{"_id":"@debito/zeko-auth-guard","_rev":"7-66a93506ba2388603c5532431ce0b045","name":"@debito/zeko-auth-guard","dist-tags":{"latest":"0.3.1"},"versions":{"0.1.0":{"name":"@debito/zeko-auth-guard","version":"0.1.0","keywords":["auth","hapi","jwt","zeko"],"author":{"name":"SRG","email":"tech@sparkitcs.com"},"license":"ISC","_id":"@debito/zeko-auth-guard@0.1.0","maintainers":[{"name":"sriramang","email":"tech@sparkitcs.com"}],"homepage":"https://bitbucket.org/debito-code/zeko-auth-guard#readme","bugs":{"url":"https://bitbucket.org/debito-code/zeko-auth-guard/issues"},"dist":{"shasum":"950cbddcac255d1a1f47f7b8f02978c34173618f","tarball":"https://registry.npmjs.org/@debito/zeko-auth-guard/-/zeko-auth-guard-0.1.0.tgz","fileCount":5,"integrity":"sha512-YhXethihHUzQ2fMaJztq0PCpiUtxymsJcKPDKNJVE1LNmOMOeRXfIOUs648MZcrYusHwUFyaP7qVXvfV0XX3Ig==","signatures":[{"sig":"MEYCIQCoen+m8RA3OLoZMg1snv/BUKg5etmK7JWxKiiWt9TVbQIhAIydWZoaQhSB9uAlxMzdMzmUy9GLAPvRxKRzwH62ZjmK","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":7382},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"fbd2da5a9650c0f76540a8367f7811ed51c75bda","scripts":{"mint":"node scripts/mint-service-token.js","test":"node test/test-clean.js"},"_npmUser":{"name":"sriramang","email":"tech@sparkitcs.com"},"repository":{"url":"git+https://sparkitcs@bitbucket.org/debito-code/zeko-auth-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Tiny shared Hapi auth guard for Zeko services — authenticates + authorizes via uauth","directories":{},"_nodeVersion":"20.19.6","dependencies":{"@hapi/boom":"^10.0.1","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"@hapi/hapi":"^21.4.4"},"_npmOperationalInternal":{"tmp":"tmp/zeko-auth-guard_0.1.0_1785495774648_0.5524219004553697","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@debito/zeko-auth-guard","version":"0.1.1","keywords":["auth","hapi","jwt","zeko"],"author":{"name":"SRG","email":"tech@sparkitcs.com"},"license":"ISC","_id":"@debito/zeko-auth-guard@0.1.1","maintainers":[{"name":"sriramang","email":"tech@sparkitcs.com"}],"homepage":"https://bitbucket.org/debito-code/zeko-auth-guard#readme","bugs":{"url":"https://bitbucket.org/debito-code/zeko-auth-guard/issues"},"dist":{"shasum":"73374b3b4985fdf6e4c3e97983b08e81b09d4b8e","tarball":"https://registry.npmjs.org/@debito/zeko-auth-guard/-/zeko-auth-guard-0.1.1.tgz","fileCount":5,"integrity":"sha512-OqiiRxetlWu/SfctgzC2nSaz6JysGYlwlM1htGSxGImoVG4IF1CXThgswrX61WrlkAHRKI11Z4IStWrB+ojhwQ==","signatures":[{"sig":"MEUCIFrtSmowUqx0/trg5p45Fq1uJtaAltaYR8fTUsPF5RlHAiEAoN4Si2fT4APEc0f4zhU2LUsHVz2q5yC5v0z/udnecjE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":7613},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"9a0a4317b38157d58552991b1bb62acb93c31e06","scripts":{"mint":"node scripts/mint-service-token.js","test":"node test/test-clean.js"},"_npmUser":{"name":"sriramang","email":"tech@sparkitcs.com"},"repository":{"url":"git+https://sparkitcs@bitbucket.org/debito-code/zeko-auth-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Tiny shared Hapi auth guard for Zeko services — authenticates + authorizes via