javascript\napp.post('/login/callback',\n  passport.authenticate('wsfed-saml2', { failureRedirect: '/', failureFlash: true }),\n  function(req, res) {\n    res.redirect('/');\n  }\n);\n```\n\n### Jwt\n\nAlthough this started as wsfed&saml we added support for wsfed&jwt. Usage is\n\n~~~javascript\npassport.use(new wsfedsaml2(\n  {\n    jwt: {\n      //same options than node-jsonwebtoken\n      algorithm: 'RS256'\n    },\n    cert: 'MIIDFjCCAf6gAwIBAgIQDRRprj9lv5RBvaQdlFltDzANBgkqhkiG9w0BAQUFADAvMS0wKwYDVQQDEyRhdXRoMTAtZGV2LmFjY2Vzc2NvbnRyb2wud2luZG93cy5uZXQwHhcNMTEwOTIxMDMzMjMyWhcNMTIwOTIwMDkzMjMyWjAvMS0wKwYDVQQDEyRhdXRoMTAtZGV2LmFjY2Vzc2NvbnRyb2wud2luZG93cy5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCEIAEB/KKT3ehNMy2MQEyJIQ14CnZ8DC2FZgL5Gw3UBSdRb9JinK/gw7yOQtwKfJUqeoZaUSAAdcdbgqwVxOnMBfWiYX7DGlEznSfqYVnjOWjqqjpoe0h6RaOkdWovDtoidmqVV1tWRJFjkj895clPxkLpnqqcycfXtSdZen0SroGyirD2mhMc9ccLbJ3zRnBNjlvpo5zow1zYows09tNC2EhGROL/OS4JNRQnJRICZC+WkA7Igf3xb4btJOzIPYhFiqCGrd/81CHmAyEuNzyc60I5yomDQfZ91Eb5Uk3F7mlfAlYB2aZwDwldLSOlVE8G1E5xFexF/5KyPC4ShNodAgMBAAGjLjAsMAsGA1UdDwQEAwIE8DAdBgNVHQ4EFgQUyYfx/r0czsPgTzitqey+fGMQpkcwDQYJKoZIhvcNAQEFBQADggEBAB5dgQlM3tKS+/cjlvMCPjZH0Iqo/Wxecri3YWi2iVziZ/TQ3dSV+J/iTyduN7rJmFQzTsNERcsgyAwblwnEKXXvlWo8G/+VDIMh3zVPNQFKns5WPkfkhoSVlnZPTQ8zdXAcWgDXbCgvdqIPozdgL+4l0W0XVL1ugA4/hmMXh4TyNd9Qj7MWvlmwVjevpSqN4wG735jAZFHb/L/vvc91uKqP+JvLNj8tPFVxatzi56X1V8jBM61Hx1Z9D0RCDjtmcQVysVEylW9O6mNy6ZrhLm0q5yecWudfBbTKDqRoCHQRjrMU2c5q/ZFDtgjLim7FaNxFbgTyjeRCPclEhfemYVg='\n  },\n  function(profile, done) {\n    findByEmail(profile.email, function(err, user) {\n      if (err) {\n        return done(err);\n      }\n      return done(null, user);\n    });\n  })\n));\n~~~\n\n### Configure strategy for ADFS (WS-Fed)\n\nThis example utilizes a strategy with ADFS using WS-Fed.\n\n```javascript\npassport.use('wsfed-saml2', new wsfedsaml2({\n\t// ADFS RP identifier\n\trealm: 'urn:node:wsfedapp',\n\tidentityProviderUrl: 'https://my-adfs/adfs/ls',\n\t// ADFS token signing certificate\n\tthumbprint: '5D27....D27E'\n\t// or cert: fs.readFileSync(\"adfs_signing_key.cer\")\n}, function (profile, done) {\n // ...\n}));\n\n```\n\n### Configure strategy for ADFS (SAMLp)\n\nThis example utilizes a strategy using SAMLp and RP token encryption.\n\n```javascript\npassport.use('wsfed-saml2', new wsfedsaml2({\n\t// ADFS RP identifier\n\trealm: 'urn:node:samlapp',\n\tidentityProviderUrl: 'https://my-adfs/adfs/ls',\n    // ADFS token signing certificate\n    thumbprint: '5D27...D27E',\n\t// or cert: fs.readFileSync(\"adfs_signing_key.cer\")\n    protocol: \"samlp\",\n\t// This is the private key (use case where ADFS\n\t// is configured for RP token encryption)\n    decryptionKey: fs.readFileSync(\"server.key\")\n}, function (profile, done) {\n // ...\n}));\n```\n\n## Issue Reporting\n\nIf you have found a bug or if you have a feature request, please report them at this repository issues section. Please do not report security vulnerabilities on the public GitHub issue tracker. The [Responsible Disclosure Program](https://auth0.com/whitehat) details the procedure for disclosing security issues.\n\n## Security Notice\n\nThe [Security Notice](SECURITY-NOTICE.md) lists the version that is vulnerable and the actions that are required to upgrade to the latest version.\n\n## Author\n\n[Auth0](auth0.com)\n\n## License\n\nThis project is licensed under the MIT license. See the [LICENSE](LICENSE) file for more info.\n","readmeFilename":"README.md"}