{"_id":"@dplabs/passport-webauthn","_rev":"4-103a5754c8213288b207339f58a5cfde","name":"@dplabs/passport-webauthn","dist-tags":{"latest":"0.9.3"},"versions":{"0.9.0":{"name":"@dplabs/passport-webauthn","version":"0.9.0","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"author":{"url":"https://danielpecos.com","name":"Daniel Pecos Martinez","email":"me@danielpecos.com"},"license":"MIT","_id":"@dplabs/passport-webauthn@0.9.0","maintainers":[{"name":"dpecos","email":"contact@danielpecos.com"}],"homepage":"https://github.com/dplabs/passport-webauthn#readme","bugs":{"url":"https://github.com/dplabs/passport-webauthn/issues"},"dist":{"shasum":"89e50b8c4d7023f8a81a2982338cd1b6068ddbbf","tarball":"https://registry.npmjs.org/@dplabs/passport-webauthn/-/passport-webauthn-0.9.0.tgz","fileCount":17,"integrity":"sha512-51GDCAXRsZYSUrLpcIPrWb9cZfdsm4EnTZUdcDEnvE+qeDMcrJSY550ixgI7XKOblna+iWaaG3sb0Mfq7ffU5A==","signatures":[{"sig":"MEQCIFNoTKusVOb5pB9o+F2zq+WhY9AFZfTII1mV/pilZ1k+AiA+v5N10935Ga4tji5iXZ36Nugn2A/bx1spy3OHguGIPQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":32898},"main":"./lib","gitHead":"13deb2d17cdafa86d6ab73a9da2ee9f21a90e72c","scripts":{"test":"mocha test/*.test.js"},"_npmUser":{"name":"dpecos","email":"contact@danielpecos.com"},"licenses":[{"url":"https://opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+https://github.com/dplabs/passport-webauthn.git","type":"git"},"_npmVersion":"10.4.0","description":"WebAuthn authentication strategy for Passport.","directories":{},"_nodeVersion":"21.6.1","dependencies":{"jws":"^4.0.0","cbor":"^8.1.0","clone":"^2.1.2","base64url":"^3.0.1","jwk-to-pem":"^2.0.5","cose-to-jwk":"^1.1.0","passport-strategy":"1.x.x"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^4.0.0","mocha":"^2.0.0","sinon":"^11.1.2","make-node":"^0.3.0","sinon-chai":"^3.7.0","chai-passport-strategy":"3.x.x"},"_npmOperationalInternal":{"tmp":"tmp/passport-webauthn_0.9.0_1708593581207_0.2726269922211615","host":"s3://npm-registry-packages"}},"0.9.1":{"name":"@dplabs/passport-webauthn","version":"0.9.1","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"author":{"url":"https://danielpecos.com","name":"Daniel Pecos Martinez","email":"me@danielpecos.com"},"license":"MIT","_id":"@dplabs/passport-webauthn@0.9.1","maintainers":[{"name":"dpecos","email":"contact@danielpecos.com"}],"homepage":"https://github.com/dplabs/passport-webauthn#readme","bugs":{"url":"https://github.com/dplabs/passport-webauthn/issues"},"dist":{"shasum":"8ea1aa3b86704e9ccd11ac8d069c8b1fa0b21065","tarball":"https://registry.npmjs.org/@dplabs/passport-webauthn/-/passport-webauthn-0.9.1.tgz","fileCount":16,"integrity":"sha512-dDXIhRIoNSYolybQZkPYZzdHJJtPLXWTZJ6mdvCxgkMuaWgQOJ+jH2Q+3g0PtoIWrLz0szE49XG6RY2zClaFsA==","signatures":[{"sig":"MEUCIBq6T8FrRZ+a0H3Lp2V0MCxHgUM5Fh/kY5edZ+27t61IAiEAlJminZa4aagzipj+OpxaAEeX2ihPr+bfUlWTRQOHFO0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":32935},"main":"./lib","gitHead":"3e84281fe5a1b7ab44ebd85abe770298aa169af8","scripts":{"test":"mocha test/*.test.js","publish":"npm publish --acess public","bump-major-app-version":"npm version major --message \"Version %s published [skip ci]\"","bump-minor-app-version":"npm version minor --message \"Version %s published [skip ci]\"","bump-patch-app-version":"npm version patch --message \"Version %s published [skip ci]\""},"_npmUser":{"name":"dpecos","email":"contact@danielpecos.com"},"licenses":[{"url":"https://opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+https://github.com/dplabs/passport-webauthn.git","type":"git"},"_npmVersion":"10.4.0","description":"WebAuthn