{"_id":"@dcsv-io/d2-auth-abstractions","_rev":"2-a41c2a4f40e8209dc2f0d2d10dd606c3","name":"@dcsv-io/d2-auth-abstractions","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.1":{"name":"@dcsv-io/d2-auth-abstractions","version":"0.1.1","_id":"@dcsv-io/d2-auth-abstractions@0.1.1","maintainers":[{"name":"dcsv-tristan","email":"tristan@dcsv.io"}],"dist":{"shasum":"989205d4992f108d61f2ab1c0c41d07f6c8e7f5a","tarball":"https://registry.npmjs.org/@dcsv-io/d2-auth-abstractions/-/d2-auth-abstractions-0.1.1.tgz","fileCount":31,"integrity":"sha512-eUqiDtDi8hI0fLEKNp9Hv+qRRAQyayXIys/NARrF2eRXSgB9vxyV5pCHAfaTGGLvhFw+NqQGxjw/8OVw6wtoNQ==","signatures":[{"sig":"MEUCIBddQbhbw3mCL53dN1E6CbfGUlkofIJ8aWZEdoklnvYpAiEAnUAN29L5kFOkX+7saMRNKDCs7IDBiB7xM6j2E1pCTNc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":66371},"main":"./dist/index.js","type":"module","_from":"file:bundle/npm/dcsv-io-d2-auth-abstractions-0.1.1.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -b","prebuild":"node ../../scripts/run-ts-codegen.mjs src/auth-scopes-emit.ts && node ../../scripts/run-ts-codegen.mjs src/error-codes-emit.ts && node ../../scripts/run-ts-codegen.mjs src/jwt-claims-emit.ts","test:coverage":"vitest run --coverage","type-check:test":"tsc -p tsconfig.test.json"},"_npmUser":{"name":"dcsv-tristan","email":"tristan@dcsv.io"},"_resolved":"/home/runner/work/D2-Public/D2-Public/bundle/npm/dcsv-io-d2-auth-abstractions-0.1.1.tgz","_integrity":"sha512-eUqiDtDi8hI0fLEKNp9Hv+qRRAQyayXIys/NARrF2eRXSgB9vxyV5pCHAfaTGGLvhFw+NqQGxjw/8OVw6wtoNQ==","_npmVersion":"11.16.0","description":"<!-- Copyright (c) DCSV. Licensed under the Apache License, Version 2.0. -->","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@dcsv-io/d2-result":"0.1.1","@dcsv-io/d2-i18n-keys":"0.1.1","@dcsv-io/d2-error-category":"0.1.1","@dcsv-io/d2-i18n-abstractions":"0.1.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"4.0.18","typescript":"5.9.3","@vitest/coverage-v8":"4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/d2-auth-abstractions_0.1.1_1784262803183_0.14569685294009238","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@dcsv-io/d2-auth-abstractions","version":"0.1.2","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"dependencies":{"@dcsv-io/d2-error-category":"0.1.2","@dcsv-io/d2-i18n-abstractions":"0.1.2","@dcsv-io/d2-i18n-keys":"0.1.2","@dcsv-io/d2-result":"0.1.2"},"devDependencies":{"@vitest/coverage-v8":"4.0.18","typescript":"5.9.3","vitest":"4.0.18"},"scripts":{"prebuild":"node ../../scripts/run-ts-codegen.mjs src/auth-scopes-emit.ts && node ../../scripts/run-ts-codegen.mjs src/error-codes-emit.ts && node ../../scripts/run-ts-codegen.mjs src/jwt-claims-emit.ts","build":"tsc -b","test":"vitest run","test:coverage":"vitest run --coverage","type-check:test":"tsc -p tsconfig.test.json"},"_id":"@dcsv-io/d2-auth-abstractions@0.1.2","description":"<!-- Copyright (c) DCSV. Licensed under the Apache License, Version 2.0. -->","_integrity":"sha512-HHep9p436k6knjWtU4Vt8+cn8K9YlLcKd4h50Yg2D1zumgZJ+U4WhXtipD0YcfFW+c8rR2OgN+lcko6fiHwYsA==","_resolved":"/home/runner/work/D2-Public/D2-Public/bundle/npm/dcsv-io-d2-auth-abstractions-0.1.2.tgz","_from":"file:bundle/npm/dcsv-io-d2-auth-abstractions-0.1.2.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-HHep9p436k6knjWtU4Vt8+cn8K9YlLcKd4h50Yg2D1zumgZJ+U4WhXtipD0YcfFW+c8rR2OgN+lcko6fiHwYsA==","shasum":"d6cf79b36ee609fcbfa31e4f8445d415c35fedd3","tarball":"https://registry.npmjs.org/@dcsv-io/d2-auth-abstractions/-/d2-auth-abstractions-0.1.2.tgz","fileCount":31,"unpackedSize":66373,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD1pO1nFpp+wVO7HEwGbfF9p1jV+eNW+IRNfrGClmhKKgIgEP2XsxMv//oUN5xy6bRGpjFlOvw6aO8RmEaXns8nkBE="}]},"_npmUser":{"name":"dcsv-tristan","email":"tristan@dcsv.io"},"directories":{},"maintainers":[{"name":"dcsv-tristan","email":"tristan@dcsv.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/d2-auth-abstractions_0.1.2_1784286775275_0.16524015525323477"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-17T04:33:23.025Z","modified":"2026-07-17T11:12:55.601Z","0.1.1":"2026-07-17T04:33:23.311Z","0.1.2":"2026-07-17T11:12:55.427Z"},"description":"<!-- Copyright (c) DCSV. Licensed under the Apache License, Version 2.0. -->","maintainers":[{"name":"dcsv-tristan","email":"tristan@dcsv.io"}],"readme":"<!--\nCopyright (c) DCSV. Licensed under the Apache License, Version 2.0.\n-->\n\n# @dcsv-io/d2-auth-abstractions\n\nAuth-related constants for TS consumers — `Scopes` tree, `AuthErrorCodes`,\n`AuthFailures` factories, `JwtClaimTypes`. Mirrors\n`DcsvIo.D2.Auth.Abstractions` + `DcsvIo.D2.Auth.Errors` consolidated\n(matches the .NET assembly placement).