{"_id":"@dannymoerkerke/fido2-lib","_rev":"3-f8e01e0b66e0c1e98bdc26120784dc66","name":"@dannymoerkerke/fido2-lib","dist-tags":{"latest":"2.4.1"},"versions":{"2.3.0":{"name":"@dannymoerkerke/fido2-lib","version":"2.3.0","description":"A library for performing FIDO 2.0 / WebAuthn functionality","main":"index.js","publishConfig":{"access":"public"},"scripts":{"test":"istanbul cover _mocha","docs":"jsdoc -c ./.jsdoc-conf.json","publish-docs":"gh-pages --repo https://$GH_TOKEN@github.com/apowers313/fido2-lib.git --dist docs"},"keywords":["webauthn","authentication","fido","fido2","web authentication","u2f","server"],"author":{"name":"Adam Powers"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/dannymoerkerke/fido2-lib.git"},"bugs":{"url":"https://github.com/dannymoerkerke/fido2-lib/issues","email":"apowers@ato.ms"},"devDependencies":{"chai":"^4.1.2","chai-as-promised":"^7.1.1","docdash":"^0.4.0","fido2-helpers":"^1.7.2","gh-pages":"^0.12.0","istanbul":"^1.1.0-alpha.1","istanbul-coveralls":"^1.0.3","jsdoc":"^3.5.5","mocha":"^2.5.3","mockery":"^2.0.0","sinon":"^1.17.6"},"dependencies":{"asn1js":"^2.0.18","cbor":"^4.0.0","cose-to-jwk":"^1.1.0","jwk-to-pem":"^2.0.0","node-jose":"^1.0.0","node-webcrypto-ossl":"^1.0.35","pkijs":"=2.1.58","psl":"^1.1.24"},"gitHead":"3b20e1c0e027d411582a940b232b3d4148f74ee5","homepage":"https://github.com/dannymoerkerke/fido2-lib#readme","_id":"@dannymoerkerke/fido2-lib@2.3.0","_nodeVersion":"13.3.0","_npmVersion":"6.13.7","dist":{"integrity":"sha512-LqB3yjRfW7IxMYoaGva4r7gM+8TPJt4SDlKQpQZzMw9w825j24q4G92CEV+4fv2JThZH0gPgP3efeIiZViHxOw==","shasum":"05125e64da8d07140e65418b8274878f1b9e8f85","tarball":"https://registry.npmjs.org/@dannymoerkerke/fido2-lib/-/fido2-lib-2.3.0.tgz","fileCount":36,"unpackedSize":420715,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJepfimCRA9TVsSAnZWagAA8WAP/2hZmofe7XGp1jMBDnC1\nA0dZMmab+X6fogPaYGS9biabBlpTHWNIpUXca6zLrkBVUeD74HNyPhXtY543\nS9lz97omBjGuDIui9vzEFyHtksmXOufjTaG9X9hGLmt9qRh3xyTSqA6fjZ6q\nspHUHDYLVxindMu+b/B1VScBXOKFNevzDXX6/CZXEBNMnuz81fYrFjMU/xDu\nYLuBL3p9FsxR8RA8WR5pzKOvnKPAtWddKQcbM97SS5LBexrAm1Ct9j27eddr\nTXO494hgUUXOcxniTdAOMGjSs41u+oolt0e5VaVgns/OcbcMg0GoQ2cZIBJ0\nGDQboGBqe3Hns2Y0CcDAxQcnEDkdE/qlfWlkwskFSkGdO8pgm+RnJUWsX6Zm\nQjxQziPfOG5kLuRjexgMdrvhE+6ioMzRMhfh288ki8eS2w3ZcnOvTf+zMR9c\nRUQyXHPS+2kAYU1RsAmIXiWbAD7RgEU2ugSxx1Jd2KYMj2LhL49QZjekjZKM\nu6tEqvkFpT5DRaUHHI6wuLs0+dHRl6IspT9HLOlxeKONaPgtLzvkPaRAmEUJ\nJ5JdSZoHtn1qCT/W8xyHlPpfbqCzKskF8EQO69eXiQKS+UM6o8G6no45L373\nSXOMhjqW6F8twv8iZczvx3V2SNBloSmMi2eDnYChxyRXXab5M7Hjgh1mTvOD\n3Vlg\r\n=U84k\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBEU4loFDswWL0xBeOMGs4985DwTIBjSrs8V3uz7IH3JAiEAqyBDrwrnVccrIhCCJn9GEqck5on8NnddSuZX979k90o="}]},"maintainers":[{"name":"dannymoerkerke","email":"danny@dannymoerkerke.nl"}],"_npmUser":{"name":"dannymoerkerke","email":"danny@dannymoerkerke.nl"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fido2-lib_2.3.0_1587935398215_0.9638941204369382"},"_hasShrinkwrap":false},"2.4.0":{"name":"@dannymoerkerke/fido2-lib","version":"2.4.0","description":"A