{"_id":"@dreadkn1ght123/auth-core","_rev":"2-566b6e1455934b3270607411b5c0cd32","name":"@dreadkn1ght123/auth-core","dist-tags":{"latest":"0.3.0"},"versions":{"0.2.0":{"name":"@dreadkn1ght123/auth-core","version":"0.2.0","_id":"@dreadkn1ght123/auth-core@0.2.0","maintainers":[{"name":"dreadkn1ght123","email":"dreadkn1ght123@gmail.com"}],"dist":{"shasum":"04c2be0a6a97fdc9d41c5b904c1967d8df80399a","tarball":"https://registry.npmjs.org/@dreadkn1ght123/auth-core/-/auth-core-0.2.0.tgz","fileCount":42,"integrity":"sha512-3HKB2hJphkz3xN9tC69CDjCZR9dox0P9jR+upl43EgjK3aKU+Uw9J5poboEUjX/4G8IXvq90WV0U5tZ1NuxtTg==","signatures":[{"sig":"MEUCIHzw1Nd/Pf5drRvheVVwMip9wGV/8O5CU1g9gV1RsXlcAiEAo83FfKsmwoacJtYi4fXrIlyWWSmpvf7llLrcauGWuzw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":112520},"main":"./dist/index.js","type":"module","_from":"file:/home/runner/workspace/vvp-iam/release/dreadkn1ght123-auth-core-0.2.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -b","typecheck":"tsc -b --pretty false && tsc -p tsconfig.test.json --noEmit --pretty false"},"_npmUser":{"name":"dreadkn1ght123","email":"dreadkn1ght123@gmail.com"},"_resolved":"/home/runner/workspace/vvp-iam/release/dreadkn1ght123-auth-core-0.2.0.tgz","_integrity":"sha512-3HKB2hJphkz3xN9tC69CDjCZR9dox0P9jR+upl43EgjK3aKU+Uw9J5poboEUjX/4G8IXvq90WV0U5tZ1NuxtTg==","_npmVersion":"11.6.2","description":"Server-side OpenID Connect primitives for VVP applications","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.1.0","openid-client":"^6.8.1","@dreadkn1ght123/auth-types":"^0.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/auth-core_0.2.0_1788174735036_0.4080650256273539","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"_id":"@dreadkn1ght123/auth-core@0.3.0","dist":{"shasum":"7fb4776e3bb8f93d9b3c62927eb55f1e4f982c66","tarball":"https://registry.npmjs.org/@dreadkn1ght123/auth-core/-/auth-core-0.3.0.tgz","fileCount":42,"integrity":"sha512-7XN4PQXf+LG+w2hiTqXGHaJ23fKlB3zbo9mbhIKh4Vo5a5RylIpx1eyZe9Fl5JmZdkDgXC8NvaqMfzqSWl4PJg==","signatures":[{"sig":"MEQCIDGU1AAlnG0FVC5Oe+SnUM+Ow1h6d9zRcJeBlWcy2bt7AiA2FwvFcqjzfW8Em0YeT/uITQNIQEktUQx7y7iz5m8sMQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBOEeT9kmYGTLZExuxxGYLr4RgVg7yrW+b19fAUICFeSAiAsazxyudljOsmt5p9HIaEKKCBwAJasOhml3FBIg9YxFw=="}],"unpackedSize":113436},"main":"./dist/index.js","name":"@dreadkn1ght123/auth-core","type":"module","_from":"file:/home/runner/workspace/vvp-iam/release/dreadkn1ght123-auth-core-0.3.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -b","typecheck":"tsc -b --pretty false && tsc -p tsconfig.test.json --noEmit --pretty false"},"version":"0.3.0","_npmUser":{"name":"dreadkn1ght123","email":"dreadkn1ght123@gmail.com"},"_resolved":"/home/runner/workspace/vvp-iam/release/dreadkn1ght123-auth-core-0.3.0.tgz","_integrity":"sha512-7XN4PQXf+LG+w2hiTqXGHaJ23fKlB3zbo9mbhIKh4Vo5a5RylIpx1eyZe9Fl5JmZdkDgXC8NvaqMfzqSWl4PJg==","_npmVersion":"11.6.2","description":"Server-side OpenID Connect primitives for VVP applications","directories":{},"maintainers":[{"name":"dreadkn1ght123","email":"dreadkn1ght123@gmail.com"}],"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.1.0","openid-client":"^6.8.1","@dreadkn1ght123/auth-types":"^0.3.