{"_id":"@redwoodjs/auth-providers-setup","_rev":"197-a16e9fc10034cf3e0a98f5d76809d4a8","name":"@redwoodjs/auth-providers-setup","dist-tags":{"latest":"0.0.1","canary":"4.0.0-canary.370"},"versions":{"0.0.1":{"name":"@redwoodjs/auth-providers-setup","version":"0.0.1","license":"MIT","_id":"@redwoodjs/auth-providers-setup@0.0.1","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"58945ce102ba1c0bc2f1b3d5f5eb5c77924becd4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-0.0.1.tgz","fileCount":86,"integrity":"sha512-ePVWtljGkHC9CZ8nmoc0evLM6qqCbQFZHXkK0spt8sNxqm4z7inqh3wlCxtUzcB0nde7geZvka35+9WN7XiAnw==","signatures":[{"sig":"MEUCIQC9tZGnl1XqhH7olR1AsjHmDmlycWEboB+882RLEE/5XAIgd9qOkoJsP1hV3nAjeCObDG427yEg+18CseB8NuRE+gg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":131204,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSISUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqGIA//StA8zAFCA9wwS4flqHiNdrCNjkTHEH1MjzR6TDMzCD3PMi3A\r\nLkWheuuds898/XGLoi9Ds4IBYJWvEKgHDYfNBNXQS5bPovnL91Q7NCb5uAu+\r\nrq8/m+p7l0eKMKICA1JPUjMwhAPlJDovPaDts3mGjDVQipaHxecTiQ7KRB2W\r\nGjPQZAijNfHjsj+fewlM/Szg9epIoe0dZaXB5uNqUIFzVl498ocy/AFcx+v4\r\nhGX/z6IBMaU6WweCvSBtuHYoixTRpQVT/fAAtQSpvsLAMlAch/7mA4ZSC7Tw\r\nwGmF/1Qb3+RqY4OQDJFGYtk13mF1OpYG7AgtUlVjtUo49xvX8eEc6+yJKBi6\r\nQ7vO+6FEwsOZcMZkGxaYIRk2Wq0UuzdrTmAlIHb6XD05GGfIty1MBp9F4RJ9\r\nKP2y6PwRXKpoR9uyVSt0uycRNJywq7TUgT5PMy+RlJwCVbyD0Bl1t0YyR1q+\r\nlRAGZtt0eNYTezK1+EduwFIF+Q1M5+Pv9LOzjkeGJjy37S4+niLM/JCCGCPr\r\n4+UxraOEyRBsryeIWK84NLlqJuY6iTiTtZI4toCoo1hLuf5yf/geV7fVjUOR\r\noeRxaZUzk56m9/uhljo1xEo6ULXWwmoDfEm1fQN9s6hGXwvhEXEGw75A6a+R\r\ntrruExHn93RFZU3wixEv225JM8Fttm1Ojxk=\r\n=COWj\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","gitHead":"3905ed045508b861b495f8d5630d76c7a157d8f1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"jtoar","email":"dominic.saadi@hey.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"8.15.0","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"3.2.0","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"0.0.1","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_0.0.1_1665696916296_0.8145321497205684","host":"s3://npm-registry-packages"}},"3.2.1-canary.123":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.123","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.123","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4cdf8b35add315047ec2f34f85a1a29bfd3a5ed9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.123.tgz","fileCount":88,"integrity":"sha512-6gWnscHUf2EbV8t7bBuzvotQ2ww6g9cxSzvyPQ4pBGJdiXhgOxD03iSF8RWxnocFLQ5gKbLhzFm6VlE8KJDIgw==","signatures":[{"sig":"MEUCIQD+GUsOVhjicmBpRAQRdFYvBs1xirU+R+UbxYminbh9PwIgOxX34mTPqnltEP6n+OqaBsW1Siv0kAH4nK05cjNftO4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231669,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSI9YACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrDZg/7B9i4RKLCpMs18uLXJjP5eJpS3fQ14Ax7yEth/GEv2+c3AOl+\r\nv5Mr2pU6qPLVuhSdNicX3KDUzsDz4kpWGXG4Qs3iyOiaBibjHX9ykQSYbXxg\r\nfAC2E8iJE+EyIR/cNDvpNgafkXZ+dI9Tto3ygrYSa1vPq6TBfR1iVVqje27Y\r\n0eo6sZsjdMQCGmGSaqvboxC4Uia6yURT/H1L9UDHTgLS7ls6hRXYUVhJdr+O\r\na/dBkoAGCfWuCdRmAJAU6hPutjW4BilqgmpbtR0qS6GZfljCr/Y2xS1GBrPh\r\n9SZQZA4CcRME83yhs9G6aLDggQaxfbvpnQh7nmNxaPey3nuTGHHCDR9tC94v\r\nJoqPdcKghsMqlaGoEK8DDSrPC5CfTRhaARcyDwJJDHuXcjYbwWbmiiAcJXX6\r\nzu6wKkhuLLmtjqsgVkmPk2mAcGB8crIX1CBzdBzbv6UWiycE+yzPnbpvNZtQ\r\nnSpVwyDdy3OwE9o6sAVoBvs1gW3Kc3p5K0upkX2kUBkhma6dn3foaBLYZaX/\r\nu5OxLLjHI1lUWZ8NPLHhKg9Eml7hJKQaPkPkcdV0PCtmQR093P/drosWdQy0\r\nCTR5JcWiMICbcye6hbdYQrAADdCgWL8vwca1m9pDOXFmmGPkZCqRRsjTI3IN\r\nwrSVPK0vt6ixmqkOTIQPBEnHRJhy/j4X7kQ=\r\n=TlxO\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"79adb685eed4a01a79abb4b24ce17b312b4c79a9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.123+79adb685e","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.123+79adb685e","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.123_1665699671914_0.04360482367719043","host":"s3://npm-registry-packages"}},"3.2.1-canary.124":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.124","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.124","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6812139e48fdead4a7b6b09755fd8916464c67fc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.124.tgz","fileCount":88,"integrity":"sha512-LoLmTBB/uMkbD8Mz6JOPVHBMUaJ2xwd552Ho4VRg8iisegQv1ZjM01f6NMnJzuEpY2egi4sbg1poRnDeKl/QQQ==","signatures":[{"sig":"MEUCICJCm/AwhfXwlmzENlTGGH+0mRh4wVCacHNMAUJdf53HAiEAylIJEOsLHNEw2YRDIzhy+BvYAyH393V6ULteZD2DqjE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231526,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSJ+7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr7kQ//bVjKCdqp0j/klBtX+IzmAKROaT4sBjS3lZ+egcM6iaAYZWNj\r\nNWFxHPk1n0nF+D605pZnV9LCj04EZOPdIcedjjc2eHDrc3c2KVGvmBU6eWY6\r\ngjefb184VjYUow9IHiZbzVnmHD3uC7J/KB43Rea3CeS9OQj7FSbjVH88W1C2\r\nOIh2mBWNYLQgrYKI3q36O7qbSPWsCnEE31LjGV96EIfPTMPRbnPRpK0lwVwL\r\n0lTVoEHYfDPQo8Huh8Q5E9E06+E6bvwkYEBeQKD2KfdG11StLzIbq+xLsuyd\r\nfRZcqLCFBU92LBCB35z0QMNIcFT4vAtXEURd2jR8MMtrW4yW0fKlxEoiUMEc\r\nsnPTEu3hOzqlrAt1xoIRiLhsMhZr8MTApY+8254CgwUb9FSbecd1sUOwJxlL\r\nIg1yXeLlDQWhgds6UDPKl+mTUQRZJ1CCsgeMTneueYebymtW0ukB1/BfpgMZ\r\n35KqeNYJSHNqz87XMuNXX5Y1otoQuLE4Ou+M+cBiIgz1weXKalEjqbnKEp5+\r\n8B8RhiYBP4IxDlSdBHVJvYLp2dI5McgFRkvWRYGdOBxsu9A8uoP13beazpEZ\r\nByMhZLmyy050uEltqEzZqRBIek8G5r2byLwZ7nwLztu5xd/PNjen5g4Efnz0\r\naHsySoXwX9tgvNWuz/j1PDz80iAJpDTf0CA=\r\n=GZMR\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c2f863d680f1d6bc1582676a46bb51605f9afbf5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.124+c2f863d68","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.124+c2f863d68","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.124_1665703867421_0.2448988078540002","host":"s3://npm-registry-packages"}},"3.2.1-canary.125":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.125","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.125","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5367fe41c1314ee6e42015f1e082d4a927efb60d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.125.tgz","fileCount":88,"integrity":"sha512-WXjdc4hCgMBdD29PXnNfJz6Lnupgu5XARSyiLjh4RPCKdRRJ9sdeAVOcsR7NjVlSqEJ+VKvhZtw3QT02/0SQGA==","signatures":[{"sig":"MEUCIEH5bBeq1/1peqm0CYJqjoq3HevDsbRnoKvTaADVKQ1dAiEApUXfkSdrLg+y55JvX6pho6ozpXu/KhAu4iptSDgrjCo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231384,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSKtBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoHvhAAod8/Uy09nNu6xKnplgAZYuTJBkYPr5pFS/t8q+E80lXk5FLJ\r\n4P329P6hoMy8lHDcQcwver6h3scmfKey++O7jn+Z1Fi53MABMwn/L5CYb9l3\r\nIwRFgJv2tAT+68CZSWhT27ars548RUpwAPMVkQI+4u/DWg9+fUNRw1MllFfV\r\nqCSeTd7RrFLl1BuVRdlkT45NgPhSC7XCyptRii+LHe+lwSv8ZF5/fysQvGMZ\r\nQuuILvSyTqrHIQ4KPT/g464zGxlgF3cRgfsPU78NeffPFAM7aQ62ZK92DQv0\r\n6UZQXWt/Z8Pq/suhFCU9UzJWZovo6nVkhsepZiOvCgHodVe0ULQiYmkTKCo9\r\ntEWx4e8qpCBcWRhuKV0sjdOPyvX4dqbA5PPWNbmZPuQGV6Z3fHl/ZjCh95zi\r\nb2YLQZzTeid3VohngPEeNdVBl0IkNdZ6330laUCwb0mdNTRuX3NCPZoCWw4R\r\nxPIqbcr+JviHGK1Ewdjrpiry3I22AuIPLurCY0QcS+jqTIm33bUjPVIVCBza\r\ntojWSxsJR77ZMF3K8lzo78GzTNR8lTINfJkeZx69Vc1v38cjjb3jrj3ZlM2Y\r\nEC9+bwlQqklOcGTVfqOS8dxwiqTkUjZI3hBkG7aXHBK5BM+VRu+a6WWOBHlt\r\nmLKHjoSTsP3OXCAPMCmzRICiM/9x1Rm7jiI=\r\n=ixrg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fa6546440e2b97519b030817cd89a613d0076769","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.125+fa6546440","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.125+fa6546440","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.125_1665706816998_0.7325689515985505","host":"s3://npm-registry-packages"}},"3.2.1-canary.126":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.126","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.126","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"52541e8fc2324c54f944e004c6f4c3f06f8c1e6a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.126.tgz","fileCount":88,"integrity":"sha512-ImdwgDPcHkBLnfO2wTUgpdAlihtQ1RYSfDL4hOI65l98D5qWXAnmgjTnblVqqhTOXuDE05JIglt2IghgzjBnow==","signatures":[{"sig":"MEYCIQCyGdQn/Q9oASj2VINmK9CwWjLhCwTDR49Dlo6KsApfeAIhANsHezHqEtxKn3cnpNgFWVw5tjoUqEq7tSlwpZVwJAAO","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231384,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSLMiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmodAA//QwsM9ajN+Q+LYORRxNsDwB6IUUW4S1dil4UI95uCzn2uoOFe\r\n3r6p+zRHrnBIwF9fpHWV+hR4qMJIL1L91ItpUvvM+vLPJuP8kyJb2z4EqJyb\r\nOh8G7Ic3jbOwyoDU7XSQXJr/RR67AGUucOb/LkaUgeuv1ihe0VgnH8m5mklJ\r\nspvWRTrTyDKa/H14lNmrP0jCEmgjd2dL0uVFGHzf4qDN1Uyfkqd4zC+t8zez\r\nxPE4dP8SLCTTF06Edvbg5Z4R/muTCwvon7r+H/ppuXiITWH2svGCNGHk1hxj\r\ntnop1vikjXtlDhZHMgkzmRQ5U4lKrBDFGkQWIDOaA9SLcEeTrkQSAdW8EgNj\r\n4qmCdluiz/h4CkEqPa3ftbb3+iPAERca1uYvIWePhNBII+unJXz2oMdBQ5Mi\r\nkqtYC9tAu3iIhWa6eSu2n8VMP1NIDTzcBka3V/jUiZiEkT41aiDHF4uJw48/\r\nFu2dYypSfxPbJLT/lt9H5vN//3/LhVpwHywmyuMFc9S4nIojqraRxxFbLNES\r\ncUGVgD5k+EUmkBlCYQvshv8gnL2l3kf2fWSHrKiW/OYo37YfDs7Ijm4X567A\r\ndMSldYjLRRH1NAlfNzxfiVzcmx0QTERahvr35TF+FW3arNbeJsLWC9gfU8Zp\r\n+1qiNxWNXwqBpbKE1a6npHEpAxCNHulHcc8=\r\n=Wpl5\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8a107fff29f3da11ee218e741eb4131d60ec217f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.126+8a107fff2","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.126+8a107fff2","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.126_1665708833755_0.45085377953008443","host":"s3://npm-registry-packages"}},"3.2.1-canary.127":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.127","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.127","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fcd7dcb096c623bf17fea7948a4a0e4390f7af29","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.127.tgz","fileCount":88,"integrity":"sha512-4Pdp2O+VU6SOVRFf9b7+q/soEMWZs0MD4xMvs2bjLfIZjrw/W32Td2Wx+/Mi3e6hB6VxsV/Pi4tP3LKkPIpTeA==","signatures":[{"sig":"MEUCIC9YaGifrfZNGAW2SBZRupwCMkDrI/VTXYdcymiTvOJYAiEAhUorwOtqyHYZuaPL3WAEKpkDKWfUpzl0dvCv+psiDPo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231384,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSLrRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqXrg//WBwWqv67+qmBLvzU69P2M1LP0j7NjCxjm/cADBFaCb5iviXe\r\nSNaD2ML9mv4S+F7SjeiSYFBmoL1X+s4tEV6hwJZn97T3OLI6JiTpgzMtOxM9\r\n1JuN/5VoreXgODb4TZHEeYWEvZfpXqvWzlJASeekKkfrVHjb4ZVZGQfOgPbr\r\nzC0OP6X38Vjbmjtn0EqYuJCTMsA1zi58sETQEqOjzehW/cegGk6RCv5lW2HA\r\ndMuRZh68U1mcJxtFduT9rYzY5bJd9YvKZkxQ0Wy0F3qhXFNG/JIl6BUPqPfr\r\nsDpEc0m479Cpm9z7NIytXD/0A5N1WM4WSeB7tVCq8INJavWAsOa3fkHlvFg3\r\nyaejEU7qj2CfLz2/OIP9xiJN5SUJchWasukAzbPqct9IOtwPsvWwZEHiuegd\r\nc3Hhcil2GYXdgegzPLOKsRsQtnCjILR/ejL1am6zHPdbIsIXzjcCNrR0BJnt\r\n4NTJ9lcLpkNn5ZeNZMZcj+jS3tZvvpvFPNu4Qt08Z55vQxBH45slZVBzVCle\r\nlM82eqF1B+AsPLrG1ki2pUo3lRzdIO7eoB3GgTrS/9WhOlSeAP4IqlPKA5ss\r\nnsTnk8ifpGWhEkSOSdWM9lvEnKioTYIQmvoYm5zfndRs0C7bMGoeJE7hFsDp\r\nihZT8kKsox63WIScZFcCxs3wwxEuVkyC4qM=\r\n=6yPR\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"48725cea55ebad9914a748a9a45b60d360697682","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.127+48725cea5","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.127+48725cea5","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.127_1665710800775_0.05907602709494575","host":"s3://npm-registry-packages"}},"3.2.1-canary.128":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.128","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.128","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7cb2d5c1d971a00a5c42977ec5abd0b537aa3480","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.128.tgz","fileCount":88,"integrity":"sha512-KDmz6nZzQ7ZQ8Guom66mo8G2Boumbe9DfaAYaN0+f5CWkHwOgvxoWJ1OfAecGeTWq2vuHSebgc3GNHholTT5BQ==","signatures":[{"sig":"MEYCIQCNBBa0ZSpi4Q/uP+t9wAbXdPsXYrscAzOfikQLvjx3+QIhAORp5Q/59DyRhIBAiUURhX8tJ9Xo9iJDNrvTvUyxu7rW","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231384,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSPbLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmow3hAAjC+By++MyM6uDQBUD5F6V4yBHLeH0pgXb6bGT+7dg3IgWTrD\r\nJqTuwY+c/pm0X3OiTMz+36a15OkYMHSacWF7qsUNZBwTtq4dRqi0REKo3xDq\r\nBO2eH0sVtBQOjaP9/zE+ztHXEiKqR4En5oZsbShR4xn1jidte92beDIshpp2\r\nvGEtnRIXzci02ZI4u6UiUL6UoNXvD+lGdd8AW3AsS6V6PAEYYOcuBBsjBBUd\r\n8GQRaKAlMdW6tDvbM3dR6gEeigQCacwdgRmzlGiYDoyF5j+95MepU0BcmUWk\r\nSf8bYym3EBgxYoPOaM77Mon3vzCKuCMBoCMu27qf5h0Qn6Xkr8h3+YfoleY8\r\nIRYGFFmF72daZIeZw2vlTvsGv7n3zF9qPMypJWhbh8GykcxZ6XBlJle/n0NU\r\nf4m5f5eMzQ9zkRlYmsHqA1fZebrAnnCBmxeJp97wIQ5XpUDHRK2loI1J6kYj\r\notcJjCI7/5IwSmPkxUOwLvMWcW+CyJyVScoIN9fXwlv488/gIrnz9wBy0qex\r\nVleaPgm/UNKRx8jqlXi3iEzlbj73uzaSjzytcqKO+8wCaUxo06cOsje1GfX8\r\nKBAWwRH0SM1JzU4h9w4WE+2RrblcNQKq2clrGnFcAt1WCm0uiEvt+YsKC29g\r\nAFDWepVwqKr6xerASZ7LBbvwKorXrN7FibA=\r\n=rrK4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e956bf37219af9c767c099bbbe27c772521e93d3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.128+e956bf372","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.128+e956bf372","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.128_1665726155001_0.6707888530128252","host":"s3://npm-registry-packages"}},"3.2.1-canary.129":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.129","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.129","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3b20656d89fe4caf86c07ccfb29be743115f1147","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.129.tgz","fileCount":88,"integrity":"sha512-qG2HTXyBhoEtxMcQYyb2HmuUxxW+cWVw0F3WYUZXzrs6rZvfQgVd8b3ZOOCO3y+YZT+AbTlUMQOU8p0AAWAOrA==","signatures":[{"sig":"MEYCIQCvZodxZXSwqTj30eHCnd6a3UyUXAho5dF5S4hQ9CGVPAIhAM5fOkSzyuvmQ1S+o6paNmDt+7LmMY6Sq++MWp0Zw+Pk","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231384,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSRkYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmomQRAAoWAGoDeMzUv9K8+YGrIan3GpFA61ngYk5/955cZdlogJzdqe\r\npKHVqQ5J1CT/yanPL/SBD0Uo7gEgr45JirEhnJazu2mwiEeDOMXfZJL7lcmm\r\nQqu7pcE1aascRGw+ntSoMXbZ5Klj6/Q25220ydw7jv1X6gK5trKcAdkP5tve\r\nDmgPtcVa+yPmHFHWUiSZFYpENLW/dlASiyVnMcSUGajRVUvkqPxPTfexyNpM\r\n5kygd08vg6BnZl2OMCkXySurOwZ23d4wn9gSUYN93mt/V7WKMaSX2xpIOewV\r\nityTgb7PtWG+0fCVcdWZNEMP9S30KhYHI7QgQYRgqKZ9ZHZcPbErVB3952ij\r\nB1az0axD3GyZGEyMdfR4S3OxpRspBDuJH/fI25Cd74SJ9L7HNaSRJ5cDZlx3\r\nMK0qk9Turfe39fdYIGG0JOzb0tdKdrXiA+8pQh7HCWiT7ELTh0o+kfkrs1oe\r\nfbjsinrYYxy+OTWut1/YrznfbyMVW15kyMTT1UXXxJOOLcSmOY4K4X7Nf13w\r\n+EDThSGMiL9+tssFVCzNtGztvTuh0fZjdFkwS/AxevAV1f0oqoCGsWZCXpOo\r\nKsqb2aM1Sa3h+rlSjgZM9D9VMG8uCMyCFOr++mk7bzkBuRqJsxoLaxrFbwSn\r\nWy1vfBU6PRpWZ4RW4ZneDkKxDH6QlHYy2zg=\r\n=fyPS\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"53945158ca21301989511e287d1f3779eb66166e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.129+53945158c","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.129+53945158c","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.129_1665734935915_0.26288361463826626","host":"s3://npm-registry-packages"}},"3.2.1-canary.130":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.130","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.130","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5c05bc601369f5d71e6e5592322dd634fbe0d50e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.130.tgz","fileCount":88,"integrity":"sha512-ajd9WeOc0ndeV/3t6gjf0MO0yod8j2nHW6e/OWmOJSTRLxrwa0WVGO/lc7+4PrRKcgVhtwAAXRAoI9BsDqXklg==","signatures":[{"sig":"MEQCID7f0Z8kS4zbVIlh+QfNYTKKMvk7JQm8XW1a+KHD7VgGAiA/yT+wfPzcdYu34Zi7K4h1+DLoc/kx6EooDoCGovFSBw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231384,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSVQdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq/zg/9EzAgO7imnaHLa8uqaiKiEdYvvMkMachAQQOQJa9/ZkW+A7vT\r\nvedYxaOodFVGqtxIxFrUG+MJnD+shPnAfpMyGkYXpNeFEIiSVLs+Tb63aHmu\r\nGrLL8FvMWWN02LHS2MLYeDRduo11rq8lyK1L8OdjwGfIxtca/XUd+eSaKLi2\r\ncBhyGtMeTjoSavF0T/zj12ewDqfqGn2j54Jo8urd75kk5HwNA+Rq9YQLbsrt\r\nrFFoi29vPTTaUYRlBV54IFxIC5v7AnFhAI1dBMF+tfYtFetmO/usaRC+s0+f\r\njwBIXvjBwnQ6VFC4MHfTNNv4V9L0m5mY72HOV1nY4SjpGDhlk3p+Pw39YiUm\r\ncxIfjqRfuVQ9zvcLiaha58bBk7Hqqpj5YIk7em7940RWA0p2eWIR5QTCDH/q\r\nd0Q5TGP8R+jV/ituK2F9AKrj+hJwqunY3FS8XVf+26qJZEP9FbimMnLqhyJ2\r\nPnZ4xMKj3ZmDO1QUQ1OOmlT7Jqq7RFVOyTjOv84rmq91J+MSt18WViUhwHVW\r\n8p1N2zkFZhYKvQ99xTfc+vDXuT/sVH3OGq2MzNNSKZpRkT9j+UAEiOHLHRpA\r\n4KcICyalMO2YtypU1O1wRaRGtm9K8OnjCn+8JTG4hx0keiO1y3/0CoGUy7oW\r\nh6lqWVOpmz9Z7UIb72pBJZYyQvJzMdXHlUM=\r\n=wa2o\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e01750d967682b8117374b0b8b96a31f56ebf426","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.130+e01750d96","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.130+e01750d96","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.130_1665750045638_0.7308777465353848","host":"s3://npm-registry-packages"}},"3.2.1-canary.131":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.131","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.131","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"744ce1519410cb77f3ce762bcae46d7291292864","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.131.tgz","fileCount":88,"integrity":"sha512-PQbnQ1qYIFMW6L2fiu71rhMs4V43IlkFAyDqWGkx2Tu3JiD29jdZHMJcUEbVcWVSemlTCn/ZQWnfYQl8pJ2t9g==","signatures":[{"sig":"MEQCIBT9viVRZu77pthsF4ktM2IAc+E6n7gFGN3lo2buaJVQAiAC1A8DizuPnZblLTGmOfK+zitoBh5RYJ4SCGzhbyGF6w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":231875,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjSV0BACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqrKQ//YEkomt2rDvM1/AX4fHYz0IhZDur7ztQFmvpqhb0baJM45VCl\r\nJyyh5cy//5KLxyyeubk3eQWuOjs2GXvLTNktpaIfealaLNo/5orW83lU8pRC\r\ngh+DdDv8vI55y16NuynebZ23/89PdMzlXD9Ia3pvlO7UAM7Vpg3cj8FTJmiL\r\n3vFvC+MzFebyFkYa2ZjR5dii/3UzFytPZ0R/iYVetUL8ChF3cJTwss0Jcb8r\r\nGyFtp6ekKUzJdURxPTmVOVnacRWEy2EBr9tHGdoSXRlwwqMXOa0vT8LdeB/e\r\ntHCPgHo8jMMLe9T4R/EromEZnZ8EfiGuivnoPDCxRc9Lj13aAo2WsiDPjGR5\r\nhJgF8Ui9Uth1l8ZSm64lH3RCxUceeaLnT6aK3i++quA9MvfzzFU5FzeH/Yrt\r\nkVPsI5VOxO7vZ0wRg88iv/vLQnxPx+CU1RyY/jzlJEjWKRtVBW2oJ2vZGRKy\r\nzRaNB+AKt7v0uuOCuTcvZWWQ116m4HeuKa0IAy63CZaxDUZuY92WNGgflPZ0\r\nYHcgUolFa+uk9pibA8KxLNgU4LHKeNHxivoFO5LweS6XNrN0nZZtiSrZL2bg\r\n+EOq79cCeReUYoPaaXY5CI6txO+AbCdKkM/h2rZZ86UT8NR9lRWLKB/vTzOK\r\nd6/58Oo5PWmNdYx1OhvnBGnhRc6QXBO5zWg=\r\n=GZ/Y\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7fbd6ba32b4ff4f9170ec51d5e7744e308094b9b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.131+7fbd6ba32","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.131+7fbd6ba32","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.131_1665752321098_0.7358113537494781","host":"s3://npm-registry-packages"}},"3.2.1-canary.138":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.138","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.138","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"019f11a4d04cd44f7ad3f04efc4be6d9ef626fb8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.138.tgz","fileCount":88,"integrity":"sha512-gvz9KvuBfVRjYvDtmeFooZY7/x8dtDDu/QFUvXkX5M5GGqm9OX42sEOXEp3N1MS8NvgijvR1pnp55idNaSZd+A==","signatures":[{"sig":"MEUCIDkfVIgTFa4p9phroR64u8DULH/PMtwH6JyDLWhyg4bXAiEAlqUjcqs2naiDpE2mAn3oakEs/379ajAXrW7F3dntl9Y=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232158,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjS05BACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpcZw//QpQSeygmBsWA/2O2gjAPRf2+tTATOGwXK6W/2qXz6bqzqlLj\r\nwEjiEkyxkUcdt8oEzg7UzD6SRvVqlPcd3jkn9vfunWRzC9HNOTiQdST90tf9\r\nWeqNXNmjqdlntjGndjCWp4YPOT9Rod1RuKG/cEy6Tgx+l214wfETIGlo1FD7\r\n9cftW0SWw9tQ7NMSy9ww/mVLyFtZqK71s4WvEYSrHGDHgWpcwjAhqbUoB24v\r\n77lKvgHAmHtisGXzGNfqr0LOsBibicSFo88WAtYuq/flPowznwAEspb4t8Cb\r\nH9sC25Nr6Jwr/c8Gov+DlIhJ1brLRNhqgkfIaZhQSYzRz5W5j30647WGbWOA\r\nyRAfcaXb9tKzL2WyTh1OZY29iBbCR+NklFD6dd9FMpR942PG8IA4idt2e8/W\r\ntLOui2gfNfGoTE5dgaYPHPPFRN/c2QP0HICIhvaah7mP8yY6l68hV4HSXOU+\r\n1k7UshmcNMtHcPMc6UHRes0otXtCNwP7X+FdgF8rxVuwXXfaBe4h8MjTnCSk\r\nttCFL4I2FwZjvo1UPEkSf7Y5Co6NSMU97+/Sowk9v20VujLOnVkS0q7srtkb\r\nBdAV+tW+MbRtKBd7cGunVGG/Uu6iHF+LLhFIpn9bKZQasBnZ94ZkBsOZ4uPX\r\nY5kCK4KmdilshGFo7J3nj3PYOgHj3y9UCRw=\r\n=JCxb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7b877e56647c5b5baa5eaa888b35e942e4500e0b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.138+7b877e566","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.138+7b877e566","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.138_1665879616871_0.059760478307441245","host":"s3://npm-registry-packages"}},"3.2.1-canary.139":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.139","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.139","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3021d230e59ae7b816041d631694261536045059","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.139.tgz","fileCount":88,"integrity":"sha512-zWBHp+Qv9TN0z5FgIUQuo9olm/7DoFr9DJ3VE/CSMXwZH2n+VqfjKw8xOENplUJHu6U5NXyIgyJQTjYXfywKqQ==","signatures":[{"sig":"MEUCIDB+kxUUzbcOdfp/pNIrPhnvQ+y7XYE+Egp2XmNoiMNOAiEA2LurJ1VvYyf/DQk7T27oCGnhBdksRL5Y/gO+HWQ/6DE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232158,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWF5ZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrCHhAAiy7UV2hvG9iJKkkvCZfn9HY3lPoSkYVsWUdy7aOYskGsvYzN\r\nqCk4o5UR3I7wevGuT9ei51LRE8F4eLUA+EpijVShJZmoO3OhbvyjdPKEuQqn\r\nfHmD4o7OnpzUsgEIEYDXPqer3Mp0kVh197dCuzMwegsq1S87U6xGvAYAfbT3\r\nkTQdNXOfx986YqYiKu+ofhJ9b+5+zzEmITyQy/sDc3Gv5Gxg45A6ZdBNnQxA\r\nXYnFDvWXOfbSJPAQa873y0PNW+72Oibo3LBTLCYLU6vVUELO7Y3CeyX5T3uo\r\nCchk9y+YH051xN3Q4HsAwbY8nDTg4sqC5XfcHeh01S8aSeFnfkLdoj2gnXL1\r\nlRl8sJLvCXcMxxPB/eciK1w6elH8aeX56VIUCaWEmg9pVp6SQiVE7pbGahSm\r\nd6d2rukj8o7biBCsbMKq0MOE0y3DvLV9JFzCz7kyUm6/ZdzqhpWxUVXg0Slq\r\n42usoAKTcB8Hu6lrEJGqfgVXZYH/LXjIvoQEtso6zJL6+9vFSuxvbr3Q6Oi5\r\nQJHxdaXUo3SL7iDVmZZmEwguLdHzPTXWd3qnpB8LzbXQaLUnkxjFx9Uqccet\r\nLcF9koSWgRvNCK1J1nqZa5VYEDz4NG6ffviaylHCElO513BEuNTVkrpD7FQ4\r\nNZvZdK37tas8k7Clzp50lzRvJfzgvF2Tw5E=\r\n=Juee\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c604f3899275a47bad0fe63f5d97f335dd7b36c6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.139+c604f3899","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.139+c604f3899","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.139_1666735705565_0.7949144457507238","host":"s3://npm-registry-packages"}},"3.2.1-canary.140":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.140","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.140","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f98cc367bdb8b21c859c3f50a8c80e793d60ba8d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.140.tgz","fileCount":88,"integrity":"sha512-v5oubRczr0kTrZFvWHpiA56WE8FMVCgB65Z5/fJQiWcJUnYympI9OesvVgdRlD//4UI0DM84Lyxas9S1tXqfqw==","signatures":[{"sig":"MEUCIQC7sa69G4ytTlFJ9O1FS7Z0krBhCLIdZRrBp6rOUvyP0gIgL1iDf1ImFDvKX6maPmrWGF9i7+wAzTB4OPsmT22/+b4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232165,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWcFqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoHvA/9Ea6S81g+S7MkW53WbhqQkCyobmqcB0sp3kK/mbIG/oaL7C7V\r\neD2Ebgciu4qWRrtHnxghhIU91b+PrtZLEPWX4He2nkWJSq/0fBRoty084Az4\r\n1lAsAb41RRe7iF0zrlKSnTBvx4noNUMH/XyJknaxmMzxV1PVgOU+89Widark\r\no3b/CaoP8ItYFfzLeG3TycpWtyueyXtOSlUAowr5vBkjrnEqGOFzNZ/a1IFg\r\ndBmwmTiUQGEtyUD+iigD+lrQfZLodaTA83V0DeXRevfdA0hJrcT6Yq/huq6V\r\n/EDN4YMcu1RRbOor5IS1QxGd+AkLoYKoSnzBrNk3d47KvNrEwHO/K4ys2WE/\r\nJ6TK3Pf1yGWyzU+xRSCQnw4MGiDezS+cVVzxL3f3V3UHXFNTSv3knVWCe/A8\r\nLcHtuQqL7f1wVbgH4BAQHxuutA8MUh/uObIX/BxsTSkvwr+bU71GN6LxxOdh\r\nl9pT6JjIC1Hhfyb7Q9xKSgGySqRh8pyouJUeZ9tGrum6KF5ao7GRZhq/N3cu\r\nXFBsDl1RasKspHHNMoNGn8YWeJNxfyAeLWJH87iRxbi0N8bberuxQiKsE//P\r\nB2z794j0gnzRwc4zHBgD5I1vu/BJNM3CuskfqQu9xBFkmSIZ7k+i7/is6b41\r\nGbhuG8QogS5NtNW9CapJPJ1lCjblHO/pnt0=\r\n=8Rtz\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"971d22370910bcd7b7a484dd98a3a08029604206","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.140+971d22370","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.140+971d22370","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.140_1666826602071_0.9036193965790333","host":"s3://npm-registry-packages"}},"3.2.1-canary.141":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.141","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.141","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3d648d94148ee98e0578e171bcbe8cb64a0737b3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.141.tgz","fileCount":88,"integrity":"sha512-7Xagk3iX0cVXk6NGbOm596Ljt9ZqQEhPthFTAlG7FRlI87t4bY8bnLAs3vwCMQ8o/fMpXk2gINoTd7tPr8a4wg==","signatures":[{"sig":"MEUCICvtYg4/fwOOjVfzAipFKsPW8IEDya6yjgT1gnfFtKcJAiEA8IDIdHVxmefXCVxF4nfkGgTqP8sNHlzvJL8EMOiFRA0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232251,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWcd3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmofRA//f2nhRolwTsVGOpaZ2SgwmApcVN3PVpJWJRRHvAdPxBFReJ+q\r\n1krsp5FRpYwKmJH/HRWG3+7Jf0YhLYmMEMBZFHm8gnmt+sVjfcu0GeqFFA1q\r\n2uWWRNgDf2WSMHUnRMOgVdf+NBI4/AR6WhI0AvhSiOWWK7uprNY9xT5Smtwh\r\nUFL+OJOJz9tq8qOhIGYsQWN/UB/ZEC5dn6qtljgSCksB5r2BOBt1t6sciSLO\r\nHct/JzntxlJKWrl18HnqI03M5Tb1cujX2m0ORz+ArccASTcfYQcrTXyAIYOw\r\nuSgHbGZcJ+f7gfOdT9DX7vXcfeejxcHc+1W1Nta+gNaydxLEezvQhS/KqaX3\r\n6qyBt2pJWEJmw8T2AyA42SAZhiXK+bmJt5pxPAKPqXDZIss/V2WGlUSKAeB1\r\nne//17C9Tj4wLw9H0PmZmBfmhi7m/3v3S9QytTjVz5dzpbMHGZeHRhjFnD40\r\nHH3tz3lvkA5rN6vL2geC3bjh+jXFoPAn5o1xQMDoxVEwz0lJSeLQbEl+QqfH\r\nAsG6jG2aUCRvwVxpfljJQFh96PMDuXc+Cm9NKeUrMH7cwmwdDLfBWhProUqK\r\nr2jleS6C8NPlndJwrP0X2FkuN9IACdvsywmgM/OvAH6MGVZEkGW3SMa9Ufs4\r\n5k+U7qLmsu7ZX8ApHsoex3tDUEcSYouBEHE=\r\n=zc17\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"570d7b49d1284194802d627278911fdd9881db0c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.141+570d7b49d","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.141+570d7b49d","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.141_1666828151043_0.24588260703928322","host":"s3://npm-registry-packages"}},"3.2.1-canary.142":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.142","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.142","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c059f338a95a2bc4c27987106270e0dba9b35d90","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.142.tgz","fileCount":88,"integrity":"sha512-06NzdNrhfKif7Ojh3zj2qQui1sWk45JwfYppwqcjUX2Cqjs2GDg3iurSLE4lsTLUUYHyiaYU93cUSKtgCYI0ow==","signatures":[{"sig":"MEUCIQDHxNOiPLVi+OKAMOyXh9YwLdWpr09+7wd9BCB2RZMG0QIgRtk5PyEnix7CcwzRIyZ5OhDGxqOdzL0tQvFcoG8Yn3c=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232426,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdV7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmplAg//TKKrYfjK9ri1Z8XGBQUW8o3SE6EzvEONnQQb0UTp5pqFnE7K\r\n2wWOWlFcuPV6bsGWhXiGE7SYF+BYhHmDS8Diu5dggQiK7ZHCCOBQDZYeH6eB\r\nLkzcDqeR7kuz7dliRF2ztpRhMglyFFBmOfc9Pkve+QN7fCnUNN0bAZuArw1p\r\n/uMN1vA+uCPeYim3bSDpqdveJBMAw51RwxeQkKH6DXYPKFXd42oiQD2lfmkQ\r\n9huTOwkdsvVHTrHTKaVPueDxuLYPPjR/22aBRp0rO6X2mbd7j9NmvFDEEJhh\r\nETf+6DQjV83VirDJrsPlSoWd7VFfd772Xv+sUbjfD0bsS5yFQ/f3T89thUSf\r\nEigSpsaR1/eXrOOa2XKMO1iNgYj9tzOkUyeOs5LdvGKHU/fl224iZ7tba+rm\r\n0MKm5+0NkR7ejYIU8u4Rnq1fYD4LWYnQ1JFbwBcbI6RqBqeDLNuz0kS7oeHf\r\nDDWYFFl0521IGJ3qC9TQMzGjaC8Qvh74tnV7L6O/oVDOgH/Y6qTYKpbEuRIU\r\nCbVgLWZymXhifSqI6D7xIHkT6qViVrp4qmPJDOUNNeFKJsl9sNCI6XwWAjjr\r\nKB+RKVDUOZU5Duylg81+YRo55RJ4lR8+hKN0KW6xqTwoBnOPWvrNTj/2N9u4\r\npezJqD/4v6ya5PjK+qWny6ZLnHJXYEaJCvE=\r\n=+ZMY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"af8970fd52f22a25a9379289c70630370e616fad","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.142+af8970fd5","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.142+af8970fd5","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.142_1666831739026_0.3566959648217962","host":"s3://npm-registry-packages"}},"3.2.1-canary.143":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.143","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.143","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"64b6cc05ce8b14f1bc5e997084a558e8cdfd2b65","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.143.tgz","fileCount":88,"integrity":"sha512-Gkx3JsWhKfojMUrOUhdnl7B5LGX+GL5gvClUCT6bF3IBlMVLOi4KVzZ3VBIoIEoLhy7NTqxPdlvx26JNE0irxw==","signatures":[{"sig":"MEQCIDFY+/6XM5aWeNuV8gmN3edJ8kzp61uibIT5vgwwokWvAiBXat6iDAXmHOsKmdp9SRAQnLLV1Iq3iZn4rSzD19xIxw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232426,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdfJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpgTA/+IpXB0b1B8853Wge6BVB0m0QObrn9Gt7PLupID63yz1VhLr3n\r\nszfFUvm493cxxmFP3xjD5/JUN3vtNlHdBpUD7wdq1ly8yvtYOi1lKO6v4uMz\r\n64R/jTWxvdvc8ih8enHwwJBmK63r9uzn1RJbg7UirFdcVLNifEFC/c0j42LE\r\nrV4PypbadjrE5MTLoczrPzEnQOxsUfetqH2i/ZWLbWEIHa4Wgxdk9pGJ8uFf\r\nQzE/5ZhHJqIunoUO9OLBrMkpt/cSJt3h3Z7D2LaWYGIsobVGnESF3ljKQmG4\r\nxPGqmhZtmqdLoXYmQ7yxv/38G53WiFlqOQiS784iV1MYEZw3f4FTcM2c96Xa\r\nITMHc0V1Ei23RhpzlDo5MMC2i8x/n17efoIMF1zGH02QZNaBRGQBJVH7+QGq\r\n8lCFq0q137mHdWzObzo3gZ+etDpbNQiR/sn4EXPqMAubrJlUOUtMADUO4Bmb\r\npc6hts+OtcJJ0eNvtak0zXQJDmyw/XQCWZelE+XPh20X5mWspefipxEvAvnx\r\nOpGhMmMDw423jh9U3pjxOJX8eNQBa33Ib0rcmIa2B4D44ewlJQolRW5p2iw9\r\nKPgZEijpkTQuX3xbSmlOAj9mEQt6JBlpKKLnUYRExwKVL70Bi77AHHnH50W4\r\nARZxuD+E0Okx/LOWD98nJadcaGoy64V7HOY=\r\n=5lkn\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"204ad9a8c659187debee48eef0861b18cea36ad2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.143+204ad9a8c","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.143+204ad9a8c","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.143_1666832329062_0.7889507177530508","host":"s3://npm-registry-packages"}},"3.2.1-canary.144":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.144","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.144","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7cea15668dad6678ff08e8575c6d112191a042a4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.144.tgz","fileCount":88,"integrity":"sha512-J0f5dQpqPj0YXk8O5xwERNtJCHGDEDyXg1bPfa3pWIbDt5rEFqK0iq/Dr3s6oRvPyBFbHJk8h4Qy5whIPdaczw==","signatures":[{"sig":"MEUCIQCAhLHuZi0EpkM0W+yVyhEJroRjWQA16TYxs6CBiqY/gAIgLOHoWtrGNtpY6jE2pTLNHFvScEjnxbyNaJaExoLNwXg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232492,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdf+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrPyw/+M+iBJGg4dCsmPHHJ82tYbm6352ZeYFZVC6xufxy8HaUaItF1\r\nSGJmZZCX6ZnW/gcHiTtSoWPuOBgxPY5GStFeKl5T/yq46ILmgPbOAVcdua3V\r\nu2rUN5eVKl+8tqMUOK7UOcnXZWWy6MFv8lhornzCwnY4/lw384qDwmU5YVAu\r\nbTUOab8Q2rR+6OQ0eYfojFPiySWfaUCZzR01mTd2vNrn2MJmsNLxrfQ8rWtt\r\nbTHEiv7bYJSHFtrswHvaigys7rCu4eJX89rLEtoNa7UhCCis90FX5iFVXNV8\r\nOSUcP7mQTsYub1/qPALm2bE+mfy5hhLAbQ12qhCv52Wm9gBTzVotlEQk4avC\r\nc5vXr3J/GTZ1xcu/s3BQXpipHuEXM3yFICumORv4aFOKttfhuMbMT5IqVgYN\r\nhkG11dXNu1pqD+svad3nTwMmj550NThFjLOswKgVWKM1/IvXzeFBs54kEIER\r\nMTcMPRZrqU8MWVzeM9kOl982JY4IEKM7g/gM9oajJFChYtJdOGgO+xMxU0NT\r\n1pD7CATkdo8P170K2uOb34XOIpMgF1zg+97LjIc9Gmeyt+I4OytBNutQjqZ3\r\nt1YeSwc9xhovv+OFV/uItcRqH8c3VQpY+L0uORciRAk97fqY1e/sRcg9O/rM\r\n6maYImwP5eSptVaKBeTpwkyZTMR9p1PDtjw=\r\n=RcgX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9a2609355954864802bb6075bb64e56e69918bc5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.144+9a2609355","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.144+9a2609355","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.144_1666832382004_0.6535861317107445","host":"s3://npm-registry-packages"}},"3.2.1-canary.147":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.147","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.147","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4631660258deec3bccfc69d66a8e7aeae29b01c0