{"_id":"@dooman87/koa-shopify-auth","_rev":"1-53e0108828396201b6c6bb61d183b3d2","name":"@dooman87/koa-shopify-auth","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@dooman87/koa-shopify-auth","version":"1.0.0","license":"MIT","description":"[![Build Status](https://travis-ci.org/Shopify/quilt.svg?branch=master)](https://travis-ci.org/Shopify/quilt) [![License: MIT](https://img.shields.io/badge/License-MIT-green.svg)](LICENSE.md) [![npm version](https://badge.fury.io/js/%40shopify%2Fkoa-shopi","main":"dist/src/index.js","types":"dist/src/index.d.ts","scripts":{"build":"tsc --p tsconfig.json"},"publishConfig":{"access":"public","@shopify:registry":"https://registry.npmjs.org"},"author":{"name":"Shopify Inc."},"repository":{"type":"git","url":"git+https://github.com/Shopify/quilt.git","directory":"packages/koa-shopify-auth"},"bugs":{"url":"https://github.com/Shopify/quilt/issues"},"homepage":"https://github.com/Shopify/quilt/blob/master/packages/koa-shopify-auth/README.md","dependencies":{"@shopify/network":"^1.4.7","koa-compose":">=3.0.0 <4.0.0","nonce":"^1.0.4","safe-compare":"^1.1.2","tslib":"^1.9.3"},"devDependencies":{"@shopify/jest-dom-mocks":"^2.9.0","@shopify/jest-koa-mocks":"^2.2.2","@types/koa":"^2.0.0","@types/koa-compose":"*","@types/safe-compare":"^1.1.0","koa":"^2.5.0"},"sideEffects":false,"_id":"@dooman87/koa-shopify-auth@1.0.0","_nodeVersion":"12.7.0","_npmVersion":"6.10.0","dist":{"integrity":"sha512-BVcoPt/X1nm7HZQ4fFJwiAJki1LYLH7F5bv/khILLiQBVZkYmxk6nNcbVAL0PGauyHKVAxqd2t2KT5t7F6rQWA==","shasum":"56232df6a5f3883db932c0af5b6ff9d35ef7ca40","tarball":"https://registry.npmjs.org/@dooman87/koa-shopify-auth/-/koa-shopify-auth-1.0.0.tgz","fileCount":78,"unpackedSize":77308,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJe7Q0uCRA9TVsSAnZWagAA6ccP/iuZ5B1EIguHUDd4LOvR\nLzrq2tSDAdLF/6EEkR6JZ0aJrqlFIDTek3Oysnfx0NGRbJdSJsezcGOHy1i7\nnGmnNSgqDeLOeqR+ty6FJoi6TL0jWgGYPxGuAUePkUJhCIfATQNKVt46QCmg\n9dDMOGPZp+x5yoe3qLb+EkQP5UmjJ1/Zp8Qx7vkk2pxSpVWhDe92NZ5dV3v7\nHHOy45E4kQ1RpHoylLrFnJTVRTyjoEYg+Fe06EzEAmPEjYZKr581vphSbXAf\ntw7LKJvMZmN1Y6bqJFZWwTbDWLQ60M85fnq6ynh9dZE+Sqic/eY6os1COAnf\nGs2SQ1D2/a9gn2/O5J7d42A4a76xE3aR1F4TBU1W/4PG6HuHjYh04YIt9Gne\n1Ja9mPYhScsHnGv0tbsYxj8JE+6h1qqDzd8GhHcPHYsXhfiObjZD8FJkc5Ym\npZ9+7qF4uVm4Iz6ACuW2s7MNLxdzYC746yUummMMEHamWhuGwD8/AN+ChTp1\n90SoSRhboXRSdOodFBV1YYH43q1fc4hoPT60qc2GoyG++6XLDB5S4VWB3C4/\nbTQpJiHNQperOL7DQYFym0rK2PZk49EnQdBBFXmaLB+I8gxDEkYaJ+RqE6Ne\n2q2IMUhTRvmNS+r5flzHw8nZuug09S/wZvTMr9/s16CMf8lNr3UU6Fhf8HNR\nV8Kd\r\n=mL1m\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDj1/VDZ7GY+Iy4CNHcnADsVwdNKq+gyLE9aSZsofFyXAiEAwj7NVCRgchhOq+FRPUXzKd+ew0zSJe1GiGm+BhOJeJE="}]},"maintainers":[{"name":"dooman87","email":"dmitry.pokidov@pixboost.com"}],"_npmUser":{"name":"dooman87","email":"dmitry.pokidov@pixboost.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/koa-shopify-auth_1.0.0_1592593709727_0.32946331889592195"},"_hasShrinkwrap":false}},"time":{"created":"2020-06-19T19:08:29.692Z","1.0.0":"2020-06-19T19:08:29.875Z","modified":"2022-04-05T05:25:31.407Z"},"maintainers":[{"name":"dooman87","email":"dmitry.pokidov@pixboost.com"}],"description":"[![Build Status](https://travis-ci.org/Shopify/quilt.svg?branch=master)](https://travis-ci.org/Shopify/quilt) [![License: MIT](https://img.shields.io/badge/License-MIT-green.svg)](LICENSE.md) [![npm version](https://badge.fury.io/js/%40shopify%2Fkoa-shopi","homepage":"https://github.com/Shopify/quilt/blob/master/packages/koa-shopify-auth/README.md","repository":{"type":"git","url":"git+https://github.com/Shopify/quilt.git","directory":"packages/koa-shopify-auth"},"author":{"name":"Shopify Inc."},"bugs":{"url":"https://github.com/Shopify/quilt/issues"},"license":"MIT","readme":"# `@shopify/koa-shopify-auth`\n\n[![Build Status](https://travis-ci.org/Shopify/quilt.svg?branch=master)](https://travis-ci.org/Shopify/quilt)\n[![License: MIT](https://img.shields.io/badge/License-MIT-green.svg)](LICENSE.md) [![npm version](https://badge.fury.io/js/%40shopify%2Fkoa-shopify-auth.svg)](https://badge.fury.io/js/%40shopify%2Fkoa-shopify-auth)\n\nMiddleware to authenticate a [Koa](http://koajs.com/) application with [Shopify](https://www.shopify.ca/).