{"_id":"@cwahlers/nextjs-auth0","_rev":"2-1b938cdad15f482e29a1e64793c1f074","name":"@cwahlers/nextjs-auth0","dist-tags":{"latest":"0.5.1"},"versions":{"0.5.0":{"name":"@cwahlers/nextjs-auth0","version":"0.5.0","description":"Next.js SDK for signing in with Auth0","main":"dist/index.js","types":"dist/index.d.ts","browser":"dist/index.browser.js","directories":{"test":"tests"},"engines":{"node":"^10.13.0 || >=12.0.0"},"scripts":{"clean":"rimraf dist","pretty":"prettier --write \"src/**/*.ts\" \"src/*.ts\"","lint":"eslint --fix --ext .ts ./src","build":"tsc -p tsconfig.build.json","test":"jest --coverage","test:watch":"jest --coverage --watch","prepublishOnly":"npm test && npm run lint","prepublish":"npm run build"},"repository":{"type":"git","url":"git+https://github.com/auth0/nextjs-auth0.git"},"keywords":["auth0","next.js","react","oidc","authentication","zeit"],"author":{"name":"Auth0","url":"https://auth0.com"},"license":"MIT","bugs":{"url":"https://github.com/auth0/nextjs-auth0/issues"},"homepage":"https://github.com/auth0/nextjs-auth0#readme","devDependencies":{"@panva/jose":"^1.9.2","@types/cookie":"^0.3.3","@types/hapi__iron":"^5.1.0","@types/jest":"^24.0.18","@types/jsonwebtoken":"^8.3.4","@types/node":"^12.7.12","@types/react":"^16.9.5","@types/react-dom":"^16.9.1","@types/request":"^2.48.3","@typescript-eslint/eslint-plugin":"^2.3.3","@typescript-eslint/parser":"^2.3.3","eslint":"^6.5.1","eslint-config-airbnb-base":"^14.0.0","eslint-config-prettier":"^6.4.0","eslint-import-resolver-typescript":"^1.1.1","eslint-plugin-import":"^2.18.2","jest":"^24.9.0","next":"^9.1.1","nock":"^11.6.0","prettier":"^1.18.2","request":"^2.88.0","timekeeper":"^2.2.0","ts-jest":"^24.1.0","typescript":"^3.6.4"},"dependencies":{"@hapi/iron":"^5.1.4","base64url":"^3.0.1","cookie":"^0.4.0","openid-client":"^3.7.4"},"peerDependencies":{"next":"^9.0.5"},"jest":{"testEnvironment":"node","rootDir":"./","moduleFileExtensions":["ts","js"],"coveragePathIgnorePatterns":["/node_modules/","/tests/","./jest.config.js"],"coverageReporters":["lcov","text","text-summary"],"preset":"ts-jest"},"gitHead":"afaca845573a47c8980307e59570712abfc0f72d","_id":"@cwahlers/nextjs-auth0@0.5.0","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-kwbcHfAioUH3micb+3poLR85S9FsRSUc/l1Q+r269SrpckHKi0RnZX6uM50HeisRi0do2v+p5oQIXvutgK+5kw==","shasum":"464c8c2ab4def7b8ebf8083a38ddbd15fbcbcd4f","tarball":"https://registry.npmjs.org/@cwahlers/nextjs-auth0/-/nextjs-auth0-0.5.0.tgz","fileCount":69,"unpackedSize":64506,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdweZVCRA9TVsSAnZWagAASW4P/iKAH1WogLOQN+nBp8Ak\nW7B8g/qxP4eXv3HrIelgj2HYbVaZQH4IlOmWupNalj8o1Yf9oVN76vi/93Ag\nPrMznhJL4FwEdkMem8yeODAOBiwO0Tqrt38tCtkhFwU1zWX66hwSeUcLiz6W\nYeWncB++Uq80NIDv2BHxW5XpYxUlUox3v+9o+d1tFdt0lBCg/vTpr6bPWNeG\n0wt61N2qlxRTIWCn42nE3WhR7yujuLZv3Liy4pL2o+ZfRiN/QFyKlJrB0/vc\n5RlSr/yi3gUtXfpGD7oIYpbWFWhm3z5Zlhj+dkR95YCBbrEmA313ouwUFFrp\nPFB3RdNbwSAy9/NyDgFtBoGPqzjhPMVYS6g9qc8Bjncv+HP0fpB1yDFwqPSu\nevBTt/XNVRj+krkYWx7NnN84L4ZPWCJV6JLhLcEGiglps8wF+nSpsRhhvA4m\nuTiykYUsUtGOuj/b/O3jth8AbPALeG2+N9B8vsEu974Q2YLKYxcCIptvw5mY\nDETAGed/HNow8p45Q0ABnlp5diWXenrLu0y6QelL5FfP5Flh/fB0dG8j0so6\n3IWCIlSRGXjr7IolXvvERtxd9xsPOiSDqjwGqUf0ESRhowHnTBbFeNSJ/036\nXQYvQLUkSej8ICGk1I3d9lMFiVmzFnW3SqER7PK3zhu0LRYoNdy/d7GQfQTm\nGxUo\r\n=s7Nu\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDZuyRJ42ctKcGVTCb2LSBSxmkY4i9vTuxjwj+xJnoHGAiEAyzBEiVIZCcAOjUKZFLdXI1byNwjQ4XWoCzZa9GMavtI="}]},"maintainers":[{"name":"cwahlers","email":"claus@codeazur.com.br"}],"_npmUser":{"name":"cwahlers","email":"claus@codeazur.com.br"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/nextjs-auth0_0.5.0_1572988500529_0.3324891894530022"},"_hasShrinkwrap":false},"0.5.1":{"name":"@cwahlers/nextjs-auth0","version":"0.5.1","description":"Next.js SDK for signing in with Auth0","main":"dist/index.js","types":"dist/index.d.ts","browser":"dist/index.browser.js","directories":{"test":"tests"},"engines":{"node":"^10.13.0 || >=12.0.0"},"scripts":{"clean":"rimraf dist","pretty":"prettier --write \"src/**/*.ts\" \"src/*.ts\"","lint":"eslint --fix --ext .ts ./src","build":"tsc -p tsconfig.build.json","test":"jest --coverage","test:watch":"jest --coverage --watch","prepublishOnly":"npm test && npm run lint","prepublish":"npm run build"},"repository":{"type":"git","url":"git+https://github.com/auth0/nextjs-auth0.git"},"keywords":["auth0","next.js","react","oidc","authentication","zeit"],"author":{"name":"Auth0","url":"https://auth0.com"},"license":"MIT","bugs":{"url":"https://github.com/auth0/nextjs-auth0/issues"},"homepage":"https://github.com/auth0/nextjs-auth0#readme","devDependencies":{"@panva/jose":"^1.9.2","@types/cookie":"^0.3.3","@types/hapi__iron":"^5.1.0","@types/jest":"^24.0.18","@types/jsonwebtoken":"^8.3.4","@types/node":"^12.7.12","@types/react":"^16.9.5","@types/react-dom":"^16.9.1","@types/request":"^2.48.3","@typescript-eslint/eslint-plugin":"^2.3.3","@typescript-eslint/parser":"^2.3.3","eslint":"^6.5.1","eslint-config-airbnb-base":"^14.0.0","eslint-config-prettier":"^6.4.0","eslint-import-resolver-typescript":"^1.1.1","eslint-plugin-import":"^2.18.2","jest":"^24.9.0","next":"^9.1.1","nock":"^11.6.0","prettier":"^1.18.2","request":"^2.88.0","timekeeper":"^2.2.0","ts-jest":"^24.1.0","typescript":"^3.6.4"},"dependencies":{"@hapi/iron":"^5.1.4","base64url":"^3.0.1","cookie":"^0.4.0","openid-client":"^3.7.4"},"peerDependencies":{"next":"^9.0.5"},"jest":{"testEnvironment":"node","rootDir":"./","moduleFileExtensions":["ts","js"],"coveragePathIgnorePatterns":["/node_modules/","/tests/","./jest.config.js"],"coverageReporters":["lcov","text","text-summary"],"preset":"ts-jest"},"gitHead":"afaca845573a47c8980307e59570712abfc0f72d","_id":"@cwahlers/nextjs-auth0@0.5.1","_nodeVersion":"10.16.3","_npmVersion":"6.9.0","dist":{"integrity":"sha512-/rFiim1NXV5lksmF/Ts9HAGkX43jZ60p45FSM0TWQXjXdQAXQRUkMAbeMNsTf37HQ/WWZaQLCOQ2aKzRtuxtbg==","shasum":"0c01c50b9da1c970a76fd2ed602eb43c4b4d7436","tarball":"https://registry.npmjs.org/@cwahlers/nextjs-auth0/-/nextjs-auth0-0.5.1.tgz","fileCount":69,"unpackedSize":65382,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJdwfupCRA9TVsSAnZWagAALTUQAJHHBiY2zPk2s0qREXJX\nQQ+1OhsWZjfl7kokG9yt7TppWhuhqFe2URsEecCUg9QoF+0mO+hDB0lECjRb\no7tPqR1qOqFrIA3k5Drzbhibm13av0zO0ZK+vJk4b+WWFFV9RHh8/aiU9R9R\nFY/M0eUy/9HFVXHOVSoM9