{"_id":"@elm-street-technology/passport-saml-metadata","_rev":"14-c62934ded08eef6f327da794549fc7db","name":"@elm-street-technology/passport-saml-metadata","dist-tags":{"latest":"1.5.3"},"versions":{"1.5.3":{"name":"@elm-street-technology/passport-saml-metadata","version":"1.5.3","description":"SAML2 metadata loader","author":{"name":"Jonathon Hill","email":"jhill9693@gmail.com"},"contributors":[{"name":"Ian Cervantez"}],"license":"MIT","keywords":["node","passport","SAML","SAML2","passport-saml","passport-wsfed-saml2","metadata"],"repository":{"url":"git+https://github.com/esvinson/passport-saml-metadata.git"},"main":"./src/","scripts":{"test":"mocha test/ --recursive --exit --timeout=15000","pretest":"eslint src/. test/. --config .eslintrc.json"},"engines":{"node":">= 6.10","npm":">= 3"},"dependencies":{"core-js":"^2.5.5","debug":"^4.0.0","lodash":"^4.17.10","passport-saml":"^0.35.0","superagent":"^3.8.2","xmldom":"^0.1.27","xpath":"0.0.27"},"devDependencies":{"eslint":"^5.4.0","mocha":"^5.1.1"},"gitHead":"75d420c23fbf72e12d4c364b67bdfb388989b465","bugs":{"url":"https://github.com/esvinson/passport-saml-metadata/issues"},"homepage":"https://github.com/esvinson/passport-saml-metadata#readme","_id":"@elm-street-technology/passport-saml-metadata@1.5.3","_npmVersion":"6.4.1","_nodeVersion":"10.13.0","_npmUser":{"name":"esvinson","email":"esvinson@gmail.com"},"dist":{"integrity":"sha512-czST9PmP/gaPSjFNsn/K4EU98lEBa2/bWYzNyXDl3FBLbwt6FSwngoKE2kB9opOvmHOSUsKwcy3EBnN6PFvWtw==","shasum":"15027e660cf2e8f37405fb965bc597683ffcbc8b","tarball":"https://registry.npmjs.org/@elm-street-technology/passport-saml-metadata/-/passport-saml-metadata-1.5.3.tgz","fileCount":8,"unpackedSize":14901,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJcNoGoCRA9TVsSAnZWagAAYV4QAJl3UvyuDrQsa9838KKF\n3Osrki+kesdUCb2mdSjw8FgkoHjpgZO2oUJwGB1be2q5O8extEPkVx1hb6iN\ne8FF83Zde31DwA52wr0OqsIUDY3jz3fVJNHWeA7DAjIzCxKMy6R1dMZ5FF4k\nXD8LmWvk/yI8PpHs/NzgKQOZHYUSCa76N+0vO+Sd5AgwZD5sfAYZgT6TvvXE\n/LUVnjO0os1uqtj6iEI1Ne4uSH3x5DT4rehI2P9gbEJpQYYydtq30oIdgAnz\nR1KJBu+5C/SIHoJQAvMyMJoKR7DLPS/uCSk2Cc26H8GDshxdxvB2jlyxgSJj\nH10jKL5/w5lCViHXVkCOt4BQWV7zqCbqfqtPXh0ZI3W4VZ844l/H9naVByHO\ncBoZEfotOB/SLHtUzxFgqf5MqC1GJfZdsodh86WWE9H9zlyoHKGnRMqcWS17\nNKDwQyrR7Sm/1UZtYe6KQ8VOeFgezJ72m2oXzlTEcyzD28OKYPIr+Elr9Yeq\n44xT6/U17M5eObC6wWAJY4abrs3frpuDIk1NtKaSyAHLy5rUXxIpjZmAW8xz\np0itneOmkawa4bL8GoKfQn14zlswBzgenb8Sx25UqbrEMpJLlHOXp+vjJV7O\n2be4ZpCWKGiibPyhZ18det3subUGQkXUW6tmnim7y6XXbGvV49N2/zv66NuI\nsct9\r\n=gPc4\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEAY24jx+qw5xR6fg8uC+W4Uy9u+3phb7oXbEci3E7rCAiEAj3wm2vRZCOjIljHv1DomHGoHM2ixC/v9y9c+x7Lg0Ys="}]},"maintainers":[{"name":"elmsttim","email":"tdedecker@elmstreettechnology.com"},{"name":"bondi","email":"michael.bondi329@gmail.com"},{"name":"buschschwick","email":"ericwstout@gmail.com"},{"name":"mattlorey","email":"mattlorey@gmail.com"},{"name":"esvinson","email":"esvinson@gmail.com"},{"name":"chrisheninger","email":"heninger@gmail.com"},{"name":"jwdotjs","email":"jwdotjs@gmail.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/passport-saml-metadata_1.5.3_1547076008153_0.49568326150675057"},"_hasShrinkwrap":false}},"time":{"created":"2019-01-09T23:20:08.036Z","1.5.3":"2019-01-09T23:20:08.285Z","modified":"2022-11-02T18:27:48.121Z"},"maintainers":[{"email":"trevor@idxbroker.com","name":"idxbrokertm"},{"email":"john.lysen@elmstreet.com","name":"john.lysen"},{"email":"skylar.borwieck@elmstreet.com","name":"darceloixest"},{"email":"tamlee@tryelevate.com","name":"tamlee_est"},{"email":"michael.bondi329@gmail.com","name":"bondi"},{"email":"tdedecker@tryelevate.com","name":"elmsttim"},{"email":"smcgee@tryelevate.com","name":"semcgee"},{"email":"pharvpro@gmail.com","name":"pharv"},{"email":"nx@nu-ex.com","name":"nuex"}],"description":"SAML2 metadata loader","homepage":"https://github.com/esvinson/passport-saml-metadata#readme","keywords":["node","passport","SAML","SAML2","passport-saml","passport-wsfed-saml2","metadata"],"repository":{"url":"git+https://github.com/esvinson/passport-saml-metadata.git"},"contributors":[{"name":"Ian Cervantez"}],"author":{"name":"Jonathon Hill","email":"jhill9693@gmail.com"},"bugs":{"url":"https://github.com/esvinson/passport-saml-metadata/issues"},"license":"MIT","readme":"# passport-saml-metadata\n\n[![Build Status](https://travis-ci.org/compwright/passport-saml-metadata.svg?branch=master)](https://travis-ci.org/compwright/passport-saml-metadata) [![Greenkeeper badge](https://badges.greenkeeper.io/compwright/passport-saml-metadata.svg)](https://greenkeeper.io/)\n\nUtilities for reading configuration from SAML 2.0 Metadata XML files, such as those generated by Active Directory Federation Services (ADFS).