{"_id":"@redwoodjs/auth-providers-api","_rev":"196-3f759164ca0b917541c7990c97a9c67e","name":"@redwoodjs/auth-providers-api","dist-tags":{"latest":"0.0.1","canary":"4.0.0-canary.370"},"versions":{"0.0.1":{"name":"@redwoodjs/auth-providers-api","version":"0.0.1","license":"MIT","_id":"@redwoodjs/auth-providers-api@0.0.1","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"baf26a5bda1b3aa804e064941bbd5e475b39ce2c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-0.0.1.tgz","fileCount":59,"integrity":"sha512-ky2QVGPgPFoT0n9xpdb+lZED/R0+zf2YyE2GE102lhp0Up5G8DY3/LLfBEsb0h1csOMInkDXEUa1RE1BywPqQw==","signatures":[{"sig":"MEUCIQCnznUzqj/9WTdy1JYDN2MyGVw+sOmCw4wn6eJuNW4InAIgFIAxIVYzrk4/vYjpSFAXzO18DbST7QnsMjr/YUvlC30=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":118176,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSIR9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpoPxAAixS7y7/C5q1YA2H3mWU8jPp21iVUMZFMY1yKeaZU5ZzW4boU\r\nV9qsVNik/zGjCCgP/8pG4012XdW38WwhY5J4OurEQ0s3k4WnQNwxyMZegML7\r\nFWLlT3n9cC17/ZlsoAqXKOfiuXR1Isk4I8cPzaQsP8MxpKSLV9HDLuU+QkaK\r\nGnhA1BgxZk3+J+pmYHRsughu0jUBOGGxiUR8dP0ttJpB4Gt8KzoLpqiq9g92\r\njabh8VvHthcKqbVOHBZiu50Kf1eRUFeFHiSB87ZCIU60S9pGCU3SXA3dCaUP\r\npUIwOOpv9IypjHdqTfsTcfePaW73/zaNtBnqk0KdiDgU4ea5MvLmhVwJJ1D8\r\nfaJfovYlZvp5Fw/iwODtpg6OgMjcd6crdjL4rc3004/AZXQkn9re73E+6+fX\r\n3liAM5AIpP3AsW/H77FLuOA9bCmZ+4wHhGYXiQxoHIcS+mhnxa0GExuJIzPe\r\nJN0G4UzSNY/kp4gtLTnWxx6B9Dkudw21VNwwLJdTIe0mG9inIUw0eAQPmbfV\r\njPgVPSi4TjpwxXS/xKs6tOeaSxb6wVE9tX+4tPkzMSPqXkhz/YSDoABshECT\r\n3H0VGlzxLegLE0UiEz5Vu/bYtveJWS2HKtTYUco9oioFYeLpgcTaxCw7x1+H\r\nDT5k7wNMtS5lIDxXXA/w+RlYvjjEuoBGJak=\r\n=V0t2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","gitHead":"3905ed045508b861b495f8d5630d76c7a157d8f1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"jtoar","email":"dominic.saadi@hey.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"8.15.0","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"3.2.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"0.0.1","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_0.0.1_1665696892809_0.28975541602951393","host":"s3://npm-registry-packages"}},"3.2.1-canary.123":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.123","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.123","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f550df90107c1d6af717f785a3cb715192437b5e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.123.tgz","fileCount":61,"integrity":"sha512-F9m+fBtn9okEf1pdr9l8gSawHSoFbXOrdXdb7uZhWTo7XZxm/WoPrknZXqgGnnX/0nWZx3r40qHHhHKxugnjwQ==","signatures":[{"sig":"MEYCIQDr0tjEuZvko4t+L9QuK8g+vZd1WbUs1ZBlo+RGYWcztAIhAN8/1H0FpJQyJ8wzZiZ96Z4v8C7MyO9aEtCsXPFV/SwP","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSI9XACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr0eQ/9FxOekHNsMQUlcBYZihCoOTyKDtPb0rcahEOv9ibBwVHvpnLL\r\nW05ku+9UVoGyfnhC5XR3SM2X4lM/QBDnakq02W+4BL2epw1b+WxUuaZUlutp\r\ntl3bpMRI2ln8MS0RWW2bf+H5PQevlvB/aF9vbsagOP3brGk0kiSnbEuOQaEb\r\nq3GUz4KxJFETBoEqgdr53g2kf6SX91gH7SrDWZ5hHh7llfEFu6nz7AyVUwf0\r\nRvBD3INYmXdlG4WhytibGurrXms+wOziHnMn9+TYe7S8UfN5udOBqkdW3YuE\r\nzx0yQNra4sm0LC6ucZ75besAozhqD+vPS2U9d04v3yx/L47s9uIud2jzVFYQ\r\nDilG1dKFQGcHHCbaD4BA370eRbx8BfYwJ+t+3riqj9L4TgVao+4kuHSPWlZz\r\nkHDyobZh2dnjBRUeKn/E+O63Lhfb5Zn69YwxxISN047dYNderFtYsJCkBlDn\r\n9N8a/sFr9QzfsodCriP2DNuOQQhm4Shlpqw7HstAbLzCEASFppUTHeTAYq5J\r\n9PUXsqrXa/UDbwlPg39PRkSU3H7SZZKVn2lJegbi75++yN6AKokcCa2ecoCp\r\nSdEz2X/qCfm+/3M3detBOiZyEkP3CamYzjRUS/4hsvGWUqFgWgu8JCkpcZ6o\r\ncAJ5ykgbh3tkQkz92fbmm2X2c0bKYTLKBJc=\r\n=2CTc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"79adb685eed4a01a79abb4b24ce17b312b4c79a9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.123+79adb685e","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.123+79adb685e","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.123_1665699671040_0.8201584710890255","host":"s3://npm-registry-packages"}},"3.2.1-canary.124":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.124","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.124","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"109e8782f44098bc6a1ef6414087af8e04095e28","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.124.tgz","fileCount":61,"integrity":"sha512-pjBaI5Dx5K5eTc2j0sWG7KgQu9WeselQQYOevU35xa2MIoKP1RHnjqvCGVN4P6+/Vb7QotMcUD65aKgh+Od4Zw==","signatures":[{"sig":"MEUCIG53bHPjPYN/vpwNG7nmqsgFDMqXGvhx/wksfJM0XjxeAiEA299P9+6iNU/jgPbMO7RwwsIH2UPbj/rVVz3tF91MLXg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSJ+6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqbsRAAgkZ/oh231fv/DNir5YTTa1ACrgenXtzhwyoDPskkNG/6N7VS\r\nwOIu5a2mz7Dwc+kyJhRhNZ9KHZhyZ9N8RD+T9BzK15hF6ZYbESxbIzg5JytO\r\nIOI9ERqrYlCuxrnUjvk3LT6YpyqQl80uiKoxhXoxe+TEXgZbIz17tsCHUhjq\r\neGHTzURgcPiGsYrwIqEftRx/lcFq1w/sg+kNiT3RNnkdUC/vVV+uYTSCXyrL\r\nZ+Q7re51IT0/oHsdNpYKyyABdVaCsAEh25vapJ3Jew/q2TJfZ+bCzae9hS8g\r\n/QtWslvyovd0TXawYrSNR7O1Iz4rea1Fz27sdTwu3VV4fQ0DFD+mSjdSy+jD\r\nI5kr6TXwQgvibMeRcYYlRaf2+IUQjnsKG3ZR5AJBuIm9XAgMNsddlr9XZ3KQ\r\nO2Iho0SN7PwzlDzAiE9Hwmdw4l3Ue8nRb/OdHydr/sTXSU+B8fz0Vx6g2qvp\r\nEdcAzcljeGmbmK32qSitDRPViLbjxIaXzF6tdEd77qsok2SzqtweOjUcs/uE\r\n9kbJtBAz6aQGBZEMMT6G/9bl2AzgPKiNeIwbyrKl3bh4HBdWoVbQ7zrBfAfg\r\nZ7qFP/GIt76olujdPQfRqgPTfBQ7k8QOznSrMjuHmfJYTD9P73MAlmrf9tzb\r\nbwLmAece947MGZzrfbluRFvwOROR+Ogelt0=\r\n=MNby\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c2f863d680f1d6bc1582676a46bb51605f9afbf5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.124+c2f863d68","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.124+c2f863d68","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.124_1665703866547_0.7901993763203063","host":"s3://npm-registry-packages"}},"3.2.1-canary.125":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.125","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.125","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bdd153c98b63838440e54190f322f48ef2e87021","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.125.tgz","fileCount":61,"integrity":"sha512-xAJ/B8F3PVkm0OQIURgH2VacmNQYu94B7H2iL2xW1Dbw2yI8WquzjwHbWx2IcVAnXH4FFF5hYRH5YAJY7o/hqA==","signatures":[{"sig":"MEUCIQDWwP07LaqVIv82Uk0Ns4z22kHBn3HwhTLRa0h+Yi8IBQIgDjcQAzCCys3QLH02u+/F+LnWvalzjpq8EN45Q5FXQwY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSKtAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmprBQ//ZNHjZ5SyYeA9QOVw+mQ2t13RXkvjr767zr/KksZkvIPmWW1u\r\n9obPBgyXSlXNCew9d4ROAhNzDzndyUN1Z8L172Bv2O/LJTbpxND8B9lHI8V+\r\nFcxs6AF1ZN9y3aZCQTfc84XsWnEctR47SaKSNy5buew4KQgTJWCgoLdqOTlu\r\nU6EJyRvMDfmnZmbPee5NAw76ygmxL1u7LOqmh40BX8JLZLpUb8kMxEuxSCJb\r\njTJkhJ7GYWpTAbFc31N6F0gn+ShSn19NxCT3vPw4zy4lVztdqhzLivytu6iI\r\n6yHidAWx77AB84B7S8Wzf3r3e1FyZ+J1FWOs1Kk0txqAtq6MIOY066grRRND\r\nCqIvBfqqnE+X9mlK++jBO2rxvRRSuXgQ02TPfufViK2Y7jzes7tP6xQUl1Mx\r\nZnFDfHUjO52aBX4fQMXignhGVpet/eHaMkQujx+WkWRNhMWeyi4aysSWq4xV\r\n60kCdYKKz6jBryTjyGdFAttjQqU1NqOqWVagOVKjTJE0bmO/H5HlilEK6DhF\r\nz4WmEf3DKtqj81p7SsfwHOL5OveyecqqsQgcYwz5ZK1RgWYIe9Kb4j5fK0qd\r\nXZkNfdXG6fblm7tUnJodW4OCGCD8U8a6Vcxi3FiUHfIruRyRo8DOTpj0LOg2\r\nwxAPdv0aCZ4shxjg2lKnKSQPGLnQZ8BuNWg=\r\n=wLxp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fa6546440e2b97519b030817cd89a613d0076769","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.125+fa6546440","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.125+fa6546440","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.125_1665706815998_0.32810397689599524","host":"s3://npm-registry-packages"}},"3.2.1-canary.126":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.126","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.126","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8d3ce13f5eedb47341762e702f44e4029e6c4221","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.126.tgz","fileCount":61,"integrity":"sha512-Swt1zkrTmJI1vQMyIf+lJEApSUsSiCBfg8ROZ1qBpWa3+tW5NneARrR1yslM8jM83keiIj8rIjAKHgMzj+/VEQ==","signatures":[{"sig":"MEYCIQCmC3BP/o4Ikz51kfwBHzYGAAIjT11nJDwh0UgJCK9cbQIhANP0IVV+nTLpHn9znQlm85IedGJIyYC6hRgIQZPBev0n","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSLMhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqxYA//VGJkQNBAFrb59z8zt98HEphWad3/begSKMbij5xmrtljDAAp\r\nRxa69qp/eOmFlYtriCU4IrbQ09Utef8PQkT+T4KxFn9O2ZyVfwtPcR84Z9rj\r\nT9m7bx6GYINtwKDX7eOZH2HQxgv2YPAILxmc77gma+rZ0yrr7JJHgsbiUuWG\r\nkXwZFdxVBekZcmw1QoV5afn4E7KRj0D/Ad766/aNVfBFoA5p6kY5VQxL3Vn5\r\n5JgVMEshhCEa84ThcZ440Wu7mEJq273TPKLLXfs66Dem2dcQueurdzhBVCcq\r\nYRIxC37WuSqF4r7Ca3E8yVmm81gIC/Jywwbp3jIpXwoDuMq5HjzqWCoTw7kD\r\nMV49TJ/3VNMqorcyr0pqmEEQSG4hUR8GDSwHfdRJzlMegMq7nYDWPSklrrhJ\r\nQMobCXZX1GX9Sf9BqXQhI9Xl8pp6wuJZVwE95bgXPV38FMOX2xe5CyROn/Kl\r\n0AbYvVua7qy4T4IGiXyAtX4bNWkhQYay13ORAZhcthoHzrugC5O6WIH0Cln1\r\nwqi05hV8jswdrf0ioavuVeXFwgxZkRAw3/bqjZly9mp2aobqX9ccG2TjQttt\r\nZycGrWOQJpxp0gyUEod5jsjtRm7ESBzeFLjVXdLWMlGvA/vsp1fIqLyF5s51\r\nWYL5eV5PnVecOkKSdtUVKCMIve1A8eeuf1A=\r\n=x1jg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8a107fff29f3da11ee218e741eb4131d60ec217f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.126+8a107fff2","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.126+8a107fff2","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.126_1665708832878_0.5818783023978216","host":"s3://npm-registry-packages"}},"3.2.1-canary.127":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.127","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.127","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c7d7208cbee4263d5b2c6f241f8aefaec3ae1aae","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.127.tgz","fileCount":61,"integrity":"sha512-mRcD+JDm4Sax8JflyFmT2COMIkDztyC4vQUW9SpyXrUtZ765DBHoUWA8aIzjjRPBxak1LeKYsdxEiACWnDd05A==","signatures":[{"sig":"MEYCIQDbbOjqPh5GG61BhoMbDsMACABYPSqzaDSUaE82buI/4wIhAKCq5wrCKX1TeTiPPHR80XLzPajE3+ZaOtqDHzvZ+j2m","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSLrQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp/QA//VKdiLLigf5Tk9ad/kY2LLdWO+skO3H+GwrrvQDa4Q+RrtTdO\r\nXh8LsFWOZ//FCC84GTXAQoxLfuBCoL8w6HI+NTQprFRhMRvaGTMWynoQZ31i\r\nexS+bMW36hbTq9p0ZRjU9Ob4Y5q5ooFJ8CMgW1nnGpG3cLzcXNX8+1fSj2KC\r\nAjtdeYcAMobtaMvGT6ECbwgnMEuj0JEzEi9AcX12oGO30Hb8q8LrjL23WIJT\r\nruEABMhfIjCOUfU78daRPurv+lwZiEWnLSv/3FnlRHklDQAj+iZjjR2X4JLD\r\nx8IkqHL9IjQB8R/CBflm7UDno9eT36SWs9ZwJiTQnGolQLY8GQumFq/7W3PD\r\ngKKUTxjXp8do/66J0y1dudwEKvAxDhtsbgh4Ms09h8jPiaJw5tt0fpDXrui0\r\nmiE+S2m+XnTFdT0Ytsv9BAs9eo0o3dZRe1u6/s+xNYK4cwS9XEJKXfdmkkWv\r\nuBHZxuxLFwtLZ9OBHdeeyXdJV9ncc5uvlW0eQpuNMChbkEz8UtBNFVtZLV5O\r\nbYEaoJdcE9VII+zQVpIMIMy1bdiazVTroB25BtNmCCU4c3TH3dCAs33yULqa\r\njErIGrYj03ywHEMm+/F6LwQlz054TN2+yifhme1QZwMWL4ivsFD4XZBy3aLD\r\nxaFWojU3KgGk7pX4fC6VAqBvP7lhxgozmG4=\r\n=tWyk\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"48725cea55ebad9914a748a9a45b60d360697682","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.127+48725cea5","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.127+48725cea5","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.127_1665710799914_0.0384390713449545","host":"s3://npm-registry-packages"}},"3.2.1-canary.128":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.128","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.128","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"24a3c060565c24a0d88bc9adac93e0334b5957b7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.128.tgz","fileCount":61,"integrity":"sha512-vuEcejMxeeIMLK65x6GRu6j6B/B43qHfvOL/boQs5JUr4HNf6DtYB4i29bXU8Q3mIf7rK5GA/jvcXiEqC1xM9A==","signatures":[{"sig":"MEQCICuljlVgTa4KJMXh999d3ePue+C19WBv6bEsbriL41BoAiA+rt/j33MziNunIY4vg9TOYYmgx5g1Wprwe9RLVYyoWg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSPbKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqRHg/+KXVAz5sw17ptyo6dRm3IBbU2JpHvCRyR0w6FBioOVo6GzOQ+\r\ngMkGLpc4wcaEPSAzV4u2yLcw/ExXXYiHXHDmFPEA/yeAtqkZimWWp+Hke5LL\r\n0lhgNDhracZU3R9YvI+Xg2prA5lbvdK6nljfnFqsUKXF31nHe7diaQialua/\r\nkYeQS3Ed1bgNGiPUfiKqjs3RqSQa9vUkOs2DoHkAQqCd3kRgABqedRaWWpIc\r\nAUnRqIOBEIknxGyLfEswo3ZFVow1bSsB2aJ9RgjB+Y1SiCTJXR4t4DO+S/TC\r\nk9z4YhO7eMSj4w3vX2P6x2IALqa3kY5GMh7VpUBACrrs6SIFgxBsLillS3Vr\r\nqCqfKmc/aLrbrYem7UgrdEOujOpiXdU+yGdRhx/+CoZgHNQXXxTqJr4MAP6H\r\n0gJT54BW71aKK4UoQjIhgSVpWp9drKN0nxkqZnuNPn3n6sCjI+f/tXQ8iKsp\r\nLTeZOlAKZucMOp3MRnPf5/48dbbZ4ZcpOXXrDwodjPPMeJiotIlnt02cfTUz\r\nMnLteM06/NGxHX64pTWO3+YJqzMwp5l5CeOrgEWvEYINpdFo+YGlje5wi1j7\r\npsXG7xRifpzMAsGo6ZPsX9bDAFKnHsuzJriKr1Xhz2hO9FJqx4rlFsIcgF1B\r\nlNyO2wzHQ7Gel5Ij0CahWqJIgj0DfshxR1A=\r\n=GX0j\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e956bf37219af9c767c099bbbe27c772521e93d3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.128+e956bf372","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.128+e956bf372","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.128_1665726154029_0.5774160904672652","host":"s3://npm-registry-packages"}},"3.2.1-canary.129":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.129","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.129","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"33167df28c8556aca0c179db5bc39475a79bca86","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.129.tgz","fileCount":61,"integrity":"sha512-KNHl5aTT6ZMyfB/9ZeEPrzC6AytWUVUgRT/9t998hGlhOFNo/0GZ4cw3UjmSPptO1GSm2nu1bLTIDS5Q8iFogQ==","signatures":[{"sig":"MEQCIGC2k4ju8eqGQ5JRWtsIYny+ShgByozuNwLkjwdCdozqAiAzsNc0DWHNsiuBBMb5KnTc2P0h+R4CkknsjUYFK5QenA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSRkXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqUEhAAozMPGmoKfXoD/f4UiA5BUMM3vBllB9sgtaiwjqo6yV7TnM+d\r\nWCP+Nd48nd1eUUBaVaiyjpSfLCprfzq4wrAl5zdamjjTRlf73VmgMXZKlrST\r\nqxM79kFqAMvmmiKDBM5l+zphWZ133MrpKJsPa0m95C5Nk+Nvj19vuAomVaZ8\r\npA2nWLvb47k1kwpVvRIVcjCathAOFBRq1J7Nn4rhE3BSO2rcMxv6/h4qzobX\r\nUXsSdPMFnIxpeumnPrdHBdXSi+1c3ZhMQBcwBLzwrH7chzgZw+64blRTvXEf\r\npiV2cXGgHfRjD5ZLqp3JezJVr3lDdWAepVDNmyrxMJ9bwiDrPXrhej++R6rY\r\ngX+1QZ0X/LkFU2YuIdCOzvsAKWC3Z2XKo9TcjIDqU63SJstoqq2p5XmzdKb+\r\n6gvAMGaoIE7/uH2SjJpPFBgKqFBYD5xg7ulEvIHS2QXEgBmIYi1mcH1YMRS7\r\nuvE3VzcWwluEu8gz3OHkvYSkNMUwbXR4P91Ncie72huYZKhBW3iYvlIFReZd\r\nh7WV9oWmn+CjQQDGrYL3IWfrOB/uH/5uPOsXfYhPBnBAuUecedHxzZzLjolp\r\nI5M9vQUv95wGmCEFauS7PYEQPI9hKKCNs3EH3K/T6470CUBLjF8VmchUjErD\r\nZ177dGmqFhffPL85etDh6ZigcNGE14S+O+4=\r\n=btnW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"53945158ca21301989511e287d1f3779eb66166e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.129+53945158c","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.129+53945158c","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.129_1665734935090_0.629365132675999","host":"s3://npm-registry-packages"}},"3.2.1-canary.130":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.130","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.130","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"299b90bed84b3723d95fb677924de31840e532e0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.130.tgz","fileCount":61,"integrity":"sha512-pvXaXzjxM1zDSq/BcGd6AQWk1M2uf0l21ksMVvdlMu8Pg5j7XrP8aHGysii2JxDs1XwwHWvu8jbhQA0O+L42Ig==","signatures":[{"sig":"MEYCIQDilEiBRsuhEMPG7cxE9+NAJ3/omvVGvD/Y8wv/vUDm2gIhAL3toN7JzxUTvU+PoTwyOBYMeS8pl4XscG3zxdVYub5S","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSVQcACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqAZQ//fstmDCHJOJ3oHpBSqO6F6r4RL+Ws8+Wxg7MrY23ApRfxJRR5\r\nn4A3Sm8VH47ng5y8jm2n8RzW0dmqKzyfDSeP6XadMu09ci5xtJsXAKVyEX3Y\r\nnouT2EzJ3UFhPXLxFCMvpdQRHRtxlLc79BCNMbtporteCVaqDhgmSbOCJTT+\r\nhVmExkRJ2W7z6DKkO12umeJphyH6XWhti3bGFt7+z80QFX/+xsInjqeOarno\r\n/EVKISaJHUWN8b2F0Of3hLFlUs7SF9pGZO86gh41xGT+7znOzdyxno8k8qBn\r\nTJphufSgDR8GCUfgAsqX2RkBTcvBtmuQStTUX/c+/uCGqE0dN+FqJN9dJ+Rx\r\nFykCk+D0mWXuTPMjpXP8a7wVra6w7UlsZ5fMiv1AKkNOGn/un11g6mTBrbvx\r\nlV3nyzkV84jfO8srW2NMosx9q+skMWqSwPIRMZhOmrHfOQL4nYgIWPOxHtll\r\nSVIVA3sdSpNSBVFU/g+o3tIrQmQ+QfY8owvMdLpywnRwrT+6BUo9ZIH8yAf8\r\noueaAYKhNVpL03shJk9xz57WCsFyQbIMUwl1xRZoLUsQbm2iMaXGbXoB7OAj\r\n615KQUX2UQTAAYQWSpNrrbfSg3xgYgcpmTgqQOusuWPVPhsVJ+Li1mtwox0o\r\nPAKSUjazjZyk2OM1QKM4/YLiOi74inn8Ng8=\r\n=is97\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e01750d967682b8117374b0b8b96a31f56ebf426","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.130+e01750d96","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.130+e01750d96","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.130_1665750044718_0.3891229616346803","host":"s3://npm-registry-packages"}},"3.2.1-canary.131":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.131","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.131","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"09648ef553ff50541d1c76998b4fb597ddae3631","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.131.tgz","fileCount":61,"integrity":"sha512-mDngq/Qqdvu4JSNJkvBpAy2E1zsCCi6a/s2dhRsa5UW7qlH1i7luUOVc66s/wT8VpOfEwxH3TTkXOwghw4xjhw==","signatures":[{"sig":"MEUCIH/0yMjg4a1vA+1HDtuww46VO9GSYEoY1UKnzqR5AIhUAiEA5cQEuoH+e9ytzfnznDB95zq9/EerDpgoo9S2LeWfv8w=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSV0AACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpBvRAAhG8xzKs2It97twFyrqn/7ATQkUKMOXZ9etDw5ePk1d+Uy6ua\r\npAo2ChBFvOhOavPGaD7RxQgSX2BsZtLUfdbmfaU1LjS6+H5mMaX2S812JBGk\r\nXECmDOaA1+wMSReZvkhnbtmleK898oQiEpufBcjEzIrosCl05dqD8IkIxLR8\r\npcj18d9iVZGUPuQ8MyaoBE6iS7VqI4pXHuEASk9Mv0XFb4+xs7OAiscgtPla\r\nstAkY1amgF9UWIkg280nQzg0nj5CK0uvOjM+g+KBZqvVdnfJ38Nc7uS8m5P4\r\nfZW5miLDiL2EQbf9d7BZoEaJq6W6QMTNMZOGhsMquvqhzS6ztMFYeIH6+I4r\r\nWtqZEB9avbxZXBhbsUAzqFM+GNLTwE+3JkT6lTlNh+NFqBtp0svrKj87f3uI\r\nWFCP2WuOWC/0+Eoo7SGmHdUlZCcQtYAvLQYxndzcQLymzE3sZ9kzzXMkpSbK\r\nhvJdjlFAyyVAZSgDOct0zol61hZ0h4YP1i0lgyiSseE7nEO4/3dSkSrWaSLc\r\npgUTBXWLWx5r7W1smnTgIi2fnC+EJ7bFadSLWU/rkSbGsQBN4EMa5yYpJOgg\r\n+9b65+wtZNjPWC1v6giux2iMws98BSrxHnwAQOdRAw9izJOXyXInC13jG8LG\r\n9kMboFTXDJYX2SV9F+RUQ0+ySB6x2WmdRBU=\r\n=T8LO\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7fbd6ba32b4ff4f9170ec51d5e7744e308094b9b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.131+7fbd6ba32","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.131+7fbd6ba32","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.131_1665752320073_0.9668837035637154","host":"s3://npm-registry-packages"}},"3.2.1-canary.138":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.138","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.138","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d91c0d0467329a8354ae3680497dd131a6cb0180","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.138.tgz","fileCount":61,"integrity":"sha512-CJl7qOmTkcsqmAN/l3HX4loxfScsJAjkZZQTw/vpGbrWDBBelN7yHtnT7g7Hth99uUqdKsL2JMu7mKbuq7u35A==","signatures":[{"sig":"MEUCIDmHZ/XkI4mQNU8uPhQdhTSrPv9vY+zXMCa2MSJ0pZk3AiEA0WLyF00tnqR2viYsNSQz6XsPNXIfYDGi8u8sne8vARA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjS05AACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr7jw//WQpXbxiUurOc7L4Pitt/BkUgwLVcbUb2PB5RMzHh8bR9XFgx\r\njzD3GpGF9RaFiITcxd4RyIcriWjWTbakmYGAiaga0pxprkdDPFNyn94uCPIN\r\n8wpIprLAdU+wYNzwOG0TEJwqu44xJMlYZ/+PB8mBVvxG/aWY/SyMl6R70IPx\r\nfmftYKhKtYpkglpXaXDJxZUR3tK1oa2rell2NBTtRDInM02b8JQzh4v8y0Mf\r\nNvQHYz5K/rXJb5mnFewPSKw/ZbNUbi9xdMaGpqe/JkByARlq75IbBmvWeorD\r\npxyhZzL52Rt6M6J6+43Z9MPUvmuWlbLcMoJHoJOrPBfoSQ5PruH3MCW5e1wX\r\neeVWOXYYo7aTN9g2+0YvFPtT0s1Omj5LD1NwuUBqhOSOfTJe/RL08WjZiOVD\r\nO0CP9ZCFSw4A+OM9K4BZuIgTC/ZI9kDRIp+8fZjdc1NUh/w/sQnDa7ORQWY/\r\nCcAtgeqN7XS8MzFITfiqKBhYq5GO4bS83G96/lo4qFwx0L78QfktSvXeL2Om\r\nrEwQ9XVEY9LdezhC/NrL2h4PPm11Gn32HXn9Jk8ORL5XeLcdmeUAV014wT5A\r\nTmQDnUNlmvp/CInn6sAa9icqPBQaMR1xq3gOjrj4avticjrjWx/PqCQG9ZEH\r\nxqlOQdc0PiQ56blxM0LV+O2RLa7HyAMhoAI=\r\n=zAiW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7b877e56647c5b5baa5eaa888b35e942e4500e0b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.138+7b877e566","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.138+7b877e566","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.138_1665879615741_0.8924092256794456","host":"s3://npm-registry-packages"}},"3.2.1-canary.139":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.139","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.139","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"eaabf6ffd6cb2ab9dfc4b2469fa483540894738f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.139.tgz","fileCount":61,"integrity":"sha512-ybmJstynESFuZt03vfEjiLHBxZpsPrn/HB3QGpaXMs6zGC5yg24FVENHAO50PHeujy70dW3q/geNdzWN7f1CYA==","signatures":[{"sig":"MEYCIQDrrtkcfXLyGKIqedC9MKfjiFjNZ1pVuiE526EtD1o3gQIhAPJAlmxHqqsJpDTTbn69HjOkJRfS+j34VxE/Uxf2YxXA","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWF5YACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvQBAAkV0uIDKckVOLHQVrFc4CiP/vNrZPP7S2a9dgElhRfzlWx9ud\r\nm7moTvINOYsefrhrw0nVRDyiORzDQbqnvxYEETotifJWYH8TKnHa4xUDCAK7\r\nzc+Y1nLdly2WiyLMqPiMoeNqutqlwvQ3aBkGqxYKt8esnhAGRe0g5Y6tMfwT\r\nmvAjids8GVQQYhBz+TTaVbvFC3a50RM9WbUpEmRiqWHORwI/qPg16IXkfB0C\r\nTh0817K3g9Ucygb287XAtLEJk2WkG+fTayYqF+3WkbgOraOvtZhh++2aE3O1\r\nbUxaPn/snVSB/KV+sPK2CtomEOaPyb7/tCiwvIkORgo1vo3mcvhpmYdOievR\r\n3OCb7dJ+IKeC6NpHkyAW5A7rPz7IlZpVdMiFNBPtHD+UVbJ/hjQw6ZXdUoq2\r\nGWL4+GS2rDFIVuaj1HzC2F0sK2uDhNA5IWswcwZLB6zLBBoXgQ1uHUS8F9Qu\r\nH2k/H9qJZxD+dT/iZFnymVoBHZX9SGGn+HxcsJJLmhgx0wGew7mpTtBvvA0o\r\nSfD04QlD6GxOOSMKZyQbKzXCYx30/Gm7NLNx18OMj1Ymn12cEc9qHuf4NfNH\r\niaen/lhGzAg9DGkupvbNPDQ7m4Xu5aGKidZauXZLBTsh2u4CjnZp/AELo+S7\r\n6VO6f5XwWKhGZSeMDm3jVVTXtHqNfTMMJTc=\r\n=Fa+/\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c604f3899275a47bad0fe63f5d97f335dd7b36c6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.139+c604f3899","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.139+c604f3899","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.139_1666735704596_0.7253918425813197","host":"s3://npm-registry-packages"}},"3.2.1-canary.140":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.140","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.140","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"407393f29088e6ca7332538bf49c0f0d6b708482","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.140.tgz","fileCount":61,"integrity":"sha512-umAdyTddzGagtonzzSIQwOtuOvxSAhqrg0GkBKwdiMGG4BDO7P6jxaReo4a92Xoq5JqdEpWlEhF82qY9EBqh7Q==","signatures":[{"sig":"MEQCIHfWfgYKiNVa4TAjmhUCYV3BKg5LpdFhDYgst8uc0jcOAiBrJkEZBtgZZChSIn8cNLnCgtntLOvEL0d5xOK8QHqVmA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWcFpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoyPA//ctMNIwm2lF43L55Ysb+mJcwBjUY5J3gUIrSWm0WO2y1aHIE6\r\nXNoOoAek4/Yh6BHalXtdzZP5hFpCW7cqahE8N2jcY4Aute1NokQiwPR9loL9\r\n7UCvfkckycAIxorHXI5b/oUQgSi9T2RznDH1CNQhCtNSJoOuBcTIZAcb5YkK\r\n/HTlg5UPcOJa3HzcEJ9IZBf2hyw5Ay+aWpIYfYgY6taDEILYqajmUimQSOb/\r\nCDG5b+Oa990Qbngtz4BUwnPPGObO9Gf6nUV+3IrDLb1YB3lI1sNMnEOlkSeU\r\neVO5JN2QP8y2fLA+MHyi8sNnuM6hg8hZCR9OdxT0qyAia0c4u1SskkJeo298\r\nL+sCYwCkNPxYNhP1EhCDluSsXYHevs6bAq1olmt00sVQY0s5xmFAnLVPEVzP\r\nzMd6PRrJdIZUFEWJuSrGfXbxwJOdFbnBI99rqasPtpP99dFRPya7QoHt3Cds\r\n5BLWPxDMFH+FIuR97qGxB70PNLQO2v2CsprIh+njoSp/dtUHSB3OwZp7K4F8\r\nC8/+cFEl9iZd7Gyl8uuDEXzTi92VbcFDQS5fplZsEZGETOgu7mzoG0v/GR0B\r\neRaip0acPMb7qh1ogP0RJEZTAhO9y0z+TwDN0K/sOURonwAi5DEVJvMw/7+E\r\ntfCTd3ljGrrGhIvGJA3LqoMEJGTWjW3mHPI=\r\n=CQF6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"971d22370910bcd7b7a484dd98a3a08029604206","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.140+971d22370","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.140+971d22370","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.140_1666826600990_0.20970331847815293","host":"s3://npm-registry-packages"}},"3.2.1-canary.141":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.141","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.141","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ebb73ca12176da0f90bc6fb5c5f8520b1ccade18","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.141.tgz","fileCount":61,"integrity":"sha512-0/EoGs+DkGiFNFdjAG2sWfHS1dBUQ0MS8tEn4wWPVcAnHTyRPo8y/Ahb9lmmbBTT7k566QOQPLWnkuh2ZS3b3g==","signatures":[{"sig":"MEQCIGtBxomPuw4qR4Yz7xBYDihf3/gXVBo5e6UD0+iStWY8AiBgMT1ZYNFuKIIj/HrtdAhTK/cLMRRdCLPzIY1Y95PqTw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWcd2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpg7A//XeL4gVI3bgIQBwnUmYr3XpEqyuxvanJrQowpXv94Cam7tRzG\r\nqPlXxClUGyEI81uyrpUT5EpXLrN+y5PHo1hnBzXG56YkDv+cis3S0KaYrTU+\r\novSOcNkkmOhAvfT1Iab9mhxei3GHkLAw0jWBYpQy9SdSgVnPfChUEMKU/oF8\r\nYpZgC9dHvadagjQEk9p6I9P2jCsMWOJ2EJdB5B0qXs1a8R5uvv3S+1mBXCki\r\n/NixVA6OroZrtPDgTCP5GipE1qecW1uugFNcxpiMN+bRPVqwIUQx08Eei8IN\r\nBZkogXDfFAhGJCQ5ZiX0P4YtuG+TP14DNgylEC/PsSiGI9+BfV4+Vcst21hx\r\n27O9BubFnXvdJswRln6jmtXIr5arZ6I8RD0Hq2pkHEKPf9DMJJ0VGlxotqLM\r\nAliwW8b4OZTFVPD6vw2nNf2LGRTYz8dk9ERW6ZVgX9smeMGglxjBU78bbVo/\r\nrFEnge805ErTQxSHlhDa0kTOgd4DFNSjetRZWr24GxIadPFIBveHNmBat0Yc\r\n3PkwaRTPonRVMA22tNE3FIBvZFtdw50nx1Iv8Q3UBAm2vMY9R+dJV5dI6VSj\r\nIMitA71VwA3po+mVe6OWVtSJDyiyf/7tWSW/q9Kryir5Hj8n4sM0YLbgA5Km\r\nDgP4J61p0o5FBfrcbzWk2lnuaWyWx1KJ+Qs=\r\n=vz9+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"570d7b49d1284194802d627278911fdd9881db0c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.141+570d7b49d","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.141+570d7b49d","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.141_1666828150182_0.9196191259276647","host":"s3://npm-registry-packages"}},"3.2.1-canary.142":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.142","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.142","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9b80b01e5db23f2b9ca2c13d84f355e9730d030b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.142.tgz","fileCount":61,"integrity":"sha512-3BPa+59tlsrddzZhq7rPB96BVleUgotKxt/mM7Uj7sMZMPV4LksteThE7dYV+vCASi7OoFk5jQn/yXt2jSWMfQ==","signatures":[{"sig":"MEUCIQDb0KojCgz5wKlWk72C6d+FdiqSU+wLUNwYLK9kWcxriQIgazbLromWWBFZwn5mSemENFNujSYUBkHtwOFMRUVFuqw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":245062,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdV6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrcAQ//SEdmQRiw4h1craj7vNxbpJck2IFX2btUmQulV/fJKILFR189\r\nPF1GwISjSh8y9IkK2T+/qty6Cym92zQmXNakCGBwpQhDew1JqYiqtuXqSs7w\r\nGD6+kfk4bSvdoEMMlcXS/eWHacabLf8E2YOLkOXhnd3xlRrIWXZiIfpULxhT\r\nAWKZg0MhPxm5JrMixIlxrgbd39avp5bmsDonR62zsG04K6jZilKcHgVT9R7q\r\nWtgT/KAL6p4hpryYxl5jCCC54VVv8mSS2YDewUzoLjrI4PW+VIqB02f9Y4by\r\nwDBAqf8egStDFpNh/yLLOQd3zPm8Tfahz1GovOR76q66JroQUcXLPJEBkRhh\r\naYv7wzLrJ7DjpArjliSGceHOrlMt6bzNhgqSdmhxUeen7U+/d4bPrfxIimsW\r\ntQDzoz7tprWvWo4SLxKj320bpqRZm3PRO/Ryr641ZZxSUfKpbXEzwiTAYQrY\r\nQEXGSR2K4X9LZlW9q4k7m3UJfDzHxdlXPGr+Be5cyWFC80pbkFZuJ3EnaJrS\r\ncp/BH82ji5e+7hGF1iY/AM6dUEMG0AEldRs3kyB52ryGm5HBJHWNJjBsn2XJ\r\njcFFGzyrhbxIShFyFrgjvjRKGxqp/D41yoVYaim/ku0nTR6osDroNirw1IwC\r\nVWNEeK5eTVcTi9B2wX9FUMEYjTID4BdRTzY=\r\n=BmAP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"af8970fd52f22a25a9379289c70630370e616fad","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.142+af8970fd5","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.142+af8970fd5","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.142_1666831738109_0.8753093844499504","host":"s3://npm-registry-packages"}},"3.2.1-canary.143":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.143","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.143","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"eea044c06006ba40732073e7fbd630b4ab99084e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.143.tgz","fileCount":61,"integrity":"sha512-7Bm4XTlcg4ziRSIMhAAI3VZkuWgThm8BtzXAMNMT9mSLs1GSGPzI+N7cm5lvDCEgBjLmvj1boOXGwOLNrkCHvA==","signatures":[{"sig":"MEUCIQDSNzWxAo7o/8tMqDCFZzH1zwjd1Hb0I5VxkUfUxJhBBQIgWvhHHKifbWU8vjUlOZVn9+FSBMrv952UlaFlAtAEVZI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdfIACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvSA/+MEPlfdzITEo8oncJeqhbANZyErN0dHL1JcELWHHz88OA/vpc\r\nAkYDlcsbW33whLHnZBb9S0QEiYf5v9hVQTVwYiaxF820SKWtN5HLvQJdyxd9\r\nxi/So9bnPB37VSOA3zEwegomlNQ1ka+HNMOY0RjkzNyOyCLbMY+AI09og28Y\r\n5MFzG2e/si9z1Xsjb+xF/pjdKYfusZFgr67D0mO7O51CB9N79UENKKB1KtOe\r\n0AuEE5FSBhsHix9LBcm7ZhU7B3zaJIQYxvnVj2Ptt68GbWvk8LKij5FgFeYF\r\nEysi+BVCE2QREjTvhLyYMVxy33SMy4g6CiJeYuVOd5t5iva4Mb4fTCB3Bkop\r\nzes6NxOzQUmm0Gei7RlhXCcu8k9sgcpHt/EWjPBUi9IJymPDcfVvZe2sBlKS\r\nv7wM/O+jHZiYm5376jHsE7KE6AjZ2laHkL+VcdGH6jWnc2X2vLka0b9MRgR8\r\nz/BQ8cyWI17EyXA9nK+XOogrhbsKgjM+DL2fPmw5i7Nh20tu17N5O1eFvhlv\r\nh0Mdudk3sGFwsdz7AzQhBez4Oa9SAHNIj6/KRLTpZ/73EUNOD7u5lama0d15\r\nSQsvElWXvJc3ZYdMgabnB3c+4L/ZQcHdkEPIRgHcRi5zhktEBHFWmmJOA8Es\r\nJYIHoInTksQ/JOfnRYRY8oFSKtMo8qEM58k=\r\n=Sadu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"204ad9a8c659187debee48eef0861b18cea36ad2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.143+204ad9a8c","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.143+204ad9a8c","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.143_1666832328260_0.019443143674646723","host":"s3://npm-registry-packages"}},"3.2.1-canary.144":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.144","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.144","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fee78364cab71d390e9ea70a3fef983bbfbec7cb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.144.tgz","fileCount":61,"integrity":"sha512-nWkqoSRBRSgicb/vhnY+IItFBce2fuyzN391PFCLUu0jjZgEyhk8YtACDFAF5IaZmvO6y9nOKQCIzAnqv/NOcA==","signatures":[{"sig":"MEQCIBA0Fatepvks8ycyT8W+KQWJHbTUduTVCMv8dnWGqgjSAiA67byl7Bm+yIT9gvp2hEXLVll9UHjCpntsLktPvuum9g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdf9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpQBw/+PuWKzAiySm5L6aU6ptSAmDo2c4aTlwNrX4q56JM8lJEoG9cE\r\nEHQY8pxdq8cUC8Cej86Ptgs5k82TkhTvrxx1tDJWOvVg9BOhAUbJ3KH4QgtG\r\n7ePcqN+pkCx2DlIIm6qHeL3CiDhXxZbXxJDzptDmUKqmnJvLyvuI+eEFFyxI\r\nj+PSxm9eIzdjtkywRpO21FQdXllolWzyoUZHe/VMLIO5mh5dcz7hDT9x1QHj\r\nSCPaC/iJGrCeLdJUUdWmA0jpyQ3snTXptCzRjy5PhAY+hfln2fDLVrKlUBdR\r\nVt85cZRRe6z3CP4Dnk+mzyqmUjF+K2CY+TvB9O3dhhkqWWKHvb65Cm2y8eH3\r\n83t7DwtZPNIv93mOzw54l4tigBPywY9i70aFGnWo+2UHO45Qd7+wmKqbUSUK\r\nB73hQ7KI2Nw29W/zGdQpbr61dsPi01O2RQGdsEoVBKZKI81v3AAUv57xkhXG\r\nNWxzBSHzJJEza6By/RmgyuZoq9yjOih+P8Ikr4vkKsQhBczPXY4psA0HC4go\r\nNxwWcrsmTJu+UCFWFLUmNoZ2/nGiKEcJxfZY3hyHWCA0OYjK9Dewe16TJ1EI\r\n3lwPWnDxVx9vQsol0m/7UaPR/r+txOvbAtT8Qaz1Jx004rJUOCd6r/surbIY\r\nX3ovsD3bjttuqjz2e5mD1xRVxjrg/AjTTjY=\r\n=scCt\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9a2609355954864802bb6075bb64e56e69918bc5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.144+9a2609355","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.144+9a2609355","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.144_1666832381084_0.9082538576181183","host":"s3://npm-registry-packages"}},"3.2.1-canary.147":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.147","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.147","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cb5d9647ab909ee5a2d7f59022c0733ce82dc7a5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.147.tgz","fileCount":61,"integrity":"sha512-Y20xhjbazhQK02pL7qyIuL2poUiSs74nhmT3SHO3JB0HUSMVFORIEw7mqRrKUmyKKF0hIAuYGNDQjMrt4Bqhqg==","signatures":[{"sig":"MEQCIDt6SVln6b8GrObVfeU68ubJVLyIV8JCya+bp9XtQsjgAiBtimON4vQla0BiR2GZTdZB8ajf4r2QwCzU4+A6MBqCIg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdmzACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmodDhAAmh1mc8p7luyZAYLdtQJMgEKFIteZNhEmHjlCO2hRBcyhydwx\r\nnGC0y9Xa4mlUCOA2BnX5hAUnLSvpPzQprv16042oITDOlnb/YQ+8SwGDfRNI\r\nxZWdKywZPgjE/+fB3Gt2iwdAPnr+yt9961hEIj6cY9TK1tLgPwYPlQFoHCjZ\r\n4rgr1eNjSXlJnxBGfJB5REeFGG0acJ8DNGVTJiZiiEt4itI2rTIYmEKNiPMJ\r\n4e1w6zrsjbbC6hA0KZZgiKJp4YQjmOmRI81xKtSSGIbt8OAiaPbmGfIZrhrK\r\nGrmD9CHV5auhahijpGaPuK9vYpvfqGv4oybTBZaYElFfWlPptGOi48b1oRW/\r\nYo9fq9i6EZaQVKrKCXyU0Ud4EldC54GGfNcD4i8XWX8t9N/upnJK9WLgm0Lj\r\nIC8hC71UKUZt/tp9v2aHYvur0H31CdA5w8ew2SxljCMVQpZTjDC0OwF9n7dn\r\n5yONh++CrxjLSZiYcsEEDVQtO09auqoYl3gaJUNel/zbSsLO5lA+lJrmdpUz\r\nCod9TGZIKr91B9SZpPZUaRWe6scZGyNAuh8RgalP3SSpKSk1wrkH+RcAXkyq\r\nwV/tbPTxFbGotLIkT0lbjGc3dJn4l1XWD1rO0mhpq6YZHQXlp4VLPjbDVybT\r\nJjy7gqvEJwr1Hss6psMB04jwSXNogxUCsqc=\r\n=TvmJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e05e08071548f30f8020012a23d7439b7b71c58c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.147+e05e08071","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.147+e05e08071","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.147_1666832818929_0.5951683802504673","host":"s3://npm-registry-packages"}},"3.2.1-canary.145":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.145","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.145","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"50d215f2ab60d03d42aeb276e8e6e90f4e27b330","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.145.tgz","fileCount":61,"integrity":"sha512-zF/sigoeBBzhsN+1bBbnnEDo3et/ClLDR2wpUNV6xhCQvYAjhEpIs1fkxwqZBW45wwZ+g4ZSR7AcOJVCYQHcxQ==","signatures":[{"sig":"MEUCIAEigZ6YgRIAKriuFXjxiM7W8891x9//C1BWekZcCX9tAiEAk0FctrtU5qmbpqwK90MlU/x64a1KIQdvyZdtPjOrP+g=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdnrACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoZMRAAnzTQXjRRvl7tOClk6KJokleVqBHvF9wgocYDOVky8Y+qCx4I\r\nUfj50NewDn7w9EaRGlnjxQleGy+qBnQ7TtNXicMxOUJ+Goi+vUhwlVFrBIkn\r\nHun4KYW3vaqBBcloLBtOrLU5UrmwyYtM5aMGqYL0NBffs+0EWVUdUSdbZ9v6\r\nwdgzQ//KdYauKhpfpqcWQtnzbrhAQAFRXi7DAzJS1U/p6M7ccM6+OH3tTQ4X\r\ndRSj9Z29MaU9r/fmYnxJbJLGZDaOjPPTsJ8lM5z7eJDgn1b9qxhh0MsUFrhf\r\ndPiFNz4hItv3/k55owc1btBmSjzzlnI/SRNwknRx5FLXIExTBfkXzue96YmX\r\nwSr/HR3YNtRYuXjxS4fwTkzQUo4wfkh2TO+7S+O/Fhe4FoKGFwX+oDEwbPit\r\n2PovRjhzssT81Ddo0DZBUGP/kw0h4aX5TPFa0BIV++ARzj4PefWoH+wHjwLd\r\nZ/2mE/FgQhC/kCzOwhCbF4tL8Vb94aOru3RsfAOD8tk6PJCd5Gh1UQO5y399\r\nCmHCb/slbaeswieoB6vuZ+r3pNmV3272KP+aWWLK+fF3yPDZ3TR5ZdycJMn6\r\neesPL6wkkziquxSObNlaunJO0roOFFWGXpGL5Ut3GVokuDtTXwHcQRyFcuxQ\r\nZOzGH8J7qBeYM0sJdwXitApLSQdJGyi72og=\r\n=1Q8p\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"50586ea0be78655a89adc88da8194129f2a9dabc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.145+50586ea0b","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.145+50586ea0b","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.145_1666832874847_0.35659251236180567","host":"s3://npm-registry-packages"}},"3.2.1-canary.146":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.146","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.146","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"60b179973d726179236bbd8700f7e6a42a02707a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.146.tgz","fileCount":61,"integrity":"sha512-ylZWTwRuTHUt3gfZ8Mce6KznG1Jo6UwbwZxZjN/4LWcQV/nNxP+T826TTSBPdYb2cQ6Ce4Qosu0QRhOJsKE9pQ==","signatures":[{"sig":"MEYCIQCOU/iAIF+UWQy4DSU/nz0Xk1SgByTy6vMq2OVajItcbwIhALndlbO7uIghfYFu8hbIfxcfvgoYhuNsjXstQZB4l/n0","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdohACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrqDw//SgQOIDakCtxQLqeJoReRhdLR9RSNvQC9XqwIRJHlTFxVy7YL\r\nAf/uwjPa23p7GO/NPdzlqCV0YT5wj1V8EwACfPsFJIMhKCZolY4ZwCwX9K5u\r\ngsCqidUP7NDgFHj5WJsTIfl1lBiBqhwYTHIV0tzGHM7z8jP5l02Ks93zb/6p\r\nJ1xTlFxu7i6TSCMZDIBr/tZFYyqv/C7ZiC05ZZXHDLtWc1o5g8Euem9YvsuH\r\nAPSX5NEH8QcsjmMTrJanucl0HREsWef72xJHuMT2Yw4yghVX6qLaK/XLhyx6\r\n/Eo/c6RIry+KDgMWPL8HEf+XwHr4tgo30GQmrastKeNQMZcU4AEuY6pB0yTV\r\nDQyrYhR+dxmuc/sq1Ta/XbfgN0+BrNSs3pxPih/qQnNeyGY/fpLNcK2gdkJ4\r\nAUgKekA/C3KRJiTNv/2KHYpk/AfyWHI7RCyH+uPRdrYfWBSg6JrRuY/BYPQ3\r\nm7Ig91aHrQDHNYperGYbLBwra5DtsJVqrGAZOsMrJMoQm0Bq7669Ye1oNM6o\r\nvIBOA6HlEO0HRq4JYSSVAnJi0aWkhQ6Nk2VOHLyaFvMi4b5EAZGDQCFMmZhv\r\nmX8i1JU+lv2S7JIXNz2RIXwE536xox7l/84T6AxoO1Xfyvv8NcY1lRKOLwNE\r\nvNkRcldxRWOQx6tFJ4yU/K5a/mdyERn35KM=\r\n=zWKJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d0be5e823d45510852bad067f541f2605ba1e5cf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.146+d0be5e823","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.146+d0be5e823","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.146_1666832929671_0.18712491341265958","host":"s3://npm-registry-packages"}},"3.2.1-canary.149":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.149","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.149","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"42e0be5bcf9e6e7550c188949b0e84fda2df416e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.149.tgz","fileCount":61,"integrity":"sha512-G3eqrckah7x9BCaIKQKkajxcSDbB8TwgvnoKiO67zfGh3ZgXgHsGfoqLB6thWbULgXzXaw16CoasTT3aoMJJCg==","signatures":[{"sig":"MEUCIQD67p8MsAlrPEHHABUzX6iB6SnCIB5n6bmoV9oUtzn4+AIgEAB2kC/6AhTXRWCrvGSzeRfnaCTIv0Wb5O8eglmTWtA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWduKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoGHg//R9XH5uihgSMxij/Aj/xF8IY+mHQOkL872sGaWgdvOTLtvQtD\r\n93IQBZ+XAgnjIWndq3YuTC3HL1iSqspbalE9GhfIk8Yav7BW1WX+M4Qrc9D2\r\nTYM4rts3uwwRM3AwK98oUtEFZYpl2q8Dzc5aUqZSaAJ++yWDtsJ+SX9IB3jO\r\nGNBODd4zM3ZQPGkU4hUn8jkdWrUuTKvlvOC1tXDUmaFR8IDehrWrpLcG8e/+\r\nfOSX5/ogvLYs/0OQihXTH7rwDScGvtTtowhCkNebtmSwhGInC/+hV+14ZDJI\r\nmMUoO0c5O6Kf4rNzCsmdYFu/gy6IXKo/ekpk/mw1zIpXvoN3Kpj08s4Bog/z\r\nD9AEHyt9s6VVygBZ35vgE82IBywJn8qw+X0cheQ2pcEGRH62vbDY4Csdc8cL\r\n+1cWtfyaZPF3ZFYUc0w3liREWyPZfVZ03JLKFFokhwpdsP88Qn6SmJUedB+j\r\njdywRogF88gyeUsufWI/loqAbCHDALg9iXTF5ZflcIvYDPo0m/FkQojO5Ufz\r\nAS5A+JylWmCL1zpCm+3s/bB8HIuhL0FnBLBRPciYEva3e+2bS4gT4C6NRZfU\r\n0Fr/PDd4vxlmxRyrPBKTIBBM9sOLXcrocT6uQ1RGMdthc8X5NZwPJnui2r+N\r\nukCtZqgQz1VvmE9G9p8KmN9njrwX5TM737Q=\r\n=ZsDq\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"810f1fecf815c111f0ebf095d07d7455e60fb657","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.149+810f1fecf","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.149+810f1fecf","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.149_1666833290127_0.37130298252142335","host":"s3://npm-registry-packages"}},"3.2.1-canary.148":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.148","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.148","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"de5a900b482631e6fb9bb91e34ee061b27970bf9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.148.tgz","fileCount":61,"integrity":"sha512-4nIpH6cY4X1NtjkDy9kU7J2nBGQpZy+/CLCy6akh0MVks+WXjvjo9RILY8yozaAMKeuW1i44n2nUvKUvp36cOA==","signatures":[{"sig":"MEYCIQCts7/oZKFvgEx4HnKv+x7nwBPrZ0LWxb8Fo4Idd57gEQIhAOxDxDaahUz+45zWnO+aZ7vI1E7pUGEXDLcB4VKMGVxm","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdwdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqf2w//UXyAzjrKMMly7hwtRUJfjD/GspAKl98q30Dh64aCCJKqybF3\r\nCJn1YPQTuLsjGGsdGWxnq2aYxzrkQQ9dMhDHQOp6+aNEjZd+4Z9DA02RIxww\r\neOll7ocoNo5i5BRNofAWh5OAruRAaN342pEx7unJdp70azm8jcvkqTRioPha\r\nEkatJ1sNyReyX4Xove55tZBkcA1JBnvXC194xTgz1AlU1vbd2nZuEKci4PZB\r\n8xoj+PB+1nCS+ESJiLNANNFC9qTTNH6knxJ58eY89cHbiG+9SYE0QfTBBElk\r\nrOEXrf8MXXR8sjvomXAP7yerf6sbmgdXtGCd+FBd3siVEzZLbF46N8TdiqJs\r\nh1MUM4KtDTxKnBTpHUJDChPSOvH3VM9zT+YAxQqWUzJI0xQLnWHGTwNkHmBr\r\npZHWZPXty2ZTjoDva2Wk+1oWyoqKjc3+2nyeg8pvpz9C2nX5KA2k1MOoMfHt\r\nPv1FHdBStPTpaTF6/vTIXFzora9MaF4hIoWt8Fw9W1AeLKr70VFfJ8zkHe09\r\nSdj3srfNGuVypGn/gvWSNuHru+fg6R9LjC3Gl+kaZGCcK36oPWUapT9QoidK\r\nVnWeiGKh3a87y0dMajJj0qxotTRfaRv65raXF/2+8bPuZfGo2h6M1eAuTRwC\r\nXqLKA7i1XrWn1ovzOrcHUiFhb6Yb1pZWOig=\r\n=nw3K\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c7cb9d975742ea392704a6cfccf1b42cddbc6a6d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.148+c7cb9d975","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.148+c7cb9d975","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.148_1666833437514_0.024959953499609","host":"s3://npm-registry-packages"}},"3.2.1-canary.151":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.151","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.151","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"eb3b80125779e509fe7e8a3d3939df8ab3c04a19","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.151.tgz","fileCount":61,"integrity":"sha512-hiQfMsctNsxme8+ZvSMQ0g4lUjDuyVIQPR3nxijMTTGj6FkMFuhvEkkK0GNzYqDeD5nUEEFaxE7MIVfkWAP+LA==","signatures":[{"sig":"MEQCIA3Hf5wuBZIDGbI6PQu5Fz+2pcBm4Yp1nakb0b3lQ3m9AiAxpxWfnsvl0hB0N2a/nn1oCCLt5Dp+YU73tzuMA/kYhQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWd8OACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoT/A//fX8L3B5G66S28wK4juY6h1XZnWz3McejH4lgrHxYwugRwhHK\r\nzy4HXOpPpViquAvRnUe7fDJdUHD1cjuUyLjDiGfyG8eTW0KUMXd0dNvQxvju\r\n83QcLio9V/9OLuf1DiqRf6jYAMpsYOlsDzH3gqhCHd6nEqmg0QhE8xgGCSPS\r\nQFkFIAPBANvPqAPvtTjHORRwGsLpFF03CbpGgu7teCXy7KuMSZEawrj58M8M\r\nGP87W3MrvrAkaAzKVlbSo3tWrHLg04Ae5anQs5QCRbpbDxl2wzgw6Pa5E2Xp\r\nwuXnNl+x5zWHGixs3nO3B0Qam74U36xnGRuiiHVhlKWE0EOc0/BwQJNGOBLC\r\nNwgQvsqLByQgbfHUL+J5+fb5UKN+bE7DBEbFoWNTGTzlqc9SH79ldXoeImb2\r\n1JUWCTffgdAz8jIGiQHLnD/lTKnVgIhbe6f3bpzQHYm+7vOPzjVzgVDm/aXo\r\nVzGKau0SMqyQCN+z0R60iigl4n9EgnTIkefYrqBIPGccJSuuxO5fwWEJU/LP\r\nQ7OMCQVzvAXN0P9aq1d5SmTQxmNqJIXNp2XjgIuNq1hCYrxmB4TJ5OLqGG8Q\r\n/Q7qOy2998R761I1O9Fa5VwjBX8fONLk2Pu1QDDiv1yZAiugfoKC5bstriP2\r\nDJfLa96oVbe5ItyuZiu1t5+uIPFCLBwu4tc=\r\n=fqIu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2f5a120062f82651e5a010067a0bf57e22be4369","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.151+2f5a12006","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.151+2f5a12006","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.151_1666834189985_0.04832451417872474","host":"s3://npm-registry-packages"}},"3.2.