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.147.tgz","fileCount":88,"integrity":"sha512-cLqb/sExyNIVfhJat9Mv+rHxM3CE2sUP+Qd/Mz0u1P4So1BPDrENthpIcQaVkvNQwM7sCXmPqUqTOQRHDi9VdA==","signatures":[{"sig":"MEYCIQCDw6ifHnHgCqpfxNATIiNsCbh5SOgm0vDfdrWnmAaZdgIhAN5VJlGz2wYBPLSnBi64jX2oQ65D9WstD0ZKiWjrBXOP","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233052,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdm0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpONA/8CBid33jnTxD52QPv9C5wpjr7TuFo8dDn1vAw7/sQ4v5+jmmq\r\nMsFEC7AKy/TtTgE5dD6ie9mBTo5APKmGPk8o3pbmPbBbdWRT0t/5g2l2N3X3\r\n/cbkQViFivjOB2MKsdJ5Rj9zxdUkADJyd0j2bnuPjng6rrKxsrHgrOlpHfe7\r\nCaJG+PfnXHdeF55oX7h+2r912n22Ys/V6P3A9KiVW98jBKWpFJh99dHx24q7\r\nyQhan4u5YGqVyVDkNEkvlYiEis00J0QWa2gK/TiyLjIZyqlkp7ilseyJCTIQ\r\n9WigyxfcjwsKKJGhU/fDpPN97aJxq+FH+annVPiz4XokcF+7zikGqKatvTfA\r\neOSOzXGobewBw136eoqS8XLNf4oYi6O52HkjrQuRiE99iBLigEclNtYgLThd\r\n+qIAfuSRscsVLinCr7hhqCDqIl9PSBNd0zaI5zCMa346pDr2R90SfVe/4c6M\r\nGgWyZ3vkNoANCFpuhLHhzmJ1/DgvaY3oCZFF91zD4ZytlWCnej1hOT0P2yWq\r\ntdOt/iZmuT7QL3LOFNic/646ATrVKnXZ4jfV9RDF5PHiJsB4408bkYcYiJRm\r\nN3UAiRrv07cPT/FW+UzQSpZ2TiCPMf03BE8t/IkGYM9KIn5pmc+DH/rRLd0C\r\nqMPPwxoYGnNoIcOCiLXknZFifrxGi8TsXt4=\r\n=XWua\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e05e08071548f30f8020012a23d7439b7b71c58c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.147+e05e08071","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.147+e05e08071","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.147_1666832820573_0.9717894230439448","host":"s3://npm-registry-packages"}},"3.2.1-canary.145":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.145","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.145","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"182d606f48cf04c4dd9a89ba7433c80eb7631cb6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.145.tgz","fileCount":88,"integrity":"sha512-RcV70xL06xK89kD6mI+e6CoP+YnvXpqqZ/CZteQTBM3EuL7kQ0QQQroscDCPJ2cCar/EQTydXrrI0Rj058moAw==","signatures":[{"sig":"MEYCIQDaRd112WquVYPlUOGx42PSYBYxbB5gQz2I8W9Wx9TYrwIhAKBiX5iQS8pkWhZ0eJxMJZaTrImu7z+vKj2EKyRBI2Mp","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232669,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdnsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoP9g/+JqSUYLRwuh3Qi3ddjgYgVV8dMuxY4GICT/ZSydO7MctZIkw8\r\n8idzzpnAwXjXHVPEbH3kgbU3cU1ToFVRSqOSvSO+tmuzOvn+YX9OTs3hnZDX\r\nO3JKIRnB0rmPnIGfjCRWm++ifupd699h9vt9xGSA3KyTfjPemUsNLVE0iCgI\r\nMxXoUksFO+gwrrTtqzWkP9R7dA2fhPKykW4ITzPdZDr9hR4B0CAL4SIGg/84\r\niH31yGka9qCTFHQKgLw7D67k7ab7bfVsYm2uv8UO4ObFrJ0bUgOnX0mDjOEf\r\nuhMOVkNSv8qlo28nJ6OjW9wgO0xvU7SbtdOADEs+sJNXxj4xVW/r618OQOrJ\r\nRdvj7fn6PANXk7zHyE08gRjVQ4q5YnxNZvhH6XIFfJyWj2MxjImMgHWDZHyc\r\n5JASQVrY9tXgRdQQ9wc1ZEYPw3kVCRT7HpVguInwaSisbQHJzrSMaYBtOgVb\r\nncr0kloXyOa/B2yV9hmaFsm+yI2U/bTikIhCvB2S9qUo3k27/qwthes1vfIn\r\nPiJxjYfpk2w02VVUArJadCEvi9WgRmSq0LOH79IQ4VLd6GczKkYnwHZ7pWPY\r\nXYiGv6x/oHgKqC8xQ6bsVIytG03HXajRZ4S8eb4LRknWdrgYw0uYg8mzDavN\r\ns9xbbDOqJ+ou0bfRqZ7BjDohvXwoiIpePwo=\r\n=tp2z\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"50586ea0be78655a89adc88da8194129f2a9dabc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.145+50586ea0b","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.145+50586ea0b","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.145_1666832875951_0.06768611172753736","host":"s3://npm-registry-packages"}},"3.2.1-canary.146":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.146","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.146","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"47124a865283be5a133cddac47bf0add62b50fa7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.146.tgz","fileCount":88,"integrity":"sha512-v4BHfnLVWjBwF6gXJo0XbLgcMkaeQYTBu6ekGDNRLYQCJL3uWnKFG9fzu3YioxsJc6YGEKcngriuyMRzwo/H1A==","signatures":[{"sig":"MEYCIQDEzKcdXMkLywVNz1XvU53LLqpv4If8mB0rHON92Ecr8gIhAJPGgF7D/HzOASylubby5cyf4KoYRfWh1TbKPuE+Bp4s","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":232860,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdojACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoJFg/8Co/OBmpm5Et+baMEUvz0qgKqMbztit0/Q3RAcwxGNWXaw9XU\r\n0uOp/IGmai6epWJe8OZqdYnZafBzsy6O3lsODjG/6M7GBMtpw89GQhYyOyuv\r\n6cxnuhi5OC2SHaZpk/9jPxmfWIj1Mgzd+aam2qb49j4gceb79jiULU7Ge6if\r\noQatN2QzBcQOE1kLmRfnanVrSyG9Byl4HfUOPQU7V3ANzVK8Bzb1oWDdf2nz\r\nt0KDbVgLCpVq6nXj+LxONPRNCrU44Q6+2f7zhyzOXqd4PKfbIduWs954mjAb\r\ne13Olb0/93w7XbtcUGm6PLcTEWDbxzuOuhPR+LR9ShFRuMz0egGzfJL0L0Xn\r\nzmg45HoPQUWrrU+4UYlp/v9bMSu99H9Xr/tS05BAGeigEKM7XBjBBZEfCbNX\r\nkkM+8k+7IcSSYDpQ99rV8V7alOhDc/ABaqyM66vw848y0mkNPBxo2uEQcWZg\r\nvxMf3IBM/P50TIX7eydSuEWT3isMqxiIh4tdO4Eh1lnZp0J/0lmJ0zUcK0J1\r\nxTJ63W7XAhrHiGewKOzNtav8DGPhch5knHmKYW4AapMJRsaCWvaY32DTJzh4\r\npW/caSyx7ZvvG7UPARTodgKZuf8kUgHKQvhzBU8rIOfrqgXsZWEdU4fQfX7W\r\nDkRCV2MgB1wvCE9JKiVibPOKCNRvGOVmbmk=\r\n=YzMm\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d0be5e823d45510852bad067f541f2605ba1e5cf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.146+d0be5e823","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.146+d0be5e823","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.146_1666832930723_0.9799760745490882","host":"s3://npm-registry-packages"}},"3.2.1-canary.149":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.149","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.149","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e111a94c03c61f659e968038aaa1e6342ad13e52","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.149.tgz","fileCount":88,"integrity":"sha512-YTBy2bCelMfU4beKykeIO3y/XseVq0ByYRUGYPGVVzVpsDS+cF3ooGziv656Pg2AFOJdhK0+q+Ue6HrQalBWyw==","signatures":[{"sig":"MEQCIE2QGxwkLtCEWfUrvuiOmyuKTdJlPdTTyB8tkkzcy2vwAiB8khABx0yRm9+AM9GGO82ILH9MtIjWaTH0OXKoOXdOWQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233405,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWduLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoA7w/+O4H6d2uRawjnP3/Lz+YcY0A/hGYxM0Fr0PfyNAJxnOzvtxjM\r\nB3/GJqJytOngPkqnGXWmf2gdYMD6sXPkt29AEuBe6SBzXGhuuYse2QfgFYGF\r\nTLDNKupMNGfhg1EYNmW6hlJ7yhdLSYA9TyyHkQga+O24P4q+sO/NHl8KlE4n\r\nnBnr4gBe4tN2AoMgG7dCmweTXuXdZ0QQSpR7qpwGrGEyLYwCkFOiVOnfrsd6\r\nDbZFO/z7h26oqhOyz8fiE/IG1jPa+E177UsZTMB5icN8SlDR226bf2kScEp5\r\nDy2/psbY9rYz+VydNydzW3p8QDVO1E36sKp5FcE3yARYIczAvUalUSZ97KYn\r\n7Cm6f+V5ksHAIJnb3OjUB1YT8diMFgztaD1Y+SCcHBRY4VQ94hCtQuMuBphk\r\no05Sn3dE8gYVN+TIhP7cQ9jSUaD2tVW/EXa+Z8UwXPcKWp54r9NFDgZO7+vc\r\nTuKQILzN2ispXS2QfiMJHctMWMIp/AMvolApi7PraVSOq/AjwaXWPAA1X/Oc\r\nzr54nmAUtHB3owh2Vy+nJsKemi4CBmmqsvoFcbNZZpAD2v3pLHVFzsrUfYbT\r\nvknDQvW/RFaQgpZT4kScIT9+eRHuF4cAIc43J1j2uq1e1YVUlDP3buxK9SAK\r\n3vBHX7vl+D5y+bA+Gp0vUHnddcl6iXw7SQM=\r\n=OyMd\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"810f1fecf815c111f0ebf095d07d7455e60fb657","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.149+810f1fecf","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.149+810f1fecf","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.149_1666833291170_0.1998127469975277","host":"s3://npm-registry-packages"}},"3.2.1-canary.148":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.148","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.148","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1df412c1fcc30609531ec6f82a3a29de0ce47e23","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.148.tgz","fileCount":88,"integrity":"sha512-RZBfNcI1PT6v7fFQI5+OI2CBvzu25zad/XlyHAGsCirPd0yXPY22nL7iuJ4ytIVTBQWW3kd1dWWxeChz2IV4Rw==","signatures":[{"sig":"MEUCIQDWVmwtbyeg9UNIgkahyD1FlBU3TrMlMFiZw3wXYYei7AIgL3gpODkMAzDlXgSb8zwkZNssZqi52I+DcApTvxN4zs4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233199,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWdweACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmorfw/+PJFOrEHStzn0BDDDSWbBSTY4ZJVl9qKaa98A3aa8FVjwBK7C\r\nD1zyyxSum0+XxK3h718EiblVa2q0FveyhzLJ5qq4QgUe6KowYbda7QGEMxei\r\ngXkGU+Y9oVkk68EE/pyz6a35+UKcl2yDBKEMt5CGbQzF2/rKS2NqlDVpG+8+\r\nNY6DBMkc1cKZFW1e6Ranj3a6Tl7/GixI7QiRpMblqq4jeYCo8PsO66+wiKXB\r\nREHLi4q6jrxy0KWjPEIBZSjdbJXdjHB+5b9teiu76ak4zzUqBUFw9h52gt9D\r\nxQSU3UOkatkSH/kBkf5Ankz8kmxfPGm8PKpMgDNI6xiOSbXjkYU0PpOLfemt\r\nw8fG7NCq1W4eZ7Cm5pa6ovBn+VXEYYdnecnsMiImMrvFv77tr32eqigPoS5d\r\nNbl1OHUpVGoL191my2REwJzSe42mXAnzKlU1mxQMsAeYuXhyYvpd5icpkvsq\r\nlJiJKYNg4EYGpuoZ7Z4X8521vMI+PfUO18QKRTzZfIvQQ/Ia3ImGelHoQu6p\r\nYkG7YW6Bbh6du8ERCu+UPjbGJui7YlqydSG9w0lAiA2jsaNwktmYE2ZCH5cG\r\nkdQn4rdsG2sAk0yX6AQ9NTM7TqZKuv5VmGeVSB/Q6ETbkSs/8MiGQ2isjn0m\r\n0nLyyLL98ncLaYHXLJW6ws2ZJBQYMh/r/Ok=\r\n=Ej9U\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c7cb9d975742ea392704a6cfccf1b42cddbc6a6d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.148+c7cb9d975","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.148+c7cb9d975","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.148_1666833438403_0.5669644013860247","host":"s3://npm-registry-packages"}},"3.2.1-canary.151":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.151","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.151","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9de5b48a115d43976e0d803e83645e9929ce2c91","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.151.tgz","fileCount":88,"integrity":"sha512-U1Ji+88Dd/8dfZc2n9W4+XRpGhtuti7Sz57WTGXKWpWJhvpzm7SV4ewXiyilv8oMRIcZ2YR1kFYQSfU80XbMvw==","signatures":[{"sig":"MEYCIQDKmJeotQEDeQ5OY4Av69fmQQ9WqPrs/iLL0DMBgtSEnQIhAMdiDvNKisNjXOoz+inagnA3p/IwSRQbR53xNsBer8R+","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233576,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWd8PACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoDvA/9GJ2BfNcG6aEBbvgHw80pADHq/gJnjc2f0R6dUhtUc85qeY6U\r\n+5aUdctG2+/4UB4s+WQ4Z3sIbims545FFpW33iKE/iVTrxqOjSVeQ1sCwaFm\r\nEkVp4DUpnOEC5g6bu2NaD61q3JkJKsydGj0+HgEBPnGhispEELN2kqpUcJMS\r\no1ReiPvIWPPgjxxKLIt9osdo3uDlqYJR1kZZkjNUyaPiyUYpOnIb62Izm3BF\r\n5uiGpVrVPDaZtc2nvZsnXYblSuOgQrD4vhNVDr04VgLCrxMK/D62HXIXdpAG\r\nk0mifU6LxRJA7we/kx8cwqsQE5RmtTuxPJdOjzt25rypHj/0gbnqdnEgQx5t\r\nGG/k9YDitmkqe7srr4xByswBj/sYQWh/fuUG+CI6PDNsDWIACjm/4GUWE4/K\r\nIqdzDoVXdGSBXxFqHe4vw5C2Co5KyIJXQ2RKTBv4AQVGXk4Z/AlecZkBNAkV\r\nM4cdfdsbj1KtD7hC/9ec2k1Vm5n8jbECxZbHvvxyGZkauvb455mMGiSj+7HT\r\nVTsrb/jBcaz0syT+39eWVTmWrBOD2QBUjm2mxVVxX27AFuj4Dh0L/NwoQC8U\r\nsR1woxGXiFyJTkKXy7ru7si7+kDDVkWrRuHGyq2jjCFcVGm5MbxWgIRKEv+w\r\nc7e/m7CD2anARF9/u/qsQrgD+7kOHb0OBm8=\r\n=cB0n\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2f5a120062f82651e5a010067a0bf57e22be4369","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.151+2f5a12006","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.151+2f5a12006","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.151_1666834190919_0.8422049835611305","host":"s3://npm-registry-packages"}},"3.2.1-canary.156":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.156","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.156","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"22f0351ae06c9cbaabfc0c473593c3b6d0136f4d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.156.tgz","fileCount":88,"integrity":"sha512-gATgUQ3z+UIL2wyjFv7EsJ4NToeydz3Bg2Qw9rkso0N/CRZ2xuayl9UApS4kRVfUsbR5jvsfOvDGARHE3XAU+Q==","signatures":[{"sig":"MEYCIQCrw4RgfqqLTf66AtZsz/g6UZSsD/s/pGklBamFUV6ePAIhAM0Pg49lLc9A7WOlcMEpPCMO6oT0ljYWmFugyPwjvIWW","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233576,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWt85ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpyoBAAmpG0xN9xwL4/bTOnFbQEja6OUgP1Ka2OphAbehpu/pRzaiXF\r\n/OtTNIDvGhZJqvPwZTwxMWiJihYH4beHTmS/PhEZNaBInMO/tYlzZ6zSt5Ep\r\nCSQskGJEBwlVNMnIxUhoU5HSeWcFmTmncNajKnDZ6rFkMr+qCacn9nZOqILe\r\np71Lolaqp2/dAqeggtS44Fn7KxxheVQMRSrLay1Qae2gYPh83T8kt8qqVViI\r\n0vnG17/eTbETbkAUpPhodG29ZD/YcxHFCBIAoyg2RjRd4UcfCE6DIPf9VXdW\r\nHClCB8twkHVc7LWSC7PQ65AnIhf6JdGRh2rnTHVO53CHaPMohC2WW9+wY9B+\r\nSKNB8vznWtoGEYnbU69E05zZevAVdwHuEzAKvXpET7eM/MkLRAriqgajMFU7\r\nETzLxqrhex29c8Le0ZFK6EpjAv5LcpwEDjC6pSc87xkJnRjrbPtdMF2TwYGR\r\np6BQ8xUS+zQZKhEYNszLeLoujKjt6s84shPsRAssLDC2a1vSU1VmYtVPzwR1\r\n47SQr1cW1XrJAM207WAVm4eBkbStGQlyUCbvPRAr30Lmt3Wda79v8iE8rxg5\r\ncgd+38PXHUStK0J/XDHLykPOSizZsyWfg1iZV1UmADRr+Mvu9he7M62SE7YS\r\n2+Uhlahn0uYZDBupwGWd2adQ9YiNI/3pUfQ=\r\n=Unx+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"113b91b269f939e47bd3c2f4b7029c58b981e078","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.156+113b91b26","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.156+113b91b26","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.156_1666899768828_0.2663369169562493","host":"s3://npm-registry-packages"}},"3.2.1-canary.158":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.158","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.158","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8705698bbf1af2e71a3481eddd7908b73c4eb7a1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.158.tgz","fileCount":88,"integrity":"sha512-jtsO9sNIjJxQfO34WXwzh83+ZTaAOYL1Eu4HyKrCxwFR/1ffsuMd1taWyXo8xPVNfkIS0D0+ms+5vybjPGZDXg==","signatures":[{"sig":"MEUCICb0gw/rhHiA3d7yesBATJE6VSVLWO/xt+EonOKKc6yJAiEAzHKRrP76HcY9zmzpV3iVhkudvRTwvltBbDCq+sLYY9U=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233576,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjWyYbACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoraxAAlUTeA6gVcnsHMEffLdaOY4UkjXZvFY84UEVgRMonsLjvjR1H\r\n8kz39/QFfAkD8H+Mdyr5KQmkFsXKWGYVY1FavgBfT4x4dV6ii15ynnyEuave\r\nilFMqH0NI1HqHK80kLBsGxtyUcdasMKd9jO2StMAa+zeQcUfOi8EMZzOEKeg\r\n3zS6WRxMN34zISRKS2yYmFe/U6wqbunKokctR2GqeUQb9ZqxzX9ipuZQz65/\r\nw5WepVGgXUeCufaXWgls+d85ujNPY3suFZEPYBZwnPi3N9Uhgc4m0z2s5l3b\r\n877FtG5+xYzDdWXGzKO5Whb/hFjqj0zPB8+n4fSnp8NOUfgXdY+ewaFWQeTZ\r\nWwBAriNP6iOfSZxGDZLBoDw5tWuM+q1XkssU5t4ecSqtvNFQkbs0QrrACxfu\r\nWrxKLsS7lb79+2Wn45Rkm+yfC8YlSh2bdpmBqfy42Xbyd5v0e13fqPOR93WT\r\nNvXDroMjgXzcSk1+g6/EJc5V4IUc0L/VP/LrsEJmcvqGRlszjhUHotenY4YY\r\nXJP8R1b74+mP1+xHNN1XwcxyPuUWSEFpt5lOQr1f06KmPedffK+MRQ0i70FE\r\niEijGgVlqsz1hFb/w4YA/vjQZHupkSa7Bcp9gp/EEbVN7MY2iiXhqHVL6cb6\r\nmpLqX276urhJzkkIRvRdqsrVHvnbtuyBBMI=\r\n=/oi2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"90a9f125daf07352d9c834727d7cfb0d0ace3fd5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.158+90a9f125d","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.158+90a9f125d","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.158_1666917915073_0.861421035122008","host":"s3://npm-registry-packages"}},"3.2.1-canary.159":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.159","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.159","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bbdb22d7d0ecd426ca6e877e96f5c304c579481a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.159.tgz","fileCount":88,"integrity":"sha512-dV5QYjl/1/sN5B34oxwL1wYkrRUmd8MyxKVjQlL1or12USf5G7cVzN5DOHnM/IJNvfPf+WdRBj4MkCghUP/rFQ==","signatures":[{"sig":"MEYCIQD7yTOYXRGHWloS2F/RUxLcKn75xIlqCC2KgTfQQvqFCQIhAPE0Mu2HLsXtL1dUE0CaeBN0VGSAQYPKLZzqtycORnY5","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233576,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjXcJmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrueg/+Kd3QXxk5/uAn2YkWoAWCV55DXmkb8PMlpEuXQvQZaDHMJsb8\r\nw1xdk85U2gxUumbFNcPi07FK/IV8+0RMMgCHU+qHY+9eB9EcWDi3FY2+Twey\r\nEJDxQb/FzfIswchSdTJosBrGMRtd81M79VolduXYq2tQqZD4hlVnKP9wVMf6\r\n2J1aOEmUVJJuHm0fAj79Z527Hw7rk16+YfzSrw7FOHG4YwKVCb6abeJs94rU\r\nDDyPhNiroWJo69KF3GAdVGCrkDLv967bQcWM0/T/io2EHjzqE1LliDwi1wOn\r\nfiUphLsDPxoXhn79nZRdWlmxLoHw6OzTnXkv2WSmZe7ldqIhatwgJyMW7Luy\r\nh1+E3VPgVvFKUL4ZXvSMt7nUp5hseVz++R3aFUOBkRJPTVNSKwY9vbsOe44o\r\nQES3rnQNSUF01sg1rqLOUiKtS6dZdJ2kPGXK1JbjU4V01V9jZp0B3xnN9DzH\r\nvEAiDNgGvpBGqfxqKGPt3PbrDBBtSUu/PdpCHwioooZvtcEX1yEzkQayKpfB\r\ncAkDIOlwoFL9AHr/LyORkgyOUfe6ffnkLDXwUmaP04BY9R63udE38FcyJloZ\r\nuYLbDUphE5biee1EbezT6tSHMIvpNAG7VkrMGlm4HBGIxHjgzuLmswxeHKEY\r\nZ1W6vKeVlyP5dCtcAwsYwTwX2qZuon/u9mo=\r\n=nz8u\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8935b209437a7342d571ef12dacf437ae248ecd3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.159+8935b2094","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.159+8935b2094","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.159_1667088997859_0.3713678074472391","host":"s3://npm-registry-packages"}},"3.2.1-canary.160":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.160","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.160","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d1c1b82cd6455237b203c5e3a1f5efb270faccf7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.160.tgz","fileCount":88,"integrity":"sha512-hE2THuUu4NY8q3TvyXAiJr9F0TId7QO1D9oDRNJOLN8gECrAfy9y/Z2M2AhTqI1XZ+oqnhYlNPc87NDSckIcIQ==","signatures":[{"sig":"MEUCIHGBKSmgC5ZNbVH/ekx3niePeu2qeXCuF0q7p3QNmHPKAiEAvN4HobaHpZewlIU+vDzveeG+Tphy1s3TXiqzoR+L6I4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233575,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjXvECACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrq6RAAhIFhM459E+Y1ymCnFcsh7rOAcPJfqXxakPQLKVYkx+LChV/U\r\ngul76JB/ZWI5vddhwko9DdT7mxhHzXx3RzoWWgbaG4FyILMiOb+zWte1UqbZ\r\nzG1tMu2xA2NcPVqC20KNSMpg6F60sG4cJl4gX62RCLn9hSZ5UtQOfjzwhMEp\r\nUfD/ALvbE3jtVnXJQZ7K6SYqeOGvuglCVStCrRCmSin4WuCMabXyyK0R0SxG\r\nQK6ROYA83LaZvpk5GWz+AnKjpycE2nu6thU65751Kv6UgD+ZEq2j0oAKD2Wc\r\nkGBqYEOdS+Y2izahHE4lUxZV0Ja8vWarDiDmqkAwAQiD3vhckynbr1yj6v1P\r\nRZG+0Gvj1mIzcp6rfn5sn7BtFahwNxQsasPl4cLGB4sEdstABhL8ZDI/SZwT\r\nmSFms2fQYozPGAbzuSfWIvtsTqs4OWZR730VbsaZKpCeLgQhP5VHsqdPYs1X\r\nTo40ninuYfFl1sZouiRbEDfK0L0gWHOEfyJ6yIqb3OBf1CxjABCydwH2Q8T6\r\nacw5taqIk5CZd5h3PmZwD1SCUFEQMLduKUQ4kQ0ZDJ9RA7YfBAA1JQe1jLh4\r\ndbR4LP9+HcktkNDBYoC3dXNq6qQl5i7FDRtWIT4xAOPGYqOMagJ9hbV+ikAa\r\nTvMaegGYGCvE4PXlFpL+ylGTbNTuF15jQig=\r\n=Zjbz\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"97f6f622e06e34e6a88f167cfffa1c1d78a33b92","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.160+97f6f622e","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.160+97f6f622e","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.160_1667166466459_0.3600342053439731","host":"s3://npm-registry-packages"}},"3.2.1-canary.161":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.161","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.161","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f445c60c27239f8295c41afaa01d79e1a2c9d6a0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.161.tgz","fileCount":88,"integrity":"sha512-Z1IlH7qY+zOltiD8m51t5xBsbhCRVc7CgRzBZen6wlvce77k3anfx0ev422O4KsIeafxDgBhKfaz7qc8Mt+ukA==","signatures":[{"sig":"MEUCIQDPDc3DvtK5mBCCljZyhAkwxLZLgM+PrUrnKk4ykLlPOQIgTGc/HivruMalizkHFB6+R2vbzL7ODMpzcm5PzAkjUMU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233575,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjX7+YACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqecQ/+JlpPUHLBBKGgllZJlgHY7fp8xgvFrsWtTL3RU9waHYbvNklo\r\n2gUyGuMpqb/rpNxhz8f4av0yP+92XjLxbTRLovbdb2ZmAqkVsArdDwC/cHLm\r\nAi0Vs6Z2B+HFZuDCepKmLmrGrtfeR46mfsbAHhQcIiF2Y+YaXn5eijmuJdim\r\nAjDnC4MGQwNyeKpWqqu3TQZirbGRAhy4isKifTk7KX3pHzUJjK5nPgK/9RMt\r\nQ8HC9nbt216uIYy/63BDuqsBvSe+leZUa6S/3u6SwywsPHVwtW9Jumm2YOl9\r\nypzwzSPEqiI8BqaUH7pDOs/PH42D33+tXJn/IXLHenSWAsxqJsERJnHtuZSh\r\nG2131lROvmqjRXfGZTf3/yvPIYdGh/4FaEW5EF+eMFhvn1vJZSQc6vfjcMiv\r\nbSjyMZYbxHlIS9QRkA/8t9UdRfHBlnuyvdqNxGeO8DBGcGBxKuuN77vBT8id\r\n1PnqP6f2Q9DxIe8XYlYlRrxqqa0RcXKtVn3h4+AM0uXAyk7n+uVVE4BfNnb/\r\nSGMBdRQP8EeB6VxnuAoYl0j3F2BuFoTbeMs+HOCgqVTjXtkretGKx3bwXRqA\r\nd5mxAcE9t29ggZdfrSe8XQtSuHbL8Hm40d1rjjb1NGsph9BMNWjxznd07IX0\r\ngfM2hA0Ub44KbH2kPiyaSFn0Q7Ioa0WTmtE=\r\n=C7NY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7f6b94ea6c11c8dbeb1b432c061fcb90ee938d68","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.161+7f6b94ea6","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.161+7f6b94ea6","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.161_1667219351989_0.8103327686710728","host":"s3://npm-registry-packages"}},"3.2.1-canary.162":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.162","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.162","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9c321f427db33de87a288c26702005c339686e10","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.162.tgz","fileCount":88,"integrity":"sha512-BkD+bBTkmQzkk6HqNSBQGKG9/0NLEQ0oVpgRNtFlYI7jb9U2RvRoDTOzpdfo0Ekt8+nSuDTXBOLNgoNgUi/gXw==","signatures":[{"sig":"MEYCIQCxMS7W4QB2MKeqfy/HwdFFDOAG8GdHgZpAC8e4BGc7eQIhAKXeyRAljh7FuQBGXoZVTb4v3etnLjf/JwPx15o/i0p5","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYBOYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrEjA//bbholz4cdkWjT+BlH3TT6dworULn2SE827K3c2IA6qaT1UDX\r\nhclQTkw64R50v1MGs/cobq5hpiioiLOUdOgFwIAZhzwHd/p8j+BcJfg/Im5s\r\nH3q9q71wXW4LVsqK7ywIVVgmMvydwF4ZJAxq7OmsACMoWTiG3SglngFAIDP5\r\naxJUR58LIrtWc9JCkydxz2HwQ49PIEZus9qScRzAa5v/LKEg+KOwC9FYBV2N\r\nJoEiah/AQPnGJC8s5DlSDilYSc/7Ogca/nVkOGq3DUcJ1kzkQsV+xjfp4icA\r\npu7BcqAjzC7brkMXdBX8hnzL0SPQpBGedwz/Qa6jnVddMAyMmmsewXbILNoB\r\nYSBAWoIAY6by3x3Zw/Ui6Q1SWLoxJUfXtHEu2RTpsXs6vQPYTC5jsH/6tRBx\r\nNBkq0aeyFHCjTlB2FCpSNMbT4j6fm7zSFi3UBwfRxusCVy3zaNgcYkoGz3Ms\r\n0rzoqoHYIhBUwW1Dlr62CbpunQvGdLq5YQ+/QEjRpbU+frEcl589rFeyaCNR\r\nAiRE0/r9YUAydOxgn5J8KObAU4/4adQXtCte8X/R+WvYHZsos+AMlJ6cWnAK\r\nOfSUuNoVGGcyaOOKgS5dqZFh+PvE/Mel3QuvDNc7l5yIgY6U58pNIuT/Ah34\r\nvXxRU34KlCCJ8sdlCt/YGTIoM60vOotkqK8=\r\n=X7sF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"544374612d6664d8b0ef4ff54dbc2a43c4e000a2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.162+544374612","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.162+544374612","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.162_1667240856300_0.8858092890810894","host":"s3://npm-registry-packages"}},"3.2.1-canary.163":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.163","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.163","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ea51950c82cad0258e16c3e2a797b6364554910b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.163.tgz","fileCount":88,"integrity":"sha512-Ys0c3iOBJBgbwTCFkZxwRH4uuGPEbT3ZaAsI8nkKHRxJ6mlGRBrM4h7BKzSeXDiyBlo9tpGxHF9Ey/d7B/SZmw==","signatures":[{"sig":"MEYCIQD2xu4wsNe96OsE6PJrenAi4jSUIsssUpkvg6Z816v0MwIhAJOITqSRAVOJFQd981J6gVbDTKRwcaLsQlnG+P/OuSBR","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYEkIACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqhng/9H5JqyrEoS+sMO2HhWnbBi+BFHPwKlzpLFUSuCOCc58FmI6wU\r\nEIIbZgNXw9U+65Zl3+5tXy3a5LogkysywTxxHfXJGiZVBZjtOh/X6BX6ZXhO\r\nU1FqLuGrdmDrgnbWIwAeEcHy2lb2bc1i+/BfTfawKIpUoswHx3KGD0CH+HVJ\r\nOtXTJb44ErxIG6VqSnhfMuszcnKxva+X7/kDMkDBBe8h3XIUzg5+VHjGnSRd\r\nVs1vbKHCGKgHlZjoi2jYFFmFXDWMvF6AxoC+nFiAx+Pt3Y+ImtpmcQpvdQKR\r\nOkpOvq/hs7Mv2Bi6jZc3el56uChIObMW7NiS9RNtDiFjYtlb+7e51LtFdhrK\r\nQ2xgfybH301hdb0zhBaqi3NCFAS/TzfXz/A7/m0Lp6zjJYTwKsCeXW9sOTTL\r\n7PaqkCUy2p6g5SQjfsfWgb4FhDjY4w9VJI1uZkoAKFcwoAa9ltW7iwRxaSTl\r\n11i43WFF2RUrT1w1tDdbl12VwHsmIaiBuMSL9K7zuEvvrdO2l0dExFY9Ip0D\r\nWqJF2j4LG0GvwZeG/I3V37F5TNCwdQ/1846ftnH2m2QfD/PYe6cvUF7QXWJW\r\nISp8dMJExYiXSMvHq9birC2iS0umdE4zyW8mS+rprubsWmWEW0yhYnBagqYc\r\nSrKIRX3MdbPAMmNZI0YxLrHyWw83Z+EPMtE=\r\n=GLvZ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a388889c084a22abed631ed4bc80451474da965a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.163+a388889c0","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.163+a388889c0","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.163_1667254536687_0.5503510460835384","host":"s3://npm-registry-packages"}},"3.2.1-canary.164":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.164","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.164","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0a76e0241f18f249a112719ba7240a58c127d342","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.164.tgz","fileCount":88,"integrity":"sha512-+O7l1/ld5bDhUBrOJYbBKkIaFAXoQKLf19SVeZMUXlSZ0M8n+9O1KYVJowEWw0F0+QjsvKiqUQyMgmmBqaif3w==","signatures":[{"sig":"MEYCIQC8pa1xUzOLYrj4OxU8O/Grbit6FhCT5G79whPepTMWIAIhAMdniD+V6NbVQ6mGj+aWIvfVMYs/RcO7HedLRnmShdtw","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYdRnACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpYMQ//bBT7HEYYOhLuPxSCKTcdPy0E2dVFGtfJU/lThT98bBkfkTnJ\r\n0vq7gx/ysImgq0VX6+yFkPHFyDZaJfGO/Feli508wxDMXA/1rs1eoqCZAApX\r\n7BmCGq4pGm1V+e+hauRgqP7Pe5jDs8a1WusNZQ6Cdbm6NMLppgkMG8MvnkpL\r\nw4ya8JQnGLxG929XMtn2WvpM2S1dLxhDVy+bJz0IvRBwu1T/mLlfPAYyc/Up\r\njv7NFlmtiSQPXI+/ePvOX49LlXQqzVa4C267RGaBkfscl7OLY9rw6mnok6sk\r\nP1u6IPVBk3AjPonhBULpZyYTKMlwZTwTO4IgwsHu0o3I9WxilB4B3FZ/EXlb\r\nNLjd7H+IpyW65lxrH38Ve5X2vrZBJFlwoDfFVt928vuNfMLUFaIKDA5bXj6z\r\nQWw8MBwP70RqMEBkazAT8Nr5Cg7bXJrR8j4lnWOnpw+DjXJeic3pdoXOR+O4\r\nJtDEDbtKMDcRZNjKAqtRDovS1Z2t+THQAkIu6dex9eCMEPUq4LRncip2Ffwo\r\nVexipr5Eprfegt3yt8g0O2pMulJeLJmKB+1ih3yamuFjt1a4ZqRiXIgJrmzw\r\nMzeX1NgngVrPwBJ5QitQtUc4AyZBR+Ldz5nWdxgVW9yQHVJuTGdJZc+dt0U2\r\nbBc+s6wYOVwnCYUTkaWP8JYrvUIrm2GI4YY=\r\n=ht8v\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4437e21b631119ae406eb5de38ea1f38b0bfcee1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.164+4437e21b6","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.164+4437e21b6","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.164_1667355751373_0.2748230360260657","host":"s3://npm-registry-packages"}},"3.2.1-canary.165":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.165","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.165","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f2484ad6b1cae907cc99a61f003e66cd1daeb0f9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.165.tgz","fileCount":88,"integrity":"sha512-/RHU6Y3iO+CuceiB91CZ/r/XWelCHexnphbiSrXfxqQ4clSQzVchNy2PEXho9f6puXGOwEMOfju7njpVf9OzYQ==","signatures":[{"sig":"MEQCIGFNEpIXYF2a6mw5FtUumkDcSbokzYfnpUTqY9476MS/AiBfcSG+O6pTVcu/xAEO/tUm0VZBAUwTiIZAYHME+G47jQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYroVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoEiBAAl0qTi2WwiKZ+siUWN7JjzEnxr9R9hhcOEaskmcrsQlH7ulzi\r\nvslR4jXKsoa9IzDr3/g/TOCCPw4pKkRAOqdqfGCQ/dQ0ydF5bCdirXfJJpWl\r\nxm4AtdXRzoZ94hGULPWf0SFDpbOKwbUxd5n7/9OoSmFeFSgiuNxwXncR/RSg\r\nSAZfohEBsIsj6oBBWzsRjHn/VwgRzUnhyejBr/1LBIsr4YdAg9anCgO+52Zd\r\nBvKgzBaHTgir4DEpn20NTwxq3CvWc60X3z6OjAg4zCbPGGC6UW1jZaEmMFyz\r\niP72yveoy8ktG+ldewmhHekRBLEaXM1Pjy9N6NRtheZt8F7dSZb0C3OnPSrE\r\nzT3BcH59rnQMMrbvjBPbIZE9SPm8UceX0+fu4IM8I7JhVd35C+U1Y5bdlVOL\r\nYujbbXekU+PkaNeAhU5xXOmw3dsPSyArWAnMyr3C6bhQe0px5+SfKBjCsKWZ\r\nOSJ0oBjEyJvHSabYwT9pIEsMDdVwQcQBOOXe5LXtuuYH76WO8wRyNQDyMwnJ\r\nVnbc7Inq3R4z1TbDDeUL5P48iNS3YKPh8E2BZMllQ36pxPiygCiPW5zQaFcY\r\negjkA8qVpY1YyBEae8Gr5NlC+Giozn4vANP/AVklSNr9micRJkvOBa1kIncy\r\nFNLZajlpqKPNnnKgGdY+BSUTLYzYbyXVYWM=\r\n=5bmJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4d506cd87984dd6390355b98b8a47ae26d7f9773","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.165+4d506cd87","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.165+4d506cd87","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.165_1667414549673_0.2515106552788553","host":"s3://npm-registry-packages"}},"3.2.1-canary.166":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.166","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.166","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f823f6377a38d26e58dea555e1589037cdd59654","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.166.tgz","fileCount":88,"integrity":"sha512-gjb3xGQe5zEgP+nA0YFLJrl6iM9lUNx2HvHdM1xxhF6Zq6OfMF/ClIv/cZcY7Nna7hWR0dE4oVla+zJMZ9SXUA==","signatures":[{"sig":"MEUCIEnF3kxenRKMuzvfdK3cuzuiPI7AcPO87zUEcTRjCQx9AiEAz1iPlA9yeKXTQHgo0EjdQqaXWNavEi1vYP0I860upVg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYy7nACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmoqww/8CoDwnyxtLYMyOmulCGuhjPs5L3CxmyjNPJflk5r7GlGrrRnd\r\nJnsy/r9V344zqI+elF2UJYAiCDFxiLE1x0mR2ZmoN9GPoZXjCEUadsMvZdY9\r\nmz8cXH2dsLybCWEwCkSwwBLXUu4h+FMyp32EVRYf21mB82ciLB0TEvlP2T9V\r\n08VvXWEQ4bdBtcoruofgYcbRnKFNgl9OsNOQKZTIQvFQu/FPdCAA3XfgRz7d\r\n3ze1UkgFOgXZmH9ttquDH4nD9OlGJizlYDGNZmelKq7RongMpaVck82wk2Uj\r\nawYyyWTjzGCNtw1SEEvVnS0G7SaX0rmil+0JbgNNWJwW20OQ0jkZo10SFU/A\r\nFu2mYm7+ObgxoPQaazGYshmR2DieCyCEL3RD7/ldSKSBz3byGWjfYzqHhqI+\r\n4hWEaEM2ElHAd7Q9T/SIJ9djSxF47UfJEPLwXo5NDMEXFVsQ3dX3+ngJU/wh\r\n+e8/VBiMG705t7g4eyGRqMCm333pg/I+aiJxhDWrwNHjSQ/jqfZ0+FwctClG\r\npQbK/fhN2myqjmdu8j+5DhR2ez3rjnaMSa4D4CIXUKGvoFqN5oukAA5QPbOt\r\nayrkRhzYZquxDzYHRM8DBdWAgdabAzSVIFGawNx1cJtXtQLgRcl0Wd0nJS10\r\npoY1+ePHrwoQeyg0wcfsuFBr7ytdRyMY4WQ=\r\n=dRbz\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"95a8702fffc942f07a2ff861e6910204d00179fd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.166+95a8702ff","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.166+95a8702ff","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.166_1667444455066_0.06812451833644029","host":"s3://npm-registry-packages"}},"3.2.1-canary.167":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.167","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.167","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"06b56afd205beefd842a982e8487d3c8ea840099","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.167.tgz","fileCount":88,"integrity":"sha512-IH5492uWWlP7U4MfVc0wGZXw91CPthzR3UouOPxPiReIFmp3gH6ynWRyZoKaSusaFZMZNT3o3vc3P4SDBxCwxw==","signatures":[{"sig":"MEYCIQDcsiwao3knL9AOKTG/Z+u/rOZAAnEWp3+1XY2yacpomQIhAOgr7BUce+AYWzFTJXnFuRh4dof1s5C2qceF/F2YRh6P","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjY3SlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoINRAAm4Q4mpEiF2SBuVIFbxuUBm+D/xYxP2nBRzQKG8NrBBkEtKiB\r\nCX9Gx6e9XMoYKW+kpFYIrS8y1hPnGg8jsQouIZk8jVARorCKee0q60c2qxty\r\nCjBwmgZqge/4y/B0e7a+cHZZz8VuF9Lt+TwZMK1cLeYqRLPuT2hx+PTYwht5\r\neCXZeo9sCAdv4SoPx2husWDAICSaaXo3q4+mYSCrdBm5O2PiYludNffYu5Y0\r\ndig8dbV7FcQMe4k9sUfvqX0BuXPlcZzKylLy9QShYeJKxNB2xrjiQmkkJipM\r\nIibqIWlZe0ku0wTIknuffRd1Bfiz7yJqn7e773/E7zOtjs0lO0usn9Uv7XDt\r\n4RYdFsfthguPEtVSj/6NvtosV9OVfhZf6b6UHQp1nRWYncr7LGXuAzKLJoTm\r\n6JlLyVwZN9Lmc47HemSD1sE5WSxlMtfaJHj8Nw6LWLE+3zX2BrTbNvMX/CCc\r\nyXTY4twx7G0lF7VS55bzyyRR/jGEJHJhB0TcGv/SQ1fDXVZ6vYImd2qKegDp\r\nVQn4JHsIpHZKai8MMQRNaaGzQqa1v+Z4MYGjU17ISsrTI9+XDrYDp7timraC\r\nunLK02tqR5zdmi4sdWMdZ04+E15iiria3QEtvqBwzUXZhZYn1mpKqtszBkkr\r\nFDFoDphpYy8IrSLzmJEar1e9WCRNROiSYfE=\r\n=Y2Pi\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"424fc08c773c5000151731bee5fac3022ae7e08e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.17.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.17.1","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.167+424fc08c7","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.167+424fc08c7","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.167_1667462309103_0.6028338338601895","host":"s3://npm-registry-packages"}},"3.2.1-canary.168":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.168","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.168","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3dfe8851b0513bf24c4cb7e57036bc1323d15f90","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.168.tgz","fileCount":88,"integrity":"sha512-TPuL1RLLmQg4cIKHih1V55o6HxCsgISlMzEeLc7gREhYiEi1TDQCFjcMtylb06CiB+n3kV+FzD83EqNsYEoB0A==","signatures":[{"sig":"MEUCIQDXqPUhhxayGjHbezCzBCYY0zCJ6SNzbaEs8TVyVWalMgIgWS+LbpKhX3BAyN0BOSDwSqx+g553byzf2AhEtw0RdSo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZCsJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmofKhAAhNuBf/6REbVEgI1ijSe8rGVWS0Bd2oYzas7bb8bxqo2TJarL\r\ndaMcZKX+SDbE9+iJqwHAM82Xa51t6zzd6GWaf06HWj60qIQgybqxXnpDvUVh\r\ny6ab0dlnlxclFJ+Ov8BpyYs0IkzZzhgxVBxpGrR9UyEgmr9nbjrQMP2+mgfM\r\nSpb6CVhRvmWXGK73RpjLcQe4kbtWgBOss15LwHBoKuboSa9oQaAPRiVXm1ch\r\n0uGMq7MVVXOILfZq5cQbRcUSTJjVp4AtxzsghCawmswd0NELWhUqi/Pg+YK0\r\nFg1AVwL3yoGyTEcIkiYKz3IlW5u3kRhOBstAof6rMwMivowFgy0cx2SR2BNs\r\nd29G/QKdsmkMUxBM7+GqhwnXXKNXswQyiv6k9N60yl+PsGkE7xNLpCYuFNXY\r\npGRI9xiprbfWPO5sDczNMhEqh8YsG7LnovCa1LcanPKCSd1ta791bHas/v1Y\r\nYMONobprW0ocaW6sTFz4JhDyZJUk2mH7iniuHATp64vqE6b2McBfSlBxVBSG\r\n8KVTYkkA5KuEucV1tng/Yi6FmuZacQTgzUXhclMQY/lc63IJNBK/SAwAKJ2z\r\nMyCiMfPwHU+4Titk/742T6LVKp3jvFSDFIsoHBsU4wuVE/Jowt7FuavAf21O\r\nSHAYOPwCn111J+C47KFD2aAecnDbkb/MgBo=\r\n=asKf\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b051e6f1a00a0fcd6e65f735f63abab23d637255","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.168+b051e6f1a","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.168+b051e6f1a","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.1.