authentication strategy for Passport.","directories":{},"_nodeVersion":"21.6.1","dependencies":{"jws":"^4.0.0","cbor":"^8.1.0","clone":"^2.1.2","base64url":"^3.0.1","jwk-to-pem":"^2.0.5","cose-to-jwk":"^1.1.0","passport-strategy":"1.x.x"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^4.0.0","mocha":"^2.0.0","sinon":"^11.1.2","make-node":"^0.3.0","sinon-chai":"^3.7.0","chai-passport-strategy":"3.x.x"},"_npmOperationalInternal":{"tmp":"tmp/passport-webauthn_0.9.1_1708599912933_0.6212708788933268","host":"s3://npm-registry-packages"}},"0.9.2":{"name":"@dplabs/passport-webauthn","version":"0.9.2","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"author":{"url":"https://danielpecos.com","name":"Daniel Pecos Martinez","email":"me@danielpecos.com"},"license":"MIT","_id":"@dplabs/passport-webauthn@0.9.2","maintainers":[{"name":"dpecos","email":"contact@danielpecos.com"}],"homepage":"https://github.com/dplabs/passport-webauthn#readme","bugs":{"url":"https://github.com/dplabs/passport-webauthn/issues"},"dist":{"shasum":"c9d1d5fbbf308d2d76db840bc65c729103c726e8","tarball":"https://registry.npmjs.org/@dplabs/passport-webauthn/-/passport-webauthn-0.9.2.tgz","fileCount":16,"integrity":"sha512-r/yFkO46hZ+90A5vCgzrlDd/n9cBUWOFAeYLAeuvX7uJ7nv+VqQGYZl72KWhItGWbsLvPt/Ise14n53xT56t8A==","signatures":[{"sig":"MEQCIEaH1FKJ0yWJ/ly5dTNKK5DTvRiIGxDskK3zTPWm+Q3FAiA+DKK+QgKvDZtaW6KV9ehzfZE5aEPS/qf0CYKIJr0nGA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34656},"main":"./lib","gitHead":"231ddd107d89d1714cec0d477e9933c0c3dfa925","scripts":{"test":"mocha test/*.test.js","bump-major-app-version":"npm version major --message \"Version %s published [skip ci]\"","bump-minor-app-version":"npm version minor --message \"Version %s published [skip ci]\"","bump-patch-app-version":"npm version patch --message \"Version %s published [skip ci]\""},"_npmUser":{"name":"dpecos","email":"contact@danielpecos.com"},"licenses":[{"url":"https://opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+https://github.com/dplabs/passport-webauthn.git","type":"git"},"_npmVersion":"11.12.1","description":"WebAuthn authentication strategy for Passport.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"jws":"^4.0.0","cbor":"^8.1.0","clone":"^2.1.2","base64url":"^3.0.1","jwk-to-pem":"^2.0.5","cose-to-jwk":"^1.1.0","passport-strategy":"1.x.x"},"_hasShrinkwrap":false,"devDependencies":{"chai":"^4.0.0","mocha":"^2.0.0","sinon":"^11.1.2","make-node":"^0.3.0","sinon-chai":"^3.7.0","chai-passport-strategy":"3.x.x"},"_npmOperationalInternal":{"tmp":"tmp/passport-webauthn_0.9.2_1783523308981_0.11063270784417112","host":"s3://npm-registry-packages-npm-production"}},"0.9.3":{"name":"@dplabs/passport-webauthn","version":"0.9.3","description":"WebAuthn authentication strategy for Passport.","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"author":{"name":"Daniel Pecos Martinez","email":"me@danielpecos.com","url":"https://danielpecos.com"},"repository":{"type":"git","url":"git+https://github.com/dplabs/passport-webauthn.git"},"bugs":{"url":"https://github.com/dplabs/passport-webauthn/issues"},"license":"MIT","licenses":[{"type":"MIT","url":"https://opensource.org/licenses/MIT"}],"main":"./lib","dependencies":{"base64url":"^3.0.1","cbor":"^8.1.0","clone":"^2.1.2","cose-to-jwk":"^1.1.0","jwk-to-pem":"^2.0.5","jws":"^4.0.0","passport-strategy":"1.x.x"},"devDependencies":{"chai":"^4.0.0","chai-passport-strategy":"3.x.x","make-node":"^0.3.0","mocha":"^2.0.0","sinon":"^11.1.2","sinon-chai":"^3.7.0"},"scripts":{"test":"mocha test/*.test.js","bump-patch-app-version":"npm version patch --message \"Version %s published [skip ci]\"","bump-minor-app-version":"npm version minor --message \"Version %s published [skip ci]\"","bump-major-app-version":"npm version major --message \"Version %s published [skip ci]\""},"gitHead":"30790f214e59245f0cde6f92d159f4e7fdc79730","_id":"@dplabs/passport-webauthn@0.9.3","homepage":"https://github.com/dplabs/passport-webauthn#readme","_nodeVersion":"24.15.