1-canary.156":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.156","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.156","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"efe998ce0fae0d3a3c95ee38685a32f7cc7aec6e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.156.tgz","fileCount":61,"integrity":"sha512-JzWJ4Wz1kOaG87NgEw3a5LQ44EBSnA8RsY+xE2dTI39oGVCVxG+9yi9Q/faRm2cvpecuwsvxRpUOeeFmFYQBXw==","signatures":[{"sig":"MEUCIQCvXCuVzYcfm0+rjUlLZHNAfNnOLaW+DlhrAHw/y4udjQIgZXBuIhDXB8ZyFPHT65Wntw99m1BrXJPFrcWd/Ga3b64=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWt84ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp+KQ/7BxmGXA+6qZmy7QYQu5J8FB5p41/Z2Llv3cJaXj1wHreF4pJi\r\n3hQecSsi3xYa2YZV4moXTLP2K/lHdb6b9XdjvwOJjWWtMFsNbFx27pANQk9h\r\nuRUsO1RnA4xuJ+febTVcA9YKERroBDAD4Na1GT2Ij31fW/5oWAe/0cax6mHd\r\nPIF4B2NjWLZlmk3+oLEmIceb6fNyQE9OEoV4zAr816C/AGR18KIahnTaXsHA\r\neRYuYvObBTTd+1YEDlu++24b6xzYaeSF5R8xsD+FIfrIOP8d0T9jRe482BNS\r\noj9BK+k19IqFRQpmZpQ6BWxoeNbx9t3r+wJ579htP31HUNpaq7CDYCX/S39z\r\ncUsbuERjdS6H390v4z6dE66mP+Ddk54AFT/qSwl7soP1BvlHuf9+bpM8ie0d\r\nT68pmK1HoH7Mui1gqs+ovBL34APwV+Hn0218a1CLvczt8OfZIEZgOPNThj/G\r\nTH128gYJBYwuZb+q2gNI/hgtO6bvfS7rlw2uKz+dcbyMXqx2ycWNYIYsBDUh\r\nv4ybEUJFE2g2ayegWSgGueDxy3Vhc41KQ+tpfE3zO9FCc4yKPDAb9p4jSZ9v\r\nt21u6uuqxpc9246aTD5RUymAXBojY1TWEOIPkJD9x/szXpAdD7bymS7QCdnR\r\n5vpqucnrPCfWJ7KaGLAth8Xv5gfJMhPLTcg=\r\n=FyYa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"113b91b269f939e47bd3c2f4b7029c58b981e078","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.156+113b91b26","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.156+113b91b26","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.156_1666899767814_0.3033474846607265","host":"s3://npm-registry-packages"}},"3.2.1-canary.158":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.158","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.158","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d082f9a8d88ed1db881d5ee7d4f3f9795e020d8a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.158.tgz","fileCount":61,"integrity":"sha512-p6xfyBcqlkqeLnQzV2xqzY8VyYi9vNuPlYe7udhcCG/FqanSnvHHQFBfBQuVOSr0Vik0VJJObC6btAgkP408Mg==","signatures":[{"sig":"MEYCIQCvrwrAWEBam+NOx+l8UmsZIFWlhdBHmq4QZ80NUF+0OQIhAN7eKu1ScO4yD3sARoV2cND6Cz/DEvzC83Q10stUfoo/","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWyYaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrscBAAi65U454hgKCTLIZDc+yJ687sLA+6H50rb7sr29vQtsTWH48v\r\nq6UGS8UTiY1BARY9HEl/Si1RzHRdSCQNmDpSSa725Dr93Vo9qNPDWRUtv6G2\r\nKPQF/1M93PUtr0YwjAM0d0uMjj4w6nYT9jv/1DEvIjGvyS96GZic1qCAQZZt\r\nByHeabje8dlgU/r/CzAPBTu7Hj+9Dxin73C9xzGVjsX9nFnX31IWY/okj/zR\r\nO7P5jMMuzMiz32EWRWZeTiqsT/Uh2VLlIjpMj40S7cJMDgRKkRBqMg0XVCE4\r\nx1qeSVIUMH0iitQ9nxeIgNFKGFzb4seVffOvQjo7KrARjKc70Q2vo4y1XjVz\r\nE1eiqFgAUub93MEj+8fCX+frBoSfHM5q/znU/timeQoR6BlQpaPyyyQTHUkU\r\ngfugUWe4T5v8u5EFBNOX+9zk4uUuVgQk1sHfEhQByVQpoxEzs1t4+ACjv9q5\r\ndT8emSBTyN/wTPCeGSe76uWSpeMtKwDgseSMJrYbt9i6bH8WdB4H5DUcHGfv\r\nDo0HvkV/XOphZLlFiTsLGcuwkv2/rB+uA9V52xQ3u9txDM3nxHjgU+hn+bgw\r\nPHg5GYC2+/NekqUBjLDkZ5L9Nxbf5ZT8DK1vhcIWrD7WsB9Oe1EJH02M2Txe\r\nzgUIPiIkS3bCZV2USq+JkkwprpxnzVK5lLU=\r\n=R7il\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"90a9f125daf07352d9c834727d7cfb0d0ace3fd5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.158+90a9f125d","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.158+90a9f125d","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.158_1666917914134_0.844444639091575","host":"s3://npm-registry-packages"}},"3.2.1-canary.159":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.159","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.159","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8d6424f5869dc63a240e4b36f15b8b687f8d5a30","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.159.tgz","fileCount":61,"integrity":"sha512-m5fXHcK66vKBfjd5g84cSKJu3XkC1hcaLnK3js4YPM0wIh6xfuTZf5MaApuspWdP3e4P9jfEWZOEWD5z0jk/gA==","signatures":[{"sig":"MEUCIQCLdcrn7jlCbR8SNQNbxtZ5BjzRif/CPAC+JgW1TMCrywIgCW+HvoBt2ykkWzA05KN4ROuRbfP4PnOfzKKGMSuIG/w=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjXcJlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr22hAAg465LycH9hefVQttoYXslcUDxUpG8Fv/4OrX4xTlHeKGVUlL\r\nKa/GEIEIs8xE1X5tMlggc4UjAH+3m15zcJciLCsB6vEW7RUjaZrRU6x6PEM/\r\nQcCLNZKxd9spYYTWBhGkWzimjPgVVaClh5A12TpvGvDfDrcHK7jxHdMGhg0z\r\n5T6jn9SR2VPFIzN4DtYhzaBJeOsNqc88qItvsgmhtDeP9Txu76Q9d8KaWGwN\r\nKScPkdapaHevJT9Nh4Yt9CjHkSzyKFfCvTfeZ/W+dCNlGxizZSs0O9luFTYi\r\npV8mzXSZbJ0KArrdrrB+G9bk9VIyOtL/4Z6kz6O+UoKvS4Ted0g/ro9M/4Fi\r\nGO8dGQ32PK2kTj6aW/VSpTEtHpmqEuWV6PwF+CKOwnPChZu1CDJXg0CPtsPt\r\nU3VieCMFYugmCe7jrydDswxD4qT16xbdGOcniLJucAWvrwCIRexsxqzbLHIb\r\nTv2s7IDd3qhJCTC/3fyRkJaBEv4TETuBwOJNRRQ/KBHPeyUnqhccJMT8p30Y\r\n1m1JYLA+cxfsE+jyHvEslPtyO+XCdrAQbC3FtwCaKkQxgdfotWp1xPEyFD1O\r\n11oyP7CtL/ukOt29BvlBbt3Wbe0M7Ix3ocF3B24PBiE57cqGQ38iKj+LwsK0\r\nUHFL3b2Y4i9EUe2Nw/XFoCJpTOiAmR5tGq4=\r\n=uHtI\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8935b209437a7342d571ef12dacf437ae248ecd3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.159+8935b2094","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.159+8935b2094","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.159_1667088996958_0.9843049084299238","host":"s3://npm-registry-packages"}},"3.2.1-canary.160":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.160","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.160","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"313c37f5ef560605810ae7425e1bcdbef5523ebf","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.160.tgz","fileCount":61,"integrity":"sha512-aBiAt61rjSUK5Voc70Ewsapbrm4f2u7/Cb0NTvcPsCr3NqkG4h67z7wWwZgrUMJuk660lx2uM1tmHKgNvsJfpw==","signatures":[{"sig":"MEUCIQCNLzrB6tgrWOd+TOTVjjDuedoiqQZ/Sijn0T5Sf45AAwIgZ2gMTivyOhQSdTjKKMgQuGHwVbS0+AlFNFC6sJCKuZQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjXvEBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmomjhAAh2AcJ3KpsriPhOjP1Ln8+0TcxZ2LKHzVzM+lQDcSLRPAYpU+\r\nU7OwFnAkL6s2fab2ZKnCovEfmZRna+6xR7yJpIq+jBGe3/PH/yfqfdfbiaor\r\nq5qk9x3XVNIVu9Oi6j5KoLPnEhCpxkNawTgX1LNj68YtRcHcrx6d3Oqv5Mld\r\nVg1wQNgVhI0g/VEPlVb3mN3YdM2z7ZQkqx9qksSnGdEWRx1k4wPrbO1Bl6h/\r\nz4Q4JAuryiKIRTa/dFD4cG22hZohKuazHQXBJzf3XmvbjtVXnO/SM1MaEh+U\r\nFU17UpK+c3mHM28up1rInugJ9tD9Z73URUW2yKjYMZ2/fCFYvMrpE8ZbLgWE\r\n+6rB7FniDcb4d0MQlCJgmL8fCMYDPCRfoh29nJTqIFfAsYZm8PTQpF3JGGlW\r\nWcyDk0S7u+zIwI0aHg4cuPUJY1TCSdlkYuVtEygUz2HC94LmiVYHvOUcBNm+\r\nz4MMTUuvJHRuwwfLKIAFRaAbFGgEqpjq8+elr6rSnO3+Y4pObbTApczGgIdG\r\nZSrrxki6cunSM4grnIhKpu7IWLPhzjh4xk8SC0d6hd8jgVz5FUxz6cYEJtRh\r\no2cB1KnyxGiGYQtMOt0aexVF7GkBQbEnuzK7mL+28X0QM+ciTYzhMESHI6il\r\nEOCHMDFeZZFRdAZAvi6TjdsyAd8Ssb9bWnI=\r\n=gkfq\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"97f6f622e06e34e6a88f167cfffa1c1d78a33b92","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.160+97f6f622e","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.160+97f6f622e","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.160_1667166465447_0.9899733925320746","host":"s3://npm-registry-packages"}},"3.2.1-canary.161":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.161","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.161","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"db52cbf31686643321217984c483d9d57717184f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.161.tgz","fileCount":61,"integrity":"sha512-pSAXejgVf38R6KpfKoKsB5WhvKErLYWyM172VtQ/wte/eOpwo/lWMelKoBfihQSUoDKmPdfJRQqQ0J3UJaR/oQ==","signatures":[{"sig":"MEUCIAsTdkS6dRxgDb2+hXFPe3L8q9v1y3GKbo0ZcuJUREZiAiEA9yofVseaH+JcH7eIMbAOKiGqCM7LVaRzFMuaZmxn8KY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjX7+XACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo8cw//WSHJCSuZZcg4yVknSF9gYetb6Oe+bMheubEwYaWXWgruIM2c\r\nT0A4vRBY9eCOVnmuxqkyah1KqeUZ2+X7QIwmv0D/QLThviwS2n/4QTNxpeFc\r\n5urdOi6QELdfy72j8y81dMZZoEDu1lWEv7UBXMN19mRxTyMh9Cs7EoVSfs1i\r\nQqLSWHIdEJoBDqfdLKcqk74zzf/HcoC3SiS4mUUfkMVt1q6dQtm+5ux2g7/q\r\nWFqdRyUy5WvkE9kX0MLnxOQbd3ViVAlUNG7aaRNln5qZXNvQwHae2p9djvf/\r\nczXLWwlR2KztqcyZX8PJ7e1sPMT+UoklstfDtxgwwosqFEnc/H1bZfHzNUwi\r\nuiB0hn7NQyd/Nxv4DTYZgOiykm2NN8+7lP2GffxPmHhH0rFCnOlSXbAJh468\r\nEmquDObqo0/WRjcQxvH8VubEVriFyHcf7GxNTPJluClRz8hUcK/TUdhwc8rx\r\n3ndd4hfHm9vpDskcGOpp2uIxRkVu2BVtyQ0ktLoPTlBdrCFSFPsxskg7/Ufc\r\na4J1ytjtOaaISiyEySuDgTWHJLYEGmiKl031Os9LpEhVGZADhtj4rxD7ixk6\r\nOgBq/nYXs+gF6VavXlwMsoZhbYnT/oEq2ocvZr423AfNW9pVff6VXs1oXymb\r\nhvrjlFbeweB5RlPEg++YMP74qMcbZO0IXyA=\r\n=piRF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7f6b94ea6c11c8dbeb1b432c061fcb90ee938d68","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.161+7f6b94ea6","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.161+7f6b94ea6","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.161_1667219350947_0.48004764285446777","host":"s3://npm-registry-packages"}},"3.2.1-canary.162":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.162","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.162","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bfd9a2ebf35434cfa667188e0035fbff1ce91c4c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.162.tgz","fileCount":61,"integrity":"sha512-Pk4MoaYdL/+TV8lrbXdb4/2pAH4ODYJaAR6hKma+6Crqi5+F7Lvapl+nKfHq6SqaiQKb7lhB8/RedDKmqYDjaA==","signatures":[{"sig":"MEUCIAdsKnqtkeKeTfEYlfeEK9Ztu5xKjhsTEU2ps/wQW29KAiEAi6CwL3as0PmnFw7GoqjXHoKfwogaIZ6An4610S78fWY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYBOXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpMEQ/+LEe5eBjQpoWF6wILXEqHRIKy+fzL0dA3BJ88aScy8m84YCZ7\r\ngHQM5v4Jp15EaOmA50MmaU23mPYF8UYa9uoxeYkif80p5IGSKS8tnJYgWRlq\r\nZGBM9r8VTdQqtFJKPXfnV873rygnejQKekmfWPt09gSSwD41mCnHMD9dhj4u\r\n//qZhvfqMwrwhxWrzabCRTn7Z1rZlg3AdziwZg+CuhLIb9btteZvFT1pI1/P\r\ndJoqUjBO8B9yB+KQUAUeEfhFaS5xVyHrRIbHj9filhtLGq0Rh4uwQnEvS08X\r\nE3PANCxMvPOeqcGa8Wf2pMTB1s84p8Nj7l1bloJwFV3L0aXoZQAfyuxUNh2e\r\nbPNqtrr32VPSpzXJZlI6KuJNQbqvtNS5zA4htSPUXW9JVpqKhhG8bPsSavrg\r\nj5VFanMVO1hq87byBhVTPO5mNG6W3q9P26kwEMj7yOKs1jIfGJp4J3gEL7vc\r\neVDzRo0fPu3zo9hRj30jBaK7v44w7IZdA0j6nA8Xk6wFuUnRdTsNGPJv7vcS\r\nYeK52hQYJT8WfUGbQhcokwJAUSO0tAE544I0nqryNmRBsY4WRirrbD2tM2Ah\r\npmsBfN9+i5F7rVlNeJRqDn9uxwXEY/3Kc8KJT8mViZ7YMfd5RWxGRzN5SeOD\r\nYMqUol9w2ULOg7CKhxR+1UQkD2tCgMV8C3M=\r\n=LByD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"544374612d6664d8b0ef4ff54dbc2a43c4e000a2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.162+544374612","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.162+544374612","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.162_1667240855394_0.1549440399165658","host":"s3://npm-registry-packages"}},"3.2.1-canary.163":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.163","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.163","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c06cdb80bbc28edab937c90bcb33f3b7174db1e4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.163.tgz","fileCount":61,"integrity":"sha512-XHn92JCX8szJBQP58FTDmbQE+MiWO5RNkZSOYOC0PteGUgK+1Mp0jVv68TS3iQHvwssfDyHwClOHu/X6w0QQWA==","signatures":[{"sig":"MEUCIHIQLiLP0UWNC6hIs6v4sj+G8Z1mERjAge4r/W+iVJIsAiEAxjXJNts9SoE5XY/VTC3AAibroQ6ZUfF2kVuraYnXnGk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYEkHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqgvg//VGXzEXn8gkY9OX3+EXdu4V0V7iagIYb1l5VNRDinDzmryqRF\r\ng5xO8AtaRxlOUcH5xR9ZNC5Z1cdpatlsc9Qi6m6/LmseNeO5czg/3TmnVr1I\r\nagczMsjdlWl/iWuNFd4Ctr5kUOc3prao07BTb732jxkPtevCTpQNlQ3QRmpy\r\nHu/R7RCcYBur9PHWKDEDbbLc2amaEmZmCsR7ch8ZbTeHJrsVyY7R3XTQbsvO\r\nSyLvL9HhMuQopkbdIu8xRTYQUi2tkWuYiK2G/yCg6sLtQ91+wj0Uc1tGKa4d\r\nJqdIRQrGwgZ83jwTq9J9xZwePqNQxtzDhUr5EzyNmS3V6rvaLEJPXIFyFQ+V\r\nD0qN37pTnn3WU5HbIpL1BmPLTj9wR/0DXB5/N/pYWh47R2FjBG3ngWAH5w4n\r\nzL+SwB3Jch8O6JcMuIkA6FX6xkeIMs2alyN8pz80kIjpZPDSEwF3tPofC9gb\r\nre6aF3eHL/v45bAosklcDuv3OsDP1ec9w0OUE41RJtjXyCwqXsdFo4RFerTw\r\nhwuvha3B7PUQx8iK6fVYfWfXO5XAXc1noBJbrmJ+TeseLKQg8KrIdlmoeY1X\r\nhi8aP4FYJNllMkCeVlDfx6x7EG+uH7k7B04O2mUM9Pe6dVyVIVtNH5Cjq9vR\r\ntofqdWEuzfndigm/bF1hB+/WYifqTF5naTs=\r\n=l3jc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a388889c084a22abed631ed4bc80451474da965a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.163+a388889c0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.163+a388889c0","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.163_1667254535615_0.2858057553758844","host":"s3://npm-registry-packages"}},"3.2.1-canary.164":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.164","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.164","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2fa396e402e485a46452548e95d3366985080c47","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.164.tgz","fileCount":61,"integrity":"sha512-NpLNlEt3CQ5o9KkYlq6+xyhauq3ZZmNjsm7ieUK4eTKSprmbdMePslwLbyPfndSg7MfkBih1utVF1i6yPxg5HQ==","signatures":[{"sig":"MEUCIQDcNPOy5M2u1AiqgnAA/xY5iEUdIvG2NRfqt7Xb2nk94wIgM9B685tUuA/yVZl9sH+tya7ZlfGAg0ZORfikzQo5Ijc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYdRmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqPwA//bdjNuUdPjR92xoUpU39HPzFeMyIO0tBCWZa0WV1RfYqFNd+B\r\nBjEa/fTbCmcTvZPeTqcG2JkCdnNwx+EguNLhoiY4Lq3dkVl6AkWEMtaDF6ov\r\nbVS4YCXCoQzlEN8BK4F6xX96V+qEgle4+44WCa3kUBrjpROPlQu6Hpiw9SK7\r\ndUvYtNkeoFBFrHNpyp95RxKSK0MEoZLwYvYFLHZG+lDmf55PrLIbmgXfzzm3\r\nI3y2BBMweN1kgqWe4TLVpHn4vUnPYBBgW7BqHbugPeiu6whXRGC1XyxOtIyB\r\ntXcGA1ACI8ENFXUDSk5PxcNMe/fo+I1iZs8OImTsn7zwiJvQPd1rRLE1xI+A\r\nGyiqinXJa59FEYA37RrgQQoWIiT5YoBKkuLpD8Rh9dqbOoEac8uWjJKTRy3P\r\nd68ypodxlYxg8Uc2l+Jz5ZmmRQJ8G/z8hfkDid6Kv4gRPVvhbZGTMzKQ+l00\r\nHRBC73ugTVgjdqlOTwuvq5IxiWY14pIZ61yFDptwlXrcxDYT2dWAkHm9KgZv\r\nTxDkZARU4og+PNiVBLJCvw++p7fC8rExBsQ1yNBgko7YnJ7Z8SFWAINW5u5Q\r\nIPQHk4UVB1dq8U0FcX3V2ggrsmff/MDLshHHMYFoKPOk+TtZqvxHK0cIHE06\r\npefwuzIiGmAh/YpsEp8O4y7tVC34XnyQmNQ=\r\n=lyUU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4437e21b631119ae406eb5de38ea1f38b0bfcee1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.164+4437e21b6","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.164+4437e21b6","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.164_1667355750223_0.9501938350049883","host":"s3://npm-registry-packages"}},"3.2.1-canary.165":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.165","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.165","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b9807c262594c013c16769fb0c75dec8b47eb6bf","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.165.tgz","fileCount":61,"integrity":"sha512-Dyhq6y0zFwk+LSZS/loXbbDFxAQYaGcStA68xUUhFUujMV0AckGPHkljNQRRqVRBiHB1etQt0RqVuKQEGGbA2A==","signatures":[{"sig":"MEUCIQCNwSkdUylB5DzDKx8Xyt/quw0nLiTkVeh4RY1IzPofRwIgEDADuSMROfL+e11XH9pyXm6WqLzFZb/gsSp67mhCUbU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYroUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrdjxAAiJLy0j1oPB2nFfk0Xx9+zMnlo9iY/WVDq7TX71Ikp4yqqgCG\r\nKKfa2DcBICnJQjVGkLkKEHOnodvlbpvnmrO+h6YE63sf7i7ejLOPk5aN/LRV\r\n9M4yC9LIwiGAWEU9toRCjuQpK9haxSddiOqLslBtGzdOXSHui00iB+zJm+8k\r\npgc5PeVx+La5bH5akVqob8IhdmhEHP7Q3QeDaMMHfdNmV8O1BMdOjdnsltno\r\nMJANOIAV7+Acl9oS+2x1tomjvHgAVFcpq9JnxohB8qkuY1zUWXbuvRqh9MFU\r\nUwNpxSZ1kei27UVw2gbij0Lsf2ZDWYPx8yhc6g9A8XKIMLG4EN3aqAk+qdVR\r\nOpxujLVcfby1yi8ikEtNVU4OUhJUvV+mOFhtZVIxaAVHwwt2LchmEpiEQd01\r\nH26Pxr7uQw82qwux1jDgGrrA+sy94NXpmwKttGkMAwFn0/AOMnzL+nV+LD2/\r\nZJwb9ZvfxN/OqsEr7NxHsia6FJz+ooes+tFI9jIu0Zid4jFr6lRvJWYVjRTJ\r\nmz01lX2ZDtQaB2Gba4U7BlTZFdq3uo6gTQ2oImdetO/IiQJWitOcv+c8oAOu\r\nF56sVD+JXRyNZXjZuTGimj7D4v2UjWGlovdw6rsT6cgey3kLYYXBO6zTvOyV\r\nXSacF3El/k1a4VzRsMAFEfrRfgtC/9wozzg=\r\n=XxJQ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4d506cd87984dd6390355b98b8a47ae26d7f9773","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.165+4d506cd87","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.165+4d506cd87","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.165_1667414548773_0.15257042223114703","host":"s3://npm-registry-packages"}},"3.2.1-canary.166":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.166","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.166","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f07cc6023b0a426344d15fb87378b05e1907e508","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.166.tgz","fileCount":61,"integrity":"sha512-H9xKvZ4ZAoRTl20VJ5h80IyfFGocOtlemj50d+18zp/t5uxSJ/pB2eBNCdiRMnq6aqVIo9zJGvCxxExSjmQ9kg==","signatures":[{"sig":"MEYCIQCDEqPPMbC78Ec+mAaz+M34E96mmRvlPrTO+lkpJVN2HwIhAOvFyHPCY9grTGMNOffpm5GjrXGTb70/3wxOimopuitO","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYy7mACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrenA//c/ZAhwnSf/5M768NMKZ+JV7h4cQbbB+HzK6UZoG4vBBCSru/\r\n/3JAjFw7LbMWNDOrpoNB47NhZmlhPAHALLTHIlradNxqjtDdiHxVVBXev3m2\r\nrO6fqIjMAwqSrHMLo3ZdtEbU77iL+waVwFH3l1bT03dNPqfkjPjsQ9Rf+D6t\r\nFwSprOL8k4bRnVo7QE0pF/ZF8F2U4OO8+vWIOp71eib7enC9bUy2UMwv/5nL\r\ngeIg80eSnxvGfFhXNh67esayQWMqAI4FflxMg5wbpsZ2cK27HM1ahLgMFOpf\r\nntjs017VQjdjpPmyrCOImUEZ6Un3cpwvpAJuACoZs+usQY3c44UmtRNmcodu\r\n9wExOiW8uqyzyWi0llxWsiRJU439TXKOzdQG/SKdcRtnRURk79Af+0MSZrI6\r\nNrKc58fWOmfv5k0BjKqqnZVjwya6KLZBC2h4xmG5KJbgg0yU+S/KlsmzT4oP\r\nqEzSISFVq2Hzcmoyau18t7SALgZvK4mG5lwUtKe+GHAkA0xGpJcmV6AodGSU\r\nSyf8WBKH0go51qJB82BHv60N58gsqXjAPJTjB5SRFqYGUzO+YRizbk8azjY2\r\nQduBaUS1uFjJ1XZbYBbDRvAfCpGM210Nixk8UvRevPFFE8BwzJNf/3xsCL2M\r\nrP/P4ygROk8SCnZOyJVZgvm+RFqdVJ8viQE=\r\n=2oiI\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"95a8702fffc942f07a2ff861e6910204d00179fd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.166+95a8702ff","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.166+95a8702ff","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.166_1667444454068_0.09904142750350142","host":"s3://npm-registry-packages"}},"3.2.1-canary.167":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.167","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.167","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a069851f84fc52688cf636860cdccdde6cf53e0a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.167.tgz","fileCount":61,"integrity":"sha512-2ves3/KszRp1oxqyfMXf7aKVVTl8Xj8BiJP5LnHEl2yxuohkF1m+rFlrUZ0f5az6UVYx1KXMOhBULl9RlMsobQ==","signatures":[{"sig":"MEUCIQCCVdWDweV2VPJD/weJfTcanW1R1BzFjkgTNbQItHTuYgIgcSNwQoQNQOQx2X0uYakqGvumHyg9NvDfceTElli0gNc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjY3SkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpfRxAAoRdb5K0YZhqGYpU6HnUmLWdM8L207J51LfTTTxA9UR5oudV/\r\nc6k4CsQH54sfBW8lk/zK2zb4OCQuzSx6t3DoHqFpXXkZ2fckv6fGcZhUwAja\r\njsYE/nELGJqCqoLzpisRRUYvN2mj2mD5NoIfHxYffaP1QXQV6RhvZuLgky5E\r\n5Q2U5TvPatWv0rXvPWdBgO47DfchQ7TU9j8cmOEZO8x+CQNq6NYNN6j28+EB\r\nDp7JDaPOQjEDZTwkiEzPTIzdq3mSe7tLLSooiz54eTIH8h76UWUvQEHXyJZr\r\nb0yuPOR5R+U0OrfetKkktWA+lfIoEuOYHuTuxPXpSZx5K97Hw8cLp3A1aTIG\r\nPfqlArCS44TazAufOpVIGQnibWS6keCxxLdWPO/fcpgXgo2U1Xsc3DIyH2hL\r\nRjkPW6AJSpRl0vn2otpi3hcY4TmweTh+EECldeNQqVk0G4E5ezeLz6xFxcz5\r\nLoRjgJF5gM/fU/nzckQ1VeuuyW5UJ04MmGaVE3GbEYmNyMYRf9xloWpouYa+\r\nh0bOAsWs2lm5TTjKrgz/3WzLoWpcrhTE5MIIp2Edg4KSl6/jpXOQMXVUfJ5F\r\nhTYGgjCWlWuqvEaKNUcS00l6gTcBPdGMdRskBJKtGzdr6xRUUY2A8/jzoP2K\r\nDhyvgG9scRVjHS9Po5QpY3PJYIIF5nE/ydc=\r\n=6Ztf\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"424fc08c773c5000151731bee5fac3022ae7e08e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.167+424fc08c7","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.167+424fc08c7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.167_1667462308066_0.28909565913242274","host":"s3://npm-registry-packages"}},"3.2.1-canary.168":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.168","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.168","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5f13c810cf5162920e4616cc25e6be94ff71dfca","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.168.tgz","fileCount":61,"integrity":"sha512-NbqX21aNaP03OkKPNFtcqJ8Lx/7IONGWAtioy8pheViQkb4CcglpJj00wX/Y5esqyqLHzFV1xiHjryNqYq6Onw==","signatures":[{"sig":"MEUCIDPA7KzndxYEkR6AmyhkCpnfE2Ly1ewyX2MJ2UrXLGDZAiEA9n+wBsxdOBmA+AyKIfCAq8sHY90/LpDtPxN5nKCEiRc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZCsHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrXBA//TCXYO1M8MxF9mEuO4B/rpdWDqA1YjLqOLd1dw2D030CNPCrX\r\nKwTUxUHlg5fbt6Si86qY2p9jOE6nKTfyt60XxvabCVe5a1kuXlwMP77+Y26d\r\nGDYr9WL7jM59fGyiWesx7x1OyFuspTL7ER9s6MPu72oR/YZaZyah2UM4XH8c\r\nr+M0x895mhcosWXu1TvMDLlNwFn/MFUJWD85pkTaTkX0RBvpJYHPcidS9e/B\r\nSdEbGnVxnrEDYzJmIdtQrDdq189vhGfDK2S6TNeQiPIGsC+mqtQnTdI2yKSE\r\nw6xR48pinPUgRhQUN4kJ6d+Fz2Y1z6edJrJDeFMP0vFZzxbocrN7q6yXxvQS\r\n0nzbZ0O+xz4z/5Vlw9TcRz4lSAdo6p7nZMykJcKnF7e0F4XXqUCsDW2z5Av3\r\nfmevhYgb2E6wlXcW7as/ZQwXwgTaQEo/cghECnbGJ3Mk/S6cQ2S60aNmA4oi\r\nqkoQbVHy8KxXuzR+yEEHs1FlSdPUBJ+LlEF5fPWPvi0OMeggudI5N08EC7Dk\r\nx3SIF3etm2RpqElmcSckbkX4Hd9Ci/mzlg5N60L+kHVu8ZCExWqrHlB2OR2Z\r\n6JDMNRxLa+/oGKN/pc6S/a3371TTiYuh2G4XwsYx+zv6hJtk1Y2B9GFP12f1\r\np99jZHJn9FhjS2nWEsFEvkPlh5ALFD78crU=\r\n=CHJ7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b051e6f1a00a0fcd6e65f735f63abab23d637255","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.168+b051e6f1a","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.168+b051e6f1a","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.168_1667508999724_0.22205488739175605","host":"s3://npm-registry-packages"}},"3.2.1-canary.169":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.169","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.169","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"53dbd24a4a0dab600243b8c7632b34640a8f6d22","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.169.tgz","fileCount":61,"integrity":"sha512-NMYSkhVsq4R868sYCOBaU/Umh6JdvVUVhbtBTdJQpQV5m0mV8Tvp2vst3dLlmPSrTHpFTZ5tQq4kSufmNjJ8/w==","signatures":[{"sig":"MEUCIGNKbJPc+HjkMNj42GiYcb79ogX6ssdjACzsf0jaALYsAiEAjX8AOtbi/r5pQYD/W4vZHG8jH0GfZpsHlrXByqvGiGk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229724,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDZ8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrP3g//WI5Kbfx9M31nBCtGOKL0bWwISI9gv62kOuo8BtQ5yCRjHmUJ\r\nrcvfvXYV2plKYkwzrH1JwnpmDgdGR3nBHQ3s2ayeQ0rHuVgXFGmP3rHXIzuD\r\n47cxKI75ePCEPly60X1BrCvIjUWNGtQ+rR36SQwZVIABT5tPIDpMejEMfxzR\r\nqErowQkuk33d8Oyg+ljXA7F1Ek+PAcnwR8a/vRRVYulvAqxnrtDr7X2FThcQ\r\ndwa+XLSJWDPTYvVW40ZD981CddepwPDKrx+hhtKmmidLpIw/eqe3hGhJjuvx\r\njRDC5nfBHsPYt78ak+YHPSjIL3NH5vsKgbq+YxAgfo4t3aVTtXmae62cZMW0\r\nDp3vwpNs3jKbIkrp0UJkP0BeIWVe78/GEk3RB8pTVhI2IRvUIOfv1Tru1Utk\r\nnS4T4ytB9dynrJZe+yc6uscaO7ZmdIZuPPopYg0by5e0EX0o1DNVRSg4aBFb\r\nfe+ve2hyGQd3YUzZgNitNnnRISvaSPEt7PoMoEKVNFHa7RTVHE8lLUcnUh1y\r\n+Dk7UQlhYfcaX+RL7Kjz5wCynJEEka5QgxqKcmHWN807xIHYflW42GTnRTVl\r\nMlZWA/GZl3JDV0GxG4PfL7EsXkz1qKjApBYfWfQEmEzFGMSFCGqyWtIkste8\r\ncu0MDi1DKcMU5Om2ZFmfnel6yaDwCyXbPk4=\r\n=6KKj\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d6f6aba40317ad21b32295112cd1f5c62039f35f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.169+d6f6aba40","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.169+d6f6aba40","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.169_1667511932333_0.9605878093777829","host":"s3://npm-registry-packages"}},"3.2.1-canary.170":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.170","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.170","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"53d7bd538b4426717b19c9a438cb2675f77e742e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.170.tgz","fileCount":61,"integrity":"sha512-umPmMjYzS6oJOeRQfP86xWOJkKvw+W++2455PTezVqPrFcyxI1egI94o+X7p+Omxn7WvziLPNyG/1aN4SUqpiA==","signatures":[{"sig":"MEYCIQDQLslpJjGjgsADXCTCN2YThlzlG5WLolNv620Aw5P2HQIhAImsp5kyHTjUVs3AgHruLRo7K8lq9cU3MKJAxCHwnWhF","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":229914,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDo9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqWiRAAhqjx9NAa5/vkLbsEWLYdhJMAZ1cRvWjVaQ4kYW3rcETfCPl1\r\nbUSNULaHg8nIZUqNYGsPA5qlFzt6w818mVoG0c4pAlyfmn+X55CMqr/3Fzp5\r\nXfeRsRTP13tUbu4FS41UEELQFGs1edKBWBIXbJTmx38qXdFYy+kdpH9vn0xa\r\nd3tjO9yyt8tBnVmNnqeWWXrJpRNOMt708ghVckpj5WfK8rN+OS1ZnB499Ais\r\nUWDD7f4zRdUioq/q3K7yXuDIPXxdUAp4ESX5YKhVKvyMD19L6PCViuSIjcQ2\r\nFfDZU2vogLys5kBkHnE2M2lsELeLKU8WUylayINf9ukhfqxzIhTjjb05vYfD\r\nn1jaCdAcm3BJmRUAFZ5ComIyHDERRzv/1mDv57amPij3u1R7MWW1vSA1+RT/\r\nyFe/DdRxgXmbkxmPGFTdxG8hL6n0Z86bTxFpksTL2dugLHPiCi9AM6EVi3Pw\r\nKmRpYpUQgaHt0VcScEw0J9oUmzevH4fm4LYxYmG8tjFCuXDNn4JjUFfuuLU9\r\nC56xc+i1b89rD9dYSahqo1oAiSt56ygsF+3gl6uins4daBWvthGdUPexPpbW\r\nIDz/OZZaSUMk5ykWfo4qVaPbRbOMP33sRp4zz5ppFI6fM4SKHv1mOICpuEh5\r\n4QmqqbMEszIg/dF0vcPBZXaTQ9FPgOTlqTk=\r\n=N6WM\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8b90a78ee5614dc8f02054be7d38c3aa68e999b0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.170+8b90a78ee","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.170+8b90a78ee","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.170_1667512893270_0.9811544464207715","host":"s3://npm-registry-packages"}},"3.2.1-canary.171":{"name":"@redwoodjs/auth-providers-api","version":"3.2.1-canary.171","license":"MIT","_id":"@redwoodjs/auth-providers-api@3.2.1-canary.171","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d2de885a08ec659b71b63e15571238a51b380c53","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-3.2.1-canary.171.tgz","fileCount":61,"integrity":"sha512-oBhsKrBzS/dKYPd1KjRTleAyQDXG3Dq6ghaBU7lH7ttCq1Le/VnLF3/hFg57NNzIkaU/a2sxP06OXrZdvgrD3Q==","signatures":[{"sig":"MEYCIQDvLgL7YFcOLZ8CJJCweAHsnKawiWLpuvphrKdw6mhYmwIhAPxzlYLv9OxfyORnXbO+ionfFwXkwR1jzljgcTU8FSuU","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDrMACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoXHBAAm+PjQ+ZVNCZHYX4p1ODX5Aj8lvwdmikg8DjEGgMmgzUVJPu+\r\ncoH/sVK5kq0tqFB80EuYf09eCnueM1/GJKH5c6lTb06Zp2JNbxtpMaLy3jW6\r\nRlHaferHyo6P/sXjZGEo7HJbHA70+tanlJAQX6+rHNhqMeXTZjvipuuXMVRV\r\ntZXS27+lXYyAm2fe4XpXGftG1BeTBstmkQX5DFlnQz90zT1NCbIEz81oSsL1\r\nDVZE6TxHiRSqA8N7RoeQi71Gx0EKqppzSajp0LntyLGSebfn6tDGCNCX6qjc\r\nAeQ8VGhRx4LcWTf0Csv2FJtYckysDGr4bVKf14GRmcmrHJ609B9w1Qt5rTvk\r\n7ZQqrJdmzfmjYN0x7CKFeraCMsmGluUKU2kPu4Aa+7LWytM9YR9awM6vBTOT\r\nRbVxo3mAJxkrvFnTfX+aIsn6aVEBiHwbCjP9nEuz+d1DEMrq9IPm3SznnYwc\r\nVRNGZ0V12IkfGsaTS70s9noXaZWmgNSgeWpBGTV1tkhKxSGpHMD42E9gRgnN\r\n5NJ+Tf89WYVKHq2ElPFEAAYMIXyEph0y8pvp691iPgviLqb9iu78ks2CCcyA\r\n0ZbsX3nTElYllJNfhzBTaQnDqjWDamj4N/vPTY1SACWRdKu4QfhQBNrXA2+x\r\n9RtWO3wTWzbDqrbu7dchx4KEyG8/E3iCq8w=\r\n=6Gbv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"82780aeeb39475212db4430e0b08f92539f685bf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^3.2.1-canary.171+82780aeeb","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^3.2.1-canary.171+82780aeeb","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_3.2.1-canary.171_1667513036736_0.4731109481504019","host":"s3://npm-registry-packages"}},"4.0.0-canary.172":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.172","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.172","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6d28809a165e436f180008a4ed3333c776b5073b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.172.tgz","fileCount":61,"integrity":"sha512-W5Zrqq6DvFks6npYmocjUdsyEbmcQFeo4AJPjjP/VY78ZO8hiCwY+VDjnkbWoEjvsmlmCsLEq9uBnZCVRQOTsg==","signatures":[{"sig":"MEQCICtMouUPst3WLVeElyOj8yPOSxH9CupxEUu8s5qbLPWYAiBA6zc8rBSKBd0G5e7RwItrkoJiIWDzcuHMuV7Ax+1YUw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZD96ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrmvBAAkxXTg4ls4JPeTZISc60xepPO7bP4WGGN7V8L833zBuDkRwGH\r\nrRN4iAOvLOjk2Vq+eJRWOepSkMl7B9m+YCjI4vFOFGoCxWSMMpKAR4HnAeNc\r\nLUQm2K7ieWzivJHbgFbDetk0tapOyHwmtrNXkbTDRnre4POA9wOOHm5iYUCa\r\ngIzhSnBiV092acduIkRLnfXZ1yaWLoIFvr1g8lwIKPGdh4KIbxTun0IsrKMp\r\nvaIbX0Yj3Sra8qa2DuNhJtiYYHPYpV3MuIBof6O9x7a8klNbQhOeyVAuZl3J\r\ndzkj9A9foZc2w2dImG7YMHd2Iv0/ZjqoxXeCd0T36V3YFvAg853O1EJJKEI6\r\nBoDrzyYKSRwpc/jZLZ/UKJJCw1UJcR4soPeF/md9R4f72EzTPb9RgRLJN4NV\r\ngh5V8wMBiQni6JOAtTfSdu31DFECEuRfDnwF2l9KV1LIXM1e4O4m8H3bw2cH\r\nOXuxqtHHCJW1X1eR31046n/zrgJRS1D1EMY+HzcQeEhQdK173dMyANEvRwhn\r\n+jdCJKdeoDs3xEeEAiOvZ18mhtfk8RzpsTmln8bcnAJK29V4v59JnbybxDVG\r\naA+xCn28J4X2NWqxRYcgUTcUHGVrom2CfT0M3no6G3pcTHOx718NEZt2QLQG\r\nkJQ30Psrq6nAdqRSzl9QmywkhaaaLc5osnU=\r\n=68iQ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"45ffcefc23fe8518a7f762ef21e223cb399758bd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.172+45ffcefc2","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.172+45ffcefc2","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.172_1667514234106_0.4281526517975234","host":"s3://npm-registry-packages"}},"4.0.0-canary.173":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.173","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.173","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"db64458a92db9f0a3c3601555d99815d0bfe9115","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.173.tgz","fileCount":61,"integrity":"sha512-AZbIRwmYVqAzB6o0VGNCruvTJfhY5U0ZfvfDCWIleTUBWkhBCxAd5W4eOLfl3/Jn5ObKN/Ucvu72KymUQl8flg==","signatures":[{"sig":"MEUCIQCrhOplMNWjO0EG27eGTByP3kDt1+ugEpmFE4vm9Cnd2AIgTqaVgslamFf5pglOU7kKsr4zt+IGANpzOsoJbRNAc98=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZUunACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp4ww//eTc2EaFvW8uKNZr6x+55MzSFgvPjUL5d1WcwFS1Jt+FsNai1\r\nhLZEQ/nXTL/TFc2ykXvcUVVxvaVeEWShaLbTlvowB5EraNzosBY97M9uoeWI\r\nEP4CiVjiYIVjyotuZDDFhh6SaZ1ZzWVebXHsDbrCxEZvBb0UHIg9TEpTGU1H\r\nw0HkIcixvcWHaLkFg2KBoDyNozHnuOplzbA5BE2skbxCECVC5J10Hr1WaOTW\r\naneoQd+WcCnbOlmDXtkuN1w7rOVvLajtU1Ft3b4mUMuk78lE2g8h8GZGkErg\r\nnWQMzaFw0d/nlEyY/LZgXzLjamBwzWrLjwR9J2dC491Xp04FQUymz9wybgxl\r\n2MPSjQ4lphKi+UhWzcJncc32POjPHiZQE+n2LrOcbivZox08nra48vD6Zw0F\r\nj6D0TwRTQWzinwtor/nCP3U3UH+rjeERCSfEg2A0hPI4F4m6TaLZdguyvHu1\r\nKOiBl5fpZJ+NivbAc5Fg9ZqkoQL1G4TsObAYqjTnqt3ZiLRdqml9tYNJ9Kx/\r\ntj9CYrkMmVlejTLEacQsfBArLkiNWyXxTtbwc8lLEiW91FHyT/XHWgzzcZh4\r\n87OATfVnW4eNry0EpriMJHV2smqMm+0C/cFJLVFXsBruqeytmffKjL5+39z7\r\nTo4RAwQOWAJnnfjuo9THrz6tb87+j5IchV0=\r\n=T9WQ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9fe7be3a9264020f02adfdd40657d612af785477","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.173+9fe7be3a9","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.173+9fe7be3a9","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.173_1667582887060_0.5495047675431279","host":"s3://npm-registry-packages"}},"4.0.0-canary.174":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.174","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.174","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fe5ca237f2ed4767c029eefac84d17e547adbcb9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.174.tgz","fileCount":61,"integrity":"sha512-LIT0ixrLaUYfk0HdD8ZdsdSoCjhF+SQtDGRV+XMr9481F6dMs5hvTdY2d3AJH/PI/NNnhI5tJrW+L/hJBWhF7Q==","signatures":[{"sig":"MEYCIQDX3ywjtkLyZbUzDcDld0UsIEYeCobx246bsn0HhqrXiQIhAO64sKVnUI+oRBTUWH+GzuyNxfPuRcs+KOCre+kvdY2p","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZWglACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpgcg/8DSEaVD94QP0Mm6flbu8WjYyu6mCkK/uQBv34fnTmI8FQkr7C\r\nj7AYne2jSUBNSoyvfKRnkX4PHfiu/QxEFWlDj5v1DX0Oc15ILe5mtUf3vd2j\r\n5S5kzj8JtQWDvM0rcvZsih1Im45maeml5sMWzdnP1zucXFv8+S9dJkfGivgp\r\nmtRprJcXub3FJGia8ErCRM961fEWfaNamsXCixADvUC/7jABGgiAO5Sg8mYn\r\nHQEyV2fpmMQwduzNEo+TrF1xu98pq7HzFKEQJ9cr3qJqqfNDY3tPRFh3QOFR\r\ngO21o1EipcbwmhH85+63pIWgwdKj2p4zAZNEUOtjooQh9nc5+TIRaNYrKQhO\r\n/sfOZ/xLmsv8Q3txT6cTn91AfxzocQgqOBdqwT4kG4XeozOdKenWRepKD2Bo\r\nvi4nY7zGxAbgP61AwNsNKgrPJG4LcNUrLIMH67nY26EY8TKIuUBvqPe1779u\r\nTqrH2ECFj6jiz7HMKxUlCzmjQv/PJM11pZovArr7HPyVpvvV/dBeNxVcsRP4\r\nOIc6nbKNARm8+ZkYIC4Zj2i8HssU7/aJXe8GFcP1HmBSUknS8EWxDRorUEn9\r\nUi/4WYLz8l4VS4nWMeDOvFbHKfzcNxOlIfn+jz6HYDHzHSubsjWbMVq8nOoS\r\n9pH2Q6NRm+utq1LzaoKdNBhWwpaZh52W3t4=\r\n=OTtc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c072358d6687fd73c7f22d529832e070bea875bc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.174+c072358d6","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.174+c072358d6","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.174_1667590181101_0.6457094405791541","host":"s3://npm-registry-packages"}},"4.0.0-canary.177":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.177","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.177","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"49356579719e6dde30b86e0513a7d8f3e0afb7ad","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.177.tgz","fileCount":61,"integrity":"sha512-s4F9yTj2XbTyYKugI0EdXr/W6sz3Eb4R5nMSU7OtOLmqyOK8PWef5Wu6mY/obBZB/hnqjQAB+CAEsH9IG97jvA==","signatures":[{"sig":"MEUCIQDI+AVMFfHK4sLpdPBCKo35yGm2zEr45iqfhWJ97vHhQAIgXw0xlg1cD2QHHhxAQxSqmNW/73pQrwvgMqadu7wAtbs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZhTDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqJYw//cN9gAwcS5S3sklv11TqiGmVL3PIyUCUmWdZHu7epSipAW3aT\r\ndnW2jPDWmIoDYWacwDW2+Kx3LWMvnTAHYVB0bEBRGGPIaPk/ey0PVQ9NOnJ4\r\nGxShlqIK4gUDP/LI2qAljcPyXFuwVG/ks5u58e31PGV68RV1QpP10RIG8+TL\r\nqZ8vwXNIll0P7zkn8JevFv9E+H7SDbWP/t7yUC+frhZo6l+RaTLJPZZKejTP\r\nrbGzdgkFNZdS6uJc/IHNZSZiaIzdVCZa3huOxJPt/NTk3VXISAVymqrKXhdQ\r\nZuLFSngIKuG8R044kvcXcE+sTLfAO6dxqufuMrn5No1J8WgpGy3Y4J5O5H6S\r\nY5HAcYIKhbAbI3/z6+uBYSRS/8dZmc2BhhtT64UNTnZw0vPPwpg26OVbIvda\r\nXbmOe7OMqFWuTpzbrFjrl8pI61PhvVAnkI63fwYYBtFb5RBMY1BgXjPCjuoR\r\noSJsuAU1xDQMYTAyvRJVeHRk+FANnvxs0dHDzxdcf8XdX2ObSjrTrWxXECjg\r\n9XBSiZo5Vmat7+kGd2drv4LuHr4xddMTtp8PE1PV/eFWA60mHRyJpFGdXBCl\r\nRkNyrumJJyfmGi8ssHmd80KFgFPwxcNlSofD5lGyab419bcpm/+/HgjcECm/\r\ncAMZYVRyrw+VMIPlGyfZ2gKZMgnfRW/dBWs=\r\n=/Ak8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d75569e86c018ce458d3c850da0f03297b498572","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.177+d75569e86","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.177+d75569e86","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.177_1667634371619_0.708498900431102","host":"s3://npm-registry-packages"}},"4.0.0-canary.178":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.178","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.178","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ada12b5b1bf99c0bba4b8f6fdf929702809cc0b6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.178.tgz","fileCount":61,"integrity":"sha512-Ny3z5cdpqfPDqiKpIgFwswOuPKjm9JHNPN+QxrMwsCtjaPzeftXIls1hmFbsw41v2fhKV2+C6llLTXfHXqQ4Kw==","signatures":[{"sig":"MEYCIQD3m79TQS1fTYpfI968DqS93qbTww3fBcxysB/uK/srCAIhAJeNjLNLQ6XJfu6Rnzb/y7NYGvZonX3LELbyDZ25R+Xs","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZjt5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqlFQ//ZE80AnK+HTTeu4ut8Komda64x6CFZC+qJjrD2pG/OS8gkenF\r\nqMCm7jTiqojrR4CgRyXd/AL9NT6A8XwIbAg7u0fULkOAhZyAoeCrP4IBsF0d\r\nWgzMLrHub5E0oCqQM8ZRMR+vdxyJDLZt5QQcjH6GJsyUy/e79wP4Omd7F+fl\r\nSQIeYCJiYg0ZjiOUm9EnF+5FaFZUTtrZ53NJc4J77FIe7ZkxIrxjMseYPqVu\r\nkRN0/udD4aTjmcMhMzY/ioSIxYCYXbgRDjOAhMSyWlaiJpsosxKI4N0pEPpB\r\n4YkSn7HPhFHciFNs1qUZRfYrlXT66ccjiu2Teq2EDyQmzuqJHcVCdT4q9fRu\r\n7aatDBp5W5JALy6TwjcdRDvc6beesMs2xdcEgfW0FuWq5CIbxP5AfBfzDwPl\r\nmVUHLfpxnF5RA5NsWPnECLxmw2eh9v5Eg2U+c0DiPtwvm+xiauAZmk4WH1Ut\r\nXzPez/0iCOclOwwoi0W9848ZOh9QeFSYAfEdhsM43XpmgZx6364z7r8fJ492\r\nOsMx2ZfHEB2vCp5oIDVhefYa1LKDGwCQgf6JzAkrbPmCtnglCmZ9V1ZjPask\r\ns4r38OP8bDcU0WAguyQUXp/FOJU3/YTQ4k2aQEjR/kY0nMh3GEuOP8eK9lnt\r\ndA/cmOgPJgOcQiTD0CMItvcqnOgUSlT2huw=\r\n=j14l\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"16ce2b034292fb3bc864e474a8a95a1ce70fed60","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.178+16ce2b034","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.178+16ce2b034","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.178_1667644281311_0.2379852494331154","host":"s3://npm-registry-packages"}},"4.0.0-canary.179":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.179","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.179","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"37d4c0e13d0f70377727804304d30fd09bdeadd3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.179.tgz","fileCount":61,"integrity":"sha512-4pFvbiLNQrJH2eL6/no2qsz4UOqZ1w7zp87fQg33e/h6Iytud9ChHNxqLc5jidB+/ztOq+paUphOSDdCZu4IRg==","signatures":[{"sig":"MEUCIQD/Sd1BLPTehiTwWYEYszZ0ERnrHHhUp1aoDx2Zm869oQIgWX8lJBGlfYZP4GAIIgQouJYzx7LBneJVBK/TcAxLLOk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZrCMACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo1wQ//RG4Pph3wSovWVYdK/5Z9Ud2jngLFLYRo0uoW1KvzDsoNo9Hb\r\n6bs+PbkJ1eMeIXHbVqDmm7MR7X5NFp1WUOQi1Nad0czKIsxGnihi1JQcetrg\r\nX4GjSZLmzgJC5Cl7nOlapamU7MTlSN4d3WbjFgIiZTSLmFlq2QHWnRrn+Q2Y\r\nBh/c9NI3VErYpi8MNdT+ucP0gRC5JlPDcSBHOK5WGeXnHqTwOsxq7QRIcFnn\r\nS6AcsU4iGzIiW8903TzB8yqa7hCGrXjOlCGwZNBwdkRY55qWl9a/01WaYlij\r\nR9NzLNCbOrULzCPsovf/oBqxD9DWtNqTB0RvJY68PHBA9x1ILvLy8XAcJvzF\r\nnINNKrvqzxCNmM2vuWHrOnMljs9aSbySa0HZm8jczuB9PPrb4OP8E5l3L/Lu\r\n/5jcqla3uMaP7uwcJxxLSvj6GlapS+5sbctParvKthZ7Ne4UM1AKeQiqqPzv\r\n/sG36mmGOjcxYmlgt5duJ5NchJ7sAROuEXmTHEAHOM8jfb9SEosVOxxM/39Y\r\nMphzPxLnpiQQxeHk1RIhkkRa4QSnk3Iwp+6WN/rHmKBGTPyFZZCsRd2wutS0\r\nMzPmNaeVkw1vTaF0PWEMrl5SZZzFjf4gVcE69mDdyMTRKX9XTAEO6HFqBfeB\r\np7nerLr3DR70iPespBlQioGhT8cxHmFElb0=\r\n=nDB3\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c7ce6d6ac4c608609cf70a1777078bccd15edab5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.179+c7ce6d6ac","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.179+c7ce6d6ac","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.179_1667674252180_0.6285816390267092","host":"s3://npm-registry-packages"}},"4.0.0-canary.180":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.180","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.180","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"877ca02ab1a6be7a6cc1327801eb8ed7ff0add27","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.180.tgz","fileCount":61,"integrity":"sha512-nJ48jjIqMhsoE+tPtIAi/h+7uI/ftwwN5jYxNqbH17W2k7HLZMKxgjhAGRzD6BeMPq65XrNJYokMDWYG/r/Rfg==","signatures":[{"sig":"MEUCIQC7sKDGtuLhZM8g+b6GM6BrsroEqEUYIWWGwjkWwUJOjAIgWcCB6idsVBt2Jeo15S3r0SgmucD+aadAyZDGdzbEcpw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZvzKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqMrxAAjjDwOR5UoxNIRER9pBaFaoU4XQe3nCGvHfNBGXKdfoWJqeBy\r\nEq3QuDompdjWtJIZNP7/Hvc0fv1x7pPrgFFdbNc7+W5twKBnSK7ywZZ1dWGI\r\nlzoHQO4WaQBKoc0gIism8mZvKmD6L+JgiWCyBpSd3kB5xWjEJg1Mv3jN1BWv\r\nzDANTLcMqAbn4MwtJpgwoP1lVDMICLtRjVBmONpzqts7cgWkvGz/1ajeg/Ix\r\n2Amy8X0o4nMSaHwt7f7UhUUnSZ4TnE9LAIRlmJf/jRoj7PpK04/PPeK93i9/\r\nIsu93Uio6JVGNfQhVrZDadZJAlC9pjanpmro7H0rQfrLyzGbU+5rrjdLvFEb\r\n/zsZ8s0LSa/kxyaz3oMRDV5hMzOeBp8FsKD5OzNpt38mHcsNuaiqCdeHcJEJ\r\nRxW7iV6XB+BUAVm5nXZ7GlzGBD9Qg28HJohagZ820mcA0xrWDPSwNkqvr1i1\r\n8/L12M75fDVB31wb6wTU0vg7QsJF4Y304foSA53zjXeD8wn4DBkjFvM48TBC\r\nzl+r8Mf9ZK+1lmZvH3Snvy+rnb4/SRI+darOeSIOJ1tk22iUCYvUrdeVYiIu\r\nw/X+BpJMCmIL2G77mThuLN7Yxxl7ZD6GD8MI2IO7IdRXVGVWtGzBuFREnA47\r\nAjH49EidjpJDlx/2jbXsDVDHb1ToN2uzIlQ=\r\n=amNI\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8c8443747b0a5c8d7b19e72863cf6aea88d6fd4b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.180+8c8443747","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.180+8c8443747","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.180_1667693770171_0.1473765783145664","host":"s3://npm-registry-packages"}},"4.0.0-canary.182":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.182","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.182","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"44802844e81242324516c08e7c25325978a821ee","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.182.tgz","fileCount":61,"integrity":"sha512-RCCeuAvoVYbdGzdOX/iVE1q/Lq816xf9bv3T71MmgYWtK6u/z6WghG4qmRwtNScjmNHIzSoXplDOFVzxJzFaew==","signatures":[{"sig":"MEQCIHjmdwNCQf3kxHmk9/r1lXJnB/bW7B/bqeUN//VgESLFAiAgVI0c2vBMhGYG35u2aRYrbvJQVzeo9jJgf1u0wzC/FQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjaUJGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqP4A/5ACaB1efUCGKy2v06+Hc9pIb5IEiygxjU4WLPkpyB0ojTfSgH\r\nOlWONb0tKsmUYrCXF/hhm3Q/JqnS9mKIcluXj1HuhPSZWHMBP11G+0qkAqGl\r\nCOWHU64uArZ4PXUha1MkCiETPEz3RReAga49mHGB1JQMwDM08ZaxfcIb482M\r\n+QbNArnoB4QHETznZPdek0jBU2rFBfltg4IBPhKiOKjC7Jxmu5qCNj7k8Bm3\r\nqycoCuBeYksuBHxEYgY7KByh3+yXrBMqhzKjqT6n7lK77jfW5IeneB4E0+HV\r\n3xBKk1lKMre2mZw9ndaXEEyf+Fl9xYiQ/nC7Ip2fCRyrEXi120aCaWU9gTV1\r\nnL7bUscmZtxiQgAw6/1mHk1zaNeDcmQLBqzAEdcuPxQiVxpews4seQcT1dr9\r\nq1BsVzH3gS0bs3zUgVc32AtykFCFcneC0hLyfq8DFqm3WOJpcWJQc+WilSEn\r\nfrWAHjkJdqRvUbFp+iyniARBdOOA3U8vvlvWKfZ62siokQEnp7uwCY63O/c8\r\nsx7WxlJrBHSU06GcPBMkcWDAgKZLMcT9XTQ+q7rNcVJhXZSG9wT5XyikVr5i\r\n7VC2rPnHBY0gUBjgPOT+uXMduHEBQdACkUvhes8LmdChu+oVbeOQcsetnewS\r\nUakuAoqvjqaWbnUkiXyT2hdBrum5b+mu9Hw=\r\n=OjSk\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"176fa01e13b8d0f2cc39239b74ef19c4a324642d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.182+176fa01e1","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.182+176fa01e1","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.182_1667842630313_0.8094152915652748","host":"s3://npm-registry-packages"}},"4.0.0-canary.184":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.184","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.184","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"90427397a7728d72dd92aaccc1878d7ea339026c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