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.168_1667509000869_0.9860903188389836","host":"s3://npm-registry-packages"}},"3.2.1-canary.169":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.169","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.169","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5e78275bf04f181e437e72cb5c9d7d80619dc5e7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.169.tgz","fileCount":88,"integrity":"sha512-GRgahGpa1I8PLAERjCvnIOUpg3yJOG8DAIxi8rxDmb/qwIH7Prcf8HqKP9feSM/ASAFnp8/+3elMXX1E5sIEFQ==","signatures":[{"sig":"MEUCIG8b2q7qYs8t4KhTSQa+iapOYJeB0pNdP7zaX6Rs2xYYAiEAijJ9//xkzXHFhkY+LROMPX1/3JZ0dU8jA6Mbq7kvs1g=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDZ9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr5Kg//eG6YnEN+PG4BapQKEgKLtsr94gHUESj7d85WZmrMyQKg7NJO\r\n1fXL/0J6LEkV9fAZEH2u0SQwzaB+8PrhJoUTKMRSUDCyftbnf/LemV0bOesg\r\ntxn4CaMctLULINwCkGWp+l2Se+YKX2M6OEFtqyKbJBt1/2O/B31IbW+cI0zQ\r\nemTN6LqXi1dr4afIHo/s6ZdzhNYrZ8XQASdrDn2ayWceM9SUhkX6O84aoBSn\r\nYFwLC3zxwN90B2iHl2f3Em6LeellntKk7A/CqJzeraU5vubbvrJt+UefnXUN\r\nXWv2VgilANNFtduxuOWagzbDKv1tIS4wJ6kvLZHi+qJSR9p2hiuv3zQbHOE8\r\nzKxp/PaxP99Xlelgz7vR+rWChnt4sxWH51TRILURbzUrOdDKMYQvjSLbO5gR\r\n/qDDBxrAcUAlMZ2VzWliC68qQUUOW3HZHE8bkjPtyOp8hjIg/mJyoSvFsc2D\r\nNuCg5OLcB7+I5IjQwcNaDyT/Mf2cJm3UMLF2q2wSvzX4TqSn+6IOHAAh/arG\r\nMFTgR1KxWdwOAm495S1GK91QEnhHU/kHmM9lONGwHMMiQciyin6I2taomycp\r\nI7Vzdm+rtLsOoG4jD6hqiCanwds615C1SCFN1Et74KuFUrLcQuBCF021XQR9\r\nfIBMDaw6XKGymeaDbc75MFV/izRjElebdeo=\r\n=7VHT\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d6f6aba40317ad21b32295112cd1f5c62039f35f","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.169+d6f6aba40","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.169+d6f6aba40","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.169_1667511933298_0.08191085921908137","host":"s3://npm-registry-packages"}},"3.2.1-canary.170":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.170","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.170","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"aa765b71711f3566a4a72820f2672a5cecb57830","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.170.tgz","fileCount":88,"integrity":"sha512-X6Qy6gQVcOf3aEqDnH/l83/SU3qlSGXW0exNqKMV0V4pq8AUgH9b85a5emsUkClzLKhUPwLpcLBK+1O24ODYKQ==","signatures":[{"sig":"MEQCIBEmoS8SiSSfxbnbmIDq0zLPGU7KzgHrjMLNwxYZn6qiAiAaWrmoctRICc6Rh6t+tauADPy9faQECW4dqgZ4Epa4lQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDo/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpkUBAAhwhC9n0P8LO32vJxWV6djBF2R0aUtlwslGIvHAeRh+pHqV/I\r\ngdMom9n5MvGbr7kPo9h39pRyXxWiK98r69pE9SnPRUB8zTWWsuZx8baFSRac\r\n5MlZCcQVbAjxPfLXn4AD/y257M1s/+WGp9fJny4RksCbOVFQq3pORfqNc4+v\r\nQQZV40R4/vpJNwwVk6KEwJDPhifn5f8mwaA9PMZ/pWSd4XZ95XHWsID5bqeO\r\nyLaM1TTR9fWzwvr4Ls3Zpku+P0owNoNoXPM/EifZ8M5irPuw7KuqC59cVMyx\r\nACNk2O24HXvpSQ1e0PE2Hye/QJ03RH+ZFEtGkstbF6sm2SNQkeIgjdW56CBg\r\nYWiVsn2IUeGqwyGlZFXD+bsBuYE01yhsoRyMAsCII+itRs9Q2YlxQUCVlEtU\r\ntPcAnpPfH3MgePyLEiLo8FmUaIVYlMHyKfG3npOmZmHrWl8qY5aYwa+SAWRF\r\nS+TLDmu54N0YqI44VNJztFFl9BkK4JDmmoD2as6ahejCFnzjdT3qfI4tQiXv\r\nP8uP0+fChmeh+tcH4LN5rT90DaVaONBCDtZyMnwv0Svl0CNexRujLy9zbPJy\r\nW+ohjhWdMJxVu2P0aZca9Qbp29nXECEzIPkAYb/UX/eCYkaiKHVj7/xCPJTW\r\nhUURJhHyO6hStZCYOXsPjfmqV4ssFh5+Yt0=\r\n=PBhC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8b90a78ee5614dc8f02054be7d38c3aa68e999b0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.170+8b90a78ee","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.170+8b90a78ee","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.170_1667512895204_0.7856444930987061","host":"s3://npm-registry-packages"}},"3.2.1-canary.171":{"name":"@redwoodjs/auth-providers-setup","version":"3.2.1-canary.171","license":"MIT","_id":"@redwoodjs/auth-providers-setup@3.2.1-canary.171","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a1426804c8ef48d3cb98e450fce57bf80f37f1e2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-3.2.1-canary.171.tgz","fileCount":88,"integrity":"sha512-AAMOyTpZBGSXo7FLKSUv7KXbX/xj0gJQsYyBlzYfEo4zHwGyXEVdyF7hUTcTBFsr/HM/9mSBWRV5bn7tg36UuA==","signatures":[{"sig":"MEUCIG5+Dnmu0C7VGL7CCdD8ECGP0Dxk8ry1ob0wdxmV4q1SAiEA6tu/aEe8URfJwukRmtu+ebVag3+AZSuzWppCCmohvcc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZDrNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrymg/+MlpCqXZWtptiRiUn9F1Wts0SF2WnIqgHvQQf+08Z7v3JchiZ\r\n1tkKpT2Is3qr3dGqsoswiEoEpGKPGJ0SSK4db96g+N36Y5AAqZqDsOjpvGpb\r\nG6co/PQv5pwN20r1VTdEi3oOKfFr0wE3Ey4POizOi+TVRyn1HKF1y/S8UW/I\r\nd4/BxWdEMBQV/1J3t3XT9i7cs0Dkn+mMlr3b6SlJ2LOLnIuIp2Sj6rwlnFB4\r\nG9IUYQT2B+8o11WkuhfP38bOlX//eQFin3wQzeFZ3OSu+3d8DwKkewq17wgU\r\nl+Dgo6M2nzFkSQ8D5lTrySpzx6zcA4N79wbhOcLsPzST/M6FRCahq5xgv9aj\r\nHjgZADMv12pTacHCZsnAQ4AZ7AcBRwSiR4lREoVlaDlmyZWirYBph1k2cKlg\r\n2NZoM3N7AcQEVt+F/T+LL4j9192STo2V+Y/R509G7IW6yG/pWbjS9IDLzRKQ\r\n+KIUIsMxw59X0IR6FsH3pxklcdheOzHrlVmAurHl/uRHPKWyrKKxczzIwyQa\r\n4bMJir2o9nbEYb+Sd8Of9EzK8STAOz1yq/6aVJEZG4GCRgqMGp4pfN9EeURA\r\n2shz1omvxviw+TIVVnJd0d2BwWc8mqgcoOB15sZeWxRUpDvX9ciHQZc7y+Fu\r\n0OwADLypSdWGw+N309M57vmRne8u6/m9TWI=\r\n=tK4s\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"82780aeeb39475212db4430e0b08f92539f685bf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^3.2.1-canary.171+82780aeeb","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^3.2.1-canary.171+82780aeeb","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_3.2.1-canary.171_1667513037723_0.3796900425479961","host":"s3://npm-registry-packages"}},"4.0.0-canary.172":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.172","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.172","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1982357b7cc12c76988746496f43f522f9c1102c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.172.tgz","fileCount":88,"integrity":"sha512-w7NJ5H3EDR4uh785FyvvgAIaEpNrI9WnxFVI65c0PpaX4oKvVLA4SXuxJ7Tn3M9s8szSvHMC/oYx9v17CbhCnw==","signatures":[{"sig":"MEUCIEsArF1ZCWy3P+/PRSwv6gZ7xRYVpt4ouqlVgDGvkeK2AiEAjg0dmDyIUIx28KqTjEQDeb7HNK0PW+nnz6QWcvUz2i8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZD97ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqfqg/+Ibcs30PpmxvPBK+KjZiRhry2xbTpnS3DymRIusBlFf3OZFtA\r\nc9w13WV7eS72u1Er0Txbrr2cDwzbK2UJ3S5yBrAOJRutJOnFZ1TAuHx+ILLQ\r\ntcEanPxCiMtSOCRw3u8xHbXVWEhvbVhYnP432N6sUCEv3y1t2WRVOAvXW/N9\r\n3embmmsGHEzkZP4uBy/6s5YzEHES0hdCBLfF1zL+IAfyRzhIHwUZlg5rF46e\r\ngFnWdvS1ptgtbY9kA4XsJf/TulWQXpO4Ly+Uti4hiToa3WDnlHXMaopdvDIU\r\nvMCPTOaMP+bhgP/etV198J3P8zRk3Ymz4lAQ05p/f6F1OI5IJpqaFQ+6ySbg\r\n2XRshf+Jso46wovbEw5mg4NBjTgV75eSis2kqsmhZb+GvlMPX8JPzFF1NHIC\r\niecrMmv36BA1XvI0xTJzxbSJbuPshmzlq6DCiprTkWaCOy+4DPCbea/pj1Cp\r\nSzDIVYBU/nKTnFcicHomIUvQh+I0y01nofG5C4yqoQWDhpcjIOB/LY8ynlSF\r\ny6vy3Jo120ZJ7GWBCNE4kV1d4eXazU5TbqS37Ivp9gMQBhhfLYXycvxRmv6J\r\n66TFr7CljA8fBiq3lbLUwyjTfS/eAfzcfKtiFTuOBgyax5ZI85BtLZv6zxvM\r\nD8gLcXl0SpSU9vJEbQM2rEUaxrIQH7JXKP0=\r\n=co2P\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"45ffcefc23fe8518a7f762ef21e223cb399758bd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.172+45ffcefc2","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.172+45ffcefc2","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.172_1667514235251_0.08613158913039642","host":"s3://npm-registry-packages"}},"4.0.0-canary.173":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.173","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.173","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8b518f2a357a90f2aea05ceccf600bcc458b8000","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.173.tgz","fileCount":88,"integrity":"sha512-+T2UgdnK9PzxgtQzzMddSRuOuHS5aep3uOu5cgffYqfNNRbp626IGsHh8u4TZd68/Zbhevp9eNvcuVuBCeG8Jw==","signatures":[{"sig":"MEUCIACIAo7Rks13wQR+bATSmrqNkGRd166Hzg7oA5iERjmUAiEAhqc0mJYQIlgLTRtOrud/mMZX0qNOWAhjx4ZE5EQEAwM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZUuoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmopFg//UZPeNZdKNfDrjAcbm4/7CabNGoJGuxcFk5eHwvf1WwRnj9Wq\r\nyL3fQ147DRZ9uf9KxKTZyFBDLudWXJXek5enI7retnG3vH5HbsZebasKj5EV\r\nCT/r0Ls3Zr9hmf9lDgFKhGzKuxxLtsq3NIhnD/YxhkrNRCCWj8sA0RJIwyTI\r\n9LLrjpqHEFZbwNB8vuZyCtGvhA6XjDDEo+1wQ42fluIy4RBaHezjrrKDjKAA\r\nqPlvTcWSAXMyfbx44Gtzcbsa9hVcO94w/kQj4ebXYNjf0XtHNYFeJv1lyzNs\r\n/Qx1X1nxp3Q4O5L+k9tJPj1lo8SOXFosHBkU7CXQORVaxsTuhJAy8Ojb9Qrm\r\nby9JVYB8SKewrKEqPqtu0xJ6Whbcmesb7dzh2xfNvv5a8Wqkq8kByoppHFsx\r\ny3jhnssoP/aG0m4cfwTFTuCKOlcFQ57DUI6SQYky8coVOQ+mxS69ILG0NBkK\r\n5wnZBXiTe1r33jNX61CtYeYKZGl6Qh3/nQ60BU2Sy1xNam9WBMSC0GrZUBWb\r\nSvLORfoJ9/UPgif7+PBP2JQA6t7VLs8xHmWs1DbaWc+OTdhrfonmYqiScdIB\r\nG0tR/F0uY9yxumXuV3Ctfdf1zz5nlzS6umZDTB9PwQX6VExX6Hf9c3lkxfIY\r\nDQyhwamlZ0b4BaxqvHcCJo3L/t0Lu1Xr4Gg=\r\n=6XNA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9fe7be3a9264020f02adfdd40657d612af785477","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.173+9fe7be3a9","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.173+9fe7be3a9","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.173_1667582888026_0.12520832047415875","host":"s3://npm-registry-packages"}},"4.0.0-canary.174":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.174","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.174","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"720bd96c20b36ef5b67f3273627e856a6772fc97","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.174.tgz","fileCount":88,"integrity":"sha512-IxhzH1Fnuem8+ZzIzAyT+7JgnkHDqaRyZoaV4nsYVYiWpL3tyXUNAdWDW0lcweNw86huV2CH+yzTnRcV55bHMw==","signatures":[{"sig":"MEUCIHr51ZG7YhjsTuxoG6tpJNcgBuKSZ1LUuT5hh+PfED2/AiEAq8diAL/kORd/USBvJ+jKRnfwtR6zKpwSuETWjUsMczk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZWgmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr8Xg/+MrRDvSDdZjB02mp/euw2oYdjfR9QZUR5vahQJIigAoX3D4FN\r\naudYQgiJJV41tJTeJuBhCo9xyHF0imppuRtOJILVJ3jYys5/3gNvWzcMN+N0\r\n5t22yPkorxkO34jmqylI0pEUlXsyRLKZM7AQ4oYFnpdveGYSdaMivlUwAV28\r\n49SmOzlXabR+VNSRTyn+/7Vmd+C3Vn76NzsSgWq26M1GWiGoitg5W3k3UXeN\r\nYQvmIz9FeD0iWOZR/NkTrIINLD6MrtsfgROxsRedjp15ZG4/V/EMX7mWE0MS\r\nuKR8jmMk4XSgBIKB7wd5/HfMv9oaerrEXi3x3QuqVpPKTDbzcQLp1BEekLc5\r\n5KV8tqqjkqyQKZA8M5mobAL0MBP002L2sjRA6R6RcS4xvihxP6YCSH0vymMn\r\nfJm1IIleyYfUvFvhDDD1q8aoWx1X9dopwtzpZlBNDxJmTkYdfKFThTCSxWwk\r\nWhFjPYeqVWzApBOJ8IbwUOq/y2BH7YgjywbSIYcsavyUKSQo+2SzUV9/l42Y\r\nUS7aPTXdLCAyZ0FWRL52j+rr+ORtxq8jmAFEkqNBgX748vrEqdSCay+Brd8W\r\nvdmbhX5UvC40qiJuKRh8EvbaloebAzHC9LBkoQcpS8+yXtY7x9IAi6ik8Ds0\r\n0FYZSU+NrpdjRDF1Ax/0vrXiptQGq4igKlI=\r\n=XZSy\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c072358d6687fd73c7f22d529832e070bea875bc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.174+c072358d6","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.174+c072358d6","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.174_1667590182041_0.8077482724267862","host":"s3://npm-registry-packages"}},"4.0.0-canary.177":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.177","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.177","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5bdb8113a5305d0b783943fae16abae626db4585","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.177.tgz","fileCount":88,"integrity":"sha512-e44QUnR/9NFoy3ZOCl9KgkF1SlNaqEtOZiz6Qwvlb59K/Zio1PjxCcZ+77KGo2Ll3aRjmJdDBil6UbkQq76UKw==","signatures":[{"sig":"MEUCIEc4WhpCSaq+/eEQW9M9Hjm8dqTo7QqTUUGeuGipWzkBAiEAlWciqtCOEsYfsU3f7/Qt8YPxJXKgvk2Xao7xybLD4Oc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZhTEACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrxtg//dgzD+ZOWN4RnaTSK8lQ2qY2ar2lGApANwk9K8/FYMbDu5qXt\r\nK+JKAuDbvc3vrq7E8ZhE3Gg6PsjObxJN1CfHwftdkeSaIwBgKYWl0Z9ikPIJ\r\neCM3whOPf62KBUcmnJtsQzrBdJfwIuJ3yO9xlkw9cgc+fLFbFXERe7at64al\r\n2cjORsPRe1dU2faN1uvOkqcPQWQ5clWqz734eirlrmX4RsdJwtJJb57YRxo4\r\nk0ilLaPPzMBCaN6dtaQjr06s4kSzqZyqmD8LXw9paxNNxrRBzGCWzGPjvID8\r\nmv7jPYSDnGD8E6eFKdXsXK/F0D1BtdilX2tTCxTx8rq2BWvI0XqIvbOeXVss\r\nja130Gj7GvlPlPXoSSwf8r+UgocvK8xiIt37088TVXKDzGL/xuC/HOgZier2\r\nt0KTI6CSvwmmL9vOqIhQ6T+M1dyORrNJ8ddAcljB1mqtUIRQmsIjJt6l9XDD\r\nrkL7eSGr7KxdOFviVWeNNtwMZ/Yannc3+zpEsv7+u4R81zyi6UtrFP7re0m+\r\npjsRb/EjFZgtqW6RhuVKhBL6n3J4AEw1EfMDS4ppghjScP1wQ9J46v2jddGC\r\nI1FIT6gM05vohkR4yRiy0MeInHHx++1CRHcxglWUQOLOTZ6RAiUCoaP2a8V8\r\nEbfMCj+0+Znf4LB+T/ErrCrQwlng6EJCf/I=\r\n=l+a8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d75569e86c018ce458d3c850da0f03297b498572","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.177+d75569e86","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.177+d75569e86","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.177_1667634372600_0.5605724815150319","host":"s3://npm-registry-packages"}},"4.0.0-canary.178":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.178","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.178","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fe3e92a8add0edf94992c4d205a30dfe48dea982","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.178.tgz","fileCount":88,"integrity":"sha512-hMCTOomPLp2DAl9J77NxuLKxXjN7cXmqTyqbGclmzw4KVPur9hVLsLju52kpMmDb3fEOY4UGl/eDzyvFOBCxbA==","signatures":[{"sig":"MEYCIQDlphYtYONCn/rSs9bqf4zgvx5f7IUWP6SKFQpyfkxflgIhAIx0l721FJLKH+hYdKpyCjSeViPtTv5kH726YS+WNzWH","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233516,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZjt6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrfmQ/+OYjgNuclpKMGQBXs4slkkPMrq07x6pwG+cDCj/Ps06I+tuCd\r\nYgkFwAQNU341uQwjAap6ATSrb60yWHwVUGgOKpE3TR+G+F3iiPyCRWXOHc1W\r\nQe4a3OF4iN//ymvdBJ4/snnmrffRcpxtB4aOAeDwh44lAYEYRuHcuxgWtQde\r\npkGHfZqBDM0+OvC0egLqrA/SmJ6JOn9o2GBDMzysp1juiO8Ng2tlslApK26F\r\nPSgHm0DUiqSBqqsvzcrXI2El8vl1K1zh78S6Lf/gsWXAHa2A+yJ1Tb/rVXcs\r\nYIfMgSOmJ2TUh6wBmfIfBcI0Rhp+CBizt9LwMmUFTrCTi1JPvZVVXH7P4CI2\r\nH5fY8xXovqxR8OCAEoMQPWZWKstYL5bYxPiuBxUVYwB973+KdnzV8IuKfDUc\r\npLmqFnSR2HQb3hmnmwolXr+sIorQ3ZTO4zUcNhjnYpD95rNDi/1mh/KtNyPy\r\nxeLs1sIyIaVn/d4Loet89RXv2IJi0diBrX9l/G4AYg2vpnh99LulIFVKK9Nc\r\n5UIWrE1oQzjmBZPwfcNeYbQxpFWT1rIdVb+QAYe+KeK8F46GGuL1nx8VB3bQ\r\noT3Ap6Sy9NQuvI7S5sjELQRtLndjEYhtig2g1rzN7QVVnR+ksOpWx4uJZQzK\r\nBPlSMr0Vk7gRstByMQLJw84X3V/i/fCQ6TE=\r\n=d0xc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"16ce2b034292fb3bc864e474a8a95a1ce70fed60","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.178+16ce2b034","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.178+16ce2b034","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.178_1667644282334_0.9746475014966234","host":"s3://npm-registry-packages"}},"4.0.0-canary.179":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.179","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.179","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"989340bfa23c89f240f01c5b4ad40cf9d0644456","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.179.tgz","fileCount":88,"integrity":"sha512-e3yi6F0CFQ9gzwz24NMAktCXbLOo8ek7zJduEZTit8mESysSoZUwY0q5txvS9sunyTKLc+lxfLYKfat7ZYN8sw==","signatures":[{"sig":"MEUCIQDH0AQw1tal4mZDS5hL6SwTL1RrLMwMQ+u+fx0E3vlXkwIgTsyTGx9sAGVsm95DCS3QOn276M/eX0qPaJHLbuZNSJA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZrCNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpW/g/+PJXzCgzxwHZnqM/bSI7QWZ9BqWbuAyGrwZIPQ7NV9dtqpDT+\r\ngkHmC3PjimUQM/9kIpaGDAM6/pgpTQ7LxOSDtIkIvr7OK4LA51GQJ5NhVq1z\r\nGah4PgzzMMt8yjNkfpy1WFAJ84HCQE2hssa/w/D+crK20I6ZL/LZRs8PgMIX\r\nTMx/djWF/f24aGo5n1xp4urWX2oyyw9Zv/gu9aNB3g9yWwsiIeidMdNjN36T\r\naKzILsJrGBnaOPpLwHDz4Un27NkWu2mPMgH4HXr1perk4ITeG+LbXVSNK8pa\r\n6bQdFk0wZSgwIqscEgGWTfMxFd2Uue690vn9oUzrGOd3SpGuhyByz0Apfpps\r\n24wC4Zk0IMtYgMR0jCXAGhPPAgmGKaPq88f6Z2T1CLY/8lI+XJUR39Vmrwhc\r\neJB3Zxy0ZCi1wZBF4uyP2ZkO44nBFm7BsuTGhrlFc0dNW6idrTl8OgWJzRSF\r\nwTl7iLXDjAMN5Mn1Ol+nH2v9pZdcH0aVCz1ah615d62xCBNxTFri6OkGiO12\r\nhW8T33f0PvgzH32pB9RKslWgBpNGUi6wbaHSCC/yvS5BSAucj45qeF3WYgs4\r\nnXP2PdpxqIjRcvhFh38nRjSUMebaynSJA9F5Lshu/DyzwAbtGNaKf1xpc2X9\r\nvgLZr3Cxmlz2C+rvFzwCSrvmX4epG3EZbDI=\r\n=Azhq\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c7ce6d6ac4c608609cf70a1777078bccd15edab5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.179+c7ce6d6ac","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.179+c7ce6d6ac","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.179_1667674253209_0.3111487317647199","host":"s3://npm-registry-packages"}},"4.0.0-canary.180":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.180","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.180","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"28041512a2d05832aee661991c31ea12b5b216bc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.180.tgz","fileCount":88,"integrity":"sha512-2DoeEst+1DS5FKZO8aE7aeql3JaxXaXFbu6/L4qYhfUPejngcwDs1/0IfoXTp/zRXy3hfxM6zoQQLGCPtWVKsQ==","signatures":[{"sig":"MEUCIQDhSMDmZupXJG2Ca+UeMOHhl0UoJOqcbjDLg4cXlwEKCAIgXIeGJTiocoBG9ELl8txJn3CMUq3/6jzzGpEzb73AnWg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjZvzLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmouNQ/9F3aV7+HpKX2wxIZv3TklfHbSNjjR34E3iwt/uInrdhXCHH8Q\r\n0sLLoODWP//5ppJm6MbP2rWPQDls98UKRRzWZsh+ROaIWOjz+x7C402HTIhC\r\nJNchYfIRfJFbkWi/hwZlo1CMlN79f0t1FH9/0U9Jg+nvml14HvvwpZbw6GuB\r\nr4iOB+ofxfTFsYc7FoNupBt0+h3vDyzDfn5GJrgV/rDOInZmrs6WwHQ36l7C\r\nMqeiyjRRY7I3AIfNSxEs0x5ycb9uYhNIDn8lfUNfcvR4hUR+AkoAFiReIOY6\r\nbrJtQ0UdlANSbzRXm/thXAPKQYQCa5VVhzSXTQKNHb6n/Kdcw5bt7iFxHRXi\r\nWSW0aHq0vyYenEW+J2B1b6JLPrhg0WZdvh3X/yBWjgj2j+y0lpWGU7OV6vJj\r\nZox/zofSXI9x4BbxvR0V5ZJE5i+XoW120NOuyporDi/Z9HIJI7IX5m9qUXHK\r\n8a1Ye80MCH3Gy5IFim8DO+COOflqwDHO1Y58resycqZliPs67XJCvyRxSO0D\r\nuH6wpJXxwnfaLAahD5gxR1iGuK5NisEalcwu7e4mWGQ6ck7rXVrVj8Kv1tg9\r\n7RcXA2uvyigbmyryQLywu93mzYfYqD/1m7JEhX3EgCMjF+waFxRZKH/njbtF\r\nhS5MNlnSvA8I+M5rtRNJuoKKUAiZHm7yvN0=\r\n=H44O\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8c8443747b0a5c8d7b19e72863cf6aea88d6fd4b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.180+8c8443747","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.180+8c8443747","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.180_1667693771146_0.8532792096272024","host":"s3://npm-registry-packages"}},"4.0.0-canary.182":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.182","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.182","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e84160f25b899c3f9118a835b6ac6c6cef21683d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.182.tgz","fileCount":88,"integrity":"sha512-Q4duwpB8xQQkpwkZU8qmn1wpxnNIPZZqUcLbTJmQEOoQ9veav6H7OP55GRmtSei7YP4z4NcJi0iv3yufeZTsfQ==","signatures":[{"sig":"MEUCIBPwmhZCOAX7cprnKYP5DKNB3d9/v8dPcGupHN05pZj+AiEA6mQQfyNdxLztjPPqNZ+j8Q/tSOZ616oFP5BQjx8ej5o=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjaUJHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoZlg//ZDrAfj1Vx20r0pGPMm1S5dndKXcNnaPhZJVSqyFkz1oY53aC\r\nCvvpVe7zm8dyjYwHQUZrKEAD+xkPff4NlikZuEzleASGOP79mzEId4OUGNs0\r\npPj0H6mDCr4jp0UtEWhM8kTzAzP6hzv/7fIcsRk1nFQII5g57UMW8qrlCKVn\r\nojDx8DdJ7RalJQMxlPhCUUCYx4kKlIurPAHyurBp6kmpH30bfwiZ2APZoN4n\r\nY1AHbyaoo317D0TAo6hviISAuzGV04gCvofbb3djdPUQdOKA86pcCbeEEk4y\r\noh+hkbfU3OypsNx3EgvxxcsMn/ZgW+Bp0B6vo2Omp+Yxt4OWOdKwtFoVLNDq\r\n8X1ZCohjhKVMrzn/RAuraUHAmOJ0zux0uv4wYzsZZikfNfr1lAXF7edi7EcF\r\nxQzdjHrAs4HnMLycDxNlwyRXjN+FiqnplcjKj8HZPY/5fK+JWrCIDnoRzEPq\r\nuJngVpUCd5BiSCM78IXVkXiawvVgryBl3nFvUhO27/vOqo278UA2amFs8YeE\r\nyZwYZCvzyRLvH8UU2RT3fYKDWImB08kvYExAsI5W9Uus4eWNUXEPV/TWwJos\r\nw4otd3bHGi++WpVxy4r/4jVtUBbTFSLi045deGQ3Ikl+FFQx297nzbvqqtNM\r\nvUw56ZbjkKbbTImGCuTkRwQXsEImYrB2aNk=\r\n=WbrS\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"176fa01e13b8d0f2cc39239b74ef19c4a324642d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.182+176fa01e1","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.182+176fa01e1","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.182_1667842631289_0.5116300654200383","host":"s3://npm-registry-packages"}},"4.0.0-canary.184":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.184","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.184","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"452e016ffcf28a6db2ef75da9b710617d7db70a9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.184.tgz","fileCount":88,"integrity":"sha512-ReEB+/6UprISw/EnNwoyb8w01xD22iD4qkdb/D13PWjCcgcyvgZViNREj/0tQdmQXFjv7Y/LcTfVZ39uD+CEvg==","signatures":[{"sig":"MEQCIC+HprkbfS4/Z20TgwSPPALSKnHFBYCJMJ8StRPbpg3fAiAbBHPogy1Dx85KPifjjqc2hWEXLafKNjXgDqhnMDDdAg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjag3EACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr1KhAAj9sogGMPZtUZtbths3Lr6wh0sShumh5B7jSa4tw60KjMWhaS\r\n/OrgS0RboxwkgcJC5nqXw8zbCxBEIx05qiMD7j3WvbmQFSWGR0jcGdKIFAdw\r\nHmbPRGd0DAh65b8cmWyTf8JuIxhgqFW2UGQAzfvAaF/Bhq7+fiKlAEPmuP6L\r\nbcPuGwZjF9/Pc3f//c1hZuVNZ1jRrrnAPBEpXMIgl2PWMEhY9G1kvf9aQ498\r\ndqUjXr+NHyJtnURkX9x0H8TtqZGD54UHB7FFaR16ZnEAlb+pGIelm2wo5RVf\r\nWqDKqLU9chG2mkDHO3H9rC/DbIdT+aHQ35fB1LjC3MBIxH9ZLWpoq2Dg9gE+\r\nTdVfPq2ujAbEYtJq454QglP29TJhuqV7zmtvKwNq+tul3EW7Z3fvbzPbxnxt\r\nUnmi+9ZisYu6ZK+Kmo7ViX00anOmnAepOp6EBsC+hfyOTAjZ51vU+J3IZUN+\r\na2wRc2yt+Qh2i0O63f22ubCiV+3jp5vXeUgDF5lw01M7hkbLHZW0cGwRy0tk\r\nXVxjVp5TXu4eDwp4ZoVV519Xh2fN0Dda0r/epV+osmEPwAo2p7Vw5A8KASH3\r\npZ0tp/FouzS2YCutfjfHOVpjIoq9VJHAALZSGmUiZTpcbnwiMe6t7Gs7gh0E\r\nAgy++kCsV6wBlgR9Z/lqImJeduR4Bhct3Fk=\r\n=KYP2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1354090a940de2387ec8d87c4bd48c5c437078c7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.184+1354090a9","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.184+1354090a9","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.184_1667894724650_0.8558386737233985","host":"s3://npm-registry-packages"}},"4.0.0-canary.185":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.185","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.185","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5cb179bafac9a3103bd2b55ba844d1402273693c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.185.tgz","fileCount":88,"integrity":"sha512-9mD8won8keWER2c6oblv8jsg0UAR4l2tD3rMli1DXAe8v1mY/P6r/AruCo6GCNy0g+Rg3R5+LV3Cd/ObTB5WiQ==","signatures":[{"sig":"MEQCIExCukfp/1kQy+4K92OWFS7PmbHgZfDkXPZZYNUlsv+PAiBnkD69EWIz3lay6mmm1evyFMbZPDHJUfBxQ+ZFq7pJgw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjalzWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo8Og/+NvhFq9xNpSa/yKLOZMNy8GBdwpk0BYUblMCT7Au7BEYuNHQx\r\nsHDDDxVRj7y1iy0Z0hAQLRtu47wVQjUppP4MIvmpwBpi5zDdqjcQknxIh27r\r\nnWyMFqnGduZHH3u0X+F7hQlQdM2kxwp4T1/53dLD/yjlB15LKGLcrQsHA+Ec\r\nV0+uyP/Y/z/eKbz8Lt0cIEKOZgwcEBCCvBRzuRBCc2Om3KpIJRFGprTc9ABF\r\n8Yd4PfX1t9pmN6WCkYHEbBuNajwYXxeQ1F+a3AFZdDjuoP9wbCQ5YYAAQkjh\r\nsmxuTC+0gvGSeWfg243mlOZhZp4oOomoPymCS1xaCz5SRGBzaityXz12+DoR\r\nVBYKxHZRi2EPdICB6D5L91Q6vju3mxCGGmko35cl2ey9mVRNnjQHbEXvteAt\r\ns1aBRI/lPySneb/B9TPO8qf0kAYB8ap0k07U5S39ZNTjpafPRjDgqa0oSSy2\r\nXB1wEF0bWbF/xD6JBzmCxpvq5nkYwO81N57qz5zS5z7q3o0xRVAYfuByIMmW\r\nu2qxxdkBPept/V2BjRwZ9sZ3pkZqGwtXVQ7s0x5eOGNQoZIxu02tC9N7GS2A\r\n51TcD5h5tCcekaq2RPrJZB0sGMWM/cpKe6U1N1Vh09UpWYyu9Oxk+Sim3ceK\r\n1pnrQbK8RrRl556YAFQRwb3kz8lfrBHPynw=\r\n=4Xcg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c2275948bd90152979ea3a0feb87021a67babcef","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.185+c2275948b","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.185+c2275948b","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.185_1667914966223_0.5951478221267443","host":"s3://npm-registry-packages"}},"4.0.0-canary.186":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.186","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.186","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"1da722f8f0e2a7753ce37fcfa595eff2ccd16fa9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.186.tgz","fileCount":88,"integrity":"sha512-nlLsa+oZG2BZLYS3IVhDoqlgoccHXMdV/Sf9ovTOjjW5rAZfo/QRFGnYGvtbJqFeNhVecIcxVOq9CPEf30p0lQ==","signatures":[{"sig":"MEQCIA1Vr9mD2a60Cia6nhJNbiUHbFIs7DQtzzFoxSSqYSItAiBnJKSBg2jeJov04ps/aino53EJBWBxpZeHu6HfVxU14g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjao3sACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp2wg/9FRj2U3qyjo7CVV75R0Hi6XUlR7yZI0RSvMphPX1rIxUpsIsl\r\nOULZSjMBB3vJs3YO50dq9h9Yzkwl11bQqHQ0wLYAs9ShM5c/cvmwffg1IWnT\r\nlyHP5HP3udOvCq1ySFceqvGz/DUDTG3xeEOCbmvCr/Btn+ungwqg932JGQ0P\r\nwy3fMBiw4qyvGE3beLjL6gBXQFtkJZO5NfYouUHChTt4nNFmOcDHGRHij3U6\r\n7G3E8mXA1l41H4PWdw2FgoKIGveY7feSNzCg1GaFzlczYRx5zRVGZKmXdY3B\r\nNBhL5Q3psbc4K5NY4lmPeLYKFFDOxb32eXN0gXo49guaoF5sNMvDoephb08Q\r\nVbLf12Zpy4XfdXk2JnUYwT9pufrSnmdPCC5WKT+QxN8QY+AEmHXdpwE3Hm8Z\r\nlXg5RdO9foNOXFVyqu3LRqNzkql/6fG4m/dF08SInqhaTjhk2vD0JIKZtZlb\r\n3aWvh2HGP5xeY5Cz0L+hgFGSfiLt3/ICI3aa38MCTFDCeZbRWFMqUL57uNxz\r\njL7OncE66CijjZflOLQKQThrbKwtstzWWzlZiUtb9urg8Thw1mPV368liqR9\r\nqQExGuJsO9+cXg4rB93ikjwoVD5ezKdiTlLzxKLeU4Lmhf7v66HYpQCaPqb5\r\ne6AsXRc+Is1i/0tCFaQvpc+nCZPOFYwb48w=\r\n=IHcx\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"49a12590cf0dbfc55fef0b7f356c23a58f3b536e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.186+49a12590c","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.186+49a12590c","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.186_1667927532365_0.9892363071564814","host":"s3://npm-registry-packages"}},"4.0.0-canary.187":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.187","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.187","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"469f40f4e62a37b9871e8a1136f10311ae5c8e00","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.187.tgz","fileCount":88,"integrity":"sha512-y87t/8ndj5Zob2nq1M0fa7v5AV7nFaBHIYuORCkROLBERa+ZojnJELKk2nDjrOZyoj7zwSue+dYQcqxDULhtYQ==","signatures":[{"sig":"MEUCIDiBsyyCXfjhJvP+OYtKdwNLnmXiiT3HHUu1JGA1PfI0AiEAqJ1tIyqo6FejHluSF/741t/0MPevzSmJ5jBwjAiSWoA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjar5UACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo36w/+P3sh0JJu/YZEqdXNY9T305dVJ+zSOqNsWi7xkpTr3OY9RT2k\r\noIMmDhPB+Jmt87GL44Mlh2dGvgR6POjc3M/4G7SLOL6oXiGV/cMEjbE11ggo\r\n6seFdMTztRd8+4ILL5n2fp9jur9+ULH1I75PnNJ0B+Zv6poXqKTcKp+8yxbm\r\n080Oj7X9Xiw+x2lLnjmGMkhmnmt5TuPuUSO/6tCjTPiWTTQq6JMPcFgEIB3b\r\nzcpUgkYn10ojBjx2RJKADBulXjfsNkZ6oR+Zwd8IE5zt/AgblLgPmJfOAlI3\r\ngVyM9Uz+K2vgck7elcX6bVF2md2fLw+WOTYWDd/hZ5y8a170QkVwA7eSsO1T\r\nmmWS53vcxDVSQdbdeRZ6iLGvdd94OxFnhDNiLn5MQJegdO7PS4+4oBxnO7qn\r\nlfwGpryBQi6GhK11xUmU86RLCJTxHTk5HNUg96uqjpJOUPqAlTioCx7MTF9U\r\nnYteB97z232uimq1cNf2Gclywe1rhcEBYr4uyzmgesuTuPCt11pVL3mTyRJ0\r\nuuErC+ridSK3Mw8CdTVk5CfHc9KJEJOLVrBWV6eL8P4CwQOERgcTAunDJpZr\r\nzrOdXNugHA8f6AC3InxVo2Xte8poHoZk9x/JTd0Z6UEGHKRS+FNPs8KayyIQ\r\nJSXwivtkP4QgMtsVFSBlbVB6cQnNDfh0lm0=\r\n=m05z\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a0b262d0bd4dc9df3b79ff6675c5a33b10c2daac","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.187+a0b262d0b","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.187+a0b262d0b","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.2.2","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.187_1667939924418_0.8002650244979972","host":"s3://npm-registry-packages"}},"4.0.0-canary.188":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.188","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.188","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"46593995dd610c7654015932504f8db5241816c5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.188.tgz","fileCount":88,"integrity":"sha512-cuEy3TkpuzkGtLD2jdjC7n9GEK67tJ+Pb0YVGmSGXp8S96JUxcFn3nGJa6o5ldGt2GkBnwrNyeygi5/Nv7KIuA==","signatures":[{"sig":"MEUCIQCs+EcrOtb3dAZRrYRwu1ukYix9kL55xHbgIokq6x8A6QIgTJS2xiaogTKmWZQMwTwXVsAzoqWCIgYj4lnn8g1ryZ0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjastoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoYtxAAm/E60l8liL2DmzQR0wQofB5iDQSGRVWajGFn1gpoZgNcrzUy\r\n0CzcY+ABijc04zlC39nD36o8Ue/jO/PXj01Zoj9OH9YNmOroVGXhXl0MBmu2\r\nW8RgwplO60XIzYIHihQClwm77AK+XXHh6T7nHRDsB8KZAnd5aKKtshbzaQP2\r\nuiuwncy/opMRl3jGyMKXuTwZ90oCIfYuzUe7vfiOPeO63jUvN7H5CVnZU41z\r\nkTPbHcBIhRmNk18HfZZBs1YPMLtJ8OanI0dpQP/dBfSEQIDxQig4oS/xn6qW\r\nR84LlH0qwwExmhpG10CMvQZVQyI94sBjYjkNYVsEesIN2L+S5nqq1FEzxLGR\r\ngxhcqZtNP0zKou26Da7Fi2gJhbEVq58LNTDgmPBxNCbTDEzjzDuY5fV5yrd5\r\nSnMx3U4KUnIX0L+R27gJFbx/joDW3HfoAb9ifeH3juGE3eg+pYQa20H/1+vc\r\nN3q94nekb2+Oa1RDzkoUWvrEGkaxWQzLAeJUSa4DqzME7zGVK6SngN67pKfC\r\nwOzzNM0bJbehssHjtJkXoIkhmKtImifyWdj6YOmVm+VmBM2u1IHJb+hjIdFa\r\nxrL3Uc1YgHtnSpVxTtfXJPdbepsEPB3AHuD9vgb7KecZp9fMx6nM4zuwR9gk\r\nVZg/gVh0GLg8kGtNazXq5dRQ4J8S8SUEdGo=\r\n=6Htc\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ca4f2bdb5359beff51d859ad8d37f8a49ba7f393","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.188+ca4f2bdb5","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.188+ca4f2bdb5","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.188_1667943272482_0.6784607799694324","host":"s3://npm-registry-packages"}},"4.0.0-canary.189":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.189","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.189","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6526ca37422550320777b1223af6494a1da7e95f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.189.tgz","fileCount":88,"integrity":"sha512-FgJJJUmaFxHJVv6Y8T+wTsQ9SeoQoQKe+8xmq7qXZ+EvFtl8+Es3OdjJxjaDTobB0G5yLiWY4sUAYLc+trTgMQ==","signatures":[{"sig":"MEYCIQCaZLZYo/ly0tAoyhSsey63VhJzq9qfRZZ89+buQvdvWgIhAO7AIxooETLsMdfeEUAT4pW+GQ5hzwiqQdkkJriOzEKv","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjavf7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmruxg/9H/D2flU/TuLUIzz1ewW//ghik7jNhUFGsdrs2T5lBu0yyJKf\r\nJqmiYcPsKYYS+HaeJYfomErHiPpT6Xv05wY+q/3kNieOFxClP8V7G/FiVSsr\r\nZRymbyPdEyd4cUEiIIfemTnD9S7uBPcfuo1k7wpe4TpUO861+VxxbI2u/Xgu\r\n0+ggPaH+vJ7CusXdyWpl6t4XYoeLsy8lDt7ZMk+93dLEVV1m/U95zje7QPJP\r\nSPfjdWT8UyEaSz/c5esDpgUSvp8D9QIxF9pLd/aYcim69GK2mi7XD8ylMQO3\r\nElKLblIZAVxAaJQ46KxqKn147/l/vNDEDWnwIRYNZRluSOQVWg5Ck/o6LzEq\r\nh49mF/DzccOwppuGbnm4W/J9MW3MpqRKvIGh103ws3jGZ/dDBH6WxxfA91A3\r\nnMX8R0Pm0v5aZMW8v8OHR3zab2HJnUVbOZmsvBwspzmu6Noazuz8v9JnrCzt\r\nbLVlCQXxKpbnv0So0rNpSAYajhiDZjcrlcsfJPTjSmkQSSjgCXRT3kD1c1l1\r\n1Lh//yH5zetyWk0ZfyoeYQ18HuOjPyniI9KVBpVGihhIbFVxSul+SrtEqzKx\r\ndZtj+Q3+oQFcKX63OX7pmUMA1bwaqHVWx0a8fMznhoax/Fzy5yDEjxTCz98k\r\nX4grh2A6lS7fXv36FD/qS0RZdf0JbFmZp6A=\r\n=p0zg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cadb28725da05b630f99493343f20b4c3fe3bd1e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.25.5","@redwoodjs/auth":"^4.0.0-canary.189+cadb28725","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.189+cadb28725","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.189_1667954683252_0.25398381199936115","host":"s3://npm-registry-packages"}},"4.0.0-canary.191":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.191","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.191","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"86f040db55af029393b7c4899b5d49229e035f0d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.191.tgz","fileCount":88,"integrity":"sha512-YnQz8XVv2I6xR4ZUTjdIzjLMvZXlSs4mwpNjKzdxFUySCIMNjJmVMOWcZBoUWtYBSoXVM8vAxZgW0WD9ut/g+g==","signatures":[{"sig":"MEQCIGUh6cejmdGXAZYxZVUQJT6PCeRMUNTMw91WZILTr3UuAiA9E+0qAWALWfg3tkp5R6AL+HjMGf3ek8WPqZQW0NCEVA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJja08CACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpf9g//fEij71SCZWQibItZsLcc4CxnNDPmJIukhsx+pWfisXR6D/ov\r\n+1j4lGjWIUcYzO7k7tiFKIifz3rlXyZA9wqO26Hq1hCwA+j2WpRyDZe2gubk\r\nYvhrA0NMqIelz96XFsSGjAmes0PFCQaVUDYPN3aG7QPjLUhcXMcTkULbhW2w\r\n34z7VkdgGH/TlnO18Epd/UaIXKmVCtKworOK2+5mheM3IMBQf0DQ1sCkBANO\r\nzi3e7aaqmTiB2/aQb61ihf0CGH8bQt1xqs4EnFa3dBb+0evIv7lm4RqI0dGZ\r\njB2SPlAfkFt5FtD5fG7p/luiX4AuUlEJa97BK/xSBnJpxkg0K4KUhP4+LFRK\r\npWDk75hiy23OGeHMpUQocoKTKEU0nwgZMNnRnuepkxH3nVP7lmT3UdWVRZ3X\r\nQWjZULoKBTW317ujDH1mMfebfbbyx85Iv6Yi3BXIMJR9PSUEvn/Uc2aB8Iko\r\nNiGO4SPSzuABo5++nhm1k05Hws+P2r4Wcz9NEfTVb348JHtpgyabHwRSbdeg\r\nR0rWsCQ86HD3j6SBb8bBfKe+PNSU2sK7tv9hFVsGeM1em2Cf34odU0PuVyhe\r\n5g4XylFJrLJDf5i2rNReaIw9QP0glnT36AVvc+0A2p7ygWKBz6xOkF/H9lkn\r\nXHCdpvi7bihq6nktehlKYTKK6+VJZ6tkqkM=\r\n=cDWl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aef46be63aea29a3e033cd9869969bb780fd634e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.191+aef46be63","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.191+aef46be63","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.191_1667976962315_0.10129287051009594","host":"s3://npm-registry-packages"}},"4.0.0-canary.192":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.192","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.192","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f213fb29180c4ffad7dc2d5bc4b55416c05127cb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.192.tgz","fileCount":88,"integrity":"sha512-p3tM5fCGVpkbHvDW6hQJXdMXKqwGKN+yl6H2h5VPoGACdTcv+FaRTUNtyqDLWU+RgHqW1JTZr5WjCvIsEKpC1Q==","signatures":[{"sig":"MEQCIDN0nVhPUQ4yS6TXOp3oHRi3pKB+mVdKR1Jg+YrbnudwAiBJT/3ilod3JR8kLpZmkMhfF2SYxzTuEd3jS+nSd5RLbQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJja3HnACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrYhBAAlSqEXDWujV9aqszh0DGJjdJMWQuV8gdXAveBLqY0YNFgV4cS\r\nWDV2j8jYkpT3DqV3F+MSBDfdbK6s6JMu4VnsI7ok9IrQ/C1uBRer5yEz4L8b\r\nD7jVkCF3zU8+DImNTum4JsyF/hnazpRw8/L2L2KSS5T/HNm9KF3p/Z/oyw6M\r\nh7j9xCaPTdvcO3gTRw82g+9x9n2hl0XpXARja7bkK5i9sdv4gaJtWU1cOCO6\r\nVtAoHJhlgjhg97UEwDXauv/CfJucnPOg/l4pgjHrEP7e8QBlFonZ2DuU9FDD\r\n/YD/1dbn+rPeXi/RBMEcxlPCADs4J34eu3zyAHf36vH49rA6uU6IO8MeO1rc\r\npRqbv9XvYZOs9eE2/XFOeson5vwL2HINHnY8SWeY4K9Obo/Pmwa+Jy0Ivi2L\r\nIrHl+WxrAYkgArxZXDB2Zw4AF0YBfE9CXp1IffbrdTkrEXtgzRSfRvYYyBeB\r\nD495fNvrUoCT4WAbiQWV/Q2sGKljcSZlOZjNcnWesNhDIZbWTKj5TYqmUTPw\r\nDdLFjb34UzXRM2tTHLZE+yvljGP3s2iNvJin09nTwml1EXhC6UEsvlsxMPvM\r\n8rVJs53e1PlmJmQYnkTceM3Xwqp/up7wMn0LpTjxa82o8l3PMARWdcV+JGgt\r\nwYburb4VJWNQ8iwi/cNUgj4lZ/FKFGVzAEY=\r\n=DzZ0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8a923c7f9cc0b20d495c7631acf9a62f3edc5c8d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.192+8a923c7f9","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.192+8a923c7f9","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.192_1667985895346_0.024780595177052778","host":"s3://npm-registry-packages"}},"4.0.0-canary.194":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.194","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.194","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b15d08501107b60766361d3fce975743570fc75e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.194.tgz","fileCount":88,"integrity":"sha512-71AOgypFE3zwQZ/I/PVtHcTarsP6VZ3+tqRxq9xVERLb8wpFuP9VptxlJvlCKjUoQV8dscll8uwqhDWayRYkww==","signatures":[{"sig":"MEYCIQDXyjkFFEH4hJgQ4IlTO2d+E7BqDEFvR1mLZouOiXBu9QIhALJlKzHUrK+6lsHFxVioFogujTgfahL+2el9bdLfOoHj","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbDs4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrs1w//f2WjuUIj4GaGQ+Q1axqRJYngVayRLQUEXcvz5g5XcixXPhjz\r\nps5858aqUdeq8ZyJj0qplCRFm1OeRATjjbazRNiTTbMLCDFrN0wOVBUBybMd\r\nNedM1NJyw84oQ7X5PMrW7jaXZNOnfmDYogrFm1qCi+JFtVokxz/01DHed+GP\r\nyu7E/gVuRTHzQkzYe54Lb9yyzBsufjCvFF1yGcV4FweIOwitbLjDakKfhbQt\r\nq6GjvI9cHK+U8zMFvWAlitLQyYTHkgoSCbcbEx541eMjskZJ/5m7sTllCcFK\r\nZA0XmNYN66qYqdi8niuyKRq77vyjfKJ9eRsPHI6iqy3NY5Y/ysCnQv1vMnH7\r\n19WAw1jCbF3h0Qf5EZNWltT5fDvb7NxhbufLlp7pFUXaa6RhmH9IEEG3q/TM\r\nxyz1isoR6dpViZxtusuM/aSUlK/2wxa0ruBHXvSJBQzRMTH9iFt+9rCfxHok\r\ndNKg402EhwRYkNgHutirV53m543sHm3t0fv2U5vvP/bT64akdWWTtM1L1+w5\r\nEL34t4miFzXViC72MZNIBDeNr5aZrWfTSOv/jDaRbRBoAD77Kt4bw63ljhK1\r\n/jVvCYfj8/e19XS37shR38ieLC+YCHqEKz8kssb1K8+o/m74pSdL9JVqUID+\r\n+DTV2bJXktQEA/Fw+lHlnLorX4Cjn7fFzqs=\r\n=Sw5V\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cf9d43921cb7119c6d00a575d4d2447d82cd27cd","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.194+cf9d43921","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.194+cf9d43921","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.194_1668037432221_0.560427519568347","host":"s3://npm-registry-packages"}},"4.0.0-canary.195":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.195","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.195","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"39b7cd1d152940ea6463dfe5a66d6f56f4ff7357","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.195.tgz","fileCount":88,"integrity":"sha512-ejm6g51GJ0T2obRSIeCzIE+BS9p5uBBg4NgEE2DpQqnWpcBu03NT5nDJ97ZMYPghImwLt/YU4sOBRDuLgQqHnQ==","signatures":[{"sig":"MEUCIEV13usB0AzC2t2WgprC6in1EwK6u49Z8Uyf6w1fewJwAiEAo2Y0DRNjurZ1uc8EpbjpNakZ9kT3fkaxBNg6TsZNODI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbD4yACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpYVg//b5uKuLglSQv506MrgFqIUYRgu9xLsPwVz+vGssspG5OsYUVj\r\nA4rIPtl7kRIEBNe/eywd16E96npOj3XOpRDwMyiX+QpsVM9W13gS2wa84GB7\r\nOm8Fld1B9VL5aDDXlS8hQtuIcX7PmVErPcHBkVuH1Wr3rHXrva9qBH1llmk6\r\ndCPPbAIwN/qB8kVSXWJ4s8Z9wMgTrNQK7bmwE3UTgO2Po2xS72VqBduqxQf/\r\n+5tGrTMPkzbai2xRrddKD/dr/R1lmmotQYYDVj3EjhTLNEZEGmCfgY0ddv8h\r\nbwkdILHAiNZefFQ7DL+FKfoYxT/YIJ55r6xEfgcoaOGjmmI+CH7ftqBj505W\r\n4sbni/s5rBvjrN9ESiTC1gxXMd3G8rjAg1yeEF/1M01SpI0/+bYVje9DdXc+\r\n9DSBhTlj+p9A1LUA6cfuaIzpLgUdCEJpVU8/vJ3BUpB7B4Dt7ugQaoL0M+kE\r\n5TzJFEw0T/LDk54pjvtCimms+mok1vI8tS8EA2zOS2q/PhT5ro7olNrkhwAr\r\nm0zzeKh7E5/B/tFPEO/bhtnEVyqW64jhjWfPDHHhTzcCFS6cchos4ApKH8Ns\r\nfnMxhkBmV6mp+vYF7/PJcfqe++uBr/iZslXOKkDh5BK57LuVo0QdSSoUkzVT\r\nY1LweZjL9IAGgD/q+Gs7x2+FDD26sSjmJak=\r\n=nrN/\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"20f872864dcd50da2da421169681919ec0b72bb2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.195+20f872864","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.195+20f872864","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.195_1668038193935_0.22780677050835219","host":"s3://npm-registry-packages"}},"4.0.0-canary.196":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.196","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.196","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a9fa3d161c16fcd43958417a8c47faa5529c5344","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.196.tgz","fileCount":88,"integrity":"sha512-Koz7aPyy3Bvly2YexO/HzKtfp7nnndyF93OZHgmwqoL+QNEDWmrTREIy4y8AOn76FamnCNgNJatQKN9WRzRo5w==","signatures":[{"sig":"MEQCIE8Qvhy5f2y5NAL7cuOCRkSgcWRaod3ILibjDc5NscoCAiAmZ4Tf1b9/DPPIL1REWQ3SiczHIT/vsOG+oog1vWoZ+g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbEIuACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoOnhAAj9mcjXaDrD0XUHe2wXpZCQW6KOLe6bW7iMtlVjWNkFrwDnLe\r\nDnxSfvpkaE2n0+hz8c+LfC4c3d3vAmQc7X22Unh+oh7Yv3DnqsqhbHslE4xA\r\ndONnrgDBZKMyP0tT7cdJNmiypH/9OGPIgSIKoUwhDDGlIX+Aaci1dd61NNNF\r\nubKrVDu19XJ4b9WtrC9wa26Ohgom8oHb6zEJZBkHA1ZxO1raTUtsyJz1BaKC\r\nMOFzfp+9CNPgkDnYcE/LiFL2KRPasAwkosak10I1ooWOpm/gh0dnxoA0KHfm\r\nZeNlmKOfoD+kmqnh57ptWYWPlyv4wRbzgMSywtXit6vTQh4VnBsPix6z75gx\r\nvIJGY9JaAgcuCHkJYTSUO1aRnPC5eO7y+KZEA2grp5vYB6ZyEkxozOpLoU0S\r\nnpnIIXXe/wxWJUDh4vqmhU5rwOk5g2zjKyzDEBjyayeqUMx1Ui0KhTM8JrBE\r\n6xW7d6yvgMCwNg9hY1+oVwwzPuPWGYYMd8Jj94SXbAxVybmf2FgRwlKXk7gR\r\nWMWLoW7be8IEYDoU3tp4txHqMsAEosZESqS6WoXdEEOzzrJ2R5zh6MzYvgBl\r\n18nT3/cqA+YnHMG2pqGWw4GP5SySDsTxFcJvfHKntLQLnnJP/OaRcavICzlB\r\nhV7vsxN0s7WhSDizL/FUGO5yjrLwNEnwbD8=\r\n=8gMK\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"333f54029835625848ea6dd2ef248065a44db32b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.196+333f54029","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.196+333f54029","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.196_1668039214452_0.04869553492523715","host":"s3://npm-registry-packages"}},"4.0.0-canary.197":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.197","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.197","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fc7485d200ee418f0c6a53c16d97d8bc393fb719","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.197.tgz","fileCount":88,"integrity":"sha512-zory73yM/16pkcPsee3g6zZAe8AXtcYk3i3kymlPZQAsS1D6nOpu8iOu+3sw+XEpXhq45XX9n9qGmcOqNV31DQ==","signatures":[{"sig":"MEUCIBBlZPtoJndfA9v0kIsQDyA4fwruU51feBIZnouy/YVjAiEAlcOJi1Nt+CdIfR8rh0dbTIc6WNhDH1mDqBX7BiQ2+vk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbEguACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrUnxAApGU/HjB40WbttaDi58AFrlzFYg86+pkeVOoE4vfOXGD7nkTA\r\nDuCDpBgNWFoZGYBnMpz010gqukwH/lUII6dBMwnzgr4ttQSIAUk9yniUwleA\r\njgsIE0Cia20QM96uwE6dMAvUUqU5YP6MexqalfGacJvSPHyeMHoMGdKMRHdd\r\nTyRdsu/dK1Uc0BC3XoeQVCGqp5pWif2AnbduD3A/QNUYLlNJ4qM8E7BR9Hzc\r\nklKIEq+8XLLol5Y29hiJD6hnVaaRPvv7+gZhv7SCll+d3b/fkONiRfwurahs\r\nlmfxfSt8VkD01V532GP8MEREJCCmSx3jeF+/BjkkHXmF9oh7AtqSmYN87BCL\r\nvJewkURBsIIrrgokRw8mYoQUZunpG3OhUnJP5M15uoTSkn9hHwrxwOhkgXtm\r\ntBs1Wc1T/wLOnWbe1H3f1Iry/fSQjpgs/WeU1/bFfW0ur7U3vysvklSpEoeR\r\nXyB/dvbq3Xy7h7oqUcO8Izh/olwCFN/bMC7Q7+FQiCZJ/kD/5in44ksXyw81\r\nUMdRSn3i2894sE76M9LaZl77PVde9xtkQ8wKEu4tmXH4FxytsW2OTJ2UNQb4\r\nfYfVfWdL00ETET1AgM4f/v2CXlppwbcTSmbCF2tuZsJXpgmt3ZMcJ4BopFdl\r\n1Jaftiuo8HcKkn5BgGf9V+9uj081yWzsO94=\r\n=nZZr\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fbb7acd6bcf7a58d139b8ed33f962b950be1c3fc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.197+fbb7acd6b","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.197+fbb7acd6b","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.197_1668040749778_0.6711384569880094","host":"s3://npm-registry-packages"}},"4.0.0-canary.199":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.199","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.199","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ff5160842c22c10e867046957ba2dedebf37a459","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.199.tgz","fileCount":88,"integrity":"sha512-pf/PCS/w5eNlCA7Iotuob2JlpoJNnX5SXIbLWoNqPbgtSUEARWhFc5DStf5ihieb6ELfCKbw7aSjXa56hmUq7Q==","signatures":[{"sig":"MEQCIEhwuuC7MdJPYDmNSKLFWqaGi52KnZz8dHqv0t04j+aYAiAZP5h0fQrp9+RcG/U/0KscyArCjWwomLLOrkBle8v18w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbFHiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmorLA/+N58AS+2QEgBU+M4yx9yLk8rZiNdwBcjJit2lQUwHl57cuq9R\r\nNdnhyChH5mzc5LgRwKB3Can7uRCss0LdtfvYTTfI6AO6XeatCs9UIwqjvGLc\r\ncqTTN+O1SasMcUwgL+AzPV8mSlgA4okoGc2YMYinva1fCwPuYKb3Zl+IxoYI\r\nNZiFcH1koB4GdyHSnGdLliw9oIJT37zsNMwNOPbTZJaXFNavK2x5gPVkPAU+\r\nX/aAlPc2ivsS45gbl2CLPdhFFG+8VuH+64ShS5S5oQ+POwawtk/R18Dt80E8\r\nv1eHkWXswiZ7Vi7ila1L0mF+DKbdtmzvE5MT02TeqRlXGIISP8ekgmtI1VDq\r\nk9Ot0blUCTnVpMAjq+xEAUB7l33vEZSJTAqrj8CuHe3ITFaF8mDyk2fb1Rkf\r\ndzVwwkGWmbuHojdpkCQEwmnaTJMyW1zT0QyGeDvjQhhlURSqaXZWaOCw9UbO\r\npe11eVbiAM1nSQoMg3apVJpbkgsMpAduRFLK3YhEKiYD9xECwLwOmjYavqWv\r\npIC8QPVS3HHPOZc/fAWS4qolBO4d7ZFPgACkty6YyGnjMX7p2CqskiDUmdSy\r\nN5ABauoecMqBiYQgs/GoZqt8oKkynJLMxYwpRzkfvmuu+H8S2B5Qh56Kf+uJ\r\n5P2hZD5DylpHtvhCp8hI0qLyvaQ2XzQxe/Y=\r\n=D+op\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1d4b2c4a0c72fd390ac9a17c7570b3ef6b6530c7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.199+1d4b2c4a0","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.199+1d4b2c4a0","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.199_1668043233875_0.9354669883591968","host":"s3://npm-registry-packages"}},"4.0.0-canary.200":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.200","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.200","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5818c7cb4a2d24ba0ccfa244cadedddec55d9a7e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.200.tgz","fileCount":88,"integrity":"sha512-usMpEWN8ecuZVLFdh2eFLCThG0Gew4yFopVMZTtLK9Owr2aQK3qBblmfRDGGs4SiSQRj9P7Qj3fsuS9sp7Gw9Q==","signatures":[{"sig":"MEUCIFpJ9h3F+oGboIIZyEIjEM7cvc6FyPCv5DDK6Zr3RGXoAiEA94O7Up9BU2GbQLXlolflz0L+tDITRlfbFIas6Fwho/k=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbGnAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrHQg/+KOH3UQKTor3HDlza9IYVH7cdgYT6cNG+yCqlNelavy6Q1UKB\r\nGqkdD5Efzop5Ao9VEVAVCTGOVVm2KrRrJakzKUhVaqa0IUnXre4GzVsjDiC4\r\nFGCowaNRUW6HvH2pmbbcERUYvqlPPqt7h0V1hsv9vv5GKl8elbUZg0ZFuPkJ\r\nxkSDm9DFLXWVyE8qcr1yOb70Nr+1AqoMsbHTtXn3I1M5f/LvaGi4kTNB8/Wr\r\nJztSGwl11C1yWsiDClSjJp1ufmDWb9Rk9PS9+ed9/7sa2BEjouhsFyAqGTkO\r\nKPcw6pqtZ7i50fTmtUwia9z7UZIxgJqKCrUVSetJzAGye+LTuDyDrKTBLWtH\r\nMAE8z5iyN1oVqcq1j7gici6t+mklDjDKvZwrPkeP1gxIpOzZTwtzQF02oiJ6\r\nK5CZzXTmCL6FNnOjisJCP25x0Furr3wykWgL/Nq+DANrn8C+P29mJTeISQv6\r\nRZzst3Xpf6OtMJTKJ4LSFce3X96f2TGgpGrvepRmywNyeAHqafI9N99l/iqr\r\n/wRPSMCH6fGz6pjb5CtTQpswwCh1CJrFnNxT8CU0sIjLSO3RrwDJ4Z3necVe\r\n2w95Nif7R/qY8X1UOFjDt8X/AD4VOOboTNrvLledKCYIGxlnNKlp4zoryPgl\r\nCEEdbpX8AVsXw3TvHXtdDw/nW99KzSKUzNo=\r\n=p+Bo\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7cd1204a56dfd42127fa63d04485e85826e71d07","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.200+7cd1204a5","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.200+7cd1204a5","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.0","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.200_1668049344161_0.7388069786869667","host":"s3://npm-registry-packages"}},"4.0.0-canary.201":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.201","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.201","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"26ce56f8d3026f22e608db133154b3e95e47b82f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.201.tgz","fileCount":88,"integrity":"sha512-oIAfLLP+lQTOpUpSiA8OwldtN/CgrrrvXtYVwtY12qnNr9xSdg3ciF6GYz6Ehu5l3MbiZigYdbzqi88JXSWn/g==","signatures":[{"sig":"MEUCIQCKa3IyRO/eZU2K+nJLMuUf0xmT0Nc8rIw7JPHpo1Z8IgIgEGpDj6jCjiNsUpNHNTkskDVxQSeTrj1K+rV3XLcvEYE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbJy4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrwvhAAjW8QRk0G646Pax+AytUVUsyu4usv6ZxAtn3kwcIt6L49bt6F\r\nrYgLpFsJOhbF6MFPJFIBECvQB1kcmq9oYPZSDu5u6k9/wBcQRrQa/qBaz4JZ\r\n2YcrdklRMBI3g4AuHFdkhsWm2bDWQAi66rCgtun5OdoclodHKK3R7MPnt+Vb\r\nZaxHo95lO4jz7/A80LC+Go5v7o64rXyff/Y8FmJgGnuVerTjDbHfhVPTzok8\r\nv6OxRHiG3rOF569mxL0L6ZtpgXcBDuu8WAOJnsX7fGiyatE4y6zG6gMEu8LM\r\nCrjT64kC2aRVl4T8ZbWQ94E0WrvdbydpfR8OzO4tj3Nr7ajxRJmp4ALdaa4p\r\ngOXcG8IP066TjhxX0VmyPYsOavRrG23sOP1o2u1XkTsUAXD4+TBjlYMjQwJS\r\nSBbM5fpXzvvyBbVY4ueSoGdakjq77FfPN5Q7itvIhyzkzXyRqfq0w+Tr1dfb\r\n941JiZe7dn9bxfprbNBmjFJH/3SifyRE5roB/Om9PXlccgqn94FPTjQM3dkD\r\nSejNtmqAtHm27G1ffdKf62QzH8a5IlFaN8z6wh7jtMhrpnYZqXbLGTH7csHF\r\naImrcCNq3ga7PXb3xi7+jp0kGEJDkd1ne5ZeIYTv78Q5xVaVvFkruEQ3vna0\r\nZo2l1rpzBNd4tPGIh8GecuMdOhmf5HdJjNo=\r\n=SU5M\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"af37167632314e97917cf155e39d8bf255999c85","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.201+af3716763","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.201+af3716763","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.201_1668062391763_0.5674424361192181","host":"s3://npm-registry-packages"}},"4.0.0-canary.204":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.204","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.204","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2f64745391baceedfad816bbae8c7d9bd0904182","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.204.tgz","fileCount":88,"integrity":"sha512-FShhFnzyesJxNpRPMm5NvZB5stSyLKxJkVLZSsHjdKG/LzWca/JqAe/m7xOCRjD2hc4U3ySWjpqLP9fSF1nB/Q==","signatures":[{"sig":"MEQCIAXTUs2yH8AO1iSCqIW3qJyZJeBhVc/xp75tJ2j0S9/9AiAKXizUuxS6kS7tWTl5c7uLk/IkDLBEcX9rhClHTt4ToQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbYM4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpArA/7B+cwui4V1sRJn9Pj1q01IBladJ2ZSSDjqJOxPTTZV/FHmhfz\r\nQIisTrPBgxVwGk6Lrvh+3KAqr0IqkuCQvrFq/dGrWpniKKjd/R3ROOEJkdgV\r\nqDdZGcTKM+vkEqTXrgLUC5QtIVDdogpi9dkKHIv+HjpjkSHXvX2XUQ2FWdnu\r\nD+f+8KqgDviOj1tQK6LWLy6S9rKmt791Nc5eDSQTEwDaZEdRnbnTfAfLIdZT\r\nOyssP8TenK3UyiODR8D4KoeNNbCWB2oxWduGbwLnrQUzw8sIAGmXblOFp1YC\r\nAvJTrz1amV3aaevIh898sCX+cci1WWxEnsFuEAOujibAf1HUnE1Yofd0x0Pr\r\ngav0cQ4Hk1gXYNlxL/73ApC9KgGAgzWVsNvRxgo3ZYngGv7ydkTf1/FpjmRI\r\nqTHSSa6gNEyenhqypGu0BOZlghah8hQdkmxdt/IYLNadYpwxfEU8jb5zEjiG\r\n0YJdsurZSTsXwsg6aCizOMWGjFEZTWJSLR0aGcCuvAMsopGabrvsnJnm1Sfd\r\n+89gNZvMMq62bHGPl6oPtr/m4B6lkh3VVOOGpkyg4O/FSRmgs5Ygb03RDwyu\r\nrPpTP11thktoOyHmrH4kQa6f3Ectoc9OzymBzLvSrNyuF2pH+Kx/B8OX0kWr\r\nWFn/908z/BMYJu912qGd9WZ3KsJpCE/II6g=\r\n=fFkp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e45963904b2640b4756d08ba483d240a62d0e93e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.204+e45963904","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.204+e45963904","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.204_1668121400210_0.5753425924590325","host":"s3://npm-registry-packages"}},"4.0.0-canary.205":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.205","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.205","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"40d8ed4da00f7e4517a0e23483b4588f62f68c9b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.205.tgz","fileCount":88,"integrity":"sha512-fiFz+c4xRKxOPMjULiOhZ70XRAzxKAtTfyPKIEX+YOPF2gkWk4VgNZM8Jynh7nOLBSFya17J0NYzkF9TkGU6aA==","signatures":[{"sig":"MEUCIG55Bblr9uhWsuKJQiw+CKZAmdBGaNKUpYczP3EAetrmAiEA/VcFjZNZ+u20gDOWE9mDE0BY+k7bNclld1QSrn2/Jjs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbZq0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpG9g/+IJ+lLrGt9KgzteAUDVJEXOYIMIs/tTEQnA63D82qjSrjCqTG\r\nlouLp3+DqVZnbcfkMIMEiosIsPAHq+V3PTEqwVdQ//OynO5soqh7yrFaXMfa\r\ny5/+9TpNcjiuKTz2YKnI0/Zi446GIm4aLqZ3qvd0LUcOYCIiG4J1FL920LTt\r\nh0asPwvU0n5qaQB5tlQMEg+vuyzTjcUcvaD30d+DHen4XrHFQiQez/14SWpF\r\n4R0DIYaB3acRZ1LeM2SzUgWlTZwy8o7R7Kv1azAOspkJaND9EKUz6Q73PoxL\r\nu+eIHlYsF1qqpG4zcb0qDrKWX4Aw7VKYdQ3P2XO1hyMA5+JWOyZe4prJJSNV\r\nbhI3O1xpXp8UeagxC5VqgSOmStrIToqQQVKXJQao9/ayr3DX+Qzr1ZJe6ZJX\r\nSgiFmQH9xjwt5ZVsNbNDK3BEtT1CUNbeBmaPkpeGDpRN6gQn3+Iuj2ZQag4F\r\n3jSjYnimtkjPUPkiGKr4dzk0rFr6Zghu55dGeQxPnWPgxSMbkig6HK/VNEn+\r\nfwSB/H5aQ12Mdrt4OqTHPBg6hFdJYfCO/8UL8W7TXojXUKWPwcgEZiBUquoQ\r\n4GOGmb04UUtZrHe5KUHXjR4xkbicQEFntsPRH+gaveeRiTT4QHx0K788rb2M\r\nfGTppSHzOLZVv1YbbiHIHQFXV5RdK87ec3w=\r\n=P0yq\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"62c49f8ddd99f6cb36ec0a969bf776b36dbf6f24","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.205+62c49f8dd","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.205+62c49f8dd","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.205_1668127411870_0.2841256827971925","host":"s3://npm-registry-packages"}},"4.0.0-canary.206":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.206","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.206","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2cc01aeb4b7b482fd66625f0703743378cbcda57","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.206.tgz","fileCount":88,"integrity":"sha512-96nsTdEJliqwEJUIXPRgvLN9m8bDRoi8BQFNVI+EH31WjGT5P2eCYaHq3wKicgrXJ8Qs2b79igsianYEVXy3Gw==","signatures":[{"sig":"MEYCIQDDycZESInACh5yapIORoeL33c0Xa3GfouPZp5wwrrR0wIhANUUT+FXyJ/lniIKKI673YUtltNBVykgPXqbAXVFnAh1","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbakkACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrKzw//dknG/DLf2Y3EfAinXZXU35XAA0G5oVaz2lsxWAIVFeLHfICb\r\nbn91pCFSptIPGiBuTAZB/Fo6KI/YAjtE4Wx5TYoHbfuiirOA/jcQKsdH/zHB\r\njPv8f7j8pLtE0ngVrPFTns0SlU28KcFq51wi0brBFnUVdDxCxq+rCcdoB0oR\r\nHw94q/t7OEE2bU64C8E8XP3wD3sPADx3NElmncGySBFsZX88IVyep1T7N/CL\r\nPFzmlIwF2HqwRUiJ/M7vBAYrNIFY/L/Kn1mZpztgJ2qdJLYW8s0WHmH8Rwf9\r\nI02LGyv+3r/mxVVR0Omu7QZFfwHNI5SzUTItL4gttEBujFILrTZq32CRSPO6\r\noZn/RpOKGLC38O5OWuXPiQFBUCycHPAje08a3wtV3qqtci7vNpifTK6lFZzu\r\nrN4oq4kt/+eXMR0s1plXXw9YwH/Mq/a6rueTO0tCP/6LH9BFEDoIX1jiohvG\r\ngKkvJLY2PwBnpMXcvNOo6AOOCTWn9LnFx1iu8Fr8MKkQl2DyKtcB1rjtzc2N\r\nZlnFM9kYc3fsrJbF4uOsDzmDu0bPa8AlafSWkS4DckTXvHOxlhTB6B29rE+T\r\nJePL8sYyK9Xyq7DR4/poxieqGidwplAI9MVtVhZkL6/Y55ruTWVDabc1WuL1\r\ncbHYXeQv9L+CkahfHxTa8jpWrakRv/AXpiQ=\r\n=FIxP\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1066348dee0293d3d2ba3b89ebc819a8757a321b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.206+1066348de","@babel/runtime-corejs3":"7.19.4","@redwoodjs/cli-helpers":"^4.0.0-canary.206+1066348de","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.3","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.206_1668131108707_0.7870689204206025","host":"s3://npm-registry-packages"}},"4.0.0-canary.207":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.207","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.207","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"90d90e47cabeed3dd6601198efc4d1ae8dff65c6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.207.tgz","fileCount":88,"integrity":"sha512-x9Q3+IuWVRXWImgSBgMn/6825sh8pNhrzXujj9xGf5cTZUgQsdbv1bFqC164wBV281qNekcoyUcsXR4I09Rr1w==","signatures":[{"sig":"MEYCIQCxm9EmbLt4o5Zh51wnxa3vx1G1BuFtP1IGLCg+rh1YpgIhAJBEuQGIGD/w9u2hsluEYaBpTqDLckSuaY7T724wxYgk","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233511,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbamTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrbyQ//cR2IrixCT/m3CiF5HwS/83mfEZ0Yr6uJSA9FGxrraMZmLKm/\r\ncPker0SyMU+n6kVgsyiepxrqSjdfnWbUrGRSIFkqsJj3TsOuyRFyrXRM7iD6\r\ndl7U4Lgv44uzLk4G/z/QyTg+6lM1bWWjozlCybIMlQ1eR2LaU2/D86gQBE+4\r\nlSCTM5ykrapW3jDyThH/eba1d3kIhpBWInoqrHxxdipeufCj/g89PANVNEDY\r\nhHmqNi5XH297nysjjw4lkEw6OmCRcsgbnINmENBCOSZbAw2VBWfss0PRT80o\r\n1raPxxkhoeE2f5MawyrKp4rVaeC0745uvKbQq1B3qb+jzAbDHyrGEtHwTK2j\r\nH86MV/u+hkWN+P9ELBflFhi+0jjBvwjCWsVRrzNui7Gz1gZjn2CebZgg23Ik\r\n6R0mL4zCw8RQl7ZsGAzwhSfV+Cqm6vICQIuUPdbg6PgI5J1ZRSQYjWtlT868\r\nfv5a/Xm0k2fTaYciDmqEc2E2Fp3vamoItBj4fJK6tYFzb7raNTbGV1itmxDA\r\n9R7Av3IimlKILdtreAc88IMyeig7YpQfXyLiyutPzJki96SyifDxj3Gk3P17\r\niCB/wzrKDENdq0yeoyGoMy6dvhXfm6a4x+WcH/JOooHNGP1ZOp1MXXppGPru\r\nT9oYGibnfGd4lZdJUYpmvXLBzTnhzQCnB6U=\r\n=N+d7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0bb0f8ce075ea1e0f6a7851d80df2bc7d303e756","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.207+0bb0f8ce0","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.207+0bb0f8ce0","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.207_1668131219601_0.7642502419784287","host":"s3://npm-registry-packages"}},"4.0.0-canary.208":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.208","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.208","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7a8408e0c9adbf37454bf420b7063bbe5d805759","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.208.tgz","fileCount":88,"integrity":"sha512-a0IVoOGAlG2Eo4S7u1T+A3GID0X2K5T4hoZQFwnE0dk7kBC3olX09lw2cHXKF3JrRUf5lrgBxOUXVozZ4Dap4A==","signatures":[{"sig":"MEUCIQDRk5dAmv1ND8dO4W4dFqURe9A4tIvT/QL8hweigbCZPgIgQJLz7ZFETP5p7hUJWOQomt/aD6Zcq9FaVIgjasOuyfU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233226,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbbWHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp3lRAAi/n12RuoXHwq4rSsWGP8v10LkCRpyw+qDgK9TPS3Dc45ZxZm\r\nvCVqAqmO8je2v2bVQQJ4qE1f2CMbG4dMCT5FIJMvR/4+/y3teObX+QsImVKd\r\nxv+YM+kTH41vlqil+A7x9LKmKpAxlftRYbPcDZrCq4kJ2PKZBNVd9g/3gvFv\r\nWNOF3xsdsTnLGZNXdZWOFQoCJtgSe3DYoFbA/sh+l3sHIFZtsw+Ab2bCSTc4\r\nDBdPEwoHH0fSXTMFHcT14hirFrhupbPICzXahphF1jCsrkBtDfNNZnEJ6uq3\r\n0z0szUfK6Rtdwayar1RSj6Rwje8Mkn0p5oH5fD0kE18etWyMddHG9qnqU4Lh\r\n1tofY5rOlztLUQFTT4QZzIn/mPLbzOJ1bQwfvhGcts3BbsW/7choNJTZt7uj\r\naxMSoEFkFQO+ykQFCAeTDCBu1ZRNCezL6ODeurDPi5LoWBECFNTBrvGwaN7P\r\nVfgWMczRS1p6YEk5ZG7AVnos8wfpQF+veGJxlBzTKTTgCu39/KtvRBlv+WfT\r\nznM08fSmLN9wtz6Q65ne7ic4yz2Xg0VXwd7p2Kw8hcgXgQiSFdr6TTajuN/m\r\nmU5/bKbdoTgdarSY11hLIfXPuehWWIqf+j1RSqYBonLqQm3zCHvHkuisdnt3\r\nQrRXIYToVcOy77bqpBH+e45kHlW3N8cH+vQ=\r\n=rY5l\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"34125a54af769a0f50f70ff8b76ecbcca654aeb3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.208+34125a54a","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.208+34125a54a","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.208_1668134279156_0.5944367340858094","host":"s3://npm-registry-packages"}},"4.0.0-canary.209":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.209","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.209","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"86ef3baeda5a7ce6b084cb96dd4dac807aac3398","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.209.tgz","fileCount":88,"integrity":"sha512-rQwLH8W5JW9OFYosg/YmcxLZKRl9lMs/zQSl0pWGhytP8POnC5ksA8mU5drjAHvQfKk9uqBQbFb9zPX0U32w4w==","signatures":[{"sig":"MEYCIQDfvI9ytFXDSX4chlsOVrzgRcSbfX8sQ1bnrW0Ewouv9wIhAKIEDHhnYCdH44NIGK3SOiN0y9V1jW7QnjFg6KQ10Pbq","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233226,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbrQjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqNjQ//cbyFW9URwNzVd3EOLeCCfNPZnU/dm3BmnGGoFOhoRGkhtujl\r\nRmLLbNyFqo38SGyBcxh7rfQ25ODjYTUN6QDyDGL0Z9sxuWd7TrWwbVxBvwR+\r\nctlYzspje4exleBDneZVx6KbufVY6nFYnRYd5ZB59ILH4DwPJsBz/O181zMQ\r\ncygUKDJ0zv69t5WFXHXUA86qOl2HZUGA0w22elLav+AzX3JDHdc7VhhvkSMI\r\nsdk84MU8YLzDaaa+fPSPfScOpHu7GPFqjvtekVIszFrD0VKnwHCkrAqvUSj3\r\n/LEzh7fS7Nkkd4gkHnM9gNha9UsP7XkqaEJH8RUifc8IE3JkcxmLxLV7PP3F\r\nCwxLlDMI5XUUUTmZJQKjz8fV9P7zAntH0c+wD3aqmLREQWhtkycm9mk6a/u5\r\npci3P2YD3V6DGqAuoozCZNwDMu8bY5LWbSirvKwZuXCQV0zVnZaLv9a14gTJ\r\nTa30IAfOn9iFQj7bz0BaXJ8rysPXz742l2FThIyCEXSP6s5QqUkFtljuSHlM\r\nHRs2wt9qHHchs8wjnq/gtXBau3ek3K9TcbkBETuGEb4VXcNVVdcsBSrkefTY\r\n1ZavI4JZdFPiAKxKEdeHBRmnvE6ktEa+6TJ7cUSonMZUFdLi/YFFLYssfYlr\r\nKbGcFQBc8HkpyJSaI2A1r3Z5ok9UGWaIG8A=\r\n=7ecQ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5ec79849675546e71a0c3bbf1ad1a958afed6dbc","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.209+5ec798496","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.209+5ec798496","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.209_1668199458863_0.20152726744526261","host":"s3://npm-registry-packages"}},"4.0.0-canary.210":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.210","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.210","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a16af6c5c1c772d7678bb698714c48f2c29e9293","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.210.tgz","fileCount":88,"integrity":"sha512-EEWzYnUewfByFIoOR7Kdon88NudEFk89j+jozkxO+LnwjqV0jEnv6J05sRnwSSsntAtl1x4Rlf9vLt081CcOLw==","signatures":[{"sig":"MEQCIEVntw80/WRNlXPhBILBL9v152rFo50EqgDEmwiwBwX1AiAPzVTJ4zCe5PsR9A4XPEU6h5JtpoSU1jTE7QblvIE/0A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233226,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbswJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqzShAAnzLX3pbndIKMc6vGBLSp6fLMS5NlNT2esCby9umz15Ns6xVK\r\niZHltLnZUzoRZQu0LZD9YrH1aLgVXnPf9vswmTP2Kdfv78ciWlycbJJBIKd6\r\nr/6yzjBZO/xX4I3PpEDXL41XZw9LRDNY8oIXDRHj+hDLW9GAa8LohROAyO5w\r\nEOOPfDWtI/CTVUr4iuTHoHSQ0+ZcSljyjBN/jQOIphx/CMIqjd0RfM7Xzdxr\r\nazWGImj0a/bUFFWCrWPehiyn1BpvJ2J4s9R0WyqDzpXKKvXUJho0wtjL1evM\r\nUrwRnSJUMTXV9+5xp9f1Ubh19zGNvIwg9QBemmciJJyceNOapsnA/hDJkDN1\r\njhcXtABiA3iMOLUorO5ZuH11RsKEBaNsz8X4UkrKdT5Gy5jEiaEkzbAowkVP\r\nUvNnSvtX2inCiEJWJ7241t590m3jZjo+1oJN2BN5kyGpphi0dVyxeixJkbp4\r\nekxWfepjlKKXqd2cktTQ3cfupbpEvtHuJs0/2PP/YXEFQ7ltEIfYpuSEMxKy\r\ni/gPikwX3we9TAWcbo1O1YMeOZFrmgSe+mMO6UOt8XlRYeLUKPH753oU2To5\r\ngnWmhX6HHH3O2v6UGl7ADNiRUPI+8JH3T1QrOSpr87xfmxLe7HiueHyFtP5h\r\nWsx1m50QS/3bdbKlNa5TP1d/XWCo3tByWRU=\r\n=lOeg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"45325f866eee43967f909c7f1d2738d6b06e6f64","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.210+45325f866","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.210+45325f866","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.19.6","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.210_1668205576785_0.33355676858538374","host":"s3://npm-registry-packages"}},"4.0.0-canary.211":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.211","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.211","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ad315ba3145214db82100cd3a21ed99ce274cccd","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.211.tgz","fileCount":88,"integrity":"sha512-8VLbQqz3edOfq3khZrNyZAETUS6rjD4Z4phTyUmLx/aGpssosrPGUL9r21txIupRfNC62/jDWGWxve36Ls24jQ==","signatures":[{"sig":"MEQCID2DVll3TYVBWxP/zgI87zONgxHfJFv04TCaO07AqFomAiBtF8lWK89Yhx/XJ0iSOUxQEOPqcxvYNVIY5fASJvly+w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233226,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuORACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoBBg/5AZTYtKGFdERyWczSnaQywImP7EMBXU8x7S0PvA/aIu7PUXZn\r\n166wNKCE8tCQ3Qu+cJ0/tG1ZK+UT0CoBmMN7TdaL46ASfwfr/Ev+4s3In0Fo\r\n8qpjVkYTEIrFRh0wysa0QrPO94hs2av1z1lG8MDonAmy3Cz6z67o9CM7q15J\r\nJ0TYlNJcOFV5meuyAMAfK91wumMyY+0Ba8wX0D2n38WPCoAsFzFIHPdK7kgl\r\nqWe/B/dJQwldUN2t2oy3mU0A3vRdSNp1SwZsxU3XoZxw51MKaf2vjAgTAQcw\r\nGXon6eJUxCCyyXZEe1o74vQVWWDRzlAgm4ydJiga8kpdJ8T+/ZGvTs7OlSAi\r\nKScrrXm+KQs4RwNyc5YN7E1o1kXpcCHmNZBiV73z6S+1Gi56oIjoakn5rsV5\r\nKG15R81A1BcGCsshn4cLI6NFq7ClqFdp7+nZlwgzcOJW5MkvZ6CWHediJq6o\r\nnM8STVebirDZeH8qQpZxaop5rx2Ay4Lqp8gLDCziDVHqMfMq1iuGaHbY3Y7e\r\nth2akXwo/rPTmOXm6zgr73fH4tUSf3iPPpdetldMdYxY38JjjhxGx5Koz+31\r\nJYelLcv0drV3FI+wrWCfhWE+CYLZJUSvgKzxkVpoQHunLePcoXQG7KamNOmq\r\nKQmevK/a64TyADbasmzOq1oYrEELALeuPww=\r\n=dEqO\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"01ec6c1ad3f9d532339c1e375dccd75b6669fa03","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.211+01ec6c1ad","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.211+01ec6c1ad","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.211_1668211600853_0.8330440080263828","host":"s3://npm-registry-packages"}},"4.0.0-canary.213":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.213","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.213","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"060ece429e7507dd008874bb850d0a5f8444aa34","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.213.tgz","fileCount":88,"integrity":"sha512-2BlhSpbgiXOlg9/hmr60X1pVxGlR7ecQI+I5DXcJ6RyCDovv3ZzNAGEcH8DUOC12K1+Q+TrfxZSlwA9UmMSisQ==","signatures":[{"sig":"MEYCIQCwD40jeSXW5Sjg61GZNfwpmsFUfSicmcTXb48Kgra3BgIhAKonLioBHUdNHdUQv5oQXOsHNB//hj6q0IjfPOaCpuWJ","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233226,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuRYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmop7xAAnyIum7ruZIuUKcDLqil5pLeB9M0/aVx7OlvEWHubhiSDRsfL\r\n4ZMPK1zJ1E91K6zJqIw+LRslqI+jeU/uV3q8yv7q6K8nbYP05HJZv3LTjCgC\r\nBR9oq7/QVt5nChvMbnqsMM9gtFr2VZ4ET4Uxhtcu+7N2D4yy62Zk03GMh3MX\r\njnzf3TkbN6044FWtx/x6MOE9VfDrv+UiMhgpo6pGgQZzN3vDuNJQxPvpcZtA\r\n3EQB6lE4ebBW3G2hEH2DSqqhp2zg1oA7G0358NzrPj119Uv/oHPsnAExBoIK\r\n+j0Ifk7Zk34LN413jCbScoh7e7e9UtYy54VQ7nkrhng4CzmGQlibd3gpPTlC\r\nqVDszM3DY1iv3w4BVMzzHpiHeZB68Al4jVptrmgJxi5dreBGUA36BofulZMm\r\nyk3QMqvKKyfL8hXfuAd3s9UjcgnrD6iUlRZAsChdzBjqgkTR4Q5mS/ISclFk\r\nTnLDZkvUifIj0sSjYL2SW64/Bo3i1PzmVIlc72UYpocaEYs5CDC+VfU8kpzp\r\nMiHXUlGNOB3rWrp8aB7eML6oesGUrPiChDE/D9L7mH4OSCJJv+M0WN1I94a2\r\nqKaOxDlh4K7kJmcBn06OnnKkK/YGNwTolUdDly2of/Mibp+cSkexAP9Nzrn7\r\njkZ2sJIlNt9boGqAYPg2XkAuOttjt85T47U=\r\n=2lF0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"098e921bcf45cfa9d02119e1f2b146e6b19b3eb0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.213+098e921bc","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.213+098e921bc","