lf5yz1C2Gsnau8bZrsVaNXRLVa79EyYHQbZgieK\n7MmlLqBoO8Rvy9HP2uDdTpvhIG49yDY2s9JTOw5OOBM52676NNi88OcgyCUg\nod/bqXpgTOtrb1RMeU57FFM5McZXvs6ZRweh/dp5AGP7NOS9V1Fq5xM1WXkh\n4G153XlzGqRxD9TxFvvPEZIZcoxAQRdXpJpzewwflis9iALmLu8ObnswL9U1\naOQDTz3CgJI73YI1MiI8o+Xhknhj3XHxWC/91Y7BADdrgLGBunQ14R9BGaR8\nb35oJ07XooWXoeFLvsCjOjgU8nR1YpQ4AfYMTVESj5xIEVIVsxFfeZgM2fqV\nid00tFeqTVacXeJK7E+uMcgI5IyDtQRtqgcBDCGVjYG5UyUFiI8Hg7BQMBx9\nKGTipO3kCVQno1UHNJq1gpImuQ7Uop1G5OJMVZYEGxzUXQ7Wstfjd3GFs5ww\nOFFnCvUdlIM6V3ySFN6e64kDm7MSPQ8xX0AlgJSKZXf3yDB6RCOcpLgheDzx\nNYAJ\r\n=HCb/\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCi2RP7rL3krZKxjmjRm/ijvwPaA61K1ZfDPwqlR8iVigIhANtWgMxFAuDgUarGSl1+sN9I0qK6KEPW0Zj5kQctDTZ2"}]},"maintainers":[{"name":"cwahlers","email":"claus@codeazur.com.br"}],"_npmUser":{"name":"cwahlers","email":"claus@codeazur.com.br"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/nextjs-auth0_0.5.1_1572993961437_0.24620118754689901"},"_hasShrinkwrap":false}},"time":{"created":"2019-11-05T21:15:00.280Z","0.5.0":"2019-11-05T21:15:00.728Z","modified":"2022-04-05T02:22:40.798Z","0.5.1":"2019-11-05T22:46:01.627Z"},"maintainers":[{"name":"cwahlers","email":"claus@codeazur.com.br"}],"description":"Next.js SDK for signing in with Auth0","homepage":"https://github.com/auth0/nextjs-auth0#readme","keywords":["auth0","next.js","react","oidc","authentication","zeit"],"repository":{"type":"git","url":"git+https://github.com/auth0/nextjs-auth0.git"},"author":{"name":"Auth0","url":"https://auth0.com"},"bugs":{"url":"https://github.com/auth0/nextjs-auth0/issues"},"license":"MIT","readme":"# @auth0/nextjs-auth0\n\nAuth0 SDK for signing in to your Next.js applications.\n\n> Note: This library is currently in an experimental state and support is best effort.\n\n[![License](https://img.shields.io/:license-mit-blue.svg?style=flat)](https://opensource.org/licenses/MIT)\n\n## Table of Contents\n\n- [Installation](#installation)\n- [Getting Started](#getting-started)\n- [Contributing](#contributing)\n- [Support + Feedback](#support--feedback)\n- [Frequently Asked Questions](#frequently-asked-questions)\n- [Vulnerability Reporting](#vulnerability-reporting)\n- [What is Auth0](#what-is-auth0)\n- [License](#license)\n\n## Installation\n\nUsing [npm](https://npmjs.org):\n\n```sh\nnpm install @auth0/nextjs-auth0\n```\n\nUsing [yarn](https://yarnpkg.com):\n\n```sh\nyarn add @auth0/nextjs-auth0\n```\n\n> Note that this package supports the following versions of Node.js: `^10.13.0 || >=12.0.0`\n\n## Getting Started\n\n### Auth0 Configuration\n\nCreate a **Regular Web Application** in the [Auth0 Dashboard](https://manage.auth0.com/). If you're using an existing application you'll want to very that the following settings are configured as follows:\n\n - **Json Web Token Signature Algorithm**: `RS256`\n - **OIDC Conformant**: `True`\n\nGo ahead and configure the URLs for your application:\n\n- **Allowed Callback URLs**: http://localhost:3000/api/callback\n- **Allowed Logout URLs**: http://localhost:3000/\n\nTake note of the **Client ID**, **Client Secret** and **Domain** of your application because you'll need it in the next step.