uauth","directories":{},"_nodeVersion":"20.19.6","dependencies":{"@hapi/boom":"^10.0.1","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"@hapi/hapi":"^21.4.4"},"_npmOperationalInternal":{"tmp":"tmp/zeko-auth-guard_0.1.1_1785560211516_0.6326451621323408","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@debito/zeko-auth-guard","version":"0.1.2","keywords":["auth","hapi","jwt","zeko"],"author":{"name":"SRG","email":"tech@sparkitcs.com"},"license":"ISC","_id":"@debito/zeko-auth-guard@0.1.2","maintainers":[{"name":"sriramang","email":"tech@sparkitcs.com"}],"homepage":"https://bitbucket.org/debito-code/zeko-auth-guard#readme","bugs":{"url":"https://bitbucket.org/debito-code/zeko-auth-guard/issues"},"dist":{"shasum":"3e15bb52b26bb96437b695411b0cfcf3058ba1e9","tarball":"https://registry.npmjs.org/@debito/zeko-auth-guard/-/zeko-auth-guard-0.1.2.tgz","fileCount":5,"integrity":"sha512-9ISic+zPP90uN9Ac8xgxDWqWF91f7YPPAHFXYEQW50irHWYuXB1OTrDZ6JSCeLZGxeBRylM52ZMX+jPsfMMY3w==","signatures":[{"sig":"MEQCIHaF0EmXQ+gdaJcvOe0J0gyVCSYwDOhp6ohi12cqAr8ZAiBpYD/ND0hZ6Hu9WaO7GnDCEJ9SlmTelbU0Fh3rX4ZWYg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":8118},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"7c758183c7b33f30c45cfa5a4a1c59a97b819ef1","scripts":{"mint":"node scripts/mint-service-token.js","test":"node test/test-clean.js"},"_npmUser":{"name":"sriramang","email":"tech@sparkitcs.com"},"repository":{"url":"git+https://sparkitcs@bitbucket.org/debito-code/zeko-auth-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"Tiny shared Hapi auth guard for Zeko services — authenticates + authorizes via uauth","directories":{},"_nodeVersion":"20.19.6","dependencies":{"@hapi/boom":"^10.0.1","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"@hapi/hapi":"^21.4.4"},"_npmOperationalInternal":{"tmp":"tmp/zeko-auth-guard_0.1.2_1787328078050_0.4084397454420807","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@debito/zeko-auth-guard","version":"0.2.0","keywords":["auth","hapi","jwt","zeko"],"author":{"name":"SRG","email":"tech@sparkitcs.com"},"license":"ISC","_id":"@debito/zeko-auth-guard@0.2.0","maintainers":[{"name":"sriramang","email":"tech@sparkitcs.com"}],"homepage":"https://bitbucket.org/debito-code/zeko-auth-guard#readme","bugs":{"url":"https://bitbucket.org/debito-code/zeko-auth-guard/issues"},"dist":{"shasum":"624f903ace7ed7a57f54bff5741af4c632858956","tarball":"https://registry.npmjs.org/@debito/zeko-auth-guard/-/zeko-auth-guard-0.2.0.tgz","fileCount":5,"integrity":"sha512-2YnHhftiCzmolsEvV2/fu2SmPAoMD+Bef6urTktxkUgEBewomPwl50KIFzPagyAoZTIdbZi6iYudDPgPSjT/YQ==","signatures":[{"sig":"MEYCIQCnnkuKMLXDM6+zLk3NtIDJLRcZ7XHZdz7gtO54+tA4DgIhANU1G6sfRjsePd5oyS+gyOOhtxisj1KX+onB+cMi1SIT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":10445},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"12cfee18a72e1136b3da95d67f0deaa407c06b7d","scripts":{"mint":"node scripts/mint-service-token.js","test":"node test/test-clean.js"},"_npmUser":{"name":"sriramang","email":"tech@sparkitcs.com"},"repository":{"url":"git+https://sparkitcs@bitbucket.org/debito-code/zeko-auth-guard.git","type":"git"},"_npmVersion":"11.19.1","description":"Tiny shared Hapi auth guard for Zeko services — authenticates + authorizes via uauth","directories":{},"_nodeVersion":"20.19.6","dependencies":{"@hapi/boom":"^10.0.1","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"@hapi/hapi":"^21.4.4"},"_npmOperationalInternal":{"tmp":"tmp/zeko-auth-guard_0.2.0_1788595245468_0.7639017575092573","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@debito/zeko-auth-guard","version":"0.2.1","keywords":["auth","hapi","jwt","zeko"],"author":{"name":"SRG","email":"tech@sparkitcs.com"},"license":"ISC","_id":"@debito/zeko-auth-guard@0.2.1","maintainers":[{"name":"sriramang","email":"tech@sparkitcs.com"}],"homepage":"https://bitbucket.org/debito-code/zeko-auth-guard#readme","bugs":{"url":"https://bitbucket.org/debito-code/zeko-auth-guard/issues