library for performing FIDO 2.0 / WebAuthn functionality","main":"index.js","publishConfig":{"access":"public"},"scripts":{"test":"istanbul cover _mocha","docs":"jsdoc -c ./.jsdoc-conf.json","publish-docs":"gh-pages --repo https://$GH_TOKEN@github.com/apowers313/fido2-lib.git --dist docs"},"keywords":["webauthn","authentication","fido","fido2","web authentication","u2f","server"],"author":{"name":"Adam Powers"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/dannymoerkerke/fido2-lib.git"},"bugs":{"url":"https://github.com/dannymoerkerke/fido2-lib/issues","email":"apowers@ato.ms"},"devDependencies":{"chai":"^4.1.2","chai-as-promised":"^7.1.1","docdash":"^0.4.0","fido2-helpers":"^1.7.2","gh-pages":"^0.12.0","istanbul":"^1.1.0-alpha.1","istanbul-coveralls":"^1.0.3","jsdoc":"^3.5.5","mocha":"^2.5.3","mockery":"^2.0.0","sinon":"^1.17.6"},"dependencies":{"asn1js":"^2.0.18","cbor":"^4.0.0","cose-to-jwk":"^1.1.0","jwk-to-pem":"^2.0.0","node-jose":"^1.0.0","node-webcrypto-ossl":"^1.0.35","pkijs":"=2.1.58","psl":"^1.1.24"},"gitHead":"353dc4b9169efd3921394147b5f34b08c12a0e9d","homepage":"https://github.com/dannymoerkerke/fido2-lib#readme","_id":"@dannymoerkerke/fido2-lib@2.4.0","_nodeVersion":"14.11.0","_npmVersion":"6.14.8","dist":{"integrity":"sha512-qntyfRmULa/aEIxHJlFv1l+irFbSsswTHc6Xr7/r5wAgZHu+1T0OHSYwSHVxOq6s8c4YluB2JeFqp6PLjjZnsg==","shasum":"12f047c5b91f1340320b96f24839cd04501caf75","tarball":"https://registry.npmjs.org/@dannymoerkerke/fido2-lib/-/fido2-lib-2.4.0.tgz","fileCount":36,"unpackedSize":420753,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfrpAICRA9TVsSAnZWagAAk1sP+wceq/PxeMWElh/rHpYm\nLMaxmNCctyRfgCpJ+eVZeM6SZtnhenqBAH0anzdzNMtVKHryjiJOJh+fndX4\nCdzFuMRlHVqupjFaZPcRwinONI2Ylr/8ZjaAUaAJYupHfMbmI9i+JEvvne9i\nRjZj/3GbNRkWppXzXObnaTDLDOonZgKTsbbIdgNKMDtG8yQvX+SwcvCLo7sP\nTfRQk97PyPhPwcBqiuwjHm/2IO9d46vsyv+v5WcEblVX5nlh2cyXIilVxQUW\n0yCUh9tgWC0WmcQp53P2Dazjjpzk2HUmPlFdDjXT0IYCebBiWVjJ5v+qjfFD\nsWReG+DAEwVHVP7kbjSfbhPmsWkR3p+8IsPPXTpIYzTOMiCYuA9AB3PG5/pK\nGEbpr/0zYPgQUfqCYfjjiQD/AeXFUSoS67zQ7+G+s8LjVJZduKYuzuYMAUiv\nNB7zpZvnSp637Wvcw8Bopijo2OagfjGoOJTSpIIo0Zcs0oqKTKuNrHFS3TCd\n4dl3syekrOG281jJXPb6KjaoQ7Di7glSZiAxklH5vHZh1nW+4JxFrJc2DO70\npDBNR9CTL9tCwmVenIbzJiyQg3tyd96YlKLwXzcgewDotJyLS5Vb9bWymh0p\n8pvP4F9HyNhyIV33eyWYIZHZKG3kV+YM3bQ54NMfK2oGpJTyfyPN9vi/GO06\nVV+7\r\n=QXW8\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCVyyg0NWHBGLcTjptSIDc7cBIu+BpktdDompekgU7BpgIhAOK8MLLt3K3X7X6UE58BXDRK0ltG1EjIgdwYLOQqUpGh"}]},"_npmUser":{"name":"dannymoerkerke","email":"danny@dannymoerkerke.nl"},"directories":{},"maintainers":[{"name":"dannymoerkerke","email":"danny@dannymoerkerke.nl"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fido2-lib_2.4.0_1605275656262_0.9610423188901884"},"_hasShrinkwrap":false},"2.4.1":{"name":"@dannymoerkerke/fido2-lib","version":"2.4.1","description":"A library for performing FIDO 2.0 / WebAuthn functionality","main":"index.js","publishConfig":{"access":"public"},"scripts":{"test":"istanbul