\n\n### Runtime Configuration\n\nAnd then create an instance of the Auth0 plugin (eg: under `/utils/auth0.js`):\n\n```js\nimport { initAuth0 } from '@auth0/nextjs-auth0';\n\nexport default initAuth0({\n  domain: '<AUTH0_DOMAIN>',\n  clientId: '<AUTH0_CLIENT_ID>',\n  clientSecret: '<AUTH0_CLIENT_SECRET>',\n  scope: 'openid profile',\n  redirectUri: 'http://localhost:3000/api/callback',\n  postLogoutRedirectUri: 'http://localhost:3000/',\n  session: {\n    // The secret used to encrypt the cookie.\n    cookieSecret: '<RANDOMLY_GENERATED_SECRET>',\n    // The cookie lifetime (expiration) in seconds. Set to 8 hours by default.\n    cookieLifetime: 60 * 60 * 8,\n    // Store the id_token in the session. Defaults to false.\n    storeIdToken: false,\n    // Store the access_token in the session. Defaults to false.\n    storeAccessToken: false,\n    // Store the refresh_token in the session. Defaults to false.\n    storeRefreshToken: false\n  },\n  oidcClient: {\n    // Optionally configure the timeout in milliseconds for HTTP requests to Auth0.\n    httpTimeout: 2500,\n    // Optionally configure the clock tolerance in milliseconds, if the time on your server is running behind.\n    clockTolerance: 10000\n  }\n});\n```\n\n> Note that when you have configured a Custom Domain in your Auth0 account you should be using that domain (eg: `login.acme.com` instead of `acme.auth0.com`) as the AUTH0_DOMAIN. [You might also need to make changes to your Login page](https://auth0.com/docs/custom-domains/additional-configuration).\n\n### Login\n\nIn order to sign in the user we'll first need a link to the login route.\n\n```html\n<a href='/api/login'>Login</a>\n```\n\nCreate an [API Route](https://nextjs.org/docs#api-routes) for this route (`/pages/api/login.js`) which uses the client:\n\n```js\nimport auth0 from '../../utils/auth0';\n\nexport default async function login(req, res) {\n  try {\n    await auth0.handleLogin(req, res);\n  } catch(error) {\n    console.error(error)\n    res.status(error.status || 400).end(error.message)\n  }\n}\n```\n\nThis will redirect the user to Auth0. After the transaction is completed Auth0 will redirect the user back to your application. This is why the callback route (`/pages/api/callback.js`) needs to be created which will create a session cookie:\n\n```js\nimport auth0 from '../../utils/auth0';\n\nexport default async function callback(req, res) {\n  try {\n    await auth0.handleCallback(req, res, { redirectTo: '/' });\n  } catch(error) {\n    console.error(error)\n    res.status(error.status || 400).end(error.message)\n  }\n}\n```\n\nYou can optionally send extra parameters to Auth0 to influence the transaction, for example:\n\n- Showing the login page\n- Filling in the user's email address\n- Exposing information to the custom login page (eg: to show the signup tab)\n- Using a custom `state`\n\n```js\nimport auth0 from '../../utils/auth0';\n\nexport default async function login(req, res) {\n  try {\n    await auth0.handleLogin(req, res, {\n      authParams: {\n        login_hint: 'foo@acme.com',\n        ui_locales: 'nl',\n        scope: 'some other scope',\n        state: 'a custom state',\n        foo: 'bar'\n      }\n    });\n  } catch(error) {\n    console.error(error)\n    res.status(error.status || 400).end(error.message)\n  }\n}\n```\n\n### Logout\n\nFor signing the user out we'll also need a logout link:\n\n```html\n<a href='/api/logout'>Logout</a>\n```\n\nCreate an [API Route](https://nextjs.org/docs#api-routes) for this route (`/pages/api/logout.js`) which uses the client:\n\n```js\nimport auth0 from '../../utils/auth0';\n\nexport default async function logout(req, res) {\n  try {\n    await auth0.handleLogout(req, res);\n  } catch(error) {\n    console.error(error)\n    res.status(error.status || 400).end(error.message)\n  }\n}\n```\n\n### User Profile\n\nIf you want to expose a route which returns the user profile to the client you can create an additional route (eg: `/pages/api/me.js`):\n\n```js\nimport auth0 from '../../utils/auth0';\n\nexport default async function me(req, res) {\n  try {\n    await auth0.handleProfile(req, res);\n  } catch(error) {\n    console.error(error)\n    res.status(error.status || 500).end(error.message)\n  }\n}\n```\n\nYou can then load the user after the page has been rendered on the server:\n\n```js\nasync componentDidMount() {\n  const res = await fetch('/api/me');\n  if (res.ok) {\n    this.setState({\n      session: await res.json()\n    })\n  }\n}\n```\n\nIf you need to access the user's session from within an API route or a Server-rendered page you can use `getSession`. Note that this object will also contain the user's `access_token` and `id_token`.\n\n```js\nProfile.getInitialProps = async ({ req, res }) => {\n  if (typeof window === 'undefined') {\n    const { user } = await auth0.getSession(req);\n    if (!user) {\n      res.writeHead(302, {\n        Location: '/api/login'\n      });\n      res.end();\n      return;\n    }\n\n    return { user }\n  }\n}\n```\n\n### Calling an API\n\nIt's a common pattern to use Next.js API Routes and proxy them to external APIs. When doing so these APIs typically require an `access_token` to be provided. These APIs can then be configured in Auth0.\n\nIn order to get an access_token for an API you'll need to configure the `audience` on the Auth0 plugin and configure it to store the `access_token` in the cookie:\n\n```js\nimport { initAuth0 } from '@auth0/nextjs-auth0';\n\nexport default initAuth0({\n  domain: '<AUTH0_DOMAIN>'\n  clientId: '<AUTH0_CLIENT_ID>',\n  clientSecret: '<AUTH0_CLIENT_SECRET>',\n  audience: 'https://api.mycompany.com/',\n  scope: 'openid profile',\n  redirectUri: 'http://localhost:3000/api/callback',\n  postLogoutRedirectUri: 'http://localhost:3000/',\n  session: {\n    cookieSecret: '<RANDOMLY_GENERATED_SECRET>',\n    cookieLifetime: 60 * 60 * 8,\n    storeAccessToken: true\n  }\n});\n```\n\nThen you could create a route (eg: `/pages/api/customers.js`) which can call an external API (eg: `https://api.mycompany.com`) using the user's `access_token`.