"},"dist":{"shasum":"84dcde7478e1b80e52e819e9b236d5a1889dead9","tarball":"https://registry.npmjs.org/@debito/zeko-auth-guard/-/zeko-auth-guard-0.2.1.tgz","fileCount":5,"integrity":"sha512-S8lX3U9NN0mUTJ93570M1RDU1oBENJfZZZSFKop7+2bbyUkNqb7+xIL84coo2fq6QxhKL7UJToJG5bLGhwit1g==","signatures":[{"sig":"MEQCIBnouUSUMBmJ0Cd44ugSMh8kxp3Zhv5aFsTO6PLuakYmAiAgychO89qpswx1QyIcCoS0vXl9LNzVVK4IhQXwanknFA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIHvVoclMjzBb0tEgov9tXIyYK2ICTpFg2UDS3gRx1+EtAiAmpGXlCSDYnBA+CZLdSAmh6XRhCyQfuX5YTfSgPacDWg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11723},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"77074c2897ed7c5f19f84be8a03178fbe9d9b5c2","scripts":{"mint":"node scripts/mint-service-token.js","test":"node test/test-clean.js"},"_npmUser":{"name":"sriramang","email":"tech@sparkitcs.com"},"repository":{"url":"git+https://sparkitcs@bitbucket.org/debito-code/zeko-auth-guard.git","type":"git"},"_npmVersion":"10.9.8","description":"Tiny shared Hapi auth guard for Zeko services — authenticates + authorizes via uauth","directories":{},"_nodeVersion":"22.23.2","dependencies":{"@hapi/boom":"^10.0.1","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"@hapi/hapi":"^21.4.4"},"_npmOperationalInternal":{"tmp":"tmp/zeko-auth-guard_0.2.1_1790061825461_0.8570977506428503","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@debito/zeko-auth-guard","version":"0.3.0","keywords":["auth","hapi","jwt","zeko"],"author":{"name":"SRG","email":"tech@sparkitcs.com"},"license":"ISC","_id":"@debito/zeko-auth-guard@0.3.0","maintainers":[{"name":"sriramang","email":"tech@sparkitcs.com"}],"homepage":"https://bitbucket.org/debito-code/zeko-auth-guard#readme","bugs":{"url":"https://bitbucket.org/debito-code/zeko-auth-guard/issues"},"dist":{"shasum":"d0e9e1d5ebef25bf1f5894bee6d4a6acc0542f41","tarball":"https://registry.npmjs.org/@debito/zeko-auth-guard/-/zeko-auth-guard-0.3.0.tgz","fileCount":5,"integrity":"sha512-s6cdPPZv6t+kJmp4S5uYOlFNcHuqoob0SMYGtHRAoJUf7WEjnDu7amYaCw/GF2tE1s27vP3cDIioKmwC55Q7fA==","signatures":[{"sig":"MEUCIQDM8xmkyqEpatnKCqEwot2W2cwA8yhQqTRRJJj+VTwbEQIgQ6OtVolitZD5QY4cPKPyRN+n8Zc874Aent6VjzU28Gg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQC9hYIJ4diIm9tV3+qyj2z0PsqwXKnWjqisNuTFnUROVgIgcdtwp5HMPolrPNR2gM6Qbb+D0tugjhK8xPOpRrSlnW4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11581},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"629e3966dd4d282850adf4b11c17882c4d9a705b","scripts":{"mint":"node scripts/mint-service-token.js","test":"node test/test-clean.js"},"_npmUser":{"name":"sriramang","email":"tech@sparkitcs.com"},"repository":{"url":"git+https://sparkitcs@bitbucket.org/debito-code/zeko-auth-guard.git","type":"git"},"_npmVersion":"10.9.8","description":"Tiny shared Hapi auth guard for Zeko services — authenticates + authorizes via uauth","directories":{},"_nodeVersion":"22.23.2","dependencies":{"@hapi/boom":"^10.0.1","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"@hapi/hapi":"^21.4.4"},"_npmOperationalInternal":{"tmp":"tmp/zeko-auth-guard_0.3.0_1790388600061_0.2566969475157779","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"_id":"@debito/zeko-auth-guard@0.3.1","bugs":{"url":"https://bitbucket.org/debito-code/zeko-auth-guard/issues"},"dist":{"shasum":"46ec1d1edfe0a4e5151dc522d69e9760d251b5c5","tarball":"https://registry.npmjs.org/@debito/zeko-auth-guard/-/zeko-auth-guard-0.3.1.tgz","fileCount":5,"integrity":"sha512-y0DfsawXDYx59KOu43YoBA3isrTV9aMEP0mCwKcwxRXnFTBibIkiSEaA7TIFPtl+DJL6CGbjLcIFiz1n6jLSVw==