cover _mocha","docs":"jsdoc -c ./.jsdoc-conf.json","publish-docs":"gh-pages --repo https://$GH_TOKEN@github.com/apowers313/fido2-lib.git --dist docs"},"keywords":["webauthn","authentication","fido","fido2","web authentication","u2f","server"],"author":{"name":"Adam Powers"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/dannymoerkerke/fido2-lib.git"},"bugs":{"url":"https://github.com/dannymoerkerke/fido2-lib/issues","email":"apowers@ato.ms"},"devDependencies":{"chai":"^4.1.2","chai-as-promised":"^7.1.1","docdash":"^0.4.0","fido2-helpers":"^1.7.2","gh-pages":"^0.12.0","istanbul":"^1.1.0-alpha.1","istanbul-coveralls":"^1.0.3","jsdoc":"^3.5.5","mocha":"^2.5.3","mockery":"^2.0.0","sinon":"^1.17.6"},"dependencies":{"asn1js":"^2.0.18","cbor":"^4.0.0","cose-to-jwk":"^1.1.0","jwk-to-pem":"^2.0.0","node-jose":"^1.0.0","node-webcrypto-ossl":"^1.0.35","pkijs":"=2.1.58","psl":"^1.1.24"},"gitHead":"d73ab9af1ddc38baf834c8a6312e6fe6209a62dd","homepage":"https://github.com/dannymoerkerke/fido2-lib#readme","_id":"@dannymoerkerke/fido2-lib@2.4.1","_nodeVersion":"14.11.0","_npmVersion":"6.14.8","dist":{"integrity":"sha512-euNYosa6Dy98hvsZLgN/mGFIiSXrWfSJkECdE4TrRuQTxvV29xEKBjujw8aWv8lryyfh9SHAgeOaVwpGyw7R+Q==","shasum":"2ce78dfe3d3cc7b6141faa1f1a55e622ddfca465","tarball":"https://registry.npmjs.org/@dannymoerkerke/fido2-lib/-/fido2-lib-2.4.1.tgz","fileCount":36,"unpackedSize":420846,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfrpYpCRA9TVsSAnZWagAAkhIP/1amFmNmlAcEgFIqlGkf\ne73Uv4hwm56EFR42ARN9xccWzCgwynXqfYBvB3JRq9MG1AMPHy9EGuKLVufO\nNbFvPDzmntn2RiBNpzVKqdki0YzQ+Jz+d0ZpTrmrq97DH1yTahqhAMVOMsQ9\nDQguBhW2DDuMEtBB63L9z/qPQy22dx/XY8IMWaLV7ldUVdKoKJMibqUK3fdz\naJDgEmwUXK3h9QDfQD0j1K2aN8xlyFCNKOgVRvccG5VndVE7CvPJd7dSEkLG\ne6mtGNPB+Br0P//Px3QwYHpOjzc13EF3M9hONFn9zL4sTeqkWBkVjGcIQKQ6\n+0V7rz9mS0PrXion8v/hSzwaj1es2oWDVZZbK1+UHiBQsvQgRUDSPoouMOz+\npE8nKjwO9N5w13j3syiU4uXocbkkeRBbwKna4ppFsAgEr1baPe20tg0d8+E2\nhBsdwhXjB0bTa6cvC/BlPfkQQJ7lZ1p2GsfRchnyIy2ntyVvnu9TTikgZNeo\nA3K3qLlfdR1S5BXP+nf7VBYPYJ1UaIYD9CnNqcbTmSDy0Q5Y/y+Cs8Xu1EsQ\nUb8dRqGn3ui0768u7K+TjvtDCT5mPY3x9eJPyTwsczHXYco6yIT/5cGdofOn\ntjkd3or4d4UCzfq1sNBOnaRAMFOoP2qS9N2IoFvVlc1oBybS8QqmcvjzLOyq\n+JYk\r\n=KNte\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC40i/G757Rme3p6tPTA8uNLsvwhtoealvM9Jd93818GAiAw9YFlf9xhBmhFeJ2vVuajgsA8dRTzzqrbJn+NAgIpoA=="}]},"_npmUser":{"name":"dannymoerkerke","email":"danny@dannymoerkerke.nl"},"directories":{},"maintainers":[{"name":"dannymoerkerke","email":"danny@dannymoerkerke.nl"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fido2-lib_2.4.1_1605277224576_0.6559528753774944"},"_hasShrinkwrap":false}},"time":{"created":"2020-04-26T21:09:58.163Z","2.3.0":"2020-04-26T21:09:58.324Z","modified":"2022-04-05T02:42:24.684Z","2.4.0":"2020-11-13T13:54:16.411Z","2.4.1":"2020-11-13T14:20:24.769Z"},"maintainers":[{"name":"dannymoerkerke","email":"danny@dannymoerkerke.nl"}],"description":"A library for performing FIDO 2.0 / WebAuthn