.184.tgz","fileCount":61,"integrity":"sha512-hivXNxAAx+Hbubdy9PRPmi81wQgyhWGOrF5xJBRO8+EzEfH9/KT840mH5JQ8bMiEEJuHNyPWrzK8RgI+ZFHlEg==","signatures":[{"sig":"MEUCIQDGxPHNKFJhmnaH87qPhABSz8WU3bWhMJiUnnZztS2W3AIgeZ11ZWYOg0ygjzE1r+D2dQ3JDBinrPIi8NWSOuytJgg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjag3DACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoF1w//QZJR4bJhmI8e0z3MPu196ddeSK2R3iPBlb0LBnGplXeWUskU\r\nrPmd2PZ0DmIcbdk3YQ71mx+b81FN+6trnT57Rl7llcjb/IEmMo8jyjw63n/9\r\noQo9ZikWAA2liDzLYuM9sNFmTOKmrq3MIgniAGpcJa11XKu51GFIRLbzcypc\r\n4YJmm87MQ8i+JKDCMWSCHOF+cZd9A5ns/t/VD3NtVnQ27XhgZ32Q4I2v7rXy\r\nOXFlhLsKYVeWXrTThXof7u1+YuWlbcbgPPeq1QScXVuqfzw/HB+6Xipkghfz\r\ngbOWjxPBeK/L3YZD3GmTRqlUyjwkm4wYlqsTpb7gJkTBUpK2iL4if/jKNg7K\r\nCB1o4O8MVYdqhuaJsvqUymAhbZ64pwPpny9tPKO08MVxDlEcIRb8G3SStub+\r\nYa97twuRinYJhOTnAW7k5gWdYM8E3svGqmrba9F4YvtdMK7hR0/p8fOiWIqz\r\nEb0KD1ojUHkl/8R/j3npkhoeHKpZ60fGcpn4WuHzDKokdiAfD/OSOIQWeYLO\r\nCdFHgX9o6wdmnLf9SYamSbllNFoT5G/4ys3LjB1CbggZbA+mT5jA800CMxrv\r\njBMwTN8e0WDHb6bASMFCZDCkwl+8rLqipyCtnenCIJ8/OHcfYhQSqPc/H77k\r\noRdAPdU6lwr1XctRpzJ+wfrScq1s6afdCFc=\r\n=lf+X\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1354090a940de2387ec8d87c4bd48c5c437078c7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.184+1354090a9","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.184+1354090a9","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.184_1667894723360_0.9304109057797405","host":"s3://npm-registry-packages"}},"4.0.0-canary.185":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.185","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.185","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"72730bbadba239d79f4903329442a476d07fdff0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.185.tgz","fileCount":61,"integrity":"sha512-6mSets7hU2wGsGuWLTGWay/ZgQtzv5DCvU6pv56RdaOrpAhYCvm9F9uxzAeQ9JcwOX/uqKddcMzHaeOulOYiHQ==","signatures":[{"sig":"MEUCIQD/n+92Ta2aJb/05PhryuH45tiit2AXY/KIrE87iCAIXgIgJwAnZiUJlhhJFZ4TmPMVwduEGgqxVUUWjwvI2XMqO70=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjalzVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr7ZQ/+LTnOKR30lgkAgrFoQF9vOj8mq9acaIcDTK/5FZEcY/fbb9Du\r\ntOKjDo5ZZz0Tj5LsaBI0qOqbIx5/z9Os5oNPImIC5lgHZDet2l2HmWUWY/KZ\r\nE2LUOan0YO0y9exz/tdrtM+VSifalfi9mzYvzQmbXTSEvuf7lWDLwqlGhSod\r\nPwZJYWIpnt3vqG4OJuKNRJSElXalm+LQL1aNbl8IEyN4XuGL01RnfuOiZ5fU\r\nLP1pCgNzZ6o+J/FZZN6Wqd0qAvjYJ6JU8tLvcpiXYEkvpzMMALBiYEpRbrLf\r\nBPCv+YR+7iMq3yFe2dCbUQkvgGp0N+yQAoVqre5IFkiTDeG8CH+POJNNUzNY\r\nKgwTpg2nmyfYa7qKji2gCSHKVuhYrtNwnAaf0yaKYWfryIWjvFspr+kAKo4C\r\nZNiG3yF1uB+ABw/i7Auq+leWaxluQ9BdU33LJ8pBscI8WOGG6BUf6xq4h5CL\r\n4+gaKIIOhcOIm9xQbaLBcDwk1QVUq5cl6Asaof+CT/JQnY5JtFLwmLFDZHLE\r\nSGEL6oVKlI2/NxtI8iWJ9pRJ9PLX6fDVhLmxp9fR7UbfXb5DnyN5A9C6G2EU\r\nn/ve1JzREp03XyuGB5HHuzpV3GgXEiow16iWQZWFp0b2EHEYYL1H7qSyceDa\r\nu4Rt4Z0umBdXXRqxgGt79hk+hEZDUJgrxI8=\r\n=dg6I\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c2275948bd90152979ea3a0feb87021a67babcef","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.185+c2275948b","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.185+c2275948b","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.185_1667914965018_0.48385855425423796","host":"s3://npm-registry-packages"}},"4.0.0-canary.186":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.186","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.186","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ccde374b3d6f15ff361cead3994439f379d0a4ad","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.186.tgz","fileCount":61,"integrity":"sha512-+LdA6Fb7LFtHr3yfWjoh/KLaG2grNGMdkkWYzxh3URcnJbTsgXh7dvhl5D+eWvpq7etMesDEXojYsmUUD1DptA==","signatures":[{"sig":"MEUCIHmujB4aCAaEL7T4iZHqOnK4l/PIwOZ2bmrZ4fFVorFjAiEA8Yik11igTHm+gzBmgZtcQBEsARbdZrSBIOs8x6oTa00=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjao3rACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpNjw/+IMKvbiOXEVHbDi63aLSmx5KsfwgNcQujFIKlb+usQomRibS9\r\noQOdblbpdtWIpvCwzMg+DStdVUTvdo8csb2/D/JPSon7KBv/OHeccTXMJk6F\r\nWldx2bPbvLIxfZSoDIUifrvg/aRJ15cPddLo21fao/7coubuNmMhtJCWZ9yV\r\n0fT+NmSYHgXr7iKILpY5BcZLveGEBjFhPayNbmD/RzqFcKM/q+KjOiiSTKHK\r\n5pWWMHfQXkKNoGqAuW0kagXNiVWa+qnHGZO9VnIQSZM3/+toS6GGUnLYy7/S\r\nRonnvCBQiCuW8VkvNB5VWY+99ymk+D8DQPxISpYW6Me93wNZUv8kUljN0vD8\r\nc/FdEUhBl94DUvryAya6/csqb7ShgZp03xCcfWdcoc7D5G9sgV/v9Rg5zjWs\r\npti4O+yANLb/5dIBaKFxhjOZS63Ht67zL2PHcFEqupjRXcX+zBIbg/puRwQj\r\n+3pQqVJDAQGAEJ040gS++C7fRVipe+CriVlg7sQXvrakdwTNVV/ztH24A1Jk\r\nHa2k+ru97YvUQhOVdrtR6s2c6pz0TKOyBgwXwnGIKdv2d7OUNRM1peb5tPgu\r\nqFaZkdCudWd1/3/3jR9TDyY/XwaqQAW+aLo3um619M+RLC5b+osc5b1HRRe7\r\n2kf3DHOVWkOwDD3XMREKPThdGiogW3XZFYg=\r\n=0gq/\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"49a12590cf0dbfc55fef0b7f356c23a58f3b536e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.186+49a12590c","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.186+49a12590c","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.186_1667927531073_0.009410423185397532","host":"s3://npm-registry-packages"}},"4.0.0-canary.187":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.187","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.187","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d55f7779835f31f8b775b661f3bf9430888bfb08","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.187.tgz","fileCount":61,"integrity":"sha512-nH/9CrKpp9z6qy4CYFmK07T+gPcyxywYPr/eciUDJS7x33WmtNSdXqdNiottA//u7mV3hPsHaMmodj865TnPng==","signatures":[{"sig":"MEYCIQCTxItQqtRCbjcV/jf3q+Pp5L2hVLjz1tXDtEgU5TdjnwIhAPkXdzmJURca1Y/BYjbZcLg3vwpObeHAFwspsf2JiBO0","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjar5TACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr6lw/+PytIUmUleb6V4SZMjRoqkug4ex1OBTf4O0WFOZ6qPAhumcvw\r\nUqddns4XjXBk7dn+7rq/wHsRglvNLp4CU6UdhH+3J4RYPX7V2krF8kckNv2o\r\nrFWWUycTuuqSrRZvSh9IkvltIEt6iFXoBoJM6ghN3fyU4HeWBoNcRPpwEY3J\r\nbbPo2UVIh8bI50FbJp6qBus/pd4Zy9m/KpBsgtJJLoCH/nPOCfF/rW7CfaW9\r\nRwkEmHIqlVeiOaEh+jg8JsTprwSI2BTHUA9WgUjU4vRO0BADXhyl27gyUiH1\r\nviP/j2PWfWza2fF8gFhV3Cgco6QMH5CFxYZcd89EceSqfaWMYe7ghnHXmS/U\r\nfC20sINK9yXqnh++kKA0n2abi+vsZeVIjFmsu90qumJVelpS67/EX9D/PvYK\r\nh7nwIm9InCaGagWtM6wmqI0/wOhNCvsrvp1HFltDKHN2GKakMm8h4tf4w/In\r\nUJ/daeXejC3XPqXxfubGD2LjZJSClyVXC0YBDrm16uI1C2oonWhNnJEdbYdJ\r\nbKxLSFsmPKkbe3mv5s9NnnVEdRGV7XBcIvkShnuWX5Fv8TTAzE+GT1nfOH9S\r\nGf4Pl47VQT0tJTsvlkYqV1QlyYE38POXB69KII8DFipky17l5uaK22Izf0WZ\r\nB8Rd0x7oxdpUUb77sSVvNVWKeQNrtzlcb70=\r\n=+xSl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a0b262d0bd4dc9df3b79ff6675c5a33b10c2daac","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.187+a0b262d0b","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.187+a0b262d0b","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.187_1667939923187_0.2400609040755448","host":"s3://npm-registry-packages"}},"4.0.0-canary.188":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.188","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.188","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ce7b42d31e57afeeff9af13014d50d8cd1972b24","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.188.tgz","fileCount":61,"integrity":"sha512-JkRaZkBZVu82qXlFiC71QYlDXzPT4cB0gO7OncWhxJ13WIYQaCpnnbLHZ6YHsYyKS98C0UztHhmoq0CD1CaYOw==","signatures":[{"sig":"MEUCIQDXBtU6JPYIbc5ktg2ZA8JX+sFSenrMn1BsOVTscPeCkwIgTBGeJCuRJa71nFdfJrgTN3ngV5x0AW4tCmXFXHns5fw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjastmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpeIw//Uv4G6zhkQgZw+YHcPGabDW+TaJ1WePk+xcftOk+ys+15z3OZ\r\n1nqA1cHeONolI3UOytQK16O0f5fyVfNZCZC+kLFHzp3jByi04/zsdOnCWOYD\r\n00icc67gBYvO4IhpFCNtXcTBPgc1dluhmoceSHU6Jup8rq26IDSgiU1SNd2n\r\n5cWMpCz2pGxrTywNsoNxeBUk/YfxYGosnVtJHWal+MXbW80AP0DSJlKmrPoj\r\nIR6vaFjDL5PEAGWpG4WfNi4B21MuzbRzfJPBsDIIhU613I2pyXYA+e6HrhnQ\r\nAeeEZ9o51svUcAajP9TmrgNxNk855JyUVdhd5KvomYYrk2W4FvhWy3jqJVYy\r\nzYFIFsVfS6CqvxJ5JgtSNd4M8SSc6Yl3s4oGcqK+CiQh+9hQVP4CU0BKeMTR\r\nD9EDKJmi7i1kWzu/4ipvDwmROs82F90c7U8JobAn69zogJ9Kqz83YGu6SDMi\r\niTR0IDJyPE/0gZChCOO556qj/eWHX7z4MVUAnjIeq5fY9UF/el1wfLvhf3+v\r\nkF59Jf/YYL5AvFmbV+uPmkMRYXOxuaSi3YfqpTiYI/tfcZdCyQXemRC/5MCx\r\nr9+Ne6oab+0U/POfH9PUWpgYXQT2DFf2R30ixaWVqcJkmMlAGQle0JTWq9NS\r\n4ppgfbYqq8R91tasHEU5PYk41iq+dSemogI=\r\n=gy5S\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ca4f2bdb5359beff51d859ad8d37f8a49ba7f393","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.188+ca4f2bdb5","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.188+ca4f2bdb5","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.188_1667943270729_0.45923719092166104","host":"s3://npm-registry-packages"}},"4.0.0-canary.189":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.189","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.189","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"dcff1a96f77716160d4a3c1a522acff390a4c0d4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.189.tgz","fileCount":61,"integrity":"sha512-ZENXJ5FB+UxIyzjj81eJZgkYzmJ2tEs2i8ZCPZgmgBfF1w2uBNj7B8iBN+KC4Z/rKTnnIRMm4eG5geWF2OS7Cw==","signatures":[{"sig":"MEYCIQDFjguOsqXWz/U/4N180+XJD57tGHrn/RgERjJKDib2rAIhAP7IugoTQKFoRdL4phvxXGXIFpQ+kLGf/DgSjSDD/1ra","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjavf6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr0mRAAmnIRwQnj/CAb4Mdik21Bua4LdN8YbZk6PVlIzn1n/oQVgBX6\r\n9L6ke8H4BYlvlZIeEFG1fD6kPOJ3e5qE/XzySUP+CQ/RONJCKThqqB4dAus6\r\nkGMATrNGRvNkcE9dYpvgtaabzUkCQCDBUjzBx/jKLVc69UGBG3YMqd/ufbw8\r\n69GNwdRLjTHb0OQOfAGOsdkiAAs6yBa7TfIRNPzXkWabm+Hd1xG0qJwOcgEv\r\nmd0wuJCKsGlfq0CB1h6z/yJ4v8BJ7atne/PaseeAJgflWjlCw2g4Z6ACFHki\r\n/RRxDyZ1iOWgGI61q1/+u2ydxdsj+LWHTPyykuMnwpiFPIfMn03wVswCo3lC\r\n7cCoViMHAAcfLpqUdtxI6eq3sIvJKgPDeiYBSd/Wl+tXX14ANG88Q+NoRiI5\r\nGIQ7Wv3Is/MeAmdE1TTxsGEces5gDobo3qhuR+OIieivxj0HZzsow7CDmMVz\r\niBReFnQbED3uNAZarDdkjg8ryGgYGEsa8NuCIQ2zLWsW0BD764H/uBQdmBD3\r\nxR/Zoj727jOTnWLrrZ4kmyESX8CQAw7w7l6j79tRUicX3vWWs3T0pcErgwFx\r\nTpUw0shsuqn1xVMDZOmxN1QaTbaPpq5KrAR/nxqnHHknQdSwo6UWvcsU/5v/\r\nJNw7VvrJuOXcQuNJvsTQKM/F9UWLav1MQxQ=\r\n=KcO6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cadb28725da05b630f99493343f20b4c3fe3bd1e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.25.5","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.189+cadb28725","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.189+cadb28725","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.189_1667954682062_0.363869595447881","host":"s3://npm-registry-packages"}},"4.0.0-canary.191":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.191","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.191","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"259a564bec7a4d26c29c4e401a9e72f67fe73a9b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.191.tgz","fileCount":61,"integrity":"sha512-n3Z6/Cg4XAZzf8uGpjz0oCQJPnslmY5/hxClOstJRqX87c5e40OY4bLcvipkrHjZO0XElGGEBenzu2eDkny+dA==","signatures":[{"sig":"MEYCIQDf8RhgsEe9KZn8QK6qAMacL42T4AyDGshcsCk9apy1pAIhAPFEuZvERjKXfr7Sx8z/V4mGld37fahqBgjJCXiTRPlF","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJja08BACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrAVQ//cRAyADtRmomdLbgHvhD8teuSES970T92uHoI/V0REx95S+qc\r\ne2GBAeC2H0spepfHYw3KM1MU8Im14ZxOUJvjSzUgTcaIKRgQ2YZjCSJ1YcNK\r\n2RpxdKT7Dszu0arTMIEvXopeul1dKbiLTLQapdDLbHtrxZ+cKp17lvGly/Cl\r\njiguvXA6pAyndzjWtAFZ23ihfQ4Pdb8FUvnDXC9EE7UHKCA5aUJn9ppc1JJE\r\nPjYJWmpG19m7rnD9dd5WykAIBUCOVJiBlVUEV8vOmpW24qfGJ4lFT7lr45vL\r\nSBBzwzxq3Jzf8NOYmj/f07XfOcPpka3c0rTIU3W0XGmiKiEwyop3VNYnBZMZ\r\nwl66nZTs6FQyJTUCo22Yl+Gwdc1oMqJGN4hlwK253t9z87ULsbLSGhTHbj6q\r\nbUaXO6NVpOVOK19DfVsrlASK1CJyxg4MH2FPGm+y8tA5gDtFnomXb8rLXLz5\r\nIVKwFPul8FUK+8DoSVDad98Ib6tHovywyZ2dqYFEPEZ8jRmFT/I1mDYOHT4o\r\newl5E2lQuQ/YWFl0ptOtyzTje3Vditgb2ymqCQvN8D4JeGJhqFMc8dMU12sH\r\nmpIIOb0gQeiXbaUkddh9kcq93BC0mH58SIe5WjZL4/FVR/3L/25oUWuRu4JZ\r\n5NMLCYFeperq1ovGM/Hn+HM/cP87qzD9eNQ=\r\n=o0Nd\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aef46be63aea29a3e033cd9869969bb780fd634e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.191+aef46be63","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.191+aef46be63","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.191_1667976961445_0.6395525129168824","host":"s3://npm-registry-packages"}},"4.0.0-canary.192":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.192","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.192","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"87a32a2d59db57c978171d096020db6a40f505cc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.192.tgz","fileCount":61,"integrity":"sha512-WLMdDhXqTGTAhrjg16v1nrf5Va1QwIWvUrdJCTtHBxw4IcjEwzdkiwhFYMlBu8cN35HuuPJvQk+ml5kBu+X7rA==","signatures":[{"sig":"MEQCIEaaDSXx1oRMEUBunizlvIuUt1MP8hDRQxduW9ospYJRAiAuASk/oGBaTZDU45P+uZ9K1a3EdRwYfT/tcLhJLsR5sg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJja3HmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpFmQ//YzpPT5X2Yog+KrSyc774iwYOydiWI4XqgG527ysGgTatbdA4\r\nkf1eYgiJfjm9fhlicg8N+NGCR++/NOUIdqjERGY1nnmMM/q9Hl34/OhH8kNX\r\nBxHcNHqmAycOK37cWOb8a22wCkIrffKVVH/ouS8pz6u1/vH5VTLEdVGbErWy\r\ngOFXh+moOL1TrYwxndmJDT70YpnACfKcouOK1chK4QAE9004vZciGt215chz\r\nuIu1ADfeqIGpvhfBY0JpoErjyYqgy9bDb1f+jSwG+XoD2sMupGqal9GrMLOp\r\nn+cAexfrnfqvnWoccg+lVMIFSX0lnjuIUAAjbouP9n2aUTeE0X3mQoZjuDja\r\npDCS0q3/jfuAgZUmS8W6fpYSFkqvnHC/fbSQ/Hwa8qsDeWkBNpFYKCZGO+F5\r\nWFq6iuYP0f6Kh3w/FK2UMIF7H2Y58H/c4K8lkPVK/lZji2EFuV8v2PiOZVHd\r\noUvvfT8kpfSBZKBc5wWUph0+1UlXsZAryAdaPFLJNq2YiDDoNe4F7xUSTw0Z\r\n9jPdXEvo7RUxdlvHcNcaR2YzZIXCoeSvY2NMwRAkcMkyv4O1PBP/MzRf1pmp\r\nnBIK6MdyOkKF6qY2gFbWVeRXv2RH1/Dr7PfQUE5+UA5yYj5AQDgLkiWczGnU\r\nvcVHmAeKYx9px+Hx1sCzEJE5v6+YgcmHFRY=\r\n=ZvEC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8a923c7f9cc0b20d495c7631acf9a62f3edc5c8d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.192+8a923c7f9","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.192+8a923c7f9","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.192_1667985894185_0.022845355166446257","host":"s3://npm-registry-packages"}},"4.0.0-canary.194":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.194","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.194","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"24cbc1eb9133fec9a8b96af0f3b290e5e6be4d19","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.194.tgz","fileCount":61,"integrity":"sha512-TWLp2tiU05IZMyylSTK0zoVIBhliLyX079FZ+8b+78D0T58qPMP/EpDSFYl4jtF8e51tRfzu0oNatwD9xU9dFw==","signatures":[{"sig":"MEUCIFz7D5vexZXB6TaCn/PBPj1uduqjlwyxBw5ZLmCvnXajAiEArt2xkOIh4hI4WUW6oM14/SAoHqOIpvT95aAlVjSxhJ8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbDs3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqd5g//dYcM1VX2WxFatFKdsycaSwOXBpnJ8QA0LtnhUndxe3M0SXM2\r\n2TpQp77SYSxtn0v+5/Pu+dxl2gpctT/vvdg5IvVeMVlNqZ7zSmqP7WW8+Ezm\r\n4ter4GMObYfsN4Yp4umrGteMeb/2J6zm2piXEKn8ye4+wrn6nNvsBc87XIx6\r\n1x/4FFe2ZuO4uEZfpv8/hmFHz/BEEHb3ldIgoZlUii+r7f59vCaV0ROjqU7y\r\na/L99fOZh67Yc7v0WmTMwC2N/KKaNBUsP+bfkPiIM836eFa1faY5b2j16dy7\r\n6EU4fSqVGAHiK1sJJEpig07qeoXMQOCmkKpslYgNQDXJw2BZS6OG79hP9NnW\r\nkeYmpCHNw9wlGS5FDYbSQBRM3Tg+T/FyN8i0h9EejkWniyKyWuMaNoOTcre5\r\n5bQdQCRpWvK9EAPJLU1JWn633EmW/gy12/GHbFW5z4YYhDiIpCWOfcx+XavM\r\n+FxCSBnMkkfKI13o7APm1jikwTdXOZJ4nrsurFq7I1wejz3cRwatySNabVbP\r\n0RGt9ZQNybwILKdSNCIBt3adAkTqszZbF/Sun2piI8UHjMnL+TwvXYnP98as\r\n+EkG6pJRhUkDlp9/0hee9LC+X6bFMG9ooOEK9aabnA9zYRiQPtyzqCHhAeSu\r\nkQpL47YoT+2iDct3SejSU7KySc0t+LC5pP0=\r\n=0CkH\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cf9d43921cb7119c6d00a575d4d2447d82cd27cd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.194+cf9d43921","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.194+cf9d43921","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.194_1668037431083_0.6143031550835019","host":"s3://npm-registry-packages"}},"4.0.0-canary.195":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.195","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.195","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"84cbbd0af42c5f7a572a60f53cbc27b9203fb3d4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.195.tgz","fileCount":61,"integrity":"sha512-GpGKomhlEFMjOAKp2cMf4z6BNvZB1BpWDMpLvta8SrppsY5BprHSYP1qV+SWYkeBj1yor09r94mrD46hQ/JPkA==","signatures":[{"sig":"MEQCIAEBsuP1sO7ql0myldeBG46PMzNiQGNc+N3U6SQeQoYBAiB/x0GreDbG8jrU/LXLba5JBXcQp6scyiou2YsdzD8a9g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbD4xACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqPxRAAn//hGpjLv8c3OpRvbPPLYQEXB3moy6PMifrB0GXTt+U0KfvB\r\nvoNlR3OT3Vx/l1JqiLUtN7Ap4pIVvHrGVEufPO10caxk/9Bis3+eeMnuOIY8\r\nzStCI8ahX5PIsU1poF71Kx60YD/O6Ysz5EL1ZlohvzujEkYuOXwcVkDqLAJB\r\nci24KpRaiXP68qwaqdVQKKI1syyAPVwfYBVC+ObHjlaOPcx+9HozmOvQrycH\r\nEhgS4l3nAVbmh82/d5O4IINDNbV1EMOltYqb7UejBxqnFojemVUepJr/ui4r\r\n/GAo4qUiduUklPJJE5xhP7+9HgM16QkENo5DEWH6L3icBX+BTOe9LD51AQlS\r\nI3YFa2TCbKaxw/llMHKKS0JWWQslp7mUOhRK50eOZ5LglzygzVoIq+EyHa8x\r\noTRy3KbIDGY6DI7xvUEK8ya3gl+CVV8XKhvQxU7BkveoDOQbb54lDFfMSDZV\r\n0F1SvLIszmY4i0yZGfZdM0K23w4tpxi6SfprFhdz0Xn6pmwdGAnCPyhVzqTI\r\nKmG65S9ILt0VkSw97Eg9i9FptGO05WgZLqaWnqX7l/IHtoni+GA5q4msTVko\r\nFfPPF3hhjopLFgpQX/edll0gfb2BxeKfvzkSWYSqgyn5p4XZTVkqH+dnzfHA\r\nSYEmThYT95aLrvLzsk8DMVh+BzEU45LkAms=\r\n=5N7k\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"20f872864dcd50da2da421169681919ec0b72bb2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.195+20f872864","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.195+20f872864","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.195_1668038192715_0.7787275918657734","host":"s3://npm-registry-packages"}},"4.0.0-canary.196":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.196","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.196","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b6e988ce1d3275f5d9eb97f598d0013836ab789b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.196.tgz","fileCount":61,"integrity":"sha512-/iMMW3BPs0OSy40vKYLpMu+ixLl+anSt7dVK8DBpgOJfbMVyJfFM+5GGgpU2L07/6nEJcovfh7FEFpOmbTqJNA==","signatures":[{"sig":"MEUCIQDdM79uLt6DrnthjpwT79O4brl+eNxHT4q7bNMlyGnlNAIgMwtawnqzKHOgoAaxSKQ+BCFtGklhoxmmXr1ozOrr3So=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbEItACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqF1g//WzI4h3/CF+qZzrCoftbGafL5JDbImWyIECPzDy23+9HH7KmW\r\ndr12OFmcI2cH/TkqsaR8khCvnpGrugANDbnPn1G5msBiSVWouk57DcaeSHXe\r\nuOyDmaitKkgcQ6O0AkiFmjiEJI2zLeYt8NgiSVLFK5hh4bxr7KL1PmcvfAbQ\r\nHtjACNhrIKoKUXu2QeaMibzpode/oWjUdW1FoRf/xzoamTlF7Dy+USwCa49S\r\nJyAVxl9/iCi/8Cm2TziID/BnXRewlMvQExk+utqaJOBlUGpyM7Z8U+LoOxU1\r\njRLlBa1hIRM1QSipk1NSTvTSOMcftpDoDtrN9T/oD9271if4NdA2TvPtMLk5\r\nJy2vCyAxA2GDjeiAmTcCONNEI+DZ2zZaX9r6/LwMXpAHXCGpqhNJytHImvGK\r\nv2mz+/iMKD1VVQ7mpxXTH/9+v15ytmgQp+IQH57aHfYGkf3y4se7PrMSIsu5\r\nsMcH8nCpuy7ceXwVlHPhHSVsFCX/IfybtgNafhoUoWOmzsw1WsHnLswm36lP\r\nZ5Xmt0ZejDpWPjKtwKwzVeU/CUoDzJssiOmrGk3nt0jjnroBdZBkRCjH10S9\r\nX7zKZkzQuW2H5/xaoq0/yxlM6RnOv6JLhdPoOofMnhkUuqmN+8oqRoPotQm5\r\nTRPLwZrZ5umCNvzK3xixofdXbgB8T14lD4s=\r\n=nujw\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"333f54029835625848ea6dd2ef248065a44db32b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.196+333f54029","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.196+333f54029","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.196_1668039213126_0.053710073125846636","host":"s3://npm-registry-packages"}},"4.0.0-canary.197":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.197","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.197","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9832478fea4e7a833a7c75c10f186709a746648f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.197.tgz","fileCount":61,"integrity":"sha512-cCA39tofb21w3ZG3KJZIzqrebLhs3TK9mSRjnH6EWjBTpmIYAjGSzffXCOtMXfJGsjtqQOzepSa0Op2emLYAbA==","signatures":[{"sig":"MEQCIBVAy6MrQBeItV9mz9IhySp80RXKuSqT3W3ZykNmUvXDAiBjNTnz4TFLjmYr08u1yDVY7D0WPv4aEhqfq+cPnsB4eA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbEgsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpu3RAAlR5IvtnhbFSHXaCQ5I2135qhVmKosMoLlmXSoIpgrk2xF77e\r\nDTPtJL4GDgaodXaalNoXMZVtULsC4WmuAV4eHrneLOpkXDQBGJuzcN7wgXJZ\r\nFKvxQBFEZPbNNd15YX3x2aurxrQhqUPXSZCdnDk/3HO4UCynb8RwI6Bhl+cP\r\nrr6S3kL8ro5KNQBvo37OjqjcUxZw6CmWuNa13Kfm6eiWSmMYLGHSO9fPstgY\r\nnSSQJ+efsjqFZTrVp0dmSs44wCKsMG4WxXxQJXpliuB0z2lEnvtl5EJck+nh\r\naJwMX9lMnP48QzQM8dLOSsz1LKf2yhXY+hsxV1yZgrAYNLR2bEqe0ba0goMw\r\ntGEUyKsvh3ZhEMtvTofHusIIMdnqckwFdLwDcuJna5jYi5nfme77CmBWEz4g\r\nhd9S1zEIbWWq1biwCTn+juM4kV3R8dBQKaRGCkmorLHUBVHUccXsJh4EPV7w\r\ngUc8y9oBHj6WT0zQO+9EI0EzECoiKV+bhAOQ181YCx1JLITMrqxd3R9yTBQi\r\nlzlf5fgh3XKqaEjGL4smNO2gOag63DknmUqVF0uX0TJgI7A+DHQYWCKDZecs\r\nN5tEHeJXWILCcDhRbWZ++pE/DkiBJGeNnDogse9SKDhDaEnJRa1zZFkJK1ts\r\nRXtTT6vXbc9X17zLGLcmPrrHpSrv2nDxbIQ=\r\n=qclh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fbb7acd6bcf7a58d139b8ed33f962b950be1c3fc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.197+fbb7acd6b","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.197+fbb7acd6b","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.197_1668040748448_0.39651879322852834","host":"s3://npm-registry-packages"}},"4.0.0-canary.199":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.199","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.199","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"685f14853020eee6666ee36991437eac026c5565","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.199.tgz","fileCount":61,"integrity":"sha512-2b025g3gAn2iyP8WsEjSeW/qZgC9u3B2bFM1Nyw+qAaHgfDYepnNZGXjLraFbsuva8lU0MSgoFO6rmer7MBeow==","signatures":[{"sig":"MEQCIFKQ/zuWNPwtUSHu5WrrDhHdW8Lo3eQs+rlts3hknyLXAiAxyTwYXDAuaRpQPV3S6xscyePzzM8uAQIx44xgjkNF3g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbFHgACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp/kg/9Hd8SIAoCVwHYXoO3U8FAFuKvQvKXGpHEmly0fx4naUxTlqaW\r\nUS03+FucFFpTubaZQ99RGkVj7+4KgAlmP+3EIxhAkK5OK6U/CaZhOtJAjNXS\r\nfkAP7EawRsL6EpIgmAoQclwBjkX+Gkbyilbeas5sHaN90nYcYkC/+tv1UOv0\r\nu2lp0/JrQti6H1k3rUE9vqwGWu/nMpQOfPJ+5DMhBzq3IwpqDYDdp9TP8yUx\r\nDw8C/F2zgxgvt881yHKsmoK9Chk9XKmPUk7g56mA333UtaIkupXyiNTOvxpH\r\nMSKbxYeBE72luuKB/LQfuEji4zjPENcvQRcWIGPTa2tjR8F+YdhoiWLwNRbT\r\nz6hiL5crh3vwsDuDd6lpy1ziZYmx4mBDwvZvAf19NC8cZhqtFvsUUcek/WGv\r\n2j/HzGMqN8+4ORRFQallUkQUPBD4V5QdDGSxI1E3sM6q4woj9mYVK47NWSYx\r\nFKeRRPBloiSkZx93clEUv9ClMxq9zXT7nA3NHYrHtIyQaY7yPZmf5RVWinBU\r\nUPrDNKqz7sGwo8n+y+LUxptDMsb0OAkZA52KHkD8NRReAnw6paVU4fiwv7hf\r\nipFHm+jvRVSHCuegNJtTz9WwG13bXSw6+/sfGzJ2Y4Dq2vq5qiz05jnu27DM\r\n3rzAjDE6AxEkOOplanIV5Wip/Sp+zHXNSD4=\r\n=zwfQ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1d4b2c4a0c72fd390ac9a17c7570b3ef6b6530c7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.199+1d4b2c4a0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.199+1d4b2c4a0","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.199_1668043232678_0.8859183033604223","host":"s3://npm-registry-packages"}},"4.0.0-canary.200":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.200","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.200","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"51dc71f85c3986486b1e9b3f1a2d6977ddcc2f29","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.200.tgz","fileCount":61,"integrity":"sha512-ttxpDPu1a9qs5qaMEimwFYAvHVkHLUsOxj+9CJtNrf4SMxhlOUe/jqw1BPzh/lq9RBX6ssvESjObfwF9NtZrXw==","signatures":[{"sig":"MEYCIQCF8QILw1Xo3HROhz6idZESXYXG1J2UyqCucKwJwJNjmAIhAO48kNk07uerKCvZbPnk+gBZpS/KD8hbcMPnQ8uWjET6","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbGm/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpPHQ//a8dVQFg1Dm0vIfgpFvf8keB3NkUS6px11Qj3tiTq3yDrIXyc\r\nBNM6COzmwZWBqTgW1198u5xeRuAfw2hJ9zilIEiLB9p2rEYNkz13jwkd1Rf+\r\nWKkvoS8tRnf0wGlfxO4zGTz1Maq+qqEKbM7/3y8MOB7UWKdtJxuLnG+QGN3w\r\nTs4yZzvKUkf/mBglzWn0cqGtZcAhEi8A699nllwfM30P+ooYm5Tq95CFeB9b\r\n8chrMlJ/2YQ6aiWw2L62jWgpdHjQgqX7t+Q5RNLF5s7ljyuAGhnEjZDJyzGa\r\nrvZtfhsipOMtqE/PfvlOKS9rERctEKeAJes4lqS+XSt/L6tZmy6MG/qs6bid\r\nvFap+10lm2+66MbajHQDX/KuDhX6VuVyYOTngg3VpeiGG8LTiP2SA0f47jTh\r\nVNUoXIA5ylP0WijKYkJdPxTNBu3G41J0C85GQMmNXBS5ecb9zEWDoLdVNN1u\r\n4EZKpHNIhx0GwEVOmqUAmSddb6FrJ3fu0H5RK3JAFe0/Lj3zQzAqF+cGIJue\r\nLd95v/9H7kK/GosZQbxetw+1/fYPWUx7NAksqU8/8wQwZZUG1tC5vB7nyCaF\r\nPGu730gZ3X0cjPbXYw7eu2Snw9SSZOw6g8tFJlmweM3znv7hKY+lKp9T2zj+\r\nqb9JtQkhfcRl6k9wV3rzXb4CpDgBHLo8jMA=\r\n=ll3X\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7cd1204a56dfd42127fa63d04485e85826e71d07","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.200+7cd1204a5","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.200+7cd1204a5","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.200_1668049343119_0.9774584386008394","host":"s3://npm-registry-packages"}},"4.0.0-canary.201":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.201","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.201","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cdaf7ac401cece6096f1ccf115b98ab2ff2d3918","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.201.tgz","fileCount":61,"integrity":"sha512-vrAslIfpgg7v7TBVO3IQN9Eg1/EpKOBDA8idA6hMBBDqnlfGPyL6ZVBgNjblSDVZJxvPhYnzB7yhGxd9TiO+Cg==","signatures":[{"sig":"MEYCIQC9Udvr5gwyYVgh3WNKzuCMMgwmn4s3IewcyrzU3dfVMAIhANZmB5ie17XRvW6r2nNuAo1ysZOJ/vOyBN5wOgUhXx9W","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbJy2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqThg/9Fm12NTEvOL9NbmrqbvCGSuPyhaqSjp6CnPPu7mwqw6QcAfhA\r\nWp5QnIZNAT3utAxOz1i1pH96c8dzacVBhc3Ol19nLGnSlduBDljIwZP4R1on\r\nca2lQ3DN8IP2SpogtPT1Nfg6VNH55b0tm6CbpJvt9MS9nwsQvUsSwOvaDvGH\r\nWWqsDlk+ArlrPhgvGArfpmtmZUUYBIkgVr/DK2HBD0kp2ZcYR5VpHWglL68c\r\nSKjMyyqVV+Nqd3ipFJSUQzez0J1p+V1/iCY9tfWma6f8iW1vzID809kcqoSn\r\nlFp79Zblp1Nv/dM1nzlpFHB1GW+8SII0KWOdH3T+yGSqCZHyJAFNyWsVbIWe\r\nmFYE7lfQzBWFdfUqLpct6PVcL4w9glLzwTAkwbCt5vrRZXc0p5PyMP/2dg5i\r\nUDqOJ26H680HPy3tsteSygFUrPc0byrWVQn0Efl/8tDIJwRXGzb2943wglGM\r\n/p+JJsCOUgZv6y1mPX2J1giCbehKP7vfDA4RRmjEJBQTNhj/VZKTPRF4x1T5\r\nrkiiZ8yN1WQBLr97SewQkahKM/Rj2aawaJV8PQmXsxJg+HfJ6+Na2Uv5Kt7s\r\n4AuFih/I7BppzRrXnQ8azqw2obes0WJ8wHCbercMl8G+yirGgOy6tbKnfGyF\r\nAmETuLwRTzRsh2oCUeiM2jD/QsmVif94miY=\r\n=TeAV\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"af37167632314e97917cf155e39d8bf255999c85","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.201+af3716763","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.201+af3716763","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.201_1668062390465_0.9119711169145603","host":"s3://npm-registry-packages"}},"4.0.0-canary.204":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.204","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.204","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"95b1dccd515c0bcb08ed78c10d1e5ec6c1d6daec","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.204.tgz","fileCount":61,"integrity":"sha512-ONybEqR8iXJ3pQ54rePwB8ELuxpxBK+0ry/rdBVP3HsZRVEZK9t6ujqGP26aAOpT4HQAce6WvNZRG7kQ9lyxQA==","signatures":[{"sig":"MEYCIQD7sKVa5J9SIOAL8VOm0ijNXbrKeRhxsmNzXG1P334r9wIhAJ3q22nZalFt/VXn1bcR9KJEao/f4an+Eoq7olHTl+yi","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbYM3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmouog//erUd3XtagPIxf7IPvzD6m9OuDGK8hYPhs4b8kclOGRRBglt7\r\naSqsPWcV499jmJcCuDU3cruIhOM3Orb6gOHgrSsqRLSgwnxy/gOenCOhdtQS\r\n04tX8ZwzthmYiAbTjWfXxDeueyyXvkyOnQyK70ZdY2DGKLlrCMG6fTOIid63\r\naXjpweH/RpDSWL4BW0lgy9mlXg8EHpSmQMrqTHpd1p+nqm5YZuI4XEJvYmm6\r\n9lKKHkNo0IVk4Ri6HUFX9PKpeP2MvsLQQltLrSNc+3DYxQFbSaiUvJLSLn9a\r\njbxQ1fnBNgH8vCGLBHCqzEpAgYC18oHO33lFrGzAgurElulegs+L5msbEeut\r\nRUp7rLC/KEKlgbh/LU9vr6CUt/w2lc8YxKe/R9ZpreGC12waIHJ6DO2qH836\r\nEzgS3CaRQ4ySS9fD70IDOG0TSEt+mtPyhTmgUcByR4c7MbBnEFANilED6Qhw\r\n3TgVeUjPUG2NiY2tIlKSX3klEeisNRyRFiJrMMB+ZxWOpyAduxa/oIgaKuy5\r\no9trNr0F0tr6kemDy0qMT8T/lM4hDSS4hNbffXWao7C2ce1jOsJBktZEiLq5\r\nWN5X6AIyyQ+aHvhvImMMns6AWCKuiXhH4ErB1313pnhnRilWsVkoWVnEY1Pu\r\niBUYNxmtGyQk4d+DztdeDBkNy/qKWAFt49E=\r\n=kCZx\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e45963904b2640b4756d08ba483d240a62d0e93e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.204+e45963904","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.204+e45963904","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.204_1668121398904_0.37669261304462953","host":"s3://npm-registry-packages"}},"4.0.0-canary.205":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.205","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.205","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2d3fc46b8f05530ab0f8ff88008b499a1d21c716","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.205.tgz","fileCount":61,"integrity":"sha512-UdTd0HWCVqoJXi62rou9j3DL7b16QiyHUVIrEi4RbkIuyVNZ1TpnB1o1b5aUlLHJgoGS77TMuaIU2N3nCKCjWQ==","signatures":[{"sig":"MEUCIQC56cB7YY4Z6av1NmFwiutt59hUxLZbogV9NFRkg5D4cQIgJRRURafyVvI0lSVGroZq5YJr1ifOgyE/BeBo5oeY2+k=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbZqzACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqhLg//Z6e/Lhrh8zizDJ8KgDILcjcqzw73nRZf9HFiwYLSQOufrr+a\r\n0qe/OVSWx+hx2COyjTIx45HZsQUng7hf93DrxcJRjaZaA4WF4JsZmdf8zKix\r\nEWNIbfJCfw5Qm7a1kok5I5etC7cj362Yn4VYaz60DLK/hjeFwirOCNsmxjO1\r\nRnRfZHsgl/dlMKUuSSjNVudyrLDmJ2Y+tdxNT6NA2iO/RuIVCdhMbfgd0/St\r\nH+vl1tS89Pgln9lS4TTjoijRO9t41YY3PF8Dn/VGOt5JNPJrf22ooUrbkmvN\r\nI7/upKS6QMOXO0fxiIrvncBFvLDdiNhlDdBFXV7rdvdwl4yuAhBzB5fpYLMO\r\n9AU7Z3qWEpxbsAT7NY9b8kUWqY9PGAtiyKSLYXhXfaAc6oNEwf54tbkNARFy\r\n2PITF1C9d0/aQB431Iwr5z6l0oMoyekmRqMFZFmGxXWyWkrndNVZWjeF1cA/\r\nWbUAs8Z1OjM74VM4Uaf3lyOLmmP1e4bR7j8gJtfATswWNFQpuqXrAnqmcOrM\r\nfKF4mSXPIiuGvn7lFZ8swGvNbfKe7Lz+Gfvi+9KJvg3/v05RUH89Db5zUNO4\r\nJJCnmhcUDudYRSTyc546fRsdD+kl7OgB00ngkAKmhHryoTAPdo5mBcH4j4uB\r\nc77Z/rV6tDgfshMuolfXuWrTUi4nNb2iQUc=\r\n=j3DP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"62c49f8ddd99f6cb36ec0a969bf776b36dbf6f24","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.205+62c49f8dd","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.205+62c49f8dd","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.205_1668127410776_0.4130146285539895","host":"s3://npm-registry-packages"}},"4.0.0-canary.206":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.206","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.206","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"71576b605ec3cc2aa81a2d8f4684651a21d3f41b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.206.tgz","fileCount":61,"integrity":"sha512-RBJBUEHJiNoBUFb8wVB5xCla0rnJVHaUyhNoL3DrhvplhYZQRNeXBDM66pUamlnO1vO0Yx+c0D2a4jdaWW3aLw==","signatures":[{"sig":"MEYCIQC4RYWQwZwClqa/mh69f/WoBv85oEdjLPHlK2lwzsXCowIhALsIFr4oOnebkylk+4Zk+2wZP347BBtLqdNwqDVGvMB8","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbakjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrTxw//eO0x49ms2VQU3lnep8pN4aPwa9rSyfHmzEedBhKGnD2nH10P\r\nL9nI+luTYK314UYK2GfpOyUPBWL0Q4HoBPN7MovFNppOglRww9hc529RDnxa\r\nbK2UZ40mAJb5BHf7eTjVesbfmRu+XWbfBqDuvXM5X+8uWmRmYhMO6RIRjzof\r\nhYlVACvVzfqQGFpyzO4fYJoEJtWEn91hYb4HgbsXlNXx0o2E3qCNMOlrlLZw\r\n1ud2yycRiHUseBbPBLFxNKusquljvQ9NwpAx8FN7ESqirBIL8yWOI1WRcPz+\r\nVluEi4+vIFqx5MIH/L71VmLUljXknAIhoq15F/j1Bfa0tWTxG2iVrL2KvEtz\r\nnHmvGg+P8gTNl//aenWxmzvqJseHShjz0bj7nGbW+ec27iqjWmCgOGTO55hM\r\nm8J+kmd4fCcc+igIfFZFrBBWiuSdiMRdk1y+O7f7SYrH3nes0hPwl57zBike\r\n0qXPiK1noM1KXGX73LAnmlgSI3sG+BI6YNq/17zCzstnCx7aIELNMbDO/1Bq\r\nfO1JT7n2h+wQ9p6gFZFXJCpyngKv4Gg1pWQFAUAxQd5kQvi9vScU7inP9DVe\r\n8BX1kSg7ORBbbdXBMrhS2YGN8BDsC/+vIVEiRjufOuQX/dvUG+daJw0bseOH\r\nYVh9TSlJMJ75mC5W1jgM8ekglUYWvWY5LH4=\r\n=dBc+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1066348dee0293d3d2ba3b89ebc819a8757a321b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.19.4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.206+1066348de","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.206+1066348de","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.206_1668131107544_0.9338900922441871","host":"s3://npm-registry-packages"}},"4.0.0-canary.207":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.207","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.207","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6cc8ee227985bf350340781c92bb299a428d6ce7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.207.tgz","fileCount":61,"integrity":"sha512-ege5meHw0ElDuEOZoGqmVHYAqps5DegkAvKH0ZcWJoUHDKPCQ8fIE4f7CYrL8qQl+sn820BwsYr7h8VEGgycgw==","signatures":[{"sig":"MEUCIB9MrR/pXqvTHe0PdTYRyhWXfZOF6IC0m9ktNUGbPlKCAiEA6wZzxarGJ++RDm01PNZLJ6m5kOEOa1aaaVbZDcEFNko=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230231,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbamSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoRug//XmuBN4cXz1N590QgB5Afa6pewRyvJqMNvXrP5wNzZGsu2nrK\r\naT314CpL0x8WDFOm2eTwEWQadMxwUG2HFSRU5DONZN+FM/PTVv74z6TqXZGS\r\neB1p1r8s/Il3+Ga/4ZuC1pa8tpdQcnmbVJBMLgxLuHK3kI85WKm44BLhCsqW\r\n7/puKlnNzRYaqSfw06Ntqq1eORzuNW9HvDlwqfjkcwvKMy/0mEu1h2s6P7d7\r\n92BlJzXi2iN3uSXjbUQa57TcSJoSrAaPmPi1qCR2BNp4WnjYPo808gorypaB\r\nkWbpEYzsQ3y0epkGPpmiMXhFgvlsp+Tr5xyQ5Gu1Fp5xLXVsoPDItLB29H0e\r\ni6JV7VW36WbrNvU1Q/wy1r4Kb+uVRoefot8NCPlSP/CmkC5At4cSIORFlg/T\r\neY82mp3vCkvh1qnRfJJFOHn+QKtZ1iCcW3HoGst+sksRYcwLA4B1Z66Mb4Lo\r\n7WMkmEnd/nwwXavhZ91G4ikwfJnIajn0LHav70bmV4ZfPBOJtWs9h/jKHgek\r\n/pzfPgDY30ZEn2q4QoGHcqZ8LPmRX5Qcn8f1oL4hxbgt60XEsaYD9uC/Cqls\r\nrQqZxqQakSuF+JPUBHp63Y4BvMqlYnFbYHrymxQwtcj+5z8W50tchqEd81ca\r\nicx3q2jl9t/MWk54aNfFr4yRAiorkei2cRY=\r\n=7L+v\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0bb0f8ce075ea1e0f6a7851d80df2bc7d303e756","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.207+0bb0f8ce0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.207+0bb0f8ce0","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.207_1668131218572_0.5369328152321882","host":"s3://npm-registry-packages"}},"4.0.0-canary.208":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.208","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.208","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8f981d210c259ca6fb71d5337effbb4800e1188d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.208.tgz","fileCount":61,"integrity":"sha512-QcW6+x9OT1BrFmSv3iLUH2mm6eV73gppgWVG+9oJJkgyziKSdKlZ5gj/o+MmUj1xLTVs2Gk0BhE7No/b1iKXWQ==","signatures":[{"sig":"MEYCIQDLjpXXbtlr0GzdEbptYVjOp4fRKb8jyFsg8Ox3a/8MAwIhAK/JGwfoYnnJua87QaNAHzTlUM04AWqSpVLyA2A2pb6i","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230366,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbbWGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmraCBAAiT9uY64GXprbXUVwjin79o5OCL107JpTTAlmBPJdJBZmDK1O\r\nqlHb2Rp3xufPJxN9zaE+YUq1/qiZrz1bGdiGCk1Q/e3EdOjI8jUyC3XEoak3\r\nt9p6r29txTis3DdqrUGWNiQSZG7IOa+jGAKHRXs7M9w6JSkTUlVcGGgC1XDl\r\nCt4tveLMlqzaAnZ635NXReTZfWTBfnbioxlee2Sw9Fnc8vtxwcWBo9xhi7Uz\r\nc0fEJ75EsH6W9skvES2dYoANDqrp7sKFO4oAZ030ccleBus8rYRga15xjcbs\r\nhKmMpr3c4iBz/Wb555maXDo+wsVi49h3cMaTO4T5dWLILguLLSCIxA0N5Pco\r\ngMHfavw1iKAjxYPFZC5WdPGXxkber7m/8F3pwBuhAygUlz3vZzPrB05jT3+G\r\nRQdRZxvcUsV5o+aAfKk2VsBLe93GafYnYy0+g7IwYAhHwdyGNSQF8pDylJyB\r\nX7jcGYAvupM9pjh9NyNuQhBAT5O3agzQQrsrgSAqjKRZbqa2OfoA/9R4Nwnx\r\noKbg5sOoFgdeSkBtByv6KtP59P7wS/pvC9wLPw81fxGs/KwPeWhz24+JY8LU\r\nm088/lQIrpnCud9o4nIqMlDtfQzv3iIHxcSlu54gAh2lIRyV/ker1qpWom1+\r\nS45Fpwm6akhMK+EHCRAyLDFhMw+hEnoCeXA=\r\n=/uHX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"34125a54af769a0f50f70ff8b76ecbcca654aeb3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.208+34125a54a","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.208+34125a54a","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.208_1668134277904_0.24650838020924648","host":"s3://npm-registry-packages"}},"4.0.0-canary.209":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.209","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.209","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"101a8dbb38b5573ab004e0abc4406b18b1b371dd","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.209.tgz","fileCount":61,"integrity":"sha512-WcE4sSa15AJ5AFoE2CldE94fdJt/9VBK/04j3DOKzQ0XPlDY6lzgWlGjC5ehDQ/T3g+QH+b3VAYtf0ga+ct4NA==","signatures":[{"sig":"MEUCIEpDftCA2aLWN21ZcNkDliJhkDhvaYeynqeaBiam0xzMAiEAtAjoyBpoDpbCqxw8jTZbYXcTm7u55+sasFUV1aPhNo8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230366,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbrQhACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpxiA//d83xOoxn2Gri53IQGpBvvW+/4w+mU3wLJs09sAO4Fa7o8tWc\r\nxQNAqndQaq89GAHNcWbMlqpgKkuLmIqprLczhSuixlvz7xVwd6POqXM7lLSM\r\nOLSkFQbeRInVor6WFRCrOp/3yAnqk/BGl9ETMkzlNslTDyDcQ58ljT9/IzSP\r\n1Fo3/Fr3X7LZua3IqQ5yHRfpC27T4mkH6F35GbzkwN1xeQYoPWyMxII9ceD6\r\n8rZFcz42BrLX8ZsbCVkpoJWoXmGtGDS5WDzcs9bbqMX1Jjo7cLuUDAAb0I2g\r\nO+3GKjN+OJMcOw7jSr/OykX2KejVjm4UZjfGdeeuYQMJZM1NbfAmRoNMUaca\r\n8xaSyj4jSDO9RIiWMTqJs9/RBlfFVG1eE7mZCpODDp62hvBlGXafNN4E/dge\r\ndWXEsI4YbR/j/yIf9z6cmBs/iBIVx4/o8BMQ2Bv5yzDdd8S4Mb2HK5yS2KpP\r\nV5QWVHQBb4dIzYH+jlZ4md/oKkJekq1WjXYFsuwlR37NxmbTu9dBgrN4JEXe\r\nYTTbPAMJbhvPMRB5SEp9MP3fKkCDB/8GI00+NtWfXK/GxR/hF4FhPnu/F4Ud\r\nzbtLIvR8yOzV1nLb9qTzcJY5HjgWkM8NduO+3IRxAAPogzRxweGUI8jyP1XL\r\nlpMlyccYHWBUIk0KiroTti+vXhx+YILulS4=\r\n=zM8u\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5ec79849675546e71a0c3bbf1ad1a958afed6dbc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.209+5ec798496","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.209+5ec798496","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.209_1668199457657_0.2620395303151246","host":"s3://npm-registry-packages"}},"4.0.0-canary.210":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.210","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.210","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"76eaeb3c247a8751ad0c8f8848131f74417aa2b1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.210.tgz","fileCount":61,"integrity":"sha512-uLz+4aEw24QJn3SJr/r4I2jvp+bO8Dbyh7uc59wKdz82rGKL50t+AaqEUmL5pZUkaAbakGXDpasSnGMAbBxuLQ==","signatures":[{"sig":"MEQCIH70XMHEbgWSH+g9IC3WvUGUcoO8I10HgDpcYTM2V6cGAiB4y2Gykw2XIH4SDXJJtB7FVkQI4RUjFOHkRc9auxjfiQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230366,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbswHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo3rw/+J7n4qWHRDpao8E0gTKcgo5wXtt8/+OvpHl3UzlXYpwFrZrUC\r\nYvwksny/UI6RVQEiuJ0imvGmDnbW9n6cAR1oIDsS0gJgyM7W2jknuGbcjBLt\r\nUmHYGQ1tSHuTglk0Fq9SMUWDOdgORbWVjlyPFDu7XYvbmsI7hIHQx9AR/Vmm\r\nmRqy9pon0VekB4KoUndN9x98XKe6l/3EZ7qs/UxuDmvmMBkOlrqQcHuSQBF4\r\n8Hz1sZ7DPI6GQjFDqCAsklfrh7OKi9HcjT9XjGy8pO0gjw+8mxYZHWSUdesB\r\nh35FPtG7qzgJLxbSuKZebI23ofGQ/uNTE3ntjV9LoruFY8r7HvmgD+TQpEhP\r\nA06jLBgRbrjGzYG3yLqXHDhHON9eU9oAxOJlt57UDqfw2xZ9bM0+9EDpcr7u\r\nh3sLkAwod2y5pfaNXhqe1G93Ze2EKLVmlY3ZEVN2MSuQsJRgCvJCNhwWovxu\r\nRWs5bxErRJtgyf9IltlIEh8HqDLJT0a6Qm7Cs1PSZRQdBNuIYD+YHaKiPpBY\r\ncgmUew9wwnmCxPRUx2zowwWH/74KgdP927YJ2t3pMCE18PXWElmHycplRN7d\r\n3tivDUUBJviMloz1g6T5RdFWDhlwV7GZncqUYmOz5HmqY2OAxtl8FFfO19yi\r\nJ1GZxI2SnsllPNmQBowIUG1x64TnOPF5cHg=\r\n=gPl9\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"45325f866eee43967f909c7f1d2738d6b06e6f64","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.210+45325f866","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.210+45325f866","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.210_1668205575620_0.7513220649898857","host":"s3://npm-registry-packages"}},"4.0.0-canary.211":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.211","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.211","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"be257cecb9b864533f0346015a13a597ead895d4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.211.tgz","fileCount":61,"integrity":"sha512-8AxXvZ0GvUu4a0BiqIcWynpNfEU/FDRnOqAJvGoL8gY2N711mFzifnVW8M+gnLGQkkIJVXWv78yi8L9owhZ3lA==","signatures":[{"sig":"MEQCIFZcL7F+7wimcK4w0GyyPXGJ90pvmn5MdlaXZy182/SEAiBmDFc/8fQlpbVi5PuLOYG18v5rD3n9UgDjFk4Zmojt2Q==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230366,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuOPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqkzw//fcWQGmm9SJ+XcWezDyF/PsjBeTRCeH20TXoEPZRFlMLpxqK+\r\nMZILQH1Kqlc9vxkIe2wWU8iMc+tDURDc2ts7imzRfiAWand7FUQMrnB1C80c\r\nlyPk+7JyCzZ9Uf4H69Bmx1wEAvjeAdvMjtloQ6FrFwRJ38qSCyxu/64ZBeJJ\r\nfWP5d/72wLGg0N7UsNSaD02K1EpmehMHqOO9+qCqhzDPgbIGmf4ZWCpx8DMP\r\nfD8s2YitIW92wqZCcvgC8+7DSva95PoaSp0TcTtHWoCkhRFEWgNAGu/LUYpF\r\nj3+vIGP76avgssEg6PlOroEaiZW2QJRUXCP43Q+F1ptWT0MeFVLrD9dPe4Wp\r\neZeEcu5ktK8eiWQ0pLxiC7GvVtdB94Fg8mtg7Y1bLeFBftcbRY/dpyo9GhBt\r\nQ6F7r6a2yvZ+k04xhSMRgGseB6mV/gMA9Y8eRYo8qywJhcSSvEM0znDh8tM/\r\ne57c3WFf2H99fqQM8aeFyLYoNF6rvQ9YutZH8DayVS3wl0xiUlT5AtN0988r\r\n9e8Ifdp/b2pSSSrhvipO14DxpkVxlJptBnooyWdYSBKcdpoCRBIvP/IWd61b\r\n5I4ie+TDBrNrsbscjiJ7cwNG5oRlDvMyl6dfrb0B/ygsWqZuqEqKbhUzlx0n\r\nAOHZBprXtPFDzpn5sEDsdapfpWHFzcGChuY=\r\n=h5Ws\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"01ec6c1ad3f9d532339c1e375dccd75b6669fa03","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.211+01ec6c1ad","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.211+01ec6c1ad","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.211_1668211599328_0.5315212200043766","host":"s3://npm-registry-packages"}},"4.0.0-canary.213":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.213","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.213","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f3c19e7f814689daa7cb8ff8d0f4787ad5bc58b9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.213