\n\n## Install\n\n```bash\npnpm add @dcsv-io/d2-auth-abstractions\n```\n\n## Public API\n\n| Export                                                  | Source                            | Mirror                                      |\n| ------------------------------------------------------- | --------------------------------- | ------------------------------------------- |\n| `Scopes` (nested constants)                             | `scopes.g.ts` (codegen)           | `Scopes.*.*` (.NET)                         |\n| `ALL_SCOPES`                                            | `scopes.g.ts`                     | `Scopes.AllScopes`                          |\n| `AuthErrorCodes`                                        | `auth-error-codes.g.ts` (codegen) | `DcsvIo.D2.Auth.Errors.AuthErrorCodes`      |\n| `ALL_AUTH_ERROR_CODES` / `getAuthErrorHttpStatus(code)` | `auth-error-codes.g.ts`           | `AuthErrorCodes.AllCodes` / `GetHttpStatus` |\n| `AuthFailures.<factory>()`                              | `auth-failures.g.ts` (codegen)    | `DcsvIo.D2.Auth.Errors.AuthFailures.*`      |\n| `JwtClaimTypes`                                         | `jwt-claim-types.g.ts` (codegen)  | `DcsvIo.D2.Auth.Abstractions.JwtClaimTypes` |\n| `JwtPayload`                                            | `jwt-payload.g.ts` (codegen)      | TS-only typed view over the same spec       |\n\n## Codegen workflow\n\n`prebuild` chains 4 emitter scripts (auth-scopes / auth-error-codes /\nauth-failures / jwt-claims) before `tsc -b`, so `pnpm -r build` regenerates\ntransparently. Generated files (`*.g.ts`) are committed to git.\n\n`JwtClaimTypes` AND `JwtPayload` both emit from\n`contracts/jwt-claims/jwt-claims.spec.json` (one generator, two outputs; sources committed):\n\n- `JwtClaimTypes` — string-constant catalog (every claim's wire name).\n- `JwtPayload` — TS interface typed on every `standard` + `d2-custom`\n claim with stable per-field types; `inside-act` claims live nested\n inside `act` and are not surfaced as top-level fields. A trailing\n `raw: Readonly<Record<string, unknown>>` escape hatch carries the\n raw decoded claims for downstream consumers needing access to\n non-spec'd claims.\n\nThe .NET side consumes the same spec for `JwtClaimTypes` constants;\n.NET reads claim values via `ClaimsPrincipal` so a typed payload is not\nneeded there. Cross-language drift on the constant catalog is\nstructurally impossible (single source).\n\n## Header constants\n\n> Wire-protocol header catalogs live in the per-transport packages (`@dcsv-io/d2-headers-http`, `@dcsv-io/d2-headers-grpc`, `@dcsv-io/d2-headers-amqp`, `@dcsv-io/d2-headers-common`).\n\n## Dependencies\n\n- `@dcsv-io/d2-result` — `D2Result` shape returned by `AuthFailures.*` factories.\n\n## Usage example\n\n```ts\nimport {\n  Scopes,\n  AuthFailures,\n  AuthErrorCodes,\n  JwtClaimTypes,\n} from \"@dcsv-io/d2-auth-abstractions\";\nimport { HttpHeaders } from \"@dcsv-io/d2-headers-http\";\n\n// Scope check.\nif (!ctx.scopes.has(Scopes.auth.user.impersonate.consent)) {\n  return AuthFailures.scopeInsufficient(ctx.traceId);\n}\n\n// Header read.\nconst idempotency = req.headers[HttpHeaders.IDEMPOTENCY_KEY];\n\n// Claim read.\nconst sub = jwtPayload[JwtClaimTypes.SUB];\n\n// Error-code discrimination.\nif (result.errorCode === AuthErrorCodes.AUTH_JWT_EXPIRED) {\n  // refresh the token and retry\n}\n```\n\n## Parity with .NET\n\nMirrors `DcsvIo.D2.Auth.Abstractions` + `DcsvIo.D2.Auth.Errors`:\n\n- `Scopes` tree — same dot-segmented spec names emitted as nested\n constants (e.g. `Scopes.auth.user.impersonate.consent`).\n- `AuthErrorCodes` — same string values (every constant is its own name).\n- `AuthFailures` — every factory returns `D2Result.fail(...)` with\n matching `errorCode` + `statusCode` + default `messageKey`.\n- `JwtClaimTypes` — codegen-emitted from `contracts/jwt-claims/jwt-claims.spec.json`;\n same constant names + values on both sides.\n- `JwtPayload` — TS-only typed view emitted from the same spec; .NET reads\n claims via `ClaimsPrincipal` rather than a typed shape.\n\n## Edge cases\n\n- `getAuthErrorHttpStatus` returns 500 for unknown codes — defensive\n default, every shipped `AUTH_*` code IS in the table.\n- `Scopes` may include `_self` keys at branch nodes when an entry is\n both a leaf scope AND has children (rare; edge case for forward-compat).\n- Generated files (`*.g.ts`) are committed to git.\n","readmeFilename":"README.md"}