{"_id":"@dota2classic/passport_steam","name":"@dota2classic/passport_steam","dist-tags":{"latest":"1.1.6"},"versions":{"1.1.6":{"name":"@dota2classic/passport_steam","version":"1.1.6","description":"A modern passport strategy for steam with hopefully no bugs!","main":"src/index.js","keywords":["passport","steam","modern","vulnerability"],"devDependencies":{"eslint":"^8.48.0","eslint-config-standard":"^17.1.0","eslint-plugin-import":"^2.28.1","eslint-plugin-jsdoc":"^48.2.9","eslint-plugin-n":"^16.0.2","eslint-plugin-promise":"^6.1.1","eslint-plugin-require-path-exists":"^1.1.9","eslint-plugin-security":"^1.7.1"},"author":{"name":"Easton S.","url":"sampli"},"license":"MIT","dependencies":{"passport-strategy":"^1.0.0","steamid":"^2.0.0"},"_id":"@dota2classic/passport_steam@1.1.6","gitHead":"e0ca773c3e4c50d33af54bba00106fceaa69dd61","_nodeVersion":"22.12.0","_npmVersion":"10.9.0","dist":{"integrity":"sha512-BqInTWmpBJNbwS2JobMGpulGR7puYew9z/qKhvQoXNs+APC3rg+ydMck/iecqCQYzkqPuZR9hsQF2gA2WEMPew==","shasum":"fad884ff18345648140b272272a3bcd3776c2f39","tarball":"https://registry.npmjs.org/@dota2classic/passport_steam/-/passport_steam-1.1.6.tgz","fileCount":16,"unpackedSize":52908,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICcBFewB6l9yKWE2nbsTj5NDJpr9V6144vzBWGSHeAJaAiBW7fuFut5I/mRKoUVka1+C5xKjP0PZe07HfDuu502kRw=="}]},"_npmUser":{"name":"enchantinggg4","email":"enchantinggg4@gmail.com","actor":{"name":"enchantinggg4","email":"enchantinggg4@gmail.com","type":"user"}},"directories":{},"maintainers":[{"name":"enchantinggg4","email":"enchantinggg4@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/passport_steam_1.1.6_1750246188922_0.08002151369856758"},"_hasShrinkwrap":false}},"time":{"created":"2025-06-18T11:29:48.851Z","1.1.6":"2025-06-18T11:29:49.084Z","modified":"2025-06-18T11:29:49.430Z"},"maintainers":[{"name":"enchantinggg4","email":"enchantinggg4@gmail.com"}],"description":"A modern passport strategy for steam with hopefully no bugs!","keywords":["passport","steam","modern","vulnerability"],"author":{"name":"Easton S.","url":"sampli"},"license":"MIT","readme":"# Modern Steam OpenID strategy for Passport\n\nA modern [Passport](https://github.com/jaredhanson/passport) strategy for authenticating\nwith [Steam](http://steamcommunity.com/) using OpenID 2.0. Inspired by the original [passport-steam](https://github.com/liamcurry/passport-steam/) strategy, and DoctorMcKay's [node-steam-signin](https://github.com/DoctorMcKay/node-steam-signin) library.\n\nThere is currently a vulnerability in the original [passport-steam](https://github.com/liamcurry/passport-steam/) library that allows you to authenticate as any steam account.\n\n## Installation\n\n```bash\n$ npm install --save modern-passport-steam\n```\n\n## Contents\n\n- [Options](#options)\n- [Usage](#usage)\n- [Examples](#examples)\n\n## Options\n\nThis strategy takes an options object with the following properties:\n\n- `returnUrl` - The URL to which Steam will redirect the user after authentication. This should be the URL of the route that calls `passport.authenticate('steam')`.\n- `realm` - The URL to which Steam will redirect the user after authentication. This should be the root URL of your website.\n- `fetchSteamLevel` - Whether or not to fetch the user's Steam level. Defaults to `false`. Requires an API key to be provided.\n- `fetchUserProfile` - Whether or not to fetch the user's profile. Defaults to `true`. Requires an API key to be provided.\n- `apiKey` - A Steam API key to use for fetching the user's Steam level and profile. Can be a string or a function that returns a string. Can be async if you need to fetch the key from a remote service!\n\t- If you do not explicity set `fetchUserProfile` to `false`, an error will be thrown if you do not provide an API key.\n\t- If you do not provide an API key, the first parameter passed to the verify callback will be the SteamID object.