","signatures":[{"sig":"MEUCIQCBK2NlNTtsGHfWdEEeqwon0DQS11koivHjom5MFB5RiAIgc3pGp1R/KxYvW1Cfw4dDRGJN5Ls8azrLYKh0QGqjcV8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIDv53KRyzywhjjz3itKgWbQfQYCi0Q4FMw5d3n3NG4MaAiEAlddB1Up+ZKGeQOZSJ1++fjFbSeb4UFP7XkDxMp8lRQA="}],"unpackedSize":14476},"main":"src/index.js","name":"@debito/zeko-auth-guard","type":"module","author":{"name":"SRG","email":"tech@sparkitcs.com"},"engines":{"node":">=18.0.0"},"gitHead":"30b0d9b98113031b0c427bfc567ad81aa8ddfa0b","license":"ISC","scripts":{"mint":"node scripts/mint-service-token.js","test":"node test/test-clean.js"},"version":"0.3.1","_npmUser":{"name":"sriramang","email":"tech@sparkitcs.com"},"homepage":"https://bitbucket.org/debito-code/zeko-auth-guard#readme","keywords":["auth","hapi","jwt","zeko"],"repository":{"url":"git+https://sparkitcs@bitbucket.org/debito-code/zeko-auth-guard.git","type":"git"},"_npmVersion":"10.9.8","description":"Tiny shared Hapi auth guard for Zeko services — authenticates + authorizes via uauth","directories":{},"maintainers":[{"name":"sriramang","email":"tech@sparkitcs.com"}],"_nodeVersion":"22.23.2","dependencies":{"@hapi/boom":"^10.0.1","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"@hapi/hapi":"^21.4.4"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/zeko-auth-guard_0.3.1_1790643990435_0.4657969989387143"}}},"time":{"created":"2026-07-31T11:02:54.516Z","modified":"2026-09-29T01:06:30.731Z","0.1.0":"2026-07-31T11:02:54.784Z","0.1.1":"2026-08-01T04:56:51.671Z","0.1.2":"2026-08-21T16:01:18.192Z","0.2.0":"2026-09-05T08:00:45.620Z","0.2.1":"2026-09-22T07:23:45.542Z","0.3.0":"2026-09-26T02:10:00.181Z","0.3.1":"2026-09-29T01:06:30.525Z"},"bugs":{"url":"https://bitbucket.org/debito-code/zeko-auth-guard/issues"},"author":{"name":"SRG","email":"tech@sparkitcs.com"},"license":"ISC","homepage":"https://bitbucket.org/debito-code/zeko-auth-guard#readme","keywords":["auth","hapi","jwt","zeko"],"repository":{"url":"git+https://sparkitcs@bitbucket.org/debito-code/zeko-auth-guard.git","type":"git"},"description":"Tiny shared Hapi auth guard for Zeko services — authenticates + authorizes via uauth","maintainers":[{"name":"sriramang","email":"tech@sparkitcs.com"}],"readme":"# @debito/zeko-auth-guard\n\nTiny shared **Hapi** auth guard for Zeko API services. It authenticates the caller and\nenforces app authorization by asking **uauth** (`user_authentication_service`) — the single\nsource of truth — over HTTP, on every request. uauth resolves the session in Redis, so a\nterminated device fails on its next call.\n\n## What it does\n\nPer request to a protected route:\n\n1. Read the `auth_token` cookie (the plugin registers `server.state('auth_token', …)` so\n   it's never forgotten).\n2. Call uauth `GET /auth/authorize?appId=…` forwarding the cookie (one call per\n   request).\n3. Map the result to Hapi auth: **401** (no/invalid/expired token, or `requireOrg` and no\n   org), **403** (app disabled for org or user lacks access), else **allow** — attaching\n   `{ userId, user: { id, name }, orgId, roles, permissions, is_support, authToken }` to\n   `request.auth.credentials`.\n\n### Service-to-service calls\n\nInternal callers send an `X-Service-Token` header (a signed service JWT). A valid service\ntoken **skips the per-user app gate** — the downstream trusts the calling service.\nCredentials then include `{ isService: true, service }`. When the caller also forwards\nthe user's `auth_token` cookie (the proxy always does), they carry\n`userId`, `orgId` and `user: { id, name }` as well (0.2.1), so a service acting for a\nperson can record who did it exactly as on a direct user request.