functionality","homepage":"https://github.com/dannymoerkerke/fido2-lib#readme","keywords":["webauthn","authentication","fido","fido2","web authentication","u2f","server"],"repository":{"type":"git","url":"git+https://github.com/dannymoerkerke/fido2-lib.git"},"author":{"name":"Adam Powers"},"bugs":{"url":"https://github.com/dannymoerkerke/fido2-lib/issues","email":"apowers@ato.ms"},"license":"MIT","readme":"[![Build Status](https://travis-ci.org/apowers313/fido2-lib.svg?branch=master)](https://travis-ci.org/apowers313/fido2-lib) [![Coverage Status](https://coveralls.io/repos/github/apowers313/fido2-lib/badge.svg?branch=master)](https://coveralls.io/github/apowers313/fido2-lib?branch=master) [![Known Vulnerabilities](https://snyk.io/test/github/apowers313/fido2-lib/badge.svg?targetFile=package.json)](https://snyk.io/test/github/apowers313/fido2-lib?targetFile=package.json)\n\n## Install\n\n``` bash\nnpm install fido2-lib\n```\n\n## Overview\nA library for performing FIDO 2.0 / WebAuthn server functionality\n\nThis library contains all the functionality necessary for implementing a full FIDO2 / WebAuthn server. It intentionally does not implement any kind of networking protocol (e.g. - REST endpoints) so that it can remain independent of any messaging protocols.\n\nThere are four primary functions:\n1. [attestationOptions](https://apowers313.github.io/fido2-lib/Fido2Lib.html#attestationOptions) - creates the challenge that will be sent to the client (e.g. - browser) for the credential create call. Note that the library does not keep track of sessions or context, so the caller is expected to associate the resulting challenge with a session so that it can be appropriately matched with a response.\n2. [attestationResult](https://apowers313.github.io/fido2-lib/Fido2Lib.html#attestationResult) - parses and validates the response from the client\n3. [assertionOptions](https://apowers313.github.io/fido2-lib/Fido2Lib.html#assertionOptions) - creates the challenge that will be sent to the client for credential assertion.\n4. [assertionResult](https://apowers313.github.io/fido2-lib/Fido2Lib.html#assertionResult) - parses and validates the response from the client\n\nThere is also an extension point for adding new attestation formats.\n\nFull documentation can be found [here](https://apowers313.github.io/fido2-lib/).\n\nFor working examples see [fido2-server-demo](https://github.com/apowers313/fido2-server-demo) and / or [webauthn.org](https://webauthn.org)\n\n## Features\n\n* Works with Windows Hello\n* Attestation formats: packed, tpm, android-safetynet, fido-u2f, none\n* Convenient API for adding more attestation formats\n* Convenient API for adding extensions\n* Metadata service (MDS) support enables authenticator root of trust and authenticator metadata\n* Support for multiple simultaneous metadata services (e.g. FIDO MDS 1 & 2)\n* Crypto families: ECDSA, RSA\n* x509 cert parsing, support for FIDO-related extensions, and NIST Public Key Interoperability Test Suite (PKITS) chain validation (from [pki.js](https://github.com/PeculiarVentures/PKI.js/))\n* Returns