\n\t- If you provide an API key, the first parameter passed to the verify callback will be the full user object. (See examples below)\n\nExample options object:\n```js\n{\n\treturnUrl: 'http://localhost:3000/login/return',\n\trealm: 'http://localhost:3000/',\n\tfetchSteamLevel: true, // Defaults to false, makes an extra request to fetch the user's Steam level\n\tfetchUserProfile: true, // Defaults to true if an API key is provided\n\tapiKey: () => {\n\t\t// You should return your Steam API key here\n\t\t// For security, you should use environment variables or a secure key management service\n\t\t// Can be a string or a function that returns a string\n\t\t// Can be async if you need to fetch the key from a remote service!\n\t\treturn 'MY_STEAM_API_KEY';\n\t}\n}\n```\n\n## Usage\n\n#### Require Strategy\n\n```js\nconst SteamStrategy = require('modern-passport-steam');\n```\n\n#### Configure Strategy\n\nIf you want to fetch the user's Steam level and profile, you will need to provide a Steam API key. You can get one [here](https://steamcommunity.com/dev/apikey).\nIf you do not pass an api key, the first parameter passed to the verify callback will be the SteamID object, as you can see in the examples below.\n\nWith Profile Fetching:\n```js\npassport.use(new SteamStrategy({\n\treturnUrl: 'http://localhost:3000/login/return',\n\trealm: 'http://localhost:3000/',\n\tfetchSteamLevel: true,\n\tfetchUserProfile: true,\n\tapiKey: () => {\n\t\t// You should return your Steam API key here\n\t\t// For security, you should use environment variables or a secure key management service\n\t\t// Can be a string or a function that returns a string\n\t\t// Can be async if you need to fetch the key from a remote service!\n\t\treturn 'MY_STEAM_API_KEY';\n\t}\n}, (user, done) => {\n\t// Here you would look up the user in your database using the SteamID\n\t// For this example, we're just passing the full user object back\n\n\tdone(null, user);\n}));\n```\n\nExample user object if you pass an API key:\n```js\n{\n  SteamID: SteamID { universe: 1, type: 1, instance: 1, accountid: 893472231 },\n  profile: {\n    steamid: '76561198853737959',\n    communityvisibilitystate: 3,\n    profilestate: 1,\n    personaname: 'sampli',\n    commentpermission: 1,\n    profileurl: 'https://steamcommunity.com/id/shamp/',\n    avatar: 'https://avatars.steamstatic.com/979e4a6baa364403e1dc268a52034162044ae391.jpg',\n    avatarmedium: 'https://avatars.steamstatic.com/979e4a6baa364403e1dc268a52034162044ae391_medium.jpg',\n    avatarfull: 'https://avatars.steamstatic.com/979e4a6baa364403e1dc268a52034162044ae391_full.jpg',\n    avatarhash: '979e4a6baa364403e1dc268a52034162044ae391',\n    lastlogoff: 1716699862,\n    personastate: 0,\n    primaryclanid: '103582791429521408',\n    timecreated: 1534350460,\n    personastateflags: 0\n  },\n  level: 52\n}\n```\n\nWithout Profile Fetching:\n```js\npassport.use(new SteamStrategy({\n\treturnUrl: 'http://localhost:3000/login/return',\n\trealm: 'http://localhost:3000/',\n\tfetchUserProfile: false // Must explicitly set this to false if you do not want to fetch the user's profile\n}, (SteamID, done) => {\n\t// Here you would look up the user in your database using the SteamID\n\t// For this example, we're just passing the SteamID64 back as the user id\n\tconst user = {\n\t\tid: SteamID.getSteamID64()\n\t};\n\n\tdone(null, user);\n}));\n```\n\n#### Authenticate Requests\n\nUse `passport.authenticate()`, specifying the `'steam'` strategy, to authenticate requests.\n\nFor example, as route middleware in an [Express](http://expressjs.com/) application:\n\n```js\napp.get('/login', passport.authenticate('steam'));\n\napp.get('/login/return', passport.authenticate('steam', {\n\tfailureRedirect: '/login'\n}), (req, res) => {\n\t// Successful authentication, redirect home.\n\tres.redirect('/');\n});\n```\n\n## Examples\n\nThere is a basic example using express in the [examples folder](https://github.com/easton36/modern-steam-passport/tree/master/examples/express).\n\n## License\n\n[The MIT License](https://github.com/easton36/modern-steam-passport/blob/master/LICENSE)\n","readmeFilename":"README.md","_rev":"1-98f6f4f82d667ff0314cb33004055f2d"}