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.213_1668211799848_0.818758074455191","host":"s3://npm-registry-packages"}},"4.0.0-canary.215":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.215","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.215","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a576b14a1cdbfe5a8b29b8db6b992e32d5fc6d17","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.215.tgz","fileCount":88,"integrity":"sha512-yCou12IC1J+KfWl1GtKJTxxzXg7vmkpNsls7/qdTw6/FTZ9c3rBIAXxDAkxNfeJCCpn1UBeolvkZGmhmp7eTLQ==","signatures":[{"sig":"MEYCIQCkNWtYn4OwbnuIgR8qPnbNIzoME56LqzDJrUk9+OWKTQIhALdMbBPNOS7BskqIHC8XOFpFlkfk5ijvts5qXebScvx5","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233226,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuR7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvfRAAiVNLzS3PG3ssc6t8yo5PRElYshDAanUWZ9IiZU7pKsXvr8PZ\r\nEiZ0ixJpYNN0iohQ25oJLlhTY6WFCy2D2iZleRXEYPCn0WzplF+fN863BASx\r\ncxp1xvmkh7CHbh3PxN7U8j8NSjXihPBs3s+54u3pXYe9wAqrV8++dKkPHWHf\r\nCjSmsMs+sBBiQ1Ykl2mu5WZs227LC09czodgh+YoNaP12F1vxGXTLGbuBM8d\r\nlXyiI5x0enmYUn4V6gvUgQoPlv9HBfv9jZFHbfiR8yWrhdiW/SQhNJtrXNuw\r\nYSYxzEfoxtDLmcx8OUFFMxn+86HBjN9IEx5dAn4CSljPv2RRMb65fppbm+c1\r\n3poS96WR/uqXftYyNlv+35mfF7Ycv2WcttPdygfE+IDB+ugjVkOQY+Fm3NxH\r\nT7EhTsCSWyHP9Jce2qosAiafKad5bJPAmzS9Qn9Nm1kwki/l2nsv3469VlLH\r\nDS+GAenIX5bNg0+3Esx9WuA4QOB3nfA8sEawhjAK/DywRe0c8AkXkwpnmqnc\r\nBABqUYfl5K8Cu2s47RE2XLKjAJCqyWE62OZJb3l1obtkGY/jArAQl5zDmdYS\r\nec6vn1mLd24KtgUDS0UVuLkTUo/thnJuUcIFl4uswKufxTYux2QqmjvdCRcT\r\nzJ2e2+QRWxNs8A9rpejUVuh3IbAm1p4JHmY=\r\n=BaH2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"dcf86a53c849e374147d34b1e77a1ffd2e397a2c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.215+dcf86a53c","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.215+dcf86a53c","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.215_1668211834932_0.5720898441502287","host":"s3://npm-registry-packages"}},"4.0.0-canary.214":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.214","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.214","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"820883b3de63d3df1254d91d5a3a8aeecf1943ff","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.214.tgz","fileCount":88,"integrity":"sha512-de2Y9Mi6ZFlr0nJ0YLsHwhboBbHEaa/LlCEuCcJCa/xWqMRs8YM92L8mSUA7xMMR+6RXfZYblOdAg6D/wZEhAQ==","signatures":[{"sig":"MEYCIQDJRYBUuqikd5RjsamTA8dXRP2iAAL7m6PuBKWTt5HH/AIhAM8VbyGqNwcsydeNxR38TlVxY5/osQu0Uv3Es4eeuuHy","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233226,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuS8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq+Zg//ZEIiOeIMcbmegkqe26oxKRaRw81RSmfZrLPs0zvdA4by39Hc\r\ncFHV84wjmady/FMbqU1D1MuC9HZtz9tkxY2n0DXlfFgU4WaUh0v5uC9tdAit\r\n/Vc1iAjnn0OSTA7dDNmqzQpYPMhf6v2Dl3DPGj+aBkYgeqxHKlrMDKVVTlk7\r\nDugksMZiVKIiD8B5lcakf9jIV1rMRl2vk6HZYlGnk3Pw1G9/mBrGIimT8quL\r\ngnbPN66sUzi/7GtadqyKZT6zol8qJ5F5cvM1aVNDraCAhAplL3o7n9/AhfpU\r\nS4znefklQFtuQUCSsYSm0LPpWDRUxIJzQUrVVfDu4IrCApXpJd01QcbTP27R\r\nWPrm+XQaLEmQLRkk6ySRya0s8K2IP16Fh0yA3+OBjPhklNpCam0RMONDCn0W\r\nhWSZtk3SI67AZ4J2YVnIhCn/QMvE4ZJmnaGPTR8fqGnWokqcpcmJ0VEnWq1H\r\nzA8YHKdYBs6BEDk3i74dZh8HyVP8DUlkb1vgcVi2YAoeQHb+djvQi7Fg33CP\r\nx44IG5NyXDkmoBny8e2aMR/rIK8PLu+Cen8V1J/q6yaJgNre2AJdfp1vLlob\r\nU9ISl5oB4t/deu7aetwpTN/UDkAleg0xbQwZNlvyFTMwUy/wumOOhpwDigN4\r\n9Tm472kCUxTWZik74g4XhH7GwX0FAmVosvU=\r\n=hOMA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"129a7e3465f12305f797f44710bb16bb456e14f4","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.214+129a7e346","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.214+129a7e346","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.214_1668211900015_0.9399947185471018","host":"s3://npm-registry-packages"}},"4.0.0-canary.212":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.212","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.212","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"561f6dcd410618348465da09976fe91e527c951b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.212.tgz","fileCount":88,"integrity":"sha512-l1QvY/qL1mPCbt4Auo7e6xj/npjrGHwHo3A+DOAoqthx14OCu95QM6/opLyOZs+MZCNBof2q7J5RiaZ7kc/2VQ==","signatures":[{"sig":"MEUCIQDQdm7ymuHXSvp04HzEHwiM5Uy6gwmYogGSaUHKpXQe9wIgM76evWD5iXhBfOJhgOs9XQnAWyW2xJnm1khdsTsm2gs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":233226,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbuTXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr+0g/+KS0wiBmQT4Ybx36kH867SYKDSbOJTWHkcN5lmsw5wXrq0HQR\r\n2skVQCbQtrJVidC+7uQYggDQfEOFvWZBwcyjGZSmS0vROndkLMijwGUIEZBU\r\nO6X2pgCB5NRcLwY39WtzraGjLhE9TWtsld0bUt0xGYeJpv2t4YilsUb9iufY\r\nblxogEtt+WjFMb8oGcA2GIMjg8shhlvCnT1tfHcsJK6AYZRr+pGC1nefxEgS\r\n2ydrkYcupr3zwT9Ksiliy5TRDVGnYSgOLkTVdRMsrzrYpIyfxAvEEMzc/1R0\r\no42qq6ci05yibj5N5dVkYwI2Nvp+CVMbNc8rUcvgv7/uQ+U4+YpxEzpNX4FY\r\nah3VZdQ6ZjEWGwubLKhJsf/7FwZcOJLz+tWvIIcNvtG3Fxk9UFebZtWl5ZHA\r\nAGEipBpjMonXFUiAyh1DlX2pusIqu9x4avObX9gV2JPg6VkBW/y8DZkpKY/4\r\nI9rvYUZ1w109l9JtcsxWASkiM6kDlQ7VSx6X1dabL66iGn/ZBAce5Ovd+9pz\r\nqLU2na8upKxPuIfxzsgXcwtkirqAHq7AGf6CHv+RP69v2t4fG/ly9+I8MCI8\r\ntlbWqcyC1E/SqyF4Wl3lR1NJ0q8Qt60OEWOQ3sa+Ui6IP1jcknzC3iYWJ7YA\r\nHzzNWh96IR5ZIZ394Ti59i+lyD23FijU12g=\r\n=5gAq\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"457550a14c0928794315aac49eac2330590f0f09","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.212+457550a14","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.212+457550a14","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.212_1668211926962_0.9491430085492278","host":"s3://npm-registry-packages"}},"4.0.0-canary.217":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.217","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.217","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"18e5c87a3e3b39268905509ba57bee93baee034b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.217.tgz","fileCount":88,"integrity":"sha512-q7m8hqAdltiseLMryBojqOEXafQ2mZDJyL/SdUW7p2Izp5fgJf3B4/xu0seHCbQdCmBSyQUARFFTc9H9GRRSGQ==","signatures":[{"sig":"MEUCIHTxVYVM5FO/GMeSh2kHLEa/cdFWpQ3DPcPoKINIBEYGAiEA4yaLcYICO+uHn9a+SNh4euOhwXIa6nrRMADH4LaZoSo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwOUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqDoBAAhqm91Nsdkq0KxNHgbTvrqHHliLhisFuwnroZX6R//Cqjnrez\r\nfHPH+IvJKZCVaZh9J3KSJBxleBtzz1Wsdu36t+iT2LBGBjqAgbRDy0mBdLhA\r\n2cEtfAqMMNaRijl4cXOSM1ww45/O0dCY2qeBGo86EN0R3a6Wpjfv49meihNR\r\no4zJ/BlEXOYoCZRzc+wxTh+53B+mPp8wcBe9J0+7J5yDmOkCAyfmnrCMurbm\r\nWH4K2fXFwfFmCei0POQiopjmIoL9cFPKyozP1B47oyFWg4NPkAXX5+V2430l\r\nFmyDyaWigSVuQ0yObeUBPrlVcRjTdltmPQvwYjlYTNm/ajvZTclic3jCdgnz\r\nD7SaG9XSZxWlr7qUtdvgVoFBe1rGHyhNH29o9KNbESQ/+EaxpSnlEzp+AVWF\r\nd4RrFNS3PhJT5WTNjwFOhSMdRA6hR26ExpI+UaISz+8IW648nq2ihKbhutvY\r\nAT8ZY4GvGNlJW87O6CLtQPxhsYM727lhyf6elEny080NA5mSpZM94JBzXBTa\r\nYkmWqz8MnAbfA3U0ADuznHgyp3rNPQyyO1hRLW27vg06o60WlIg+ggqlJLcF\r\nKss4kh1t6nnjVUvxsblztI3IPD30xCPz1+kJyQ7edImFwyrfvav0h9zliRpB\r\noCXqUNTjdBKEft2xpbi+7VIm5Pb3ERWDlik=\r\n=c2e5\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7c2443b30569b8617a88d52503a51ace463c4cc9","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.217+7c2443b30","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.217+7c2443b30","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.217_1668219796753_0.21500865498379862","host":"s3://npm-registry-packages"}},"4.0.0-canary.219":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.219","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.219","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b01c5fb87423045eda1e626dd987dd0a35b9299a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.219.tgz","fileCount":88,"integrity":"sha512-wlYngpL+xlVLkjXtGPeDoXGit4JK9PhySOwkHrifO6O8r+VmO67i9IbfVOt1cfNWnnIj0JAATNM17JAxFGntsA==","signatures":[{"sig":"MEUCIQDClG+imUH4Q/CHFc4+LiN1AKNp8v6LMbpIl8T6Ld1kjQIgVf2Eahown5nOSGsPr9fYestbo16arh+2YaJV3/bIrfw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwQsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmps5Q//ePAWYL1rte9dLQTL2C4xPpJdXlyjWgetfQo1ekpzxuwJly18\r\nunYipWopYTQA9VWb6X4IGbJ9k3mPXRRKd9tq5/5SDwkUor0WOraaq1SGGZ6j\r\neGi1MbfjPKEpdWKwrR/UyrHmxBlbTd1557plxM8M33UYZVB9D153IVt29wUH\r\nMWUlb44JWfey5dj2R2ejIzeHae6aR11MqxLtdav3+BP2j55x29S/QtMFaSfO\r\nKW9Ijbb1SApdxFkSxan/8+8SeZMXy8QVaOiViV/qIEVdqs3XJXQiCvcKVpeS\r\n7iJ5C+N8dot/e0Qn4qKXVAeU/LKmIpBi4NNRU/VKcv8Xw8tvNATptx+40YKk\r\npro2pjkEiyPG0l3FRgSOLXhJbgzNm5uCUCoECwVzds3RI7KPccrmo4OnMQ4P\r\ndQAbAnQWr83pl/Gg2CeAAeuiWwBFRUMOWH+k7mhPsYpTAd/E6ct+emXznAcE\r\nQTERbIYvn/1s/TvL9W4+2L+lwW5R/Aw9cX3wvnW4hZ7bVl8mUYiH5kgwF1da\r\nLnV7IArhNhMitnCRRMsYRvaqAMWjO82Zxenvd0e6WuQL62fT5kNI0FbNDCi0\r\n+mpv8tQOztL83X3b7L9LhznZ61AcLzdrx+90M/doR/y3zlY78lKQsyikCimv\r\nx0e9AWU+XHjSjOpEx9wH6OC3dEiDmr4YJ90=\r\n=GNAk\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"46b9b34ce0090f9765b829516e0d970c9ce2b8b0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.0/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.219+46b9b34ce","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.219+46b9b34ce","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.219_1668219948442_0.29572962185447227","host":"s3://npm-registry-packages"}},"4.0.0-canary.220":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.220","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.220","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a8c706cf8ff53446ad53f4f9bd431400e0d8b1c0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.220.tgz","fileCount":88,"integrity":"sha512-OXZV/+PJlHiskdPpcIMH7nucEG9CCL86Ztt82Zsf9fOPHJIn6hdOd1UnRJ9H6Xd0uuNpDXfs5hlIUf3vgowOdw==","signatures":[{"sig":"MEYCIQCKi5q4Vt3LrEASB+DEFRxixJowbKqIKPwGIfxfscJx4wIhAJNan2UjaShZFRzsDvb568nH0qmh5zOLfwhq0BLrhMZ6","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjbwryACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmojsA//dBoLgg/7lLLlBbgpRj06rSlJMM1/2NVXUUE21gFfMuqX5bXC\r\nbfxdDljjYRtUIzuyU5VcsE6fSQH8zdQH9WxfNiDMV51pg4GG16QP/yzq1muD\r\nnxw34eyyXbv51wn3QcaUyThzp3VKWyM+X9Z+JDiqyAICbyA9U9Q1CZa0w0MR\r\nJK7oWf1bVchcV0pnPOAWBbvN3IKpBVPQn5+ayS2tyBwdtUCwUSx9I6FQvqWT\r\n6JZ3FbhVT7UsEzJJynBzbwMabfhFtPgrAbSMsA8jNCZJqrYAMM/EcOkoNnAB\r\nIieFyaByRQ4G/+Wza8pRdS5NG3oi7ETJJtIrmOpcMaZXe8RpqwiK7okN8TLh\r\nWtGfwDbq+rJ7Lr9zJqdt9nFd1IbrTYEUsV1KvJXeLKzyrCcImrYp+FNTJhSO\r\nKK9BKoVkBq5eMRsD3oslkv7fuGHTSe73I31d+hrRzbRDZjSLWxo940NhUb6Y\r\nOPyLTAp6YgYcL+KytsP/8JGvlcE2GfX9tybf5DoFJuaVGAmUw2WZc0IfyskO\r\ng2+Ga+xLTSUmMcC1VmVVJxbZp/0s3p5JubydNnMN6/9WPtpQ+QRK/dr5qxns\r\n9kdStCrOZkBkyRt8BiKpJnxoPAi/yjYOw9FY9aBY4ZAC5GpVqMRi4LHv3GzU\r\nULkwSrl7Na2mPs6r2qZCI0t/47mGMAyp0N0=\r\n=QZjC\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7aefd74c3bfe12d56ff56c8852ea280076d3ecf7","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.220+7aefd74c3","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.220+7aefd74c3","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.220_1668221682484_0.10275102353477195","host":"s3://npm-registry-packages"}},"4.0.0-canary.221":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.221","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.221","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5324b3c5bdb9188e6cb14af2fdc212c1186093f6","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.221.tgz","fileCount":88,"integrity":"sha512-f396fFXwmVut+TrdBFzTl1ZwlZ6bdg1VhVdBbnjl7fSVAU2BoJTzCxXytT87azgdKzabWpMHcJ+HbNSa1Bb71Q==","signatures":[{"sig":"MEUCIQC7SV8765PsRDAG3ueTnlQ1MTyI/0KDHlEgShredB7lAQIgAvesAzuB0i4oTT6g2vtdVIu1IuXUoZR6qiqJ40YdxYg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcApZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr5/RAAgsR8JZpvnUL4TKfJwF9pxErhD3Z3PRNjOOcrG5GXI59l3BJF\r\n0HOXhXbEbhze7WgYo07xoh46KMZTNfiv7TQHO81HmNN6rWAwuhGORCuS5oJq\r\n6jXE1bfWQoIFb3LQ1nB4jstbERf0aMMTAi/lddsAK0hIXmtyeVvx+VH4KtrL\r\nUIqCfghcbAhygkJIAETrxVosLWk1WXo4a+Jg43ACOI7EtRIJzVVf11m3HlsF\r\nh24H6ADPu3tQKRHj+HR6HxsqZR1jbbR73fYWc5lr5/sd+ZWW/6zyiOPdsNZ2\r\nwRMZ8BwqHnhdzdCBOCqRDP9mbVexAOmMQw6BUv04c1BQPuyH2pLpeENFEu7k\r\nxIbW/fVWqJeehGjZmEleHdv0EnyEWlSAmJj9qCbC5DCSPPVNRZVdYnrXdNbA\r\n32DXrOtJCkhwn+OsE0ifV0/niFmjkeFHaxbz4teFnmXdv3337G0XNK7SJkrc\r\nSjG38hynXO49FDp5J4r/r1dMOvvkJFM6c2s5Mp4opzXU27c6AKjOEVUoHEyu\r\nCYQ8Vd8gm1d5BekvinivkAR7hEYAJr6PMpB7N6WY57YoSu/goHFG/szgkxpf\r\nYQ3rF3rnzUyIxNwRfSSlkgD9W9jymKRWQ4gweoH8b3X5bXQm9FIYxlC8ruJX\r\nnmHEQtFOyIkMIr0eywA+ECeg/jhFuHPOMjE=\r\n=FRkj\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4e3005252577dfb74c83429136b8bff043fb3342","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.221+4e3005252","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.221+4e3005252","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.221_1668287064751_0.04161971260062769","host":"s3://npm-registry-packages"}},"4.0.0-canary.222":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.222","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.222","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"16626165a4c80bf8ee449f42fe4ab542fa5e8603","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.222.tgz","fileCount":88,"integrity":"sha512-i4BmSD4pZbFW2QXqp/MI7W/XwRcPnjguh1apAJDrURxGibyJLl2OouPa++83qEjTQiQVmhI/8niKnvxr1pXbhg==","signatures":[{"sig":"MEYCIQCI6G0LX7Gwt6tZubtNBhqj60H3OMUxLhRj0G1/M4nfVAIhALKMqawQdXxT+EdCeAGGrksyDH8iFj3FTIVTqSSmMqUH","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcArDACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpobQ//XujiIkFRnwKG7YlWsL+p/aGnvQ9y/Gl604+DxSGoCip8fyiA\r\n/Deuo8fJqyo9Khs5SCpX1/5cbc7hW1ii9p/hSvsb76018ASNrFDvDjUqChwF\r\n2TdVKSVhG8QV8n8P6AOATGxQjSTxbJv7065Q/yjDdFvvXKIHAVTC+8++ZcVU\r\nsi11qObj0PQHchpXE0sIUr0IOeTDFuQCr2bTKOS/PvEo8XrM89S9PNjAywtb\r\nqe3hVO+jBTJ8Zj/nGEBD718J9HJweqgdTNLh0AjWyGxe0PRs10KdzMn7ygQQ\r\nHGB++4vgqLkU09sofBuy58F6O3vskgYxrJMtmBr/LAylroJoc041qCYgwlSn\r\nSUXhrK5ddLlh4rxf8o03sLSD60eNDsW4yMyxTTSU1QGR8lNhiGEP+wRfsnk5\r\nHC3cvSUmXMTRgoRR1Riq+J61j8O+IM8AU84vdBeOiQMFxTYP8GVVUHK2Ezdj\r\niigClUkDsNme+0sA3sGClXbg9KJXFp0ofzRQZeUlVQnfnhuIlPEtPWXRJjQi\r\nTfLTBm2KmU3MIpLcnwmSWaIXZqWKCkorcdnbCPSIcufRcFoWNDZkYTtG5N4A\r\nEJP8E0ZI72FusexlOww00RX0fqIDxCVIIhgxqpPvnI4juIphHW2+hUq7F8t5\r\nQBpWVAu+T40CDjoHUgy1kof45TCBwtVFjUs=\r\n=SvFp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a9c13f656ecd9ba22b9a9546b0c7fd46a2e43e55","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.222+a9c13f656","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.222+a9c13f656","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.222_1668287170891_0.2605056984728562","host":"s3://npm-registry-packages"}},"4.0.0-canary.223":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.223","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.223","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"30f7746d85705fd04029a9f5409cc54fd78abc20","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.223.tgz","fileCount":88,"integrity":"sha512-dDG4rfgXQ8kdVT6GlsgWgt3iDjE691f0ktRI5AzWJBZMh17yB0QE3fk6dbjj/AVpHI0WyK03Kyr3ta2KyhUEwQ==","signatures":[{"sig":"MEUCICMmxDcdmEC71RmBsGmc7ZgBiA3uESyrNMn2ijIpFXhsAiEArrNxzPQ5cLWMr3sWf2SUKvU7NM0YWXhpfFWLgO28Pqo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcDeQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr6rg/9H5RLoav9RgXKAuvIgISN0Q1+Vbx6PHA85kVU0/Sh5yU0veln\r\nDwNFAJY6ZpyM7I+S/BkAlAbMiyBMX0Y10Ky+7O4w2gAHaXvzwE5UcDoXvRGD\r\nMmFwHJLfV5nSEtojXzaU+bbLF1a+8izxXYi8WgjAJ7Cdh9sskjHTV6ibiF0e\r\nLgspzlzIF9PY4/SfWT5FIANSCgxSc9KXLRtUPykSprnRILDFmwcC9xLZbOwG\r\nREshE41N21xbj6bmQPlRz2GE2udX7tqx7WmMcvvnuj0At8sxGmOPguvC57dZ\r\nb92hjVTax0jMI5EiyTk2oaPZedTww4CTxgdObmz66bqpW+vvHuC1aGnZP/Tg\r\nX4uCA/YWMZGnyuBcHXNDKUdciFp+gQS1ggD08mfQuQb1j5vAoFOChgzSSBun\r\nmGv8SyW8YsoxpfrwgJ8umnfgR9nAIOJsVAreHn7rm2hfbRxsbV2pvhIftJWx\r\nEfdE7bJXOL6F+u4JH/KOm2mavfkRg+3KQUpwCFrq0DT5fc4CgpbpSqFcSwJT\r\nJZnazKdUc+j0zMjCR+WwHwBZoJjJPpS0ZNofgE5fT2J+y6spzUFpTiLvuV4T\r\nWELRKauYSUiG4Z4MtKc1m6FLslaSss5YIJx48XcjGfENujviXijs1nRrVxbI\r\npDMbLVKP/MHWC79s/SNW0AVC1Xs+qj0WjqU=\r\n=/c9e\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4737667f45335d1de687b51b0ae8ffafac184d3c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.223+4737667f4","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.223+4737667f4","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.223_1668298640014_0.09425287460946596","host":"s3://npm-registry-packages"}},"4.0.0-canary.224":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.224","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.224","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ce4e96d6e41aff2b76a4a63edfdcb4d4e9850da2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.224.tgz","fileCount":88,"integrity":"sha512-+E/sZVwdvDpaD0r27LhBriaOIsBx+cqwiVrBy6VEv2c5hqoJEZgLuAJy8Wv5YOTYsOEQggNfCrA65m/h75g3cg==","signatures":[{"sig":"MEYCIQDKy8KbTmljRQ1yHIHkFhndcEF6rRHZdukWYO+G8CY+PgIhAK+9YMzvsxwTCWVe1bWHUM6NkquE5YrYe2bK0AOGL/U2","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcFkFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr04A//SoaoJpeSzYktsp77lGUXbpEIM+Ci8z4wE1+guH4f8eknvOC+\r\nLkYka+nr1HTeLjk/U8dCz2VLRJLfNYXJCPo9EO2eky1oAMHIQbXElPs9cKF1\r\nvy+1IPUeUGMnAqb8aazLeLOqb8+U9tvsSqV+tTAVsZxeanDbPPtuYJIVXBtY\r\nhmc2fNpE0fCjCGI3M1vi+MepdbO4g7mFPFORmC1c3ZK2XhB9irdZm1gYZKba\r\niIjovsiiFnNsub89Qqa0ceJAlhOq/VhrKXntBR0L2MRUZ/Nzx0XTZHdlhqQv\r\nU0JS395u6/f7u9MsAPrDbBLvNwTPqPDP883/73Hhnqjh/Qs4AB/GyTqYLg0R\r\nTbu7iFSRfO+2VbKeB5qpuzELQksyQOJ4MWEQ/j8gOkvOkXMu+CJhmnPuRwfr\r\n9BgwszED3F6YLN+08cNvEdHUISQI22I60fa1MUV6qPdfqzad8c+GS48Ys+Ms\r\naVapr8dh00yuT8iCWWYuGSeD+cUMmx4K7Msydru4JTPOJA+GQByHnlcMGsoP\r\nXdCiL6rxs2QT4RH7vzHMm/gllj4Xapz/bsFeth6h5pN/IxpPxH0W6GEf8vsN\r\nvENVZDXt6pd/L+JrLiY5+A9ug3sL80LzwwHvGML6Lzy1md3IboQfQoeVsQg0\r\nX+8xUVi9cE4DkNC7DHsmBxtM96MXV1Qzuag=\r\n=5fTM\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c6bec27b4e51e2d214b28ec9d3bd25971d94d50e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.224+c6bec27b4","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.224+c6bec27b4","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.224_1668307205416_0.1761787201568803","host":"s3://npm-registry-packages"}},"4.0.0-canary.225":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.225","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.225","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"47b310826d500350b207ad25dd0362cc1cce3410","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.225.tgz","fileCount":88,"integrity":"sha512-cJJ85R4VpAM+Y2Q7GxnY/vZ2cHkJTcq9ZOgWXSQ0JDJ0eGsLYRaAtAf1GoAcO123MMEw8UPBvhz+ERvNkPUgfA==","signatures":[{"sig":"MEYCIQCDWnp8H7uUcF83abdLWmuXIPlsPqwjMSud7c2ML/8rsQIhAM1/0mlP8URo3EzY6UohLlDtS0nUDai6dm6I+nt0m+DT","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcIBRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq8hQ//Zro5wzHpmbnakScyYGr2Lx/OzFZIAXC4HAV+WoXcMVk+ZjGe\r\nfPZ+sF+jW3nO38jQ5Q0HhwmbauE7amzlPXSAZYWv3wCeXmo/qcX4oWGnDNNG\r\nkqHYVbKpyMl9HT6MPhvdK7oKJxB8/UrzKTC3L4Z5j05vk1pQd/14N8g40qDS\r\nSNqy8U0wU4F4iS4R1ws+dQ2rjX9Tec+DkvuMvu4I2FncNFyQbA6Hnt7RQSZD\r\nQhT2S7NWtSXJdliBmE7LrM3NHVATI3u7mHDMe+mBYd/nAjUy9b4/oOqLpIgK\r\nCfel5TXYKOGr/1w6nsFPn0OjFZpfdXeHpuLdqJBKdg/wILu47iEzrA2/xbGZ\r\nNXeB+QEuZ0gqw0+rKPfI/CWeDweeVVLvI3K4AiMALxnT46SKXwEbqXYa/G55\r\nyRsRJR3Av0vWOUBPSIhkv13zyGnCWW0qIrHdkyw1fErNktDbxGEGriTiLI/u\r\nO0+cRjadXTcNoxaJ8kDecibw8fNQ/67PdOvu+INHhr2UKc2XkcsYxOC/x8iU\r\nq5gzd5EUegZLWizo/7oFa7rGoK7/ccq69PMZBuYPoGj/1l3x00dC7zpMX7/w\r\n0KYMNVjlaCzzN70SJah9GHoV5aiPkHKrdLt83Xxv42J0hVK2FT7o2F569DW3\r\nb162BcM3hqya2l27QNzkDPThyBJcWcQzwaE=\r\n=dmrE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"88d8abc4a18a4f70131a8dc04364a49686318695","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.225+88d8abc4a","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.225+88d8abc4a","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.225_1668317264888_0.14802513371662984","host":"s3://npm-registry-packages"}},"4.0.0-canary.226":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.226","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.226","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fe8eda7382f1366c9bbe563a836dbc87101865f1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.226.tgz","fileCount":88,"integrity":"sha512-Gnm7mVdMVNqrWo2ewQkJzbobk2HgS+VLUp48qMjOapT8jqT7pGJLcO81PFt4xNjMyMp6gaoef+IDxKWL45+sOA==","signatures":[{"sig":"MEUCIFFzY3CtOOcnrX5bTMCdReT+IEvhXDC5uB3nR6LZLONhAiEA+2oNbyvGHFy7Pq1008PEF/auiiJS4ZjwIlaulL6W6L8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcKJIACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrsPRAAjcx0F83n2PE2K5ZarbPxq4Dj0JsQf6s9PMgq5Y5VG/q+ZFHU\r\nZ6ShTQV3Z326KxFbqbJtJvcrfNR7vrHIbTFzBncURNYEPLvRkXBZm2vZIbkY\r\nugK8ORM/nGJlkQw+KWUtPOLAeWartEgARRhsX5jyRG42HHTCDedwKrkZying\r\nUY3IRgUkmuT01gt1gqgtJ41aVrV597zgwi5lcklTrmivxbF+c6K+zyScqmAs\r\n20YSui9w9gyQzwk3+BqnCAQw/WBtEJ4C031Jdt2JMljgKZtzM5l7Rb2xn0n1\r\nf4B2jD7VThExhinuw+z+T9trCnBD42Gg/g3PnONPDNXodu0SAvBRPrmozYXW\r\nJW//CJN5W1zvgXa2EgpD956It9Q9aKdxYEtZDRvjbPxFhCtJNcti7DKrXLgi\r\nKYfvdTezGpUwhjQfpddqFjRFr0gLpWWzS/GUecZlSG348hvFqfR6Zfem73Az\r\nYOc6//iUje7CJrtSvLFZd4ClsphqCOYELbprfQIjmFpbbe5X1iwHADglsC22\r\nx2TZwWy4ft6HOYGeCzd/LsWFjrFlt4U0eZjItBcGI5AY/xrKN34Tge4oapaZ\r\n92hCr5LK/WsSQOXjEac/WWbvGjPUAnZWltq1ZSQ18Ep6V3b/GlAQFvv2z6ql\r\nmE93hSfCN5kQDxdKFirpjBVAsyyA8rW9y3s=\r\n=HPit\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"36f33a73e47bb1c29cd76572b531be04cbb4a974","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.226+36f33a73e","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.226+36f33a73e","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.226_1668325959921_0.23274682259050405","host":"s3://npm-registry-packages"}},"4.0.0-canary.227":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.227","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.227","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"82a17e97062b76e6df75e4a59f380cdfcaac4046","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.227.tgz","fileCount":88,"integrity":"sha512-k8zb9DJbwQ4Y9xM+g6aPlt14WPdmwT7eoU8fGxAGlJOfxTTaO8GXxbePpxKCKxITXx2Z9CM7bJ8fuJOx9LFLAA==","signatures":[{"sig":"MEYCIQD2JMyxlDeFMXbCS1Cos5mLSYT2mMydLz4Zjj37UG+nqgIhAI1OxfUtTCKmkXVQIk8FvPo+4mAjPhezwp20dMdfkMXr","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcLtsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoWlw/+Lh4zJ5+peKJVKYuADtnxnEvEJcP5FxNdjLe9VwS+ofBIFyCW\r\niQc5SVeLR4QPu0K/UvO+S0CXPI1FQoXTODfs5aC9dXqquKJoW4I4VmvG4qgj\r\nHXzqPp0IAVeYqax9TLpyuplePug0dKy3uxJy6JScq+XQQjzKQqKc2sFuMnIE\r\nf6hwl7FuVzzpg+A3kFvFOmB8I7iRSLLRlDM2PmBurZt6OO2yZa6DFqi7muP8\r\n7GGzPGi9wWSrGc4jw0nz6fBgm/P7x1rBAX0XgrPPJbbBAlB1uo1p0aRrOhwe\r\nm6/jQOZeanfL7KxtjEg+MGsF4RE6hxUz8ZVzVglOw8AVS5XoEsDS0plnxtkv\r\n4QYHtcfJXafmtVhEPrzATszb8aV5xdITBinnpsJRL4cbeJpT/T8SyMJAnSAY\r\nnbEkxOd5tuTEMl2bZP0WC46Zo4GDXyk0e5XYJfGCkEpz06osC0t4eqlrmXlv\r\ngZmYv/em0ITE7halsUhDPJa9Gs3HlofsdCSXlLcApVeOlltLELnX8JdKMU1a\r\nRvQBGetqoDe3xzdPVFbclR80s+M+ACdHRNpuUodraqmkM7HSwO8yLI1THY1D\r\nrgai9EBY64Xd/M12Q/OnbFA827BbthV1UoUevBn2hnfti2nZ7a0/fhX4j3Ik\r\nI7Ndavus7Vr5atxOfSdB6WHoVckQszdT7gE=\r\n=tQCV\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"80b207b886595931000b1bf127fff5fbcfd4edd3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.227+80b207b88","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.227+80b207b88","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.227_1668332396471_0.05508104338389064","host":"s3://npm-registry-packages"}},"4.0.0-canary.229":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.229","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.229","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"99748fd32da4a01d3edb5c7f1cc66f20e02afd29","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.229.tgz","fileCount":88,"integrity":"sha512-ooZQ1v967TpKbvjQbiflfamntUJdEBO/zlH0mn2bKMsQAFOeoG+lSTUVIGuKDEz/oLNroyowHjhOTFUi/t8h4g==","signatures":[{"sig":"MEYCIQC4vwZXXxLSzn8RW/PpgBWQZw/RoRuhPxIUk+NVYfECGAIhAOJ2DxrkneYIFIDi+5IkKkeN/3/ntdeim5DEepZJUMSm","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjcQGdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqxGg//ThxqN2EDiWGuZE0eanI6lK8JNgFAYfSVP2dsQGwoO5vNKgo6\r\niGaheLu5HNeQYwgaPtVlgAkwPvS8MzlQoRK+taVxVvVwagxcklWi8mqOcT4+\r\n4/RJmcLX7pJelaUuVZE5L6p3J2my5FIB1gcNk3jBdUGMnK4NwojdcdCrFH/Q\r\n0ewkC4sXwoHST+VEXwAYhL4sIxx0l948m6zFWJLSPnwL1240ULz1SERBhVx1\r\nkUhzHii9fOXrwaRRDFT0t5Qj44PQuHc5S+8DH9utbRN6C6rCauTdFUlW8Hm+\r\nJriTtdHOEqaHCanvtWYvZOBdEMxM66WETNuqKowH4cTOzTEkYkbgRbEeHQpU\r\nbIKyF5zJGphXRH3cZqP2C79fAoL3a7Rklim+12LDRwcVgZGJFbzpQlKmq5P+\r\niKjdaKWrX9YU9sCNPAjRghWn95TCIWDnjqzoByM8NAMrVqha9e164OaruFBl\r\nHEgiLDUAUfeDLImQLS2uQwqIQG9mqVJXyQImH0z1PRvq3ogrtVx5vwLrZSTA\r\ndUGJ3NJCjIty+jbCwUcF42wJ3OE0Wz/DtWljUF3EJsa02z6eOG8XM5apH0YY\r\nScJ1RE7FaeWwPWwg05kA1T4LLQ63P2q4XRkRygyKb8LnSe+/cIUJTqswm/kM\r\nCedS2tWqaM/kmhzV/OSqgUpv3CiFQ0NRau4=\r\n=G5hp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"61ec0fe65985b41e880020a656d7ef7aa88ebaf5","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.229+61ec0fe65","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.229+61ec0fe65","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.229_1668350365433_0.39552405527794554","host":"s3://npm-registry-packages"}},"4.0.0-canary.230":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.230","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.230","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cd66c27c966bd1e5e7c9a2bf0c9282a4c26df187","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.230.tgz","fileCount":88,"integrity":"sha512-7UxVyWKUc6rbxfbiu7WdxY7MlkUlfuqmcu4XkkyMFYsRIRivCy70lrNE/4ytL2gQKlYF+dTaJPngCvni1RCWDA==","signatures":[{"sig":"MEMCID0iS8Z+K1zgmtFSkg9R88+WgcfckyOnPKfnUA9mXyWyAh8MzuRYdMxjNbPXRxwaNwhLOnGNF1i+PJzcQ7DivtzS","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjc0HcACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqrbxAAnqTMQu5ZctZ7FSXQUcSatiPhe9jn1vtL/klVYWnnWplAu5PL\r\n98whAubyJec5sZhrV1AFNdKZwMX/DZeqKqDXsyBqBQ/2hPEjhYhp5UjXUPUX\r\n0hOyvHR2RWc18d6FJgW9AgvDtn0K8BlTk+ZJJbcn5suJKQqgOdrXV71camzX\r\njpBUFvFl500tafASKIcSfsc86aMFIDPK58pKiWAIekjS3rK8Wh9J8p6Sw4AH\r\nKP7XfnVR5TvOdvV0Wh6G5X37fDEJrSl/OIRg08fd5FREvrU3haGxHgKOBFNH\r\nI2c8wbh1NiMUz79kKqjip91QxxnsrhlaDmAOy+CKjEvOETZ3Wn+BI3l9SOmV\r\nqrOa89J1+GXW6XRtvQEdotWK3gtmDfXAkQOfmpIJcXHiskSyn2ys/H53Y05d\r\ntwvlmPkhcB6dp8gPVe5Ny9zwWpzcQwhULuB3oWjjQglPUvagMXKwW8hV29N8\r\npNH3y72oyoHu+TbA4R5FpJXpdYKg99LT+EnZ28YXHYiwoRchYgyTRGEGaUlb\r\n6wYbob62BpwjpjJdJPg/HBNdrauVJEiL3O4rPqw8s5acxhViLKPgtAIYAOL9\r\nvxazlLcYiGNCqt3qxJFcp8L7ImmntVjvdCkFewoK2VRdOW3ZEb5BF3q6RyDX\r\nWhnOpnGs7HsYOxl1w+erW9d8ouV5WIjn5pI=\r\n=XyBe\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fd8229c550864f11c8140b8f8cb43f8d609ebd52","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.230+fd8229c55","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.230+fd8229c55","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.230_1668497884152_0.5584273156898523","host":"s3://npm-registry-packages"}},"4.0.0-canary.231":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.231","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.231","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"29ac2ac7a6060a10af0de23364746752daf95775","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.231.tgz","fileCount":88,"integrity":"sha512-5OmjkfDIbrannOePZTRMFVMFUvXYJHg7ideHPUm7YeOAZPTJuMWJ/cEvWqRBU3vFYysQs4y7NjM5xBZeqHlVVA==","signatures":[{"sig":"MEUCIQDsJ/kD6cfl4QfpsC0GCGKTiPNXyLhZhZoNWFvEk6idRAIgMn0uZUqVDcHb+TeHFmXP8hJos/+EiQo1qIPaT1n/rxY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdS7gACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpa5w/9EU2nkJs5z2PHfkuL5By71vAD2gWBt/FZwlep3bh2Bf97/L+s\r\nysgH8GmCw6ufv9HqB/jbzed+CTlllK5AFUuV91xlu4Dmvc02gSV2AIjTxr47\r\nD3Kzf/BRo0RRUvajmq2IwmHZi+oJ04CJM621gE3Bo43+o4a4Y8eRn/ul3ozY\r\ngEM6ZkVDSyGfvFr5s8t/qD3CRNUDg1JELppZ7QIAwdB4cfJdtKcFprySk7Lg\r\nCJDPyWkIX8M0UiXsr2yEokVfkNw+0bmtxcnvo1cNLfBPBgOqdQDkhQVOARU8\r\nOp3/i7SqeghOkihGdQ/19Og4J0XEJzxnosypVwlYFl9Fuv50ZwnPcXWWlm9t\r\nKmLnQfgti5umhKseJrCYP/A3hEjjFwHqAqvalufB5z+Cp9/cW2/lgJ6kaX3E\r\nWQ0e80gpT61Efug+V7NnN6sMM7bpkFJQ33Pa/mtHz4uNSlqTLiFrseGWQlO0\r\nC4iJxGIYgQf/8dmAsXHcY3ExXngd4NM0MlqWYoQ3EX6DVTbvp85QxQTm6J5T\r\npDM1xtbKfRUNhSiD7ZZBaxhO7Cm7QIjEgLJHi1QUp6cPPYrQR4A69km6K1D5\r\nyeHpRx0awKzOuKRBBnEGD9gKv8RBAG6PvIOB28ZPeK5O8q+a6mDUxdZnqj+C\r\n0AJ8vll+sX0p6fdyzueVWhKOtiWdh3tNFzY=\r\n=0Dn4\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"97c36e1de6ed3579056aedaf6c0076fdff550c4a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.231+97c36e1de","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.231+97c36e1de","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.231_1668624096259_0.8425076516565788","host":"s3://npm-registry-packages"}},"4.0.0-canary.232":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.232","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.232","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8114786f194c91ecef4f8554af2509aa109b5915","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.232.tgz","fileCount":88,"integrity":"sha512-Jyien9vwsuU8EHTvn96VsYZtBiD0xS/dwn9YxsC2du5apOylR8LFBdeMd8oB6Aw0zGBjpK6CrDJGIYNuMgl/6A==","signatures":[{"sig":"MEYCIQDGeqiBpBdjfYTIVMhIDges4N6cBD3Cg6NC3PIbfdX8OQIhAPUAoEneYpWvb5DgeYj2nnigUFUA0LvqUz9cgIQgiVkJ","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdXV6ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmomHg//fBamSNqjf7YEvvq7KnGSLZZihfp+vc/5CXSuLnzL71XtP0Hi\r\ny/v5rWyF3Vg1KrQjK2tkMLxZ4uxxdl6Hgom6xCmLsQ5adwbyeAsEi7NYA7l6\r\nBhmOxqVY8QeZsfncvShCFHEIxnk1xv0FN5+9r55D6KwQSyBmzLPlVr2ahv2r\r\nTOLCuqPbVJWi5iWx71QqZui15lEsvanJMgXKJ8FZGLbQ5WKTTucO6rnXM7c/\r\ne+fkh3826tGDkO/Kx1Fj0zCeuK1XXXlBG/PAqPn4+HZoXLJRBTcQN7KtAmZm\r\nd7yx3xrc1oLkmpR9lmHo1lFyQCkpVS76dpTOULgMx7PRNUM5B+K/HKsgqida\r\niQjkYjrHKXOtpT49hOUpRllTpi8uOu9c5oT8o4L9IlvCAzaWbjU817iml39M\r\na301ciqcw3E84uJFIVtr94VIFXpzlGwwLZG+uP0j8MNfC6vs/wKMRYipjRGl\r\n0ChfoTjIdUwjvKd1pxd81Mmmt5Bk8srrZaAYXkdCAKXrChw4M4mFzUNf1I6M\r\nKQhggLwvzw2+qWi6XIA4umMYXb7ocM53R65iPvv7J4aQ466YtW6VxrjMcMwk\r\nFNBOpEMYwLgrIIDQJZqknZR720z5wCiyTVx4rMpeqDOqbCpqlzP0Sks1Y1Uw\r\nXyp5c3YdDwwFMSjP2TV7ByPgnhQURj8DKww=\r\n=NQv6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"da8710fe030f9c517524fd88f304e734298aa56b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.232+da8710fe0","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.232+da8710fe0","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.232_1668642170647_0.4517157713873696","host":"s3://npm-registry-packages"}},"4.0.0-canary.233":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.233","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.233","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b0ae801fb5d80f3eb160a6066338621bb5da12f5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.233.tgz","fileCount":88,"integrity":"sha512-0U2tJ4RAvnLqdzk0JJY48VcLh0YYjEg3GMsVBAXLY1acPl9P8LIMukLX1K7kZhnEqOyOU76jyvszKhVrOuDWpA==","signatures":[{"sig":"MEUCIQDvKOYMvcAtDlLOcbDDepD8fpxKQzoMLtO2+eFwSdYrQAIgEkpBx+GZYuIUP77FCVdyMMwqTQOrJduil7SP2NBMHgw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjdoioACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo7rg//TEdr4pSIGT8h6egWoitiYNz+GeTWMsuGWMUBofS9vcZkspMd\r\n3dr4gP+TnQVMwrrudgWQRPwQyw/dD69QVbIxPwUaR5jZdzEtF9Uxrs84Hzlt\r\nLt2Ap35bhvmuI8HJx6vhp+b9mpEZpNI7hR0lhIeVUM5V2lwGfnLevfqVC6Gv\r\n5OEf9F03LG/lcurZQbbqfvold5lhyNJgh/9+AMiWpNyxAjWjktj37QFFN72H\r\nI37lhgF9VO4HgTFKdF9y15/PyRfxXQ3xgYxF/tQmdlY3LkLpTfaikDZEe3rK\r\n9d669CPfVkTCilzoCUrlYoF/Xp8HSAhlhKeH/ZlQE/43Did5j3rSoIy4BQ+O\r\n+EC07TZazUqJ0encNoMGypDsbq7dmdg6g0ANmiV2HI/aiMLGJqVq2rOqYKwA\r\n4u+qCdXADekQKkk0PnwXYWEU6DcGovCtdZS/XqXr0Rnzxzpl0b8a90YZLTvZ\r\naULf1Q8Am6XmdDTaoV02OUsSe1/opKzfkxMhQ04WNHd2MIV1uR3AOPMAJKTc\r\nJjBn2hlc6qax31e9J8d5WAGmAzoGHUvoZFyvpdEkdMH4+YJ81rgJpZlZNVmd\r\ntb0sxTww2f3Cw+rVrWtsK0PWGOZThxHq3Ub/Zi9WqAmUdEZR+RPJsZUsBXq3\r\nLFzRetKGPjbDo8wdu8vXK8BSM3dM3r2sT2I=\r\n=GFX1\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5c46d7812ff415f1ad30838ba8ffc01ccb253bbf","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.233+5c46d7812","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.233+5c46d7812","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.233_1668712616421_0.6627235758499739","host":"s3://npm-registry-packages"}},"4.0.0-canary.234":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.234","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.234","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bb394b4cce8801694da540d87d71efc89a7f4f3d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.234.tgz","fileCount":88,"integrity":"sha512-cKHo3PmYT0VwtQX91M58I9xf3PNGjcIcO6xdgs4r5Jk7lm3eiDlH5kTTAGRwDb8HzO5yEKNA/VaD0tNScV0LWw==","signatures":[{"sig":"MEUCIGjnVhu3Y0j5Doawg8SEKWQe1hZ4eEWozAKGoFPVWQlwAiEAx0wRyeVXpHQg1S3P88WKZWoXGuGxxBbjP5wgZzYQgvE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjeD8OACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoGfg/5AU/BnMstB78znp1Ab+87tRLVe4y6PUz6TqlJmUomNGt5oOSs\r\nqdw3ilg3QAIgNQ6738u/HgoTsLwlW6tnMQMpN6dWwMxT8XG6DqSuXAaNU/m5\r\nssIbOyFyVktJo+YzH3/1vdbr7xe9K3RlI2VKw8EFjEgztoPDAcmsQ702SbMn\r\nmvg5U902udsYMAh3HiYAo7qTEo7OnA/sSub6QPYw/n6mdS8sAHTyGYxSn1Jq\r\nbGzo15//+6BLxYhzIKo+qNq3tiFer2YAD7XCVPD30hkSNhmMpkuzEg5kVvib\r\nfdI9uQLFlJImCw3aRA13AGcDQKD8NNghneWjIj5vrdicOjCnbpiY+3yVr1YT\r\nSjNQuH7cnB1VJbTuLmn4vhonQDx+3ouOivHOiD+m1tZoVMDlCHCm7NeIUgs9\r\nUFdL+F7i9is79SkLGvxs8slDOxyEE7Cu8QyQ2iRXHKBSLP+gyJoJqijVZ9Z+\r\nRnCmQyd8Fm5BPnKP2DEvCrElge0D58MVZmmyg9dt1RRNA9JiqXeIgOFMfj4S\r\nN+eaye/zJ8uiKDVPil1xVVcg/x/8UWfg2v+ddQCKZjIsKmzpneAT8rcXh6xD\r\nS0y2pIFrku6vRf0fFXTB+RVbcEYCHbl4yciIbGIuoHiBypsWgkPja7V+YgWf\r\nZtmAnEhA56JtRyn9iuFVuHrLIBnOq9/zaMw=\r\n=9B5C\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"5b772cbf4b002297428127ad804631fd0c62386e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.234+5b772cbf4","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.234+5b772cbf4","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.234_1668824846238_0.5929446680546662","host":"s3://npm-registry-packages"}},"4.0.0-canary.235":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.235","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.235","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"e17f4a664c59d1aabbb399206721b3366ae75a71","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.235.tgz","fileCount":88,"integrity":"sha512-bN01Aq+C++zKGDzK1C69dRjd2H1VNXcZa2XsxDu31JZK0YhKq9P5IBM7/kgk14BevspHQUNiV01ugZtHTIrjmQ==","signatures":[{"sig":"MEYCIQC4WwC2KgrZ3pKOgJr8dL21CpVEm84n3pt585Oz0csc3wIhALjGxXw84Crpc/CGtCWAqiUDsbH0SQVhRmix4Uyyt08m","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjeXKLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr3Hg/+LTH5HNRxewq/Z9Lrmr2Eic7g0KsCG80qEJAO/Gvg/4bZI7nO\r\nKGjGjuQHx9SO3R8PkqptEuXLpRfYUrIk0k3O3jIviQtk/xFw/j9kZsvDoYFm\r\nTfnwbpkBEchXlO3dm7WsuVyrdrUq1FnZp/UPMduTjQCgXo2m21ivR7EwRolk\r\nLPVfc9zKj+UmoXZOSLj8V7lok8If2L0c+O8TJcqnl3whNqoFs6zH/RybodYH\r\nelnOC3+c014wWJXi66vxnKSsc36OBUEYJ51vSCfb+ZjjBXerBiMhjWwbT4Uo\r\nLMI/HXLGtygAYw9gw/vtm/lJevPDfYCWk14S0PHIogr2pT7fZNpBvG/uaL+h\r\n9KdHCu97ebrn1tZudfSVamZEOjitSa+504E6D1fKFbf8FEZX011/l7OulOKo\r\nL7zULwhxvAvH3a4EA5ZLy0p3gDD4387pFPvh6/cxlVICKRxLLO7lAagzYcJP\r\n1vvbYB1UMIa03iWk0KpTTRdwFu02I/CXdJw6s4uXoimLgmOu0kp99r8sYpcA\r\nc+Zhk9cbk8TtNXjmOQ1QLHvxrMYLkRynJ/bvzvMx13GP38pibHWWIIeLjkI9\r\nD4kd2i0ObbuT/PZFK9nMQCn+j+hlePKXAE/DmAVUZuzf5qrpgUY8dDwJxNzm\r\ncU+bsYrTfVqDifkBahq/LmZwJP9tMkrZzM0=\r\n=E6mB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2bc3a544167538da5c12e66902f6a385f4a374d4","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.235+2bc3a5441","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.235+2bc3a5441","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.235_1668903563325_0.31157113797556435","host":"s3://npm-registry-packages"}},"4.0.0-canary.236":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.236","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.236","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4d5984a8ea0900e2e10ae866d4cd091df8f00ebb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.236.tgz","fileCount":88,"integrity":"sha512-N7ZJn/QnCVJYLePkUE6V+vPFQigL7CfdO96+HIqk9cYAN3L53Ij7TdvQrprQ4PmMJJP5ZKZyTko/clW03GnxnQ==","signatures":[{"sig":"MEQCIBIh5nP3d3iEFGf/NGjhUJReK7qvntwLZ1o8/I11ItBiAiBk4+wIpmmIBe0QccUJLuRo3k/jiAeC4IO4/9s9pGqBBA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje7uCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo4EQ/+Jr5CQ3NE5HLGvJg1xItWWtwQWmJSvYoUCQU0d1f0bbHCJrZk\r\nzxB3VuvunIE6/yR7P2ZTCvgFm5kZpVl1vkZHu3r6z5IbsbM3YY0gC1exntbT\r\nnCkhLzMMgeyt3wijIHYR4h14zU1uLpmbKE2kv7XHJmkybZCE7epvUjUoRTzh\r\ngIg/SU0EXay2DUIUxwp6PEBeDRsgVoAeIKO6i36vOakZY7PQCKTKlRHyrILH\r\nGTuR0Z11pZD/tjwo+B5fMLIgzvsy0nwOBkUmQiSnz/kpTAqZdKU717pgPZ2q\r\nIBCCskDuc2bOxTQRbKs8SAg1M915Wc2a0jIzKOJnc6KOOMAbZWl++f7VRKWW\r\n6lZMUtaVYK7bvhJ85qvooLVApeipZ5BkZW/7pePa6zvMg+XkOxGfFRexTsMH\r\n1dltbIGirE5r0modQdIHNarA1BOHPR7cBq/+iKEJKRhhxzO5m9IVSPjm4GHO\r\nYFJeml73hmMsfITUR1ASNqWdNukp6lhOaf1eWlI6qNqQU2FAtiaD7Fh/i5Oz\r\nklzJkmrqetNwDzhQx31egC2KMOWvLeabq+h5jEM/4pciP+oTL8YbszrcKVTA\r\nOz6l0SXsR6ZPzDerpulmxfkEtnGM+VEZWnFvrtCdrJvNgtcoTkFoCP08i35D\r\nNw+lp1KuXCbmaYiaPK5Ue6KM/7sfr+lfBTA=\r\n=sN70\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2e4e4e136ffa40d913c629dd392996233c6008c0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.236+2e4e4e136","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.236+2e4e4e136","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.236_1669053314711_0.7230018346473026","host":"s3://npm-registry-packages"}},"4.0.0-canary.237":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.237","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.237","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"93a5f659e963a0aee9464bbc11508853426c6d55","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.237.tgz","fileCount":88,"integrity":"sha512-TMO82HyDebyLqbAe0Tg5kkOra7VmS2U36cXhYrFCcqFQL9IftGlB/8Zwg+hUPh8NlYah/UdsL2iqr/ZhbOBM2g==","signatures":[{"sig":"MEYCIQDPz5s080kzjbbJdhFekYWE2amBzfH5o68PgebgZ1HRiAIhAIBe0IfpxACAnSgS4NzF0qLDBYSnbVJlS+qQ/6Owpymv","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje8dmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr4oQ//ciY8rBh1lESJa4oNEu0QxGeGXoX1SMf98zkg4hiQRXaqpU4r\r\nB43kD/I3iRx5lQe5O+3gCYFCtVNgcbO9avWlpjRNAXU9NrL4mw/ZK+qORM1S\r\nxD1KBM+geM3G1DJVr44wW35KMTw+uffstl+h7Y8681dvN4ubdm7Olskx3aIz\r\nq4uGF1gs5cfL4J1/Fk1IjSvRE+JuaduAuhHPZnHnTVYNqCo1O9HZDPeTQB56\r\nUjxzacr9opiS982fI1l3JiynVOypvHeDAM6E5vY/gu+jgyyPv0+i4QEjcx/9\r\nWufXquFv+1B46uLLHnN6omoXOl9GSo86V0Ew1YN5aghVAfanfZ5XjTiSjKde\r\nBKzwBCzowbHOymcW8C7L2QlMosNdF4N8D4n8MA/MtKaR8mg/AomENAxJdHXX\r\nYaJ2nk29XRUBAh0tzaP5t60/ApXITGE14fSVQ6qHUjKquzCZFyZ8cC5qltW7\r\njXKkrtBY0LyML8zRySfVgor3U2jfWgbfoBrWlYDdNufzBEcT2md9YoDc14fL\r\n3FbKCtpp6g0fvx6xDiUHl1OuDOm+JcjZ83Lj2yoP1wnAyRdv0xmyps8dcuAn\r\n0oMH+SHjQXQ9owupLbMPOCIGsVivebbbOtOIDPrXZBP18vLMB7UGZQ4r9cJ/\r\nzgGI+1/0sPpSw5hCIqkla5TZ0SlSRK1FfMI=\r\n=w4hD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4e0960a81f1b73c7055e7ee8e9b1666829df44a8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.0","@redwoodjs/auth":"^4.0.0-canary.237+4e0960a81","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.237+4e0960a81","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.237_1669056358349_0.7628298698931446","host":"s3://npm-registry-packages"}},"4.0.0-canary.238":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.238","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.238","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"943075dd5632266c1a54ed7a113470661add09e2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.238.tgz","fileCount":88,"integrity":"sha512-13fmBm36tVDxXEmY8/KwMWo/TL29WYwCBoCGVZV2YcIYjpH9BW65isQhIC29Z9yoLWRtVjIRvKF/WDQazl+7yQ==","signatures":[{"sig":"MEUCIFLHrcH/E4C6q53rgAkYyPljk0/YyxmPIRtkes22DiUxAiEA2ZQu3b6WwsjzGhrPv09qHILe3mH6xU75ocJvrjOD9sg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje8eiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo6nw/+OFcezgFxyva3mJX3r/UrP4aALsZKLrjrrJwWY8bXU1Cxe4LD\r\nVfja0Ujh+O+CULXBPOKXsXp/jZnjR1LQBIFcwwh/j2RROfSwz0me47mkO1+A\r\nL+PMM71FmGqFCIyphwL1R7YJu9jYZgC2x4UlINFC6/n8cd9mw5Fr4bm5zhFj\r\nrLk5Rg2puR2+FTQ2yowSB82ygN6jeiUGWu99dDundT1kvZuiJZx3jR7InCdT\r\ncCbZHv+7okSeQnUucGWHeQfaSQOxJw+5oskoZZwwXDbsINCebMvbmmCnbJTL\r\nhMQSw40lDQyssKpJNYo8rjO7SvXIwq3nnvCOlvmSPQPhl+kl0MbwK8cKsFYp\r\n04qTYKwKxa2xpO70DADHwI+9CGhqqvSPV2pqD0bv4rXYXuUdp9kvb8c/iP/Q\r\naz8+HPjbcLsD16uO5lRcghkThZVgka5PmBeKiOVEqP56vyWmMyc1Uav/7asq\r\np7DrniN0UQq4fRTIQgzGvdfAZhoCY24dbh7Y+W8Kb0japJhJbtM6LBRLUpcL\r\ncmpSHAFd7Oynb6k1nwXz5KSnradWTp75K1XhjkShZNbUIn+z/oz9MOiqumAs\r\nlRjupAEI6iX+XRvlfHa9iCNtjrIgNL9os9h/441RJxB9pHKKoqxBw4tsXzwS\r\nSia1iAoq5DULFYlfkOub8bSf+gCfU61yS6I=\r\n=bb6d\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e607f1e030b13e2a085742aaf06f41afb1b445af","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.238+e607f1e03","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.238+e607f1e03","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.238_1669056417944_0.34946764932577334","host":"s3://npm-registry-packages"}},"4.0.0-canary.239":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.239","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.239","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8110bc17e3a9afa4725b6503cff19e95ba2c39a2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.239.tgz","fileCount":88,"integrity":"sha512-wBzGPxdbBw9GMtajZj+1Cpk67EG/Zl1+kesUAOrcv89ywly0sNtUc2Ow/rcRTw7ILvOJK1fI/47EiITmJlhgDA==","signatures":[{"sig":"MEQCIHIUPTpfEcA19tkuSAytLO2ZLI5fyPxTX5ZqqcznokEDAiAnAuUdKibKryO067HHABkgPIq/2j6GdiQYQcBYQbRgxg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje9AyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqJixAAmvKBkKPU1jwYHMCVE0CNoxglmE9U2IIWEXNT9fPwgXC4hWG0\r\naYsBhIFOPvyU9guZePoHiw539sL6ez1o/5YUbw1Qs5TvYNqb62uaS5sUugS1\r\nzQ5HJLD3jWza7nVler/2xyQ8b6ls8oRTNk+ZZuQ6xO1elKKo/9PpokyVK+b5\r\nXyNuTgY2plBjKFcyFC9ZhUBJqPoeSsMzmFwsJQrwrD7mMEbN1mblroSYJwmk\r\n2gv4MgxG6/O4kbpcVDX38lBvkQ5lVW2EWbSTB1sSwYmoGGUeuKKk7DL6soX1\r\nNs4h/oHA/S+kK7QKbsVsPo3VmGCqMIT3FjA5jnc75O9yQ3+lP50AeGf3Qn84\r\nI+mpA7pF8zc/rPdxdSERnJZkmmHa21UrzEyEbPkyCfZn/4qo7dHPTiNARTje\r\nryEXE/eRZwDYzuN2ZaEae7MvqtVuiQ5vnRqn4VNYiozr6vAprnscP5g7PhNh\r\nk73SaDt2Ed1/xStJLLCu8TqcoRdmU+BeboQxIq2nY4CF8+pCsyB4/1C0Caqm\r\nNK6BIbzt+BBDaSNaLeia/2gti6yZ0rcqZzbvmv4B2jWfEl7rRIUd5N1qQNmN\r\n5dtM+S7j1TvgDoWfyDwYvX/h0EtK0x16hIX9pBh2hWRn5bF7ypQtE6LsbEWU\r\nNTHS9q5sKyDCAAI+m4ik5cVq2MV3xOFkclo=\r\n=CcyI\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8f9cbd7e1f3a7db5463a1b809ce799a5f8dbcbb3","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.239+8f9cbd7e1","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.239+8f9cbd7e1","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.239_1669058610030_0.8800241039379189","host":"s3://npm-registry-packages"}},"4.0.0-canary.240":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.240","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.240","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ba5be7c881a800121a3888d77f0e34f7bf7d6e34","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.240.tgz","fileCount":88,"integrity":"sha512-BIcFzhmdHkbocIQAXAjzd2AKzG82xK8tLoNHf1UqMNauCYPz2ycgMWNvtGxaXoDpZSvg1nRi6zQ+uDRktJoWQw==","signatures":[{"sig":"MEUCIHvMlkjzpnst8U2hnDLw3juuwVnCmlFH+Z85QwrxuhEWAiEA5SItohy2sFU/Pa7C/ItxD6D2Slf6VXXOED9J90ngsQE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJje/qCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpGiA/+LZceqAZnL7KxU3OGqbN7+zXIOwicMRCzqkokXsqriwLtqOBa\r\n5DgnxkFWill7U+y6BMLksHaVBa00I5Lqnftxs1gjD7yZJF6CdZzDr8dspY8j\r\nrXAJtq0vLduyVlngWJA3oOSfq2/d9wflLlL/pi3xLEdHuWep+ZbN03SmyTu7\r\nyy4Vwxp0EKAlPHliIWLlCR18OhTr5Zkz+kzXGF2oQsT2h6L9jZ7Z494nJsRp\r\nMXUILXzTwjg16uvBXEStgVmUj46ahgO1cl3K7fq7OtjwgeAp6BbCP4T37GTw\r\nJ5HeMO4Sz/U+akJi9ju+xKyEzTd4kMpgyOLKroA5f34eRvHXXR2sdaHnxdM8\r\nHaF1NT7xrJwg5jIdFkW9pTKG3SAwGJb8VlhxyfUsNnc+ntqXtmiqczilhOpO\r\nbFTaK7c8T2BIeLrpN5Z1I+xE9FcdvvZfcV6GrJck384DLSdjW/ug5PcBIYxH\r\ni674/d3FhTJcoW5Sg/STTNLXAXWsWhLPsdwQOIYVGdr6HgmVBheK63ZHgPjt\r\nvfPyugA7tqP9IcYAJqfiYeSNsZ+6P9UtRQuA6YHhWIuh9jIfiC1qI9CVhfdX\r\nqzsiXLwz6+lkx9z3cdtyBXsfcYlvAu7O82Bfp4B4kKPRh5lJzYveCbhm1ZJK\r\nMZrnpOFKwILFLKs8WC/s9gEIjrT1uqdQmBY=\r\n=NjBv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f4533a8c65db36a7a697b2c9c1192823fe4ed04d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.240+f4533a8c6","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.240+f4533a8c6","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.240_1669069441967_0.3305656507815622","host":"s3://npm-registry-packages"}},"4.0.0-canary.241":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.241","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.241","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ed2c0cdb7346767d5a681cdacbccc570074cb03f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.241.tgz","fileCount":88,"integrity":"sha512-cfMlbxKvmC2y22vDI9z/6iIkkRrSARHMby4LFMny3LiotK4ieqA32konnxSmWf0V8EA8ktyObSZCfBjjztMezg==","signatures":[{"sig":"MEQCIEgI3aTA4i1f86h2G7UdkxAByqbPBwRqBwfkGd5A+uZ/AiAsgAIjU3GMBP1IXZF8fqYh9TCTDeVsv8QysRk8RH5Yrw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfAjUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrcfw//UumbK6gJM9wfEyn0Wy7aTGJn9e7CCnWjYgCIQKd1j+EwU10Y\r\nC7p/D5hk+aIaVJCDk9nZXhc9dB7RQ7qbCUfhduWP/e8Ge/AE+UKNgHNjazrv\r\n/Hp5PrtaBS5C9ZxFaF2qGDyXefL0Ttqzb0GrALmndhVqGldcwfglPvgv4ByU\r\nGEDkIDA4YCnyrl9TWrJoeoM91LfhTY1bd3Vnl6eHInK77aQVqN9Vt/JbNh63\r\nnr18vfP8UFuME46igGV11gK+gnSzOH/9ojMZV/tnapUycgtN1auv3t3mXRO7\r\n5HHHZD0E8olnLwDU0l9fNZ8QD7RY43OK3xlnCNz7JZrrNJjaBnPlZDTIeTk3\r\n22ZHf6Gya6JnWEP5Wx4EcTp3RQkn2sYbqZlNKV2elcs3LmP+5cktysfFkgfn\r\nuVV0g3nhOA+th3b8SHv5HZNTYhxb023TNbvqxTZNuldrxvbSk3/OwAIH0PJ2\r\nAEbKWRcGQOd4MIVMWudLY+X6xEwwCuNjqVmoJ428Y0/EPdiW9FdsyDql1Zp9\r\n3y4pIeb3oZj67P/Nr9hKM+krrA5aPkLAI+LiD4/KeO7odaK/pFZAS1JJw3w5\r\nTMRpqAACRXQwFJJBbEYKfs31zBWf8fuGSVABKuLBMjunCyD3ExiBiSmQTS26\r\nFyoiHje/gwQdGIhySGPdyIO8/D0csIK4PKQ=\r\n=OTUN\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"7e5d60af9f0fb2fa297503e94cda9f3c02dde944","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.241+7e5d60af9","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.241+7e5d60af9","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.241_1669073108214_0.9677083159417539","host":"s3://npm-registry-packages"}},"4.0.0-canary.242":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.242","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.242","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"af38031da640ac43281ab212c7443285d6c6437a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.242.tgz","fileCount":88,"integrity":"sha512-/q/UlNduV19nTZI1MezXxic6AFAs5wKy9+pUCNNI3ppcRiViH45xYHi/c/i93jv1T5lRjlhKT+bC3y1wfRhCGw==","signatures":[{"sig":"MEYCIQCoy9/3uItbYwx6a7B8nr0ti6byfhjArk9ySlc5nOoRvQIhAK26zDQ/ECqycmnEh/iBjcbUZzNcNzyXMnifVqh8Q7zw","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfEzLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmopjQ//YUMUYc7yq9S31he0o40nRvsiBFlyU0PoKp6pN0CZdIJBIZp0\r\nsahhiVrtFEpc0Ij3XCi4PkD1w4VBWcjw/e6wmEMs9cWOyXIT49UF2E2YyfJV\r\nG50pU8EWVo+xfdz2wHdEf5/wyjybW+RKFkI4wnIyPVa5ByJv6GqdgG4posbZ\r\nQS4Ifx1U7IdAMEJGVokewo4mModtImrND96SZlcHay4JZq+q6VnL52QGm9Ia\r\ni1UXCyeeT9ujT5k8AFHjP09GOD+NvYjKwGnbRclRDJG+3yPqrIaNEOFVr18K\r\n9yKwALa/MxTI9yV5wZ0ci38RF4UcEsiben4AobL2xQGcNDVN25tjWWxFQ6v/\r\nhJOACu0yUeVNnlKx46HtGz1j1+4MxTA1TOQRaF/uHd1f6q0T10YuU+2W4cXS\r\nhYINsTUc/r49IiAQ3GfP8ts09FWmYUK5U0XoDhVteCjC6bhTzSKSa++de++j\r\n/YWVTdAFCNb1IW2zWI5LB01dawqTuIEH3y6yEoR4eRlRmMbAgaODRhx2T5sJ\r\nWpygVJ+fOtrP1S3WeD6ZQ7QhbXCAIcCxt4xk4VE1FNrB81RpXuPoKXdcZR+D\r\nOkoBfBaAA+jwvqZvkyOS1+E3V0dneD9y8F8EcZroH9fc8IH3MEhaSTvsVqSx\r\n8SXJdFQBSKOzhrNM5tlzVM6ia9s33yPRLCk=\r\n=c7P7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1c440126df57ffd3654f5db75513b19a762f2cb0","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.242+1c440126d","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.242+1c440126d","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.242_1669090506975_0.9907466922510846","host":"s3://npm-registry-packages"}},"4.0.0-canary.243":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.243","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.243","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b446138cb34ed50e4f7fecb802177e7b23d161ed","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.243.tgz","fileCount":88,"integrity":"sha512-gssgjF7Ltpi6WdZYh1hVcvVO1fDgvUKdqcKilgkDyrJjHjWaEmUtqJy98MXb2GWQRqdQFCZSriNWt8O9g2vZyw==","signatures":[{"sig":"MEYCIQDopFHfidLJhqN+Fex/CqtnMzG9B5/iUETHPVUbYOpbnAIhAKHReX0c7TKBR2eWyL/nPC2FSm/KzMTFn+07HfUZuDmY","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfIB/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqA3A/9E/pWI93r1jSf0RcgizcyAb3zahxSnjVVi/NRIDX9Zobdei4/\r\n63iN0EDigT8RgfCoV916qgiB2Rn+fOIryomgcoQHMQTPgaz+yG89zoK7jHRR\r\nd8t7COSGIzE+AZt8Hc87rmxHQdy5ThWg8pc4UmMNV0i8TkiJy/3DD26NbwIY\r\nDpK7hFDhtaBT9AeIk6qRGzSrNFkBNGeDuQFNmg0lBE2AnmAMsA0MzcjIxaoY\r\nQe6bZorqVcycuBTWz0CgHo9Uyo1OwuFh9NdBHQjAQhsI4kuLyOLDLRiBut3e\r\nEMqI7rNa5B15/BnmfZ0vnMcilokEfBILzouUjfZBbIMyjE/5zNunx7NdGiZx\r\nhRdcSDD9yfXXCMVazzMj4/Ith47+Wg9oHMcQvJJTLsGQBmoN/IboF5ql5vK4\r\nFtMQ9LIJQetn+K6vwHbNZOMetvYUeBxYbvZVV211oXAek8BI7FPHOwloOS/y\r\n8M1PH3Rs+o1HmR0vG6gf5pgbqNAof6RUOOq0tZ817SqSqTJrPAVQkWMWpla9\r\nYBUVUROmPe1WJFYW/jAYZjM6yuDqHkwTbUOWmdUvFETWvqGEs9zzTY64YIix\r\nwu/Q/jKqN3q/zblhThDa20O5DED2bx46vj/vMeTh1MoKKZqzrkIf5XprJZ/v\r\nFuUXBszTiU4LPt7W2bJPiwSzHBcgnu9DZzw=\r\n=3l8V\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a7b811141b201b544530354f815200e19027863c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.243+a7b811141","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.243+a7b811141","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.243_1669103743037_0.7098956169348996","host":"s3://npm-registry-packages"}},"4.0.0-canary.244":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.244","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.244","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c95a48bc09032eb3a610eaa2fa66e51af79959a2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.244.tgz","fileCount":88,"integrity":"sha512-D+OlDGIni+ez1fDptOjcx2RpFYnYUH6AvjMYeleBB0pI8CA9lMkJfUqDmIKQVW3doFc/dCPBph0y6l8E/cJrZQ==","signatures":[{"sig":"MEQCIEXdGGA2WF7sWaaElUyoJ2lXmIDNFObJ+a7mf7bUfDQSAiBmTFYi///lBK2vjvByCxm0EeZRQ8OBFphJYURphb8yZw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfsrcACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoGdQ//ZtI+gMtjb0yuIotXFWZxH/AkAACaW4EFyn3pj04CyknP4FL3\r\n318quVUXTimBS2inx469HmSSWjSWKMTqIgtKvKkz3Nnyg0HStvOSbT5i+LBP\r\nJ1+Ejnnx0F4r4RuCJU37lBsspIYgUDEUh6WdTo1IX8Ji5DHi4WrYVylnrkqq\r\n7sHK16XXoVWj5dhENzfEhcLClXXqY0M/VIG/uc7kOAfwYA/UV/X59cgIZJvo\r\nC66A2qnOb+aRllIL1VqiOaQRiQ/opBRX9VtJgJxlxbEX4VZ/UrTumq7oAAkb\r\nhtov46JgFL+xelt+Qorf8s75iOQWlhNa7mT8Wd2V1cWkTuBUyP6qpNv+mn0X\r\n7e409bRGNIcy3EQX8c3G7E6frhfrV6FmSsp85YNrvwFVUIHv/aj2UMIhRGw5\r\nuxr5U4QJdCWFexnse+Kpa2V0ofB54np5Q+xft4WS7mWIotDM88fUjJO6buUR\r\nARlc9zNtLAPmQdED2XAKYexRyf7tPbwTFA8kQKBO4MSyLeffUmmIp6mIEeqZ\r\n+jqsv4lclsIoB4UEEVFOryOkgE3NS3cyCXhhqyGZIlyLTaPa+NsLWz5Ej9JO\r\nyAUZiD1KWtQaaPRy9QgHuhd6op4/jWA0GFbz0pi+rMVibnCtNaBKpgJDiLC3\r\nkSUL/jTeweHxWkKXqiORS9psTuY3MIjoIgQ=\r\n=L8bB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9f92a63b8c32b872b2b45fe247cbfb2ff2fcac33","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.244+9f92a63b8","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.244+9f92a63b8","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.244_1669253852690_0.9953591827864472","host":"s3://npm-registry-packages"}},"4.0.0-canary.245":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.245","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.245","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a95f308cd32b8d99371790b97dbfd895c3122d5f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.245.tgz","fileCount":88,"integrity":"sha512-PqDA2GPWDvnRNISj2TquZYHSEN+qhSAbgcmKNRullUtaPuy4MWZiZd8UuzJa4Rs1PlCYXZqV+TQrsUAcFaf+/A==","signatures":[{"sig":"MEQCIBoET/WIbRu6etVaB5hksuYSuvPAgzj1aaygHkprYCR0AiAmved0hAWeKPSF94+/2/K6LQa7n1+MK4k/8BQzQ7NERg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfstLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqqMg/9FYZCQaPu4MTYYldT0iI0O7hE6Iz3XkwSw00e5OU3WH3hI+L3\r\n+0AnbcGwxMpApBm28ZJPbql4KmiWRUesuS2eKObr4o7Vko41Xrnzcs2NDMWR\r\n40Lu0GBw/oHPA7RH+IrTwiZG2mCWVS9pATb+xRCl4yijnnx8+Sr7RZSzABWQ\r\noDQEaN564Ovp515MDmtiaNSTKgMSTHR7VaKSGAW9pbHm/dR2MKGnX8GVeRV0\r\nGltLoW5xWG7N+VZ65pVZpUYAO/9gFFmH27pHA9et9/fhQDveeIxLCKPzT3qE\r\npWR19QI+GZcLmUZyb/zg6sPRkPjLcO0rIpcy7AMVUwPEbqKsBk2ngXkTfDrT\r\n6UOe3nU+0IXxP34usLWElKkVcwFbwypdMISF0HlJOGcSu0tfVpXpFovlcjR6\r\nWBbtg5CGk/u3UtMyUq104UVH20Rn22lqe/TjlkaPTIT5ZOJtC6pd2HH+jhUr\r\n6ZLMfEkKWt+FbWgJNqjtqZE9Yy0dSQPyK2+13xjTpq4EDN7r9Pxi+i9Ujg0r\r\ncl/hoVzAxabxXAlHQTYN3J+KWHEeUdZiuyozjyim/Gp1LLFI85Y8LUH2dn4K\r\nSdH9cNdsg/u0QPNbG43XcqnmEkpI8R0h2SeEo4X2Yte3bNFCdXWJ/BOIwUkg\r\nyokCKw5TQ/NSXIpOIHdnp33Mf6794W2MbmI=\r\n=N39a\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0a57f38cc27b9c2acbc31da52485c66b0fd4f445","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.245+0a57f38cc","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.245+0a57f38cc","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.245_1669253962738_0.7590017017051836","host":"s3://npm-registry-packages"}},"4.0.0-canary.247":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.247","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.247","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cbf0abace7fe09eb6e8644b2077460c3566930ad","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.247.tgz","fileCount":88,"integrity":"sha512-ghUVGHaymo/jiY0z0Gb4C+2HC+ms0oRXD0kxFjiiSErzhSXNwjvv9Q2ji2GeCH5Rj9PJsw3u2usMXM2RpOcp3g==","signatures":[{"sig":"MEQCICeRDG/wRZjAFfes9L0cFyB4Ba2u2awjJnybwMrVOFD3AiBDyshjWIe8BDlH7QMFogaufOSV8hHDbJttK2is/u/HAw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjftaZACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq1eQ//VLvSRPAr3dlugD9uAH/B5A7MyMzZaxThwqcuZa0lsgLfxRa5\r\nTt9eMdw/AHtmttOY+X4fOnCdPfy/lupYWaP+zggHp2rwqtfo2z/NasCH6dpo\r\ndyNBA2Uy78tDMyxTY+O6SSSrDO55h3NxcHqA3LY3bP1UnvbvdbscFDnYnSge\r\np6X1qrh0vN/K/+YD/HkpA4fvW2WCaDvU/kqNHC42B20/SmYUAQoH2prno/j8\r\nR0QWOozVIHR4gtBeoUJOJyR7RrtgjbV4whcRn5m292qsWNrv3NsoKO0i2QDV\r\nqRRMi2iS73kDzF28QlCUSKnsFwtdl7bGZ2/949d4n32N5ouimzWbtgX7nnlK\r\n8/LmybcObhw3tC3p37FhVcP1Ufh6QnXPP92utuiQ/TaG4d++ywbjhDK4kqmM\r\naxQ6Gh8rWEHEg8Px1Ez4PlVARzzwvzaUYcRo5YRYa3KKhbu/cmNe7WIJ/SjE\r\nOM9rYCQkMSSBkZVs+Qgb0FBm23y/TpBjfWWV72IzBYjqagiPt8eLD2mTqw2/\r\nMNFsa+vslcphyC1/UfUSw/G9hIvEvV/EBOAi64iXQ7IkuysrcVMv7HbSve2P\r\n+5ca0K3jsiXNL6XM6Ksj0twvUmP15Hp7aY1cjovpO2fhUmXU/2t9TVvli0Y5\r\nT1T92N5bGbaCcyzC4kAg4gUziRNI4LXozwA=\r\n=YGK9\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"72651134ddbfe0e2d56b1cc310156a9ddf49b4e1","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.247+72651134d","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.247+72651134d","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.247_1669256856887_0.08965860909232326","host":"s3://npm-registry-packages"}},"4.0.0-canary.248":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.248","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.248","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5f23d9f4f42d0a20774f7c78c8c24fb3b647728c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.248.tgz","fileCount":88,"integrity":"sha512-m2CI5o4MXeYQTLAm5GIGDaV81DbWSwuBI6xTwX9qBLVadcR+J1mMEo/5ErmC/e88AB7RPPDqlhd53viRDC4wPw==","signatures":[{"sig":"MEUCIDII6W0EmA5Xpj9GLPnQKYNBcdlHvKv++xuk83jFxHILAiEAlGxbinKvXXyQPMF88ea6I7SP0Bu7WLlwfFs6IUUbAu4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfwZ9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpkDA//X0fYtDoDKMnzb4x7XGvLuIxTR8itpjU5xpFvXfNWBf1yyg6B\r\nKES1pw4c4jkRyXqkDQzyVhtzIudVM0teW1YCwL27T/gBVLYEGsmRcaU2x4xv\r\nV9XLXdC79Uw7rbNeGBxUXXIs1LryrWQDumBVt7Ltqiy7lnsBl4PzP4RrSRBj\r\nY2JDY8sQazooX36IiJza/LtmqwZWuab6bs/BSf+R3Ai/ADffHF8SikkVnsRD\r\nC0UIyW4mJ0AWL5WU2OukyIeYEIxCTOh7UHNGsxgpfbuYqxzgATIdbgcdIQQU\r\nZg1QHvO00r24NPTIR/78778soLTLwd9X2kHGBT361lY3kwD3/HvoexO56A23\r\n4kEm4Hj2AMtsFBfRubGzjKELYYUV5uKK7Bz+Xd+FJLrLsd8dCr+Biegf3S94\r\nuFlnt5H/uqwdeNV3BaloATRnWZknZWSKQdXB8zuX+1KsT+EzdIapJC1H1A12\r\n/SXzC2pJNQ+lrCcFs1wIJXuGo7DK3cjam0GTF7iIZgOPpQJrprO7Kq9dnsct\r\nNQfMNGm6QXFP6pGrkMMZhitkEsFj9U4HU58Bc0gOKgBPJiwUq0E9BYGfZ5s4\r\n7XsmGjQ1fB+PU/s5RVjvrXqX74pL17UD7dB+j4f04bqAepQfCoRs3L6eDTMz\r\nA1rkZuD6u8pp2wFH199jGaOMV8h8DTp/ImQ=\r\n=s5sg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c77202d4a133168f6e665a65bfd09bcdd5ab34ab","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.248+c77202d4a","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.248+c77202d4a","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.248_1669269116888_0.06919663771299489","host":"s3://npm-registry-packages"}},"4.0.0-canary.249":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.249","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.249","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d478abb5c4ee5d220060ebc1fc5c4791c47abe8f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.249.tgz","fileCount":88,"integrity":"sha512-TD5AYmzKAcjGnzhnA5nOWgT3JIHvozUPznwekaB1tsM/c2ZdgIEWU2wgPxwEh80i0FvQF13HnRQ3xUIGHvSEBQ==","signatures":[{"sig":"MEQCIDbHGZRgnzzKasYElKFn5DV1lpmDrZJ5t9PMdVXaE6mVAiBbIkRtqCYwqAJWPahFld0PwLWR8TGNcwMEBMO37k4YbA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjfxvCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmromA//fDMcl966se6DL5RXlUkz89ebOBDr37bL2TPe2GgofSJ6D8l5\r\nCdjdy0RAcZYY+ZpDabfqqgVw7EtLsDvTGOomGJb7mJ8KNceKxlpIDo5d0RME\r\n9pekgmkjnp0AbPEso31PMQksn1JxH3aZAJiVSusPn9q7MZ7cAmzDnvIThK0m\r\niwBv9SGUDpO+/uVv2e4NR5DIaW9N0ez1uCgkwhNq0Up6HHC4g1cbQrpaYvqH\r\nS0FWPL4+JjDupA/DpI/IlJjQSWD2lRB488UHWbMkAQyasHw62DxnBDKE1oz6\r\nmtlPHOnPzmORf9zUaX/TitZQQVx44g3uuf7vyYkT6A9HN9pgh1OQmfT177kZ\r\nuQmedUllyXBXIgAtY9QCzVPnemcD10L++3cUKp0D9aP4xQtVaaVgjTnAqDuz\r\nacAqsvYQGyNUGBhsRG8AOa5jvC8PUHLl6GrIuo1QJg6mVzABFf9hHFK8tyFX\r\n2VC0rwZDn++BZRX96SB9i2wL0CL7J5PRysp1wdd608AORjGfMgBGXZVvT84i\r\nmdrN8lPXeZwR4EXjIIvRuT16FfCpGzhm1wpjgpETD25Wi8ZHzto/EF7EuNZP\r\nkEhfgl1Em4B3QM2BsWwYqadAyz6CdYo/u0DBFS9UE0iIk73EMw6kBjJZsHEm\r\nA4a3d7qKJahzNp/i96Q8+Ozz026DiPGfdY4=\r\n=2Qmu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0e072837d71db5eb3153d2d94638225067061bc8","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.0+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.0","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.249+0e072837d","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.249+0e072837d","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.249_1669274562110_0.8445567637385614","host":"s3://npm-registry-packages"}},"4.0.0-canary.250":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.250","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.250","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0b9630b77373ec702c4750b50ea4cc66f1458f62","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.250.tgz","fileCount":88,"integrity":"sha512-1kHZPSidswJRV0OZAMydgZPk9I5gbFGktvihGrLgdHBMISkmybXdtpU3wq/m9aps9ZIlezLTLYh0Ob0mxyN4vQ==","signatures":[{"sig":"MEYCIQCggyVD/PmvWeb7NQ3dMdSurcFbbNlPj5G2mRA2Jgm/hQIhALruskExfP5UuS30t7KiQKzCY6x4flJ8Bq9Evl+G98+0","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf0vlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq92g//QFZly145qIvH649miH4O4xFEH5nRA5cXPJruHTo1QQI/UmXB\r\nl4RXzk50e7Pp6fzEpbnQC03OIBGPdtIaqkMjV1iORdEXWvkjB1LWdQ4Ly4XB\r\nsKYCOuEH+hiK+DiDFXcLTAwEgqccod4jnumNdzhDFCT33Gz8TOwWxzpR5SVk\r\n1JwCcLobqg8/VKXkfEqlpH3iPmwNcmxafHN/z1A/3+z1/cc2NPLe8RW1X+cw\r\n+gxfgPSIe6UUmA1qq1nTr9uIgOkDh5TzpXsvtKpBbieM3wEl+QOMDPYKU/D1\r\nSEvAGuPCaStxGOocgrcGvrupkTpIb8PS8sOjZlmqvaJVxvxuzYE2Co5jPwU0\r\nQFr9gIgtcZQHl/QeMCw92FET/LtC7znbK8vXXJKbqcSnFfTne9hKbUgavmg+\r\n1vmTskFlZd1ioMkE3TmMyU6NfElUdfWw9A62ZD+D8iEG97VV0oUt9qp2hrK1\r\nBCZmxCwvZ35qP4q+3FKpeBhQCDBF9v9QHF33SfS8LT8ww8SpyLI+hQ+ufODl\r\ngyN4wsbBZsUMFICZUX2SZdKBRO8Sy2KiGiPcretG8IUiazh/1K3m675qZrbn\r\n/HHYFqBkd9O9yDpl7g/ODmplnJirfQLbgghOz0VD7IkHsVQS0UOHe0cDS556\r\nU7KDebWOzgDaCdLudPysBlILyTJC/C7KyWQ=\r\n=hzn0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"366ff2e65d97bee609f9f24404e56384839dd127","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.250+366ff2e65","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.250+366ff2e65","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.250_1669286885226_0.3940558671671297","host":"s3://npm-registry-packages"}},"4.0.0-canary.251":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.251","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.251","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7b53c9976e0caa807d169e92932e3b124173cd78","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.251.tgz","fileCount":88,"integrity":"sha512-LD3PSAPEPP6bwjakjlUu4Tl0N7O1zMt1sEVnbpiXORmGGaatSsoMSeh/m6Nj7S+ZjHbzdXjvINoiTXVz1uxe0A==","signatures":[{"sig":"MEYCIQD3veYNOnbGnPFVg6WuNahaRzYDdsikWozYz91Pd6C+ewIhAJyv7ASCfgpQh+yy8i0RCajJNk41cP3FAcPa1l6qKg9i","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf4ujACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq8yA//W+1NdFA+no80fQ9u6raQAgYA3kPDPZFukzsSm6CHpo3ox+BG\r\nWiIy78IMwug7B61cB24Uy5c6pXYVklYs3Brf0aBcfyQ2C4NuCqMCDLtOqB8W\r\nyPJUGX5y727hNVNmYBH+fCs4ctCaNxRam89tudzFaaGZiPkhiynMAR6v47Di\r\nVIewDjY0AUudgTXglhlPgpac9gEiv0rBdYHe4SNS2TKFhcg/8ETdYQhzBzO5\r\nskNDHD5NHX+eY0ooxy+KB7E1KL7n5B5UQlc1NQfKnYbuNRb61vzwhsjnQgUQ\r\npkeRSCGg81fujBkmzDbaxxOLx0pEISP2MHRbswed15K8UXZqLW3Gm1G/spo0\r\nJ4QdCJ1rP2SxtYIAYMzAkAzrGxBe25s3XTzROWBG1/pRFo1fnrzST4qc2tip\r\nNm2kWuLtTNcqVR1ZC9UuKJyhXmQaqkbAvlLg59MZBcAyCWpdO0wxUREPs/g9\r\n8eWYLR+pm90woxU1LOYY1LMSu243JJbSKcpoao5VTTVJhCTSSd8aQS+3CNe6\r\n1YtSJAxZIeyIhgD8K4QA7tOTEoMwuZqrldIFUyZ8YIMf8XALdC9FWiPshzNZ\r\n3lmQBSzrHWHVrNfbxz6AP7VkmgeJmztlflYT+ZfxRbx5WWXT2XDvTjQQtNga\r\nl6nCX1mquL2Bmk9jGqre9jPGScbbmvqt0V4=\r\n=mNh2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"3d8807be033e0bf9106f3a62988686d4b10f98d2","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.251+3d8807be0","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.251+3d8807be0","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.251_1669303203535_0.4557358807730316","host":"s3://npm-registry-packages"}},"4.0.0-canary.252":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.252","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.252","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"346c65ef37b6818b49ecb54bff63e12b58dba7dc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.252.tgz","fileCount":88,"integrity":"sha512-Xxpx/O0N7AgHORdp25tDybRdL/5AQ51kCKTRxpqn+u6fIIxED6TsM4R1tfTFgKCyZxWXZRSRZg+qWpU1PipOtA==","signatures":[{"sig":"MEUCIEe/bpbWjApTUNL+sS0tmrHJfv+Ky4fRJhHgvnfPbHoOAiEAo/a93qcJl9ULTEsp7Zvv5auLrr9QDYWTcX8O9FWcIsI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf5QEACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp2gw/9F8TOxOIjBuMblgBO6iE4Lh0DCMPd10ZL8ZCLAuNcbvlvVmJw\r\nGRX57K9H5avt+IXRDQi6iF3cEEMuPhbPhm57uddUDqIi2wqgz3WpqMuCWtdZ\r\nmFzxPug0wO4uYTY+IWPOfvez+Bbo2ydquVJr/YnS9XB3djXacauEX/i7GHN6\r\nV2JEZI2CbOu0iFdfCUQEhSR7xhCBiRcoO2xiARu269KXd5ct/TGVzDA3qCb5\r\n3zQ4eSqpTZLbw6DW9d0RBTEsBkJtc51h+7C/AifixzNAYJ/nwb7ca/ffjHAJ\r\nHN7no5p5c9R17oUT95B9grdCltG5abE5qcQ52reZ/8Km8ykAZrPDH5kflHae\r\nzXyoJnr4J2AtRoueL5FML2vryVyqg/x5k1kB+vCvCtAr9dbjOx4QqO73PQ4a\r\na2xgt/oTMidQlRwU4KmXTsBvQ27l9mJAq6ykGZYjFlynfatqWd9U9632ddD1\r\nF1wkgsfE7N8B2tOsn5WZkLHTcp3s/bkuIdzZrGjXUai45Iuv6tjZ0Ww3xxeq\r\nfmKz4jBlyEzG1803sLK4B+1WGKxbheDMM5OX1lBA4PX5915axa8LKKeXSH8b\r\nqLPemrphxoNaxhCRKKc+HwLdxWbnfr7Xfj2l25cDgKqHO6zAqHpFPp3yLLcG\r\nmtyHpZGNhumlvI9V4tCbs4B/X06FQueSZbM=\r\n=uqGz\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"afea5cf7fa9e4377a7a865bba797f7ce4bd74371","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.252+afea5cf7f","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.252+afea5cf7f","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.252_1669305348416_0.9266587935220014","host":"s3://npm-registry-packages"}},"4.0.0-canary.253":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.253","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.253","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8f1bbe2f36dd76d4824b9732240b4093e7e30a71","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.253.tgz","fileCount":88,"integrity":"sha512-bji8CF9/hqYp9ioZb05CAiIU5t/lvPTSPJohHpjhEP9cvRMdgKLbDIA3f8yv3bIy7n8u8tX89c9vi3jnikTFUg==","signatures":[{"sig":"MEYCIQDb6tZVmsHtVqVKyuoh/DaoY8n9QK1K6OS4pslzpLRzDQIhAK686gCUuPGM6edmtrVws1PFE7vdXIqZusIxPOgHj2qh","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf5aXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqqBg/5ADoEC148eisR8SBigI3Gs9J+RSrnFlBrzfp0i/faw5NhAOBp\r\n+KmChEUkgZF2YKwQlVX/w6bWL7MaMgj/McfvJk5oFyYcKrmpOqAW/EPUWHGJ\r\nxLg9LRRT0S8e1J3cBddiEMGWfFaAHYErNSqSguvtRXpCXeFAfZdXsDujJpMI\r\nJeq+PUb3GnoV+zIDG91IWcdml8t/dh240krfMEvUCzQIS2kW9Z4uyJDoYYVE\r\n/xRrQsRzGuPrzS6tUYPXdEVkMg8u4llMHkYVZ1S7YAIH+vK7iyCeu3oEHQ4/\r\nCwCW5lpP6xcveP0h4UxWeZtaEWB2O3sumuiwqzl7PSiZVK66Ph9M7FkeRq5e\r\nwdDikHziUvmbDcvoOG13oxxR6HVj6wVXwIelSHCaxtqpAj4V2XY/wI3bOM6T\r\n78c2X96DiLagczh5q+I6hBR9YXMMAfUkdOQzWcYgI8w/DLsvdEAX8TszBFPA\r\nvqPhc2UzG5akrFxn3ll0JapcXHNI2c9P38/YccmPRj4A/4TXzF3YeJvwXGr9\r\n6Q+eoiqrfDw1MoUlVCkgQUMSgV09mw/N2Q57n0FhL3T/8jc93H3Ql8WcTuID\r\nG3VXl9CRzwCoJLuhnoIGYW7oiUzrQhniOUeUSU4SjA4hzPbkA+e6htrXVQIu\r\n0vt0/DNFOkQMqWUC7PTuTov5ghE++BXprYQ=\r\n=hX9C\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6543352b7162b7f18228aecf17495d2c96d24e09","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.253+6543352b7","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.253+6543352b7","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.253_1669306006926_0.17336735777277346","host":"s3://npm-registry-packages"}},"4.0.0-canary.256":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.256","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.256","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2e36650c404b5b34fc6c6c0aebeae0fae72f5242","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.256.tgz","fileCount":88,"integrity":"sha512-I3EJweqLgpIOMnqmwgBWHY5BQfRQbtaYqytc1sQu7vW4GU/fgNZ5DS8jPWcqCOAozEn7K/RU3VnOBTvPzUGB2A==","signatures":[{"sig":"MEUCIAfsVnxa0apxX6wYcBNDcJ6GWfJdtD7/IWbjc1xSk8xcAiEAxUHS2jgwDH3xksFiPVn5wI/zway75y90Nuz/5wCkv5s=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf7DHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp8Ew/9GhLfiNIov7DUFAPDGBr2IbPwBEXUnmdli8Q77Igu+E9eqN5i\r\nGG/2qOKbM94IPbosLJVOVM49wAYip+wVeBbQc/FZs2KDA/gNaYH6N6QP9tWS\r\nE12PzRXKUoh/08dWvfryKt+Nd4EPQtRaS1StpErVtmlhyU2gq80GYPZ0ynVd\r\nTLdy6xtjZZktXMMJEfF5Hvt3gDL1t4rRysV/ijKlfpEwqro1yyaGMeTsIb09\r\nAXjuDixXQ0wDBg+ap/2Ytj/uZiiL5KM/FBVZSDdCb8zqLPOUdLjnVp/bjj2F\r\nv+nYVTYXUKa7pMTr141IzNV7WAonD+wj3XK2YckqvH3PFMfpHtD/5V7GHd0N\r\n94anG0CUz6x0RwD1blvSo8QRHgBg30NG+i+2xnSGvrVbeM327QW2lkowRvnN\r\nZgR7i2R612osaeszgtZc4tssLeM636iU/1eDMw8us7+8PWAwqGHfFQ+e3I6v\r\nvgt8nqOOmP5sOanoYWyYSTakytIRxZAFBKQcNe8jxNvqS3JvA06t0W+qECGe\r\n2+9eWm2AohX1pzWUZtFHQIz2ooRa4OMqejNyH/dJsFqUgNyXPcqTVkYLM+mi\r\nUsoymtbEN8pZgAzrOBfwfPSjkNB6lRJhDUwJHVBHJkEdg5ievV2cVzml+qr6\r\n+MiHHdRw53bKCL36J74m+og5VvNSYU+RCy4=\r\n=YKwu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"42d9754e5c4686422f9bf85676084cc5cee8752a","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.256+42d9754e5","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.256+42d9754e5","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.256_1669312711385_0.5577861616106314","host":"s3://npm-registry-packages"}},"4.0.0-canary.257":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.257","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.257","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4dd42e85bbf095320b7615b98cd51fab265c8e1a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.257.tgz","fileCount":88,"integrity":"sha512-lsT/i2j6jOczmyUCpUQ1GeVJeJ3BVGezPQF0ZB54kCIrF9USTSvXcfxzhp7A7AFQwfr5oiH9NUbWVqUJ5dCRdg==","signatures":[{"sig":"MEYCIQDb11cTs617ua/4SoMUVVYas3UMoXje/6lxZ379eSa1zAIhAOYS8ooPUsamyLrI/K/nGjFNjTYIGCsrzVEc7KV6KDE0","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjf98EACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqvlxAAlqJ4Ek+vshfkxwq+7kDfXmRI9Rn6b3U4j8AFZwiqeMNHr+J7\r\nEqxMim1GVPGeNpO5Vv3cGWzGOurGYKnmNsTb+Ao172YJtyLvld690lhcDeFU\r\n0S/XlduApLgqSwhwfebJrkbBhMfi9SC/kycoJe+aotI+xl9qUdiq/CvAtSqU\r\nMbmownG8knclNd6PVUKVNfxLzi3x8w364/xApBWeriYQI/6Z35ma7cKIMNSH\r\n7vdIl72cYYeFG/mFhSjZ6r2CYAZp15dDvM4OjeYcqUlcJW7VeNjslFXctIP4\r\nqTLIniMxciZyDEEgU9kfTiCRK6Ok51+VE2/13RdoOAElL826TAAOd0gBp6Rx\r\n5n8uBkS4YZmSKYwT+CXAitaBxExcEpQ60oxTytQGRtltc7Ef0s7/9TvUe1f2\r\n1k/IiVE+dG+Et5MUZB7mVWJmBrMpEhcu2CtX8eBXlvnchOJlzVICVMJpJi8q\r\nlQAG+h9OH/h6d/BwAqGwKjOqLQoU1B++rQnAaH4uuvxoN3M8ew/Q9VlmRfNM\r\nBUYnSRSRQuL0yJBEyLgwk13uHx9riYkACfbJw7qROE9v0ZbhdT3mjKwk6fJK\r\nXaELrlq0l4gBQQ/GyPn7QOW4eGq/tqfVvxUuQYmp8I1T2bGYUQEf+T1Bfw2l\r\nqI6v2KxzKuF0sxtL5+CiA4PYWP2wmTE8OcU=\r\n=Bq7e\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d20729b709d800fa472c60915e95fe5b862977f6","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.257+d20729b70","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.257+d20729b70","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.257_1669324548764_0.38219892492898944","host":"s3://npm-registry-packages"}},"4.0.0-canary.258":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.258","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.258","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cd5fdd21400fccb7a0433484efc7543cdff71b31","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.258.tgz","fileCount":88,"integrity":"sha512-zsi98f0L/awWv5GvT1eHDsXUDLtYcAyl2u7rB4oSbwIcH9hr/bY3t57ZiGCJG8S2a83aqLgAdAATqhEAZmAGHg==","signatures":[{"sig":"MEUCIQDhmhYr/ZX2JGBbUaIrtYKruMXLcRmRqdd4T1KuvkiHnwIgGl9HwPBBqU81axXBCSA8enTWHEa3k77bO77sWWKQ2i0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjgVZ8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqqvQ/+I9o7YH0tcBSxxaOgdVpHDkERy5xlRrd0ndxLYgjFhrlYKpCA\r\nQD2/63heuzLCZLrMcuYHAWMZggrDQvkv3uSCOAnAzqQ4tkZKjbfqKaU3HNN4\r\nkjUb55wxVJILlDwtt6WuMNqACAzBZYc8O/u0Fi2nxEAZPKBrAGPWyPYVo0WL\r\nEfvMT0f1pcC7CYksNPWMfA/iIulXaJZwSH9ET6mwZgzm8EYFU9hz5lB4OoCP\r\nuF6K+aYsn309qQIqUjvgMGpFyXYQoQrtX4GFSL5Mw9YIBoFnwmcxMzePTqSm\r\ns97HdYHBk8FD+6kt+1q/6L2GUK60dIX/sgH9earaM1ZyDlX6ch5x+ucJnESm\r\nZwBDKOERKgDj8EbVO6EGiaIBcU708rDCbzW48R77uM8zQz9L0Eh9bLKtWmrG\r\nAXJfIF1eRqHiLOJdn2XKpJXv7TnsJVe8fe2M8Gg8hiAnT30geWtsbVD40EQg\r\nwMOkYxJ5ZAEzWXtteU+eSPj9EY0wlGeQZ6DqoJX2rcD53jFZKHFhgFeoqNpS\r\nnuNsdi3o4Uze83HZnfJzo+9dW0GN/EgwwueT4nlXM4tWEKau6TtQlMwb2znA\r\nGGEy02K+i/hk4goW33LLJM2ycuyW9zjC1rATtrrF/2eJIbt3uc+/iGkhEO8C\r\nYQGrP3TPcZXaQJWdfn9wdCDP6jxETpbupGE=\r\n=JxDX\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"35737636a871f6e77db725907f335136cb1c6f06","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.258+35737636a","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.258+35737636a","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.258_1669420668373_0.5992033055254988","host":"s3://npm-registry-packages"}},"4.0.0-canary.261":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.261","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.261","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"7fd2f9ccfd118dfb806c4116c2485896f8e2cab7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.261.tgz","fileCount":88,"integrity":"sha512-e0iIAUqLQFJqJHacpbp/0RCSjtOD9PbFJuUpcZ0Tn7x+Bpp1wooHaO3Eh1zLCs5A6ZDb66Tzr/DD1EClEx9o3Q==","signatures":[{"sig":"MEUCID5bRIW5LwlvkjK2L9unYRQGbXf5FYqq9M8EaOGubEQIAiEAxaELuMz62GnlPOC4T7FCM//SRbyq8o0wmaVMOP38yvc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhOsgACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpONw//Qsl4/RYpCZHrajbg+AtGNSbErIIBzDsgWwBVR8X+oG8AwboI\r\nmRAIIjqvoYCVSfSEbZJ90r6YNXCyBEWhRHceOn20xiZ0NkW32LBwIYJ217Nz\r\nRtkMlv+G9883HI+d+ugpvxrJbnyP/9GAW7Fe0odxPGEht+ftUz9PFvs0DiYK\r\nt1n+gz/bptQevpGyWo8b/jUS2yjgqo8ZJUUiOySGMXnkeT1cPhAojvuaHh1u\r\nunENbouHREDrKLSbqHiri473TskGVAM4LeCtUiwrLXFVwPMInWlW88LtxeFC\r\n4Eb5CgKuZ+xY1ATvLzRh2p3yA/sC89j4vjhAVcNWeHkStEptzNEE6xKKLjU0\r\nA5N5KTbndIdMkWbBzTZ6b8g+EMS6SKS4B5YgAMCd41N2hqSQ57ULb98i8FIx\r\nzBo9cS6gRpBeJeSPif+WunMlVvCYqqfAueKiYuS+HXSsSVEcXYCgCZMVKQ2r\r\n6BKtFqnDL9H4yPEvGjgtsCFJfCzZ6hrMoE+ivOsWZ6k1/ImF0Bmk3fdwVfvT\r\n783EqgXuy+ljvLphPoiOcN4T4bJ0sdKl7uOjIzmicJ+Kk3cIlf+qU95LC+8o\r\nqO20/etnIHDZHTGQ8ozHgQ6a28iXyuc59bhlo1jqA1aQBiBeUMRhkOgccOWm\r\n4Bawu8OYaqrM5srluIi/8g/7X7S2CGbWRLA=\r\n=yTkl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"4d5cbdf745d7cff4ee6adc9fb70ea8811983b879","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.261+4d5cbdf74","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.261+4d5cbdf74","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.261_1669655328076_0.37428048432868355","host":"s3://npm-registry-packages"}},"4.0.0-canary.262":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.262","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.262","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3943ad70340e46ff886a2c5b9a00d17c5e9fc3c2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.262.tgz","fileCount":88,"integrity":"sha512-guwkGqYoWbgF3+dOs7gTq2dnLM2lzclqA/r8wMkz2R/ZKtHKAKa4j0fTFoUIr547TKtjOjcYZpDcFfAnqOs6ew==","signatures":[{"sig":"MEYCIQCrmgYyVqc9rmh6v2yCab2qMTtVnEd5ldPnngb6VaNsTgIhAK/re3y7VABRm2pYA4ExWnI0nIDeBrS9KWmu6GYY3nJb","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhQQmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqvpQ/+JBz8YjpNXUe2mvjnlS9yRv/D36onwUzwwq3W/T35qRCYggGd\r\nfw69aUbWTAql3etDsMBOyL8/3vCIM4jP94cyVzWZl3tKxDWinFc2EJcWHDhO\r\n/znRy1vfgIzvfL2f7wzEEIlHchieOcbfOepEDQaM3c0nfPwL3ECG9h4sOUHV\r\nAgWv2q3MHXHRp6XupwEdg/UMvVMraLWvzmZyQ5gUxwXTHDqjxW1o5hkCZr0k\r\n5tFCVWgKEmOsU2wAw+/s43PHhGj0pyEeQ0SBoqxQSvYVzeCgZH3oI/qoYvQ1\r\nircpbWlViJLXzAvQaS/ghShDQCzjEPadzrjZaH5Wf/r24MTGvgiYnoinkG0+\r\nQsZe3lAEXefswvxwWQ+EUf1O8wpI/lYkVD4aG729if7LQnx+liCgm8g5+PXu\r\nxnayGTq5eDvtQR/8a02tHSCXMmFsZ3Nd+d4LRAiyJTMCmlqJm5RnwsgIPnUs\r\n0XxU1GoAVUOIam4gUirIN/EKSwwm6gd62CXVhaSTmFuAUq6ZLyd7MsxlVMRr\r\nIo/OE+gi9msYn9QXYjK5lArgBpdbUOksxmVQKe69ZNez+b3CPgN6oKtzIzkh\r\n+04KROhdNMVNKEJEm35CAvAH2Ybl8Yytob9nBeezO5eynkeahoGk/DRVFyMo\r\n6kekkNsz8lYyAvwva8fpUpdK0Qr9fDL2wsM=\r\n=5WEW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"37ddc9d3a293daef2ac6ee4e62b692336908c50c","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.262+37ddc9d3a","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.262+37ddc9d3a","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.262_1669661733788_0.1865661496033213","host":"s3://npm-registry-packages"}},"4.0.0-canary.264":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.264","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.264","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5ef4316ce9fdc371f3f945a5a3495f91f43c62a5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.264.tgz","fileCount":88,"integrity":"sha512-dXEfQ6DKEvcati2brItwwYP/AJMHLvapP0DZ2Qo2WMD/pLvXFuw4u5mXRUZbuOWwIyCfi/qbqyIxpsYscYcJ9Q==","signatures":[{"sig":"MEQCIEZWwK2Rypb9zJm1SCcaizDUOUJ157yg04AZQkVfjZBEAiAclfM+W4eeaz77qvFEBtI3P4wHrQoUTMMbW+uXc3Jj8g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhRbaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrSvg/5AGA6uWH9eGZMM6OpY1+ePCVMr0mn3IRxxMQEZ5rI6CpGRtcY\r\nvfOCLZPNZ/LcFJkYjpP6SLZpD8ZJOZZQzdKjlYA3nQ1zDT/3y4ev6B0qo4qa\r\n8b6MEZdqk7nlRmCaDOT0cBnaC+NcfOd26u4HECpTj9PPKaDBGPdCH3g4lqgQ\r\nbwjX0merVWqFTWW7oZTkZd+mp3rZnd3YOTzPI+8bxj6Gx+QqsPlpOy6uc5yy\r\nkJWfqPa3GB4ibZZoFGBpkBunNzeyBTY4/nHgYJ7rzGA3kSagqtNZqxTXQRTJ\r\n7mmN1T0Xb/Mv2n6Y2CG8966P/rLIYYDR9tY29ntADwiSznQmucLZWxx886Tv\r\nX8zo+m2fJgQvDz3TEW1dNivmrhWXH2mTZ67QYCYgjz4akJ6zmiHDiIz6lcXy\r\nzXcusDpLRFqgXj7Ae7vNHlxC4ojwAuMYeCy5slPA8QtevlifRfJiPwEBOhkF\r\nQqHUMn5D9aLW6+eDqKuTv2QWGGEAss0UsD6KtoRSjnVLesy6eC9PSP5OnAO0\r\nKh4aRMMDLejiGsw0D4o/SQHAaq92/S2DU4eTwC+Nrdqf0HpYXVpUYzyPCrLz\r\nGvW+nyLmkh6gAkil4VF4qAtmbub9S3aTteGBSytzqw6xXHt1OLkuGX9FQOF0\r\nRjZCeUtzbPkynTYBNX4y8heaaE9X6c7sVNg=\r\n=Td9+\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"286dfe0dc88763f9e5a1c78f22f4ff8dcd20886b","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.264+286dfe0dc","@babel/runtime-corejs3":"7.20.1","@redwoodjs/cli-helpers":"^4.0.0-canary.264+286dfe0dc","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.2","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.264_1669666522453_0.5694968661834516","host":"s3://npm-registry-packages"}},"4.0.0-canary.265":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.265","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.265","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ce44ca2a84afc2c332656534ec524ff6eb025b96","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.265.tgz","fileCount":88,"integrity":"sha512-GOTdXs3eaUKX79Qzh4vkW2fYU/EPCVDDhZjNCqXMYF1nDgtA4I4gflFjCLh4mjvIf7KfiYoUa4pO+zsBP1a8Qw==","signatures":[{"sig":"MEQCIBPsn2GoH/Zh4HN3+Y6v2NUfHXEhyWq1R5DziTMz3saNAiAld9J7++FRT5IylD9bx/I12xtNdNrosI4Q+0XET21Wxg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhSiPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq1ZQ//TykRJltIuPZRXhEY1pTJZE1mBtw3aG4NyalkEfPB4rUbAOnn\r\nhPW/mM8GNZ5cuUUC8YOv0g4z3+oTa2NolQAHKkc4zpMFm0Xz2OjkhVHXTehQ\r\n4CpLJZ0ymSFc01t86u/FB99JUUZLAhoIg17/gRRts5fMQYU4RBlvCC9/xnQR\r\nqM7zgf6EuNopnzDcfTe7ytc76ZprWTBJlAPWcpPu2UvdObBYyF06xAELdTWg\r\n5EUdXP5VUk1pzS5/eIwmK2GzUHmcmeKgfveIvRe8dcFJ8iX1O0ph2AwQTIls\r\nHlN9Izz+lmWw1Xs0XaDV4L3bWtBXQGXinjIsWeC4E4TVSUmjV5FBDU5IkJiR\r\nSABSidLMDt3CJ8Wj7Mz0VA46pyLf9z9ABQdZNMFp6gFUoZOqr4FUHJpqv0VS\r\nAv3YxHXNNBiundw8sZKrk9B0Ha0QZjM6IIf8jyMr3cN/MSGUToRVfIH69yXU\r\nxwOi07xGDlo4Y8uvjL9X2lFJkkoYx745xNrjf9+HdXzdezxQuwLc5uBz63b9\r\nN5WBMKqVQERwbPuJB4ixgfidZJqqyvjTLSD3ZlkIIus1qOG6dM57Iy/85sjW\r\nmG43FBoxeW59raT9l80hfi+Q9JXGo8+mfwIX6YqAyCJJSSe0hxyG7xD6ciSp\r\ndanETEavgXyZE3icwkX56MiXqplwVBCb5J0=\r\n=MbSE\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c3634393c1f054ed4d7102de5cacceb13cbb953d","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.265+c3634393c","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.265+c3634393c","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.265_1669671054936_0.7982871387026786","host":"s3://npm-registry-packages"}},"4.0.0-canary.266":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.266","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.266","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a593f491122f4006011e33a43988c3c354794e1d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.266.tgz","fileCount":88,"integrity":"sha512-AhFUCLreYUj7UmSl5TvhIgEOWpVHd+P3Em89UhjYS99xu/KXLkc37FWfbBaK4JcraH6Ehe6lf0J2joygW8/ELw==","signatures":[{"sig":"MEUCIHXhdoVQqrdRn6bTKhSSG5z1l6VvqndNKeFp/pya/REuAiEA2ap5Gf+a7TFmV0G30lgcGXBCgI4r7gLccEzCzBmU0HM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTJjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoHyQ/7BDvsvJAJnL/bnPtB731ixkAGNjAYrnIy3zeylwi4jGEzJcaD\r\nxjHXwbn5TYmJkHjD7emO1Ly/zRDheDFAqbAGuupNwHdTmqcWaIrvewidxm6f\r\nvuH+7SEVH/eMRa5AcdojI1aX9L6pyOKAy695JzlCaIQpr8lCCrmt79CaYr62\r\nir/HNMfK4pj6OheBw/0pzgM10czWOt0rlzXz43CwZaQc0m14HrAvRPeu1qR5\r\n9VNlsVDOSaZwVViexlDre5r8kxnQ4t9UV6E5AhwLQumuVvKNmqn3ynPpoJhZ\r\nZSYjfhGziOzq8KzJQc+MeLRiokFaK72/ypIKv/rwtrHw4EnD1cirfvxqaEZs\r\n9URpB6kL73EiVaz4PMwpMewicuLFsa3l/7Jwz4sVqET3d6Nf+DdjpwcPgokD\r\nHHFXzCgAZx+TRuTTu4TjevFCM9QH8GO3MAnlSDt+ftsgXDtFEm0LDrgX2zKF\r\nMk8YLYd50DD+lYaHDIyinyk4k2ix8CRcPIycvu5/DO1rtE5cMIL7y/jzFU6Z\r\nlDY9iInONxyH2I/+YawFmF6U/WrFzXFkfQpqKLjDEwOTSUkcLSjrnJMzsscq\r\nSPS1eeMmZW2VKhJefHdMgUqgLaUdblLkTt6+YolchDnvDIenPSdCAZ/MojSL\r\nhXl4OiVElgkBxzcwhRhs6rHu+hM9G7j+Gas=\r\n=ytZv\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"56cd2495f92780c39c68b52d1a330874c12b3a5e","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.266+56cd2495f","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.266+56cd2495f","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.266_1669673571762_0.8408458694350385","host":"s3://npm-registry-packages"}},"4.0.0-canary.267":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.267","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.267","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a89329cb8dac024ef55bc98e589c5c564b7e3ea5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.267.tgz","fileCount":88,"integrity":"sha512-lu8tGCq71A0V0nm9qSX8DOjNtGxzYt5efRTwAPCMCkVTi/jhfrOcoTfj/Rr3gogdXRZQu14kFtNJobp0nInzqA==","signatures":[{"sig":"MEUCIBRb6Qgr/RwT7ViFUIWwsTMg4iyPOEGdjQvjkdHqgOSHAiEAkxjlXufrSPohCUTrsnVLysSk4ZLznIuxUVldGQ4TDL4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTK0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrUwg//eKRfR53WEQ+2VaY6tNdq0/AwYBqfGHbwMjFsznFO5bqihjeD\r\nUgfteimOSAU6WMQxhcIMQNVpZ/Yd5kTpysmJldCiNt3fS2vP2o1fmd+tOhCG\r\ncyr7CLqGmWeM5EntsbqEmExT67LA3i09CTrqaHVsaNViDIRAGY41AEcab99b\r\ndasfI/6d6nWBvosO0VROivHPtDa7Yub0/p4AkMhm2ZuGa8wmxhuZzmvhzEuW\r\npKAXc//XaRx2OhAcMjDaaSx52K1zjEIBcn3KYJ6pb8LZxyOP22ZEDoCxj0fa\r\nw5fN33VE53o4V3aL6uFLukVHLByq9uS3dKs49ZPIiOuYo+dNbA6I70i0JPRR\r\nW20hiHY+Vqt4xFkMATsOYGb/gz8N4ZJ0/m5vfw5JcCFQkH9eYFjH4RdToakF\r\nNyom6iNMY6xPtAPgb4MmqNyTX2JTa7U5dgppGOTK74oiZBjMYL7/fM2miYXc\r\nUVrJlf9gS3yXOjoifUGzcFjUPPaT1uDToB2IL4f0M7Tno3wL0Z5xxlMAUaHl\r\nMEOS3zod4rBqQUhiwzO9W+pF+De+H+TMis3eeAJcaTl3GWws5nlnpMLvXEAb\r\nhYa6mokrwW15G8RroXi3j6mKqi6p9Z3BJGL+MOp7B44g7Aet72D0QePyJs70\r\nif6mq9ZoueNK859V7mrqoy6+7uqg+YZnk44=\r\n=8CIe\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"82eb282fc07d1d6a8d0c7136f17b680a0c6d5597","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.267+82eb282fc","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.267+82eb282fc","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.267_1669673651947_0.525534753207924","host":"s3://npm-registry-packages"}},"4.0.0-canary.268":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.268","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.268","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f868489e34f38f736581d57744cb1bd9bbe2e2a5","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.268.tgz","fileCount":88,"integrity":"sha512-ujKQOvoLGp5uxcvJkeTkU60RURq+Yeh+c3S5u49gGptO/SiX7uDwfaoNzKpnArUTGIM6t92fKEdze0p2rJ1HoA==","signatures":[{"sig":"MEUCIQDDLdVfTgCV2V13jauYLfGV5fFdKhb4eZDCKJ1fpHTCugIgYl99jYzAaV6vtPpz5XpyE6/e1uVOPEqFdLMqtgDW1Q8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTLTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpCrA//V0Y0CrvTB2MZNU9h/TOKaOYUOKaaRRwZdLiaN0dLl/KcKvSU\r\nw2l3nv+W3Dasm83IVDCAIA4oz/wB2sVRwqvI9gczD3Q44lmxk6mDH+7BEC0Q\r\n1L/+VRpfwFkXAqfoIWWIHM6PYctYNLLiC/WPaDaBiyL3lGnPFapTSzY7D/hT\r\nnEk6FQdLIcGlNdeRft3tR8Vy2oUyfZxSY6kRKIC+LH93dr7rou9VMUnQtYR2\r\nAlsH9XWNZGo5n5DFYs5Tk+02VKLeLD+WOcfLtcZUXrz8RQgNdp6/WYUz1N0f\r\n6DNTsDLeKjwYK+11dXaQsc7ERy5JZM7RuqXJ7f0YOoEvEgT06yeE4R4FUWis\r\nsJQ5p+2OsuN2weCnsUQmKR0ToQn1Kj5xVGYMnzISU9oyfVD1lfqVpZuvLqJB\r\nXxnhB0EYJg1lsbWHTL7FPDwep8I2bWW12Qq8HX58OOcKFz1B7PQWPIhgsLJa\r\nA31bVV8/MRTburetmu8icn3RXzHQE9bfAXmvhXUPqoN90QyWRi0q7oVMKBhO\r\nflvNXN/Mkrkc0+7Ezz5bJxDpv4EpQh6ZTacFw2b8W9pQANAbmFl8z4CELBvh\r\npwDthjAZZxU5knpKQ9euTOPSHjh0RlZ//idu5AeWF3TAuHnBP/i04BcxPxMm\r\nyy/W92BWVbKPr5wI2ej7yglg1ayAz39vw3U=\r\n=Y6yJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"83176fca7b13fa78063d1e05b3bad4dfb48c6d99","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.268+83176fca7","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.268+83176fca7","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.268_1669673683728_0.0029683096138277687","host":"s3://npm-registry-packages"}},"4.0.0-canary.269":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.269","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.269","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2a6018bc87e388b6236f5bcd4e76dd49716db645","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.269.tgz","fileCount":88,"integrity":"sha512-BAv0nsEXLCOBCb1gWsPRFhLY/Bk2JOL2rx0uKpwP7zd55RjD2HMLIRJR+2q21c8gQ5KyhX7mKDcPfxeVNyNhWw==","signatures":[{"sig":"MEUCIQCAv29QoKu2L35s2kM42uKzjrT7LLeh0093grLJVN3UwwIgZlox1vPJNXGHtpfiXx1Og9lkqqG6TGn64thC89fyOCg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":239481,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhTLmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpH8g//YMOcOjAMJKFJ+tIB7w/T+6i71pFrkR2CL31eIMe4PxAlrxsJ\r\n42vxnSrYMfOBD2SbWZ+/mf9IH6TouzWU8h7ls+gzoqGwRamrJxK+kHtOndZt\r\n5Z5yzpCVhP27uSY466z2KOdCrmMOVM52vtkyGNQ9od5FiV99ZUHFQcyOYdv+\r\nC/fP/RVU4vPgEAycW8WwZqL8YQdQcpK2Vt63cot7p4lrDvu+5fFDoHcDtHJN\r\nTO5kB0ctAgxszfd4Jksw3eqtyKl+OgqDu2iPV1QzIgnxXdW3y4TZbhLzLMja\r\nzzY+hF8bPA+YoKeJHSw56ToiHvIzm+se8bKgpOwv5nQ1NODOU4wWRMzCoSKV\r\nxs0JWRomlfbSR/erAf43B8XXyGcavEmZErNU8HsRyk5Eg6ko5+vMohXL1QDI\r\nDBuzxC232IMuQRtyb0H+emhlxcxd1avdoxnh0moxsH5hyRytmH+P42P8VPzh\r\nMRpwpJS+Je0HiRErnC5ETdufMKz/gwO96GYdNp4tXFhp6yG9NH2SYYZCDTdB\r\n0g4dD4LeY2s3WTcYdQFYbAE8PaRVkmMZRprSXli/Ns2xxJAypA//PJQY2kzc\r\nYZcdPvEG9R1UlDf+p3ykUGeliYviyAih4pkUqL3Bg58/VdcFRl8uJFyCqcdH\r\nInEFNyevggzYPABFL1D3gEEBZdZ7mW8iGUI=\r\n=F36d\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ad419b957f73558b0692d8ed0902f62343f9bb48","scripts":{"test":"jest src","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.269+ad419b957","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.269+ad419b957","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.269_1669673701912_0.7117838768233333","host":"s3://npm-registry-packages"}},"4.0.0-canary.278":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.278","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.278","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2a58fd799911c23a3fd0816abc47fe9d3cbddcd3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.278.tgz","fileCount":68,"integrity":"sha512-e6ECg3OiJDNfpYiDf8G139V5OnOvZ6tjtlVJEoNhx4d0ZpDEwLel9SxQ7Mw6fHcf/58N0UrqLErSj3ZAP0v6cQ==","signatures":[{"sig":"MEYCIQDpLd3paBailqOonefcsuPgjr5AnOmFqiWLeTGnipjzNwIhAKJrmYRTDklOQeow9bVrL1KaQF1jiqTW9FMKZqHYMHqp","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":205139,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh6zpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpUew//VXkIeEvse8NbH3mnHgxAz2YHlXlQ1Z4RzYHuiybxzSkVIrfX\r\nSV5Qs9BPnMCSTcFurL+Gh7SJehWBnTzZLsMtghI4J1jxRFrPm506VJRz0RBh\r\nA35pixtjPtzMxlPbvLj4Ulgghfn5c+uhPevuaCK3Xwro09btvwdSSqHEQfNT\r\nqY27lZUBf9om/d6j1zw9qwEaT1BiATHgX4y8XKGIiAD6V5E9koNNbC+y4nyJ\r\nD7tqoXTF3Afk8em3B5g6ajrQqEOQcblb7kR/NW0qtUjyFK91k9JGIC1GYIwh\r\nrIeEEJQoqIsw9LpLiTiSIu3nc2LVmDtGdNSZoRYMOlsoB8NVvpdgKWH2HHYE\r\neziHjWWAY4bevsCWEJ+k3BcIB2Tkf7/SWJn5+YN0SwTODUPhYEN5AcysjJvc\r\n3l4j2I5jptFXbomhX64vA17nTidY4/iuJOU/a5YRxT13fYHv7b8D9+lGgLaq\r\n4CdwEkkzVCi+G0QkT1Zlf7DOghqQEIpzzIrsgew//46CheJpnU3ZSxjpwW06\r\n9Yp7CgDKKT8xFNuhuOF+KnPDapYgxzOguIFinH5mFPW3tdo4dyWHHGriFJuT\r\nvhu6g37dhZ6qKp+nl7GmuGqCHD+fKbvWbusEdQ0UUOUlRNmjwpmT/eq17D7+\r\nVHMpMcZapw0PgQKkcTc0xW0rXjXjbhOcb00=\r\n=ReeA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f25125a4cb3dfca64c69bfd297d4594d33b32a77","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.278+f25125a4c","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.278+f25125a4c","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.278_1669836009763_0.9783379660622407","host":"s3://npm-registry-packages"}},"4.0.0-canary.279":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.279","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.279","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"511cdbb57484c4e30844a7c75e4de90236b0d032","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.279.tgz","fileCount":68,"integrity":"sha512-C611R3tKzrtxZ+Bm1BDItC7mNHWq2r9k3qsMTicQxkmWcRjdE4xeZAqyj8it/DnHWIvYjwvqk9qC7NTN8L+Yfg==","signatures":[{"sig":"MEUCIQDqjlTt5x916tBUrbQbHE0r/OT0m6xcIyCEjSN/NT5N+AIgH93M3sKIwOEklu9xUgQ7NyDvZ9Nhxf+ZEj3gxZYruh8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":205139,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh9IYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrl9A//YjafmTsQrwxrOup6i2h37qcdf+zp8bujLem3s5loU+VQ03DB\r\nsZ04suNGa50aP/+RurAbAjVOU7NZhHkBrb7OtanGnQkAElMS5WtwUo8cGvie\r\n3VeCPCALIf8JsRJp7mJoQcy9TFGqdeYRzIjhpRlf5w7v1ACEJGUT5KqDEd9l\r\n5Gk9avr6Lk0UHnjl6Xz9xgrggzbLr4gDcO0Zs4q1cQHPfnXbIFTJscrOM5xM\r\nUx0qPL0JMLmtc5tioxA35QEoEHRH95AvF7qtmNn+RHY5yLnYspKGYIRF7gWV\r\nroJTBoiF+LDzV9F6ipo7/B9L7xKm817K//HE9NQ3f2TDEKLs8xNVIQ2JzPyP\r\n97oAA889oXT2Y+h99MWSrrtLjx+Bcd/p4UMPy8hS/jqPYl7h1j+TsuElzen8\r\nzy/WeIpYASqSIpS4w71KWfs5DUY6p16qQbUG2X3qR0kA/2OzioDkWyDEKCvZ\r\nx4rMXoArpi8iau++vyuBqnlT6xeGtIe6wCjG7s61Mvh5PIFEOtT0fholNjIB\r\nnAM4aD73R+4YFXKo8+LRIkOVMeFzDVc5DlFZ1ps3wb02fEWbM1p9FMH7zed7\r\ntaKR3QLbIf1y+SSuwZeADKE+7NAL+a0/ifq1z3a03UBeo/a3EFnnauenaLH2\r\nH+QHKazzPkspzp00berHQ9UtkCBZrMALRnA=\r\n=Pgje\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e0cfed48e0d35046a93ace47d8c2f2c5c01a5764","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.279+e0cfed48e","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.279+e0cfed48e","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.279_1669845528551_0.7751675630222656","host":"s3://npm-registry-packages"}},"4.0.0-canary.280":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.280","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.280","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8ab0f1b61707992b3ac95a561bfca4baadff4e75","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.280.tgz","fileCount":68,"integrity":"sha512-C+UStXmOCf4Gi/YBGHUmUNXFZfKXoIgE2NSfAWvvo+hCpuHe3fmVf+M5msjH+TjE8B/K6rtL49g4OZkm6vObbA==","signatures":[{"sig":"MEUCIQDohP5YeeXpKuO/9m9CbHssj66Rf0954BE3Rd125TxZzQIgY9yPCWECYvHFVUlOaTcNMVmZecFXh0i5KiOaYbr+0uk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":205139,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjh+poACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpvnQ/+Lrp7NDylztEjIyfXEckGXliLscaj5rK1i/NwgdpAl1b1SwAj\r\nZiO//DKttSa+PS/GoYjFiEHrX4lNeOEMQ4KTpVVPRQNLyKs/pJ8EJF9MYxiM\r\n1uwbK7XAerfGlfSp7zkyxMtYcZ636bbhjSomOQZ7T1zxA829cEgbmonoEiIj\r\nmMBpO2jasT99LcnDF78Fm2ZjYvKMOeM1OFGEvUCQjJNP4FOAzyCR+ovrTxTo\r\n73Aw52YBOb+EXGHiGSeYCKQpUYyTG8I1s0FesuvN8zWCFqB+McB5hRwuL8MQ\r\nE8LRLnMI9VW92hXOvG6vduCKSNaqQZYsTFQ9836PpujrrDV5rTKIh2m2R2AA\r\nuPy4I/C+SqS/yp8MLN9nEk8XK4EnTJbdQ4mktKANlvF1qVWkBJdQASW8hYSk\r\nIGzdtKyggJlcap/36annA3F4n+6UDO+XHXlsBG9Ck3RZTq2hM4RWIdhUgzwT\r\nGmkpHIDRMr7o8+enyyht316ZSEHZElOUCDDyNntwZMLcN4386YGxktW6YKO/\r\n+Nb1KjkTyVNlZH2umpeJH4dbd/ompskffpiPKR46F7ioExWDop1Y5rdpsiL7\r\nlubBiZpVtRwW7lDslfrhygnowHQWNw8V/BlHSHzLYbkAVZrGIXCsXwpJlq4/\r\nYVT4Un4pbCMLsVUbwvWOleTea5mlxOPTBSg=\r\n=jMeY\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"99c86332709f1b20c5dd7b9a5e5091a4dcdfd001","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.0.3/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@redwoodjs/auth":"^4.0.0-canary.280+99c863327","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.280+99c863327","secure-random-password":"0.2.