.tgz","fileCount":61,"integrity":"sha512-QJLujsvKFGc9VE8gQOfJVzSa8nqVVJ9J8wFy7abNK89oFqr5fgItc3vl38a+I5AIcZ+4XUDMdIwNSYAmvABi2Q==","signatures":[{"sig":"MEYCIQCBNI6SWKdc1Irc53nZBcIBHclW501zr2HO9uSxbZvJ3AIhAOv7sKzOsUrgZT7QOYz1BdHwfETdZn70awXkNHobn5MJ","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230366,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuRWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqJxA/9FI+AqTA7yHCTnRCnyjYMJch3s6WN21OEBGcn8EzXzM0/hlZf\r\nI436/f9Vhkoca3TmTZxc2aydvEdHfLH1JQLKYZlnLUA9GAbDILxxTpO1qdGq\r\noRwG3uLP/lG1k+Z9H5t9umyraX91Pc922EmvJkEmsuZJ1ILMg0nmtzjJPnhL\r\nxU9pZ7H5myccX6FjCVXGF8jpPRgg3AAxj1LxhHEvt6CzyCrrxkMF2L1OK7Cy\r\n/RLUuVtKLQPYCCHd3QNNuAOrLO4wikr2JdWBKLJXohUAQnA/I1Zq/8PEV3Bq\r\nsL5y9dy/tE0hoFyahHMqeufSS0GwOgEtZ6XfGunlx0h/TvABsSMc6nypAKjp\r\nM88rpu+J19A+d1FWBKhhzsVgqe1n79jwOzP3XP8t+EDTisZ2wO7u44UD+9Up\r\n2WG0//Lh1To9lfM6mLnN/RDY+ztyb6fDAiYyIKAPipydekz+9KNCkIdlF9j+\r\n+VlS4WERgqMa/t6nfrKpH5mr6gPfDn1qstqLQjMIW9YWbjQ2anrgcpQvHHpw\r\nxQNfSGstUxh097mD4bqvIcgDaGlJPD0RF7T5mrC8xwfDbuFxhBGTVbSxUPdM\r\nKedmy/HdbRA9FUwr7f6O5SJEC9O9g/ZUabN7+whpz1D5kykalVmnDonAwQhh\r\nrlTo6P7btryodIdBpoK6KKj/TtGiy5jY4Yc=\r\n=NXEj\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"098e921bcf45cfa9d02119e1f2b146e6b19b3eb0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.213+098e921bc","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.213+098e921bc","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.213_1668211798701_0.255320570100678","host":"s3://npm-registry-packages"}},"4.0.0-canary.215":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.215","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.215","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c23ba79a6656156a730481bc42af95436123f12d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.215.tgz","fileCount":61,"integrity":"sha512-feb3C+QpUPoKZgXg95Agjqd0a4/e9yRhzYNNTqIeIqy24PKGjohvRoUFIKLOxXskohLwOzuAsy8J/RFkIkRvkg==","signatures":[{"sig":"MEQCIEV6g6PJLzXc0xQuhZE6a+Z21rTkeNJ6qvYgmi1GXjuZAiBXfOK/vuCBYvxDX/cMLtunJ0+TSsd803kzlKdicffFDg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230366,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuR5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpoWQ/9ElKf/9Cq3y1C7WvH4lhTiPhtTa2xC068/dtZ016jFUy0fK41\r\n7MhikZuWHYA6Ebs07igxwjk7ASEjIt4Gnkx2fmYDDF9pl9wnXkmWh0cGR9ql\r\nrTLrJNskcSYyuFdDIDNHYjlSGB1z37kaWKESmmyE2WjGrgePrM18HenPjTDA\r\nJznYt7A21wQ7V6vgNbPMn9XGaNG2vr7cCmIhYXeBAZyCiASjDs1z1DtVU0Af\r\nTqWhWRyg4Pzl+vKRWJO1ibyRzhvcZAdHB22gfS+b7kS9wUFncV2rj8cZMHu8\r\nCMrR5gV0iePE//+zqFJ0vLyPEeYPzuTepalxsz7ZIBwJYBXBBl793p4zXPZ8\r\nq5p75HG7fGIsBWtZWQZZczF30RU1nq0+N0ExU3ou8EiZf8W1e7w1Ukd+SM7B\r\nL13ocCroUVQdhuuOeffIX/3/2Thevw2I709F7jEavQ6j4SVsvmLWYD/E3/21\r\neaJ6TdKhVujJwFq9X4Wi4vUCF739mP1h9NFC/LSqx/XYfQ9b7UIJ0gqrcnUr\r\nOHojDa6T+rx0Zc72EpDj7kUxRQXD+lbrKC/fDdXV/NwZ8M4/mMk5fX/WvBQB\r\nEjTE/cP0/lFew1qffGPJDlrVSzjRKLlyWeJaB8W6YVdDm5XTigSrLSwm9VDN\r\nLekSrjqbiPcI0/q0juf4ifbA+i0YC1GXlys=\r\n=V+EE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"dcf86a53c849e374147d34b1e77a1ffd2e397a2c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.215+dcf86a53c","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.215+dcf86a53c","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.215_1668211833549_0.020562827590194566","host":"s3://npm-registry-packages"}},"4.0.0-canary.214":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.214","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.214","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"489af8fe3fb6b4ed4e6cc09d6885255722687997","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.214.tgz","fileCount":61,"integrity":"sha512-hcBohf0/pM+yknVIK3OmxXe0wRAoaiB2Bewvd23euHC6SgWpJ1dWXjh/eOrmOdx56VtrO0vzkJBiidSTab9lVQ==","signatures":[{"sig":"MEUCIBjEU8NmbrrGVQpGQeHttwIO5WQVLl+LqaNJ6bEVVL1bAiEAlHs/Sn+rk0cVmaemtBB80dBPcyrtulTELGN+2Vh+6GI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230366,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuS6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq8Ww/+LASD3d7xND300eNr99bZ0v+2ZU06A2jvgfI2oJdOgk4wffvt\r\nB1CnYHpvoZWHeknsCaa6DVSR/i3hs0WM8oGmOYq0bNBFZunM9YLpL0WP7YeI\r\nn/zZIUpLl4fy/0fHmDoMEshgNMiZHwlOABqjQJDxVqIlnRBjCuXS2iGcHsQY\r\nPx7ljjeS/ppmbimAtxo6wa272Wpw9wRB9RLS+VMQVfjoHrA0GDQ4f7L3o4Ey\r\nyR3UPXxuw1x6RJETgxwMAKlUI9qPmoJXhzKJQy2t2/A+nVcUIeoqP2+WDgxC\r\ncKqNImqOPBbUrLcA0JEaByJcgdqlc5/mMTuG1ziRTjZqWZwoSdr92Ed3yTDz\r\nzLll8LsRXwevthQzQhqby6maoJxdOSqKM/ELZUxcFe69BDkNq9b/CrZy5jvW\r\nITfweGT/wD1y8yw0Jagv0I5K9SpHVzG18BM9RLJF3JBhRABG63FQjta3CfPY\r\n+LoEnTr/Clzz63LBrTrBsxJxhVXPBnOTWr9UUSpi0jyHvjRMy5MGcKl0iSqV\r\nFjPwzZsY4yt21vfzj/llOas5JouJz0Cn7loUroVZgfdCtHJzoA7CrJRA811u\r\nTjZ2VKTJ6UT34BmFpu2LQE1cPYtpaWPUX0lzynzpMiEtoYrFCffwW7KI6fVr\r\ntILqS4lGVMLOhLjW+/HsE6bVHawSChDEBHE=\r\n=11Py\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"129a7e3465f12305f797f44710bb16bb456e14f4","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.214+129a7e346","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.214+129a7e346","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.214_1668211897979_0.9823438172036709","host":"s3://npm-registry-packages"}},"4.0.0-canary.212":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.212","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.212","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"86de96f92d8b02c98a19f0bc6de0ea96bcebb615","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.212.tgz","fileCount":61,"integrity":"sha512-DAkI9W8pnzWSXl2pGu9L08+Tr+nj/OWncQ7YgCYGuBohohx8n9JgUVoED66ZgtBMZT3P2MU2bTDYECP7PYPH9g==","signatures":[{"sig":"MEUCIFbBzN4Vxf2Fl66E7WM5Wz4nyXz108NFDg9umfvNSq8XAiEAjJl4FCXr3O0el6pw8g/bk08jZ3/LYsi/JtdWdn2migw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":230366,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuTWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmphBw//Y09kYIxYC+1HlJYpvvytehGdZHfcU6AKNOvk4cXxYnwy34gN\r\nlq+DgJyb48uVy50ka+5fQuPd9CFL3d8R3tZgGQFf3Hi8Bjy3WPBNMf6fBnm0\r\njzcoN6c+QYStyJoEdW0v6BhUQX+H6dWboddtLjq8u3n4ku6CAsmSrTNKeD1X\r\ntVo41brnYLgheJxJhGJw2VQBCWFti2zHIDQiHkgXWzi6dJ8p53bEQRk3FNZt\r\nOsnheZ6MwKc3qbyFac2s77KvMhO8Fj1oTGHBgc5qbjWXf7TJziAAgtHKeXwl\r\nuV1+Ci+ac8ogKOPMnVRgZOkqGOW0KiRZDjI+9f9jjtseF35x45ft8fQy3lGX\r\nnlgSKuue96uuOlDQilAavBAoBIDM4dXT+7PyOLbOqq2BN3Uvk2t/tXLmcbBA\r\nwZrkufaqrQN1sZijV2tgP/l8xfM0kWmKnAI4ovE1KFrgN3cti6Bx9CHOFHvy\r\npyoe1/M7yLla1MRVXgjnhJPVg7IV1iU4S38D8YsIfgdu5ZIzpP0SdCrgJEs/\r\nhkTsJHEJLfsokAL8NMY7pA1qs6U34cmXxOQdFkb2ygWNXXrkQp7LZI+VkWCG\r\n8TMSLqd3XVN2sKRBA7fAyyaShmooWUUiTtI9iJAIjyoYZ7RnelN8U1I2Dbgw\r\ni42wrHFGLHqT1UXQvHwvn43D/j7lPsduT+4=\r\n=dSgc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"457550a14c0928794315aac49eac2330590f0f09","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.212+457550a14","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.212+457550a14","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.212_1668211925884_0.9759807615987306","host":"s3://npm-registry-packages"}},"4.0.0-canary.217":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.217","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.217","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a4e0310485986197da37bd092f074f17260e8eea","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.217.tgz","fileCount":61,"integrity":"sha512-yDvU3ebzJ0xeaJoSbthd3sa/331qGyhg6e7eiqaeT+21JKdCwDe0TdGQPQef2SliPYONlig/rZCnYJHjVmpuJg==","signatures":[{"sig":"MEUCIQDqvhzo7w6UPx/+e+S9Ebo9PLQm5BY0HCyGKhsXGJN9/QIgdb235JOHyO7YG4UglpJBg6HNFehICGDxWdBchdopXmY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwOTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqPzQ/+N3Y/62+PMWpLGP6np6e4Q11u/CQxSttiHy2ro/xGyO86xvLn\r\nQDWbd/EWXLmDrnTAFcKYHsuzPumC3CeY4jBS61d48KNBh57WemIRtN6mZfdC\r\nkRsStwGP0/c6kN0i551Q6fCTp392HgkxttsJEhFz5nviqRE7oXQ9WsDGgXfE\r\nXSSk++9DZz+XNrpf8CWxavSaEDOcb799fmkczm3puTzZfBnf77ytm6wUuqtx\r\nj/jO4zyKbtgY20xHrYE/pJ6Fxr5ekARsomOqGr26vbwBjm5b7ScUXebwqbAg\r\npp6LdIKqI43Mm1unwBUorP+eE15zEMsLTbtDE6noL7yQcKM9Hl74uqJN9pOP\r\n0iEuKC5mALLyQ0AEyfw2B2x1+q45RUXHU4rCVaRANECU/zFARE5BQvl02w3b\r\nGCF5JrJfxGzYVd0vaRt6lFljctVzXlZ7N+JvlolULQZq9xxxuH6PhlPH6cO6\r\n0jWGpzzCcNb0d+w60+Lnr/niEjuFm5letvSy6YuGahVhshTbieiOo22DEzar\r\nwWcOWl8MDjz2EYGwH/JnpQT3LR2Dm4wJaUAfubwLr86LEYpxRJOofUvFK4ES\r\ni1c87EMqN0HXD2NQrnq26u/UxZTXmvctEj0g8Y7VHNFHjvIyl9urOXVWMLGW\r\nsgtiB2i44M1jDWjDJQ6yqUIwAeHrwEjVi58=\r\n=MN0x\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7c2443b30569b8617a88d52503a51ace463c4cc9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.217+7c2443b30","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.217+7c2443b30","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.217_1668219795535_0.6115017604807158","host":"s3://npm-registry-packages"}},"4.0.0-canary.219":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.219","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.219","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6ae0d65b48d0dbad95faec1130b52d91515b0c94","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.219.tgz","fileCount":61,"integrity":"sha512-S9YjWm3NiytNJ3zCInXoa5QUHRPzuMGxAyffGUGFBcslPYMJvcOxAtj97PWs0H635AS5H4fM/YVvJPfuADUODQ==","signatures":[{"sig":"MEYCIQDi60+ibx6Nlc3qv0WpfGbNFx98dy7tL0IL57c6BRO/xQIhAPlj6+gd4Q7NAtLadI25xL1TnrUrMjyeloRByu430jgp","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwQpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqnKw//ZLCcrqc9lOIzTnqv7QpHHwq2GFH5bD0md7JVJLPQkp2EQQG0\r\nsBnYztiONs2OaNcjrl4om4bUCmjZD0gPMfEVEwLiNTm3FUo4fjs4LMQRgHH4\r\n2PYCOWGZvIf8trlwp/o54gKIAykaijO8oXYOuh5g6souNiKPqLtToQ3aoi/H\r\nhDcr3Wt+cf/vGWZtH/r5zH7H0Vc+10Zo5R0nJ2xL4ca9//vYX4qi8WJd4jOR\r\ncmWOuSOqJPK1Z5aBTuGs43LNFM2CDZvjFyq4eauPXWQ3n2WqdWoolpAXlLB9\r\n/VxRitOQn4yBlWSER+LN/3Eov6tMzSactbrHpThXOrRSJ0ZkomeeTqCDfCqi\r\nTlKxFklk9Csv39806vIycbjgyKCNcyCbzwshtN7r9AZfW4lF5nKf/48qjjy2\r\n+eBeruaErcpVz8F8AmPPuoj6ZAXUvP0sRyNIXywjx/UxPGvLOwluh2LWBjFS\r\nQ5Bh/+uqbpG9E7gjp8hgUdUgDe5zKU7c6hJQ4Yp/5c9xxXQKz0rc7sK1OjSh\r\n78VB0zYjnYsHm1gmY5Qub/RAyBbAL1cXD0L7SU1rxaY4oXiy9/K/YvLDfjjV\r\n9Z5DWM5nMU8H0VTLy1JqgbsIcKeVnMyHxplUI40w6z7Qe5H7SFcyi0j6L2tH\r\n4NGfFL9fMEgAKQjchMs4vElrffh/EN33lXM=\r\n=zTXu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"46b9b34ce0090f9765b829516e0d970c9ce2b8b0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.219+46b9b34ce","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.219+46b9b34ce","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.219_1668219945658_0.0016694735711952902","host":"s3://npm-registry-packages"}},"4.0.0-canary.220":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.220","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.220","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e6527ffe2e5cbdc6ca0e607bb986ffcda9d005a6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.220.tgz","fileCount":61,"integrity":"sha512-XXYZGiaID6sVc8gquIhdYoMgpo8LvPDC4AE6Pcfhs2cZqo9y0iPOhnU4ZigYT4p6OtrpD13KtAD+7rqNVY8Saw==","signatures":[{"sig":"MEUCIQCbFccZNUtEKh1ZLji53NfL6BH/X5Rihcx0dL4Jg0TtTgIgU+nAwj6JL3TaqvCP6/aRPPZATnTymKSZP7CDEY2wtXg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwrxACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmodaw//ZAHF8FBXuPAvexzWTIynwLNKS8wOiaZJQAMriPLM6Ws7JwOi\r\naUI9pANB6hbH2V5yo6B/XaWpusybgzG78Ib59t5L/Rrn0YlbVwH/KBD/80+J\r\nmHT26BX5CHoWWQ8EzB1UVY6z5uyXunxsS/0MACLxj8YTxaN5Cza6QpOfHLtp\r\neZKRWSPWq4kW0WfSchUI48ZdqdkTc2QMGyoBk8MhS93IRGPZt+briUu9pR8Z\r\njvP2xWn2Hy/a+tybhxyl+1J1GdZznLq51s90Jh6OGMuPMVAme32zlQjCS/F0\r\nVDI/+FlSzZbGJOCcMS/SATBpxJIGf1hbuteJGCHONlz8oHOo987d7mpGInw9\r\nduvqpJ+pgjYLCknFNpJuxH0tJIjukIXa5SmznTjchMq69jGG/dsJAlg3Jz5S\r\nTHBdmxc/YeTGPaofPUkDuI/b7VlNyp5ietadQCaZYMcx8PSf+AlFCwIXVSAH\r\nvp6PoD/VnL0Fu9W9I23dVV7P4CfUmI0xQsrVG7DqOFnedwk2ejkv53WVvqJv\r\nlgqTsQ9/n863iyQnM0kI13dxZat8VgG7Dh2ll7uDZv/DFPLRLH1jVCgBik46\r\nywSYaKDeyDk9huIhj28uPG25ev6c4LPgBcEP/j6hea8O7dPWRLeWVLCrpLnt\r\nfIanDkSsI5hYUlGxzX/KYC/fFVCsQ40QFlM=\r\n=cwfg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7aefd74c3bfe12d56ff56c8852ea280076d3ecf7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.220+7aefd74c3","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.220+7aefd74c3","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.220_1668221681529_0.1401080753715931","host":"s3://npm-registry-packages"}},"4.0.0-canary.221":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.221","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.221","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bd5264f32708d6c709a1d396f957d51447213744","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.221.tgz","fileCount":61,"integrity":"sha512-X8xsqY2PixeAQsKIjL6ybfo0K/wZd6fsbiQyAeW1qgEeT4qz+RTFqHrgQraau0Yhgs3ax3A6RjFDnpQutThU2w==","signatures":[{"sig":"MEYCIQD+A5EexY91w3nAdpjPJgdDUCnARtRdws6IRVuYgoCtIgIhAMrggsA8BZuhmQ30Cl0QVSt2xWjSKdX8OGT/V9EYNSJE","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcApXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpU8A/6Ahw8XYQ7h/b8KA3Jdlrhjvw+lN7qOr5oT0MUsJUw5qx/e+qo\r\nuIEszzlW3eUjBOzOP+o2A6cHJBTFSPH7vR4KvTlZfDoNKrij2gTX8D+gNm6G\r\nmEUBWwAAZO55xLJXh/7rr4lZ+Y25kVgGWvf2WN4q4kS+5lTY1PMVdMl5P98j\r\nMWuuX/ylq6tQQ5DBGdv8536i146+BR0WmOniIhyesbuFv0HSfMWoaP4PGr7U\r\ny3v8iT13ibxLLXWjCCoZE5mpPFHsR6mQ9D7s10Dp9r8OBPoCDCMhnVVaRLmQ\r\nirYHkduarmJBR4d3DeTm2XkoWSH5Vwdt8DSg70fLghgQ3p3pz0qyca4SfgY7\r\nQro1IjHq0Qaem3tWN/GIszK/bdtOslbB7xn2EPNOi/BrX0XzEIPgu8eMGCMt\r\nMPPVKAH//bXwapr7h68z5bp/a9cLJvk/KI7KYaGHGRo6nhSwUilJ7hvM3b9x\r\nv7vbjcf2sU/vM4rpPgJF15tx5uR8i48tsbb+NOr0PsnQgOIQA+TdPcsPt1FL\r\nfKMtZOdlRo5pGAdmJGkvR5w5LrsHSFkOSfbWatT8dvLyGOzk2sBLeT63HmmK\r\n8rf+wfw0i++JlS5aNMiHPUWSzTWkBU/9rv5/yrGj/0NMStStp1Ez3IyYqDPd\r\n+0zGgiOAQIyMheFdsBlXkmzdcy9xTovDp5I=\r\n=Q3Er\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4e3005252577dfb74c83429136b8bff043fb3342","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.221+4e3005252","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.221+4e3005252","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.221_1668287063577_0.29536509052618665","host":"s3://npm-registry-packages"}},"4.0.0-canary.222":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.222","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.222","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"18dd2e19dafb7849cf489d1b50d78b6be7842a16","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.222.tgz","fileCount":61,"integrity":"sha512-bF+bWVg9/bTz2iEmRYNKLxgkeNwChT8N2N0a14PN8kJEKAzhDRHNSvVWwru/SgHRL2PgNpPupuis/0YMWr1sRQ==","signatures":[{"sig":"MEQCIGdP3K7RrdzvIFtbJwaUzcAb+3alffAsP4cDU+720NLPAiAyLgRR5BWJkj5eo1YSvmRiDZ0F5YLLuxJNl6Xq7HF/hg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcArCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrfxxAAg7XYeYImy6mUqVe5/CHNg2CY8chufuUWDgR+gok0KmzR1lo9\r\nnkOwE7N9EDuWFCk7lwVmHPXW1sd4CVnCsPuDKmI38uCIjWeuqVW7bZB3lr9r\r\nwGT4iSWBCxpe5n+i6OZVr8Z3EZlRhhyH1RMGJfe/d42PVcp811lh694g3UqH\r\np2xwcSRPuT2fdnXOSS9XkCAIkXQ6774qaZozSyPb6IWltLuXs+CvHlsucjix\r\n7SwpNWsrsDy5KhDyP0h0PLAfUSuiXLfAehw3BjmXe0IWejxuSewVOaa4i4GS\r\nf7zpDI+qpmDetwdtpwWUJDYR0VoNHXkibmjQ0SpN/sECDTlL2XVtmxKDklAk\r\nk18P51J6Q7eiMcGcEf3h4boMAB7KnMS/7cAI2kyo3mRpFAr0pjKd0YYuUPb1\r\niVCkOsKlWNVsQxtjX9DxEGozT7+7GhS9WYJiIitks237p3OXwl9QinTA4Tp6\r\nHRrDRQ54pbr+yIFC9Abq7wXG13YfPMdmZtq8QhleNmvLyqdeQ0VpbhuOVv5L\r\nE2NF9gZij0KrvF8PUQW5S5d43/AIXpSFVQGEaRbeUnETfCpjhHpH072k0JjT\r\nhyZspYaf2rSMROMZru7FuRWJhz2e/XgbIviw3MRAzRwsd+5ipY0W2XqcvYmS\r\nCYe/9cA+KGdtNXQPITOhUl4NwW7T5+dL0UI=\r\n=mb/X\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a9c13f656ecd9ba22b9a9546b0c7fd46a2e43e55","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.222+a9c13f656","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.222+a9c13f656","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.222_1668287169908_0.008437069957629495","host":"s3://npm-registry-packages"}},"4.0.0-canary.223":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.223","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.223","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"562bad8c9fa803c60fdc03bdb8784d59db516051","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.223.tgz","fileCount":61,"integrity":"sha512-+WRcDYSsDQN9c3i1822QxW4/CMUz8C0oKCoso+LCa+zeTkELTbIHj3KvVSHb8ychOJVoJbkZmrMyvj5AAq1PHg==","signatures":[{"sig":"MEUCIAloPNyH13Wg3BaAjmV+16kEnws1ev3qKAArcn5uOETpAiEA4R8Qx7Kwls67WTPl7IUbLlAyXt13419gWqmhUleuAXg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcDePACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqqJRAAj0bxsrrbkCTDbyS2/OGZOhK/h1otgaJEgfPHfLHJPrEHkPpM\r\n4RxItvU8MgfjoCecbK9dtmbi7+oM+hQesLlyt3U7damiFmdFAkrmltQGT7xi\r\nicpkLSwOC/CL3HxoM5aoNYeNVKQgvjw8IHkR+ycGWkxHsJs//tnkYl6g2DL8\r\n2o6CSLGbskQmLUO8ndG5YDudA8N2MmE5GQaKBfbTPmmOrGHTfhiqviaIJa+E\r\nodQWjvYuRlVdB8/zfMEZ7D69FSwNQbAzWENEAzrJ1E6vuxJ5QLV6C7LBNIvn\r\nNmGJ3NWu8EYP5k47XPJpXpxhnSkudcOrcbyCtBW5g+S7+g8isKO9yA5aZdgN\r\nat05w4QRQF20PHnQApzcYoz3npBSMGLhmRvdHPHBKXOO2CVGbPCEHv1OJTvS\r\ngJR24m+G5MUtMK0OJWFTaE6sqMR3kAk+IUvLD0o0jRCYPDwnv7i/3Y4Ns2bj\r\nLVQSIMrO71zgc9Y3Hsaa8hVCai8BqNgb8/gJ0amknlxEifkrSi+j8X+qod4k\r\ntK9nD+MGIZgGTZvvU0YPFVisdWFXgV409JvpjWqcARtCCZQTqPFFF48O1Gnq\r\n4vxx4AHZaH1iCh8wL//wlNdcOKo3f1FqtoF1r8MoY2+TAISY4dkUf8uefnHh\r\n75q2fm+OUhv66ViL1AqdVSDYUNbGwNO/bAA=\r\n=qUq7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4737667f45335d1de687b51b0ae8ffafac184d3c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.223+4737667f4","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.223+4737667f4","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.223_1668298638832_0.21709391037798897","host":"s3://npm-registry-packages"}},"4.0.0-canary.224":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.224","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.224","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"98459603ec0d551a72b31889070f2bc13a485854","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.224.tgz","fileCount":61,"integrity":"sha512-7jtz0f5DyVV23pmUUBPw3eP8hZXm7E/WGGT4kEmxl8DetVyCwCuEMkXSFaRdh4o2NkSqOf/N92bMDShGZnppww==","signatures":[{"sig":"MEYCIQD9uqKThErm3P2GXn+SNdJQkBaRJcFAlimQInSrEBd8yAIhAMRGj1PpAh1wkzDSA+yBgYHcHM9jSP3muJ9HJi7VFraj","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcFkEACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpzqA/8CX4fzI49VeSMUayKWWd+jsTO6o0ms60hMIO8d5rvx8FqvlTB\r\n5XnubQc/l3WyrNdEYKrAF9/O//lX9XFBrzk8KumMuTm9wPRc0P1q/uZmCtHg\r\nnih5Plb4z2jBegaulZeSN2ONE4obBqGEKUFapcA1sYDkHLzm+hTAvWt1S/SV\r\neQHj5onRL7VHJ6YR6+/bM3tiI6cIbIXuamFfxpA4CTQlNLZZ9+gPM3XKtAOl\r\nMWoIUBZEoEJsNwn402W3MxCJfmMo8ADdaouYIkm5+Ml5CVSlUtq3DfeeotZW\r\nGgqrAnq6PG98negAfZ6HVDfowI3cOnvJ4CfVDDv74id28C/jfSAoAE3owjyK\r\nnVHo9xnqwEGn/oXSjBK9Ok+b9fhvY+oaI6FXGV966hi1WpD/fkCiLPDcUEUi\r\nh01P21t4Pu5LEG1mYkrdS1PGpgJh9zDB7jH+hlGgIDVklBeFqYT8QRNjODeV\r\nQZgJXAKqRwA+SodS6sW4nUwLdfY84GCSfyyGZVzvo5reaPvQ7UYOXgHS687B\r\n2AGiythBRN42E1eoZE14XobFuJEo3sdRL6wbVIAAvNqXsg6BgCW4olEUSPiU\r\nurykKDDEg4Mpo27qqIIiiwhfIwyOmYvR0ZCN6Ygc5gT+GUZ9Ny38cXY0YhPV\r\nR54FSg15tavYlTMABPy6uKAPuDgspx/OMtE=\r\n=tAiA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c6bec27b4e51e2d214b28ec9d3bd25971d94d50e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.224+c6bec27b4","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.224+c6bec27b4","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.224_1668307204238_0.34473393527221385","host":"s3://npm-registry-packages"}},"4.0.0-canary.225":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.225","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.225","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9782861899ec25fe69c2ed6631a4e3cbf05899b1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.225.tgz","fileCount":61,"integrity":"sha512-9Q4T9SIDdbjBOI3OrjcdeJ6mok4MWOX0PU/AMKVG/aNWg6zYQwD3vgup1qJbXBAYsgpafN0JYeGz6NxYb37lMA==","signatures":[{"sig":"MEUCIESQAO8/NrEs2PYaBiCRNwsDqfV19HSf7K8wLFP9W7STAiEAjIbXcGcupu4pyNGRmCPI3grQuqWJfVb4uv1yQEUzF7I=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcIBQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr44A//SDXjGPiCyIlZUZ+4raj8+DkcOHn2m3eQhIz74LamArExZJCY\r\n4xsZkvu2qgUWBVRRm2dplOmCOxFira5IquUeUHxteeJFPg58hlJk5N37Nmy0\r\nlDByodXzCVKlcComjWR/PdESpqZKZ5ut8/Hk+P61nh4cvd3lVR+JfW5lnzV1\r\nwB/YTEhsURmjIqMLWHPLaq4B0j7rBs7cbB1X6U8eSF9n8pwxi1I5vBbyULWS\r\nbv92Unt6nZ3gZlGQ317rLCAF+06pCuYOeHKbXOfiHyMqEdWR+TL2FGlb53y7\r\nQT4cQ2EQVA4bp7DAOc5Kjfuu0QvLKGj/F+PjXJHyhhwHUwgyWcaKJZioE13M\r\na3KnracHSzmVRZfkRlaHJ+p8HB9gD7ushxqJgt5s2lkxkmGt251eEb6sdPn3\r\nr3+sMqQmjS5i8x32G+hKBI0XYUyhANAQGHHeDU9hkFfwLa8niwJjjCIVZvkr\r\nku8S6aQJCWcxS06z80t6E/c6cwoPrGlrFZZCuNSqcQULCvtbWNr14N746uNn\r\na19N16pyWqoD54PDUvAHEBpiiDJmR4bDDQRHLr2CHhhADZ4WDyo8wpw+JoYV\r\nkff3X8VNlr/NmoBxxSIhZ9zZ3RSZq7aXnT3RXuU+2yvRZBxqfJC1zHSRv2Sb\r\nDwdw8JOFpU/bA3cwtvcKtghQ3/spTKyo0kM=\r\n=I9zY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"88d8abc4a18a4f70131a8dc04364a49686318695","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.225+88d8abc4a","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.225+88d8abc4a","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.225_1668317263740_0.6488873566826359","host":"s3://npm-registry-packages"}},"4.0.0-canary.226":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.226","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.226","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5d51573fe9699fde85777d5ea895a96d5a39d266","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.226.tgz","fileCount":61,"integrity":"sha512-jAZT0YN2yCpfRFyUKIz76tMbgHhJftf1aL1aX+3uIySfbSyK3yCJCWy5fyvbQjMZx4LDpdEb3s4TXOLVQxfscQ==","signatures":[{"sig":"MEUCIG27u+7kOYyOZxtH6hGe+Vr7XayL/YFBGuYrUEtHCkdkAiEA8IaZyHhXSaGQhrPsFyGLCZEDHPtYfc6gsyFyU8E5h4k=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcKJGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmodJw/8D7eunbOSbRwamdFbsiPxV+NyoHz3pwRIuXtTC4vHSBAC/qST\r\nkpTtxHXI39ADDQ6ZmbFyQe3M3Oh3bc4AXpf3JLUUGegFakknXgCDIRSgprMe\r\n+djZK6bovxNcWJZ7ZBFCcnM9ab6ifSMs70vae+piaZKPEuky24j5iGQ8RnGY\r\nFOXWfL6V3tnysS7cAjb3V8ACdllqxJQiMNmUI/U7E81xskGyATpRLmS+qW7N\r\neeZ9Idcm7HdHx66MjqVwk1hl54xiUyPuX+YZp3svQZcEhAUoV+Va9KDECiP7\r\nUnKVJQSIRGBjUriuIgBzg8j6kNJT3cg1kpfPz1o/rTUGzDQ/+JxRav/ctNkB\r\nN/Z3f4/CO28u2n7aOENLhG6cDb5PXRiksvWwYBLiisWxBw+aMx4ahN70Uxtr\r\n9a2o8F3tHQQXC5hJVYE6/Rm1JCZiI81O3vHoTakaSPsuFlWPFo+adOXrGDEl\r\nKyb1A5eZ+eH2aD6iCF1nH4hjrzmCoJdutvvf0o09AWpSy3ZLd0jyxur0tF9U\r\nqm1UY83+/kDBpWj/xO7JD4TvtVPfrO++2vjmVuKajCTNeinz3ZWLHFOqNJxm\r\nFWKDP1ZhshhEoOf9XWC2p9NC3oF+dsecbTbut4f1tKOyy5H3n72+bwkU7LH4\r\ncZ//bqokC2yqIkkWWFeQImTriOIELxhz1Pk=\r\n=D5+z\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"36f33a73e47bb1c29cd76572b531be04cbb4a974","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.226+36f33a73e","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.226+36f33a73e","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.226_1668325958718_0.3154721622292609","host":"s3://npm-registry-packages"}},"4.0.0-canary.227":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.227","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.227","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"159757e21ab478feb83e9445c264566f1a123b2b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.227.tgz","fileCount":61,"integrity":"sha512-vHrbRDH4l2FvD5x4WXtwA9w/iFPreQubDYrJUfPCar1vNafZyv/XRjwwkYH5b5TRzqAXPYsHgQvss8ehNgiW3g==","signatures":[{"sig":"MEQCIFM+ufWObxrK7XpByiIgZLSwFkffs63jMIuTZUe3wCQWAiBVFt/EAFOCpEtuteGii9Ltgzp5Jkrfnyyq/v9VpgaB/A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcLtrACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmriNQ/5ATFkKxU4D6VwlCGIa8sndqSqkWn8cFmt2C3LEJgV7sFwguLs\r\nveBzFnu2fIiozcpSLa2U6LXlJx3lVBl+RdResRpN2U0xrFQ1fvBmy3Kzpdin\r\n2uNgh+VzgDMsJzmssV1ShRFwzNAZQBNh0/znneUOGtTjg72I9+lVWydumh1x\r\n3d/aqKz9rsgs7Z7PPw30epgC2Asjx0EqpwrSlsl+IQGL9Rp9KIc53GwUCApc\r\ntvad3y1IZzFdRVAHGPMZLA44DQ9FbtIB+rAOAVXQDRtCIUXcsBHS1T+EEnu2\r\ndbhax+OEVsqn6tLWYcxrggrGxz2KHvDN8BaRvggUK2ZF8keOkqMRxPag4T3T\r\nSttoB2cDoRihUVXabn4I5G4qI0hBwgl3rzy6rsYzNgDmWR4N5sMW2de6eU4V\r\nW1FeUOuqYs5WvlTUj5ah4+2MFBq9cBvZSSQxCAiBNBwBCOHjn46THWntivuy\r\n6ZMufWgpRHz5E2/1hE2Ex/j+AXFYD/E18o7Ty+PuXI6y1K9d56gY3E3pYx5R\r\nEFn4mE5qnyIEwVQAKwDStpgNcQrse2VNMsJHW12KzswPxrioR404jf23wPxO\r\nEc359AgmaUPur6Mi+E+jmysye7F9TwIf/BVxOLbk9If+PFO42NFPHGWUxwB+\r\nUNUM7oSTRGdruiKitMpGuwdI0+AoKaDfPKY=\r\n=RDKu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"80b207b886595931000b1bf127fff5fbcfd4edd3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.227+80b207b88","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.227+80b207b88","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.227_1668332395322_0.2681106747389128","host":"s3://npm-registry-packages"}},"4.0.0-canary.229":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.229","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.229","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9ab813ba79070c93bebd99f374d838cfc38f4649","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.229.tgz","fileCount":61,"integrity":"sha512-7rbX+o4ZeTCn6cLvwfpIZspjCCjVLGi7o1ysQqvoVW2j7sYIp47HqBDEXboqA9uaglk9fK7Z4hifXI5Lb6rPdw==","signatures":[{"sig":"MEQCIHdq9zv/gj3ij7ZNjKmr+szXRM+GP6lKWFM2pfmyuRSqAiBsAt4hVq5Yfb7Ct/GMmImWiF0Ot2hD7k6lnu/UUwwiqw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcQGcACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqfTQ/9FcFr+GVHJPSdYAO/h5Sk/pvKw4+TpVONtS86kJaW8iOoYs5Y\r\n3pOv9NRvy+AJco4e2bYhRRWj+dGkIyKzZEA8I+rqwx/jg9JwZvavvzCu9au2\r\nBdFq4pPjXdteU8+BXLV0IzPpUiq77mDSlO79VcC2NR3iI/Gc3ZJEo4wRmuoJ\r\n/h74U6sv/KgLOG/gc4qz6KneuGWSijg+dsQ1kkNm6tDQKVyDaHfqZSd+0F1k\r\nT55xBHXO7lKS97UUDdm4Cr0e/HcO1gaRn/oRJYQ+v5U4vj4YGpoMAv2vL25w\r\nUrVwPBHe+MUFFghHDNGhF36Nim7SPRfkIx7zALsaRgPzh/gdbqYfvhfXrrhk\r\nHg0ZBq4eqWqDZm/sJtTnmxga5JiQtKlpgyH9kDvflRr4zAq+7es5sQpfW+zr\r\nTFxaMaCLiUSlZ+r1U3UbaBbwHUtyOZHP+kVMR+BkDnYj7Ms8C69zyF+t0J0m\r\niwPjYsnzsylMCp7lwh6PAnqaoYvlSJh5h2GdXFz0gKz9VZYnzSIfwpHFWZ0u\r\nNeWnsGvLaEql4R9OEkIIw6aopTZ3G3oKByE0QPgMe10tXL5/I2iF5PLcQ+QK\r\n/8TtCVgtcyC9MXJvDNhFvitO+DHFleDOk+t3bkej8A/rOn7kRT7Klh3JN1nV\r\nyv5Vsy+5OCwvDKXTc+TlaUXqpo6rk42JXyk=\r\n=LkiC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"61ec0fe65985b41e880020a656d7ef7aa88ebaf5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.229+61ec0fe65","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.229+61ec0fe65","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.229_1668350364300_0.15178461575843172","host":"s3://npm-registry-packages"}},"4.0.0-canary.230":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.230","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.230","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"747c9417249a60b0f45301e31dd6d801e8b96f90","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.230.tgz","fileCount":61,"integrity":"sha512-/zG/GZpoiOb+v8cy1QJPxonmr9g+sapFD3kiX9B++L1C7u0F/LnZppM65NEdX7Ee3FdBmhN0STaADhpcw4F3Tg==","signatures":[{"sig":"MEQCIFlSSsOK8E7aF9xHN30MqjB5299xQNTG1iGfttCP3EekAiBRrkBATdavdDMgNAhawr6kkpH7ev8NN/Jk4Pr5F1Wcfw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjc0HbACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqVEQ//d/ux3el4M2WmPbKqd+MrRuE7B+OHx+Yyd8VvP3nXH8u1/WXZ\r\nMBAAgpsVrrlIiV4qq0fY1B1IYKeYQ6h3iKjNLG3vnEz4d4la7rVsUst8b5oC\r\n0HW/1T/M0WRsjzzOHHvJAF2BzWIOO3cEWl7dLqTjSakXjq3Mb5ITfNGpgDeg\r\nlYSZLm5AM+plEr0RN4HAannbs+U6XLi2+Fqp/jV0roHclh9dK35iXgFkre0u\r\nGMarIKI3K1Wc78ra5m2H9TH3kUKGqmQ3zaoahwUIB2KhmGfmO+Abn4z63V21\r\n3S/fL1J1hQ12f3IAKvIxwOI5tsaJpNWueuha7Pq2e/OhRKy7CR+06Ia1bbdm\r\n3QYre9rRkFtHcEdqBCHE/BBcNfJrFxcRd3WX4iE46ize2xwqVDrYgkpI8yTs\r\nbP2EdSwRgm7KgwaHAPLUOI+H8VxStXsQm7NjHzIocCJG/xmhnLzVyLRW7rQc\r\nTGbwR2B7cGGtjy5U0aZACOiDUJn5RW54V4yJnZu9Qz6b5ofn3TpeNf54cULP\r\nDoincwjTYCKDMUX9vJaYDF7hQrLXDrlRsAmiN3bB81wI4ni13Ee1HVaP+13w\r\ni/DUGBSBCC9PTcJV/T5PZ9QOR+gvY4MP/7cTlgbLDjAg82PwLmqJYVx0cKi9\r\nQY/7ggc1UHdVfadpKc/1C1Nf51pwn76g90E=\r\n=6/rL\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fd8229c550864f11c8140b8f8cb43f8d609ebd52","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.230+fd8229c55","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.230+fd8229c55","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.230_1668497882985_0.5198475729611596","host":"s3://npm-registry-packages"}},"4.0.0-canary.231":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.231","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.231","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e6516329cec97b15fc6c49fa1e22011f5185491c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.231.tgz","fileCount":61,"integrity":"sha512-fhDO8SXMkD6gVc2UgtZbN9J2vLdVKq/YwIBWmLczh2dxUIcoICxkQfQ4bZaVlPrzCX+UpHACea1ROSJRcnOVhw==","signatures":[{"sig":"MEYCIQCo838XyRSKZEShw7z8WqnPxISxpHdjqA1LSlaMafyMZgIhAOnopK6LYypdNHkAaAH81B1pRsHK0xDelOfuigEYZgxE","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdS7bACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq74g/9EXO4ahGlBy08qoyBZS8MQdgX8dY5M05i/r6Hho3joMk1EdBu\r\npojJuVeRG9nXowhLZ0Mh3VZuJRe1a/V1h1a9JsZtNrw1nSi/MIXpMjPFZ6Fk\r\nqFsPBWBkCuzo06pw9uHw9AH2ZIKVSQpN5oQPb1sme1+Ucov/EReiDJLkvkRI\r\nrQJ45KSUxaGxHaf7XXmKCSGN/EOuNS+p3Uh4a52eF0p3RuL5DgjRoMzQJuDA\r\nn2os73wGR4yQ38oEqyI1vBlIEem1liI3+nDWmcJxGzE75KvdV5VgisIu8NOw\r\n4/allrho/4rFaGglNekylbzSIdI5PYKNnFTWRAuh4PrawacQb3KQCgRoDJAw\r\n07Qla6tMuFpdUY7Avbcs/26ExbOTVE9oECV+4WtO3uIPLtO/3s9+7ffcSRPu\r\nKI9GoGbUhrjOLRIqwOjfHJ4jcYfCUaEoL5ub11bQtWTe7r59NN9rqPoeqSN8\r\nsQFPMr+Qg5YBq52wnnbycK36Lql8Trel/A8PjPMC5WxTSyniropqPrhN+MyC\r\n4jwrNItyxHO4/vvCpOsidboRmcdZrDB9R6vGLMd1fZ29EUbdHNAOp7UfcOQB\r\nuvCa5rx9noqB7h0z1UquiCM+XTbbi7yUUnplBsWfWejh85rbt1G2wEajucdO\r\nPnw33hJMWiSub+RfffSkouUJeuZ8+uOFUCg=\r\n=8+Qh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"97c36e1de6ed3579056aedaf6c0076fdff550c4a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.231+97c36e1de","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.231+97c36e1de","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.231_1668624090939_0.5773125137970847","host":"s3://npm-registry-packages"}},"4.0.0-canary.232":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.232","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.232","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0eb8331cf362ee0322c94d8f7bb889a5a39f8fd3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.232.tgz","fileCount":61,"integrity":"sha512-jVjdzDbJJ7vw0QJdomZBSpxKgZk6dgQjjOfY1tZgj2wvIw89E8YZ3btGEZHpZS5giiAnAgyu8+6R9WT5NAUnIQ==","signatures":[{"sig":"MEUCIHPoi8wrssfWAkVyU3CGbqR+P72mIlbhMnBXxnoFg/8pAiEAhQcT3R+vpilsNTjb4bRfrD4ZdzEKe3FOb6LMBaIDi/M=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdXV5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmofHQ//eWrr16HOJGgaI5jv38rOWhbVoRzJUvJ3dnDG+n7/PHfVluov\r\nDWbIaeuxNZqFr+XgAyDm87syV2ytn0IHWPY4m65n16mAMdL8oJVjYCAFYlFm\r\nbBGDKKK6oQqFpGSqGnYIpaBXxEqUsBX3vDqKe3v4XdDng7JfUgTAEWYCpRXE\r\n5Zyu0Igy4Oequ19scFKqROWMmAgmbDxWztL7jIiNSDXZL/wghzb2dSe3rmTM\r\niAhvLzDVhZ+tmZqhuV9lWh0lED7Uu40uyvJOexiR4rRObLgFy65PYR9t0q+4\r\nNG+87rD/hRvX/GqXZqtwl0tBBR/9qqMLSCqi2gzW98qvbAQX5/EFYgvpFTzw\r\nGPNad6riOGnRTvs57XktP+wtIkL3smAkgri2d5kmaSm/MWOE5Np20a0DJv2v\r\n4sCJH9z0N/A/18vOaCWzOmVJ+716pxWshvwiBjlgQW8rTzCndgTeY1DAREV1\r\nlNOBQCtBInxg4AXXvcY0/E6ikntzrxMKBPPKGiqXQUCXclnxntP3+RIn0wDS\r\nsegljXj+BIIsOY/DI5m8PzSvXwlSMkEOKrdK7wKK/gZcUf4BHScWhm63cLIf\r\nYFkbRzOuNkLiWRGPYzACm0LNsjLgo1mMra221joH1v+zwf44wYqtAjKPL5KX\r\ndvmz5lP7URTrjL5nLNlDBhK1UtkkH0B+0XE=\r\n=ZopV\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"da8710fe030f9c517524fd88f304e734298aa56b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.232+da8710fe0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.232+da8710fe0","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.232_1668642169343_0.08138126746901908","host":"s3://npm-registry-packages"}},"4.0.0-canary.233":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.233","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.233","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"20dec93fc48d7754a8240e28fec8e5ea6c50c032","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.233.tgz","fileCount":61,"integrity":"sha512-Fnbg8Tz+X/KCKOyAyqpP2h+OGXrjph/oPWl9CMZLnKT1shwTYSBIoAoZaUlTCEynaJVafU2+GpZfnu29mmHIsA==","signatures":[{"sig":"MEUCIQDZrn38pZfB6U0+IkTMLsxEDA3AlOJws+r+cVoFV8IWlQIgU1A0K6Z9tvW1r6uuY5NyQeUAJcCQWStCdlaBanPktTk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdoinACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp/AQ//bp+2Hyy+iFJpcsyqQBa8CoIUzcfM4tkrohtL9xvS5UmRJUbg\r\nUzhpWefHyx+CuBFbCRoOvTSm2C3WRaMYOA3qL007GxnkAlr0l/iAlQBSQo9V\r\nQB2rqma5Kgntc/vCTp3Kj9ThEx8L+PP6yj7PiXxF66pOQE0acT/A6d5lsfX0\r\nOEs4rseHf8FRr0puBSdYtxu0us0Dsd0dlatfhBqScHqbwneJZfdhkG8biCCT\r\nOhfJwM2I/cwWyE33MnonQ4mobKgMkHuY3zF25bVpKMXavneO7A7p62AT2H36\r\ninjeR9XPutkLsLFPHI3vxzjSm5jPEnnkd/ucHsnZt1nI8tcYFHpOomEGeKfp\r\nEdS+PWAkHd81myh2rEA/pi7YX8+/Aj75IPx5cYuwHVJcMGnUDK73M7b/DyHp\r\nHXWpDXBwjgpc3zh5jAseHZXkpurj6VuX92r38JHPHlnDB2EkZwRRvwE9tVbL\r\n7ge4hxSqlPGEcyfUJmw0GHtlMUfvkyKtffoKEKVi05pLkNqtICemehd+5l2j\r\ngPz1LnrKAr/dc/hNaMsITonqFuLCtZMGgPDNfkUDFqzhHoX0JplHd5Hm5ceO\r\nh/U6TSEAAejslCrUaqU8KcF03mE0wFArTpKMaLEAXFOMw4pFDi5UF8yJasUy\r\nQgq7/vlKNEfZ+RkYUeHQ2r4/Fz/pwzZma30=\r\n=x1iH\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5c46d7812ff415f1ad30838ba8ffc01ccb253bbf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.233+5c46d7812","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.233+5c46d7812","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.233_1668712615150_0.36182435422928405","host":"s3://npm-registry-packages"}},"4.0.0-canary.234":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.234","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.234","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e1f2021c662f6ac2bafe1d0376c88ca7234dd330","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.234.tgz","fileCount":61,"integrity":"sha512-EVs4SMdSmSoyNl60dH8MCTfp9wCmtbd9tqDuQPj0qM9Pi1NYAWaI9EL99Mm2nmwMGmNp5gbeT2Tpm8JjaCpCtw==","signatures":[{"sig":"MEUCIFmpP/dgTS4wZcKQfU8DUEG/Z2zyhQL5hg8JQqL8npIeAiEAykzme/Qf1DNhExvRauRnKeAUX1bJyCDkxX1+mqkDAXY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjeD8NACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoDfw//bEvHDtenHQ03UjZ0MXBzcJjKK43Awdqkn+HcP9nOct1CBVa2\r\nXe+ziqQkXKyncPIRhclj8RLe+hTVqEWBuugVwuZj4cCel7JIBruYvoSw3q6i\r\nm/n6l8XvMHLyyM5inYlsjaP5gAvL0+joJxs3LsWXw57s5AqQ+lWyDtPOC3dz\r\nWdZputYt8f6QRGHglIF4ErbO1+QbVK+FU7DWj49qOsNhgVOSmg/QeBU1kEwj\r\nQWQuvEkrSALPFXa5ULV0/kjyWBgxUit6ClUdsiBQTi/D0lOfcJtfVv4cIZ6W\r\nbx3WiCEgDBmwJIBmKo6EpthF9QYET+PkhBycFYW1VQ59Q9tt5nEVGLuDXCGB\r\nAA16YODccC3HDLsJTSDvqp9x+QCFAF5I6FuHWd7I1bG1mabdSclaRgIQTNNt\r\nnDvRKrQzlUNxzrSwZJ5nenJqMHXWPsKkORGiUh3KAGfvND3VLfC1yBwG/yK4\r\n+tRNYE7wk/sErb43vRkuucA5gViRmhk9EK6He21QsXECwO7m1XECYvtA2JBF\r\nIHhF/pbU2ltHsoIVcU7ryO+T4bB+usiuRlAy7cYlnMlzx5jycEf9TjLRz30I\r\nv+d9vktRdUvhS/PZouY6frBdbuSQK2K0iBp56zHfWT8GjAPOY6Kk/GWA9w9s\r\nrjdOTkxPFBcSdb0JKHRauOIC2t9zQ12cGpc=\r\n=lY4O\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5b772cbf4b002297428127ad804631fd0c62386e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.234+5b772cbf4","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.234+5b772cbf4","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.234_1668824845114_0.8344248380527168","host":"s3://npm-registry-packages"}},"4.0.0-canary.235":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.235","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.235","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"543a80c832904140eda10d514ca378e61c9a848f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.235.tgz","fileCount":61,"integrity":"sha512-pbOM+hsrO7x61JXDY9kDAfXam58Vy+dVroRFxzEYeZs7Z6AMZAQTiVkoJ+2jtEtTKYgXgNyYGmSHDPP2WbQUVg==","signatures":[{"sig":"MEUCIBDfW+CoYyljKQ7BrwkhcF6uNcjsA74Slmuz47K39lqwAiEA7v3+6ZdCGQgv0SYVZlGfxyQ07YgX2hGubldCXkmn29o=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjeXKKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo+bRAAoJLKEJCDFwYupCYxqzxFf6XeRPyswdITU/ofHZotf4DXEBYC\r\n/t6tVZjdq/0n22Tnpe1DEBGvfdj/aRhgNyE47cjAbrkbC3XdZV0uKV0qMMe9\r\nXK/YS0WYlA7BdaXZBXmjSie4ARBhc7cEMzmTD9QolYJ1SyOyzRNBgsNV1AyD\r\naIWqh5YdZzJAPfzSfqjxLrzFR+ZHKjnwftIJ/43nYon+hZ9ITdwxDjJ1N4iT\r\n20xbFzB8RO6nZCRE32lTAlSeuUInDqcE/CjSo3iWkLaIOF8KTpdsCCJFcIjA\r\nwYxlcx4Fon44ABJKAHD27sfBPi54Fg5RyFWwL310gAGPv9eVySkU0I4lc7Rq\r\na5Eo4AD5E28U9biYpuojUqbiJYcxwh4RkpWrsdjbjA0jloEWCRRI1MyGp2xl\r\n/f+jLnribvIyyH76vSfmVSvFTERKWqbMheL46p+WBekZGKAI5d4/BvJn6U1G\r\nNvCvTgB275B4tSozbAeritXhZex3+4EmO+BL5Di5uVHJQrRjNzZXtiR6RwAn\r\nOKWtyrPnT2Nd/8GfmmF2UNa78zTT/N/+2LJsynv05/00om2reCkeU1o73Nvq\r\nvjwzM78CPERrdgkFsd/S6WvENWwFbmUEQTP7/wQHIIzeqcxRAMzkD8f+eoJI\r\nMrG6E/lnXfA4Jc008zTd2nQGDaJi2LsilL4=\r\n=1eIb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2bc3a544167538da5c12e66902f6a385f4a374d4","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.235+2bc3a5441","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.235+2bc3a5441","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.235_1668903561986_0.9529688437096422","host":"s3://npm-registry-packages"}},"4.0.0-canary.236":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.236","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.236","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1e27a070b38fd2497cdbca371aa70f14d530b544","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.236.tgz","fileCount":61,"integrity":"sha512-uILQPQyl0Z3yXvKaXM2larRWiqeR/nu9kxYYlyNwG0Fiv4sOzbNnFDyFFXD+P3Gekyam6iITd+deXQJkYaIheA==","signatures":[{"sig":"MEQCID7mf025SxgejIBtmW1ZsSPt0Ug1mnZ/8ATFnDfOpzMqAiA6jkRMilUstyQdtAI6EAaND3rbFbDv9BFrspAMiTv3iA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje7uAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr50hAAjAGWTS5fQ6MuPrwvBWJ0+tmPB0xuAlxKMQmnmcPguST55g/7\r\naQ9I/VEtSEEl6ZdQtwoJ3trz7UhXlt01n+QX/GNPd2TT6afAFx6FtgJ4dTEj\r\nMZ5WqPIEReCiZrYxIch1GIRwibgPi1oQg99hlaQSdEcHUnWNPvPxmAF2uuci\r\n2zKqeGEdrjogwKoLJUIBrL5SdShIZnfUNjcePfzTBdrnPBQfwKh/QxYLVRIW\r\nH6DoqFxCqgxNQ2HaRDAK9xTFIPys/jGjVboiEo0xkFzTspG3Qffl7UQCLu+0\r\n6Wk5+TK15mBgDdJ+U7H6kDv9jfBjxGorTm6StDGlqzU5rVann6PWbC1PX6hk\r\nWJKNU7GDObPUr5Qgw07rAnQny4mABd77ecjykwpQjLTqgAS/SzhYnrdRdg6g\r\n8CJaSJYgtDzf1X65OdNacm+8lN9ATdMQUib3jdeabsWPUCxMuxXpPa0wj7g4\r\nLAFr7U9SO5BPVqL5VmooXf1hTBjgv4Aypx2Ys/s+ClPKPU43cjejVCpHSvI6\r\nQJy/bkYSpGHSIL+DCPgp0CK+ezu9BUhq4GaEJway+uoUnKclYTKkbGxEnGg6\r\nd210NZHLgMDHbvBXHhn9x3WXbAUK/70yk63u5Eksbx1Ip5cDRTY1DwVVRmva\r\nWxt2FE08Uu/a7yGnNtvtRrrpEodSzwDRvfY=\r\n=aWVW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2e4e4e136ffa40d913c629dd392996233c6008c0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.236+2e4e4e136","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.236+2e4e4e136","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.236_1669053312538_0.6911814999540686","host":"s3://npm-registry-packages"}},"4.0.0-canary.237":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.237","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.237","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ca8d872d5c6df6e7380cb7b26bed24cb09d1f7ab","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.237.tgz","fileCount":61,"integrity":"sha512-1s7fBiG1XdubTfQDlYq2bTvzkuVC6vAD8Y7MUVAO4sa4C5FjnD1h94LVKhfhqMVpwYxyTax+PDaxHGVzMklbnQ==","signatures":[{"sig":"MEUCIQCgtb7YKdCvo+p3XB2WupKnf0jhlWOot/Ilc1fWMIwgaQIgeGpXrHZSSp5PYWmW1BAPayPyC7hN0WiRCnTimd6VEkk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje8dlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrQ0g/8DJIGt29rUewfmbF9WtsQeGZazW3sIFWLjen/5kE05O5yKqiS\r\nK7hDKxBGBhNQjEnlvuthpaZmRBix+JHKLDo3Hz/+9AGBbi9aipFZ5NI8zFWE\r\nfwdduSS0c9GfCxGD3v3kMimLg4iMEBK0tQFS7TkgSXW+gCrbplkcwbNggh80\r\n5MOvDWXpiqlDPdJ79pL6Ddrh+Az3tWa4MEc0xsxhMS8/cOOB2J7YxJZ7fB1E\r\nj7XwiNU+e1e/4/zXJgiuB9vywpbIVERuNw7OhKKcRslvrmepMNzR+q6vd43r\r\nCUUqlhl83/4n+IwfT0z7R/laFI0pAPedKCOn9EN/nrvRiLTpxRvegJ/iC+i1\r\ncPvagdGtafN7Vqhlv/PKQxfom6/qYUZCN0Ek2RPqs09SGeod0HXcB7ED0JBs\r\nFAriSktBVQlXg2fSPgLuZKFpRyUNGp3W6nFTGYAyH+pDMCGr6HKZgEXoC2cd\r\nb2v4sUgOqGLi+4Wiy3b1RZjYhU9D/CUC2ZPZ9wlJy9nIOO8Yqxn51oPHuBV6\r\n462NdD3Kk7VY8XgPuBv6hYHYX0t/up6YSFKRrGS1yFWBpDgGszOf1ffxuKN6\r\nkWQ4lRW2vBE/dPZ7R9VycG26n7DZgfHEuEdE3agBD1TEGFonmQawFZBYefDR\r\ni3gvB028NVTFDajM1eZ612fkFclKIAwwPjs=\r\n=+7SD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4e0960a81f1b73c7055e7ee8e9b1666829df44a8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.0","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.237+4e0960a81","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.237+4e0960a81","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.237_1669056357051_0.8450832604369021","host":"s3://npm-registry-packages"}},"4.0.0-canary.238":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.238","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.238","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fc6bd15ec11af9f48f662a3037159dc3b386247e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.238.tgz","fileCount":61,"integrity":"sha512-kqkgjwJxXW6B7qWIieSckQ0IinbY4tytUr/re5jPcNLQSdqXT17p1YKe/u0danwH3AkafthbnMiBMjYtUeJwyg==","signatures":