\n\n## Usage\n\n```js\nimport { authGuard } from '@debito/zeko-auth-guard';\n\nawait server.register({\n    plugin: authGuard,\n    options: { appId: 'vm', requireOrg: true } // omit appId for identity-only (infra services)\n});\n\n// protect a route\nserver.route({\n    method: 'GET',\n    path: '/vendors',\n    options: { auth: 'auth-guard' },\n    handler: (request, h) => {\n        const { userId, orgId, authToken } = request.auth.credentials;\n        // ...\n    }\n});\n```\n\n### Options\n\n| option | default | meaning |\n|--------|---------|---------|\n| `appId` | `null` | app to authorize against; `null` = authenticate only (infra services) |\n| `requireOrg` | `false` | reject tokens without an `orgId` |\n\nEnv vars: `UAUTH_API_URL` (uauth base URL) and `SERVICE_JWT_SECRET` (verifies\n`X-Service-Token`).\n\n## The door out: `createProxyRoutes`\n\nAn app talks only to its own API. Anything it needs from another Zeko service goes\nthrough one route this package provides:\n\n```js\nimport { authGuard, createProxyRoutes } from '@debito/zeko-auth-guard';\n\nserver.route(createProxyRoutes('tasks', { crm: process.env.CRM_API_URL }));\n// GET /proxy/crm/customers?x=1   ==>   GET {CRM_API_URL}/customers?x=1\n```\n\nThe map is the whole list of what this app may reach; anything else answers\n`unknown_service`. Method, query, body and the upstream's status and JSON pass through.\nEvery call carries an `X-Service-Token` **signed on the fly** from `SERVICE_JWT_SECRET`\n(`{ type: 'service', service: '<appId>' }`) plus the caller's `auth_token` cookie, so the\nfar guard trusts the service and still resolves the user's org. No token is stored\nanywhere; the secret is the only thing a service holds.\n\n## The trail: `createActivityClient`\n\nA service reports what it did to `zeko-activity-api` through one client this\npackage provides (0.3.1), one call per mutation, after its own write succeeded:\n\n```js\nimport { createActivityClient } from '@debito/zeko-auth-guard';\n\nconst activity = createActivityClient('hippo', process.env.ACTIVITY_API_URL);\nawait activity.post(request, {\n    action: 'account.update',                                  // <entity>.<verb>\n    target: { type: 'account', id: 'account-bank', label: 'Bank', path: '/ledger/bank' },\n    scope: { book: bookId },                                   // optional, any shape\n    change: { before: { label: 'Bank' }, after: { label: 'Bank QA' } }  // optional, any shape\n});\n```\n\nIt signs `X-Service-Token` on the fly and forwards the caller's cookie, so the\nfar guard stamps who did it; the payload never names the actor. Anything but\n201 is logged as `[activity] <action> failed` and returns `null` — the user's\naction never fails because the trail did. With `ACTIVITY_API_URL` unset the\nclient warns once and every `post` is a no-op. This is the one function a\nmessage queue replaces later.\n\n## Service tokens for external callers\n\nA system outside the fleet (Quicko, say) has no secret, so mint it a long-lived token:\n\n```sh\nSERVICE_JWT_SECRET=<secret> node scripts/mint-service-token.js quicko\n```\n\nIt sends that as `X-Service-Token`. Internal services never need this.\n\n## Test\n\n```sh\nnpm install && npm test\n```\n\nIntegration tests: a throwaway Hapi server with a stubbed `fetch` — no network, no\nrunning uauth. Covers 200 / 401 / 403 and the service-token bypass.\n","readmeFilename":"README.md"}