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-paDNaZA7CpPH9FP7pZY5BtWGmkvh5j2hRvUGb/0DZ5LIgrU5VuhE4TLw94lcqjbjxOINBgdJcgnZnlWZoyQ+1Q==","shasum":"c9c75db6cc159f7fa17dea2d5da8f33d90133997","tarball":"https://registry.npmjs.org/@dplabs/passport-webauthn/-/passport-webauthn-0.9.3.tgz","fileCount":16,"unpackedSize":34656,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICQA1fgKEKaOwLHDJ5n3JYf6fsJgFQJhSxfGckJzJypVAiA5Sf3hL8DIrqYFWy46VN/+3SADqpOn4f0B696fFrhsuw=="}]},"_npmUser":{"name":"dpecos","email":"contact@danielpecos.com"},"directories":{},"maintainers":[{"name":"dpecos","email":"contact@danielpecos.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/passport-webauthn_0.9.3_1783523383839_0.5076434732589314"},"_hasShrinkwrap":false}},"time":{"created":"2024-02-22T09:19:41.118Z","modified":"2026-07-08T15:09:44.107Z","0.9.0":"2024-02-22T09:19:41.373Z","0.9.1":"2024-02-22T11:05:13.090Z","0.9.2":"2026-07-08T15:08:29.181Z","0.9.3":"2026-07-08T15:09:43.989Z"},"bugs":{"url":"https://github.com/dplabs/passport-webauthn/issues"},"author":{"name":"Daniel Pecos Martinez","email":"me@danielpecos.com","url":"https://danielpecos.com"},"license":"MIT","homepage":"https://github.com/dplabs/passport-webauthn#readme","keywords":["passport","fido","fido2","webauthn","passkeys","yubikey"],"repository":{"type":"git","url":"git+https://github.com/dplabs/passport-webauthn.git"},"description":"WebAuthn authentication strategy for Passport.","maintainers":[{"name":"dpecos","email":"contact@danielpecos.com"}],"readme":"# @dplabs/passport-webauthn\n\n[Passport](https://www.passportjs.org/) strategy for authenticating with [Web Authentication](https://www.w3.org/TR/webauthn-2/).\n\nThis module lets you authenticate using WebAuthn in your Node.js applications. By plugging into Passport, WebAuthn-based sign in can be easily and unobtrusively integrated into any application or framework that supports [Connect](https://github.com/senchalabs/connect#readme)-style middleware, including [Express](https://expressjs.com/).\n\n## Install\n\n```sh\nnpm install @dplabs/passport-webauthn\n```\n\n## Usage\n\nThe WebAuthn authentication strategy authenticates users using a public key-based credential. The authenticator which stores this credential is typically the user's device or an external security key, either of which may be unlocked using a PIN or biometric.\n\nThe strategy takes a `verify` function as an argument, which accepts `id` and `userHandle` as arguments. `id` identifies a public key credential that has been associated with a user's account. `userHandle` maps the credential to a specific user account. When authenticating a user, this strategy obtains this information from a WebAuthn assertion.\n\nThe `verify` function is responsible for determining the user to which the account at the OP belongs. Once it has made a determination, it invokes `cb` with the user record and a public key. The public key is used to cryptographically verify the WebAuthn assertion, thus authenticating the user.