[{"sig":"MEQCIAXhXWQNlKQyX/Y7f5siBK2DlYc6tCPV9NDo9yC52dFLAiBz+BxoTgHKVNJBCS4hvDEb00gK2Bd4XA8BYBYGZmJVlg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje8egACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrrxg//b906uaUrRwj5pvFTyQeI3ilQoilM5mZnw4oNURgJ7ojd5AXE\r\nuR6JEhp5Sh+P15pJts+b6Kl3/7mddVhPzj6sjYvaaye1pxhZNX0uLLcji1OB\r\nPKh7O0XSdyZNfBUrLFYi8nIIDSLcN9+hdgb12BfrwgojIPkh1oxDLQXPi2Gl\r\nqi2NSD+WUCn6r0kpwVtLvrLGlPArhtml/LycLVAHs2/Vl/4RtkGAqnzjLzSU\r\nRcIEr4rJ0adJJimJBHjxlhc3cL9QV/Mjn7xH64xKUx2gh4Fo0AK0/ax0RclP\r\n3fAvEE8VD2GobxVc8dSLiLyJnAoSY95ZQw4NXCssx71tlZLeHXQZFjrOZF8s\r\n1GlYQVDIXBBPN7zjfEYtqPVWfwRBhH5EMASKBNhi/3effd+PXXPv1pnRTMhK\r\nqphbcewrgp4vgJdfReVx+PuWVAZIoPzox12t2Xxkp/hgIBcqPQ4FAPw4pgx/\r\nPMe6m82UN3wTdDZR4EI9lRATSANlqu6KbPZEVTzhsrGzOXAP3lOlJfT7AWJv\r\nLY4LuwLMeZjPeALkds5KidFT925IgDjkvCF46uKGMGDrUkp14RIlvZ6GOeUh\r\n/ydOuCpWt6yMwggD7EP3KaFxsWSsuD7kq1nhLSJXv2rl21Gl1yzEHknalBwr\r\nKhSOM/9b6FdTt52vSlhTg7i7gUt3EoRMJP8=\r\n=uCbN\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e607f1e030b13e2a085742aaf06f41afb1b445af","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.238+e607f1e03","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.238+e607f1e03","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.238_1669056416532_0.9968398161169469","host":"s3://npm-registry-packages"}},"4.0.0-canary.239":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.239","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.239","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ec6a3d2f5a4741f8ea627778e023158c3e368e1e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.239.tgz","fileCount":61,"integrity":"sha512-ih595Yv/L072aFb8MXJbol6SI9gGJAa1qoeutYqvk/5gyCBs7NrQ8FG66KO1tUJRqoG/+qThpqMQaxWBDSSBbw==","signatures":[{"sig":"MEUCIHUxpEtMJAWlBqiweX4upeHF7Rl+uU3stDC4CANsDFkkAiEA/QDUz1cAZ49ekWRytNkLCh6zGsb8G8rqEeRtBPAu9dY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje9AxACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq0tRAAhl2Zpd/pF5UPYqn2aoByi5CtSszlz6rD2uKEYyKSNVsofmRs\r\nQc8o+DciWAbzZhpAd2sFZ115OovFUzO0BDrC9XXJwY9iZIO25N2hf8GX46IM\r\nz+mboRI2w3mhoUj0YiSninUvD+KF1cTG5OkErGdqJu0NvzynVcBPHpvC8NkK\r\nILiXDU4rlYg3sj2e8yH95/NDYnEmy4J1IEG/3wUlV0VAqNoLRzEM28dV7kvo\r\n3gMnImE6QQtEpb0+ZvMURXj/fGou3Zg85HycLl4s9bTKY+zmB9acX1984XW+\r\nTgp7WA+HuYqcGSA8TGNTgavcwHCvw/BcQckprXXaGwoIVfhLcRZN23LcR1el\r\nCwNY8ojjaEjPooWkvmtZWy31XT0my/MXQecZ9bw9edj481TamPAvBFwXigRq\r\nVPZDjSoBa2NjcnjKupnnbfgRDQhCN4TF1fYALCOnqg15LJiw2vc+vTQYe/L4\r\nZGvLd1HpDpFRgmj9UiKuKVFttu3ZeNaBExgAt36YzXJ2apM7/NvF0wChzgCT\r\nGJqPzMotPa7nnVL1pG9zj+Toy4lEoYYXi3T/rPJj19ax5Tpe4l/yqLJ5NS0l\r\n+ArHQjd1eKHopTcFj8JI7RB/BxIJV09cmgXUNX32qGoh1Sugohyb+rZXsnps\r\nqwVPufFHs+Gz+4HzvKsoE9TF2ZVY8eTo3Us=\r\n=0Gg3\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8f9cbd7e1f3a7db5463a1b809ce799a5f8dbcbb3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.239+8f9cbd7e1","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.239+8f9cbd7e1","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.239_1669058608838_0.5809177297556842","host":"s3://npm-registry-packages"}},"4.0.0-canary.240":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.240","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.240","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ccfce682af4f235b85689b32b2e6a9c81d58066c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.240.tgz","fileCount":61,"integrity":"sha512-KFKfeZdXk89phZ6GPE1ylDOA/b+KV69fXVOUNV7jd5YXtoaTdWzmvdf7nnJeIfeMAc4TLBqnXd2CmYVozEUM9Q==","signatures":[{"sig":"MEQCICdQpk8wm7KifJHcp8EpteOZCyE5pfIGrAHGkGIF1yl5AiB1XTSXJBSHUzAhj/h6Rc+amiHqDtFDAnn28HkPtqab5A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje/qAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvMQ//U/2Xg3aDgrBcS8AdMer/SQ5r9OddYUW1XAU6VeUyVrulpKTN\r\nhdKqsmMHtOYDz/36ldNhxG63ABCurmOV6iEYwZb/gR5a56V7xuqiFin0523u\r\nha80/s5NfPO/yMp9EwP65WV1b4I8QT78IIPqhXQIMX6FRjqkGqF2qhgyxCkq\r\nDtbWyRdoDv8/Psp7Y8AqkDNE9yLnCsbuzslm1QJIWCQNxVNfBtGnjiyGdlx1\r\nycO93O211l3hi2wJDkI8E7m+MBqs21d5+cMFj3Mi3W/Vu7WZqKOsNAbiAi+l\r\nxQ1YRQAVX+f/yuX1h8ank4u+uOM4bEVC5NrKeGvqM5ycQEUM97QumfEOUxIX\r\nosqPzwUqP5x06rF1y/t9fW4zKzBLqXDNmCLc6vRJC47+LwgR4G7cNa5Jb3Gx\r\nbyh+2VkE9zWmNmNDA0dOlA3ieTqfH0eP/8rtor2YQOOCx6/CjrKGs4AjHsWf\r\niMprtcabnQUBF2ak7fuzrFvdcZ+WPSsugN8KO1vvnmiE7g+mQsgt6az31nhK\r\nUHKj0+q/VJi9/JbUpU3Ftdm7x2R+L1Cp87ptm70vqHa6Yvn02LGXq/aHqBEo\r\n0B5R2zHuLDVJ7a85rQpx3WeLy9E10YYf3PHnf1X54YAYAEovzp9Ht62FOKLw\r\npSYKrC8NJ1C1L5Nd1Ad2Xfo5EffjgqqgMZA=\r\n=e8ls\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f4533a8c65db36a7a697b2c9c1192823fe4ed04d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.240+f4533a8c6","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.240+f4533a8c6","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.240_1669069440508_0.59248959190073","host":"s3://npm-registry-packages"}},"4.0.0-canary.241":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.241","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.241","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4b2151ae662cff01c5f89047d1784f0fe404d058","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.241.tgz","fileCount":61,"integrity":"sha512-/yhq5fnejSc24OmTUJFDxQhKavw376Qvhvt9Vnwu2bKUJc3+h69xnZ5mFf87CVIaUGy8C+aE3WSO3jsYwabtSA==","signatures":[{"sig":"MEYCIQDEGrCX6XB5jbzxpvgVpmqGM4SudE5JKdE5rI2MncsnMQIhAKNNZo02yNtgfNMGQDQJNaB2xhdQC5HB+FpxyTeXFr+B","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfAjSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqEORAAn9bEGFekgm/A9ZWTM8DtXFQHFSzE8mjx5sHScR5Z1l3NUu23\r\nNPhLQDqPFm/4lcV73dDk9pLkxsrTGCsxTeK8P2Lp5pQ8PaRdx5Bp4zgC1VRL\r\nPfVMkmUBGeFiORqec3jXivkStYZBxDGGCHbtLS9uSUAHTQkrMwDVckQw3vQF\r\nddbZXQShdQcgLYxd3kxN3SuZsSSBXBeRiyCFWbPtol3EUhQUbaKuFZTAhy/V\r\nrQsBxaebUEtkpvJ4/TJV/Mc/R+gXdwCZDrt5Z02fgPS9c7Y4wfjCPahqN3Rs\r\n/j/PNWxQ1daPIPMiUbLiTMSxeSPzDdw/z57qRJTh8/VH+82LCPSr/t063sIE\r\n0t/g4dDTupfqFbZcyDk1eoYpxtF9ysAYz465de+oJlf5jmv5DTa9AW1hujL6\r\n2Uoa7Z+o9qpuNGuOBCyrYRG+CpZSs2ma6LzruJC+bHVaxoX7nGZg39zemigK\r\nktf2Sq3sB6QXaBjgjq20BIwWWEtukGSIPLMHRFhv4pM5NKLp0PG0LWGcVYZ7\r\nRSvUEzRC2l8RMfRY0rKN0oq6XeQ6jT334OIGYQ9fUFgifGmehEvGuQ2fDfJR\r\naaHWvWN6w1ihfVMqozPs6wIp/wByCzVy2UFsXhJ0yuViq9C3a76pwloMd/7O\r\nsVXkeEroRx6pqmdnG/VGhGI9YoJqgA/esDg=\r\n=5ZRc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7e5d60af9f0fb2fa297503e94cda9f3c02dde944","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.241+7e5d60af9","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.241+7e5d60af9","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.241_1669073106619_0.2110086421462869","host":"s3://npm-registry-packages"}},"4.0.0-canary.242":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.242","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.242","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"81bd003759a0142bd01862b32177de3264d3f1af","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.242.tgz","fileCount":61,"integrity":"sha512-4KX7pbs/y10+zCgx8dHPkFTOM9QiUA+ycQNMieOEWI2NL6Aw4++nQYkqw/V0jKW2Ck7cyYCmG+efqPNCmkAcDA==","signatures":[{"sig":"MEUCIQD5evpWR50STpxgx0y0wZBbBibP47AnX9zy8rgKJT4rEQIgeayrG72rhRkPbCMEvil3GvKELTUCJ6FDWYJ7j9zaT9M=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfEzJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqaOw//Zi7D8NYkczV18S72U6GEV618OMOSJvyxj9nl2UrcLMM6GkR3\r\nOQoIwbOtZly/myv6CqstNCmw0B5oCv4DrUu61RW/vZ5EMLFKCpUCGjwb/N7O\r\nYSIBe2ncObzcDq8K9wd/M0JTsKWwr0ttk+S09d2ELcSZbzPoOAxyr6I+UYdw\r\ncmsZGQJE5CSOsSPZV0v24Pz/VEemX91bXCo4NTibYc50csildwewWLq11xNe\r\nqpsyQN0E94q/X7LXUYOYU5VC2lLync04V39WAMXem7koQsvRE9LNnNa5BOG4\r\n3yZb85UhMIyPUgESbrXP/jj2e+AymNI0LGXaX9h7QU9ZR3xxWH9TL3ke4r7u\r\nmOE0qojGJEogpZc+KV1K7ijOk8whv4G2huilOLt8AX+VK5wwluRMIO+taBzC\r\nMjRRT6NWatmerIoPw5OP9JdqhS5SKbi4HqcT/8o8UzIb7Ppp6gh0w06gBMF9\r\nts8MzHdT9KNxlw6Ecu6bMTD8DAutJQ9Z/3/D5Z6TMfZy9gfCclMBSMqEo9vD\r\n2HUq89sqrKA7pNeymD+vuLvDMThSxTKE4LN1fv75fRlxYDWHQwFM+CNPrkyq\r\nGmRtCP/2AuREiHNKJQ1F/Lqhv9Cij9VNm2H4iXt/AKP6MycJPxdC/BJ/FDX1\r\nR9XRGASog+3dJZWGfYvlFzr0xl9DbYGDorI=\r\n=VJDC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1c440126df57ffd3654f5db75513b19a762f2cb0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.242+1c440126d","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.242+1c440126d","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.242_1669090504970_0.571532337313589","host":"s3://npm-registry-packages"}},"4.0.0-canary.243":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.243","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.243","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"92b55fab4dc9dff184b214d7f18c651acfbcd1de","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.243.tgz","fileCount":61,"integrity":"sha512-CvCJ/cKuMcmsarlpu0T6mlRfQF87gu81Yr4yzbF2ShSKujPLTgITqQLSy6a1i4wespzOMcXpNEekaGYtAFKw8Q==","signatures":[{"sig":"MEUCIBtJ4LpAuAVjLOawF4ugVVLnIfhO6fyarSDs/+D+msDEAiEAyZ4Y3/5XVL3Ovhj/bxGLFC5IC/MKb5L6Gu6VaFc375o=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfIB9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmowlQ//YaSRtm9Y5KNfwH6lu9nPoLyW3Ni9rnTz4D5imuVt6Vo9QkSN\r\nAGo8k7jykdLcI8W3nJ1OsCBpAak8tgtmKwu4vA1ZBQblEKHTEmyPF17+BZ1K\r\nCHfkovqqqEcmbVggGOSc4sznhalRXp9F6bQ/GqZIIvWfFhqeexTyIN41vB5y\r\ntNedOtDD7Vo0nf+KeH9tDK971iZyFOkqohR4gQzlnQ23zn9jyfrIWhGKdKKj\r\ng+Zrub1SgSUuc17kHcrwTWu+zVzbfWkYIwbJP+jGoH9mVDD2oL+OBU2COnkf\r\nTBAwyXwr5D3AZ9Od6lBnlRe67X4y5Jmb7/iLTfc0IqpX2U5KJqDu4egUrNx+\r\nmuauXEzAhWVnj1UqPu5LVBVv+BRcqbnCG3Nqw1GTzH2ZH6WAecGVo27c/A3h\r\n8XvkpqGN/OKQGUMPUXAJemYcyLgmps4wBWh8iQ3VxjKLvF9T8fLuCTXFQTWx\r\nMSkBBwzEYqlKLLjThuvTifIv8m84nmjRm34fR9Tn/4Pnu6rm39fSqvfZ7910\r\nKWYUhngNGuA5n00Ge1gI92kG1/jiCG3+ahe7uB7i6y8TmzswAMGFM8g1AEp8\r\nCV3mNCqRyPb2q79LVCIT4NGiPwt25yoyCj59e4i/6RN3aZXTZE4ouAbcR2rP\r\npcsbMtXdc9eC9Na3MLySGndrYFYBLSME+ww=\r\n=U0t8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a7b811141b201b544530354f815200e19027863c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.243+a7b811141","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.243+a7b811141","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.243_1669103741693_0.5092889205234692","host":"s3://npm-registry-packages"}},"4.0.0-canary.244":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.244","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.244","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ae09092dcd5b54fd7a58f973e4b6fb28eb1530e4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.244.tgz","fileCount":61,"integrity":"sha512-vDLScvQtEVXDFtXREeWP2JczsbcgQPGC6QwFrErFaorA2y6JzRM+OB5neKqWVFgh3wdVGXoX5xJApObef/Rp+w==","signatures":[{"sig":"MEUCIQDxC9NBpv/5jUo+eYsL/Up7vkLoKMVz4DA0hgZ5Lyya6QIgd2JLWtRhieP43jv5Y1QxVaXIcm5fNF5JkRGhLkKNMjg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfsrbACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrUhg//W3IAdy+y6ih+URj3SKq93qVIzsj02piBn0GwDwFV3LVDnJNe\r\n6TrWqnHktUimOSQ/N4W+Ho38Vr7Rd0pCs8dAjkklvWLrUGgTGeN5Xfyozrkz\r\n6F8n95kPyagSUH0hwcXq7dUT6L4ZlzzkqgrbTW3z7Ir46FWCmtwLuEAtOSxy\r\ndJ1u/7rawZEp8aIBhtzEWTppcNV4oMbKGdi8D67tfQQYGyLWmKadfqNEGjhY\r\ne1IbnB2NoVzyk8/JdQOwn9w/2kZyEqEY7bCdcX7zFm6RpOIQpx2SJQpeje3Q\r\nHH6JIFQsN6C9gOwQ61pbh/JiDWEKsjvyqyuOBsHSSA0F45A3eUVYVM5q8goh\r\nx3be0+MBdXOomlr7iVP2Gz47lhpLsqVKSeVgl4VV0oKw29toY+UN0xADFgf4\r\nLFLfopgKhMbPAXExzwcTevBw05talS2+mmnCLGooC2U1tJNrvKJ/tEPKjMsp\r\ncnoON9G12LIvIpHrNVmlX5S2EFI+WDSfrMn1EVqwB5ye0M6CJOPRPSj0reTq\r\ngv42C5a8BI/XdnbsVkknP1rCXTxRn/sPVifcxME6tf24tknJM4R6Zs7Fx6op\r\nlcTiTg++PLtSZoVo0BV7itId4wXR+VzINHqI7s5Ic+YrdKCjsX16U9taVBjM\r\ng4oEwUYoCJQ8muIflEohwggw7PyEmM8jLH0=\r\n=FGc3\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9f92a63b8c32b872b2b45fe247cbfb2ff2fcac33","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.244+9f92a63b8","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.244+9f92a63b8","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.244_1669253851318_0.6745115136091093","host":"s3://npm-registry-packages"}},"4.0.0-canary.245":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.245","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.245","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"288d0585faf470f45dd4ad65137ec330f8ca1786","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.245.tgz","fileCount":61,"integrity":"sha512-qzo7B5ncaVQvfvJ6ptKKZ3dZ/sjM0423T7GlDcKCEU7xoYtNk25AOYkmeB3Fl9bQ1fuUCMm7uMRryiUmC0t4pQ==","signatures":[{"sig":"MEYCIQCPULGLf7wTrceszvUvK/rjxEE5CyJNBH4edJfOpxc/4gIhAOzzaGG+ecIfXcVNoAU1FCRlp0B6BbZXB3rbwraz5tg7","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfstHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmooqRAAhGhCpqnewXIE31rLV/cK+vbzcI2s+iu81gTjSgVcAfwQ5wYH\r\n1X4yKfShcDkyHzqf91cCkj0ahsN1d+9ZQLyfcsnRO/uPB0HGQMrABb3H7akg\r\nsaIxrnJjNsgpbl4gQp2RxX3NC79n7knS7v3XiTlgzvtg+MuuFI3JMBZE9EBT\r\ncTRGdPK2gfryPqQXap2cUtqLExeNNKtDgYjmFouQ0aF+Y1S+ynON6uuk0TKG\r\nTf1LZmlIfPXO+ZY23EnQmjhHz77ayWoY7sO2p1yPIcHfH1BnuK7TeFWTJ+Ie\r\nHkxWUFiE8gxpPSCo2ybo92kUzHdRVlXt+MjB4ydkp0jqEil/xC8WpSwJrmMs\r\nm2g1gvqVlrQUbZlwcbv2JMmSTbff/9NxCvwjwpsZxgAJK7cKxPa6oRafl4Vq\r\n2qtdm8GpX/X0bWq4xAZhEVkapTzK4e8Np20A9aT8AjE3P7rIcj0Zm4n42v8g\r\nlp5TWolACiLzq6ogWgSzhwWaTOvtgy7OJSfQEGQ8lxKOc1BHlZTYrYyb9e+C\r\nORX6VEXfnt2bR4la/GO/wfaQfvPD3TJbQy5cgs1MdqAsse37xYGIrInKdi3g\r\nBWg3bxGW5IkoajGvfDpDjsfUa2pz40dG15zs2ZN5KNQ013nMGJpwtTC6VWNO\r\nkSxtFNDXrV+pWoqYHO43s90T91spUc0QWTo=\r\n=Q2pE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0a57f38cc27b9c2acbc31da52485c66b0fd4f445","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.245+0a57f38cc","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.245+0a57f38cc","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.245_1669253958888_0.07288932323997344","host":"s3://npm-registry-packages"}},"4.0.0-canary.247":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.247","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.247","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"80dce21dfe536904c0027cf9d865a63a95d8e545","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.247.tgz","fileCount":61,"integrity":"sha512-oFnN9HzNubPdyPoUYbwmPCv1nCZumgcSGAZqBuTBFH0r154hvhCymtED6EG7dWKHHXEjmlNYbapVvfRMIMHLqg==","signatures":[{"sig":"MEQCIFsvLvbJn7BOWsm1rzgF660kAyWpwa2kOR7oW99lYi6/AiAKFFVy76qpAGAIjlFsgxVSzIL+72JDeHqtEztyauvdyw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjftaXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpkxw//QucHvfMM8NLCg1sQzQUrM3D89vU1uhDrwRJp3YL/0yWQgCx5\r\nJKm13EQr0vZ1RwrVzr3RGH2yFVBkYr8Gfd6PPvTiPvMFRaSrPXzTnqcSXdTx\r\nS0nLPLy7q3ZBtJ7PuSiHjXzJHIhaejPxiYBYIl7awodw46NOmpocDTYss9FQ\r\nU1+/egoECiXBZx9Lxefze2iqBqmUy/RgeNj/90la0nsM9hOxK5zWp8Dcyk8G\r\niOG3jFhc4bohLI0je7v4W4Ysh3iIdD1At0/3gObNHBlNhB1rCBd2o7xi7UhU\r\ntMZLQamsPYWgdVk/BmChZZAI1nhdyxOvifw6rXfoS+LwpdIpkbJLeWgqN1jw\r\nPDukRq0j4R/I4TdVhfCqIrnPtH778ypOe4R7i9tKhkbruJolfdgO+bz4XuYV\r\nwq6drnOlHDMW3ZdtuAiSGKgbgV6MngsUrx4ZxfNCXVS6l9cUf6bwSk/mOxjr\r\n85KaIk6yddf6DBfxj/NM7OlHxM+x9N9YXHoMvs4Uc+6G3Ntg+eau3mACZ2hN\r\nf3bTYYMy4wlDLe5tb099BWxav+2qDoi3owavjUMEfdStlJkJ2FUy9SFrNxs+\r\nXn8YpKRxzWQgT9kBOGfMovzP6qXAXmZ6c86uZGF6UjuLJBU/4/FwCYrNlGdc\r\n8Vy2bVKb+tu/EeuMAUVH7Q/PzIKl6Czg4gU=\r\n=3aFo\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"72651134ddbfe0e2d56b1cc310156a9ddf49b4e1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.247+72651134d","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.247+72651134d","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.247_1669256855723_0.6907432026139779","host":"s3://npm-registry-packages"}},"4.0.0-canary.248":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.248","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.248","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ef04d62ad34b53d76bf53ebc9da0b1a1b67d4211","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.248.tgz","fileCount":61,"integrity":"sha512-m1UuO4IT9SCuQlr+rB54xDrDL2wc6ZbfhjhlsvfJ1DClS8EF5F5FcupNgCnx4xv1YNircOaAtqYEKLbRoZrMcQ==","signatures":[{"sig":"MEUCIQC/Ameac8ckeK2v75ZM6Rl+j4FxXyA0UUY/6Wqgmixj/gIgVJDnWJDDDLPs1uvAeYwpl92Fb8oFSsQm7fAlpRPNpuA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfwZ7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqfnw//WVr7szID+WXTsobD1BELwgrGM6vCXxlGS6x8ei/Yqk5uNSyc\r\nRS5mIbR6yHaHbNGfZOHF3L0MSWfmIsOgM+auBMmIJCtVSpAVZlMvskxeYzdK\r\n0FQ5H+uloeWnhEDGMC/15g2KkUcsfmhKfBn6o5+rabg9Ov6At6pjHl+pqouG\r\nAW+plwI1cPw+QC+hK8q7QvqokwBN5voWJh1WmcSGFx+x6xxUqDQtBQpZ6KVa\r\nbRJCZIMMLwG/u0/k8NGeha8nGVwaZYba0yIA6hPoWpIJwu5MYPb4lNRDYaG5\r\n793RwIBsnsYi5aVV3iWVKBxz7e7Itk2z7T6zAc7FeCDwOzjo5zAwYpVrr6yZ\r\n7QJXXFziLqufRNdYJ+SoK66SJV7nhvXYPrT0Gsuk+6HtvEm18ecKDJIAQ29B\r\nQkjmxFL6AdiEQCNmFwVp4ceESbZM9Q+5LalE/i5IYIXwsiYHHWHue1PuQ6PM\r\ni2WLaIt/GMkS5mQ6MrreuORGU9XiM1+yGuUDQir0fwSdvjuoEN3oDxS6IRSb\r\nr4cwGOo1+/ICi3OIb6D4eVPxen0x7FVjxNa03U8ISm8K0AIuYbwSM36CQOYP\r\nP85KnSqbpTd3WI0YX4A4QTjBE8fY0X5f9ZgKtHaVpCCcg47a4cegZBPzE7b6\r\nsf406pypHSsdoc2WK6N75i2ePB4vR6HeZe8=\r\n=MOvk\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c77202d4a133168f6e665a65bfd09bcdd5ab34ab","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.248+c77202d4a","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.248+c77202d4a","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.248_1669269115572_0.7567238814296016","host":"s3://npm-registry-packages"}},"4.0.0-canary.249":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.249","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.249","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"654243533e187c3c7e495089a21d27afc6c0a9dc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.249.tgz","fileCount":61,"integrity":"sha512-2XAfE3blSnIKXCdCp1wjMV3EGy8Am4W3lzRpPjjBUoq4/mGy2B4ei6YlTAEsRp+8cnJOMmkkRIhb6BUdNvMR7Q==","signatures":[{"sig":"MEQCIALRsetP6A3PyAUc4I8nDwZr/kzH+Kixn0ZTw2BYdKXeAiAIetRdrHx7p/m12vH0JZ6oIq4mfdjoLc2xvSdizVF0TA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfxvAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmohlg/7Bor43vUKxXPPLvgIASDKmR7Nb1m52SjdSbLDyX5G9Dnih1y0\r\nHeBdVeEFxS9XVeHjpGjsYp7pbEqHOliPODzlLEExZGDd7PvvvtoIaCyEzDAC\r\n9GuheYlgZhcfh5EnqZ71wX2CSfN7uIDeun6svCrF1wMf16mE8kzlmYRwUXTE\r\nf5mdyPce9fySctAUFDNKgzjfP4Nl0y3itbXXx9HU3fF1PtgShYTyOZBIVeo5\r\nDXxOpV4xtFPGIeBpXgVDJgm1MtU4OTpl6WEfuU9SzxS+DsI3BjI35wkhNVLG\r\n1D217n/dZA9BkqNQb+gHsLI9RZAcScSHVSrdnugPy4tsEhHDI2YwF99BK5m1\r\nSoqGN+yVah/H9rFuMgT6it3fd1/fNKMukpKIBqpuPxwmw63awiyFZYBU8rFu\r\nVZqsx26F7jneAQ+ZaP+qRUj7PM1ZAJbmaQk4VoKRPDHSKrRGJ6zCe1xanPLK\r\nlTbsTxw35ZkbYGA372Ix9knfXCepsPj91hfMDPFSFFJUN1KPdBMMudAufuU0\r\n3ImUNII/z5WtrH+lGdE8D4Mo/qV0OUSDzgaBSyI9sKiuFY9P2rEpQ+BIWmAI\r\nyL95uN9cD9DqEjbrRBM+rVAF8Ihvzxf+2XmPsc+CIuWGRNjyMzA6vNfFLUod\r\nTxSVmNM2aT1VevxPtTnCIWw1j1FNS2aGvwE=\r\n=NpUY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0e072837d71db5eb3153d2d94638225067061bc8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.249+0e072837d","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.249+0e072837d","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.249_1669274560718_0.4065464411945221","host":"s3://npm-registry-packages"}},"4.0.0-canary.250":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.250","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.250","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a6bf830961b19eb2a457338f79132751a5293fe4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.250.tgz","fileCount":61,"integrity":"sha512-7LPHP0JBYFdDkWj/w3YKEYXDiziDB7lYq+yrFXGLBi5VOdz9k00eGO7ehOQGLNk6IUWWWVhj8/b+7OW0mC789g==","signatures":[{"sig":"MEYCIQCyW2oUOf4IrkwT4Z4sgkgF3rMis8JiDIvHgbu05R7JewIhAMDAhcgc3B3qI3vP+m4FpGnudG6o5aSRbJkcn0RWtd1m","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf0viACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrgiw/9EE4Y/304R/1mnOY6kX3Cp1IhrQQ9mxIq9ZjndMOwNfGti0LC\r\nbyu9iLhZWRAuNNpCFhqZBHaSAHO8bVwlqhyXpyO9DplPYNu4h0N2Jokv7A7y\r\n9Nyc6hsbh7iO1Dg3gyRDYyk5uL9t5JTpkTZISZt+17zkY1Fkk6thNTopR6Kn\r\nEvAiZV1pIt/cBE4rJVX/aQMGSDX+/W8IO0mxFZ/tl/cGhAtV+psTgwIW/RVk\r\nXItVRnuzN609ZtF6s/o49vSmxpfNrPPE+UbCn614uZ4HkiCfp17D75d3Tqva\r\nA1pjdIRKD8LU3M8DgnOyx8dz06S6RxG4NuhGvzvfM2UQAdCKOfCIbKUOfmN4\r\n4gh53NaXN60WcCPKsNHrSDI6sRP3NOI4xEb2gHjBEGWdJJQmQXhN1OBqQZpj\r\ngqYWIOQs4BWOp/U0sFc+3nhH61usQFSvG8vLLjSm+lCUwB7u3f03lLAX8WCt\r\nPX0pioA+0Y3f8joM/cesaMQlfdirSW1JzXaPS0I8KbXEmdxWvFVF+7L2Ouc/\r\nOQ6kyBROJTP2EQ/Xwp83dKcqVHS+LWk4+LLxKUef1iSxTzzUCLgbob9Exwhh\r\nO/bhSA+qmuYU7uytaF692MXTxfLIPPWKnbJm3JNMJy4xmI7OsardZ5P8HrpP\r\nnv/0L/fUNbfoMAArYL6M0cPC10j4a9FOvmw=\r\n=xf/K\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"366ff2e65d97bee609f9f24404e56384839dd127","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.250+366ff2e65","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.250+366ff2e65","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.250_1669286882695_0.09017727238593976","host":"s3://npm-registry-packages"}},"4.0.0-canary.251":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.251","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.251","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"674b7999be8c95c7911e0b58e635425d363ff67d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.251.tgz","fileCount":61,"integrity":"sha512-LP0vWKY4/bSXdk7v7UQp0tLFqdJeDPao7MrWylYr7k5g5kWiVe9F16Vf14u+H2HbPEjh3b3QL6H7gWG3weHckg==","signatures":[{"sig":"MEYCIQDrlGB7VxVKAfWWTi0C4latmlp2a99bbXo0Nh26bbgzwQIhAPxfs4spO+Wboco18G8avKkWR8C3r+8lsRPQiNZ+fXMu","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf4uiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqo2RAAn20mJo4rB7jciet7GzjFsX3r9vO61ZFsV96OnOETzhDeSV9s\r\nj5G3bjS2KWu+bFeWPtVil0uFhRJASKAcmVBEmX1T4Fc18Iku6+CKFBNFfCJE\r\nW+IqgQ805xMUEIMNOtYFa9HuEqotjalFHTeLZE34kabw5HCeWjSkImaUDw49\r\nicsm3l++09vUoL66obRO7na428wUjVGsz28GxbCIUDbRzSv6qhmDVel0xtIW\r\nZC5P8Y6ZCmOVQr/DH2hZo5eyXgamiYg1NQZdqGMkeyrJbTsziqnOFA32CzMM\r\nFR8OufWhf5ZELNRPS68N8ohF8E1eJ+LBRi/4w6OxcuUB1n1v0q9bdve9/qhP\r\nvfRq3EVX1+h1gMW6S+8ZlgEjh4Bt+6h8tFoggOkL2TyqnKYqm76q9qzdTVrd\r\np4bZjHX26/9gTPj2yu6qAdRCHq/Yf2KEq5boll0oFep3wl+wjCOIFg/RzFgt\r\nQ7NfTQSDqA34b3E2qNajvx4JOSOdoB2KZKJ+x/l5Ai2He1MqomhOzyJz8sE+\r\n4C5Kx/ipv21e5yiE651xyur2D+1PBGNag4Hl/e4177Lxj8gY4juuurk+G2xO\r\nd5Rdw+jwZi6T1VfcLRfryWtQ8+UlYI3LMf5reBN76UeH8u77wJzdYUf8hIHd\r\nYCSe6sy4fNqVL1VW0kfxWgqLC9rh6se4HZ8=\r\n=K8/O\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"3d8807be033e0bf9106f3a62988686d4b10f98d2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.251+3d8807be0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.251+3d8807be0","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.251_1669303202009_0.5116848363766142","host":"s3://npm-registry-packages"}},"4.0.0-canary.252":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.252","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.252","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3fc4d00b1aff458e1ed3fc7ee230f66503771db7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.252.tgz","fileCount":61,"integrity":"sha512-TT0ChXvmY5x2yPBy6lZTU7JT9qljuVXw3NIsrujWEkPQwr4kDRpSVKkwfOywDS7t6SUAKynfy1+9+erXF1gdlw==","signatures":[{"sig":"MEUCIQCIamAlEYxQVzGuehGSRiMuNEWUYjduxFflYSjU5Lu2GQIgQU5T/GTBbsxvIveIkcQL3tur4VZ74byv0Nd7CgfMaaA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf5QDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr3XQ/+J0+ZtxNMhSPtmXVDHEvkLelI9AcmnwxXNSVlrCh50etHq2P8\r\nMX1DI/+yHEY4+vtzh0VCbYhQeYrkkwTE/8BOzwWo9edQ9vc+M1HFMdUAPxLM\r\nAzn0OIu2SMAD8QSMmekr4586RH7LKKJWVwM0kwInb1uZIfYHM1owbvkMd+uX\r\nUDDuZDMGI6h3cmP2DpBMmAsWPRcpWL+xNQ3JBVXOk4Htd6INvJ//EIMacbs9\r\nwX3qrqaKFp1a64iHgoi8Fr0eakjyQeUJTDyJhMSNaSt46JCep+vUu7uNC7RX\r\npEc8ADwPDFstUQ8GvCqUN5hdn76FwgXU1g+iKDIvCtvxJNyuKRc75MIEk6eX\r\ndWwWLakYe8UUQFSsABTJBNPuFyIPaD3IMbUkIl1crOo1Q87vJyTBgv4BTja3\r\nBG8/VSBxymdvu1Pi7XtYKlQSV6OmP+eE7sK+uOSxJ17nsJo4BweQiP6+Zh4g\r\nDkdXy+10UHujZMT+IwfO1TBjzB8MHOlQIR3Zn3zl8wj9zlgr8h9LPNJ/jwyp\r\nCjvOaPkanmNb8wz/IelIcgNlCJVPjxG/fqZYtV/vmk/8r3P783Teu6HDPSrt\r\n5gKvtf9m7wO68iPRpAp7n8adzOhZgnG56uSf+kRyUEh3tjeBwJ1ipHEcruTS\r\n1gCvf2sHYf/Poq/T++A3gr81hfe6fQ7cRM4=\r\n=8ee/\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"afea5cf7fa9e4377a7a865bba797f7ce4bd74371","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.252+afea5cf7f","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.252+afea5cf7f","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.252_1669305347118_0.04733361127457747","host":"s3://npm-registry-packages"}},"4.0.0-canary.253":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.253","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.253","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2b56bc139ef8235cccf355ac2468cc2068525557","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.253.tgz","fileCount":61,"integrity":"sha512-adMbUkMZckS7MhV50pg6sN1Audyvh8d//QzpC72/Dk8z/baFd0qNrMEYoJrhBh8inaXG23gRee3RUECtFX12lw==","signatures":[{"sig":"MEYCIQD6YiJIa7MCtrc/0C6375VIjA4AhsHNj063JhzDhKkCvAIhAOXC95cxBHFKFmWuGV74eEnE/jA7p6++aZBtHnxS+8uf","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf5aUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmreNw//clxgSdv+yF1zL1mbHdSliMA1KhktBm6xadM6j1RZirmTD40R\r\nmoK/ldPESOBIWonwDcSnq01TQbIYdBZGVH8Y17vMGUa0SoWl+QrEwxpB/HJ5\r\nzkav3c95WewFj0SqbSVjlHK+skVxho48vgbMaG0Gvvm/o/PUJfHRUv4yVdrQ\r\nzkxjUp4PqsY4VN8wB1IOe92CYPKTTRcvR+/TZQ2gARQKOuVQvYPU2IvfMEba\r\nD72hyaqQozutW9dzYepVaZ9UgogcopQ4IwL6mQUOKwwTJjKA3fQQTdTtj+xd\r\nRzkfbH1X7Nq6iM3p/yEHlhjXEsvtXMSczEjoL5Z6gMlWCCFCf+nAUlg+Cn2g\r\nIbHVXlQ/0p5g9ihn2f0YFfGJgFc1K2MCHRRVG7JodsZw7sgn/TCuTeC3noy7\r\n9aJPHmtV6AhgeWB4GOX5bZg6S5QgbxB/AWKxM9c1VjTaJqRPYd0UgO9wVepP\r\neZ2e/7VTLHwy+xlxZeu/cMLh1hO6zpjzRRfoFf9slhkEwCSmsDpkQx9w5oiw\r\nT88oUERF1eycViYaav9uNZowDZ5Lv3vuCrUYBqdlBkcJCNO2Gx/iid868oIr\r\nDCugQMMYcHxGty9Ups7+pIJ4I6+4ZOfFiuDyC/NwJSoMypSdJVNcjY18IYz3\r\n9fEaQQmKap+PEL92QMVcV/xcxrjdIpPTDmg=\r\n=ywwo\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6543352b7162b7f18228aecf17495d2c96d24e09","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.253+6543352b7","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.253+6543352b7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.253_1669306004383_0.15418054984881646","host":"s3://npm-registry-packages"}},"4.0.0-canary.256":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.256","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.256","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5fa3d207f40ba563392c81d64242a2d08c32418e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.256.tgz","fileCount":61,"integrity":"sha512-lXivmgCSDJZoq+1lBxoHtmoo5gX7b8X55J58sJ0HbY76D3leqTcWe2b0uMUIFU0MJ9B/OMyPIO1bUuiZv1dfbA==","signatures":[{"sig":"MEUCIQCuGQVQ8I8HYTkLrth90tzO+kVUqAbvIWtWAM3eJXSU8gIgHk5nyUubcQxXcMRIcofBr7joZHz4HboG2SNqXPoxr2o=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf7DFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmol9A//caeniTU+ZlqMI67khbNMv8/zCK6wjsL7h90IFLGb2P9ik1gu\r\nqpgXk9wnjIt8YhqbKrCH26e7gpZu56/TkQZ21ZFoBfrKUvRjT1iNIYpx5ta0\r\n5KWxoxVB42sWcaOWZSewUFv2KVjy3KsgphpddUpDLkAcy8U3KJSOkj4J83P+\r\ngqe43ndABkAo7NsptlZfZHzMoNCsaiMmXLFKLeghldfM2ZLeWMxUCILD922Q\r\nWimgRBSxddcq/c85Bc3zyhjD/lBR6rIxQzGsNNoBjA4qPwoX4gVUKp+40Os3\r\nMdrLiJv52KmL2ujKOLTYVIO3Y+zzL4RY01CY4XN/o6M8/miX73JitATeHmnD\r\nxB75WbE54wDMlsJ25inT98Ri+aOgRt1ARgqvLhYkxtWzoYBhxj9LZ8MywnQx\r\nXRPtTSQrU0PFM0KHgJYRdB76mptZ7ACgtFqwQEHyPG88AEwEjRStdjBvXahW\r\nnVrJx4YFSKbCUyU5DnOlDjxDpAnPV/85ZgkdHyTiUxHqPg5CdLaCE1vvMKLp\r\nhy2Pg9NOSP4aSy0XkHH1/tD1/r+i7d8R2QKtck8VEs6HA7sU3C+SIXlj7NEp\r\nYBy7i8/Ess2zlNX0bzFoAvicjXz0QVnfQwGEuOn8u2bAgRmdE6yleSkEGfUx\r\nKsDZ4hAq1HsxigzM1bA7hLawIzeBRzLcEZQ=\r\n=d8Kv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"42d9754e5c4686422f9bf85676084cc5cee8752a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.256+42d9754e5","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.256+42d9754e5","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.256_1669312709522_0.8942739869271719","host":"s3://npm-registry-packages"}},"4.0.0-canary.257":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.257","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.257","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3c962e51ed4012c54fe11bc39a2592f861ff0aed","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.257.tgz","fileCount":61,"integrity":"sha512-15yrEGfUp6WY4EEiHkYkDfS5qOCc9x/x//GZAL1Vsm+QS2DY8VdyghH40fiYG5WQy4V+vMG/VlYFJ/TJz4U7WA==","signatures":[{"sig":"MEYCIQDx3oCvUxccWYvtKwUfsqESEYdDXmtx4P0hyuD8syBUagIhAKLmkQGkNASDCinGOUINCwH/OGvKLl9gkWkxjLz8SfNL","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf98DACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqeUA//Wq2XPLxcj54q9ibDAIsB3cJhTYF23Ki/7CnvsTM/FfX2aS1F\r\nOsy9nrUzSiM8dBBzsHazsT5cVbpjH+s9xKJAXuY94QsfPYPNn/UTcOPj3NbN\r\nOrH97KPhn0LBkxpo9CzqvYW8ZSGXT3qHCtNx/P3rszSMrJfnjjyvJh2usRN1\r\nKPAm/K1T0G8+oYLi2I6L6rxiJWJ4Oi+6peZqljvDmZRim0+b6lHmTX44KdKW\r\nifwotJCNpbRgLLjnYyBYZ2+Wa/l7b+HUX5C4fjny/MgOxt/Vjsrubb2vpKvO\r\ncJCWuSq6LqmEt8bTHBlHFRosMDfuYeSl9nNm+GQLcG2NcOeUGffgf1eCL4/t\r\n5zriRK6XN7UfKVgEKBRuQOw4XYwL+m1YbThBRRTXh2xKJ0jLXw9Zhv1yKTnv\r\nwHLbmPxsp1eCfPzcmvimB5jhKouTZyb3iCh0HIR+RUZfEn420mOQQMmHaLbF\r\nvnqbrGABru/8+jYekNZf3lKTlgEPjDZGvWEaU/JwM9f/7MijiSnlEXGSzdqj\r\nVwi20eEevw9CNZcG8kUutIVJxhju/dctfuh6YjWt2iSigWnQ1bjYwsPo7hoO\r\nz/ydNEJaougvnbf9oONQMVrmaNiwi/F8eLZx91wJGuZyA3bkmniVApiTAiWE\r\n2r3QO8c0UYkJaAXCTNUcBygmxztirccj/mQ=\r\n=A0Ak\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d20729b709d800fa472c60915e95fe5b862977f6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.257+d20729b70","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.257+d20729b70","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.257_1669324547615_0.5633911738699939","host":"s3://npm-registry-packages"}},"4.0.0-canary.258":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.258","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.258","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"27d147edccc35fa87de65f68511e8cacc703c2cc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.258.tgz","fileCount":61,"integrity":"sha512-7eKmDw/blDrifglR1qmGWMV5VDTIV9QGmUkP+PZXjzMJQ9/td71exWdorBFD3ptYb+elS5WmwQcnyRw9mIy9VA==","signatures":[{"sig":"MEUCICzZCd9CH2QSN0UpTMUNUb0WeIs0Q7dkPE6yOdWZOP/PAiEAgINwgk6+waUiJKpA0txy5BsNKHl78bn00wONLfqAQmo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjgVZ7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrJ3g/9ELjWpYQp0lkiXNozFIEvlSSnb2kzjJq/jrfe8CRzBRPfxusW\r\n4U62LO4kmehPGCGVZwzV5297lbKLeDgd183GghvDQk5Go4r07+o+/4+WZ762\r\nol92rsioARkv8Eha8hpIrRiMiXsmpQ/rtbV5HldHuCSBspr8xjvKKvqyNr1W\r\nR5i3E6dbq0kdG67AbrdvpkDd1DMrVdL9M7i3JA5yXo/mNCvLWeHUBysuYj8a\r\n3eIvko2+YkwnfEZWPE4VEXOjr+HW64JXDyzbMvplQze+D2DRIymbK2HvuhXJ\r\nW3r28LIBMnH308VQ8gHU6mt5dxSSTVGyOkRCmcYTBx6PV+8M5iGseJa3khHp\r\nOOiiFDE2nBAlXRa7jubksy1+KAoSMtkcWSt8ESt+jBMLt+VW5BBI6bgaa7sk\r\n6XGjq2Ib7bpqfHdEXGa/GLpN7WAJy8JJQEnTovONZTEnEKI7eq6zZkUvlXz6\r\nj+RJefiNJkCu9e+b0yXp1WnAf+WLaY6ROg3nOiXA2QtJFKqx4ZYrwdJ1WTx0\r\noxnPbzvlzrwlGLsuBALX3Hq98Ezn0Wd/lCWxqvRekCxR8TM3IHw3qQ/7sK26\r\n0fm1I6g61ClDzHjmXjM7KB6TOtEEg7EbpRQYePrepbz5RC+WCmyWluF/jD0/\r\n9JgC9nexcR4lPjoOep6tpHZQqWBhAfO993o=\r\n=aiPD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"35737636a871f6e77db725907f335136cb1c6f06","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.258+35737636a","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.258+35737636a","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.258_1669420667056_0.12212477164314084","host":"s3://npm-registry-packages"}},"4.0.0-canary.261":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.261","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.261","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ec22cdce8c457648bd62862701605c094e73a555","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.261.tgz","fileCount":61,"integrity":"sha512-TOaOuMXSySkfo+sUy74Clvv8bEv5eRpNYYumiShPw56HvJ+YPJFXzrs1vciJ2B+zhsw/MR+0J7RidV3dz1GOzQ==","signatures":[{"sig":"MEQCIBD7wvYdWuV3NzFPqVDbNHM8VlKCeHfDk78xwjGYK5UsAiBn69PDc649vlpgs0QAjpYSoeDEoIvQSS2aXlFAgsoO+Q==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":236621,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhOseACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpLBw//Ul3A8IG7hUQep/OMV2fTNbmqt4Q16IXbklkY7UweFqWfkJPT\r\nW47TXH/h3A4mg5sj45J7st+P53HaNLxliXGJ+isEnKMVDhnh9/4POsYKEJxR\r\nHunXPnLy6VCI4nHv+cssM/Nrz5w9aYyv+EMcckbBUwXqcqvM0xPmvybcqEI5\r\nFoVJRyeJvOVqGWTVL4juPZBQtZW7ml91prZTtPf9guDmpeagfg4JO5E+dYRN\r\np9ViINkyz+FW2srpBt1GxEDTVQWV4DC1DYLD95koytuvss78vQPckoH+n4t9\r\nPaU++ZN6mzjR9NET7kI6xyFUQ2q9OU3pOnOUJIUOSeayBgXqb2c2KbjnP+ua\r\nz8Dd/Nh41+MY8KhNpjb1cC/FaboXNJPU7tY4i49w9luhxoCyFk2nQOLu92+6\r\nIZKd4yA1GQitfT++qkH8Ifu5LG+rGil8LRGmorKlR7iCH1Or3g7P7fgzkEhv\r\n+FBiP9fbecOyLJUdTVMEM5eq7JlAymh1jvAGsvmoQXt8mkIK+0O7J/4ASQ+i\r\nnrRMIPyV+Tf1nJrV3DOYTzr/vo6StZpa3iesRqzO5O+PPQqVKS61MgRMQu2M\r\n9uSEitsHXRnE36F9YVPHZryhNKzkALIvQpWfVNXjru1r2ytb9rZigahAGeo+\r\nDBqycQQhRpQfm+ofyl8t87k2LT9ZDxqlKas=\r\n=kt46\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4d5cbdf745d7cff4ee6adc9fb70ea8811983b879","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.261+4d5cbdf74","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.261+4d5cbdf74","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.261_1669655326468_0.7388911751302771","host":"s3://npm-registry-packages"}},"4.0.0-canary.262":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.262","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.262","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bb33531009d3fe55d2147c76fe9f8ee24b50a645","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.262.tgz","fileCount":61,"integrity":"sha512-OnBPEHM8JOHfwUkti4CTltIjyKtv26J31aCX4cy4aprt3WcDy8NqxM9C3WrlwSxRx73I401O0R33QEGxn1wDTA==","signatures":[{"sig":"MEUCIQDWgLz78WwyhjCXnCMyz3YrA+ZXtP8aLMIDQDD2hTESOAIgYL7u6dvs2GMx/qqQfd1mkRYeFRm+pJW5EJD/FMZp53Y=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":237323,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhQQkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrhgQ/9HetQs/SYXsqT+TBtmfQKeqbt9ZBqsmHAFGHCjZ84k7leWGtq\r\n6GJi2z5fTUnfqgZs3QmCLoyL4oHMW0pmE/AkM+6lZ8OCXXx+sItLT2/sage9\r\nxDCBZz6cHd3BaBkVhnthTaX17/qZZiD0RE3yYzQGDWGuKiIV5oXi80mP+g06\r\nbSGSWy8ORu3LvFNuZamNNDzYOBoLP/GsxVo5t1Qlj+24u1g8uqWAAZZQswck\r\nwpaT316tQjSkA1c0dQ7j6MPmLTissSuxh3cKHVzxHIffhgs1We+VOIZ99iBG\r\nAMiHJqTiMRbbGMbcM2HlcGps04pUgRMgZzsalUA4sM+sCaA1ggs+Ol2sWO34\r\narIPNaIWmOlxumUV61QVwh04R26Yfp/SokB9nfSP9V0mE3dk639F4MeF/ZSJ\r\nVadFwmcUPHP9RrfDmzt+ky/T4BBH1n79FDXbuqJkI38HgtUJCUzvweFEAPPx\r\n+ROKKJzrUQDcZt2pmp0KXNMrPGimOogwR8+Mz1yX7eblHhq4c9MeJxsBkBGO\r\nfq27zZ4Izm4yHYb3WR8XimSAsuX6OsG2cvmYlfh5DD6qglPkyosleJmfvh77\r\nog4QeXUyAWN/Ar2XiN7EKUIG3Rc1AWJz1ywAlCdq/XFou/POXik/A23BjuwM\r\nFua+RQGR4wtu2CPNPQr2dGPYWMod4aRTh4k=\r\n=mdHp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"37ddc9d3a293daef2ac6ee4e62b692336908c50c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.262+37ddc9d3a","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.262+37ddc9d3a","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.262_1669661732046_0.5628003459241193","host":"s3://npm-registry-packages"}},"4.0.0-canary.264":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.264","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.264","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"86ce6f22875806b9de7758f66272ef2fbdd15dfd","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.264.tgz","fileCount":61,"integrity":"sha512-D8q+JA5RwQLSYB1g+BCn9ARH5Hsq3OE6hWK6WSs711P56AVt8sRMK8xD9stBTRUi7QKFdGct5WEkyMmxz1jIwg==","signatures":[{"sig":"MEYCIQCAyHb3DsVKhifdaPLak1rjdrKrsX25yjL/k/jyhsGfnwIhAMa+vzce5FmA80KoC83Kom/NRLybDiGuDTjqoPR3qkyc","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":237323,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhRbYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrHAw//U0LLJ7qGryKYmMlzYIPx+kUOjmLPUhpnwaw5NMatiHbDGWSO\r\nxQ2GBmy942tE4xzYE3MliNiDOxI9Ni5F4UCNyHu0ePQX0fBh33ei1swOIknO\r\nBjZJTmKkhvdjeP4MiS6/2nclbBNKxoK86NWMrQ+q44AmDH+wl2XI1DFcGRqm\r\nLQj4V4NOiHDZKPZ2xgKGMBJaDOcOo321N3mUZmUEFaUlq9q5KA1+Gr8uKSMO\r\nfU03pwQom06DVZbnU5nHeyEiUiARX24vzJlf2KIPchCQVjyc/LAVE/5No1c+\r\n7PArGRjD+cW7g1nXi5yzZubyg04x5V7AAr5VZ1QB4zOtrz7lRKSe8hMwgnuV\r\nLE6SIReD4Mso9EwEoTzfGfGnLakCIXX6o26Gm7+mGf/mTUU1MtcbvHADwo7q\r\nU+a1I+8WKp6t7vGX2jRFxZClcFFJKLw92fYfn7Ctx/I22757k4YVALA8stMS\r\nzft8yZ/lms42bHe5cAE0kTC9ZlIXxzefTTHbokGXCpQYoici7AvlRVkYzsvs\r\nkuCXfPccPxwUBCI18gPbieqfF5ckBGHSsWpWSHsuk/zn25g76OiHR1qVBtJc\r\nVauikIhI/3/2OQzN675q0gTRVC6g3AMMVbgjF2MMA9ILz+K4dOxJtrPXCBkj\r\nEJfWElcPja+Qok169D349VacGIoVpgcxYqI=\r\n=C+Rd\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"286dfe0dc88763f9e5a1c78f22f4ff8dcd20886b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.1"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.264+286dfe0dc","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.264+286dfe0dc","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.264_1669666520281_0.6911664598424039","host":"s3://npm-registry-packages"}},"4.0.0-canary.265":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.265","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.265","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"df2396ac8c62c0d96dfd89c234b51e8178f87edb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.265.tgz","fileCount":61,"integrity":"sha512-XIelyKcNUrlRCqpOhcrVPIfTAEsmF6Cc+QcISHHCFBBCa8Ugabx+34IUaK9QktD818KlrddBxAVreFyw5ofn0Q==","signatures":[{"sig":"MEUCIFCVJiKrhIwnmL/eNpfOy17OCMuESBQJXcBf/GWK+vouAiEAq6Y6oopIfTAXyhPVNzaWgJPXwT1U318Q8eE2imHQsnM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":237323,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhSiNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpZhg/+N01XGybFh8p3YoTzQlcT8CCvjxT7k/FpiW1/s4hqm4Z27xA6\r\nioZdxbeT9L0md7OcRgU685jdjNqEY1Tra7ykmqKZNjkPL9+4Rv5qt5lSY8u5\r\nQ0uP4ZyDQMnrSJkKnD4aTVU9AG89gugTjro9DLD67gTm1AjwRHnp9RBFh8oO\r\nEcRMSkddlpn59W4lTWvjT7NssxcAududMY44YHDrPFJvrKjHEHjk8w+RNmbP\r\nUne2mLvz6a8foQ9j2pEbeargazpOMhQ2ZJ47JuNZKH/JKicQ7Qcj4cWF6i/U\r\nzSbFlMbgY7gD3cG4jo/aapBNA/Lp7mlFgeoHrKlMs7FLrAS/xgVwZoPSVpTC\r\nv3UT0hmH/S7HvFd4uocmdJY8ChOUnN3ZdKpxpRTv+cMQDKaV5SFSFs/hbcPB\r\ntIqSGYF/OrDTTIwjwc+i31qYQ62wl4YVNBfkO+3o2LGXDjh6dW6H61brx83y\r\nJqPHhGQO8V6P4Np7sCY888h4XwbckzJavVBZsv72LCv4seIBx5vr00RiLeBO\r\ngEAPUMLDUE86XjXr/6x+1Y/CLeFn5PggJL/kmusdMGv3Mfe6pHbm/wAjO9JH\r\nLYjsfDcEfuWqsrMmEnUuQHgoVzqPpsttsoGxoIsAORzZ/oF4Jb6M7xUnRsIk\r\nlbMyelACXsjrR+fa5NpaQSmrTxGKy845zDE=\r\n=AFxA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c3634393c1f054ed4d7102de5cacceb13cbb953d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.265+c3634393c","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.265+c3634393c","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.265_1669671053208_0.6584988043966844","host":"s3://npm-registry-packages"}},"4.0.0-canary.266":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.266","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.266","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"45b98e0cfac63895c79fcdb85d6fbec0d8f7799f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.266.tgz","fileCount":61,"integrity":"sha512-FePXaHc+b9Sbm+2bAzXaLGBQ6r54yRqydLyKtVMae8UXmceoovvhJYDc1n5R114Xwgh1QYN9hQq1BdWvmwv5hg==","signatures":[{"sig":"MEQCICUUb/lA5vXKQHN0jbBQx1QpwoeOsIjwxcwLzvoQiHCIAiBYdxyZxQ9uR92hosHp5eZo9l4TSai/8tKeeWqiTZMLVQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":237323,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTJiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmol6Q/6A31pbcfcW8KP0S2Eot2sShhJYxdzFndBZjMaD9dkVrgQTKAn\r\nMRND1MDvCGUKyaVwMbG9oYWOtq3E5XZ485xWozemJSJZy4m+on3V6XoKq4sb\r\nkpOKLVAI9Vc+1FIHABfJGD2qt6bLBn97ehMMdguYW6/2fXwT/nNag93MWMtQ\r\nT2gQVdgLyLGx4+/vusOh8slN9B3rsgYzvsc/P4YnXXZPiD+BLzpvqTsQ+BCK\r\n7FXQZEcstSyC9iSgorHcEAN+O6IJ8R3YjNV+Um/4fDi0Si135qfhzvVlC9yT\r\n7wJWeuYQJPMkE6HvD6qapnTemaLDc4O+j5JfJK3dkB876iXPiY4ov1WQGHMG\r\nmA1hZm/qHMjzfNix5bfdXPlQvAFCOZwrgjpyXY6aOK02ZleegSRSqZGQWnyX\r\n3EIsZma2FyzYj6LI73GN0XOcdpgjhU5EBLsjXWkVCWlBa7eFIQ3HQJ+XgU5J\r\n9WpHu/CwedfGzcevKDNOjExUHoKj79UgVxiUpg9TMFoa9n/lGcw+ULCLcmtI\r\nnMofGJo4LCbYyO726ik/Xskra0VHLqSZXGUwZYfdytxf6Cd8qB/jzI/JAe4S\r\nXGTUdlFtAK/gEDG1BvhLwh8NsaH9oXATrGXWQcFxHKH1vY+7dAt2ezOeUzLM\r\nJ4w0C7z+iTDb4eu9leQP9qI4A9ojAy71NVo=\r\n=yhCI\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"56cd2495f92780c39c68b52d1a330874c12b3a5e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.266+56cd2495f","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.266+56cd2495f","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.266_1669673570393_0.1294338571820537","host":"s3://npm-registry-packages"}},"4.0.0-canary.267":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.267","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.267","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9ee6935c87b9c86bc6b47cdfc23b02862767d8f1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.267.tgz","fileCount":61,"integrity":"sha512-yrLDKiZc/qVUAjng+bfdkRGo9PHlUomDL8Jt8CBe5j3OfGHPLxL3EkT3gawzYs/SQrTZTaq4Zqy7+wHOstDPXA==","signatures":[{"sig":"MEUCIQCjnIATqIXsLR518s3LeRI5jJ0IFjuB4WrjWqRfCmxtvAIgZzXZR/0u/6iyvXzBMAtLzxMFdXkQIoAw6ma5pMXvR8I=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":237323,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTKyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqc6hAAjEjes5yRUd6pkITtEzdt7Rr3yJFPsVy5eJvzjaXjyqoKkyL1\r\n8ccc/GhBp+72dWoF1hMJ1FgXXVUSwv6ijs1YtVxDRA2GcpT4NvUcDUtKc+DB\r\n2j0VW8on1CHhUcwOP9z1MM314BIYz7eDgTFWd5jh9zmCS+bpn2Ss7tXj8rRy\r\nzA0ntlnnTvYrZx4In6sGxnCSwoz1FRGr/8jTL3EeakdpOmDsUELq+POtvnEJ\r\nAkcp0k2ZiFZA134W28SAH3c7J1HhZkI68MQe9JPcF0dvlRpfVbWJs2KMzmTK\r\nU4Ehifg2LiwZWcCmBJ+pHCfam+VpR3iNQvw1q7u9YQJS5ppaHE9gbXGFsTEb\r\nuriehwUO8u75QF7hQN5mTNJYGgyQ+UaEc1+kqt8LcjhM0y2xUbZr5CETaHNz\r\n8wDv2oeJFH8JlPuYQIwxZKpn267NT8Yk2H5yNomN0+CA0DPft8N9wqn1TaP9\r\nQDybkQkyR52G9cIpD871CcoZMSmClpYZrmzM70U/+9jE4Pld/466gmnySaGW\r\nzHol9oS1K3jeGeoa/5mEsFJ1fiQKZFNaq6oXrrgV73psx8VG8tCVcvbt15ON\r\nVT09Md12WEtaIeGRvFCPq+xVeGDYtF6Fd+8XSs0e550kVUcL5qUrP8MY8PuO\r\n5s8pyFVx7wObyU3mMgDakY8ZfhhxwyICyBA=\r\n=CriU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"82eb282fc07d1d6a8d0c7136f17b680a0c6d5597","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.267+82eb282fc","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.267+82eb282fc","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.267_1669673650402_0.5505577927055694","host":"s3://npm-registry-packages"}},"4.0.0-canary.268":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.268","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.268","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"56946ef0fd75fd7a1d2bad7287d324d90294d5f0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.268.tgz","fileCount":61,"integrity":"sha512-pslJAXmPlk8IeVkapHHc2A2yMLw1WmN4xS7ObwPMMMOtn8mQzi14ifvWtXh8UoA7+CDSArUdou7NGQEDvtHWSg==","signatures":[{"sig":"MEQCIFemQ4j6iLCtrcyhUGaDAzfsYM7JoepNwqczfHwzf2YkAiBtzod+76uiAfeGQo8YQDmfghNthl1Sf5AGgYoeXJuPpQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":237323,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTLSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpOUhAAmrMBtWy0+nXkw8xQ+0YWWBcm/RFK/ZNk+wc4G2AU+BFeUTQe\r\nrqCiytHe+itv9dSOxE5gb0KylC4LuHvjMBc1pVH5f/kMEO70KenIzLnANqST\r\nLtzoDW6EvIVrTnus4klYm9ZaDJrLrnf3kjEaswmlD9oqjsOhYsr39v4QxiiW\r\ndeVWpQToOhU+cNWjy2tBJ0FxYkQcZwpv2gL6tCl2XdgEzkMKbI0nYQdY+7G2\r\n0fBfhWBvpWy3xbGATg6azGdMPiRHZZnDuZSCCPv78dWvMtVLd6scXBAHW9I6\r\nMpqG3DtsifFnJr4OSw+fT6xHXyZCLMmBvHaFMD6DalApkngGnTMUENE+s6hx\r\nekTs+VNVehKMIhk2PsDGVemaGuWuQ10NTMOAMD3xZ6IbK7UIOaLHBUEqR3Gb\r\nGhn0GkNbRTjX6cgpltjfr5TMU433uXN00srQhToahUqqWt56EXOd4yiVy9KE\r\nM5ysBrtk6HHe9GcFC8acefseqIeiueC1+OPJSZwwibp5Dqp2R9Ce1vHcdMGs\r\nVJjGbCOXUGhDkxvSoLIWiVAunAhidhq97kjLQQBs/zserS8oT/BfAeuqMmic\r\nj3d811IpXJnYAHJg2cnuqTGZDpGe3YZdpt1233S4GBdFvWn9MD2xyhct6GeK\r\n07xqDRBxdL4yitomH9GNO/812qIXrSku/Kw=\r\n=mZZb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"83176fca7b13fa78063d1e05b3bad4dfb48c6d99","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.268+83176fca7","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.268+83176fca7","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.268_1669673682202_0.9791953363225534","host":"s3://npm-registry-packages"}},"4.0.0-canary.269":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.269","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.269","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"64d4b4f6ea3a357b96e8637db80ffafdecc15757","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.269.tgz","fileCount":61,"integrity":"sha512-OHdG9gPaRKMq8/m7/5uzsIbp3NucpH5JP1IuxnD0dqIA/TyWMnROiIRQYTw4PiMy4GFE4AGt/UI2p64GMfNr0A==","signatures":[{"sig":"MEYCIQDplaSH2mTq3tFdA26UeJ4sgNDIwi2cb6d57HXhRpmjFQIhAOL1neYzRk/BiVcYfuYB3fYSnzZuMPdSPg2tgMK1stsc","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":237323,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTLjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrrDQ//WvMRpayXyo7jFX2eDkuJd7IPbWFT+z9gACy2aPyeiK2I1hGJ\r\nqsyI5J5kTsp/xKNOw6VW7pFJqDpPumOaUU/W5vgy+1M8zY2E4XDZPc139DOU\r\ne+cEQwRcJnoeuJL104X+fYQviFCQ/kbL0kEIe+PVVpGi7TsQE6OtItsL2+Z3\r\nlMPA8xt1A6bw3Y+i9PLNoWtg75BkTUP86U3h3JUqTPPhlFPjAP01rRx1kvKl\r\nOMpm2IgbehUUDL3Vc6khSS7pnftbC/q1LBAQY13KgB2omkZeUBco4qy0LREK\r\nc40e1rNJ6K22SB9taXnT8DAB+8CxoW9qxhGqTM1GDn1oZ6OQ9ftLLegOzo/m\r\ncB6ZbGtdZXKQ0NfVP3TNREUSEcVVfMnkShxrqyrkFFbm2QXGtLio0XuVZdSN\r\ngfycmXMmYslVQnqneP+shCsCsJZZ7fBecbwGVTXxoaL2DmVQ13NtQadz/VVt\r\nxKYdqfhFsQxL7eP1vvaPkIn93wVaKloPSsJ6/lZzJwq7dMfBZjXfOVU5Ikca\r\nmV48IfWvCqiYUTucaWGlUzS4y6VOzo3sp+ffSsCAZrdcxpNF4enGN4BnCo81\r\nFfhW/G4VRWa6bEq0vCaV2/zIh4kc02e8FmEC+LF5n6JBYH8oHifrHiMtSNcd\r\nCJ7Lm5ySXEAqvZiM2EuE+iAG0Fj0fEWESUI=\r\n=6MYh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ad419b957f73558b0692d8ed0902f62343f9bb48","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.269+ad419b957","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.269+ad419b957","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.269_1669673698827_0.525935659886523","host":"s3://npm-registry-packages"}},"4.0.0-canary.278":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.278","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.278","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e57f5ccc793028cde9acecd4fe9692bab224645d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.278.tgz","fileCount":49,"integrity":"sha512-8XjOpiNR03U3JHzSsE/eggfz7T9RF1itg2/3HRTa66T6kmmHxuZNEXE2yb5R7NZ7kcfg/cAtFQpmYkOdnptvmQ==","signatures":[{"sig":"MEYCIQCsngTFeE7NM81l6XVUG2BNEI0/WGhXv3x4mGzxFutRCAIhANAswzBRXaaeEXfz/rd+75R1WOtuMSedmdT1oqpOm5We","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":225872,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh6znACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpTDw/+Pu6NfYJQwAVAZh/vIXItBq3LWf1L/eXHrN8yNSIkwyhkXhpn\r\nHjglxZ6bCWaNExnCSVdvqz7vLGmu5oD8ZrBz6/2cmCXHMkvK3N8c9Nbsm8xd\r\nBGgN+8vHfWnnFSRuJ7gbZPrMC5PWbRTMKe+gSPLkwM6nLCzfsw6YdSfYD8VW\r\nMJWZqYIpZG6wbQphUuto30nWwMQzy1pEOcihTVR6//7DoDmC9K2HberfrnWt\r\ncbvgZj1BGZkkgWD9FYM4tP765R9kOWCXcaDg1TlKaknrodGCUYt/qwjUcXKi\r\ntFdjZ1RC5cuuwdz7spHqej7KcVEJvCeZK4PdZz37TXuR33OHt1hSk5gFiT8g\r\nvXTGRCJ9Ui560wl9mu4k/QJSuttZe6l65PwxQo7iIfcfR2o/1BhP1i7n05EQ\r\ntD04XcEJFveB0+xpMbYX67qyB/ZOIA3G8TOWBzXHOdU4qwAKeJYQzxxTO7n5\r\ntr2Ga6k85uNb56mea6kMCQ4rqLnRXQf9bvNILjSwf0Q9c6bb+s7Y0OKp8FgT\r\nW7vpBM1+kr95B7lU99y9zwtfYhJ5yF1B0ShyZY7qvhy5jbM0+lt+/LrIYxmz\r\njza7g4Bjkp1zlopKZvB0awuQjQAUokR5pDz9Hx+A0kFIG6622b1WVeY9mDGJ\r\n22l1BF5MBrp0rGYzXWqtfA93TQKn5HM/JNk=\r\n=CwIu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f25125a4cb3dfca64c69bfd297d4594d33b32a77","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.278+f25125a4c","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.278+f25125a4c","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.278_1669836007381_0.12470309082850384","host":"s3://npm-registry-packages"}},"4.0.0-canary.279":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.279","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.279","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"afb10af2f932983aafcfa93faa9d6f2f8d36dd5c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.279.tgz","fileCount":49,"integrity":"sha512-P3cL04RrEZ/E/2nt1lIZj6y7z2wdf4Wfc6Dismr9eGCRsng7mSqBHK6oOjmdWdy6rCep25EoqT+rAwfrb4g2qw==","signatures":[{"sig":"MEYCIQCAkJ66IBOAFI34y+Mni6EKllqd0W1izIJHDWv3SD4I0AIhAKRU1sIevVR66wzqU6DQPBUNkHDE1BvuwUcauZPpVb9e","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":225872,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh9IVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr0bg//cnXDTEuXG7NJfO6vK3vhUduovSPeH9R35DTsK2mZyuTxjEkT\r\nPHXqkfqVnsRYmV2RXKZmHoa8eKNwBSvisKNHJDwGbgUuxXOfKf8/i555HD/0\r\nRqdowR2rdQ7s7WJzg3gUrwETb9Eh2lwoT/uO2kCNr4JqaniyVI/vt8ox3DmA\r\n0NRxlNRLAntAbMINa+w+GcUz1OHQ6sUdIPexNOkkRt2YyRgBB9Vb4UWPUimL\r\nFw38suo2kT96zS0Oy8V947b4Lzi530IXthxFbOpkr458iX1hbjDrj88cyKnn\r\n1tl/rv1Bur+XUuNArksw13Ciqs0PtpgUakv7JT8h3TpSin+mSFYcM3F7WEjU\r\n/IhQeCwrUQg8H3uggV8WVEyT/3HMlcb/GBUxXdT0eN5l0P1V1FrGsezCR0zz\r\nswu9WNUp6utmfjQLwty63F6xUmNMrX771LqwL0uA+HDbz71seZjYbzbL4CRs\r\nglxQ2KLLyKBV+dP67ouiHJV2zE1XboQpudqcgcov03sogBwMDcAyMWAAYs/k\r\nANr76rXTuB6x58U75FbirEa8myRN16HZvo8j3GH5pLoe1LynKcabkOmYf4Ys\r\nT6UNNVIK5WKxPLPSz+Puy36H3HYPb6TwIhpRenVqPv9b4UEzLih1kH1V9fQC\r\nuud/MWCsy/lfWi5Sbh8QZAHH9ZqYcKzKlsw=\r\n=iQcQ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e0cfed48e0d35046a93ace47d8c2f2c5c01a5764","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.279+e0cfed48e","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.279+e0cfed48e","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.279_1669845525433_0.21912597096647124","host":"s3://npm-registry-packages"}},"4.0.0-canary.280":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.280","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.280","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"92ed4629b46734c27e0425ed7ea4a38411d6a6c2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.280.tgz","fileCount":49,"integrity":"sha512-++BBtNjzwI1I3QoGdGW7/F4fv4aiMesSf6X4YTfxwCC21sXeDsgv4YEOgeGuBiSnI5rXYdm6zc6nROyQpJWHYA==","signatures":[{"sig":"MEUCIQCHr5Pr8xdHmUhZad1JkSWZejj4VuBpNDzZ8McgWtavhgIgPCwWy+tzIrttR/IInyPoT8cTmgwsHdTa3gaik5e15nA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":225872,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh+pmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoPLA/9GwC+N8TJBXpP7Sqb1gJRvBIXuZZVBVtoQy3HnbRcJArKFFiu\r\nad+Nw2ORMErsPTnS6PrtaSqxpy99RwEJg8rafxggOBiGaAO3zlUc+xQL7yA/\r\nB/POgWtJ/eaXKMHsrRRzsQAfOIn6iCyPv4mO2BjDZwlS+/lg8c9ZLrytd+w/\r\n0cRxG+ddK7bMRGFu5/clsaXgceGdvNQ5uQEeO+10xHBSFKuN0EMrWy/9FZpt\r\nCIMWe5+wifRdgTlIBqohkJhqDpha8ndmnB1OEgiEX6y4nvUuJi09r2Fb2sbs\r\n7juwjx1fJuOeJoXf/EpE0EmMNuvNFcuS4mPdgKp+a4tDvUoCaTTIxog/AY0Q\r\nyrpu/sLDGw6t+YxJ1Mwtp8v7UVsWFJkXvkABR4l8pZW0aaZLpWygFBG5rZFv\r\nzrupKRBjH6OSs2Eq33t73Rallolflr9vdB2uxEU9Pjmz2At46uw72H1GlORw\r\nAnQRWw7u4wK5iKyAlPG16jUPV05fMgyMkkyFbOUNtwa9KEJQjhtzRsOgv+u8\r\nF11YyQK6qzHhUL0DF7wBGSjn/xP7N75Ng+Ilo7ApLuk1I3hQscvvVIFv3OQe\r\n/ilD07uYzVTHaJVyYmhhrPW2HA4z7n4OOTWQBcIB8nvqvl9n8AuJIPuZZlDX\r\njjJFHjqUklBdTrSn9xap2kDoIoAXcGcXch0=\r\n=BiHa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"99c86332709f1b20c5dd7b9a5e5091a4dcdfd001","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"uuid":"9.0.0","core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","react":"17.0.2","firebase":"9.10.0","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/uuid":"8.3.4","@clerk/types":"2.21.0","@types/react":"17.0.50","firebase-admin":"10.3.0","@clerk/clerk-js":"3.17.0","@nhost/nhost-js":"1.4.10","@redwoodjs/auth":"^4.0.0-canary.280+99c863327","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@auth0/auth0-spa-js":"1.22.5","@azure/msal-browser":"2.30.0","@types/jsonwebtoken":"8.5.9","@clerk/clerk-sdk-node":"3.9.2","@nhost/hasura-auth-js":"1.4.1","@supabase/supabase-js":"1.35.7","@redwoodjs/cli-helpers":"^4.0.0-canary.280+99c863327","supertokens-auth-react":"0.26.5","@simplewebauthn/browser":"6.2.1","netlify-identity-widget":"1.9.2","@types/netlify-identity-widget":"1.9.3","@simplewebauthn/typescript-types":"6.2.1"},"peerDependencies":{"firebase-admin":"10.3.0","@magic-sdk/admin":"1.4.1","@clerk/clerk-react":"3.5.1","@okta/jwt-verifier":"2.6.0","@clerk/clerk-sdk-node":"3.9.2"},"peerDependenciesMeta":{"firebase-admin":{"optional":true},"@magic-sdk/admin":{"optional":true},"@clerk/clerk-react":{"optional":true},"@okta/jwt-verifier":{"optional":true},"@clerk/clerk-sdk-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.280_1669851750669_0.0013326798944324203","host":"s3://npm-registry-packages"}},"4.0.0-canary.304":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.304","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.304","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"252bfd6ff84289fe548f6ffbbff43e62800de988","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.304.tgz","fileCount":22,"integrity":"sha512-nReE7suH68ePr0Pz/fE1pjorTpcNCQzBHuazX7sFS4G9mcH8vB9ziRCbQ5/xm/Q70bh0XpTA8kx5rtxz9zIIQg==","signatures":[{"sig":"MEUCIEM2+Ck0te2NMVkoFRzjG4hRsT7pQRLs/ffIES1vUGfLAiEA51bii7S7GHH53qu4QHLWoSX3TlC+pSFMpJi2YWgVHqg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjj4neACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqKBA//Y6dpBaX1gEEgVsyE10aNlccNkT8qn5Il/nJeF2Xkrb+OxyHg\r\nYPq306EJLIIWdofhG9a7x2Pa4VdjJpkdTyBRj5g1COdUz3HcBgDL7ezQjflE\r\nZC7RrgdAQdFYKlPg2mbywrI1reDkCh5vg9XKRk+WVC5ph03s3AvFT2IS4Fwr\r\nUBIL6f799UBRU1PDK3mo0En4y+PfWnX86kniooPEvpq57OwmZGaMfTrhjnxb\r\nNBD2IcuRyXEmGbWRRdC4qn4xYA4ox/M9uD7E44f9HcbjK2iirRTlOfla+gHI\r\nP7t47/PT/qIQQBcf+0IezT7QPkYEjb6u4n5Wp8NQytP+3atCTMhbBMgEw00j\r\nV/IEJJqzFQaN2xU8zJJrboTA+kyOWBv4L6yV3DZzacC7GGad5p+3sDenDOq7\r\nLT8wVoJkXkr0VSbCMANnQOz6KB9PPhNT2H9olhmnYXQiVdo+ojxyHJyvoF19\r\nlgjP8dY+p+UqTJEWIPvntzYijall/X3y3iqqFOgxwH+pDaJB+nIQtMpLmxra\r\nyLsqNFkBCpb9HHKgFH79kj4Z2a7FA6pTrO2FE7Y69QMOgGfOG5cNZFHI4eMZ\r\nUtL0E90nWNw46mZVnr0o2ilcMXLApvndKulxwLlrfe2PJMbSMjueg3SF0kj9\r\nWKTLjp5FbXd9HtwHjV4Y2rt/FOSYJM4r3as=\r\n=Q3YB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a897cdf2c9bea1918e604be576e7288598bfc93f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.304+a897cdf2c","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.304_1670351326023_0.1576775579982037","host":"s3://npm-registry-packages"}},"4.0.0-canary.306":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.306","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.306","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c521063fc678caf9b92b5db44cfeb0bcad19ffd4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.306.tgz","fileCount":22,"integrity":"sha512-M5pBXqHcC+OW0IL2cCLHDYNxLQMqWhoVjwVhOsx1tzNe2Ry8ZGhYE6WTcE7nFtGmou/IL9W0ggq8K8uSqmgy+A==","signatures":[{"sig":"MEQCIDfc3Pa3vWbwILbP7A7JBJ9hxx1qKU1Fn+ThWSQLfPSYAiAPgi+HJz4ilom4JdIVbsEpVWvODi2p8bvvT9jk98W8wA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkCsvACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoATQ//VCGgShNLOM+qbAQ2EtnOYtCRMPELvvNzLKTpLMs7YFMQ42Te\r\nafo/Df7Jg0Lh5GQceYHxJdvthNp9yf57JuEHaQlJyFnmtegngMkKV/iRbCh4\r\nHtSr1Q4gOURVVJJ+seQeSUw4GH8qaOHYOmd/wSKux56P+Cyos6jix734dosr\r\nOeeiYef6sUI+2mCckaBjyTffaxOeZwZ8kiqdJZG5HtiXcs9Xm964DoorJsmW\r\nwGC2ZCTVBEd5DHGFoLaAWLDaQc+EVO5EGa1MQOK2IPXiFnH4qWeeDfPeuSA9\r\n/GU+GtfULPwrct0wuM4cbpbiaXvuflU3wEqN/N3lbM7KMgDUaBLar/X60lL0\r\nEMqnaDNL0A/TpvRBM7bFBjHZdxFSCiGCRzIAYKfJZchoWkR8CcUbRtRrt4j5\r\ntjJNXqQZ5Ub7LTL3TaWav/BW1/ScoByf6XY8psTykwfZxY/VcYZR1UbEeHX9\r\nS1aSLPZZnd2IRcZHwtHD4JM8rO9GRhacdkzjoXcRtxetCK9eHBcyN5nFb9UK\r\n/z7kYfhz+gOtU0G0dZyCnjzzK4sZ68WpzhepC0tOf1GdyRnWGZFH/6nCPzgc\r\n4FrOBSi9+24IuV5MKWwVPRNhV3U5zTiZ2a+1O+i5BS85YWltmqu3ut/xbzY0\r\nRgNeAWigN+q/jo4fb4dddXGdG2xSTSN6jcE=\r\n=vPGl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8dce180c0eee6b5e2847da8951d684dfa3a234f9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.306+8dce180c0","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.306_1670392623274_0.7386539369383855","host":"s3://npm-registry-packages"}},"4.0.0-canary.307":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.307","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.307","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"629f5c1aee42f6a4e1e58c3e0fa8f1b849b38aae","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.307.tgz","fileCount":22,"integrity":"sha512-JjSalSLchpbkZB4QVz1UmfD4N0lN0V+8N3/YzKEB5lxYUG2dNY+YLLW/rmnCr4TyERdKnn6RlXzUJIJK8gLPZg==","signatures":[{"sig":"MEYCIQCw6vabNKGtK8gpF0ZxsapaWRGdC2b2BFcnyzrhWcVT+QIhAM7iT43BV4iV+u8gnLpNTuARGjc03cD3sde72tZ3/D2J","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkDi7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqWiA/+L8nHiFd0rgdQcF9x+6KNgKr3f4oCAQTcuIKvF0Cl5yryv539\r\n17A9sbRjcARpQcSlNHfV2weuQHzMz02XN+0cHQltzAJGKmwdbhYhaQbu2crD\r\nOquwYjizVh2NP4nO4J/dn1l5LFSadP/wahv1KU50NtOvW7ZAiIdMRJ2r9vrZ\r\nde/Eev1fMdEvgYb0IZUO2jYHelziIvfzWXhCQ77CUhzKQR4/coGeT7hLlA8s\r\nAgc+Fwdjs6+Hc2nkziCQmTnsLR8XAAYaON0+oafxey2qc9PuXgb/tXLkYpgE\r\nwXc4g5J/YUNTfDDQb/+fC4ErsSeRQEWwEq8e4s4N4eCHX/AmJgR/Io3EUOO+\r\nXsziAu8vhafpjU6+YjHhTO0NuEEfkxwgjzry066wm9x/6tWhvZh5TX8hrFLY\r\n5I/ECEGdjoQb5rDl/dKq1AnnCgOafmeLN8Z3DmPXDsa98O9XDZQ7zRQKX3TF\r\nD053islvleShjYLfdcXo8DYoiI0lI3CRrmOj/V6pcmbHavQfNWKftSA/Jj5Y\r\neiCwdJBe2ShwgbteE2a2WgzN51dLQEHfv+B/7C3+NATcRNerlB0X88pTdbdu\r\nfeUtAxYvrISN/pG99JWr81tt+X8mAkggX7vbnduAMm+81K2Fs+pMZNxQmmWu\r\n7Ndd//HVcPMUy3Vea0WoUkhgv+Wut6XVxDE=\r\n=kvf4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aa2f6786324c3cfbaff5667c5f5d1ffa03b63e9a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.307+aa2f67863","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.307_1670396091538_0.7814593006736541","host":"s3://npm-registry-packages"}},"4.0.0-canary.308":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.308","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.308","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5f1ed70d5c445d545228737ee10ef7191dd0613f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.308.tgz","fileCount":22,"integrity":"sha512-f+XzhlkEIHjpolQ1WbYnqJeGVPJEBi32/4Ei0+APqOHWhmMbUmA7/thQP2WVutrRiRAm9fUVrs6bRXIQ7LG6Pg==","signatures":[{"sig":"MEQCIDnMmzPYT2WNPlO/IGxMqgS0RcFnmErbNWREbVtvB235AiAoonWScj1cM7KjdEfY/BM/q/KoYY/n4kMX6R1KM7dBvg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkGUjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpqgQ/9F5F33n0mVk9AfVUstHYqRrCU1VX/gnHlZdpyrpnNw/0sTJrU\r\nj113bpaJ9BJCiCyXIgWFUlOhhwuA7/C02Qms79VRDztAQNj6C08BZWo1K/We\r\njHjOKXGO5fatRUAbU0YUJOt/p8AG531YARzgEYp6VXC851vt8DQDPgdGjy+1\r\n/SfFsZvh3BE6SQYAxepggRpTf3R410Bdb1GNn4nWSdEvdYAd9s2zCmfmC6yN\r\nN8L/UYuYnyib+TNtB9NgZdxF+8phYmyTqzNBgYNNsXj1LfL8CYt4nLWGC9xm\r\neefsCZVSxXnqWrz/lhXrfPejgaGSc7lk28+8RJOx9HSM9kvXBOt67k/7H/O7\r\njVbQRFlBMXZLn5S5/eUhX9rsltEsnKpzNmOEVx3J3n/1HFtWzHPJXoRtBW3i\r\nOmeLi4toaFUZ/oWvxyFkBp7fXPbNHefJiovwQ4zmRHP9o4g8EUWbI+Y1YVPN\r\nb6vzP6mV/4nZGsGNhOskqSfNUZ2crZRMdKAc9EhOAsca4acXKuIQkdAU2qX1\r\n3rtbRk/SUKkYSBByp7yBvKHt7OrRx+irXSLtI/nw08J/S2RVVrkTJuY54iVN\r\nbZ0/rTQ9MbsZrj0Bk7Z1KgXIwrhII/iDNgeyRrjT3Z9UykH3IKNMvi7H2QN5\r\nNKnlOZWyTYHPkuokF5tH11MOXssEahW220U=\r\n=u+HW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b7aa70a1948a57e42c83511399c64eef82a0ff62","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.308+b7aa70a19","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.308_1670407458804_0.4989645856045164","host":"s3://npm-registry-packages"}},"4.0.0-canary.309":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.309","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.309","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c16bf6549734799b33061ca23dc9050e49238d6c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.309.tgz","fileCount":22,"integrity":"sha512-/XWHZ0QRiXCckicZUexegpD1V6aQdS9XTF1iX07OAuiNKpu0YVLbLMP1jawJFVCbGyZV+4cQUW73lJawAUYTgA==","signatures":[{"sig":"MEYCIQDD6hbwy7Jyi3HG41VSBp7s2K9gqXu3X8dMt/rfWSNHXgIhAPW2DoRu3qBQLOm0ESNKHO0kKhGBE9qVzLhyJemi+exT","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkJ9KACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq0bA//djF3DYKR8U4Af1WTTfEQ//8sE8ePaPSfD+vmjz2to6zCp24q\r\nsVUyFN7kTZerV4IUgQCU5GNxCVqcFTUUvLv6OC2UrLWVvUx2s7oxNMYXPLP8\r\nWRIvQGKeJg0i8gsmSxt3UpnALWndjQRLhrq6t/dIqJk40xkwIwvmcm8lBheb\r\num/R3ZxGMx1UmjDm+yrbrMh3Fbvz/itCRNHF3NTRlcPn6MpaPjv+6BpEWyzv\r\nJO2FKcjpU82HYV0Z4lVO8FwjcZHxrvUVXqaYOZ8c5Rrg5RLkLfhJzkgDMkpT\r\nqU+O1jqTzoOoPfbjuMT2Xtg1QXEq0EOSkvXOiMxlvuhc7kFv20t7eneeDapD\r\n7v+61rHYiiTGSiZhwb522skfF7ITwZCqp0W4YAJXBF0u4iRKgcr4jPbox9fj\r\nmJnx7qZE7+2IWgV/eI71Ic5hMZmkCQmEfO2R7Cz08bvxIj4B74EDW704bx50\r\nwgCnyg3DvthpV25p19SITRpR4ASi3we3SznB6N+T2IUUnQRRphd/MRU4Jyai\r\nVgQlXInXm0ppO1++MwiH6bLN2YmT45EtTtVUCQaC2PwugOQlO/f8GuHY/PI/\r\nWJoETXSv5ynIEPReFBxIrGyLc/Vc0ExZLwqA+zdZ3UfEpEyjRMzVaEJBeqdX\r\n2W6A0FRVRiXBmy8V9WKF1Ir6+EL19d+7yvM=\r\n=hc4f\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ea5e9bc23ce5d4f8f5c1d68774adaba20b899aee","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.309+ea5e9bc23","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.309_1670422346220_0.9924765751991835","host":"s3://npm-registry-packages"}},"4.0.0-canary.310":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.310","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.310","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b9d7b3613e1adeec951a22c6081cfda9a67d0a94","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.310.tgz","fileCount":22,"integrity":"sha512-5PWdR2DB/XrJ3A8nPv0h7Je8AvXhLS00RaoYaw3AID277x0G5qqw5YOXcZfgz/5vjIHw9L2ecT9V5+f1P0RoHg==","signatures":[{"sig":"MEYCIQDBKur7b1RApTlXgaj6Z4wEaNia/e+keITzhZGWTgtiEQIhAIw+XFakcR3cK7hqSO5Z+EDwRI2TdRSRgu2d878wismk","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkOtJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo3lw//QSxalp0qu4WXOnOc6W6bIHIc3KO9AUaoqn3Dpew45Bhcpumc\r\ngIfNQG/3wI6x+MIHDZqWfxfyR6BoqaH16z3n4frHAusyXbnG4SdDQrA9Xf7v\r\nyWiI1aOMsjVgLiMdqJTRZKRmz01B4T4sEsm8afotyGKi3QIDTZpDNtWUPm6E\r\njjzPYuxT2q4TAjNWeYKEuhtCGeyk9fwCrZ4CF496QUBsiIShpduwpTZUm292\r\n86U/zXlxJs0G3ysIGyoG8Of5gJ0L96d5oqRSsMGf8UQd0zvPS49Hycg1SuMe\r\n3eAq0GFa9qV/eeL4ljLF0hqb+Ae+2C5uKeepyJI5OkcUfCOBkD1Vt5lI2dLO\r\nMAqHHNVkU/3YkLTvl8q3PqNENpQdG8OkCRstaJO12+SSkJz5ktMxcsxChUeF\r\n8nuYs6NfPJoTr/AjotabnHA5dKejRt49br4Sqfv00OfRt4TyQYEW2uA+FVZa\r\nLHs+rGo8aYUBSNK3qJNuAgcJOr5dhb8a/18oLvw6WGf4QQGBASVc3gCrPgYa\r\naTKuluSH3vCpuqRMwOg0dir3x6rbPnkvTKHBAWyF7dnB2RXoPCLsmftgxM6a\r\n2WT0TdxKREEJGGPcbJBzM8vcqjlwYmZtrAIl0rTkdlyIdthfK/f/7SvB6FwU\r\nw/SoYeLtadzhvzLh0tCXOvlnRzack+cTwlg=\r\n=s3yS\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c273a476ac687d8cd1bd71d90c377893330a8f74","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.310+c273a476a","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.310_1670441801010_0.30914803140139524","host":"s3://npm-registry-packages"}},"4.0.0-canary.311":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.311","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.311","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"512cc5796365ef8e93fcdd7ce57a40061a834fc5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.311.tgz","fileCount":22,"integrity":"sha512-yBGXNrJu5+GNhepwFB90ESkJlhAPBzwMD8hSFUGtP4mmBjWQ6f75sahK1PVdljQaAjNt/9PsKYX7wmpo8BWs4g==","signatures":[{"sig":"MEUCIQCInJ0ylhVQfO3MWpZjVBTt9/RQW6yZe48J8aRfbWRAfgIgX8yV+rQ7+FFr/ZgmlVtZNp20xP28zjDlnf8T8rkNu8s=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkO9+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrifQ/9GjCPinYO17UkDeMwMMvZ9H7CmOhFyLYSctjhjBFm2hMI3KjW\r\neAJKVVYoKZ1s8Pxghy1hU2qGW2fJkS1fj5yoKFxKK88NWgAnLZvyoxpkiTwz\r\n7PQxodp2Xvp/LLBr/ruNKF3L5AbHcMBDu43AZ5cW1tP4xZyinaRgp/kEUTEL\r\n29kGS/SAAau0tDWbs1QhwvPzewD/1cNs2Gce6chlyPpfTsYYUiVa1QVM5h1m\r\n7tqYprWhuV1Vi6cXVxAEeV90B94PdVaxze/y7dmhuSgOC1COmUryLb2pFDdk\r\nuy0M6vWx7xIS1188r6mjwrIShRtvWhtUiTcLMzr8h4jMlApA+kZSSsB7hs5F\r\nHqRBGTbEvjpufMT5O2K7vqzzT0B67VCycCF6hJZnyNiekcgi9ivoV+ilXKAS\r\nUDlabmhCtKWhMwA16CoVVY42VM/Yb2nD8TulNS22p5iX3zuDQHswgiE1n+x4\r\nml6E07YWH2T56arU2w9YGX9sJ9AX0XPpT6IQ0ihqsTmrPIH5Vs9RzCikvQqk\r\ne34lAc1XiwBQv8gaeBH93rBslM0Mu4vPi+TmUVfF/XvINQTBQnlDWAhh9hxd\r\nfoYhBZkBwA+yTDzJmbtnvOI8qcCtvw3TWpRXqUDpMBqtEb+DgidnH1AGJL9k\r\naDNmSGt0vw7+gY5w9huMY5xSZGELL66Q3+I=\r\n=CU93\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b61d5c4b388ed33e9853e07b119f081dddf690ff","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.311+b61d5c4b3","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.311_1670442878175_0.4403830092820338","host":"s3://npm-registry-packages"}},"4.0.0-canary.312":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.312","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.312","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3f6a3449a8f53ccf0f2b1a325758971d64c2c4aa","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.312.tgz","fileCount":22,"integrity":"sha512-dhE4HvxMDJDD9iobbQ6pVVx6tR5c83svZcbWtLjb4JhDwDNteJqM3KDPu2PSWYiYEoa3WQl/yzhYIHWQYPi3IQ==","signatures":[{"sig":"MEUCID2jd48EdbFRblp9vvzPucBlRMbePA4Z99WXg1yCkwPoAiEAljqBgov+Y0hOW1IF3HRTJRl7U5KYAon5LD9vtT/3Kcw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkPCpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqRbg/9EOdIMwquq1FM/hskneEJtNHpZfdliw45vqYbO7OI5huPurdT\r\nYW28EWud0r5nww3LxYZuscV1eVSan0wHhKY3Ov7oXdqwtw2Pw3kf/WQbKzNh\r\nT+l7WMtYKv3dulqhuzgpN6i1MkFxbqYt+Vu05yjZaaJoxxUnWyR1Nf0T+O5j\r\nE6HBhVHOJ02ywJt2tPN8jTh5yYZLOT/Ps+Xoi6PdX+nB8trxvDlwzkegqMBx\r\ngFre71L2qXKlngllqQbnETkIbOxWVzarhL2zKv9NlbisN2mMjGSq9mUkaRbO\r\nUE5ClmNufkQJGk8NPsrozqfMcmS8r/vBZCBbkMr1hSaWBYH/awU5OuA+J/Xy\r\nBgixFRQUUjtYFbybOVBU9amnVM7PdZvGWDxoS/LXa6bUc0v0B71B36VCFmJz\r\npHc9bXmVxx9ET/aH5qvEZSmpfgi3vYfxtwkjguE/V1nyPq8pE7/dS7CJ9Vd0\r\n1uCte7TXq/Quy/jkBb5zdW9Wo5/+mtnOlR1c9lnRgthNCSqcwMJJHTJ2ekFd\r\n0LdEvk2TrtSAY8UYtaMujQFh7WAtPWyYm+8FP2ksuMlvyl4TDyRq9CSLmy/l\r\n0UhJ1HjQTCIuJ1gli0RyBZnaCTWv/VyQfQ/axHrnjSQn9uUpuINQ8jN3KQeZ\r\ntAV6Fe53NFj4i4uARHTqQ8ZWVRFnHOfNydY=\r\n=cm/F\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f6a6e640df9f6ae8321253fe8975c1887b1dc260","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.312+f6a6e640d","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.312_1670443177085_0.026693473753874652","host":"s3://npm-registry-packages"}},"4.0.0-canary.313":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.313","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.313","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"35df2c0872b0321f00991c63f8171feb799740b3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.313.tgz","fileCount":22,"integrity":"sha512-7oWSt+jfIyP3QF2+HA6+XVOiIaITD8qifV+APXG/5j6mryxHrakU4JgJ1LAgANrvVjv8x2hfm7RagjMlsHJ/GQ==","signatures":[{"sig":"MEQCIBEnfiZYGrzH5w+OeWDfkvNMOhpYrcKYsipyxal527suAiARBWBzQkvUsYPV4RnTxzQzutPh12Bbgn2CV6GisJJJQw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYWGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr+Ug/+MQodjUYL5wv/LOm8AEt2RSzKg/96bUufR/d4e49wB6JVFAwG\r\no5th/J6o7ZX+PIjeJtrnhkYxMkBYvBj6qYAyRCYLR86l4Ruhpym3r/eCfwFR\r\nkTqZYmN0XkHh9UByMyd1dZbKSVLRRZXpnd/bk5i1TIvT6K5M3bIzhUHq6fyd\r\nc8tEQLMzdzXyyvuo4rcN9E39DEcZMuKpaIDXjqjilfrBsisbeiqZuzP0ZAgA\r\nCW5dnspoSxFa+jXkYrU9NIAtFPiHJAy4pYhiXDXAYsu6YKt/RZdBEeuMXwY6\r\nBPhNwBM7GnUwXKLXbLzxxgcf+/EBERBXxx2ZTrSW8p5DhXfcApc7EWJO+Nw6\r\npM+ySSLn4E4yTCmzRVws9tmdk/ERgtAeSVvFj1fziLrdOWIyzHc97YFXCQFm\r\nDxICfDzafUyETZVX4id8dplRMs/Wpj/A4Et4lyy/T/kr642tiG3LBT/yoFgm\r\n0VzY05tXJx6HVt55QBgFILfmgtCOYXhpELSkfrRvVuC51639aTIBMasWldnm\r\nqHmU+UMMbvURp9yF8f+OD0D1gugBP5MGTPLnOyI1L+4bLyejCNLimrgKJH7z\r\npThwkCw4lNp5D4qxguEjSBl3NONWx5hm0M4OzzMIyUVF4uJk0Pt7qx0aus0G\r\nyeQNwbwgZ203zhAVbXK9HfGM8Tq9jRU2NW8=\r\n=5yA0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1fa8ffd96659c714684ceab1ec0b42e98d9c6dec","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.313+1fa8ffd96","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.313_1670481285838_0.9664434950894725","host":"s3://npm-registry-packages"}},"4.0.0-canary.315":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.315","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.315","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4b7ce4bdf8cface3fc7bf644652151c843b0cc17","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.315.tgz","fileCount":22,"integrity":"sha512-w+OG+12idoWfM2wzJk+lQ7iEiOZxGjBTixZ3qLvBlKTWwnsOikewkpHkKj0x5ikd2vnfVTtgciY7GaIFxgLdWg==","signatures":[{"sig":"MEQCIHJzl7+Xf0kMBvxpVzcfp+3awyYDM7RfQFYNY9KDZ6PeAiBmZdBxIlqfslf4u0/Km06DhyxkYmzs9wVoT8ud5BparA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYY/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpT6A//aSF3wShEN4KfZ46isV3sdigTPXrqZ2GCbCRNE9lRw/Z6BKry\r\nozblEYWGPl7IaCRV/mlEf3RuqTbilYNlnb1iL8v5sH9x2qJ+gpyQRphvqbIT\r\nSIEyrIXvSQLlUjJ+grXtQ0kLlYNrlrnBrOiqVmq8u9wYfCglAVzgb4JZ0jH2\r\nMkNxIsYL/uZ0PnnlAb9IQa74bfrC4R2d4wW8mJW0kJRU/o/u4ECcp/tqHP3B\r\nMr/iHjaHf1fxa1Rnp0aaSy0cP1SLFtM/GTVP16Hbfywv9LR1GIENIn2FN352\r\nm7SM4fa0Ey+hjSGb/8PjzUc1YDPXvFJFx27VxpL6LqZKqfgY/Sgab560d1Qq\r\nOMVEuK6CDr7rhMbjBAhzb/zs4y/1ZJSFFefPBP+d/gahx88ptOzbDvFC5HyN\r\nQoc6vCbUjwF/kQGIXGLMXRPO5Nzj5EPPuCvpwc2v5YEea8YRxbAY+tAMyZrx\r\nQIVk1EnmBZFXW3h8X1KYCWN0Ox2SaKLpXCklpDF/Sjw5iQJHbxBlAhux/dl9\r\nSol4NIb21OJaHnp8oTytuuu7q2abr5zKCyOkVRcF+wBlbFFx+0XK4Ieljq3a\r\nZa7tX1NuOeIps65ySvIWAtB7RfUP6ljB32EQ/tlF4qsIeBvxe0ivKKU0Gu/d\r\njikbHAQD8tCfbvU2exhCwrMAcJ5d6tCmwHw=\r\n=tCmB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"73a6075930789baa2d2affab1c7dc1eeaf711859","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.315+73a607593","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.315_1670481470907_0.3917601937680868","host":"s3://npm-registry-packages"}},"4.0.0-canary.314":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.314","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.314","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"be8b4c52333ee60861109678088ef5ed9f48b25a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.314.tgz","fileCount":22,"integrity":"sha512-TtfhoFvmgWV4VgpbsexZh157VJob6kVvIX3m6a5tAqSevrj3WA/TmfCwrATLhG0VS5u8IFtbBaeb4uVjGTCBaQ==","signatures":[{"sig":"MEUCID21HaONRZDCTUk0INlRSDGPWxoo5YwGQoXPhJdm1AfoAiEAp10sJrDF1ewJ3w53JIgDCvtFGwBVAjFUOnOTz5VvMRU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127799,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYZsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrUvg//VfOvdUsYBX0DOilODzkWwwzmsCBm3grf6E+zVhmumnTZAP4w\r\nCWpt0qASJYQ7ElN4UEciFSoYrBEuSBWo9a+E3csaGdmRxylGvsg0eESkKKtE\r\nI13U8+j4RNMYOtLdr49NFRUQHJmj7TNOc89gV12Beixj9tUgW4qQTn0+1kAU\r\nleCuaJ7v41hHAG3p7QIIYv+Jm6RzWGFbIyM/HyXJfFIsvpnwHctxH8R54J+h\r\na/xizZ3PECl5xnSD7QgL/5+22zCnN1/XPeQk3Ky5BC1yJbQI1PDRDWueRx8X\r\nAXpwprkikEDVyt5VU9Z8Shv3P9iaxFdXfVjlgghGALarGC/VOKBX3m5e+/0w\r\nL+gzAp70wxvwDdM0I4p1DOmi0qpb3ZTXQIL454sWzXWngjgB1y0rV8GjsCSn\r\nWIPeyru8fGiTBNLEdIS6H7fAnxUlt/RbIKBhw7laMdm+mghcnOHVjvuyCjrS\r\nFdxcyjh3BTer09Xm4ZGkAehpbyEoSfQGN12Bbq4jsfEGeOVqvvSB/3aEfcFk\r\n8fKx/wj+At6Gdt8ygp+AqVBeZHAJi6ceGWH3/RiOiFAIQ1T6Ggx4fOA/kOAC\r\nIC+UZPIagNYscA89sRU6SMf+b3jqYIDJJtVfQv/us0U49MEug1mfWPB22IcL\r\nOgaU8ac0gaEkQNvzKupOOezjh6UHpfFHRnQ=\r\n=hJMW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d5c219f2e8521aee03aa26e08225487d85f80106","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.314+d5c219f2e","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.314_1670481515744_0.2618253874243879","host":"s3://npm-registry-packages"}},"4.0.0-canary.316":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.316","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.316","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"86e72353f5a947dc9047042a56f5d76a390ae542","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.316.tgz","fileCount":22,"integrity":"sha512-+/ArGpjvIsnvoF3s1I/WqWDQxmBvR5KtEsMhRHEEtkvX20Fpn40h+rpjC+OuPfSsyrtZeBXDmvQ70x9FAeWTJg==","signatures":[{"sig":"MEUCIDQXazdL81ZP28zo6TuT6hwMahF+E636HCy2Dk39MpHUAiEAsJKnDfyPbnJQE0uQqW3zs60W6Px98/klSo6CYL5EChY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYaPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqavg/9EJp4uB3tZgVDY/NuxLJGhucnjx7a3VudW1rlu5C/K6Lv1fzq\r\nraqTsbgSuhkc/xkPsu2PeFKHIMIjI4qjW3DbWOUcxBkeK2bSqJU6lU0Rl0tf\r\nHvPFQCDZxqiyBo2+FR+/JV1e4ihDLIo+ahvrYeKBw3ba89G1iWIpMtVeqmzk\r\nu4U2QhGQSFb2TTZAVeJ3mMjL4lwNkwshXS96S6w0Zf0bbkAEsJhDnUmPuPlg\r\n4Ha+jlKzynTw0x7lTt8ezWMRXgS7pii00Khn9R7JaZKdsBb0zqwWFcugSRM3\r\nLVm0D52l70Rs4zPocU3ev5RWSTJOJq7TnHrxrhzbNBxSjbXpx02G1V3e83CP\r\nXa6y9ocutp4o7NEFHX1uOAV9GE7xX0ETyjMgl0WpJSg1RtV/OS9IUPaiInQw\r\nEBnWFGzOsTanXYNKRy4EfU2VkmVILubYmW95F1Y2t0W8oFlYJ2w9ymttwcHg\r\nUl6crTXqJdL7jFgO6MBqgiNE4Viu3rHcodm8bb0aYLJxTWRVbHzTF//UoJK9\r\nBZ0USjjDoa2VJpnKocOTMHxz3GZOx68MWpu6iSbKB0h/QzqLYBpzfMoROcv1\r\nrE/Z/Qqgw/pzqjQ/TeoUQefSfT9Xs96JnJJWqz9eZO5XRHJLgaeJm511jX9q\r\na6g7bJDrDDv1ihOfZSUrx1ZkHxlIwrfYW3c=\r\n=ymlE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e5a7643ee1e57f1d025622e9a3c23ee669952943","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.316+e5a7643ee","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.316_1670481551578_0.6167710079673003","host":"s3://npm-registry-packages"}},"4.0.0-canary.318":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.318","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.318","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e36ad7695784f863f5029d000d73fdfdf9d71fe2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.318.tgz","fileCount":22,"integrity":"sha512-gTPGqXVXy5t2v8bgdpIZzLjBBvjL7mNmdPMFskttqGG83F/1sgmDXaw8U0JcQyfrFci0VGGNBT5/8MQUwDS/2w==","signatures":[{"sig":"MEUCIHJkMXidu8qEWNhzOGV5u+dV608INegTu/OfWt2khOtYAiEA2W54kZ/tjP8fRAuwmJWVqGYXuyFb1fledozEbopILv8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkiEYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo3xQ/+Izj+lZ9r85DApwI6FDDa08lfH+L4+mm9YTuRBKWVGL9U/CsT\r\nMv9oUp9CB/41JMsnYm3xKDk9VZyFTFweOeco0q/7nXV1it23t5jXHXORL+/c\r\nrp8wm6QiGUsU8I0r83cY+RFJ1JBD7qmuNltyJaWm8sYsRxzTrBTVVuEyverz\r\n1hrFRTTuhH18cDogZz8qMNXnpp32VY2YW0ipQdQkTj7D9ZG7zr5U0ViDaZaL\r\n6sOFh7vxSmUBTnN/BbgsibN7K3ddkLSSnmpK0/GqRy4cEfaR1TycBar0mpBJ\r\nI91o8Zwz/OZZvhc0gmdEHd0pM0kP7LLq+/VxNzybZKRICzoI9X9TTATOxZH6\r\nXFS3CQFXHJdkFu2pl+vp4qYff1c+W32YiQAdjEmzVJ+N7RcIGrh25crEn769\r\nF94aLCBqR1qPGKWGePBf4NvwTFxe2aXW3TScq+/mwVQfjxuPc67wZNL8jMks\r\ntnC6SZ2T0Y/f4kuARR3qBMGVYcpaMb0twevgy6F7TDlgZ4XgDKRwQJ66dNbe\r\nx+RazboKZ+LSbcZOgf9PVmlCPU9JohUYjLLQ6TTnEi0Bs6esZXwxRNutZyZt\r\nH/T3AXxraoDuFmbhDSPub7moJwtlI5lmL4C28EHz5KBrJvQnLIWQD/L3YzTG\r\nTUIRF0VIWv+MfQ9biBE99j0UcDeF32B4W20=\r\n=tnak\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fc84893ccc7eaa5f87b39cd12ad49819fbcf9a37","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.318+fc84893cc","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.318_1670521112572_0.6760263420470689","host":"s3://npm-registry-packages"}},"4.0.0-canary.319":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.319","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.319","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cb868a038ba8ad1aa5b08ec4406dc7524a27ed06","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.319.tgz","fileCount":22,"integrity":"sha512-yuSP69gZPIF2BrdHyLRep9q1Ht/pNWRAR7ymt4nfrhbGtEJ2k9XwkhMsQ9cqOhEI0bOcxBiEZrsW08o8VvvuhQ==","signatures":[{"sig":"MEUCIQCjzla37CFFfhDgWUDm8EuDL5SgrXiJxqGVFCyKA8CNuQIgFkLyhITn11/A+sjt0zTguQbCKoP+zPhZSK6+7WJWgi0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkiyAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqkYw/5AXCu8rilO5ImvSWgEtDP9/qr3UVGQXFvAy5zaoYjdeD+VzBa\r\nXQrCJ+nfO3H1F7iARixtpK5c7bL+vobmNCDL8bYEfjWFocapWxft7ctLE6Ou\r\nBXeZDa6JVwT2x4Wno+8qsx7Z6h9WdRJ2cxVOud0GdmR/muexlpWc5wTBLYtB\r\nHCrLrdUiwdfwuJqgrrXkD+AkPedSYlKOqpcWfmxqPbRsTGF/bXOUAe8aNWVx\r\n2pmjC0ek7lve3F+6tGnhiXw5gGEEDcR/rophLlzuz0Pa6z3HwO9OJFOcYhpD\r\niFdIdKxIeyISdAJAGPfEO+NxuFV5EX8uQV2GM1/LL29DCrQi/nJl3I8bBCYz\r\ngXjEkRJdS6tIMVywjo3S9L8ixTdcxJWOxzqlt7ngNMJp6noo+i4k2H86V0gv\r\n7TH5pZgSP8gxZxVDosRqDwH1bRsMOVP04/UknCvDoKN9ivvU1HbTZ7URp32o\r\nTChf2nc6iit0+LzSjOn20OHvtzaTfww7cLZdfmKpZCytx9L8DiZi1RHhpu/T\r\ntF1J5x4L3FwpsFgdh9VnpVTtWHK3nOanRiU1ZwWVGF/rtu7+GgJknpXL4AC1\r\nFSdXXf8Ul1+U/ooZV91u75OgiT1c6g961pOaW/qB42jGiUouY+5k0K/eh6VV\r\nYkYU2em/Ubv1o4RGH2H8cMsNKndMzdqs+98=\r\n=pmS1\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"867569f2865df108af54dc645468b79d881ace78","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.319+867569f28","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.319_1670524032289_0.8665299433718237","host":"s3://npm-registry-packages"}},"4.0.0-canary.320":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.320","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.320","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"639bcff8d506b8b113f8dfafacfae31fd81738b0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.320.tgz","fileCount":22,"integrity":"sha512-M9NGaWrnbdtyi+NRDGnvwcCsYW7ntS4iM5s7qBsCm1YvLjl9rmVVWWnqbxChCF2y/ZRNKKtXQmE/hvl2Wi7cfA==","signatures":[{"sig":"MEYCIQDGd1WPwZ2dbuD+tr2vrKEG2Kg2cmSJVUr6CwsFROffrQIhANJFXcc+LXr1pIZuwVM9JQqXr3YNajMqoCA9cHmb69ID","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmY/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq8KxAAmbsRA4EK3MXehQrxR4h1Myq+ET4/JmQFuQAJ0VvJ7uORMkAo\r\neBaKJPsEg4zt2qTXkNNv+jEBIX39ZYFyeR0uHrXCM6T+EN2pDzvaBrauIEWt\r\nqlt4sFR4msCOe6qtlPVYJXPtZONQK0F+RuISq/tm97JvIyIlIyWeS06OsBN2\r\nHWUqrvcSRUM80823pOdGnzQ5R18kY4TXJpHH7QpB702xWFmjfVyCjtE7Kdu2\r\n7rMB4JCclL6AgWOTEbC/8wvamERz02xJ+PkGIvIoAJ2Q0bkyoNVQWNt7Oc3C\r\nPR6cR8EL6cQtGuCzbFYusrzL4bxoumUSMNZ7defMVIChu5d2+PgnxefzHUMK\r\nChp2HFL3UG2shTzRsiYHivP1virncEkkF7kUH1q+Uf2cciisDtmtHng5rM2x\r\npCvmadmPrhmcriZvsKqL/o+VRI0Jbliu9ugh1QmHRmOFJzFFuI98cW09DSrT\r\niKIkjdz2xLq9XbOUZSFeIgKcnw1fXq6EU9UWyToXKwKbRAmIBst7cXfXA2cJ\r\n5lQlbx4jXH4oKpPa8Y++qTxaNxzNKWWDDntgK0zgFnaPMmzSVnN6Csls+XWk\r\nVbFjq91hnoYxdB/zlGfij8BvDqwPKYW6S6IW//nuIbLCKl84XA77GpTik+RI\r\nVQucjgMzzZlTXl2ffBpJnIF7gKhmyeveoe4=\r\n=V4lt\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e26feec2abe33b3925c492970d1bceb2a2a22297","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.320+e26feec2a","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.320_1670538815230_0.9259389109845393","host":"s3://npm-registry-packages"}},"4.0.0-canary.322":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.322","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.322","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c11db998215c346c1851e508c22b715deeb6ba9f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.322.tgz","fileCount":22,"integrity":"sha512-ox8cbWwuhjPTDp/3SodDeZniElUFs+aDg+IwQMdXb6Tp3GKrdM/0EUMG2jIq0Mpr5JNB6gvW/OCYk9FtTYNE0A==","signatures":[{"sig":"MEQCIAO/G6XGTYMSRMsJuyo18zQb8qdcfZTn/JY4ncai48tNAiA3XeWLdYrTYB2xf7vLSU/G107lAjQDJjv7fpQ7FijW8A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmcNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrJNA/+MIEFwTiRUGdApK6tsq9lu0/cB5son6WBSESpjGnOXOsL8I2S\r\nmsxaZGJ1OqBnTXE5dJdhEIbPDEdSTErdljQweUGOTJLnWlcqQhyijAsE+zac\r\nLis1kKUeYlv7YQ4aBfA+zsJ7ROMXPROuF3Az2qNGkj5Q1ybNeAElUeHMNzkR\r\nRwu2aGAz0gURF6lmSg3WZa3L9dSeep57aPeffpJJ3h5KTWMCBH7qrr8KhWte\r\nI6vsN2XhwOdooBTYh2mf636uBEzN27W1QcNyDn3ixyl1Pomk0z2/Z2YeZkqa\r\n6OszaOkTBQInswCQBc55y+H4fUq8vECKoUZDafBKI9JJrjHsRcbsypBY8IC9\r\n06nLtHliieUEhHP5ReNyAEad1t5fe8EpVh+PHWaNfoUuenoy+XbOi/27cYUj\r\ny6IEgxvguc1vW4ZuhCVq5UD3g5B1QbqUVf4EPu+2YhyIwTA9SUYunCEFHcoa\r\nloO2rFTDU5dwTQI28k1DzHEMsWtEQ9qkyXkXnu2YCtBqkm2Lac/U8eCmdHqF\r\nG6o2yDJ2YV3f8yIhlyrmAINYeIyzp0KpUS5HRlnMGEvAMIKlbqamrurlmc5l\r\nxWlXl7IJF7pVCNzwElY+6KN3VA70fmbRe2bs5Q9cLRaWT77wMkyLV7PZVwSc\r\nm4MFuz1OVqUd/ZpnR8BV6wAw1ryI5v4vd+w=\r\n=PyIQ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cc4d4a4e4a23e184389b8f29fe007ade2fadc465","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.322+cc4d4a4e4","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.322_1670539020895_0.23459407752942152","host":"s3://npm-registry-packages"}},"4.0.0-canary.321":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.321","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.321","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e2502d52fe51ef0cdc3eb02eed2ad24843477bf5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.321.tgz","fileCount":22,"integrity":"sha512-RttuK2PJ1gbYW9RO8I6pp6Osh9OZXon2NZlQRxfLoKMxrncCIPRoUk0NU9/rvxNVlscY2yXeCYjQ88nMkwOFLQ==","signatures":[{"sig":"MEYCIQC6ia64+dvCfZKScfq72tpzhpGq3GEXt6TQaiVgq0cCnAIhANlwMVuevqPVt6hcNWvCNB0fuz2ElnxLZ0cdsXr0wGnK","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmffACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqChQ//RZ8eCqOriIZYodxSoGnZi/8BELpMjrCyFt+sZGCgdIRlUESO\r\nV+8p9w0ZK1GHv3awfpGUi2UuYyv3uEa+MjMwb52iHsLajHLzqlRSOKFijKRD\r\n9e+N/LHBSll2XeIXXBDNJkUEgojLkOTBlcon/8tVhflb29kDzW79LvLxLGN2\r\nEAyyDoL6qZ4C879n6Y5ZgpI9alT7u3wxU90WwF7E9pmlxvxRQqDwgB9CFMfn\r\nvsEjFw9B8uaYzYdj/N17loGcx84PKCxv7GT9ZB8ShnlqXDqFZYzbv/1uQMZ7\r\nrghDZPSGDG36lMuMFUdS1EY3HYmTmTrCWEL0fqxRtHd1P8nBYJnE/u9PgxSE\r\nDkldEGm20sSR4csOyZdTnIKNb8qTqFJnhx8k/0QS6cCdAqf7vYVgqgSStNYk\r\nAyK5Auswhnznuv0sUY3cYHd99motRTStNpJkNobzRn5FMtGBK2ptKNff5SeN\r\nAdVEAftlkfGlqXwwg5Z1ukf5aGU8ep0eslSBdRqC19TkILOwcHs8cgzV11cT\r\nnkxjKyiOf1Iq7HDXvZeOvcxZ4ikeoHsizcxHfKpUf2eiHGMErJ0yDBaw3AWr\r\n9+L4D6xBT2t20gSbLuIxeOWXmySy/93Bo8szQNZHQCygRRU9jOqlnLqS+aJ1\r\n1qVvsSuLiwyVWwqeUkgrzTmCMDoZUfJoKQw=\r\n=vaZa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b1f242ee395097beb24ed4074f7318defd12d340","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.321+b1f242ee3","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.321_1670539230990_0.0825950929980872","host":"s3://npm-registry-packages"}},"4.0.0-canary.323":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.323","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.323","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"74554cb1258329a2d221b5add45df2bc05217687","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.323.tgz","fileCount":22,"integrity":"sha512-Se0Wl5KF2w7MvEU4mxCZc67GRWEuefWK7mUemZuJKGvKy2edxwkFjSXFreqeYxBrstCDLxQ37Y2iX/ZpFq/t/A==","signatures":[{"sig":"MEUCIQCweOCbdPjUJqBniiZPlGLu/e9iRVDJM9vEUeT3sC4OpgIgPcZ6GVrNpr66uyqUASfddS8gclH9mkRa2AdI/JMtdr8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkrF+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrLKA//S45Ccpat/xJg0sB+uMVomZGk7sZPmJVb+tSiZYDVNWhCKArj\r\nY6tRNBiQ4vYWwtjkSN3Fug6YP1tQpWjNblan8arT/cNz119xSOAEu5Iyb1qO\r\nLkVzzVdvAfEaz60l8QUNb31wUXq5syVaxIr5uEf49SVnrBuJlA05JFOF4eAe\r\n+WdKotXqBpJCY0ATEz6nvpTc8pi7WqTxHn1Ar1vQkF8qW+y8MpqojCJkUXCG\r\n3tfPJWLSKM8saw+7gyF++iH5xnA0XAvC60cEWjvWvQYkjLW/GYxtbx0f1WDZ\r\nNU5ZLzK6Xmn4jidiZwoo6k48T+9FUT85yz8fyJDDEzLun/0pPfcWC3DS/qxj\r\nX4VN9dhs0RLmMGV4lI3Ftu4NET+aTYzJQpy1t3ok7ZOWxgv4XrDaDtfhwYzb\r\nDMHkDtROV8WP8AuZ7Zu8WA4L9N3kc0Qt1FvPex1hnaMVnrjj5nNf0haY1Pje\r\nXmKZ11bcM+2pZrHho9D/A0YLMtdQvbLPYJEsryza+WYSiWr7iSqXE2z4Ogmd\r\nnb4Y76u0t0m2ZLQBiAzNVQRPV3TDjwqJnhp0uB495ar4Md2ApXNmmcqZBKpK\r\nC6dR6BG3wv321DSvcakmJAE1I+dDQ3Yi6MYF/twcYfpG594brlyl5dmd7EJx\r\nBrLMMhC7erHUUcP3r09GonpUYosFtNb8DxA=\r\n=ldf8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1e2c8b748c33baf6d289f54c8c1bc39e969ecdd6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.323+1e2c8b748","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.323_1670558077894_0.69274540146536","host":"s3://npm-registry-packages"}},"4.0.0-canary.324":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.324","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.324","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a2a63cb6eca9ca8aa28cc4262c6c4a380e7812f5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.324.tgz","fileCount":22,"integrity":"sha512-0yzPIvFWX0Q0EdpioQJTtNV3+91QBIK5k/ePJQeQVAKZKzQB73Azu+LydHOinvqYWn+BVP0Au1bZRthkjKJwWw==","signatures":[{"sig":"MEUCIQCOfHLPQrcH4ouX0ZPI2EuZu4qJY7k3RJbOccOIGWC/YQIgRMTrdXh0roDbVQJCd9NC4K6SRIUlBuUDRbjfNyg4d7k=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkrO/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqJnw//dmKDi9QpVueIPATiMMhQBIJWwrd9Us3rYGdQ1rhlF4jUyFIO\r\nwOD8NAWZ4X4QrIydpdH8MZBjUl5N9GCSuKHN+CCrjYiKl/pPDSpcSnmEdo/R\r\nu/HsmcZs//Ozt1CASKch2iKrO4w+ZO+1jyvBahKBLJV1gfEHQ7uJaniwCnPu\r\noo84teo6/qKc4Rs201JBF4JjRiBJl0K7Ae0lOxnjB2aflpeMH9sQr68vBfT3\r\nlEQTUnF0HLPM3dF10QDmqVcFrEPd17yGpu7gXywcanyny/e4KT06Qfs3ytsp\r\nkoVqJ7ks9uTd0pv2jk7ySTkJYTrnYodJQBJWNEHRx0zZWlCx0+Lv27Ps6tr6\r\nBdxd17BuxwiavqKM4j2iD7lMO6ahCOUg8cBm72+8Zxu9WRjDngjnrwG7ilm5\r\nAIsZMTllbTOM7kB6u5hsE9pIv56s1vU00ZEVmT+ybrt0rNp7qkL+a8/f10Gf\r\nJWssAq+ldYt8CCiqtgL3XElYJyDkg5vNwT6pu4CvCUbBipPxsdpZp7pVS07F\r\npnyK+0sxlBpbynIdvpDTypXH2r0x7NRhb5jC3cZOKnlGhN3zncFN8FVSoKBJ\r\nR8R9Mme4569rW9QvtOTg2PyzB/5NToWRB55tV96gxezuaGul7cURbb9b6jNT\r\nr9m/zOthZYtAuqH9Po1cAON9Sj/CtHxDWdk=\r\n=OUxi\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"27b1666f888eda8d1cb76bacde2060846d1a5e9d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.324+27b1666f8","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.324_1670558654863_0.5767443116802515","host":"s3://npm-registry-packages"}},"4.0.0-canary.325":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.325","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.325","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e101efbc9015edaee569b32eaf0a6cd445f754f8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.325.tgz","fileCount":22,"integrity":"sha512-AYpwN6YkjHXhm3mwD2CNxOdUuXoVfZxHMwsiZ0JI93JXoma48y0wd6sIhgnyk+rMnjqazsKMir9JGkrYhUmphg==","signatures":[{"sig":"MEUCIDdREiukbflfTZnrjpqtHK8ngta2te9W6N6wzm9fPp68AiEA7FGPy1nh/LhXCu5dd+DPUP/yPgtAIcPzWWPqWTm3QKM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkwYFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmobkRAAogYqgnTuciaSmNnk+2DxxQxn+PUDdqnsGmS10z16AqV0T3Tu\r\n2mXTfqgSgY3S6Kugp7WGdotHaZuGaj5ku+/kTRleULU/GvMWy5jZcpoLkdKW\r\nU9mHnhkwUJFam9tQnD7FxBlUDPnvUhvw9g+JIzGP+hpeWFQIpXqlAop8I5ST\r\ngWiy3je5rQFwFPbSBO22ttotX6QSns0RfJ3I6SPUFlDx6QXxUqppmaMdSGaR\r\nILQDH3UuB9O8BUknMbdInjd5q8NQUv+ZYIpM/oZ95NYoP38Ftv0ApBDMcwaE\r\neU71CcetFbb04gCglGrAss19xvUNsNBsZ+baYWn4q7ErIGsJxbfilakNMMet\r\nJaQqvWDt3dv0WjUrz18BeXcsqI92Jx4sTV5kOGw5x6aca5uFcfNRWe7OmR4l\r\nDlKdViRLf7V4X8YItLEkuyiYP/AY3SJdnAmprhn7LbZ0owzBV+ZgWTcU/mVg\r\neH9dHMFx0KJWMJEvttEb2idX0qweBBr6+bRxh6gMpsAysYQt7S6OWtMCcSU0\r\n1zQFa+npY7E3XqM7RqhQ284plMr/AR8gKLloMEeQVqwTPznb9pnT7tJUyxlP\r\nKfGRjAl3uDUVP78TPXfa0yAkwRtGHzq6YloDJpLcLPmCbn7XvRtGW79J4UI1\r\nY7VVrYAXBF87yzhVmwTV6AiNzZR6NjEoV0k=\r\n=Ybjv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b480d88606ce33c4311c52302ba346f1c9b5ebda","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.325+b480d8860","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.325_1670579717254_0.8581401750798843","host":"s3://npm-registry-packages"}},"4.0.0-canary.326":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.326","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.326","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d83d052416db250803b88b00f61f7f32ba412b43","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.326.tgz","fileCount":22,"integrity":"sha512-jQUUq3rJRQ2KKTTCBW0vTOgzIVpqmW0AfimEEyvXJinYTzaH4cpwjZtzMlrl7wQ1vDuJLt01kuj1V+wYPoT2IA==","signatures":[{"sig":"MEQCIA7kQNteSqhn12VIPZkUlldAtO+C+2gdLAvSZEEy9V2qAiBwtF7pdcV0cF3q3CiLvru8hct2FZ0VPFJ3ff4MFkVm9A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk1OeACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq0BQ//W4uc1gBmrCb6H28YnM+LqXQXJxBi63SoTkOeFrpF+UN1bg2g\r\nRCicrGUtUcxDhbiuLkF3/3J5f//tWjI6rXnRPW4o44l1k0nVpnUokzzApPcP\r\ny6kVF+/g/f6FUay8oPn6Lsh7nl6MaZQBKYVJjfBNd0wTiQHwEZhMX2fAApDy\r\nd4vGGdlOXAXS+unyIncdeCjpRqtlOPjwclSO9l9azDdfOTNAaPqsxliQ6DHu\r\neatutXKqHAtcs02zi/+jCiZ8EcSTpfH4qbc/r4uMyuJ6e8/wXHk98D152NJh\r\nSbjv37I30adb2umdw7YY9UNDM/ivdTVSY8OdHFsjbaBW8Rxtl9PM2ciIT8w0\r\nY37YjqK33dZKHGq5s3WVfqploEfpzfhMZN+nhgr+7JHlP6mMOjugVG8Ecb/0\r\ngfAAW+llO4W0nY0KYqfMdTz0WY9THLKtJUgCIsO3IKbaZesAFDfvFyMWj/3I\r\nqc88GGvtU29+zwTJzUz7UnJgVztUv/RtENKBN8L4MrOrFMfAE9QPfcSnMkH3\r\nK1X6H6y1Q+AjKu5mW7HA/BdYxbegLBg18BNmGNz0IdlOB1qhQKH/rAzLzFJw\r\np5tRJUfzFVvTz/uHwFZC74uj2saNiFIwp123xq4aBBsCXlRqzsPP3+9ywqJ9\r\nV+kL1/U0uIAY+Nc4Yreul3fTU0Zq520oKpc=\r\n=t/jm\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"808fb276433e9e103bc939f65fb747bc31376a20","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.326+808fb2764","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.326_1670599582096_0.2221317273680392","host":"s3://npm-registry-packages"}},"4.0.0-canary.327":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.327","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.327","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c438d94bdf7b607a5f953e764637dbe067c7108d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.327.tgz","fileCount":22,"integrity":"sha512-/tRo5QrMZfYDI4UqiCdWUfLvVg1gv2LC9saQ6wjgSX6Qz4E9Hgb8MHAi9Tv1QZbRjRZAA+GK4+bJtQNzzvhqyg==","signatures":[{"sig":"MEUCIQCN/0AkCqVU/OaLgxzrwqb2WSVyjNcJaIsMzCLWVDVOQgIgQGNFzxqdh6yw6Kg5/y+h92g5wYjCP41kgyaNTDQq3NQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk2l/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoyXg/+Iu8CUuiHmDW4DOL1Pd/6mIX86iwxb5VULgMBJVo4++Snlasf\r\nuxcfD7HvTSGcvjil0suXdjxd4JbJjvDGTX7Xb1luUffEbTypiLFIbHo5KfNm\r\n5xU02NKoYFnVj9Nv/o7I2HtYRNkK9viPsUD3Q7XxZmNdTtbnVQt00TNSXLIy\r\nYgnRR52vcckc//xyE6yiqelOwZ8jGhSwnHMIHLQQfvwqvIQIGLHly3TNETT9\r\ngRPCCb3eya+iuLulspijspyLKvuD3A/0KnDZqs5+Ijsm9ZLWMj6WHcex0csQ\r\novFINONk3VnT/mLl+icpGrSB38kcm4m7/xMKpblaKA+ruUU+4WiMJSIcYE8x\r\nhmG9Z8ma6pHCPKS63XZLG+QoF1JQq+S8GdhqQCdCgJoJ9Vb0cGEG+F4yP3T3\r\nGP/1AdMJGNakJkqP2mgCuKDFT6dwGFO5/+X6JfWsKt+vzQNNtlccNNqkShdG\r\nt+aLio0Dgslt5oMoXAP8m5Nt7XlH+HD8+pFAbehwczyx0FzVkHeN6sZrtMLc\r\nBltwwCqHoIETrgK4hwqWdEcRUlaNJmAImX/KoYYr+RtNNQxiM3P98TKAY3iG\r\nUFVjiEAUPVSPjsUVY7w+boSWScSAj8oW/ZuNPflz5FGA8Fi6SGEsqs0PyziJ\r\nYyxvrbWzzJetzVqAmd3+foVDVxw6zapVOMA=\r\n=7fZt\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ff58c53fa943f942d162f50bfeda5a69e02f2ea8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.327+ff58c53fa","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.327_1670605183515_0.9755996268491438","host":"s3://npm-registry-packages"}},"4.0.0-canary.328":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.328","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.328","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"20dbcc4be2ae09a98ffbc0d7c54ec2d86a310539","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.328.tgz","fileCount":22,"integrity":"sha512-9KktTqUdaODvns7D20MIjOZ++L1g8jtJn2j91MMVfxrbpDH6u29nCxomx5OriAPfi9gLP1vXPDZ7nEqxzWVEUg==","signatures":[{"sig":"MEUCIEWvAP0kmqYcv7Tn5h5kH5IR7WRJXCI4nZ8hphgB433fAiEA5X6+hyBqxkzv3qAS+bn761zc2dJZu66lCiWiMUvSqoE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk2oBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqZug/+NSOHfDlm0LPffAkfffGpTqx1Og0QrYjx65a1Ix9yDWnnJyYG\r\nUaElYVksp40f7SDHZczPsQ9dh4COBXZOcsLS2jfyALY5iHexF0DMKigGwXCX\r\nW9pFhSXHlD5kTx4UgUGuXwSZDWcwaBMqWw4412043pl/Q5RiK7yFL5J4bGto\r\nAOpZ69XsNZgj7awkY2EWaSkbvzOiNms/2V+JeRID7cinSqzftSEuKLpY7UkH\r\nHA6DYPV4k6jHT6nHHKb79Kb0B4iH0ooWT6Jc9s2gAOBkg+rywBk73zbOfvgC\r\npvUAt47WsWi2du2w2P2ZkKvuMksg46GfPdrjGGGMUkcv4zEsuvUO0FarbHNQ\r\nTZSuDPRAqcFEW6RKX+r2iwrnH1mCfkC2djAY1Uyaw6wSgVND4cIbZLALXxCb\r\nIB5Gz8etCC3jMelu+b9XAtqk+QiWGMg9yN63FTp0Z/59EnoXvCvnarRSp3SP\r\n/qncTwy0Bm7R4tk23AJps9NQ4OjmXkqkDHyoN7S0nvRtre7Rzzh8GoO14Wop\r\nxaYuHvk2t70nRJz18p6Piyf8LFURZeePvgMhT09fNAazQ+sUBcYlP9lVZJli\r\nY0EzVm4b00kcPwtV9CRa+tpBR6D6lSOoOyGNs+w7h8p9zEIahDYs3dcCIyWb\r\nzmNMwRuh2xDJ+OTsbHIBKPjbc8pGBahCUu8=\r\n=iVyp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9db6bff71824f0b2042d97cc516a14644841d7b2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.328+9db6bff71","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.328_1670605312956_0.7021234731611072","host":"s3://npm-registry-packages"}},"4.0.0-canary.329":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.329","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.329","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"44cf41035c5a61e7575995a8e16cc9073bc2a64c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.329.tgz","fileCount":22,"integrity":"sha512-QQs8pfJ1hVWCtUnkcgcsbxUjkJXhhlBJa/FT736OSdwH59tz6bPmXf4mArfBaSEYum4vCF0xUBXYVL4nlOcQ9w==","signatures":[{"sig":"MEQCIGhWivXIO2fQ5GYNOJuc/nv0dCHTXtxbC8aTHa/PXTyfAiAno1ZNeimaxuf/j085cqz1G6tZXSP03gRUOOIwWPxkYg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk2qUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqJhQ//eNhjoLqcxAeFpRXZyG1dQ+oKymcns2isESv+iKMbUo6UOpXX\r\nEiErGqrXqVzMJcFe93EAyd5B6FiBUa60X3RYF2k/cMScbxM1BxfWpI4eiIC0\r\nOPlodpfD22j36Iq1uLagrZGamfDkQ00dfKV9D+UTCGMzmhw9A/KbfLJ2Q0uV\r\ngUZzwq/xsyawww9bA07sglB2u4N4YMVtgygLAopz+qc4iKpsGXx1MbQDP90p\r\nbIDiX5Qo6xWu+V/SwWVBVWN6Ih+uGHT1PmeOEddA9YIdA1FQiAZSi3PFkjHc\r\nfJunQhxxtM67q2hXBodgdLP5hzNBgMsUFcn3owyiRXy2aN2BqS8S6dL3D0s0\r\n3xwbqmaXTWsZEIrAQ4/WuAgT9R8TLCRJXFMyivFJAncTvZoyg1XDJfCfz3V3\r\n81oMMH5fm+mieePDJ0/w6AUfIxCEfT+DBhZpmmO+2GaPxE9EfYO35H/WdZjw\r\n9Z3A4MbXwF0xagu+PpngpXVfdfogdQsE8A+Ow8xKEei+EJx+HZD9Wp4Qhg6i\r\n+hjiBwnQXkU4AccXP/m6FkGpOhm4NS7A+vNkWxlGyuehUdi2Li0403wGgl4N\r\nsePbRg9tVGEePTN2b5uzTi1zgEkSdGWYYx7wvWJONPsZ/aD1U4+NpSQDhmXK\r\nOpvI+WNR5z7j01N+Cr4+eXTbyiib8FKhWXU=\r\n=9+Ax\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b997c06f2228a8a73bc6e1a2ebe98e7a3904b004","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.329+b997c06f2","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.329_1670605460541_0.27608462608538553","host":"s3://npm-registry-packages"}},"4.0.0-canary.330":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.330","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.330","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2ac32913c9db34efed99b304bd2f08deb5277957","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.330.tgz","fileCount":22,"integrity":"sha512-WmXzezuwMLfFJnck9gtLLM2ltYngq9TXZn/gT+glsJJ2jTBi4AWh4MWOHXRw0sXNkqDo8BmL3sVn23vjmuxiBw==","signatures":[{"sig":"MEQCIGMf2+4YnAGhfJOuoZKPnqAUb2Z/w1TIi5R30SCcvrrCAiB1Esmo2Z49SIuDChzzdmC2UGCbhTdd7uvRycxbhaAQlg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk4TaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp3BA//e6WeTmNL+OSSb1lRhtEvyf2zMODV9x2+CTcbG/P1pirhe326\r\nJTanBMueratqFM+srk2VQNy/Cow7FsRoZHmtDUg1lhBsrCUImmNO74CZKGnT\r\nB72KEg6evzGSHI5Il2zV/dGQVnDqbjI2di2km5+aTEQaQ+QmLl0w6QJSGCrh\r\nliz34t7spTtcMyG2IBgQN4vB374vQhSEcVNuv7T376POu1n2rfSxZcZupvnn\r\npwP1aBQEWdIQhI9cOO+qETzNAcxoS5wbYJezjNU2YGOrxxUk07kwXiggy4Ee\r\nlbrYuOnyMu9XWvCNd5+ijYlCmqZLhxh8jlpmMf32dy8gqkjhOGua20qcTLQJ\r\nXOwW8wsnErHlrVAkT6naVYhw64dm/EWlvNg7W9QBmNBhjqEIUhL+1yUrNdQC\r\nMw3Kf8zpCyhJwQEYbl9awg4Dza3pB78O6X3wx6Uxyo6P3q2DOqN+YrSfKQBI\r\nOf/+vG0WITqIwR0DYxRl9pnRsKkWqxju68lI7/0gVrQdCoy+Qc6uRv9VkrKb\r\nSOAgrLLWinj40dIKIURWfpKyoVcfDyYxsk0p6RFC94gPzrRvZWqzyMjbeJrD\r\nraS9lbaFXmP03qSX72NyN58imfnBPCwO1euUe0FQDclYdW3mjfcO1nAJNnW9\r\nPusUmJdwQxiIDI4D5nomMrxph0aBCEZkd5E=\r\n=2y8e\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"05c8b66ea9637412ddb377684cb90872db55fd9c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.330+05c8b66ea","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.330_1670612186362_0.29384915916312293","host":"s3://npm-registry-packages"}},"4.0.0-canary.332":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.332","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.332","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"276861f9c248e99b558c559105644968cd16330e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.332.tgz","fileCount":22,"integrity":"sha512-QB+qyLKfFJc18YC26dXp1T3HbzgsVS47zu47WAY/aCthxl1spSd8oRIaApa6orQt/Wtigx8nYjZh8LOtngCdYA==","signatures":[{"sig":"MEYCIQDv1aauOtT3gJlZbVzqAiaIBk8W5YYglV9X9uCFUgQTwQIhANO8BOhewy6zz1IUv5iCfC6onnCYY5Q+SeDFA6OSavyo","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6LDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoX9RAAop0p1yWV6ZuKyDmLvWJgVuk3Du/evtuEvcg8KbI2e0+PlYId\r\nZvQxscE7YOg33bgE8tb5btGg9nw0PGaRSAuhS8HUsbSllf5W5GCdLw1RkOCW\r\nw5vvtst0rznw2Q76gBX+k0gbRJOF2vIszg3wpcwHsKZhGRjuqsf4LD3YXlXz\r\nW/XH2dA9fmjkEUHpWs+2Bc4HLmbURB3mx2JVX8Cvq2J+txkFFAWm1w9anxOj\r\nUv9hGnjqvDW3jR3gD2lDk1aAQTP/hk8gs9kAlaycXnJs3+WVuZW8fR5pCGXH\r\n82eyfxER63fZaxTB1N+JmCjsi2ZW6VJ+51jhUibmiy1QfjLvhqcZPxEIt2sI\r\nqNgppgRg7wM/SvtcupWSstbZZk+TanFFUH/QwxA9uj2Ld8pC1UCMkda1QKmr\r\nTFs2ytr9TC/OAiXtlV5Pu5ZO3wcoy544n8dHFEe2bldbaY2b6zPpIzq2yM0i\r\nBBfJi8+mgYNbLN318oRowOULS3e8slBftH+wrSxJXAX+2opbtwmb9I34Lkty\r\nmrpDQ9do/7178YVU2kTKBb3SbT1PXg7GPOYMssa7QjBIDV7nmefQpwEWgGzN\r\nWfstTf2eWIf4h1SXA/R1nJ0E8XLEi1RcwcNBPyov/Za+R7MUtfVTDGWvvOPp\r\nyTocOfs6ISAdhwZdPli9ADCIfjZ1HHDxaT0=\r\n=QVK0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e903c90927a9dc062ef0aad5ae3004b556d4cd26","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.332+e903c9092","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.332_1670619843387_0.023116909466920577","host":"s3://npm-registry-packages"}},"4.0.0-canary.334":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.334","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.334","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"38a374349b37a9ac03a34d0e0d673b7d2497b04d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.334.tgz","fileCount":22,"integrity":"sha512-wd/3U4BxVQet6q31NgvfSma8zsZICK5pMJGiuhBxwEZZ2XCafzSajaaCTuiW+izHhzwWrHO5CAQ7P7IZ+qXeuQ==","signatures":[{"sig":"MEUCIQDNT6065i3LsaOyYalBF7KCzMOyjjLfE8o7k5mfXRrkyQIgQJh7mrCeKmRRRXAqYzpeWWL8n5mWQt4ud+DqA5tvD+k=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6L3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrP8A//VCUrTlWafD1XrdkGhB0ZZ/BgsTtCgL8qQ0B8VfdPvVCqOY14\r\nb495tI9H/XI/dvAOrE28R7Y6R50nudu9LgQRfcqiWCjljWqDBILOrhznCzAm\r\nm4mz3abC1e9qya0jANBLrGOi9YjLfMs1uuYz3qKHDvZLKMqzoksUxpwU7G9P\r\nUHNu5dGDb3KdBntSgzkRlPgfUDn/I+XOj0w84ni7D8QdRmixj92QJsC58eXU\r\niD8AStUCBRu1301apV1furAymUpbGY2I450CAK24d4lV0lg+YUe9fLtb/DXH\r\n9U86kCikPRmOvMm/NkKwSMJEQRvGV0VmN25p4wBy8JH3CCX4KQdahLojPlLA\r\nULNn5aQ5UPxHcJD0jGTJJBfbNLS7Xn18DsWHuUy0tfGxZB2hVX3DOgunCiPx\r\nELNVpfAUmdutCDGq+ZrWjPa//On/y3DRO5BlVlYCBeE/fLS+XrXlebVz/k2V\r\ndjC6SGCXK20S0ytJvk6DtFjxnXmyE1pKY0qFsA5X3+UhsQCF5hXWTFD3vFIj\r\nBResx85wlGxEojqvBQEhgjXo60nYbeeBgzYkEvdqNYzj7+mDhfJrpDEN/lJA\r\nSyulJIyVlq53q8KuXHatMh/Cah8ANOYZfc3Hs9uQ5vz8hNSSx/OgiW/uCjPz\r\nir8HMuiLSwLG+7JXuJACG8nWy6Qjtou3sgc=\r\n=HMxD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d305bf35a9360e6227d98e69a273ba38905b6110","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.334+d305bf35a","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.334_1670619894753_0.8617067701209518","host":"s3://npm-registry-packages"}},"4.0.0-canary.331":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.331","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.331","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4ebf1e64b8a4db2a7629a7875e30a54268e7a3b6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.331.tgz","fileCount":22,"integrity":"sha512-UCJtpfKNB0lB8gWja4o5xqMB0tn46VFbhRtGOLMi0Wrgdh/D9oAZRwuyD5TXh0yOLMqcFD2rHVXqBGN4gAljCA==","signatures":[{"sig":"MEUCIQC8FG/DllTRzP6lw9rRlniKCisdyauVvmtS3ttJCmmCnAIgX5JUsib9IIvihBesAIs6kR8XYbJldHhHeTw5+fJxbkI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6OIACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrD/RAApOgu1mk1RB8Ualggrp6Mh9CrSnNvzpm/s/S3j9S6fMJQiFuZ\r\nvkrWtI1Cq72pyOGUQLmT0x0nr6VvmNtcr6s1dPENI+uSnu1Gnyw9JaIdue2A\r\nbui6++2uSNwQDrBbNwHE09xHndOPwLXDFpjY3bCP5G7hsjab+5ubN/nj/Xj/\r\nc7PlkE79po8Ul+lbxGPXoLX65UMUf/D36ytAGkiHnS3vQS8DAmdUY16LXva/\r\ntO+Cws/xMznbsZxMMdZS8X9wVT1vJNP71i7JQkHyMJLm75Jin2WpKTx3rE/E\r\nlNsSZLTUD1DzCkWxr03E9ChredlLGNUDHcf4cAFi2RnUkrGezyWdVAyQY/JD\r\nJ5pGADP80sDuqfRIASe8rS7pa7WQHBmFp9yxwtPXkbEcCriS328C26fZpwF1\r\n9BQAcuFbuMGXI1qVJqborzooJKFIDO1mNdc1yqFObtKmn2lEvNrFsl8pWUma\r\nYbCoqim51pwHAq82MqOOwKz6bInQ8UtF0wI9BRv1Eq2jrAEOBiEXSa2Mfo3c\r\nr1yWWuyQTpDSL4jLUSX8oepaNwRrXFmvotx71fqjH5gHdciukwd/bo8netCT\r\nzMONkWBmSP1oTsWgLdHY8a/Mdq1d6/FENed4LjzrnbXA7D8urNn8lAeEI7QR\r\n7rJxYHBD/d8tpfAZCcXIx+IF7HqYPmHVIfY=\r\n=VRq3\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"44e28b657df90ef88bdf63c2b89d1c723d739a57","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.331+44e28b657","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.107","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.331_1670620040210_0.4037612065193068","host":"s3://npm-registry-packages"}},"4.0.0-canary.333":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.333","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.333","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9e5c75b7e471660ad4f6046f70f4da6e61cd31c1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.333.tgz","fileCount":22,"integrity":"sha512-PY77m71tYNHW/lpddSyhcJrVwGoKF8vTPRlqQMFHfSDMMCTjZQJNUUhCP1PfnVZh6235iDLIpL1snTuW9GfGog==","signatures":[{"sig":"MEQCICuROIbLlof37XCHrTEIF3uQUzatKgrKgCwl3n1nmjOFAiA84R+/xEYUsH8/eu+m2QR7hvAKUUNg6jh9Bd8Mk4Mxkw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6PxACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmragw//b0r79A6vYeUSbojGI+Pptoqn496OTB7ZOVrT0imMsQLX6O7Z\r\n3r2KfpQlgQL4azJW8HvSfo9Vyq6YcWILKRAN80xBKHmUVGAtPhWD8Yoz07mn\r\nVxAZ7g30iyNIOMamLHkmpP9XUo6QsNGp00sRkauZAzyIFup3EnxyGmUHQVCs\r\n4Jng5t3eUxITf+Z4g+V4iAnmwPCxBTCaCUL7baKcJIxU2eLZ8PR3ORpmA/4J\r\nr/i1WEQQyBIIUTizSUxczKYiZ5Uqe2lYPDdZ5I/6vwdcqki8BRmPIR7IjVr6\r\n0e1IFxccWlAAvjofrRgp0Z5xdGw3X7GcXIZqK/e8ZkndwZMsN+nY1Lt1EHjG\r\na4z4K9mtLSJtlJL5yWmDEUYC3JJKUvQvslHsgJqanIRCqm1bj/VGubFjpzHx\r\nrh/b7ZeJJhXvPaztwX1nCLw7qF+cuivyqpwkSRP3VIq3pChl82lKsrEZkvZE\r\nhrP0rnU/lOYJud/LBob/KiPwXMlbbgG7sStk5kaDsyqRF1A25DZAMtLOIlUN\r\nvKuPLsNMmJcq6S/yT4HgOoZi9yLyDjxrwYC89kWx95SC4RysGk7GKmUChl8X\r\nO6kxUoxDg4/eBkozhGav+TqlW5kewy+eGTRcl6UwLVRD8Hiob3SydLmAIEOz\r\n62Hhv0r7OtlqSCSsDzTK9MAvWOV5LoC/DoQ=\r\n=HOSh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"61d5d587986092488e13d37ca3c65e052096c58e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.333+61d5d5879","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.333_1670620145555_0.473944182207253","host":"s3://npm-registry-packages"}},"4.0.0-canary.336":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.336","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.336","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4637d125d8b101bf7c73231a0ee17e2dfcb46e82","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.336.tgz","fileCount":22,"integrity":"sha512-tgeI3FikhJFnc4saZZF1mzbMwVuuba4lRqSndKMpLVemw634ZhFmmSxsoYWmDtTcSIDnlKW/KIQ6M7peFm8d/g==","signatures":[{"sig":"MEYCIQCuLLiMDVz/9PUFgBEY5Tux64lITSA36DH76hbUrIDEigIhALoBSK0WxUZXq65tC8wEuoA9OZJaVeyk3EpADOPMZ5YT","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8RkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqNgQ//XGbMKqGjNPJy9N4r3/t9d7h+RKbeX3AuLNbBrF8t9SyPfa2p\r\nHiX2xIdKPArQ+/mekjSr7YKVHhUHMLoWPo2dnuX3eTvUYS0P141TKWPzX822\r\nPJpZDDyfyEIddMFBeOJHuy5Hg7Lq40fWkAeqohwmY4QiIR0rcve7QiRgVtKr\r\naIDKfqj1kqEAVrrIPZ1DLbZKMB0/HkMV3uLlk7naKk1wufCNw459mxpAL8oL\r\nN4TxWSOQo248Tm7jO0Z/IIJ+h7daKnCjvQ6ZJJ1MnFQzqMR0aA4Tytxh6+H5\r\nP1mBsDc0Vd84KryJG1tYtMM8XHSvIUqcnOUhN+sqcbWcQSaJqJRyV0QzR6ve\r\nc/jEO/fcnxOhTfBiMrSieDLVG8w3IMyYnSEdP94ucrG7bbDecvV+T3ri8Ef2\r\n7vDaAg8ARc+v3Tj0+NCUg9aS+UXgPfReFonhONQukvWH5qxcckroFY9EAe5s\r\n+3VfQfGpSFoooQxC/DxHrxRKBLOv0xjE2MkCcGlveM+GXBPhIIwgl9P8JCWf\r\n3/rN/umvzRSvT7ZPnXzJG6VpR323Hz+wfmpqjLQ6fwtyD+N9W8ml2oIbfEsX\r\nadL33pZUNZwpdCid0rP9UHjBiO08kfSwp24TQgpYpRMzOglgex3iV8tiEdk5\r\nu/748mwhx2NYt/vfWVv0kxzJDUAMe3R+/JQ=\r\n=Wq+l\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6895e7286184d2ae6f2b6d3246d99774bd193891","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.336+6895e7286","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.336_1670628451860_0.8519541963333259","host":"s3://npm-registry-packages"}},"4.0.0-canary.337":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.337","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.337","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e7afcc51c17b15c520c2ad1440bc7620afad0866","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.337.tgz","fileCount":22,"integrity":"sha512-W8hiciD0ezgox7qJ3uyO4Ytww+Y8AW5ty2rjExEhZ6cFQDC5M7xkj8qw8gOM08WHoVYvsH4sqYl+fZ1qrfjwTw==","signatures":[{"sig":"MEYCIQDSCAg+z4RmddN5E46B8l8AGI0jMtpWrqXn6/KTNS+gegIhAIaHbF9U8otnOi1chHrEVHoMYUylvOATZ+wwbHAVxGsD","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8TzACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrVkg//TeyuQPuIqPhh1kZW4LddyuxS3LtQm7Ikq62/RDZ4kzuc6XSI\r\nNpJrQMUeDwTuyz2AgLAoLouMuwNaiRXUrubxEd+OgdQOzkpexOyOtZ5SPim3\r\n1Vyh21ajRPDEs0RU5yrAx5TmdGRYYGL/V3sp/rnZqaxx9/XLmvcy6TM4EgJs\r\nw3cIKJZRqpMRPblE7pIAa2Uu1UAy5mI5pcCefoCOWQkVWj6Wv9j13wAG/U5e\r\nvYc+iZe4FgFt/cYxqb24Vpuz3WaIv8m7UZ0Kxp8WAGCyj1OWrTW2XuUPjlvF\r\nf0ACYXlYwiovw18CQ096KTmCSlrciT33e4TOO99Zu6ybcKcgVWFxEUFew+yU\r\nTuT/L4ZwTqTBtrn1D9oUpwpOJVEwddGuHaZhKSEnlCEjvSbe0CDfTBdL5L4Z\r\nAjc52S/JSNHieZxs9hWE7DdkDADmHSqKZ7JTBokoya90W7EAB6CZ+CyX0YU5\r\nfeMC3lILLp0cNYUzAUE2u419iXEQouFPtx/lcm5IsD320N+xq4RdMeBe42bR\r\nX7LvjgH0eJrSMLd3CI1xGudyvCUmdrdAjArst5I/om9EahkTPbIWczWhMcBF\r\nUwaHD4exvISCMYY+GsgdARXR6vpl5x7FFxVIRu51M0e/zeqfb8dpbv8PBJS3\r\nx36W5yE3akfWVGkiKpj45RFRzyA9qVsvGdA=\r\n=nrgZ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"44aa04f7607cbe08db8ece83bc1f24d39c512c26","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.337+44aa04f76","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.337_1670628595462_0.7075117592741449","host":"s3://npm-registry-packages"}},"4.0.0-canary.338":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.338","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.338","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cced73184f74270a39606206c6c9c38d84ecd6a8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.338.tgz","fileCount":22,"integrity":"sha512-+7fc7KuG17+qmFb3fbJd1LGewnTKwaJgvx3XbG8Vfy6O7Exz5+gmR4zYmEbjxhPEg+YHp3tNw+4lvXPG04QUlQ==","signatures":[{"sig":"MEQCIFsYWHAd9kYRXI+5L09h8SENISJVP/BeWGXzEIQTB+cWAiAC4IJuWXhDC3Eub2T4VnadMy1PjqY5QwG66yX5oi3iSA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8VGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrSrg//d93wbnmr63MX4CkbeKNyOuNPGfNgbGKoxUw+uUDAP4+Fn1wT\r\n24dNC76e7PkL4KDvLX0IxZFiL4FlD0Rlj1QQqhG4aBGQBDAlHfCMktDs2lJy\r\nKNdYUeqF/qRX5loVH1mhKIPp9mu90bY8fCa597ZmyQnRPDkQtuIf8FaYOP8R\r\nYrlOJYuAIxVFOba4n6VakvVPhuQNYYUJ9TPDWkyif88WOFW0LjzmZHs5lGa4\r\n466HkBJrnY/Ra6seZQs/hi8WdoxMkAh8IYNQjZwLl13JUQZg7J9AiZj5uk/N\r\nb+ByCsK63PXlK/iXYLBx9iznxqW8r2CBKVJPVRNDF2NLEOOYaSyzy4IIcjCm\r\nFq6ommIy+bosJxuSLeqaAasWAtYf06Vg/2xKEW+W6bYQ2rSKk4yrSw4BUI7+\r\n4a1BZtwQRVEiPsR+Jzb63/XBbLl+y+vIPdE8+4ZlvrZruJODM6cetSPTcKYx\r\nPPERGI/KHSmnM4haS0iFIa4WPMNyYemsDLZ8UGTkn3VVLhaspFL6BfZhDBkJ\r\nRZWTgRwlEg4DFQpjfiKdLvZNhALKPZgOZ9XK/7A0nbyHEKnKmFpOWt0lK7IG\r\nD26/VTjqC0DQwxL8dOd0bNluwE82jCmRYcDP+Tlw0ErZSl1lXpiAj6ROf0wA\r\n9OJuewVI8UYW/LkitYUEFHuYJatHFvQ4zIw=\r\n=SdUq\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"afeff253347718480b822f961d0cebdbe094b3a2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.338+afeff2533","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.338_1670628678501_0.8795138532487161","host":"s3://npm-registry-packages"}},"4.0.0-canary.339":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.339","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.339","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9b15da40a6af7504efd1fb7ea2a9e61743a81152","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.339.tgz","fileCount":22,"integrity":"sha512-CQPY/LXip/W3wJ8JF4o/wj7TlJHs7x9mfEaAVDpRDoC9nSk05NB8wFdSCMbCRIDHR4xAhrd/FKOVPsrqGH9rFw==","signatures":[{"sig":"MEUCIA22UF88GgvvOqkg3zSfYJ/kh8OdF3WCaBjkj881XnJyAiEA3VyqJj1xouJsoP8u2E/FUPoX//XJla+rWSOPrecUGns=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8ZuACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmokcg/+Nyt6Zqf1sf4pKSy1IgdgA9AXglT+anLvdAc0vXfm3wUNZ6PI\r\ngsoi45GNyFb8Ksnw5Y/yELLWShE2fsYB/C6rbkhOznBQyCpqMOB3pNRa/3Vm\r\nVmNTOuZZMHKfIM0ly+m9z+X6NhLn+jI2/ORZda9LahBxUaQfIEtMetzu403o\r\nc4wjyCyLQJgQ2RZ/MDD7tkteeYTfmwvwBpRc7eGJxN7XBoOBuREuX2uhFihC\r\nMUz7qvseyeLNex9ufN+yaX924Ow5ekkPi6AQoocgKI5FL9C8AiOJqOgqNRfk\r\nZ8MaSS0PYF055l3v5hh2aNKYlGT2G8bIc0D5M1HvPltF7dbQ6h8YgZSxmHaj\r\n7eEQD5FNEdMyiyE5lP4afhPSqUWArty3MAOKBMU378V/vGosoAPgYWZ8lJ/U\r\nMKN4zTeDqKOzaIUgCwZ4Ae+r2nV/uwpQo6LaReJYMCI4kiUlaabG1dylVH+z\r\nv0NCiNshV48Njo+fyvczRblh+ZP+8fzrxwWybgQBBq9yPVcxmcjV6wemjj7Y\r\nllKqfJOKiXGkxN9hJlLqUKUDGGARGRagMjdVv3IoMW/mpjUQPJmCVAZj7B7R\r\ncALMSwHviOFCQ9i7VVK4Mi8IsZnGCVs/RTZ9FTEmYQ5k8vOBfoXsKBJphhkI\r\nlwESGVJd7XwYLmeB9f2Y3FLZHvXopPNDWuQ=\r\n=qJDl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"43d21d1952978944cca731fcbe862454c5ea0b43","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.339+43d21d195","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.339_1670628973840_0.6892927513390104","host":"s3://npm-registry-packages"}},"4.0.0-canary.340":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.340","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.340","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ff392c24e7400e756f6a07dba13b26ba1118b804","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.340.tgz","fileCount":22,"integrity":"sha512-VaNPpnO0KiuVcd151q0k8e0plfM8ByMqcZt0I7hyVZkRSVn7BZYV46B+KBg3DmYyjSJ9/AQrYRDoyWy/VAc+xQ==","signatures":[{"sig":"MEYCIQCZ4DY+SDjU+mdhod6ItzogRJ56vfuLmJyuG7VUomVzhQIhAKB1Mls5YdS7CN0G5NDgz2rfGWNKHkB/1byqr7CQeEWa","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk+3gACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo3kA/9H/1mtuC9Mm3YVbPOuUJ27ecX+adfYteYLKQ1kwwZPA226TdT\r\nukohoxNwhWUcBXTdjcnXvx6Ytd6g5WuYtDealuKWmceo2Kk9QIQ2aaGEABBl\r\nFuPnwAEHz+5sebp5fGUN2PxOymWk+Fgr4y1UUGM2yZ06Fl9D0kqo/LOb0VS6\r\nWMCpGliWSN6K71TM2+Vn1C/GFj0lL8t2SdCHYceW8wXDi8kKVv5En+SYJm+c\r\nkonuDmZRKG4Zn1npB+bL6JVJ3DihgUPlxH170Z4dWe/cDKHjDPPCQjnXBW83\r\n7Vrrn8MbVEaDz1J/15KrPVmq+2I4waQX4exy4OivjL6jgDHLnlRHP3Xyxu1Z\r\nG82AWLc7enaZpNHi+B+Rx7hvcGivqom6xfRCbMBBErni3/rXikF8Gs5CWBcl\r\n3oIQAdPGHnqLFPx/wn9Vkzs8fyPWxiIFJTk5MlpuMGsjA3j1BdQhMayvQx9b\r\nIQhd5Bsy3sCuwYgK1g+KC6CurRXSD3zRIoIgSw6r5cOQLYN6nfUM7exDiT9F\r\nEeN+92exWWoRssWbWHkb2qPynraHR1Rjr1W5dEd0bqaK7ycWitRGwhgt7dyn\r\njUit0X6CBR92PGMkfnUB6EjRE9IVQljxqkGWzB2Nsu1y8RNygB2jQTfjUBfy\r\n2A/lorXp22TaXQ+2J0aMhe/3tBa0RdnoOE4=\r\n=C7ah\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9696505ffa17d93d2a333ddc257f8af3a50aed64","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.340+9696505ff","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.340_1670639072054_0.8232154386570729","host":"s3://npm-registry-packages"}},"4.0.0-canary.342":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.342","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.342","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cb8787b0da198dbce824e24019a9003befc52a1e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.342.tgz","fileCount":22,"integrity":"sha512-iNrji2/deKo20w10yLGdwh+DD8YmBIqNcbRc9V90ce2TtZSPOwh+kpJ2d7ynjZDsaKo5QWtrIOGgpzouHJepZQ==","signatures":[{"sig":"MEQCIHv7XSSMOciLNO/lDaj1XwZFJFgvqJ52Kak1KM4TF/g5AiAt33FI5ty2Il3Dg1xEn4LB1Nk6LkdkGnG2JhamE0RO/w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127802,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlCU1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoytA//Yay0kpu4rYsvHK09MCy9mvP+PoIiabgd5svCehcV6VxXvFgh\r\nj5Emz+hlqlzRKd2epZXg/AbJvaa8VK57H9UiOmU1bwv22YXbqmQAmbZcB4q7\r\nRP4CcYqlTToMTbF+z6ow/yf3Db26g47R4p6haU0IAICFCanW/tkqCta5+0SY\r\nBIks8VKcKUxhwjGhudiLWsV8ir3/rNzVYyAT78lKhMkhHvMVHJ3YWmhoBnul\r\noZRdTW91BwhZUy2MNHrRQGJL7pHgKtMzlHLcP4sRlS6PWGz5UtSiavtjMOVl\r\ngnLHOmKveFa1KKnWiskaUMetQ12LYE53p6HFk2GBE34GdHh/6uIJXy+St87b\r\ndEcUOwr7mKws+Te97CIM8DSdj+r212X6/lu9yfmsbuwN1Z33VUL7mA9topc6\r\nJ3jwWQrp1VZ4oX8ePbgVM95PmsSFVxoippLhTV7PMT0p6x0ii/w0nF9Dei5I\r\nfRwCFls+he+2b0016J4zLO6bMrI5szJMXtmh5H4+QecxMmphJnoSIcJvV/to\r\n4NZ16DsyD9cgxI59Uhoa+R1tA47SYV/S+PQOUUTI4WSW4YEB87VbFzX+SRtb\r\n40dIa+23uhTM6iHqzX1WFDtjZC1Qyb1hKsLs5feD7Q/W2BpNIyWzBEKT0vYz\r\nZwaxJXM589tnmFBO/x3zK4o8gX8OJL+msIs=\r\n=c/4t\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"eeb4fda1ed15e9e141957eb7ff654544abd31b3b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.342+eeb4fda1e","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.342_1670653236981_0.6244931461355321","host":"s3://npm-registry-packages"}},"4.0.0-canary.343":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.343","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.343","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c371d51b162b09dac83e7550e9b60c956f805ab3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.343.tgz","fileCount":22,"integrity":"sha512-e4jGh4WQHV0yCXm3oIdapXUkr/bL2y5ujYG0gY0zdudvs8fURf2BQasJMkWIXVzsaJ6JRnDtbhPr3JccIugs4w==","signatures":[{"sig":"MEQCICyL2zBsoQvUqGp00mEMCxW5sKoeYdID2TWBwDyRDsC4AiAEsulF+uiVOyxueZPyj6sQDPbtdde9N/hZ/0oBrOeXFA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlE2OACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqozQ/+OjdVyNqpPanBdwnlrddZ9YpVFFqmO3FJmSg4ei/fzzbuQcFO\r\nuQUiJBEaRbCF8cL4X0USsHIDMgx3kgTn/kwCcEze1Ws93uZyW9S8TQ8XPLf4\r\nt3i9lLPtpYwqm8poPPAfA7JIPckmAYxjhSsb4ihGHXAVTQFYitv5Tk22b6vi\r\nFIylekRZACy8gUJCUWD1EAwKziOCLo2/zpgAFj1ZAj6JLL214unyeWNvSKfx\r\nYTwH9j/OEMDKpXnL1QF/zlq4DQaPlEIW/9pSm3bgr2yEKipuIBSst3f+BgvN\r\ngudg2cizQI4z8E9rda8GD16fLtp/eB+aNaRIiBZbZIFU8yydEjpi/aIMf/d7\r\nW6JV6zUDYPsfTSZ4C6yBHp8CG6CqQPDBxbMOZTIMyD4GofE6WiMiNHqabNPt\r\ntwwevFU0CQ9DbETaZ+Ikm7ep/g1v+Mmoe9OM20nRzmnBwZh/o3rdHZa5lBl0\r\ncgEJTbVHzuU6AiEVSYbD7lwyKSmboWanJtciJ2514hurIldvNi/XaLqATznV\r\n79zhuAyQndh+saC6XQX2CPJHgM7OHH7aqthyR3hXBgHyS/nQ4D7tugYqaklQ\r\nH6eSNm5KP2ai7FvLlhhc9SraVgnuN8RWSbAuByWVNGUBrzq9Qt/uUW3UKutI\r\nQ/hzGn+8Y/oBt7p9neQDs2Ee7SOx4DqmQkQ=\r\n=swp0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"62da2df8e9734724304a8a013b0f3ca131df60dc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.343+62da2df8e","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.343_1670663566086_0.4641568206296869","host":"s3://npm-registry-packages"}},"4.0.0-canary.344":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.344","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.344","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2025c5b0918a8265c255011f20c067a83af63666","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.344.tgz","fileCount":22,"integrity":"sha512-I0ypi7MRGN3J07AzUV1NMTXcbkbkS6Vz3qezJbV9aPFBMO2W7fFB1rDMYTYF3k82J+VlLuLA5o6QimG3VrYerg==","signatures":[{"sig":"MEQCIB0qgeRTTUcbMXLMgSLeFd5t49TWMiQJ3IMLdKxGyhZcAiAtWaX9tw2f7Xhu7yx17uUEE/wnIq44s2uD7awBVdVHVA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlLI2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq9Lw/8D28sbnsHOxyrTLpAP5W6I2pQQKV6LvjwYB/L9arVPOQzNqOe\r\nT25W74B3k9U+kPfH7/g70Ii9zkMWY0ZiHknmRZKK5PJdJSgOejm8qh3gA0Si\r\nUQiU9cJILAMAUmXKIvn/3nI9Pri4J9o9GNwveCHAzlrbIUo8pQMetu5hC6Bs\r\nywpRBxD9MEx7ezh8kMt7FqIx2fOs5WH7396gucO9/mGVIl29ZVjSX3dAeoxu\r\nBU6iy8P14HobUjxCRqFC/GzrfuiZTu+VwQIn+BgUGB9ZsoaL0HCsugKDc3cu\r\nmcWgfp+80TdjuTm0wUS+KotNeHtPdAX4P1VATnS9mnaeoz1opJrh4E7QZedp\r\nkUUZxvnihWGD/ZI9xD9DS6B8FpKsbTalhwVifcBInOLylVL3CWDPArer/NXW\r\nxLID0YzehvF0GrTJWIPSaIqlbn0TuOtM1VdLz+Zwx5qwtl8/1T51fkSV27ZO\r\ndpZubcafKGeMb6CP85BHRKf3P9cOg6vRhzfma2paIyj3uALWVLr0j+u8E10w\r\nl7hsf7tJzeu8A/29vj54Jbf8w/jUNV/CdEr8aKa5S8ev07uCJD1nYDhK+HbX\r\nWWb24pfN8coT2rBeb2nNoDP9TwUJ3HSOi80mgemdYyKEvAkgp2GPE9xnBMEo\r\nbpr/lanWOVfvKc1etQYVymzulkY5OYCgf8U=\r\n=r9tb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8d6664cc5bf9f760161ae8cdcc3084612d078943","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.344+8d6664cc5","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.344_1670689334492_0.18609119014499154","host":"s3://npm-registry-packages"}},"4.0.0-canary.345":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.345","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.345","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bd9ca11bc51a5e29b2e51d0d9e6eb11e8c69978a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.345.tgz","fileCount":22,"integrity":"sha512-BsOyx/vEyUJhdWlPQ+CHS1iXAAe0wXR1ycKYuOX3ZQZMKU3XEYxg3ddZkPBRZ8rhmsDK1NXnE6nFRV2evEhTog==","signatures":[{"sig":"MEYCIQCc2ouV9WSYKSZEfdT4bwL8AsYe8CkNcL8OZxaUsxUKMgIhAL4MJ0bmI6LKqlBx7x9jyHKexqQqZvUKGEHxjJRT9On0","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlQ//ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqlfw/9HNzs97jT7/WdBGDHguRN/N9DV62cSDhAFpgPZxrszQm8u70E\r\nPfSigU4s01TJpfOJSeJu9FihEJEctvhsed0B0hsBK/zbRr1NaxjDN7zlcWvi\r\nBgazh5zUsfGaFol+RoceC7B9rPp0RhCz4J+3k7hkMICXCy2hqmU4QZFXwWd4\r\nD4qImjMkfbyacoutLRPwAM77UG12R5IRlp/kRNPpn7Av5QTcHXA67UZcUSNJ\r\nOY0mFOEMuCalxewIG5Iqermj0jl0cExYHQtWX2zRSSyvKt4lJnc7SLMhUiJG\r\nnCp+xBNxiA9YBK4pEZF/dCSbiFMSua7SNZXA6Qjc+kyPrPJ1QpNonn3gDBqE\r\nHMNdG6SmF1EeEBi9ZRVZVm3s3f1S6lv2/t5GHGrWHBa2LBis6D/f+B0Q2Mdx\r\n+ZUsGi0MF1xsyHpZe+Squ5z60iL8k1xRsj4oGZ0sOtkveqCDqqnJjy3HspEQ\r\nQt0enclpeuWpT8z9rq4eZwC3AyPNkoqKSC3NKfEf20GOzzB0RAHoAphU+y10\r\nc6L2cqT/2kqfY9VeMcH3CR2rdLXZCvzJGxMnnNwOdmSGXg7YsFqxbl/tdQ50\r\nj6kA2p9Ju9P/saqfHynAB8U6xvjtGKDpRxljydv/mRolylItfC+j08fXWoa3\r\nmMxHs12XoE3wtjPhy82qqpV/AIXgrW15/2s=\r\n=d65U\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ded69a3e9362bcfebbfd6b8be56e46441fb52d68","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.345+ded69a3e9","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.345_1670713343656_0.6424087665961684","host":"s3://npm-registry-packages"}},"4.0.0-canary.346":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.346","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.346","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2bf3999795877ddd9910a3ba9b618d102eaa899d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.346.tgz","fileCount":22,"integrity":"sha512-4nei5UCdKBmEAoVfIojKngli/+RGztZ7EbpYMmz0LDiLrur4NnyN/1kRJIfru8PRyZF5crfXPiLmdqFx7W2dvw==","signatures":[{"sig":"MEUCIFgte/+3EuekU6/dq0UHLggXjOG9CDuGnm9+Ei8aIYzlAiEA3ylwhuDo/1aX/lR4Zl5t2xLzLNKtfDDicgCDrynh8Ns=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlSKZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrdpQ//aHiR8w6VhaWCuv4HIU7K8ypbW9W2D6HJDGGxnHY9awowylIb\r\n5Qm/2VLfO+qmXjG8U0r83oSEHY7zmu/R5MwjVjTiDJyMSgaUAmKBrSOM7ONR\r\ncB/apoMVEZTKD409HQjGleHGZlIKCt/Fyd1UtjTevsGaS+f7iw6vggCCLG+9\r\nDyGTigBzlrQmLg3uym8+vRoWTbcto3nmWz+UHEJvpMSraF1CkZylKAW0GcCW\r\nGz/nyRqbo+G+lPjKyK1wAwZCOSrA7bCQXDXkkG1ALJx/VWnFAW1wyybcnrR8\r\nKUXOMU3p5ZFq9QR7hU8BcBs04qp390HR3E3JDDhmvsa/vfO0zAFPn/b2RPFj\r\noj/jCGuGBNcDji5a9WNBmyi6bD03wdqtp298M23DyMZJ2ILI06tjh4kpTuWu\r\n6FsnVblZ1ZeFeGiObB+X1T4GP7ZAkzGB3ZAqshMMARnFbbYw5WTM8W07M+ax\r\nU/rrizqMgXmJmw5R4jPlPKxrIHj6jNFNVjxD9Ny2n0bg3sluCsjxFWBidNYw\r\nMHKUfVx//d2fXIA4VtryEohC77bxx3muYSOWeynUuoRtaIM8KhB7HVHHIrIG\r\ncTQw0XO4M9YUhun7bCA8kwfixZiK+NhpEvxAO4t3J9a0DFbKypNNhNKYRMeO\r\nDxBBNC3K4mIrGFpwg0CIq6q6eA0n77a22G8=\r\n=7aqo\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"871addd33b370b11c21c734eb59e53a9ad7dba58","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.346+871addd33","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.346_1670718105613_0.37547338692402854","host":"s3://npm-registry-packages"}},"4.0.0-canary.347":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.347","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.347","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"46cffeb0f527ff7ce13fb9ff968bd85b0404f806","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.347.tgz","fileCount":22,"integrity":"sha512-doaN3+ESLixxRCvPAXbPP33JsPFy8MRvFZ5k1z3/ahF1Zy4dTue7dxzbmYH4g2soOR8xt96cNHu5gkawqqVFEQ==","signatures":[{"sig":"MEUCIQCu/n+SWgb7AzeLq6GUcHtAQVth4EPaBh05nNvQVgGKJgIgX3qkOundTwfZcUYn0TQfTDKL8Y/UcjcEvHcewEw+yx0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlVCpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoMRBAAkPKpaZ7N58R1Xk9G+RgQRPJoOsn6mEQhLMtWUD4QWi23bIve\r\n/Aok/mogNaHyKXZFLZnS0F+YAHWvpgO/+IWkMT88G9J/x4h1uQDbku4vt87v\r\n7tJaYzVPyqB6ZlJQBxiHbOnjfCcrQQ0uX1TW0NQj6on//lwNU77YnTy951oy\r\nyHMBkdBfOH4Xb4j+l8yZi+xMDvxSjgn6J5z2bUqb3o9fOwq7Jn381PlN4MLK\r\nfXmfANfZEfrNmk1YDeZmYGr3U7y6XGavHU+YMquWJZmVOsjmM6AFkH+QNt0+\r\nVg9feXWvVO4T9qzCGphS9gAQ2guLMMO3lYdHb3k2fx2NenBHO+qra8+QyfjL\r\nNViI+iIzMTjwRpaoU4j8DrWKxcFHaqJCzhU3PdAkUJEkkHwtL5lWvJbfMNgM\r\nxVDKUzgIM8oHls8Ae/c/AmPSSJMR0r9vKAHWyrR4GxszHWi0d/bvHb+5RQ2w\r\nXcERb1beO5t2tJZVJCGhB7L+A75qWv5RGgTGQA6q7mddScH2pgF0+IjAVjz4\r\nZGa2PVP9xBWbXaVyBPVAHQN6wOU3jVhIcHUQbSFU+QRpc0sGDA2YamHsusY0\r\nUQulGc9fJpqy7CD65DQ77c3PfVXwq2nXFG71nxNIT6Gq/9Op2LoOl6ihZviu\r\natDFMVR0ND9KFI5z1c2fwLkLcOuYEs9Gd4w=\r\n=wsdF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fd44ff3f552374eca00d6d881e7e75dd25e6a45e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.347+fd44ff3f5","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.347_1670729897464_0.8688552572674844","host":"s3://npm-registry-packages"}},"4.0.0-canary.348":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.348","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.348","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"05dbe7cb775ccdbf3e6543afe2d56ff133b45c58","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.348.tgz","fileCount":22,"integrity":"sha512-gZKPk8OVFQUJ5m2XATvVGZ8h+I44tumsMN/ds+GD6GgzVtAnaaByD4J5o3TLzRtE6lU6z+dQTGws74mEBa/fRw==","signatures":[{"sig":"MEUCIQC+YlmJldo+YiD/DAoOv3z7vUpXuk4ROYakN8KsfCWr0QIgDS4AbUdXwdbasGE/AJeo1uu4CADTtDCFlNEW1BxHXF8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlzm5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrgHg/+P+g1qaDTmm9c1P+irU2hRMB3yAepYdOVWZ12/fSJC7vBo9oO\r\nYVBbhKkQWNlwIxEK6j46YDyqyXu3YGG/QJ2aDl+/vdpGRAf7TqquB0E43sGb\r\nYz1WMmuoUYkv9hTkpoX/G0feAHuVs4zkHIoQqDMjuSB/afl6ZXxtlENDuGiA\r\nbjuisMDShtrACAFXTuy+NFf41L8rkkjZ8gQJ8zrPyfVJ9HG/exFGR1wex/gv\r\nhLrJEWlwQoPTZmyOVtQhomUHWutcJpKT5NBgt0rJyzL+jmpEpvWmRUDgGZkt\r\naoV3X61xNR3mvyP9O9bYcrWV0HVLjj7FsL5OdRpeKI2bC95PMsyiIiPeGgvf\r\nhbLWo+kBZJg2GA+V1Rp3Xib8P6MgIvRJE0UPAPEoPyxibXNhgmr9kaJRRyhp\r\nQC8KhfaBP6V4H4leDSK3gpNZ9bw72IcUhHgMnOeDBnT1as0wki/GTJOItmcM\r\nMj1QJi69OLMiZ61Tc8v3o2szlvudimJMZUs6Cah9OAkk+GrXw6Fp6jK48WV4\r\nPhUP3mIAr03RAgiUO3p+y1YbiPUSXUeX8AO4wR969zQ8t5mDqdlPo+Ys+BhL\r\noSVGpRPTwG1rdX1pBWwX9zhDVBWSdED6TJm1qgOpZUOn8fnR42Azs1rSLB2C\r\njIaMr58/AZ3GJrU43Eq1H+lXqvGa6Ra5QAA=\r\n=T1Pd\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0071302ec6b0241f47925d480c41f39ea82340b8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.348+0071302ec","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.348_1670855097097_0.8627915477168973","host":"s3://npm-registry-packages"}},"4.0.0-canary.350":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.350","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.350","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d949bfd6a4f12cc1025a5aace6f97ca373996bb3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.350.tgz","fileCount":22,"integrity":"sha512-PbgT6p9UCbGtOv9NYAc6Qie9aCHBIEEaDa0bgF0QdeKh5EHDAjWxoSn3xuB8j670fI2GMz8SRhbypLvmDF2Bfg==","signatures":[{"sig":"MEQCIDYeBnADkZM1r3QpBwxez97cJXYFajMl38BvsOsZrPYSAiAqE2P0g0ntNKmEZD8j5bc5q1aNy7JChPImwHA+Kov8bA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl3gDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo4dRAAjHrTKeRTg9VqSZ0FHuxgdy6YUQG6LEqLr30TWNe+8jarqB6F\r\n8qQRC6IQyvzzRnDqk9uEibMZhjZSHdJvTc4M5/9ZHz7yUVuBJQO/dob+wIXx\r\nttacDLl3qRxjpd7WwKdqeb58LXa1d8nXvYnYMZVeERRUk/tRuFOu2fV5wwgf\r\nVr5P83ocedH7YAWXNJu2M+8FUXYzwz0M17aQX37LvK/jmg1RYXYxxKTRHg+/\r\nqdVsF7AKPJ912Sp1E2T5htkUFiB4pWLENwytrvOcYuN5Y3QFsqX5DdICRj5j\r\nnrTZavBf/6/UYBQAcSQjWO5lFOQnfhd0mp4g2GoiP4QVbCLVQeSjfbEDW5hK\r\nyPTYWwtYcr979bJ7bZbwf8gLI/MGi312YUN/gb6xZG0vmWB86sIrAggHUocL\r\nFK/6tMdoqJca3qQhmCKZbdX5qwGXEpnBk/xrjBfzXio7BoOz+kRvScJLSlW1\r\nYLKMWPTuLmdCsdO3wuRnmSjcRMZL6ebD54XLnIrtzG2TBuc8+1RASpVKGNkc\r\n9zH6C2IbuknGSQKQjF4kkFUTd3rASz0EweJhvA7JOuv4qElTH6QIcW2ztIAv\r\n74qmcRqaCQEbPRRxSBlSOFrArwTziAYcHA0Fw09sMMUeRvC6u2UZNpwgWkf3\r\nVWdrad7JPhpPjR9u+lZFAbVWm2eJ4wbUOkg=\r\n=5YTT\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8de7b4460fe8b81680498a98b1c90c822fd1822f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.350+8de7b4460","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.350_1670871043214_0.37435171909082765","host":"s3://npm-registry-packages"}},"4.0.0-canary.351":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.351","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.351","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8dfdd0ce0809dd2f6aeab6c2356899ec6ea9d4dc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.351.tgz","fileCount":22,"integrity":"sha512-LONjiftL4Fs8NXOLmmF92+M5X93ykVTs/yRzLG3eucivlmg+3SDcg8TPre54rQi56GPBKi/fQe6Vg1CT9c8ZsA==","signatures":[{"sig":"MEYCIQChyOVAy+6C6eDvx6hct3FnzUzWdCAlwrtPsoQDG5YCLQIhANMpmZhk60Wfy8tT6Zy1N/tcllQRu9nfAsZu76d8hVhR","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl4rmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqKEA//dyT22RhXo2lrS7HzV5q057qt2oNzhgWR5jwJ6evi9C+dm7Mi\r\nWGh+c8bJKzkVzOJ5dEmFcyuk0IL7XakEIg4Ip1pZjD7omyvZQKbo7qko7jDm\r\nn5L2lFGwDBAAd7F5p0t67EIIcl1STdKiLeAUc01we86DxhVbzs46nm+wNvZH\r\nB/BIdhj25HlyAiuD6J+PBQFpL7K4xv1q7WM/PpKN8i9CVJgvmf8EZf+wP8Ae\r\n1DOOTxlEWVGvfepZR8zAxdT12ZW7ps5j01ROcSPhgJcs+N7dZqCneQY3WaJ3\r\nTxaCePIzGdN94LBWYAFUV7BHCnMoPMWR+t1m6SbNnNmeCYA6OW/pWbYXQmVA\r\nkNq+3ANR0dG4seT5+DivrE9FnfSxHUZSubkv0U83CspZjtje5ns/5mSApMjg\r\n5+i6NZ4XYeC/ZJ5+Qs2P2IDLCEgu1qUCq0PeanEZtETaWTdCWv4Ak2JZc02q\r\nHpiTZ5SPrTXb1Aj2u5IMUn2YW9JhLUMhdux1aTa7Jnh5P5R+L2U1l2yYX7Q+\r\noBqbu2z1zPOg+B8o8SBFisns8x9NkES0V5X6EikOP4c9xtNQssOGf7oW5j+g\r\nSVBMHZpxnSYB3dgUGin6Vghc7/KeRtEnMXXo8EOlm1aGSK4xzt/5rzB56fAC\r\nooGhJl6V4HlEfSwVlEa6A07u1Uw21SJ6pLk=\r\n=6ng/\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"df1b410f264710cb7b4a1419d04882cc4f0a8441","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.351+df1b410f2","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.351_1670875877978_0.9098044968909864","host":"s3://npm-registry-packages"}},"4.0.0-canary.353":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.353","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.353","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"58e1ad0757b9e36b575a307f5675c5614ec3871e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.353.tgz","fileCount":22,"integrity":"sha512-d/SYz8yNB+omHOi8G5TBbjJNq6bfLVSPVU7SmZpwskyjsW8AFGYw1V9idS6GkPDEmc+mzSgw9YBl6RYWRdfRUg==","signatures":[{"sig":"MEUCIDIlmqAjNdMC2m1sDcyKPgoZ3lGoAvfAgWwV6M8WFDK9AiEA+vI/WmbV2GSMD0EUyeFfeXKYF6ep515GJJiZR2n8w/0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5lNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrxDA//a2iaNvrUHfnzrJKw+iXh7C7F12yDvDV05pcJTFbZKwGpDy+e\r\njpia441rFxfGLafNnzXfVNN4kXVVKVnNCThuSJDU68Rho+fpcsYn8vjvDwOI\r\niPh+Afehn1GbRVk8+RqXDXWn7zrBf6OpW9oALkiI5jy3DtGU7t0qI0ah7rTr\r\nvqABrrOtRqAHZZHcoBDTk8W1g2DKLC8n4FOBcbBJ0XpRNTlrJ3UbKQPhstKJ\r\nd+I6WgyPntOiSiM/BZGRtJHvpDy7209+lE0vLD7CVN/Wdsp8TQuh7pSHKkLA\r\n2b3CSiIAyeYfMCGyNTjJQ3A5YXBVqmliH/Xs8L9ibLFzZGd2h1OtW+rPldcK\r\nkuzqpiJd4wvqKxkc3EYkTPhEmXyIRGcJ3H7fRxe6x+i3qZ449bXGeh//LCH+\r\nLJOBKmIdgmy/Zi41XKRsK9mG5Z4vH/GAG5vhacSiUzkGkw+oDt42kI4rA+Uj\r\n3o2jQMFhy1YMX0FueNi/+EN1hjPSvtZ43wzwzcLwN8iRqze4WAH05IFOAaFR\r\nSEdkpbJYqdxSR4HUtgipfpVHW62j77yivMQckG6ZhYFt4EX0sK7YN8D/pvkD\r\nY+LXdKsxpIB+MFXL2kIGRSmuUhnb2ufm8VRj+7+L6u1VbUGrF8aBiOoCPS4o\r\nEDXDg8B1TSZX17VyqPHAO4A/NrlGyPp/9jM=\r\n=7ITZ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b98b2a7aa70e091560d93a77e0d8777f4273a276","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.353+b98b2a7aa","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.353_1670879565342_0.5710402847338008","host":"s3://npm-registry-packages"}},"4.0.0-canary.352":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.352","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.352","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5a4f6558464b89fed0862734cd08983c238ca8e3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.352.tgz","fileCount":22,"integrity":"sha512-M+vaCJBnYJ1AYg0Wsgd6hv66NmuvqRWOgGyxNMTYZSEGcKl8pvPz1h8/+X9l77A9XtJKl1TjvlW4/M4wVQhBZA==","signatures":[{"sig":"MEQCIH0qqNKv2G34TOyqhShR7VhWDsJS2wvFPRZYOE6KbSuVAiByDwbjazmo1DL3FtHT5WHXM3tzfBo1f9J+d+C/sIXjuQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":127947,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5poACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqqMA/+JnRInI3QI/G1x7vRw5Hf5Mrb8VaKtITemIbp9O+Oh/xMMRVp\r\nlCKnD85JuL6dUHZ840y/Ppm7eeKcLHVH9ltPWz/wOou7D1DVHeBOJMYraxE6\r\nFHIqkUYPsE2go0gqNoVwiJNVyE231FkqMP8mCuH7hZW7/pV3c/gE0/dA6GCB\r\n15nbel2gIZwFYLv7Q5Y+kZPxPBfIKFoRHKW3ED6m+HJXeci0Yc2zG7p7uA9k\r\nMCsQhM+CWXV3+SEVDLQpJSuohyVqUtWkqsTSJT7/M+y2k5R5eTzAPOwaOMQU\r\nGNnTbWjN0bKS/ZuOju5wMta85jsVRCgBgOtSdVkYM37K9+hG+e+fHpbCel2c\r\nkHLeFstMpERNpMiQtn/70pA4Lc/rWFYNT2PRlDVHdOoDVD+8dxB6mwqLIe9k\r\nGg7WTMiOWmunX518GeN2ZFG6KzPDEhV7cscFrVa89bdLKmAdeDEMZAVQ+jLm\r\nMGuGpk1/0xOSullTxB/l8kPhYpa0PQI5z4RdJqHwu0jgPGhJrz4FJ0nffwJk\r\nDQHaYLjmSYc9pGeZWDCO5xCm9K+GbwZvl9pcC3VvTxsfXMdfyHfstygxUisd\r\ngf6iugN14OLaXznZyIuMK+w4wD3Iz4Wr+RFGvT1ITMQ9/BVdrdUzPe/vBSrL\r\nEUV6+TqyOcvHXqGHYyEb6I3Cf+xhx0vSWCQ=\r\n=NlXB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"21b6b51dd0e38d5891da1fed8e7c8ffefcdc3d8d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.352+21b6b51dd","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.352_1670879847798_0.4922785485689287","host":"s3://npm-registry-packages"}},"4.0.0-canary.354":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.354","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.354","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"aae9df5a5ac00de3e1efee23ec8e333ea8fc7f78","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.354.tgz","fileCount":22,"integrity":"sha512-p81M15dFf30puWGnKCOeshffiYlXwshJvamuGTBEO7XVZPJ/YQL4dPnqE3mRRokzLwHYP7dzhNfsK//9Qtd7fQ==","signatures":[{"sig":"MEYCIQCrUgteBnL6P+YXontlu2gPEkEKhee5ccJjI4U9mkUkoQIhANxqbdVSGNwku0+V8AeQon5/qHN8vh2puSYlp1iXHjBZ","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5woACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrpvw/+PsvEt4eZYdhYaFnLT7zQpHLq4Eji9KUjA1+zKXF7CXq8RIpj\r\nJKc5XN9dGIub71pxZl2rwiVlgUvGoYl4rskZp4BXpgwTLfLiPlkvPIvd3k+S\r\njAEzwwIIq+3IKbrEKy7vg6w6zAsS2i78Gz/wJyX/7hPxeqyy9LECUmcHitYJ\r\nZOzpiVQXPUyVsaCa7qiPKVVymPtKHiEndZWemXV6COvK+ElnVHOi5AzCWcYo\r\nnum2v2WcsHh0kYGceyXMbl5K23rLUUlsRvy5EHOrdqpYL7LSZuk9Wi9+FLNQ\r\ndFeuloN/KiRbowxcO2hjSVlYLLYKcQZqsknKczHJvNNgPKGitlLF6SM0hlt2\r\nlL8pjMrA2vyF6mTRXGZMkPqM/68UHJoQRYQeoEskljZx0TFMP2emKvuXwCdY\r\nSPOyTCfcEejZD2fUvZV8/hbfj+4RquDFmBnsER/fWtm7o6CcO40AAlnrK8Ly\r\nVrtt3RwmpO5fBJgq7M9GNRzU1LhN7Qchp0aaJDZc9u6QnegbWOp7B0+7tL88\r\nc4b+2AtI4SU2EYfMQZdVs2xmVKOHieEWpFjJM82EU+IlTcKPDmxlNtPQa4SR\r\ndB8hqg0MP06gVQWR9A7nnfVh0k6+wO6jD5ODNwFYQD3q9ihPWUDmQ68IDvQZ\r\nQHsw337KktvPITTrkK/slgwbR1AuU4VlQ/4=\r\n=+DNE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a9fc646485acb068cba2335d1f64bfb16842edf2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.354+a9fc64648","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.354_1670880295915_0.29773120425181854","host":"s3://npm-registry-packages"}},"4.0.0-canary.355":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.355","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.355","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ec404abecdd56238ab2e0f73a4fb6a9e5fd411d0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.355.tgz","fileCount":22,"integrity":"sha512-n199epRH5XOz1FtZKmVNDh3zLRWd4Hm+JRRDrc26uARXCjdNWFGLGtkLM8kpQEjWbFlexPc/YOAki2u4Q1doew==","signatures":[{"sig":"MEQCIGuBbT80SjyetGfqQr/qTicceBJUx2vULhjlH4Bgjb1hAiAJvkOpdPaB7TQ8vmub3Xmv3nvMdiXTO52U1w0c6WtEqg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5z5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpJPQ/+KVQ0C7A7UiSpivnCMDs4jsQAoA6dU9VQTovUtGoXdo8tl8yF\r\ng6M3NDZV4DgsdAR2NEey5zrXOP6CDOA2VFeuVs+9Il/0j7CIAE2HgHMSZeCc\r\nULcLiV/F2vU/DlA8RI2SQW1PqEqKsGdMb5siI1EIdG0nxhLZKKHpW8suvCV9\r\nHqj0ZxArr4nauVhypyJtqVzQ704DfO1M9xtKuq0PjwisZ7NyKsQiJa9Bn+zu\r\nt0rx/TqCqKC5Yalu+gvNSdJKW8m0SaKxVMLZNUxCmjnD49J99AdsYonCnpGt\r\ntmGFwCixwpuEreX/PCPuDy4F1IJqMJKi8c6nipMgEbsYQoQF3zTnvKjDSQDP\r\nqkL2wyEl4EOd0tH+aqJdCoHHHNaABvOMn7+hXx8ddu5eky6UF9NaoS0Vdc1h\r\nBh40sx0CHV3Z9ZptT4AX8/O71L4LsqP+C0f5vzk7t/8qUACZmyd9oABsiXhh\r\nvYvOjpD18H1n6Wd6Wl1sBhwwg4oYOpSuVAd4bPQysz78h4J/p+jCL4lHs5qO\r\nRSZKjB+iEcW1wPRQ32iiRAXapvrxh7AwTCm4T+omkDOHbYjdRuo7Xwo227mQ\r\nm2CQ3nmluzOYiaPY8R0UOCYktLLh/5EZSmJguXjadBgf2gIVPPbWRGORU7K9\r\nQdFZQYVQW8HjzhAg9c8pVdP2wmqEbrINL2k=\r\n=+rek\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"05ef6a40caa9bd765659f842d23ee0e267c292bf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.355+05ef6a40c","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.355_1670880504741_0.47052214413723403","host":"s3://npm-registry-packages"}},"4.0.0-canary.356":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.356","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.356","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"21273209818a0e0abe1d7c5e660319ba9622e789","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.356.tgz","fileCount":22,"integrity":"sha512-nK7fVRkUnvzwEo4r1tBqzEtSr6oP4pRpuemyEXsrC45cwZrT4lRSjPUbVEJfoJsJYYvxTfzRheiYBsCBCJRUaQ==","signatures":[{"sig":"MEQCIEMeow6LGw25MoXQeYgvN7UO44LgchU9RdD8/FgTEu6bAiAcpe/eb+Gdet0/BVje83thEEgImQ2jeYwB9vMRz0JqWQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl50NACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoARBAAjTrXmdKbIDHSGNBSS/VQPvp1F2oaAlJ0VM3ofYVEV8n4hRGw\r\ntl/rllcM+yBz3sGAT/68R5c8Niwy8C1htVb2EmNhJJmeDQi6c/YSwUbrha79\r\nocswBxP2Ii5bXLi/zBReOI+cmVRoBFn12W/ubtoP0rK7WupDsweZ/yADudDT\r\nyobCTVnntkkB5P0yYvXIEjZGV4JEWqYwdQ27ak9XmvJR7VHZGLDuFE47NIsc\r\nVh4NOn4zD8BJvsvXPqyQQzMjJ9c6wp9vpRCedGXir5zDmPez9ZN2YVV75xdY\r\n1lIGiBkeU8MplBBQpkfMMpW0igU1qg+h4IBDhZlpRgvAdya9DHL0nVHQD0GG\r\n+via7vyKykg42YR3GwZjRG4sMUytZODVpWYJBRXX/ZngpWI9JKhASb8+mte5\r\nb3c5xafmvuBJYuY26hsQ8w+PsFDPGbo357ywG9YYXR4K8sw69DPFhfA694+f\r\nscz+7gsWSuWD1R4U7K7LtNZ/EWDyWRXxEpWzJqkVDuLatoJY/TrwBN0ZoRLc\r\npPy+a43TETUVmSyK+rVkfEWAfjPwez4PEG5NWu9Sy5iGTHXVDQYjHtQzBGMa\r\nfm/mqMH1yep+tSYWPN3q6hjKNvbZJ4jtTjKocYv/KRuRaUUJFuFNoELrgj7G\r\nHtMXts4W16fUUq4vW9wS+/h9kHj+93DsA0k=\r\n=FgaS\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"256cee55c7124571a9d243513df4939ca30cb57c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.356+256cee55c","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.356_1670880525462_0.33697945662127204","host":"s3://npm-registry-packages"}},"4.0.0-canary.357":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.357","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.357","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"64aa9068746f6b32a94e97a0d535eecd67ba54b9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.357.tgz","fileCount":22,"integrity":"sha512-+CoVgUG8j237xsCwxW/kgN0xzFwk08xy5EdDD+LUTnANN0HUHqfMRDUlOF4YSJjLWTmRrJR8N6+YPRgEQG7qYw==","signatures":[{"sig":"MEQCIFIeNIkn2FOJ0CSKpJxdPryIc5r11875uli3gNImN4RoAiALK8qOKzH0kBpnD5tlY2bKa3DRnYve1ivCozofJOT4TQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl6P7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqFCg/9FhBcIXEjFuqdlB3R98sxXqHROX1wvv0SCwVZ9XJMxRjNO2RW\r\nAJhw5tUgJO/7Z5RlwVOe7BSMjBsgC7c5Ogf5jqIFKhYajDde+dRNoeowme6j\r\nURWRG7KB6l8FC1FjU3kx/7yuLbv6GGuPWLahCf8dezoOdhyjpHzHldwBLB8g\r\n3jcpIyptx4StXJzVNhl7n+0S8lPzg2XVO2lKgMRiNfbMNaSK+vUgG4RUG5/W\r\nJ6WlVYM6VewtzJe0SWlHNwGnYkwJ7omTw7aPtcUC60PZ9j+3D3yobYI55RD1\r\naNyal34OQMDAhWzBpvCrMyhM0uNUlP2v+19KWD+swmw4IxSchaSbdM/RZvW2\r\nDgLqGRMO+cWFLhsu1NlXLuKxMEtoUhG2cAQUWwDjp8CIMDMUUgZ7HSqNV/Ry\r\n38oZrZ5jbG9owV7WFJE5CNj5372BsePXGQ3XfOj+zj5eYZFtt2bfOCZO3FZ5\r\n4HNyqIC72yYV8R8tgGwFXTTtHG890US6BruegdajG8npKr8e0s1Bx/MhnOYz\r\nAndX3L7O0wGgoLSxWhzQ02+1be7p23qwDExXDDTbnT2z41xK1in5txWNUajy\r\nXby1t/+GsZfSPSk7iVFfuGkhy03fb68q0lH1ukFzN0FEmDEI2i0luRy6b4NJ\r\nOIflcAc/5gV/xF3VREaCjRPSnlD8ANjGE5E=\r\n=dDWM\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"58a18fd08a30724d0eea8927d9408e75da623ea9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.357+58a18fd08","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.357_1670882299273_0.15666966808281102","host":"s3://npm-registry-packages"}},"4.0.0-canary.358":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.358","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.358","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ee5e1d2aea68831bce14863ad04bfa8826598aa7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.358.tgz","fileCount":22,"integrity":"sha512-JARozbTy358iWL2HC2jcYEOlajkMdYHBwNes6havWxy8Xy04jtYkT1wQ2fMAjBg2VrmxCcvwYOsE9EJCtSSwMg==","signatures":[{"sig":"MEUCIH7zHohl6csfS8DDt/Ma1IE9d0SWkzd/Ln9R0CRR0rWAAiEAv59qJBENqe5zTGcwieE4RRjMPFsHaW1V2EFVfQ1ykbM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl7HBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmokbA/9F7oP9O/9nHrZSeBRpO7EdJN+7jyZQuLTAXTK/Hxq2Wvl/aeQ\r\ngriwEyLY4qChn4RKhYidYMOUubUuoDuNOMw2VgxSCHJgPsAuxnlgjuoLcKbV\r\nmg6Q/nV8OBhm1ng92p63fSuDrHb9uvddqhXPmKaPI9oA1uAvHSw54XVFZjwn\r\nry9tpsc3Hyn3MbCcuQJnE+sRDw5k8HICXC85rGbr3PfMdYRPzsEnhpuiPBZ8\r\ncGFfim2oEEhN9kK2wonEh6oiRo2gwzTBBnTO/p2h9ypTUv1fKCPC3fmE4K8j\r\no9qkQta0tcvCZojskIwJXziDSVnhqGeENmyiFKSI8mZedRwlwJwYI9VWEkN5\r\nwfn4/CueaAr15sK7+OJTqRkNdv/a6IiGLSKKu6w/+11OBWCKQGELjh7yJ4tq\r\n3uN/yGF/G3bKMPPtKcMMJpR88zQYeGT9BsyuiiJ5b5+0VBMSTRckkL0+Pudt\r\nojda8gKgRIVtNFuSrUohNvb8HufhX2Ja3Juu/s8mHnW2D9zUFRWkI6U8Fq+b\r\nOy1XSNQwStD+dp70Hha/ceeBQ/JGgxYck1Iji0BuWw7JAcsJVcKu24y7WuBa\r\n0N9l6Yg/KSS9oy5E70mhgIh3C9frLLkTlUZagjmG6LluaHufBT+YjopurMaj\r\nXivz0VeSWh3GnoJAxxlsjd5Q+k1+VuFnPG4=\r\n=DQ8t\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"bdea4808f42115957d11cf86fb057118dc733a3e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.358+bdea4808f","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.358_1670885825651_0.2737105480832078","host":"s3://npm-registry-packages"}},"4.0.0-canary.359":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.359","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.359","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e8a17c973f53f2a034a2447e6b46e6a53c2d43bd","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.359.tgz","fileCount":22,"integrity":"sha512-XPLFjZYLWjabe18Fp55LJ2wuATgRwB5A/SP6uL+dNOVu+JkqJHE8lsZPUV3mgakyoYnQwQyDNKxl8Nw+KAc3rg==","signatures":[{"sig":"MEUCICuE0EQ1b1MB8u3f59+F+e2HWdJwWbOBFox4zzQ1QpqaAiEAqWaQuLsWEMCT/BUMvMctGEtBrcDPVbkwCF808fzaJjE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl9KQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoUfA/9FRsHmBeUqYbPmXF7Z5ZdYGgV3pq9tUDuSP/Ri1k6w2tq78cs\r\nMeoFXRgjVBYWZOqQ9pMp0Tuj2CzqhYRadD+Pkk81sGcN4dUP9OiI4RTjXKZ9\r\n5bFtyn7gxefnyFLBbwZqZQinE5mKvXoAOC8/ymU+qln7/PX8Kvm24luiXKID\r\nGcXDiGf5MOXhZcWcEIFUuZirWLK97n/tHJuFGFRe2Q/6Bi0bnfhJ9rntCJEu\r\n0vsOevvfKMW5tRLQrO6G3Dd4cWVD7kl4o5E5oFFFhWQIqujrAB3e+Sv/+/Z8\r\nMjGebqkHotwZ3sA/RMNt2VkB/c/Z/DRtRpE6u2SeRN13cvl/eRnHxrPO6kKc\r\nTHgkzjowjzgNb1cpijTjzrj98rThZLV9/0sxBVnfZSS0u23OI+BJjG7yzVQs\r\nlaTCllMJUseNVs/5xOQbaH7PRM05oVaxdLF6pKOxN/qwSf5wcG15EFCeAcga\r\nhNIzWpCLcJZhlIb6HS0l8TujoaXRRqBrYyEJp/fUCXghm7YB+/o366DMzD8m\r\nQo5rh6IbVUGuIFJNcVELOZ+KbJ7yQzsGnqB462Oj6FI9D+CCsNTMbI7YWkpx\r\njFOjQi1mAO0Act0bTtNQ5zmhGgp9ArfPiBkSORSGX5W7R9Kr5Kahzdt6M9us\r\nBk7FF81xaevXbc27PoZ30OiFGLnjpQg7NbE=\r\n=sOhP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ef3600d14ada83c0265f52f623e19b43793562d0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.359+ef3600d14","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.359_1670894224613_0.49956888959260315","host":"s3://npm-registry-packages"}},"4.0.0-canary.360":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.360","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.360","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"dd03e94e7bace3ffdb154a5adb11f7a53b385467","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.360.tgz","fileCount":22,"integrity":"sha512-MfJVjnwjNyr2EPhOSseqJHFIPAhcmfsBp5Lud0DrWuuhlW+helHTlt5YjSrI7y7k7+2zZZGKtDLFb8LpHxchRw==","signatures":[{"sig":"MEYCIQD5OSo2eU5Bvx65fFyg4zf1VN/CLaKkh9yOB1CcerjRVAIhAJ5MmCXnb7O8qllBo27CsNzjQ3UOkcSV3jS6t9b2fj/n","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl94NACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrpTBAAj/esUS95qXxYUoqFeSWMzFiOdZeYis5KjhG5qgEWh4/pv4Is\r\nybhkPYnkTYVL8TaeeQGTAP/nfaMgzEKyvOSGoqMB0cyO22ujPuuNaPFGVO1y\r\nD466vX2r33Iu1e4LrXAUk7QZUDRe0MUg1zrAL0Uv2NPXy8Ix1lDsQ3J3hvJ1\r\nfgV+Mm/0DBFEdh2TlzzpWgplAlLiUBCtWsLGhIckkmp3xcOvul9QrfXxgEs4\r\nU22b4KQEbTxda8YNzJS05W0XmVb3oQxFuG7fLPKTBGPkBor1FU4EOIHc3IC/\r\nFysOFdpdD6RnrvLncY5Hu9JudwNjzl+I4SM+QugbZTmwfBzHJUr2FXfHcgtg\r\nhlilYtr5rAt7xpPAcBsk62Axamt9H/w/Z8p2EOu3n3dxel5YVVEQCRrQDEkh\r\nJAkaXrXk/yi1yeG3K/1MolH35pvNSQ1f9m6Qjvkc5c0Eef140jZ9Qu926gMN\r\np3xJKoa2dzWDghyXXHDHXJC6pU6jIDRBNIeht51IYgJ7XIa1G4EgFM8wv509\r\n4p5GNzl+ZH1/mK9mNdGqZw+RlRq0wxEaQ9Uk5UPEzD1xHD9QAeXfv+aRTN3Q\r\ngm3ud7/yyAyElV/FFhfnIQ+dcpiAqE7cN5Mr28PvZuHk5D/Hh6ImVcHX1FgS\r\nWZj538zdmptyvNg1+RuMUwvIW7RoJ3gQjCU=\r\n=KqFa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"51d21a00cea4fc1bf8c5e0dcc20f4cadb0d809ae","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.360+51d21a00c","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.360_1670897165361_0.6053495390792645","host":"s3://npm-registry-packages"}},"4.0.0-canary.361":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.361","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.361","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3ee71c1995f3c2beb963968e500f44e9cbc14f8e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.361.tgz","fileCount":22,"integrity":"sha512-8I/KKrfpPU9FpyXLCCyjq0ssOSVGjZVGkaTHfEVSnkXj8LxBWEOGwyIhc8fj96N8PfYH73Y0GAIyesFHMMbXtg==","signatures":[{"sig":"MEUCIQD05uFUjRorxEioVb23dz225QAcWsJ2AvGKax50qYqDdwIgDmL3vgjVCvLVpVIVIJrKeALOXNNXeQFvxXklIYdXJWs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl/S2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrsVg/+KFtcvLmUh2KwnQgyFoMz/tLPUyN1uamKGb+mT3Z8YC7Vwd4n\r\ndK0Tx0NuLE7gYn9jx/4qC+mqfxG9Q1PQmSXsxBerrThDwvamWCFr1kkQiTYW\r\ntRGv9W6mwPIHynlxB8jK3Pgx4E1UHyeQ9rq+MJ4/Qs6UxKzp1YJHdB2JL2qd\r\nc9LUJmWtHv/I/AIhhME9meMgLwgekdhee6+gtQOPeiJeFt/eG+ux/MARNI/O\r\n5+IM0SfqYCJcgeuOndcO7/a+gYGivtK4sqa+5RDlSB7YqXOeqngJz/7lete6\r\n7PCEvGmG1GDBAjHkCb78bDbf3sSMcBKMgkwGuHXiXNy3iflwPkIIL2fibrk4\r\nKyGXNjLOTTA6Y54CEqZrL1qnY6M+isTfg/8XHXp01VjDTmwiaOC6hNdtnxJc\r\nA82rNCt+nFQ9ei8LEjOzrkb5z518OY5Qw0VfBykzB+d39mRb1RaZuYOrT0pi\r\nJhu7Y3O/IGnL8gjDJXv2L03azxx+pJJ7M5BhvxOV+DdNsy+ajqHXVd4JIl9X\r\nAKwoSlx1BqfmXIga09XKHSUzHfaA0GMLdELTHgE69qW94NZ8GSwHPhIlqlZW\r\n/KnJwNUuqGMbWzJrmtKW+2Qhg1qchirlGH+y2+3hITo+Ex/r5kUcCgAER4VL\r\nJinEHzuQERinrw0OhgKE09eEpa0YRtTwkZ8=\r\n=MIPY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"680a2b5a9fab2318e6a4a5caaf47bcb4a4e6d136","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.361+680a2b5a9","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.361_1670902966290_0.7936938899243591","host":"s3://npm-registry-packages"}},"4.0.0-canary.364":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.364","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.364","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9c29a3d7a4dfe1336e75d9fd621b0603c144c47c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.364.tgz","fileCount":22,"integrity":"sha512-oFI3582gAM+Odo6WvwMOwA4t5v6lHn8qCPAkOmdiXJFLCJPOS5G+HEL0T/Dj4K5AY6mZx1uYrjgtpzYabb0Njw==","signatures":[{"sig":"MEQCIH1IcjV8azyx6j2oTj9zjBTcFmBPzALmWCUqHrppH2dFAiA4cJOcq3DCFGhOSxOhO11im6aMy9HZvFckwFCYnSxSpA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmEXjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqk9Q//Rp2+miUvPaVn+KMV9dqX3TIpprpc3UL8344pznRb9JE0L5aV\r\ngvolqILdQVWPCasM0Gp7oAQbKC5iqJSCIFBn5aNWUGGSCuNXPgviyBAXL9mS\r\nm7trKOYZ2EbzyWxcT7QCtFpjBfLL+GhppCfWQk1bMSsyZe4mZ70qhU9Bu+j0\r\nlXyvC8R8vLaV2aBMvtDkw8SSAtoy80IQmdnkCd68j4JmEEGgzVOJm3PS1mwB\r\nAY1XjylbwNp0/6GFvHC3fmIIszwboVKGH8c5/QeCGpfIFJDuEmfVxRDhfR8r\r\nlCpLbWW0f9Fpjkb+2JL1R9ZLcTlCPeYW9O+2ufnG+OiiJ1ORo9P0YLWjxkvL\r\nwb4RZvE29NX4FfkkI0frpKn89tNyI1c7Om6H2QRsjS64aldjKEWM5osndSkh\r\nIPa6v9n2XbA8OgWSCacGPqwPB9k3KEZYt9oAExCSejKhKsNVQB76Bf4jO5FU\r\nS41H5RCxLhZ2NvW2QvCgI+JzN7cZm+nOB/t+7kBYoNl/NWmmGjfZEel8csP4\r\nh9uKrvL/5Qc8nSY6uufaIRhTkAmcZyt+7hDDPOynZ5Ot/bkq04l22V/56oPO\r\nQ4g6IFQssTp34SFxgg61nd3zv8GLjIdWxgErITzY44ryN0df583mA0XQvxWt\r\n/SfRlTeUABaIkW4zUXffaMhl7j3C4E1rtdA=\r\n=Mgc3\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d7e7af355c70bcb56f548e93702ed33b946a9418","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.364+d7e7af355","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.364_1670923747777_0.035035430667311074","host":"s3://npm-registry-packages"}},"4.0.0-canary.365":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.365","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.365","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"52a04cf15ff46de8e8cb1b8c001f786710fd2779","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.365.tgz","fileCount":22,"integrity":"sha512-I5EQ7AhgxT60qL3HJM6I83kz+NlSirubi4vb676+niFXsRkemPFFKN76m3oVPX3O1QpniADtkIXValT6LRg8wA==","signatures":[{"sig":"MEYCIQC7vxGY72gUGRQ62o5fUIIWPp9/t2adHqIWXrJSD2bXUwIhAJUFe+vc5XMnMTuJQsyENcOMaLZMht/QWt2gv0pWBsSw","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmHb2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq6tA//cMxce1HqdWbwHcBJlvlSHFopeptn+RcCtegTmhoVLgf44db/\r\nAy3lfnG5H1Je0n98ieYki4IZvnkDWDSQ6LBeAtdnnjeu2uxPjqbcqkaAL8m5\r\niZYG/oFN+4w7TasTvmJ1SFb4ZKXI/pB5nG0UtbOmTzqFqbmK9N1uqjsh2SgD\r\niIw0ZirYlwLC0mdHyqovSFvWf7ENQk8SOHTbPZPdfP3AMRc9xt0APKlu6oLy\r\njeNQ4P1zY7WuDxtQuU5PvpOlDZeDwsff4/Ha26zm6BnUlTycaXfY+pA3+5nJ\r\nK2iZcheMy3fMp4TDILTTQFQ5MC30nvJsnmk3YIMV8KchFpXsa3cnq3zb3GUg\r\nCejJ5w6CV5qeEzyVC0vNC84DcCeIQVUgqloWvZBejngwEwTaGOJpjcJjjoXh\r\n/ZVtRxjGEhx6haqfGn1HdgZzQRN3f+Vi/+ZSVnUltB3qwTJYbd9HgKzTHHus\r\nY7sccKaBZcpp99YBrI/IjlY6VRqq3bMIKQQO/iQZex2ni4Dd2T0iZhBY6/k/\r\n3RG2n+MMLr+UlMJhAShwN76KgwiPii2QVn9C9xpdqPocDyab34zflqey/096\r\n7LspoqTqDT4mViY57sF4LblWGH4odBlhP56FDqO7ttW7vZ7LkADUBTtq3sCV\r\nAJGouHrdvKDLdzJvtj9pI7I2H+0YRDeVAPI=\r\n=1gMB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0cf872dc32a525a4449dbabc23745a8c11215746","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.365+0cf872dc3","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.365_1670936310268_0.9706765119110459","host":"s3://npm-registry-packages"}},"4.0.0-canary.366":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.366","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.366","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"338c68cb4c82ce0467dfa747c96c15437d4c9064","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.366.tgz","fileCount":22,"integrity":"sha512-3TgypPseDCpDwxMbHTdmUOJCt2BvuW5fXLiyCr6SriutfjLjRcn6PhM7Zmjpr0EijmqzNozxhPYHTZAhNN/CTQ==","signatures":[{"sig":"MEUCIQCpnI+IKo/Bcc/5f0EhTde4cSbiGRWQvWb3e4AYmqAwVAIgNJE9Y9xGkt4Q0fbvHx/c0UoY2ssxzqbs5oEV0cnk0m4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmJzPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp77w//UhrMvGETkySDog7Zh93kJP5KRLj1yZLHlb2XN+Iid3YvKP4G\r\n+Nl+7TKtjhWn620jGckVIz1uC55SwjHjIKeJ+UEfU+01rc+THOc0SbmylIsp\r\nSyw2J7k8sQKjGVktVagJh4J1uvBryfGwddw4hcwqBsoXZeQjBx6i5A8Wsm6j\r\nY7wAp/NAJALvwbVDvSG2U5DMR58EEja13VWDR6QdNLUqYD7fGn5xZqJKBTZI\r\nS1AJxCrcQXl7SEUCKaRMLvi4ImcqmQLsI4d3fTbtLSjrUbh79NZtMhvyVvrg\r\nAPfF/OnfkLTKOuVPVS2iiUrHEd0hb+VBDtslBsNuiRg2fp5k0uJb70oRmb++\r\n5ovK/O59hYBE16j62XQvmyD9nJ0HBh//6WsLxHnn3mrpxvCBSHp3NZZNXrGj\r\niyOCC4Z+U5GEH/qed+FnH2OfCFsdP+2Oq1PSmbD0B+bzRDmebHxNs9Q+EnUB\r\noWtQErlqw6DLWMsliX2JFVtbWRCUSbfbHXOsMKNgNztkUo8uKEMnP4w6AND0\r\n8QMf55Nx7MNnNtJINk7iAvi9MObgpbz/jU7Sih3P8CG73BhbEnzR2MEbZHZz\r\nG9BViun4rWgr7Lu/Df4bcPiH703ncuE4ws+x5Wkbs5Cq0z2IiywQQfOyqRFK\r\nBTL03Ec1lceJXX8KbB/OBSf8Z1WtwNsVdVM=\r\n=X+yP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6539f1c4bfb6dc4935a84ce32a7f762da4c9795a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.366+6539f1c4b","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.366_1670945999711_0.4735722808545957","host":"s3://npm-registry-packages"}},"4.0.0-canary.367":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.367","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.367","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"34faab87bff6791615f9f674fc7d2771f1a87a8e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.367.tgz","fileCount":22,"integrity":"sha512-rzbRcQGE23eF+mVlA3UPn/AwoNTsc10O9UTCrWRPI4F59rCBiOUvmwidNwau87sriRVPspaL58Qae7zDknVO2w==","signatures":[{"sig":"MEQCIAfj8O6aLKwyuBXJwDTnJzqpGOIugsSG0D2vsXOt7As8AiAjIWbT23FBX97rAH67sNlYKgL3IJrZ7rZ9FUcY02FEsg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmLQiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqMIQ/+P8xeRpRcyWXkzsbSaeUnjoT7rGnsUUfYc6VStv09oWJ8CJj+\r\nKgyl2nvePSmJzkPVQaK56e3VgO4/v2szdLmKCPuuaQxE1jK0UgBTOwtibpOQ\r\nuRsHaIwuLrr58luM7hGJFyG4UqY24bMsSi+bsL1t+9qRG3/CljwK5EMoBrjk\r\nYWTCRzgLm1Jb3mpS6qgY9bGFUWWamUF2g0wjGewsXQVSE/oksSC3rYaL8XDG\r\naZ244sBFPwsQTt2Lv9oZyoAoEPDwlfAUvhEySroZzSORRQojZg3sWBvWK3fX\r\npO0kOtPzNHivBptg8xwfAIAg4Jbx6QBw3eZRC//rONuZH8fdnDa9MErx+K5d\r\nZJpJXBbEXjuen+YYxgr3jImiqMTGBsC7NTJSNJ3XMWCemm/k+TszAtcMKBGA\r\nnwBjmNyVmxCZha4e6d+ddSo/UiN13cqVi34WJEkNuep9lwWL+RNCl446Vx6Y\r\nzHc4026tJq2i5Y3jPd1v9whqvG1Q7Rl9ToUnzyyqZbjSVttS0rS27OLO9oPF\r\noUJiwNGNy9V7RZkHJ9ycIWJ5Rzuwq7Jo8kQjtduxSY8PhuVl1BtGy8h35Vb9\r\nfHF5T95UtxpQIXlbvCX0KA6ozpnq4BBohS2fyQobjfdTyDRLuMrPyaRgqrYa\r\n6h8QeNTin2o2+nv5/4ymBuKvRZzlTtPAyWg=\r\n=KXZc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0b33c59d950c2d78625f4ae7adda0c69b7cb8e4e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.367+0b33c59d9","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.367_1670951969983_0.4609745294210399","host":"s3://npm-registry-packages"}},"4.0.0-canary.368":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.368","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.368","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3a41cb16d075a708f7c7541e20b433bd1bc4c3dc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.368.tgz","fileCount":22,"integrity":"sha512-8JMdm7kV5T2w3uOWPSmKtzLGXcB2nxmGyVK9EL/uSfNhoK4KPD2l/Kxq+0sX74fkZIL9op6jk7clwKI0ptAtpQ==","signatures":[{"sig":"MEUCIHwZbUyrJ24QDG/rTap5KNfoxku1hHIesH3fKuTdDfMSAiEAlcfQay/JrB5pKts4PHnyMlBqjXNc9nweWHtC+4mQD9k=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmPf0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqF7g/+MS6LXRulDaH5UVP/0dDVMygu1U4tDGaOgemht5YbqhRXgws1\r\nGRk88DFhgNT+kpyJc/cmoPzSzkZ9iSKW5ZfucfUgr7eZkXn+4qpzUx1I5pwt\r\nwDD92Xjq3zSmRWopAFyD/imtqJrgC8s3mwCYlm+wAUStP6nZRG+RzrOKrYPU\r\nLzYuVjFXN8KXgQxlp2vejqz/XJiXK0705ztmBE3E8sVByBdr9viLRmfsPWds\r\ncs8Lt17chM8VhWfHrMVmhd3TwOJeePSrET48+6RXp+PwrKZsdev3IDgVIUwj\r\nzvC+wlYcGE4lyrnRbYztMkvDHMS/nMT+4Adjgqq4QnEefbnwWNnWrmsK8hig\r\nw3EVN1Bqg5c9WFjxioCA1PMdWq9P7qoVhhwHI/iR5/uEMlindRz//6yOS3SG\r\nr2tsikhA77f3Zv7D7JaobXoMXNk8qvYRboeMkcd6PgqP2Y9q3y4J9k2uDllt\r\n45olXtHgukomLjEOmASAPpf4Am7w9LaLSZpdTZPB+gAFdMu/RJNi7DdukOEY\r\nqvjXYSAEZyXP0rwiRv1Vf4MsUbcsZLyvn3Vh0Dv0aQ8t6fWCCNOKZNYvWF+Y\r\npUAYcDzfNW9MjSdERpdKml5D0Zfbr4gXcLZvd6UpQBfjrgMmFRJEkKRyR3uC\r\nCV+he9U3LPcAaDl4JSp5FUFT2W5S4nyNWgY=\r\n=vWDb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aa6fb1e09cd4a5876fcd775f3291190c8b9b2c6b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.368+aa6fb1e09","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.368_1670969332498_0.18971038649195582","host":"s3://npm-registry-packages"}},"4.0.0-canary.369":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.369","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.369","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1a012c67e1907283759b0df22feaed2f29fac81b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.369.tgz","fileCount":22,"integrity":"sha512-zoMwVuG19n2u49hLobWeDo+RgXgbUpdotMAH7XsxTp+jzaPZ9O6spRVsqZUhmyul6DG6MYL2je3dq8D67qcqnw==","signatures":[{"sig":"MEUCIQCpUGLTsr5a4YiTsir1uOdR5NypPLHCVuYE8ArPubQP9wIgFtipCmBzIQYpXnMboGYQ6MMHAwzXM7rAAgPZ8B+2mhM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmP7wACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqLKA//eHpyEAJRzbSe51ose4VDXVxw9uHtVARI0Q/8zOfQz8cEYWia\r\niav+h9Bo0bvsUORAxieQLp8wiNQc+nBvz7ppho9XF1KTDUDZZNoKtMOgVjcx\r\nccPJuZ7b4zbUORROpj4IKw/cJU2zdlMcMilc0tzjTBhWm3tFyA69Cg/39Z4P\r\ntM/LPTlUWTHO90ksW3QJ8sTqZQfhLEquJhcPYeDSZOm4gUjNW2hd1ULS9gZu\r\nRM/jlhgyEfQvwImodEhm+Yet5hD9MTxOcVf3kXv/sGfhHMMuv7B7WzqbB8Bo\r\nODiogv3Mo3xBGwYO15MKlla6CT+QL6UAXRQnnd9Ojj7QsNJYUP6STXv7CZUd\r\n/krp0RRY0F7nWDwmVs42T9lXbCuMzyPgUKJYwmbKX/1madMUex7Sslp+KqY9\r\nuv/gpytNKxa5PyhSwR8M0WLCpCbK9GyiTJxCwjOTreNcsPvfb075sfboJRJd\r\n8Vp1ZCMqagypFXqW2KbjA1f4XYWlx7gjhQQoK9mHlM5Pgx1kAYc9a6ndn62w\r\n96n5vqq8ChVJnxtFwnypOSpGEJJMNvi5uLMJUnSNLeYyTpQrD1u1DLTBUyhW\r\naVrNmPfWa6q95kVHjcYad+aiJ8FMQnc8gdtno8XBqr9O8nIIj7xXxu39Mtof\r\nD70BcAHljyXGZsaK46NI2YgE3K57TS2/pD8=\r\n=vDfx\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2f65ef0a385c137d6a770c385e06da1ae7a63e0b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.369+2f65ef0a3","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.369_1670971120481_0.3611704714765551","host":"s3://npm-registry-packages"}},"4.0.0-canary.370":{"name":"@redwoodjs/auth-providers-api","version":"4.0.0-canary.370","license":"MIT","_id":"@redwoodjs/auth-providers-api@4.0.0-canary.370","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"58db271974793da4cd28d34d81d504f1e48c37fc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-api/-/auth-providers-api-4.0.0-canary.370.tgz","fileCount":22,"integrity":"sha512-9r3QvDz+NqesI8H98hbUPESni7uHm/pKx8bhYq8AR+d5CrUjblZqGak0frQA6d+2HQb2Camj5uHsNoopiZhOwQ==","signatures":[{"sig":"MEUCIQDY92m398YXXUYdq5z7TFk/jcuAcv/oWIQk/ZZuw6cSAgIgCmcgPLT+Eu1hJUTxAiiiWkDWCq+iOxYJg+FPJIRMrxk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":128093,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmQQUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmptvA//Str55tavITxZsF7laLKy4MQylI2wAJ/EyBKn/HTE6uGavEYG\r\nBX/NxM54H6zlR5YxZH/VeTeQkJH3nW9jwGqUUjbFo3WRoqXhMfTylhTzuDN+\r\n1mp91zAIWpof6sOv2bhVdgoLIPL4H0LB72FDLq0R8dr8J9x58d+sq7AB9W0b\r\niF+Ktoik3vkwIh9yApXrEnP3DJJucFRS0R2TeIe32wgIL5tBKl/PUBJHLFze\r\nSpX/SWZCFUCMWezFnmzMVmug/PytWI0yF/Ly/o68SRxOIYFhtSrP2/eY7sg4\r\nkiyvC1CGfUolNVfF79qzNOB4iWJypvEnpmLEI115NlsjVswkxGWnKlYgfOsf\r\nBH0aCS5KNPKg+Am/lj0aJm/MXnrvhKPi6KMRKKtkNxG4SqchR8DNsgkTfj6Y\r\nFMq7/cJVahmUgRs3NY0RAdYFHWajv5n0aFaA+gHRIShJUkamTHjD0r0D5Q0N\r\n+6jt5FHGVKJPXH0VJ0thGpGa5CoVr2F9O4YUqxWG1hxlqGq+QRh6rtyX1wdr\r\nhpuboi9+EWW3p4MDW7Of8Mef4UdH9+XMtz21B5heBGyXx7p+ratNR4lGBCw7\r\nUCuMta51BT/sj5U3xJViA1bPNlLJwWb8zQxupOWfD7mEotalqAyzvuDT0goe\r\nlwy1femZ6GlZ9thmZZOebV/zcQXkULT8bTs=\r\n=SNyG\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider there's more info in the\n[auth docs](https://redwoodjs.com/docs/authentication).\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"3d057db199487ea0b17240317d66ddde3f83f332","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","jsonwebtoken":"8.5.1","@babel/runtime-corejs3":"7.20.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","gotrue-js":"0.9.29","magic-sdk":"9.1.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@redwoodjs/api":"^4.0.0-canary.370+3d057db19","@nhost/nhost-js":"1.4.10","@magic-sdk/admin":"1.4.1","@types/aws-lambda":"8.10.109","@okta/jwt-verifier":"2.6.0","@okta/okta-auth-js":"6.9.0","@types/jsonwebtoken":"8.5.9","@nhost/hasura-auth-js":"1.4.1"},"peerDependencies":{"@magic-sdk/admin":"1.4.1","@okta/jwt-verifier":"2.6.0"},"peerDependenciesMeta":{"@magic-sdk/admin":{"optional":true},"@okta/jwt-verifier":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-api_4.0.0-canary.370_1670972436773_0.9370305204046419","host":"s3://npm-registry-packages"}}},"time":{"created":"2022-10-13T21:34:52.753Z","modified":"2026-03-13T13:45:49.313Z","0.0.1":"2022-10-13T21:34:52.988Z","3.2.1-canary.123":"2022-10-13T22:21:11.203Z","3.2.1-canary.124":"2022-10-13T23:31:06.780Z","3.2.1-canary.125":"2022-10-14T00:20:16.274Z","3.2.1-canary.126":"2022-10-14T00:53:53.074Z","3.2.1-canary.127":"2022-10-14T01:26:40.087Z","3.2.1-canary.128":"2022-10-14T05:42:34.241Z","3.2.1-canary.129":"2022-10-14T08:08:55.264Z","3.2.1-canary.130":"2022-10-14T12:20:44.888Z","3.2.1-canary.131":"2022-10-14T12:58:40.293Z","3.2.1-canary.138":"2022-10-16T00:20:15.985Z","3.2.1-canary.139":"2022-10-25T22:08:24.800Z","3.2.1-canary.140":"2022-10-26T23:23:21.207Z","3.2.1-canary.141":"2022-10-26T23:49:10.406Z","3.2.1-canary.142":"2022-10-27T00:48:58.307Z","3.2.1-canary.143":"2022-10-27T00:58:48.483Z","3.2.1-canary.144":"2022-10-27T00:59:41.268Z","3.2.1-canary.147":"2022-10-27T01:06:59.163Z","3.2.1-canary.145":"2022-10-27T01:07:55.059Z","3.2.1-canary.146":"2022-10-27T01:08:49.931Z","3.2.1-canary.149":"2022-10-27T01:14:50.336Z","3.2.1-canary.148":"2022-10-27T01:17:17.733Z","3.2.1-canary.151":"2022-10-27T01:29:50.129Z","3.2.1-canary.156":"2022-10-27T19:42:48.124Z","3.2.1-canary.158":"2022-10-28T00:45:14.348Z","3.2.1-canary.159":"2022-10-30T00:16:37.116Z","3.2.1-canary.160":"2022-10-30T21:47:45.642Z","3.2.1-canary.161":"2022-10-31T12:29:11.171Z","3.2.1-canary.162":"2022-10-31T18:27:35.579Z","3.2.1-canary.163":"2022-10-31T22:15:35.817Z","3.2.1-canary.164":"2022-11-02T02:22:30.391Z","3.2.1-canary.165":"2022-11-02T18:42:28.966Z","3.2.1-canary.166":"2022-11-03T03:00:54.215Z","3.2.1-canary.167":"2022-11-03T07:58:28.237Z","3.2.1-canary.168":"2022-11-03T20:56:39.896Z","3.2.1-canary.169":"2022-11-03T21:45:32.546Z","3.2.1-canary.170":"2022-11-03T22:01:33.433Z","3.2.1-canary.171":"2022-11-03T22:03:56.941Z","4.0.0-canary.172":"2022-11-03T22:23:54.294Z","4.0.0-canary.173":"2022-11-04T17:28:07.272Z","4.0.0-canary.174":"2022-11-04T19:29:41.297Z","4.0.0-canary.177":"2022-11-05T07:46:11.792Z","4.0.0-canary.178":"2022-11-05T10:31:21.528Z","4.0.0-canary.179":"2022-11-05T18:50:52.352Z","4.0.0-canary.180":"2022-11-06T00:16:10.366Z","4.0.0-canary.182":"2022-11-07T17:37:10.509Z","4.0.0-canary.184":"2022-11-08T08:05:23.578Z","4.0.0-canary.185":"2022-11-08T13:42:45.208Z","4.0.0-canary.186":"2022-11-08T17:12:11.297Z","4.0.0-canary.187":"2022-11-08T20:38:43.364Z","4.0.0-canary.188":"2022-11-08T21:34:30.887Z","4.0.0-canary.189":"2022-11-09T00:44:42.244Z","4.0.0-canary.191":"2022-11-09T06:56:01.622Z","4.0.0-canary.192":"2022-11-09T09:24:54.421Z","4.0.0-canary.194":"2022-11-09T23:43:51.248Z","4.0.0-canary.195":"2022-11-09T23:56:32.945Z","4.0.0-canary.196":"2022-11-10T00:13:33.308Z","4.0.0-canary.197":"2022-11-10T00:39:08.759Z","4.0.0-canary.199":"2022-11-10T01:20:32.853Z","4.0.0-canary.200":"2022-11-10T03:02:23.287Z","4.0.0-canary.201":"2022-11-10T06:39:50.674Z","4.0.0-canary.204":"2022-11-10T23:03:19.080Z","4.0.0-canary.205":"2022-11-11T00:43:30.980Z","4.0.0-canary.206":"2022-11-11T01:45:07.746Z","4.0.0-canary.207":"2022-11-11T01:46:58.723Z","4.0.0-canary.208":"2022-11-11T02:37:58.122Z","4.0.0-canary.209":"2022-11-11T20:44:17.882Z","4.0.0-canary.210":"2022-11-11T22:26:15.823Z","4.0.0-canary.211":"2022-11-12T00:06:39.527Z","4.0.0-canary.213":"2022-11-12T00:09:58.925Z","4.0.0-canary.215":"2022-11-12T00:10:33.803Z","4.0.0-canary.214":"2022-11-12T00:11:38.258Z","4.0.0-canary.212":"2022-11-12T00:12:06.117Z","4.0.0-canary.217":"2022-11-12T02:23:15.765Z","4.0.0-canary.219":"2022-11-12T02:25:45.854Z","4.0.0-canary.220":"2022-11-12T02:54:41.730Z","4.0.0-canary.221":"2022-11-12T21:04:23.818Z","4.0.0-canary.222":"2022-11-12T21:06:10.073Z","4.0.0-canary.223":"2022-11-13T00:17:19.026Z","4.0.0-canary.224":"2022-11-13T02:40:04.462Z","4.0.0-canary.225":"2022-11-13T05:27:43.991Z","4.0.0-canary.226":"2022-11-13T07:52:38.910Z","4.0.0-canary.227":"2022-11-13T09:39:55.584Z","4.0.0-canary.229":"2022-11-13T14:39:24.484Z","4.0.0-canary.230":"2022-11-15T07:38:03.215Z","4.0.0-canary.231":"2022-11-16T18:41:31.185Z","4.0.0-canary.232":"2022-11-16T23:42:49.538Z","4.0.0-canary.233":"2022-11-17T19:16:55.316Z","4.0.0-canary.234":"2022-11-19T02:27:25.277Z","4.0.0-canary.235":"2022-11-20T00:19:22.186Z","4.0.0-canary.236":"2022-11-21T17:55:12.782Z","4.0.0-canary.237":"2022-11-21T18:45:57.263Z","4.0.0-canary.238":"2022-11-21T18:46:56.737Z","4.0.0-canary.239":"2022-11-21T19:23:29.043Z","4.0.0-canary.240":"2022-11-21T22:24:00.682Z","4.0.0-canary.241":"2022-11-21T23:25:06.869Z","4.0.0-canary.242":"2022-11-22T04:15:05.129Z","4.0.0-canary.243":"2022-11-22T07:55:41.911Z","4.0.0-canary.244":"2022-11-24T01:37:31.494Z","4.0.0-canary.245":"2022-11-24T01:39:19.092Z","4.0.0-canary.247":"2022-11-24T02:27:35.907Z","4.0.0-canary.248":"2022-11-24T05:51:55.813Z","4.0.0-canary.249":"2022-11-24T07:22:40.916Z","4.0.0-canary.250":"2022-11-24T10:48:02.834Z","4.0.0-canary.251":"2022-11-24T15:20:02.255Z","4.0.0-canary.252":"2022-11-24T15:55:47.341Z","4.0.0-canary.253":"2022-11-24T16:06:44.643Z","4.0.0-canary.256":"2022-11-24T17:58:29.740Z","4.0.0-canary.257":"2022-11-24T21:15:47.808Z","4.0.0-canary.258":"2022-11-25T23:57:47.343Z","4.0.0-canary.261":"2022-11-28T17:08:46.733Z","4.0.0-canary.262":"2022-11-28T18:55:32.358Z","4.0.0-canary.264":"2022-11-28T20:15:20.516Z","4.0.0-canary.265":"2022-11-28T21:30:53.441Z","4.0.0-canary.266":"2022-11-28T22:12:50.628Z","4.0.0-canary.267":"2022-11-28T22:14:10.626Z","4.0.0-canary.268":"2022-11-28T22:14:42.396Z","4.0.0-canary.269":"2022-11-28T22:14:59.060Z","4.0.0-canary.278":"2022-11-30T19:20:07.584Z","4.0.0-canary.279":"2022-11-30T21:58:45.629Z","4.0.0-canary.280":"2022-11-30T23:42:30.816Z","4.0.0-canary.304":"2022-12-06T18:28:46.221Z","4.0.0-canary.306":"2022-12-07T05:57:03.435Z","4.0.0-canary.307":"2022-12-07T06:54:51.688Z","4.0.0-canary.308":"2022-12-07T10:04:18.964Z","4.0.0-canary.309":"2022-12-07T14:12:26.464Z","4.0.0-canary.310":"2022-12-07T19:36:41.164Z","4.0.0-canary.311":"2022-12-07T19:54:38.318Z","4.0.0-canary.312":"2022-12-07T19:59:37.295Z","4.0.0-canary.313":"2022-12-08T06:34:46.023Z","4.0.0-canary.315":"2022-12-08T06:37:51.075Z","4.0.0-canary.314":"2022-12-08T06:38:36.017Z","4.0.0-canary.316":"2022-12-08T06:39:11.751Z","4.0.0-canary.318":"2022-12-08T17:38:32.745Z","4.0.0-canary.319":"2022-12-08T18:27:12.856Z","4.0.0-canary.320":"2022-12-08T22:33:35.460Z","4.0.0-canary.322":"2022-12-08T22:37:01.123Z","4.0.0-canary.321":"2022-12-08T22:40:31.214Z","4.0.0-canary.323":"2022-12-09T03:54:38.105Z","4.0.0-canary.324":"2022-12-09T04:04:14.999Z","4.0.0-canary.325":"2022-12-09T09:55:17.556Z","4.0.0-canary.326":"2022-12-09T15:26:22.277Z","4.0.0-canary.327":"2022-12-09T16:59:43.749Z","4.0.0-canary.328":"2022-12-09T17:01:53.127Z","4.0.0-canary.329":"2022-12-09T17:04:20.714Z","4.0.0-canary.330":"2022-12-09T18:56:26.543Z","4.0.0-canary.332":"2022-12-09T21:04:03.548Z","4.0.0-canary.334":"2022-12-09T21:04:54.990Z","4.0.0-canary.331":"2022-12-09T21:07:20.362Z","4.0.0-canary.333":"2022-12-09T21:09:05.693Z","4.0.0-canary.336":"2022-12-09T23:27:32.032Z","4.0.0-canary.337":"2022-12-09T23:29:55.650Z","4.0.0-canary.338":"2022-12-09T23:31:18.655Z","4.0.0-canary.339":"2022-12-09T23:36:14.014Z","4.0.0-canary.340":"2022-12-10T02:24:32.216Z","4.0.0-canary.342":"2022-12-10T06:20:37.166Z","4.0.0-canary.343":"2022-12-10T09:12:46.282Z","4.0.0-canary.344":"2022-12-10T16:22:14.700Z","4.0.0-canary.345":"2022-12-10T23:02:23.828Z","4.0.0-canary.346":"2022-12-11T00:21:45.769Z","4.0.0-canary.347":"2022-12-11T03:38:17.736Z","4.0.0-canary.348":"2022-12-12T14:24:57.260Z","4.0.0-canary.350":"2022-12-12T18:50:43.419Z","4.0.0-canary.351":"2022-12-12T20:11:18.233Z","4.0.0-canary.353":"2022-12-12T21:12:45.520Z","4.0.0-canary.352":"2022-12-12T21:17:27.977Z","4.0.0-canary.354":"2022-12-12T21:24:56.176Z","4.0.0-canary.355":"2022-12-12T21:28:24.978Z","4.0.0-canary.356":"2022-12-12T21:28:45.589Z","4.0.0-canary.357":"2022-12-12T21:58:19.409Z","4.0.0-canary.358":"2022-12-12T22:57:05.868Z","4.0.0-canary.359":"2022-12-13T01:17:04.789Z","4.0.0-canary.360":"2022-12-13T02:06:05.582Z","4.0.0-canary.361":"2022-12-13T03:42:46.568Z","4.0.0-canary.364":"2022-12-13T09:29:07.961Z","4.0.0-canary.365":"2022-12-13T12:58:30.476Z","4.0.0-canary.366":"2022-12-13T15:39:59.905Z","4.0.0-canary.367":"2022-12-13T17:19:30.164Z","4.0.0-canary.368":"2022-12-13T22:08:52.713Z","4.0.0-canary.369":"2022-12-13T22:38:40.632Z","4.0.0-canary.370":"2022-12-13T23:00:36.962Z"},"bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"license":"MIT","homepage":"https://github.com/redwoodjs/redwood#readme","repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-api"},"description":"## Contributing","maintainers":[{"email":"peter.pistorius@gmail.com","name":"peter.pistorius"},{"email":"justnvdm@gmail.com","name":"justinvdm"}],"readme":"","readmeFilename":""}