parsed and validated data, along with extra audit data for risk engines\n\n## Example\n\n**Instantiate Library (Simple):**\n``` js\nconst { Fido2Lib } = require(\"fido2-lib\");\n\n// create a new instance of the library\nvar f2l = new Fido2Lib();\n```\n\n**Instantiate Library (Complex):**\n``` js\n// could also use one or more of the options below,\n// which just makes the options calls easier later on:\nvar f2l = new Fido2Lib({\n    timeout: 42,\n    rpId: \"example.com\",\n    rpName: \"ACME\",\n    rpIcon: \"https://example.com/logo.png\",\n    challengeSize: 128,\n    attestation: \"none\",\n    cryptoParams: [-7, -257],\n    authenticatorAttachment: \"platform\",\n    authenticatorRequireResidentKey: false,\n    authenticatorUserVerification: \"required\"\n});\n```\n\n**Registration:**\n``` js\nvar registrationOptions = await f2l.attestationOptions();\n\n// make sure to add registrationOptions.user.id\n// save the challenge in the session information...\n// send registrationOptions to client and pass them in to `navigator.credentials.create()`...\n// get response back from client (clientAttestationResponse)\n\nvar attestationExpectations = {\n    challenge: \"33EHav-jZ1v9qwH783aU-j0ARx6r5o-YHh-wd7C6jPbd7Wh6ytbIZosIIACehwf9-s6hXhySHO-HHUjEwZS29w\",\n    origin: \"https://localhost:8443\",\n    factor: \"either\"\n};\nvar regResult = await f2l.attestationResult(clientAttestationResponse, attestationExpectations); // will throw on error\n\n// registration complete!\n// save publicKey and counter from regResult to user's info for future authentication calls\n```\n\n**Authentication:**\n``` js\nvar authnOptions = await f2l.assertionOptions();\n\n// save the challenge in the session information...\n// send authnOptions to client and pass them in to `navigator.credentials.get()`...\n// get response back from client (clientAssertionResponse)\n\nvar assertionExpectations = {\n    challenge: \"eaTyUNnyPDDdK8SNEgTEUvz1Q8dylkjjTimYd5X7QAo-F8_Z1lsJi3BilUpFZHkICNDWY8r9ivnTgW7-XZC3qQ\",\n    origin: \"https://localhost:8443\",\n    factor: \"either\",\n    publicKey: \"-----BEGIN PUBLIC KEY-----\\n\" +\n        \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAERez9aO2wBAWO54MuGbEqSdWahSnG\\n\" +\n        \"MAg35BCNkaE3j8Q+O/ZhhKqTeIKm7El70EG6ejt4sg1ZaoQ5ELg8k3ywTg==\\n\" +\n        \"-----END PUBLIC KEY-----\\n\",\n    prevCounter: 362\n};\nvar authnResult = await f2l.attestationResult(clientAssertionResponse, assertionExpectations); // will throw on error\n\n// authentication complete!\n```\n\nFor a real-life example, refer to [component-fido2](https://github.com/apowers313/component-fido2).\n\n## Sponsor\nNote that while I used to be Technical Director for FIDO Alliance (and I am currently the Technical Advisor for FIDO Alliance), THIS PROJECT IS NOT ENDORSED OR SPONSORED BY FIDO ALLIANCE.\n\nWork for this project is supported by my consulting company: [WebAuthn Consulting](https://webauthn.consulting/).\n","readmeFilename":"README.md"}