\n\nSister module to [`@shopify/shopify-express`](https://www.npmjs.com/package/@shopify/shopify-express), but simplified.\n\nFeatures you might know from the express module like the webhook middleware and proxy will be presented as their [own packages instead](https://github.com/Shopify/quilt/blob/master/packages/koa-shopify-graphql-proxy/README.md).\n\n## Warning: 3.1.61-3.1.62 vulnerable to reflected XSS\n\nVersions 3.1.61 and 3.1.62 are vulnerable to a reflected XSS attack. Please update to the latest version to protect your app.\n\n## Installation\n\n```bash\n$ yarn add @shopify/koa-shopify-auth\n```\n\n## Usage\n\nThis package exposes `shopifyAuth` by default, and `verifyRequest` as a named export.\n\n```js\nimport shopifyAuth, {verifyRequest} from '@shopify/koa-shopify-auth';\n```\n\n### shopifyAuth\n\nReturns an authentication middleware taking up (by default) the routes `/auth` and `/auth/callback`.\n\n```js\napp.use(\n  shopifyAuth({\n    // if specified, mounts the routes off of the given path\n    // eg. /shopify/auth, /shopify/auth/callback\n    // defaults to ''\n    prefix: '/shopify',\n    // your shopify app api key\n    apiKey: SHOPIFY_API_KEY,\n    // your shopify app secret\n    secret: SHOPIFY_SECRET,\n    // scopes to request on the merchants store\n    scopes: ['write_orders, write_products'],\n    // set access mode, default is 'online'\n    accessMode: 'offline',\n    // callback for when auth is completed\n    afterAuth(ctx) {\n      const {shop, accessToken} = ctx.session;\n\n      console.log('We did it!', accessToken);\n\n      ctx.redirect('/');\n    },\n  }),\n);\n```\n\n#### `/auth`\n\nThis route starts the oauth process. It expects a `?shop` parameter and will error out if one is not present. To install it in a store just go to `/auth?shop=myStoreSubdomain`.\n\n### `/auth/callback`\n\nYou should never have to manually go here. This route is purely for shopify to send data back during the oauth process.\n\n### verifyRequest\n\nReturns a middleware to verify requests before letting them further in the chain.\n\n```javascript\napp.use(\n  verifyRequest({\n    // path to redirect to if verification fails\n    // defaults to '/auth'\n    authRoute: '/foo/auth',\n    // path to redirect to if verification fails and there is no shop on the query\n    // defaults to '/auth'\n    fallbackRoute: '/install',\n  }),\n);\n```\n\n### Example app\n\n```javascript\nimport 'isomorphic-fetch';\n\nimport Koa from 'koa';\nimport session from 'koa-session';\nimport shopifyAuth, {verifyRequest} from '@shopify/koa-shopify-auth';\n\nconst {SHOPIFY_API_KEY, SHOPIFY_SECRET} = process.env;\n\nconst app = new Koa();\napp.keys = [SHOPIFY_SECRET];\n\napp\n  // sets up secure session data on each request\n  .use(session({secure: true, sameSite: 'none'}, app))\n\n  // sets up shopify auth\n  .use(\n    shopifyAuth({\n      apiKey: SHOPIFY_API_KEY,\n      secret: SHOPIFY_SECRET,\n      scopes: ['write_orders, write_products'],\n      afterAuth(ctx) {\n        const {shop, accessToken} = ctx.session;\n\n        console.log('We did it!', accessToken);\n\n        ctx.redirect('/');\n      },\n    }),\n  )\n\n  // everything after this point will require authentication\n  .use(verifyRequest())\n\n  // application code\n  .use(ctx => {\n    ctx.body = '🎉';\n  });\n```\n\n## Gotchas\n\n### Fetch\n\nThis app uses `fetch` to make requests against shopify, and expects you to have it polyfilled. The example app code above includes a call to import it.\n\n### Session\n\nThough you can use `shopifyAuth` without a session middleware configured, `verifyRequest` expects you to have one. If you don't want to use one and have some other solution to persist your credentials, you'll need to build your own verifiction function.\n\n### Testing locally\n\nBy default this app requires that you use a `myshopify.com` host in the `shop` parameter. You can modify this to test against a local/staging environment via the `myShopifyDomain` option to `shopifyAuth` (e.g. `myshopify.io`).\n","readmeFilename":"README.md"}