{"_id":"@crownanalytica/sso-middleware","_rev":"1-ac20f5dc58cb337c5949e51e011b9597","name":"@crownanalytica/sso-middleware","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@crownanalytica/sso-middleware","version":"1.0.0","description":"This middleware integrates the application to synchronize login sessions of users with the SSO Auth Server.\r All auth related tasks are forwarded to the SSO Auth Server via the middleware.\r The user profile of currently logged in user is added into the co","main":"src/index.js","scripts":{"test":"node src/test.js"},"author":"","license":"ISC","dependencies":{"axios":"^0.21.1","express":"^4.17.1","express-session":"^1.17.1"},"gitHead":"c7acc7a1b12354a189e61ebf20857eb462d54ed9","_id":"@crownanalytica/sso-middleware@1.0.0","_nodeVersion":"15.14.0","_npmVersion":"7.7.6","dist":{"integrity":"sha512-1p6PiyUscrLRxilJpFazHxCgPF3h7zIERGM6T2zTdsx1uc3/D84y+rMV3JQV9qu+koQo1sLyla1u9Mb4n8AZlA==","shasum":"dd9ae5c3a5de84216400898061f42c52d8c694b2","tarball":"https://registry.npmjs.org/@crownanalytica/sso-middleware/-/sso-middleware-1.0.0.tgz","fileCount":5,"unpackedSize":18591,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgbgirCRA9TVsSAnZWagAA/psP/3hNwBav0HsP06p8sTV4\norhdXJ9AQYcqJYro5D6s2NrmzIYjizFIgVoYudhm0bFAhoQ+z/BajfnWrHti\n7xubzsWfPmBu/73CT/IcJkrAEnHBcd6dA119tT9ecPeAscPR6A8OkX2eu+fZ\nNUpJY6ppKS2AT5jDb3gId2AZbmmqFfO13yACKvMT2Is5u/SQ3SQCESdAmCZ8\nBbOuMIXdcUW6p/phH/8lAk+PF3EzefDLRL240M4OTPTRoOHhOGKLSfMgRhi+\nQVZOLTZ2DmCtEFOIkeiXZr68OzIEtAvd3jhaFiSZC8YrdS3ktgvQHV9FBDMx\nGFa3Eu+RygGYeUpwR3I6gspRLceLcXy3FxBlY/DVU65Xa3WuQbLML3HLUtWR\n6fMwrQU3N5EjW+PT14ZHxSuFh5TLJHkG4OXEGNu9JChSvkJrnOYRVaJgZx4/\nXdq5ZsI9oKP4sx4LqBeywiI54JZ0AzkOTBLxdQh/VgSyqHXJeVWDQ4kmlkhm\nDSTpo2bum1+O44wU0jbkz7BenR4HW17Vodm4KPa8upfyv8uFdddDEsqFGmsP\nRoiRhjzRMJFQjuEnQNYltYo+H0T+mbaMtCC1WGRVQuB+UjJuUA+APAoeeklm\nboaDv1TAX4vOLxgrNcrlCG3ef66yKP7VYOVPVNs20kwPJO7jQRukUJ7g32SY\nYJ+9\r\n=mMoG\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC/dr/xyWhuTE/C1vG06Zx9AWH9KBQE2Y3e9rsYlAsmLwIgVtWYAevFACttj10fv1uhwPOLDey9z7KPaVVPFNTsi9E="}]},"_npmUser":{"name":"princechristianbasiga","email":"pbasiga@crownci.com"},"directories":{},"maintainers":[{"name":"princechristianbasiga","email":"pbasiga@crownci.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/sso-middleware_1.0.0_1617823915044_0.43715735277638035"},"_hasShrinkwrap":false}},"time":{"created":"2021-04-07T19:31:54.770Z","1.0.0":"2021-04-07T19:31:55.191Z","modified":"2022-04-05T01:56:24.935Z"},"maintainers":[{"name":"princechristianbasiga","email":"pbasiga@crownci.com"}],"description":"This middleware integrates the application to synchronize login sessions of users with the SSO Auth Server.\r All auth related tasks are forwarded to the SSO Auth Server via the middleware.\r The user profile of currently logged in user is added into the co","license":"ISC","readme":"# SSO Middleware\r\nThis middleware integrates the application to synchronize login sessions of users with the SSO Auth Server.\r\nAll auth related tasks are forwarded to the SSO Auth Server via the middleware.\r\nThe user profile of currently logged in user is added into the context of each request `res.locals` via the middleware.\r\nThe middleware also establishes a local session.\r\n\r\n\r\n## Pre-requisites\r\n- You must have been given read access to the sso-middleware repository. Please email\r\npbasiga@crownci.com for access.\r\n- You must have a valid `clientId` from registering your application with the SSO Server.\r\n- You must have `express-session` installed into your application and configured: https://www.npmjs.com/package/express-session\r\n- For development / testing purposes, you need to have registered an account with the SSO Server: `http://54.219.190.15` \r\n- Have your account be granted access to the registered application. Please email pbasiga@crownci.com  to do this.\r\n- You need to server your frontend from your backend.\r\n\r\n***Warning***    \r\nThe cookie name for user session with sso server is `crownanalytica.ssoSession`.\r\nBe sure when configuring your session that your cookie name does not conflict if\r\nyour application will be hosted within the same domain as the SSO Server.\r\n\r\n\r\n## Installation\r\n```sh\r\nnpm install -g install-local\r\n```\r\n`install-local` is a utility for installing npm packages locally. It extends from base npm link, adding ability to work with typescript projects.\r\nYou may install it globally or just for your application as a dev dependancy.\r\n\r\n```sh\r\n# Clone Middleware Repository\r\ngit clone git@bitbucket.org:crownanalytica/sso-middleware.git\r\n# Change Directory into your Project\r\ncd <project-dir>\r\n\r\n#Install middleware into your project\r\ninstall-local <sso-middleware-directory>\r\n\r\n```\r\n***Note***  \r\nFor the moment, there is no private organization set up in npm to host modules like these.  \r\nIncurring the monthly payment for a single module is not currently worth it.  \r\nI will also not be publishing public packages to npm as this work is done for the project under Crown Consulting Inc.  \r\nTherefore, until a private npm organization is created, all custom npm packages to be used be future node applicatons will be installed following this format.\r\n\r\n## Usage\r\n\r\n```js\r\nconst ssoMiddleware = require('@crown-analytica/sso-middleware');\r\n// ES import\r\nimport ssoMiddleware from '@crown-analytica/sso-middleware';\r\n\r\nvar app = express();\r\nconst config = {\r\n    clientId: '<client-id'>,\r\n    authUrl:'http://<auth-url>',\r\n    logoutPath:'/auth/logout',\r\n    onAuthenticationVerified: (req,res,profile) => {\r\n        console.log(\"Profile Loaded into context\", profile);\r\n    };\r\n}\r\napp.use(ssoMiddleware(config));\r\n```\r\n### ssoMiddleware(config)\r\n\r\nInitializes SSO Middleware with the given config\r\n\r\n### Config\r\n`sso-middleware` accepts these properties in the config object.\r\n\r\n#### clientId\r\n`clientId` provided by the SSO Auth Server once integration has been approved by the connected auth server.\r\n**Note** Public Access to SSO Auth Server with custom configuration is WIP. Link to that repo will be linked here.\r\n\r\n\r\n#### authUrl\r\n`authUrl` is the url the middleware will be sending requests to. \r\nBy default it is http://localhost:3001 which is the default port that the SSO Auth Server will listen on.\r\n\r\n#### onAuthenticationVerified\r\n`onAuthenticationVerified` is a function that is called once a user has been verified as logged in by the SSO Auth Server on each request.\r\nThe function is given `req`, `res`, `profile` as arguments.\r\n\r\n`req` <br>\r\nExpress request object.\r\n\r\n`res` <br>\r\nExpress response object.\r\n\r\n`profile` <br>\r\nProfile that is stored in the context of the request once login has been verified.\r\n**Note** The same value is stored in `res.locals` by this point.\r\n\r\n```ts\r\n{\r\n    // User Id in SSO Database\r\n    ssoUserId:number,\r\n    // Username in SSO Database (hashed)\r\n    userName: string;\r\n    // Email of user.\r\n    email: string;\r\n    // Company user is apart of.\r\n    company: string;\r\n    // Role of user in respective application.\r\n    role: string;\r\n    // AWS Credentials of user.\r\n    iam_access_key: string;\r\n    iam_secret_key: string;\r\n    verified: boolean;\r\n}\r\n\r\n```\r\n\r\n\r\n\r\n#### logoutPath\r\nBy default, `logoutPath` is /auth/logout.\r\nApplication may make a request to respective backend server at `logoutPath`\r\nThis will send logout request to SSO Server to terminate the user's session.\r\nThis will end the user's session on all applications integrated with SSO Server.\r\nThis will then return a response with `loginUrl` provided that your frontend can\r\nupdate the current page to.\r\n\r\n#### port\r\nBy default, the host name automatically added in headers during requests will suffice as\r\nnormally only port 80 is expected to be exposed. However, this will make sure all redirects\r\nthat are configured during logout calls and sessions ending will work in the case that your\r\napplication has exposed another port.\r\n\r\n\r\n## Testing the Middleware\r\n\r\n### No Access Without Authentication\r\nOpen your browser and go to the url of your application.\r\nIf you have not logged into the SSO Server before, it will redirect you to the login page.\r\n\r\nAfter you've successfully logged in, you will be redirected to your application.\r\n\r\nSubsequent requests to your application will verify that you are logged in and go directly to your application without redirecting.\r\n\r\n### User Profile in Request Context\r\nYou may test that the user that is logged in is in the request context by logging `res.locals.user`.  \r\nUpon logging, you will see `profile` object as described above.\r\n\r\n\r\n### User Global Session Information in Session\r\nYou may view the session your application is keeping track of by logging\r\n`req.session.user`. Upon logging you should see `sessionId`, `ssoToken`.\r\n\r\n### Testing Logout\r\nLogout endpoint is available for all applications.\r\nYou may add a logout button on your respective UI.\r\nUpon making the request, the response should return loginUrl with redirect set back to your application.\r\n\r\nUpdate the user's page to that loginUrl in reponse via \r\n```js\r\nlocation.href = response.data.loginUrl;\r\n```\r\n\r\nIf you login at that point, you will be redirected back to your application.\r\n\r\nAfter logging out, if you try to land directly on the application again, you will be redirected to the login page.\r\n","readmeFilename":"README.md"}