\n\nThis strategy also takes a `register` function as an argument, which is called when registering a new credential, and accepts `user`, `id` and `publicKey` as arguments. `user` represents a specific user account with which to associate the credential. `id` identifies the public key credential. `publicKey` is the PEM-encoded public key.\n\nThe `register` function is responsible for associating the new credential with the account. Once complete, it invokes `cb` with the user record.\n\nBecause the `verify` and `register` functions are supplied by the application, the app is free to use any database of its choosing. The example below illustrates usage of a SQL database.\n\n```js\nvar WebAuthnStrategy = require('@dplabs/passport-webauthn');\nvar SessionChallengeStore = require('@dplabs/passport-webauthn').SessionChallengeStore;\n\nvar store = new SessionChallengeStore();\n\npassport.use(new WebAuthnStrategy({ store: store },\n function verify(id, userHandle, cb) {\n  db.get('SELECT * FROM public_key_credentials WHERE external_id = ?', [ id ], function(err, row) {\n   if (err) { return cb(err); }\n   if (!row) { return cb(null, false, { message: 'Invalid key. '}); }\n   var publicKey = row.public_key;\n   db.get('SELECT * FROM users WHERE rowid = ?', [ row.user_id ], function(err, row) {\n    if (err) { return cb(err); }\n    if (!row) { return cb(null, false, { message: 'Invalid key. '}); }\n    if (Buffer.compare(row.handle, userHandle) != 0) {\n     return cb(null, false, { message: 'Invalid key. '});\n    }\n    return cb(null, row, publicKey);\n   });\n  });\n },\n function register(user, id, publicKey, cb) {\n  db.run('INSERT INTO users (username, name, handle) VALUES (?, ?, ?)', [\n   user.name,\n   user.displayName,\n   user.id\n  ], function(err) {\n   if (err) { return cb(err); }\n   var newUser = {\n    id: this.lastID,\n    username: user.name,\n    name: user.displayName\n   };\n   db.run('INSERT INTO public_key_credentials (user_id, external_id, public_key) VALUES (?, ?, ?)', [\n    newUser.id,\n    id,\n    publicKey\n   ], function(err) {\n    if (err) { return cb(err); }\n    return cb(null, newUser);\n   });\n  });\n }\n));\n```\n\n#### Define Routes\n\nTwo routes are needed in order to allow users to log in with their passkey or security key.\n\nThe first route generates a randomized challenge, saves it in the `ChallengeStore`, and sends it to the client-side JavaScript for it to be included in the authenticator response. This is necessary in order to protect against replay attacks.\n\n```js\nrouter.post('/login/public-key/challenge', function(req, res, next) {\n store.challenge(req, function(err, challenge) {\n  if (err) { return next(err); }\n  res.json({ challenge: base64url.encode(challenge) });\n });\n});\n```\n\nThe second route authenticates the authenticator assertion and logs the user in.\n\n```js\nrouter.post('/login/public-key',\n passport.authenticate('webauthn', { failWithError: true }),\n function(req, res, next) {\n  res.json({ ok: true });\n },\n function(err, req, res, next) {\n  res.json({ ok: false });\n });\n```\n\n## Examples\n\n* [todos-express-webauthn](https://github.com/passport/todos-express-webauthn)\n\n Illustrates how to use the WebAuthn strategy within an Express application.\n\n## Credits\n\nThis project started as a fork from [Jared Hanson](https://www.jaredhanson.me) great work on [`passport-fido2-webauthn`](https://github.com/jaredhanson/passport-webauthn),\naiming to refactor it to include some improvements and fixes.\n\n## License\n\n[The MIT License](https://opensource.org/licenses/MIT)\n","readmeFilename":"README.md"}