\n\n```js\nimport auth0 from '../../utils/auth0';\n\nexport default async function getCustomers(req, res) {\n  try {\n    const { accessToken } = await auth0.getSession(req);\n\n    const apiClient = new MyApiClient(accessToken);\n    return apiClient.getCustomers();\n  } catch(error) {\n    console.error(error)\n    res.status(error.status || 500).end(error.message)\n  }\n}\n```\n\n### Requiring Authentication\n\nIf you have API routes for which you want to require the user to be authenticated you can use the `requireAuthentication` handler:\n\n```js\nimport auth0 from '../../lib/auth0';\n\nexport default auth0.requireAuthentication(async function billingInfo(req, res) {\n  const { user } = await auth0.getSession(req);\n  res.json({\n    email: user.email,\n    country: 'United States',\n    paymentMethod: 'Paypal'\n  })\n});\n```\n\nIf the user is authenticated then your API route will simply execute, but if the user is not authenticated an error (401) will be returned:\n\n```json\n{\n  \"error\": \"not_authenticated\",\n  \"description\": \"The user does not have an active session or is not authenticated\"\n}\n```\n\n## Documentation\n\n### Cookies\n\nAll cookies will be set as `HttpOnly` cookies and will be forced to HTTPS (`Secure`) if the application is running with `NODE_ENV=production` and not running on localhost.\n\n## Troubleshooting\n\n### Error `id_token issued in the future, now 1570650460, iat 1570650461`\n\nIncrease the clock tolerance for id_token validation:\n\n```js\nimport { initAuth0 } from '@auth0/nextjs-auth0';\n\nexport default initAuth0({\n  ...\n  session: {\n    ...\n  },\n  oidcClient: {\n    // Eg: increase the tolerance to 10 seconds.\n    clockTolerance: 10000\n  }\n});\n```\n\n## Contributing\n\nRun NPM install first to install the dependencies of this project:\n\n```bash\nnpm install\n```\n\nIn order to build a release you can run the following commands and the output will be stored in the `dist` folder:\n\n```bash\nnpm run clean\nnpm run lint\nnpm run build\n```\n\nAdditionally you can also run tests:\n\n```bash\nnpm run test\nnpm run test:watch\n```\n\n## Support + Feedback\n\nThis SDK is in Early Access and support is best effort. Open an issue in this repository to get help or provide feedback.\n\n## Vulnerability Reporting\n\nPlease do not report security vulnerabilities on the public GitHub issue tracker. The [Responsible Disclosure Program](https://auth0.com/whitehat) details the procedure for disclosing security issues.\n\n## What is Auth0?\n\nAuth0 helps you to easily:\n\n- implement authentication with multiple identity providers, including social (e.g., Google, Facebook, Microsoft, LinkedIn, GitHub, Twitter, etc), or enterprise (e.g., Windows Azure AD, Google Apps, Active Directory, ADFS, SAML, etc.)\n- log in users with username/password databases, passwordless, or multi-factor authentication\n- link multiple user accounts together\n- generate signed JSON Web Tokens to authorize your API calls and flow the user identity securely\n- access demographics and analytics detailing how, when, and where users are logging in\n- enrich user profiles from other data sources using customizable JavaScript rules\n\n[Why Auth0?](https://auth0.com/why-auth0)\n\n## License\n\nThis project is licensed under the MIT license. See the [LICENSE](https://github.com/auth0/nextjs-auth0/blob/master/LICENSE) file for more info.\n","readmeFilename":"README.md"}