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth-core_0.3.0_1790107872346_0.9899638192256393"}}},"time":{"created":"2026-08-31T11:12:14.757Z","modified":"2026-09-22T20:11:12.725Z","0.2.0":"2026-08-31T11:12:15.206Z","0.3.0":"2026-09-22T20:11:12.504Z"},"description":"Server-side OpenID Connect primitives for VVP applications","maintainers":[{"name":"dreadkn1ght123","email":"dreadkn1ght123@gmail.com"}],"readme":"# @dreadkn1ght123/auth-core\n\nFramework-neutral server-side VVP OpenID Connect foundations, built on\n`openid-client` v6. It provides discovery, Authorization Code + PKCE, callback,\nrefresh and RP-initiated logout primitives, claim/role normalization, safe\nredirect handling, safe error classification, and pluggable session storage.\n\n`MemorySessionStore` is deliberately limited to development and test. Supply a\ndurable/shared `SessionStore` in production. Keep callback verifiers, session\nidentifiers and all tokens in HTTP-only server-managed storage/cookies; never\nsend `ServerSession.tokens` to a browser or logger.\n\nThis SDK supports confidential server-side clients only: `clientSecret` is\nmandatory in every environment and is always sent with `ClientSecretBasic`.\nProduction also requires `publicOrigin`; callback and post-logout defaults are\nderived as `<publicOrigin>/auth/callback` and\n`<publicOrigin>/auth/signed-out`. Explicit overrides must remain HTTPS,\nsame-origin, and match configured routes.\n\nThe default requested scopes are `openid profile email`. Custom scope lists\nmust retain `openid`; applications may opt in to `vvp-identity` for optional\nbusiness enrichment, but it is not required to establish application identity.\n\nJWT access tokens are independently verified against the discovered provider\nJWKS, including exact issuer, lifetime/`exp`, signature, and configured `aud`.\nApplications must key an authenticated identity by `actor.issuer` together with\n`actor.sub`; optional email and profile claims are not stable identifiers.\nFor a protected API, configure `accessTokenAudiences` with the identifier of\nthat API (not a list of callers), then enforce the Keycloak client roles/scopes\nrequired by the endpoint. Configure Keycloak with an audience mapper that adds\nthe API identifier to access-token `aud`.\n\nKeycloak `azp` and OAuth `client_id` are audit/observability attributes only:\nnever use them as local authorization allowlists. Do not create\n`*_ALLOWED_CLIENT_IDS` or maintain a list of Keycloak clients allowed to call\nthe API. A separately documented and justified client check may be added only\nas defense in depth and never replaces audience or endpoint roles/scopes.\nThe SDK does not expose or enforce an `accessTokenAuthorizedParties` policy.\nOpaque tokens require an injected `AccessTokenValidator` backed by a trusted\nintrospection strategy that enforces the same resource-server policy.\n\n## Safe diagnostics\n\n`AuthError` carries a stable `code`, callback `stage`, `reason`, strictly typed\n`details`, and an optional `cause`. Use `safeAuthErrorDetails(error)` and\n`classifyAuthError(error)` at logging boundaries. They recursively recognize\nsupported `openid-client`, `oauth4webapi`, and `jose` error families but return\nonly allowlisted machine fields such as library/code, HTTP status, and failed\nclaim. They never copy an exception message, response body, headers, full URL,\nquery string, `error_description`, tokens, or raw claims.\n\nAn unknown library error intentionally produces an `unknown` reason plus any\nsafe details that can be recognized. Do not spread the original error or\n`details` into an HTTP response.\n\nFor Keycloak setup and expected safe claim shapes, use\n[`../../docs/keycloak-client-template.md`](../../docs/keycloak-client-template.md).\nMigration from `0.2.x` to the aligned `0.3.0` packages is documented in\n[`../../UPGRADE.md`](../../UPGRADE.md).","readmeFilename":"README.md"}