\n\n## Installation\n\n```\nnpm install passport-saml-metadata\n```\n\n## Usage Example\n\n```javascript\nconst os = require('os');\nconst fileCache = require('file-system-cache').default;\nconst { fetch, toPassportConfig, claimsToCamelCase } = require('passport-saml-metadata');\nconst SamlStrategy = require('passport-wsfed-saml2').Strategy;\n\nconst backupStore = fileCache({ basePath: os.tmpdir() });\nconst url = 'https://adfs.company.com/federationMetadata/2007-06/FederationMetadata.xml';\n\nfetch({ url, backupStore })\n  .then((reader) => {\n    const config = toPassportConfig(reader);\n    config.realm = 'urn:nodejs:passport-saml-metadata-example-app';\n    config.protocol = 'saml2';\n\n    passport.use('saml', new SamlStrategy(config, function(profile, done) {\n      profile = claimsToCamelCase(profile, reader.claimSchema);\n      done(null, profile);\n    }));\n\n    passport.serializeUser((user, done) => {\n      done(null, user);\n    });\n\n    passport.deserializeUser((user, done) => {\n      done(null, user);\n    });\n  });\n```\n\nSee [compwright/passport-saml-example](https://github.com/compwright/passport-saml-example) for a complete reference implementation.\n\n## API\n\n### fetch(config = {})\n\nWhen called, it will attempt to load the metadata XML from the supplied URL. If it fails due to a request timeout or other error, it will attempt to load from the `backupStore` cache.\n\nConfig:\n\n* `url` (required) Metadata XML file URL\n* `timeout` Time to wait before falling back to the `backupStore`, in ms (default = `2000`)\n* `backupStore` Any persistent cache adapter object with `get(key)` and `set(key, value)` methods (default = `new Map()`)\n\nReturns a promise which resolves, if successful, to an instance of `MetadataReader`.\n\n### toPassportConfig(reader)\n\nTransforms metadata extracts for use in Passport strategy configuration. The following strategies are currently supported:\n\n* [passport-saml](http://npmjs.org/packages/passport-saml)\n* [passport-wsfed-saml2](http://npmjs.org/packages/passport-wsfed-saml2)\n\n### claimsToCamelCase(claims, claimSchema)\n\nTranslates the claim identifier URLs to human-friendly camelCase versions. Useful in Passport verifier functions.\n\n`claimSchema` should be an object of the following format, such as from `MetadataReader.claimSchema()`:\n\n```javascript\n{\n  [claimURL]: {\n    name: claimUrl,\n    camelCase: 'claimIdentifierInCamelCase',\n    description: 'Some description'\n  },\n  ...\n}\n```\n\nExample:\n\n```javascript\nfunction verifier(profile, done) {\n  profile = passportSamlMetadata.claimsToCamelCase(profile, reader.claimSchema);\n  done(null, profile);\n}\n```\n\n### new MetadataReader(metadataXml, options)\n\n#### Options parameter details:\n* `authnRequestBinding`: if set to `HTTP-POST`, will attempt to load identityProviderUrl/logoutUrl via HTTP-POST binding in metadata, otherwise defaults to `HTTP-Redirect`\n* `throwExceptions`: if set to `true`, will throw upon exception\n\nParses metadata XML and extracts the following properties:\n\n* `identifierFormat` (e.g. `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`)\n* `identityProviderUrl` (e.g. https://adfs.server.url/adfs/ls/)\n* `logoutUrl` (e.g. https://adfs.server.url/adfs/ls/)\n* `signingCert`\n* `encryptionCert`\n* `claimSchema` - an object hash of claim identifiers that may be provided in the SAML assertion\n\n### metadata(app)(config = {})\n\nReturns a function which sets up an Express application route to generate the metadata XML file for your application at /FederationMetadata/2007-06/FederationMetadata.xml. ADFS servers may import the resulting file to set up the relying party trust.\n\nConfig:\n\n* `issuer` (required) The unique application identifier, used to name the relying party trust; may be a URN or URL\n* `callbackUrl` (required) The absolute URL to redirect back to with the SAML assertion after logging in, usually https://hostname[:port]/login/callback\n* `logoutCallbackUrl` The absolute URL to redirect back to with the SAML assertion after logging out, usually https://hostname[:port]/logout\n\nSee [compwright/passport-saml-example](https://github.com/compwright/passport-saml-example) for a usage example.\n","readmeFilename":"README.md"}