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/react":"17.0.50","@types/secure-random-password":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.280_1669851751866_0.7073636774019953","host":"s3://npm-registry-packages"}},"4.0.0-canary.304":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.304","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.304","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d4bb922164fb1db62517bb0f7b3a50d4ebb4eeef","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.304.tgz","fileCount":47,"integrity":"sha512-ME0eV6+9Z1SE3xEy4l8zQWKJhhc2KPiijx5YL0EmQBUguk+OmoZsRXHm8pUGfZNBMH4ABrAXCjCyUFW+6yjPDg==","signatures":[{"sig":"MEUCIATk/3G8lNSN2nmU7dzTiYaHnbRFZI85rTxXaCW58z7YAiEA23gD7HGH6baI+lYL/bBR90+fSag4+MWbhGvSZsd5XN0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjj4oPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqsKg/+PAFjg1TIQswHcyyP8W2Z6hQxFM0Pa9dj+CW+kz7M8hzBzoqu\r\ntLR7rFTGZR8du+3n6sRzN0S7VcKSXStNIqlkZySEx38qtjggKQafafkN94q6\r\nsBtJT+hl3SDCGH78uqEHWtON+J+nl9iy4rHE8WWRSD6kGaTKnzHe8MRmj4mg\r\nHbhT8gAhxT2FIXhTfWput9YogyPr3RU7rjhslbel31sxmu/kDg3qcEn5ymUO\r\ntusVlom6JPey6dAJa3vD8MD8gs/TtAZrsI/+W44Av09eczlruJUnJ5eQ1fCt\r\nMFT/4Cvzf1FHj0NpbQRHY7iUb1DB6L+5Azh4EGAR9masUI8T5GNQ9+dN01Nl\r\nyeIpf0Q0C4GWNjvHA/2yBVR4rytzeLTS3lpkHf2ekZScRTopZl0S4aOMi6dy\r\n6cBiQxXiujzyUIQ4ZReBbjNeEdpdwszp7akvAUadieMk5eVK/YbXaPZnNHaY\r\nfJJteu5Q7WuMKLBiFsWXlpxvSTbjkASfhpjb+JYb6ZyD2yh4T+GoY0K7ay9n\r\nAQeHYLGyu+AlyGztzojHigvCHysxMah+T2x5jqJDPA0TAr0xDbrcl0vQ6QLB\r\nuR1/T4D0winnDhtzmpNJkvqSLqsICKnhsANpF7u2l98vPjnGU6yirVJUoir3\r\n53I2jO1EUbTXAbgqPSxFYWrw+JN8+AHogyY=\r\n=IJDR\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a897cdf2c9bea1918e604be576e7288598bfc93f","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.304+a897cdf2c"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.304_1670351375124_0.557478655913952","host":"s3://npm-registry-packages"}},"4.0.0-canary.306":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.306","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.306","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5798216cc9b90ecdfe4627498f2a99dfcad4aa17","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.306.tgz","fileCount":47,"integrity":"sha512-rqHtvH2lyqWi765p27lwzb9JF8wbCPigWymoz1u2H1q7SHBExQHXqT/Gzg6IhtBgw6GcpfruMn+UGXNF/qTWSA==","signatures":[{"sig":"MEUCIQChV7z+y68WP+l3OED0ZoKg67DWKHdqbyFacWnOoDWw0QIgAKkPDcuBCS+QKpyFA2Po/2R4DgAyezGxuLX4ZLERjWY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkCtXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmphqQ/+MBEQ7C6U6xbO97shT6PG1cBrsUCck7MoArh6uCqavEM8VRa8\r\ngbjCBp6r5DjbaldN76HsiKPsIqqEKCq0vHieep/1kjQKSXu1gkqf0Mb7D7zM\r\nE5l1dNbF2zXwzL+Blk3odlURp1V0tPezFmSECTjzb1Jy7fWApx9mTc3T7Ztx\r\n5xAvx90627Ht9jwh3ZHTOZpCFgSgtkZyEBLfgIbLGSNdkBiI11O7OqSTMNeu\r\nAXoc9tHIOb7VthC3TLxfXtNrbD2TRjxri1hWeK9hcICOKkfiImgu7w7/6w8q\r\nTBgqNhUsN1P2N4L+lgC9lme+xSEf+u7tUJ15AxALqFGpVsfCKFV6JR+4ZNKr\r\nIGFVBc6mP9rGUndk32HTilIdY+nwmtOBP4HajI11GtRvFs6uM2layPdy/IPl\r\nuLRlcuS3feaucjwlgp/wkFOD9q4qIgbeEtcUDo8ckLNRcPgaJGNeTp67fb9W\r\nlTo2yb4LagIpVQ2ua72anv+/p8LcfMMNCtDSUmottwCNmG/ih/v+rD0vUQxL\r\nYHV4DxE6K33zfiM4K9v6mHuskYNVtr2lbDRvxjvzLZCzZGvDqKllSV6iMeno\r\nvtZsnqAiNCuM2L3pFNWBw5pVQItG92nIkGdQ3G1runOce85rCinAPK24e24N\r\nvOpraPFZo51oe3deds4mCh+9j7aI2n4Hw2A=\r\n=8iSn\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8dce180c0eee6b5e2847da8951d684dfa3a234f9","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.306+8dce180c0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.306_1670392663404_0.9754569253111545","host":"s3://npm-registry-packages"}},"4.0.0-canary.307":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.307","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.307","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5b2da6713507e3893d8bdff059631312a3d99b32","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.307.tgz","fileCount":47,"integrity":"sha512-dgii0r4Uakl5UKJlsXa35ZRHgXVTAkKBo5pM6rQlhat/fRQ2UYXAyAQboOLA2pU2i9w98adC+Ly7EqbANui99w==","signatures":[{"sig":"MEQCID1AsG11iXxIdIxGTQZhguX45sXBHUPPo5Lmex2K3oQrAiBU+bG97HVY3TOIPz2gy7lfByZ5zMkqhhJP16aqXYX9qQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkDjnACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo7sRAAm5GEbeeQ+XjRJxKTwrM3v39ljTQQsp+DaBk0PwGUouLKSmNg\r\n1S1i5goSHi9zXW3pDLeHm2VrjMuZN5Txeh8YkEly8e7140Rz62OaMID0eL++\r\n5RitnGbOfqCEDBVQhg4S62GwTJPJLHnqI3vUyqBpQ6+I5FvOliHThkZvAl27\r\n8u+NnlsMLwFmrV1ee+5JUQWPk/l4cwktmNntMOwis5a5RLzwSQMBD9xcuS//\r\nvQETz2gO4hxZFQjhzDUXDH2vSa2MtBTlRecHAdE8t1Au8xzUmfikBzN4h9es\r\nlY4tywFLCcaLH0lvjK7ykQIv0i0Z2HRm+BwJBe2c8OsvfIZnUTSYP+g6yvoI\r\nt8tp8ScCZo/wo9ibcfTEHJyaHBtia3tPzzq/KqzojqpRLiX2dyjWp4Au+x+K\r\nwfNcZzmtdqe3LKKfr8brkjR0XqL1SkCe8d4ef4kn5voN5k4YF+8qoCq9fRkd\r\nVFMk9YptY6e5EsFSprQpGzYczYgQEsC+fp7TRe0SXrgHUF+AVatjeGRtSRNB\r\nB7gzxrw5ld2lMMegb/Me+3Pe78FeqFzc6Ji6c6FmjOWSmBIPybCq/nXdeeKX\r\nDAk2rCUwWdj1+kn47ejFdCctrV0yxHcHK8lM5I25MRq8ZyHFzDJnvcMP96U+\r\nyhvYUZUIYry1qQTXRKCQ7C4Sp7+vnu27bsU=\r\n=BOkM\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aa2f6786324c3cfbaff5667c5f5d1ffa03b63e9a","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.307+aa2f67863"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.307_1670396135502_0.31458361788339606","host":"s3://npm-registry-packages"}},"4.0.0-canary.308":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.308","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.308","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fc0835eb22b967abdc0759f3a58e78113b997cce","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.308.tgz","fileCount":47,"integrity":"sha512-SZJua0UqFn29vOkh/2nskp344IUbPuf7wr1ekLPRD6ptAYjzqBqBSKYQp4KyJXJqX0WvwYal3WTmvcsw7VRN1Q==","signatures":[{"sig":"MEUCIQD092Wg9vQI8FrMPshe18G/0Fga1V6E7TNffYo2NoQ/dgIgQIzDyfULiCGGo2ArrrwaEPVV9+Qij9mEWZMIOmy/ZWQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkGVRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqv+g/9GTPMEobeE+7UT6fJ+EAFSY+cFxiHB5VuwUHBBNFwJXdYTWu9\r\nggyrL3uevHM8+/o0Yp78n1ygAx/FWW3oNfItrDre1UzE6/6xWB2NaO0tRdnY\r\nVRY9JKAjo/AuUadzovaw4PA1tY6UtFq5KG98v15jMJPdjQX9sjl66I3ChvLn\r\nTsCpslK97gZFwfbyST8LkBzTuKNvgk7Mw8pnFFgvQftJUGxARDEA9YspRAkM\r\n15yxBkGUzD0QyMgkHFwM05hNPte2TkmH7iFfKDnRkzyks1Pd7pKtEGnNVXjr\r\nf45Esu0SO4KH0Muss5Vtd+N3dRkEUcrfsWbncUCJAJOP8matsx38gO15PTEF\r\n6qVkXWal0e8qDiQ3WhJ+4+fS2KcRjxvMQFqgwQjuOHRj5dJPeRq9JOWHu0G0\r\n1nVZKJPNY09bLgIFkn4H7OHpKJ0uJGYcMp6u8i1M2sAirWBBlxgMMGtLlexR\r\nDN/ToKa50KhNlvzTzOMGylKTDdQTBjBQplRNSXX2xCYWbtixLVLTSklIB4eg\r\n1H6vPRgSA5407cShTJ0ZZSalIOyCLfpnnic7+QGZgfxRYt2ozLTljPA2Jhs+\r\nLBsjYQmXnjwTTBnFsLQeXGqncNEDM6xM9kCxkCytqKcVZdo+5hnrAM0ZkWLc\r\nxTOCJUol40el3M+gVkrUjNW7GpQLqrjTaeM=\r\n=LTk6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b7aa70a1948a57e42c83511399c64eef82a0ff62","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.308+b7aa70a19"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.308_1670407504962_0.2749216826900778","host":"s3://npm-registry-packages"}},"4.0.0-canary.309":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.309","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.309","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d90cb18e454f03e4aea6f7a62769eac6d6dacf98","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.309.tgz","fileCount":47,"integrity":"sha512-dYkgZR+Ia5pzWLNh2gaM0E2hUP9I4smIHO5XARquwkVbw4/zKfG2DuaaJUs3WlOz+PWWEQIAv0G+r+bRE8mTgQ==","signatures":[{"sig":"MEUCIQD64ZFHyLMRFUbaiI6FL+rUW7UEWZSiJ0of76Q7i7HD+AIgQkuvQD9/VTaUs3utMEQU/gH5+ZeUnnArSM4SsJp1ZWQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkJ+DACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqj1A/+IxKxKoYS/bxAKxh9FKbM99FIS6nAE1AqwUBvKODWJOkLbqgJ\r\nXYEVl/WyTLn8owAuiYw8DNwdHPufsIW8eRQEjKjtdBhE/O6h6PSjdL6ocrLG\r\nTEMjl8ZBUd7V0VHWY2tEjBt82JbJ169SdDTKl77csIkuiYA9o2+BK5jaJZfy\r\ndhZJbcD/J8eYKaKLmDXTg+oML57+sqTIjibB+iBxGYpwOjgjjm8GsbrhB3b5\r\n8XzxNfgXGADmA4rHJDCX9lXCbavfZu/4NbUSvyEy6lsX1MnEjSZAmCSy6vgH\r\nSXAVj6AswUAvqbjCjYnua9vER9DrZhQv3h8wjt7osVg2c7ciRAnlzKhA+Uao\r\n5pqr7z2vuA8gr+T5x6SKjujBD6sQOBtBtXwA7412CN0MSEdZlbr//gvCULmk\r\ncYB9h4+/lTumnxaYJn6VW6sFmHkn1E3bXI1PCut+6M4rLnsjYLM5kwlrrNID\r\nE74QYAxZmGmQ5rd+lVtll6DjKr9wy8l0NrV74F9VcbG2FYNmVwWBdgwXsLWG\r\n+c114Ms6GrvZdapgcbPNx1gkZc9UNR1/asDf4CBI5X0UCOHUCz7VJGPWL6ra\r\no+TmRXT424/T4EclelY0Tqbwtv8vLQ9EHopuz852dGZCVhVEwJ3aBU/JYZSu\r\n1qCK7OIYyW557lC9lzQdYUr/1WNCO4fwaCI=\r\n=jn/i\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ea5e9bc23ce5d4f8f5c1d68774adaba20b899aee","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.309+ea5e9bc23"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.309_1670422403038_0.5625723844645143","host":"s3://npm-registry-packages"}},"4.0.0-canary.310":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.310","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.310","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3df509eea7e3348ff8184d3f6c04a7466c079c54","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.310.tgz","fileCount":47,"integrity":"sha512-Ps4aRVaNbqY4XfiL6YwSH8KDPzfGnD9DwyNXZOWnBdKCoGGWqvZvYeeDsR65FooZwRSaoRUV5wRBsbQLa3rkMw==","signatures":[{"sig":"MEUCIGwpo77ljsw4SuFfdioeW4vRQn9yIOTp2xbXAVcRdQlxAiEA6keQkSufjsb4OReAXFtnsd5sGTcPoNNivRPyM/kSXrU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkOt3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo/Tw/9FwWvkGoAD9M7Fif3vZAg1j94YNJoBw7fOpL4D33I4GBQcCtK\r\njakFbhizxvP5wbZznfJ2JIUEgUSyfVxCINOOg98uNBO5u/ugKKaWxaRoHkWg\r\n17LKE7vQ8CFou6Go8iujZsyJ6Y2hgG8susHFFSpA7S0B/wLsyowCktQukr4h\r\nPd3hw/+MFeblrZ8rBWtuy+aqSlvZiH6r8GoMpdFRszXPxrykzbjYGDXphGeZ\r\nteToAF8+1oL+XnsnDHwu/FVcS/V6h18OuXQffOTuFOz1BW5vzKjYB3M9rwHK\r\nwBkfg3tYgbUx3Rwa6tNB22qsRvhwJpceKy4tFC37nW7GN/80dvNmE9RdouKI\r\nu126EUKbnjS6+71/KxeJG7SZPqRl1BjWWutWRjDiNy3yXFxt+eJw2pyA6wej\r\nMuSegozdwyMxw/7k8od0G5ggj/q3yv7orfC9BbsrS8C5NQPM4/V3p2Ybrf51\r\nN6oLXygu/eCMNIoSPHWZcm9HebwrCvuPq3bw65zKh2t12+wmbF4EcUz4mHEa\r\nwjk+b3obxXUyeqMx6my2lVAhv2G6mGF1M5yCnD75T+dkTf7sqT4EZnL2Vv6U\r\nA/3n701+sZ9UDPcisUOFc4BCN9aF+Cd0rhVH66k8QIyvIlm9FbGaTolScEsk\r\njA6iBgcZwD/2QMmDrQFRNsSXTtRBHdkUqbU=\r\n=B/g1\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"c273a476ac687d8cd1bd71d90c377893330a8f74","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.310+c273a476a"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.310_1670441847225_0.05903220810943788","host":"s3://npm-registry-packages"}},"4.0.0-canary.311":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.311","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.311","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a95c7ddd6d91bd1d6c8a036b3c0f1975d65bd8e9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.311.tgz","fileCount":47,"integrity":"sha512-Je09t2ejCR9TxllSTSdRpbHyosJVmZrF+/2o+G04eoQ3RTOpMAan/UKWrAPF5Stpf4r8j/PQ1Un0e/iMhg4y1w==","signatures":[{"sig":"MEUCICMR8iIYO6ndB+21nnDTdEiS6OlDOuImHXXxqT3q+YH1AiEAny3rRWaN8aeBbXl2KS9LSZmPz70CsFhyL079u7F0AQg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkO+qACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpqTxAAjrfYqey163HNAvKIV19IbIg9WPs120JQfT4aQii+F8ZnAYCN\r\ncYdEhAeJCQW4GHsS6+NbcI3kPMeWJihK6FyIN5jU7ISBXmvi04A0FrkbUiIf\r\ncuuk5MGSGV7L9o0o+PgpwqfGLXpnFTHUH1euyOAPNOKRZ8OuurOdGBhHyCgg\r\nYf5JQUpJwH2X4EqK8exzIsTPqeeDHSPGEUCvKv3ktkR9K7T3d9f8xAavbf1r\r\nbUewZf1ElV7TLotDrEWRefE2H36O8sd4b7wIvXa3+dpVpLsNArgrC+YQ3bpz\r\nCgHb2RSKf7iUwDxJIq+iJQkh0haxncvpwEgUkq/ByhVEpRYO6b3fyhxoPrnO\r\nDIqoO/Eop9j6vQC+tcov+Gt/unDxshcQz/EhjLIfstIl7xZLNujg3wfnFrvI\r\nb8qlcH+89F5DEIQClWuozf8fKx+/Ub/S5eXyX+r1GmqRVJ5rX7YzHupH8VOS\r\nJnj2xrJkHbZ3iA2xY1VUS6xk/qwbr5R93FjOGZ/ebx0AymHDLTp2Rhw9ZGHu\r\njU1cnX5B5JvXCxef9+ATOMOOy1bh1QJRKIVeptqlDko4LukZgV0vox9ZNTuy\r\nZEFLQImRVYWl/AWY4gdSx6Zoue9DyPYimlv1pzwZGBLYeJmkaGDftU8Qa2vF\r\nSQZTr22+Hzt1g0sRS4h+jZxVxAJg0tT3JRs=\r\n=oqG5\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b61d5c4b388ed33e9853e07b119f081dddf690ff","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.311+b61d5c4b3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.311_1670442922651_0.5628093663581366","host":"s3://npm-registry-packages"}},"4.0.0-canary.312":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.312","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.312","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3ecc0307349cd95e192779d5e84a67a113a97d89","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.312.tgz","fileCount":47,"integrity":"sha512-NjPEvdA9+YqV5RmkN3xTlv0o/qr1hXggptsT1gtyVg7BBWFwTmoVsioG0iKAoVFJDg0jSYtGxSH6yHgCkYSp6A==","signatures":[{"sig":"MEUCIQDaleCAga95LDyANm0eXnxz1nbe0vTtsN6ALVIVO6trfgIgTJbQDpXRWn7bEAzElplCQamPYsm3f4l+PiklqLMOkxk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkPDmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpFZw/+Jq5Ri6pUl2jBrgh8hBw7np8xp3IAgi2Fy34nE0BYzFclGvnU\r\nA3fumJfU+CddmrjQsgHd8XtGA6s/U29K8OXFD3ZREo8iqcEQ5Lmp3XY+pOeP\r\nR6Nzh5gfCNSWXrjok2ORbZQnimNqw7oY4Le1+wCiRhq4NALgTrv0nhpIxynJ\r\nM4MC5vptgVZ48GRsbfsnzydbg0lQUoKqvXzWzhFx/VEzTZuqPfInIZDHX7ak\r\ntyn4b8D0un62k43WyTsZesNgGu8GoxboupxfcGSyXzC/msJ1tsxAHyKFVDFX\r\n+PdtDh//Im5QNIjgQA/vXfjp+nb0QcPs7m94z21k5s6n7NlJR9APvwf06Qjq\r\ntKesyHAgngsyu96a+8LepFmyY78C5aftrl7wHowMAXFPHpqNX/tfY/UN836u\r\n7DhDCTxNN+gsfMvHxtu/YxVtt2B0VmFb2T55EKZOqU/ak3Cwn/GXny8dEWvX\r\nWuanWH8Pik2Q0WbJDBWGcwEiokgzWeIMdRjhSv4/g2jSktAOVhiYVh5Tr5pG\r\ncEofV5AR6Tj3LunxG24nm4z1zy32P4svFaOQhoV0iZ0xFHBskDCMKzJATQnV\r\n0QdUKDfkpxorHHzWBOnNXDCO1MuGBMO4WGi+KvKB6EtrIiJNUn1C1tl3n5km\r\n3QRf/iJ3I07KuGPn9x8Sq2yHgdC74ayCgRs=\r\n=vk3D\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"f6a6e640df9f6ae8321253fe8975c1887b1dc260","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.312+f6a6e640d"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.312_1670443238514_0.9197947017045434","host":"s3://npm-registry-packages"}},"4.0.0-canary.313":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.313","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.313","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"07100e262d68b941ceb0598e07ddb24528b54167","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.313.tgz","fileCount":47,"integrity":"sha512-ftDHU785nZDoKqbkmIRpiCJJCCFHMoBZS4h/KDI3yU8g3fzjVi8GHRiSqywQueCWrlGTdKhbNrtFVUdf9f+FnQ==","signatures":[{"sig":"MEUCIFcoVTnPcaqoUOs+3wr9QK6zGtp3uHPTAkZXyjNLa0nKAiEA+LZ0FaiXqGZtd22xHBrEl75qkOVIwblUAIlBKECODzI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYW4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrqVRAAkv+WzMpITAqNCbdqNht2W0/NdTfiEaewiI6DM/eRj368j9Ih\r\nmYLBbtVz/jwhtFzezCFf1AAsjDshjuwRMYSG6aX4tHMg+PtNfs+JzRaCH5Yq\r\nEJPoovCaUfzxK6U/BPwBlhoPkSBQB7OnoRjQZMBvw0w+LmXGsAXCshHI3SyE\r\neJz0zud+1hU/A1aHHy05TIKz+vVgHhU8oT5rihzpPwePIQ7hIgwl6d2pBh7P\r\nOk5h6zArMsMRQfl3KIma7NFGofawlg1ynYRjafSVLUZQih5Fbo64YRyDY2vP\r\n4srsu5j+Ix1B5C7XKwiHs/FDHUw1FRFCqy8zZcZ2+Qd2ivER8++TCHCOfJT4\r\nLy0EBFXgilablYLQXitLgWx1Iwb/LBKp9k8GzBdx+4wUdRB6kpbK3Oq1N4Kk\r\nMT1RVQUANiLizQGIP8/+8AnSHOWZAVcJTjmS9+v4FxCT1z/p91iCCrmBeERh\r\n6byITf1lhnyTN7ngxq9g0QZgqord0nvxBhrdOwwp2VEm3tUOfzQSfYkVAsp5\r\naDnKutzoDHBL0AYKuy8Lk8moNc5UDlwerou3yiBVL8k4SaBLHVKn9qqjST/9\r\nbyvW+dqCQelfTwMyxDCUtUYmgFkz6QdEsFTP+JsM0n+aglZEtsVe0HKOwE+f\r\n9hTcEB1RgLdgaDGPoGvuTHSI+d2wZ+V1OlE=\r\n=qk8N\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1fa8ffd96659c714684ceab1ec0b42e98d9c6dec","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.313+1fa8ffd96"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.313_1670481336042_0.6501276093650261","host":"s3://npm-registry-packages"}},"4.0.0-canary.315":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.315","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.315","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d7b3a84e1061197ff6ffdad2eeb86ee7a7aa26b3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.315.tgz","fileCount":47,"integrity":"sha512-1nYTL4h8qGLypLsIYTF7kgFrqj4pLm1I7So3AYM+/eI45PGWMjOMRr057nXDHE242YCvih7oTP052dwT5XDdmQ==","signatures":[{"sig":"MEQCIDJ1ijSe5DMtVV39QMCNDnd1o1Kf1+f+Wtr35KGyDfLLAiBuqy+c6WU42mBOfR7KqsXd2Ts5pw9uwiTx7y5TnzYY4g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYZyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpcBBAAnqWTDrYLtDwRxHSnHb0/ryVrmFetSMr1cdOf953yA/fx2q2j\r\nnRWQAwtDzTuCFj/IH4MzJBEgA90zF7EdjAriS8bIlRJfXnmQ+2Kq57uc1edo\r\nQOHEU7q3iaRxiVGma5ZU1DbRsHPZE2SS7xEFfSKkm8Joi0EYu7Tt3hl6jzaw\r\nBLDXkYpihfmD69L4kw/O3fmzv7OPEBxwM3XmItStyh3EyUOC31dbjxBcbP6f\r\nDTz4W+6oMJGcoNC3ozh+L4/TnWceV4uGqFjVnBCak9VfX90DTl3QVDlINsAR\r\nXwm+0yrZ4IWGU3E1Lk+++Eb3rwo0ir14QzpLmkwT6VTfUHlQ7lzhpu09gJ/V\r\nyVodhMdheZ85V5PRaIjJjOR5scmuJFKEmpkTx2NjvPvcKLLVqIAgCJQvyPwX\r\nzG5I99XSycXIfCN8optoF6bvb2/oAIm27+bVD3Qyw9vunLRECCiH5IwYe4tl\r\nMHCdJF6r1toQT9L+7d1aVS/VZnDzX0JBUDa1jjBTeNzZgpiI3DY6qFn+1pRL\r\nIFjvndHdO+f8a5+QULiBcCfD5wmiu9tBBeIHXJL6MHf1wFQz1hA7i02e8cs2\r\nd/SuEUOJiywKO8+RiiVsndeAbk19BrRfoTWUsU6xfzczflcFSxY/x8XqXliE\r\nQ07qM8smCf8m53MaskuealDrM5XOCSsYm3k=\r\n=UUod\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"73a6075930789baa2d2affab1c7dc1eeaf711859","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.315+73a607593"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.315_1670481522401_0.9828418757658504","host":"s3://npm-registry-packages"}},"4.0.0-canary.314":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.314","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.314","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6ff1cf86447b9c2ab88ff87cabf87b788b27f142","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.314.tgz","fileCount":47,"integrity":"sha512-pvK0KZtUlS+NFJoxv2IyLvlKQ1gCDM91/plr4RW8tFYU3Hpi8M5tXNgPDwgoI73310vthu7pd6q2PcsLs5lzUg==","signatures":[{"sig":"MEUCIQDZP4o30Pzj7UYq4AiHfeHRnZ+5XR8EOU9r3b3Jf0ljlQIgPIkzPro8cSw2+mZXCbEMtpyeeV7BPQ5h9JKT9NbASak=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146851,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYafACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqcmhAAoRSTxVR6lY1qeDe7QOqZUQ/A9OjPoIl6PGVYIVb8nB4jdIGy\r\nD45T6uHl/6Dw+3qVat71y9pbOr4sjCyLXdB+uZpPJgnpA/jFQ4iL/YLLr3Lk\r\nZpusUzt0Oesh6Uu4ro/Awx+0fYb1iiuxAwJZEfTA5W3G4Q20KnXl5ytruxk6\r\nrl1EZb6ZgXr8PAcHn7b+eW3ATqSsY+r7mVezp9F1IZucLNct0Bqncor9fi8q\r\na7LRDWMa5SX07uJD2Igaem+b14ckp+oyh1XWHIiElvILnWpbGY/9RvDzYtbF\r\ngNvAIFh13mFaZXoTRiYw3H/4FQYRpk41ofXur4We+OOSF3j/3ej1RFPP0yiy\r\n2eiNHEhDK6b0UL9a17W/Y1/gmkcKABNtLNXA4T6yQVjR8goyUBKflwb90w9T\r\nLFfMDCJPIQrIsLGG29KvZZfvxrxGv44Vj5r5jqMcT1ErheItOKe0pSaEJJHQ\r\n7KfUS7VJCeD4osbYmW/7/rwExq54yWtdQP3mWzHV84h11SIOOSFKm31Wos5b\r\njXYmtTRZjroSgwIpzYhbYP7vwInexPltAMT2zSlGmski9tbUwFhAOoNC6KWp\r\npLsdgND5BLR1OKpqxJ4QRARZJjPxWPxJKegY/rXkYYTGaWdqGHIXR+jilaW3\r\nu4Hj1ESRnq3Hym6iqWw2Y2EsyC2fvuDcu+Q=\r\n=cEVK\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d5c219f2e8521aee03aa26e08225487d85f80106","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.314+d5c219f2e"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.314_1670481567085_0.9972211409156175","host":"s3://npm-registry-packages"}},"4.0.0-canary.316":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.316","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.316","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a5e19f64e10de7435a598a576cc2d81e55282e91","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.316.tgz","fileCount":47,"integrity":"sha512-AWsZVWeXvpg/itwADoZg30F9O834X9jvoA/0PApeMnTpIted8MwyMilSSGtcMajeyYmnqjWLQbYW0EhR7lTkQA==","signatures":[{"sig":"MEUCIQDJjsDD7+o08EwSDXLimDb8vWY/Nh9Odd4KUfXmXR7kWQIgBw0v2ISGSbiV+HZUYwC2fxcZbrh+EgJckXoLxRMGFww=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkYa9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmolRg//WvQmCZUKen1PtmoXzKfExmOMZlGc+hF/WqxjRvdU8XQBIp1R\r\nyQ9L4UdrS45OEpgUUohesOk0K9lBO4uuIh489MyqONtUgw9ffm/fCjywdEJk\r\nt5xbw4i6OpnxAZmUWAluwy64mdnr7Z7M6Xp9Zh/2Pdbh98stu8TNSLERuiM3\r\niLTJcqQywLvEwyO8hpwSSjQSKmTJkUB+nmm/kghvj3Uap0/leyTQAdLh/bYX\r\n7YTnt4vWO6XZ0aia+GibqZiQat5ecVu65Cn+zzFr0+418Xp9J9ncb1ygUF+u\r\n9yJn0ofz+44hFGHTc8iFBwwT5uFuPn/BmDnpITCWCQ1IMxx9MY/FI5ozgVv9\r\naL0M3uW41H+mnKjzYSsZLJzmP+TTecnJYIMY34FPc4ZBwj3WlefozGO2Gh4Q\r\n/Q2u9wcOhAtoTFoNk9oePKbcPM6xvDGSdKNaqmyWZEYxzFK9uz/mVM0H6nAi\r\nqSHLOH82iJUCko5aY8TGVyLZfJKkEOVqBhNWujT0oGwjCrUGG/MA0yLlDTfg\r\nt0UN2Tm3CYPDwYMzKt6PCy7DNFXpT1HrYxPmoQrYH9ueoLdReGZ8IaC2aNlc\r\n9AzqvSQ1TZdiViC11HmFxFomrG0qkxymCxkYGQYVLCYXVA2JfkuF+/hR9m2G\r\ni+fAgetgv99nHpk8sMPh87rT0lNHoMWJEzs=\r\n=WgN0\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e5a7643ee1e57f1d025622e9a3c23ee669952943","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.316+e5a7643ee"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.316_1670481597365_0.5442438143100308","host":"s3://npm-registry-packages"}},"4.0.0-canary.318":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.318","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.318","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"416b6b72209c594664cace5ede31510955ac8af1","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.318.tgz","fileCount":47,"integrity":"sha512-DQksy8ejqxv1MgEWIrZ37dj+x2EOow3poiSEe+BsaWtv2/cgR47siD0aupILkguu3ohQ3wcWqTzUfagYvPwiWQ==","signatures":[{"sig":"MEUCIQDGKV9H0ptgepIbJ0Nj5dTBq+O0PUHPHVJ23BI7b15dSQIgPz0M1q9WKru4Y5Jb5Aa/2ui0XlGv4NVMt6dDnQymrbc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkiFNACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrVQg/9H+qJHJMUOTA3nBuZxcu+ez1/60XD7CacCsl+rQZ4g5a7GGEH\r\ntC3zHFTbsL1AJ51j+5jS8PmUUOzrBmf1N/R/qlnORe75b9bc363oNgyCzFwm\r\nttEfI1Bej5cyfU5vwIa796yUJj3QB6I/5JUvyf+Vlmdycfq2VIq1kFvOoYr9\r\nhJBdHe3QtdpGDAL2ILuopH6/ic/AU+BpPq1J9EOFHpc07LgMP2QQKub/7uaa\r\nG42DdgYvgt3CPfxeAU9tz5zVf/SRUZigPXjosJElbf+1BDbLW1EtPkN0WzjD\r\nlIYwJcKu4tcNcEcG5YZbJbAj/2LkwZchOY617Z+6O3oszgoU11t3qyN6Jj1L\r\nOJOjXQLJpYywKCkcmdWxnoI8N9/naNX7BLUpL0/Xsu2aJOMhkvn5ML60wE9q\r\n1QMoAyHbkpCZ1HotUuLeqHHrrCP+kc/F6/gaNpB+7dlHvHVD4m7+zX4UzTg/\r\nZa7za8qP2KW7sIQ2CbZppeLF/JUeJKNUJl9J/qT5PMQ+2Mk6Bv8nkjk248be\r\n3y+hAgDDQUxVEzj2GFEU3uhpoAWOyxkYLHbKVVwP0+d9gnEKh3u/G9mHsJk/\r\ngjykQpEWW2AswgdwdCxgxehWe4ToSXEUmqENe5MA0ma3rDZ69ySrHCPd4lFA\r\ns7Sv2YLL2Flr3unpEFac7/KlzNnRGYB4pTM=\r\n=RSg7\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fc84893ccc7eaa5f87b39cd12ad49819fbcf9a37","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.318+fc84893cc"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.318_1670521165480_0.11985950238191001","host":"s3://npm-registry-packages"}},"4.0.0-canary.319":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.319","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.319","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"59856f3702caba9235592583f28841251095fb48","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.319.tgz","fileCount":47,"integrity":"sha512-0vSu6kvzrOTncDOunPbsSpNkPkO8+0GeqFRleYyLhOWNJjHe3/DHxcXU4WxbIKhIveP6BzX9Fu4KfVEsrWvz/Q==","signatures":[{"sig":"MEQCIHdVQGHMNnDDEd8lb0Qdwfi1K1+ml38sMutOkAlBJv6CAiAEhJzk1rhJuZGgaqcYM4yRfh5f0lodpF0DmxnrQHuY4A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkiy9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrR5A/9Fzo+ycIouY/n9cVYVYTl9VQA6Vz1HoDVvdJ4InffuS20Cism\r\nqAZCIZQ4H25eSyf+vhRoeHdqn3rGMXkhFOh/WnqCNZjF3Bz+5Kcm/bfwmO0c\r\ndF8Pw5MJLaAMSyE6wWrA/hp2h9YHCZN1DrUsflc6h/lLuK6ORq19S3AsRbkZ\r\nJMVQPa40d3dq9MRzyl3TE9slbonq6/MIK/53U4uLmFeDeqVljJaPNNbnN8gE\r\nTostcPiQn21V+5WD1rEU8BLteYvOIBRCjSXxBvCMcd7mrmFx+5sr+uUHbFrs\r\nUjHl2YrxRfcbKPyHsT2IJ8a9/HxFNXua7O4V5tymcnmFLOzSRnNUcFoNSJaR\r\n9Yl1f5Mi3QtaXv4DmQVJrwpAQtRQW8msaNL2NPzC7Wqr8q+u0sSlRzzGoXha\r\nh6V73GuHgk93C3AZGI6sAAeWBNzyr8+8+hTuMxquPBeabvTrLbCHTa699blf\r\nV/49I9/6H10JeNl9Cqd31bh7Yw1JvS1tHmAwMSZ7SLsa7JUTPUudieuS5agf\r\nYyhFrcJBxtIK4sA3NIC+U50HuYqA3w1PU0/mDkEoXtKEsxiE5Tdi5gzcdvKO\r\nvVqj/v6GkZhrE8erCOg0eBTHdoGWzuVYL4XDoiPyIbBTAW6z/XCNEFCn4m86\r\nkz8/OXcHZ7ewnxJVuOeZ0PtJ9p3leq6lUXQ=\r\n=MoqA\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"867569f2865df108af54dc645468b79d881ace78","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.319+867569f28"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.319_1670524093643_0.6346472668075678","host":"s3://npm-registry-packages"}},"4.0.0-canary.320":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.320","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.320","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5bea33068402afad3a63ce3668500b9beb674a69","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.320.tgz","fileCount":47,"integrity":"sha512-VYisYVgLXoLKixf4xPQsuq4hxvCrvLkUL7jhRgzp91MYQmD2TEdH33rRdwRuHV2Glyi5/rfdsQJ4b/yEG8SLrg==","signatures":[{"sig":"MEUCIDfqXCoAQNvXydz5G6gdI/njXmej2h33aBNWYX5b+LY5AiEA6e2xTNkmgtSTrExwG1a9VDeJEC6Mxp94fo0kAOEtKN8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmZpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrFZxAAgXznA76+k7KZatho3jPxnB2/ZXZV2LMR5y1CIpcQzADdBqlq\r\n+LhCb3CaH5FwlNwW4+4oPA4q/KcLBuqLQBfJ91dh/PXFxcPpahAKUdvlcXx6\r\n/gEz2T7Uh7xxlNyuPPh2eonUJgAgDi+lsDaOC3X+CQyvWoQP7nO7bnOy4n2h\r\n3T1KsJ5YTZDLssd5+TxUIfyoxywgMVE1G8KxHpsL4FCC+KvqDFLAOE5z7ksb\r\nkOHJUG2wT6xqEVf7Q73OBZcBt6syQ2rS5lesjGM91tlQAH42J5lGDU2hn9dE\r\ncQGApiaqDzFepQgUpv7FCaCpII0aRBvekyKaC1Kf7PUEhAzR33EGF1sIj6l3\r\nXzhBRgv5mvdUXmndKc0m6gvracyUROkwVHV2tij3jItgHbKYC+9fYbqqmjOQ\r\nJkLFcO5snXmNJj+k3uNuJEBtJ7zIw+8aUmKEeKyedXhDW9DK5hRYssO0AUJR\r\nzjwYrS3JP9u48c9Ejkrnihh4XLlQQjTIVi7Tf8b0hTyaO6tXzZm/o2ckKG82\r\nA3egboCSSR4ZVoQ9FAEtw6ivbtOVfqEjwlvDo82MVinmIdIeQxCngD7MgvDu\r\nZ/3kf/4obfXESiBGoZHmBHpaJPLGpbbA5pmSqsSIFZQ1IbrodEO2kr9ItAZN\r\nvd6hqxprPYrKIUz1CoPEyq5dmpPfhuWqTps=\r\n=8H3i\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e26feec2abe33b3925c492970d1bceb2a2a22297","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.320+e26feec2a"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.320_1670538857555_0.6854833873596129","host":"s3://npm-registry-packages"}},"4.0.0-canary.322":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.322","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.322","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a0b0e041d1e89643c68f1b90676eb8335c43c2b9","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.322.tgz","fileCount":47,"integrity":"sha512-iCQdVVviv8a3hgsUZKfK971gsZH0okk+qoITYkjcC4r0rF0WvcRI0r3+D22sKLJ1mKvcxDOqv2T/THxrVw+5PA==","signatures":[{"sig":"MEUCIQCr8U2JyIrtaU/MFaGibLrACmCza7l8Iu1NsySRPXK8pwIgRLKlOwtGcSUXa9MpN9tDUvE8Dy4wRfz3am686QS22MM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmc9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqkTA/8Cl1KYyYBVb1iAXeqKRk5b39nmklLSFf/r1uod9NJhEkQPyli\r\nx8zYRcZNrgr6BHA4TngirJMjFrblgv8GBzbJ3Xb/jLD/hbwZ6yXXkMJ4ZtMb\r\noOHaIJBAE+ZFI3V9u1axUyXXKdyB2m+RV6sFb50Ui0ZInno1sE4VfDu9EYkC\r\nfFg+yjq8JHyLsiNerWsU//b+1oJgv+Xtr3EZMK023Z5QnWewe0rzqWboWl47\r\n1nm6tse1dzSzO1+lRUkhaCEmImAWw72r8kr6lELuvr6lWM3xvxai+/OBIOTQ\r\niGz+9vgCjE0i20YoDGrhb74OuJ47rJH/Vf3HUcXUlOzwLljv32x1WwKp4BGK\r\n4NZvsii/hI5qiDgTWMsfvBmEDtJUgDrAT9N7tk2d7vPL4p55ffa3wNTrtrUP\r\nZbOWJTUhWXMI4CBYm2ZRr+gV8s3gt3Bc6rviKGX1gAZ5yqxkfT+G+0qZrvdJ\r\nJwfzXntIFJ2PyVubIfigRgEoizwXstvVlq658w+jCsNs2dJkxYep8D6dOIke\r\nT1slFgS4O+tMTuVmzwJU7V1vTSENBcorWjmZ8JbLabgIEI9K8scqmtEVYYRn\r\nnL6iLxdLfENq5LkNVpiI7UwvINSVavOHgB6OoqaMb7vTQCXzguT4wKI9+BsO\r\nSEuYtMVt8kc8Ht4QuhxPwC/5qOHzXqKdXrw=\r\n=tE4K\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"cc4d4a4e4a23e184389b8f29fe007ade2fadc465","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.322+cc4d4a4e4"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.322_1670539069010_0.3590610954330544","host":"s3://npm-registry-packages"}},"4.0.0-canary.321":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.321","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.321","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"3fcd025f3ef7c604a9f963b40fdb2966b51aa392","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.321.tgz","fileCount":47,"integrity":"sha512-8kqbea0CR9WbG/kcJTZMqAETeK7Fc2d01MzTRViORL5tHR3/7+1gnlcPr/yEI4X+MNVE0Xkj/gATXYMG0XTblw==","signatures":[{"sig":"MEYCIQCgullDLNJq47+YUWvHam7LW7wk+lKclxALSOVNp8IT5wIhAN/cDLGxpX4Bwb98VRqRk+K+nYHCLgxhQP510yKTx7Vk","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkmgJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqA/w//WbczdC9U9pjehNIRGpBZ7s4Ga5Exhj33uho5qfMD2JAu6VuC\r\nua4CopR0tvrIz52BjRs40hpXkxvzIo498zIUrYTKPbor8hWKNpoKz7uu44W5\r\n9y6KOvZeVoQ3kScPjQ0ZSKE/W3WTl0tSbZak45dZLdXnqNr4qDvks3GnoTCk\r\niNnqf1Pe8Dqap8pCZ/prOm5ii/vN4DqWI4rPm9su3OJ119dUtuitbPJ+ABzQ\r\ncTEp5hD6fI07z0D5DEoNNhpEGb4r4WVTNHllLihfxf/y1VvrpckjR4oSTTt7\r\ncuGQxgSbTZOK7ZwZDtjoHTZLuPqqugi1P6OjsOk1NdWcfU6Om7CS9CET7LPI\r\nVk7UE/wSL1wHiZOL4YRjjDPPyh5mKDXDteBn4/21cZ+OsyVfN4Gr9xzomZwm\r\npofdWfdhED9QkBra3agG4a9qEyg+YcqHPWq79KHNzUndNipoCXaRY/RkeAA/\r\no3Sy0/3fSEXiRo+0xg/GUaO70/6HYSH+64JRgU83i1tknAFaOxtYKcAyqcJe\r\nwEg4XQQcfQNuIxB/sYJJJku/+7cftNgshRw7idlm6XFQ9og775vR1jwzC7X0\r\nI08vqqTKrgFkpDA9MCrwoGN/jC1sTWp1oAi74//0RrZQ+4H6u4hW9X1i/p7G\r\nKNnQ5TPoBwHdl+AM0UPaJzYwwc/orfR8nf0=\r\n=GtJd\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b1f242ee395097beb24ed4074f7318defd12d340","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.321+b1f242ee3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.321_1670539272941_0.317703034026672","host":"s3://npm-registry-packages"}},"4.0.0-canary.323":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.323","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.323","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"541e7ee73b1127e5dd4ae91bb6fb30526a1fbb8b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.323.tgz","fileCount":47,"integrity":"sha512-ZUqNsCqC0yN/HjXMQnxpkhsfqs6cU16/zLMqqpn8qUd+3zlEx5bCeVxyRGb3RcnijAvgtvFeBoPwybMDmFgtmQ==","signatures":[{"sig":"MEQCIHNBKS7y3SbVvUmPMf6xQ83MU4PCzUeFAg4UJ6DYV1ciAiA+XUOS6He+F22Ms97Gex4OhAJMzAVzntip2IZVOw/5/A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkrGrACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrXAg/8C1/dbu6CTtf62BMpOVB7nVU1Fb85CgzATLFzs0xtQWFpmUjs\r\nU6OCx8NNUvfOP2WXY67psjiJmR6O14z++HiHKH8NScHZ/vKhUvRg4ed8JYjd\r\nUkQJ8BPVi6ggB4thuQBhkDYj0gryd9exAmT/a+8oBVdIcjwcQDDjzf2Nyz4B\r\nZqkDblQ0TKLAybTCdKdlZlyMQyEaY8fG4YhQOt6FLim5OEWgnpQHAks2DqfE\r\nZWnnOZGU1xmQ5J9AZGgrtX7osuPrN2UuQma5fix8CrNV7FPXN3sYgWUAcXzS\r\nx3RlO6nh3yeuB941rRpJxrspk7TqindHpdFc/S89/+uNIZr7I613xgHFJ30K\r\n2bLLhb7QGXt4kvnF2jCy6yo+8DzIZq9pbiabPSp1k2NQ6L0W16yI7gG7OLHt\r\nHMNns4g0DKAM0r/F2IjgnkHh7b10JZ9lyQsLq4OqeAvigx1iReCJVGVFnXyJ\r\nIu7CegqOrJOmKDTGr+DHqpkSRPq0mg1MW2J0sAgtaWiFqn7VsZDSGpn1eHWV\r\nigBjUcTtxC32Gcfmp60MoERHBxAIxKM6PEa4gTntOmh65qN8XofUgc5cC7TA\r\nv70c4aKOZzJABBLQF5i3QaN1Qpv+0hTkRO8flDfJmbDLbuWzQlEVJD2wVjuQ\r\nMz4MAUy+aNE2YU/0S/wtc+MK+04LLi7kAfs=\r\n=y8Qg\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"1e2c8b748c33baf6d289f54c8c1bc39e969ecdd6","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.323+1e2c8b748"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.323_1670558123368_0.42820439161145196","host":"s3://npm-registry-packages"}},"4.0.0-canary.324":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.324","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.324","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"672cd241cef0c84dfb75421ea6fd921df41b3fc7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.324.tgz","fileCount":47,"integrity":"sha512-LRiJNOeDsaCs2XV+cnDwSvAOV5jiP7Qb9YigpPi6FUDVIlsM343KS6bYICgJURdfEvV+yvAiUCQ6agFOYzQY6w==","signatures":[{"sig":"MEQCICaMwE5xzdqRIyirWgAYApUx51m/15nOlHzCd1B8/i8TAiAan6cukwLgJ9MX4E6jddPb14jGQjUkbmnN2LL3TOCIhA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkrP3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrcWhAAjx1trWBQoNW+yO9vpdAUKuB2mUbuObJ5zhHOMZrgZFBxiHpA\r\nY1W1gKqWhO0K0vAqnPWUhcsMWrKEa6mkIvWY5ZeBL1UROjm5PMTdzJBI4HbY\r\njtR57RrsAlVrHxtPHlDwuxeDeSNm/aSUAlBL35SYL6qkNx/FeUIi+jUhE3Cy\r\nXoIloB5SIAbKYO9DXg6hUqEGCM+TuICH7Ha/jEGuXO9xchhIdKp0c0H4phZ5\r\nfbHdBqLyX7mjlY3sdE5dy/kx8Qf3+qXpq6X71ucyd3NJFJn31oXYWJxDHksn\r\nGJ58o295FnIfa6ozw16yKAsW5cBGueo/cJDTuH7q7frqFc8zdxdXPUugPsYH\r\n2mBaJO7HnXJrl17xFB/e4ddYwLBqxet6CXxNvyihgNubXPxRoO1ekhlDVlGh\r\ndZTzMZPfVayx56dwNfxOFPWUZTiW6f1Rfr3jb2WdfQNHXMe01fv5RhyYMVZi\r\nA0U/A7WqAST6JspjTuMIb80OB4cj2kxiQHyyw+Jb61mb0uxnUXAWmCQZKG/d\r\nPRACdAgstsOsptP71Wik5lgOtCmb0b2gQWhPbdZO/PvtaKTaUzbdyfbgHqDd\r\nVdlxXtDUzbMrsbIXx1PEAE6VrmuH8uL5GzviWTqOT+FnDddJWfkY+03Qsn84\r\nfkTUvVCz/o0ubBTGS9/8Q/npKCdAehMsNjk=\r\n=K1TU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"27b1666f888eda8d1cb76bacde2060846d1a5e9d","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.324+27b1666f8"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.324_1670558710835_0.2886009862478127","host":"s3://npm-registry-packages"}},"4.0.0-canary.325":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.325","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.325","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bb63f0bf24f0a1c70196f74ad9dec2a58a862d1f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.325.tgz","fileCount":47,"integrity":"sha512-t1NJs5rfU7v4n7cT8lHK6im2bK/GbsLdc8P0VNXfBfSM3T1hL8nuEVvhQyAaYQH/jmaIlCpbGqCCimBYPDJjjA==","signatures":[{"sig":"MEUCICv5I0ZFAhW+aZ0HevrnjXvPtZvlZzSv5+JENmhkOxEDAiEA0L3wsReLsTeCAO4G0nYGGyiNaUn9bgKRbAVCchHS/S0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjkwY0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrohBAAgJLwhYg6+zyuLxZkoMasEmF96Row3lBWvBA2ImFls84NjROZ\r\n657nHHqnB6uoeeoVeiYP0+X8mfg2wHLQ6BXm7SsmVQqxMbg//D5nDODwZrEu\r\nDm/o1OJU187F2ioAEILD8WaW7+5kHogluzhk+CwtGo9veqK8rrcx//MAy4tW\r\nJ+Uh2mFGJJmie8QW+WGpTpWFRVaerT7fMjKR2zt+yxRH2izjqHtD6T2Ej2yC\r\noppQE+4OohQu78fQciUt1BQ2fSe0uIiAMEHgy+kYB9zcanjlLmb45BWFcHrM\r\n3G2zkH7wDdKuwlKoux/0/LJhJgExOKl0PVLVH25IcYrzvYGmhisU6MWj0pzq\r\nxB3ZoTkFpENvTp3QKIF/BYBIvHxcsdwXtCnU51kHlbGHgregVlTYSgeFsNvj\r\nc+3elD/0qV9XGi9kKWUeA0Pd6QA6QWK4wTYgya+Lh6V96UGw2jvjATr17q5h\r\nlu6Q0XQbFzzFPdMtPI2CVGPg/TzqCGBxL3NkRXVWeHDft4jTkvF059iUFIE1\r\nTMzwcCujPVr2xiUghp0UWwUxxgN8q5POI9/HUyiTMJP842mKR9LhBTAPLhBV\r\nHwRIk1dQ01+DEciUICI53seGOUiquoRUdK/7+dJwZS9KshchWobqIiHaEaJx\r\ntKMShuLE1SwuBao8CYzqFj88nvSUaSdPmic=\r\n=96Gu\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b480d88606ce33c4311c52302ba346f1c9b5ebda","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.325+b480d8860"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.325_1670579763912_0.5182516375635595","host":"s3://npm-registry-packages"}},"4.0.0-canary.326":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.326","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.326","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c85389b9f0719f916c8b050588c6c2c6408b44a2","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.326.tgz","fileCount":47,"integrity":"sha512-m5vyRoN+Lz6+Qh75Rn+2uBhFI3pxCBY/g+zyILTBT1+XtY2JUM8j3GBwk0QPmvQd5WFabN1YmeFEJb8djWnAbw==","signatures":[{"sig":"MEUCIGSUAbfEIs8Ft8E9FypGt8Lx4a7XpIfgb4d4fdxCd/tpAiEAlXEXr51iqvxI5Kn3A7K3prZRyFl8LSX+dnvkLboxvL8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk1PdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpgvhAAnEcAqVHgYrSHmn2/xfT03snkX/eusHxdM3eWVM9hqHXc2zs8\r\naAF6nOyIW1O8OC7EB0BCrvchcgFcL/OMvCs11Zflt8jRRkeAf8bPWfesZkHa\r\nhPQistN/WU9RXbHNPl84lzkcw4DIIPLKfqW782G6QjCbulIqaWrdDqbLuRu6\r\n2oKed35oQqkGXmHNqWSvksv121bXNXxkiabCCGEXBvET2edROHiOI+yhy/UH\r\nqH9FWKMxKd+v6+w5CcWtddLg/J3E6cMHy8camfaPnnC4ohzSqmcMw0o4u2N+\r\naf+S0pQMnt+nUoL6j//pZnA0uO1/FuZmSBEXoXqZbJwROIvo0jyvdaBYQfEg\r\n5gZZbm4MDo4Cymit1Jos7sn12cPdceWbH83qFYqKPF0sEngWKetOa8D9Vhmm\r\nGTNeu2722eNNNO9vzAG3vr0idrnXdmYdXZRIq+XwCC0N7BBXnyM7KKPScGi5\r\nWm3dMTHPDegSLVlxsTTBJI5xGHeCIJNoHmcvbqHw6uVGGnhozY1DzAXuOAXK\r\nURfSHo8L8Yq3jlB1x3JUXhfq67QbiSj5omv/vm3UycypCAbWMOfV/RAef6Ds\r\nY5tnhHPh2YWOtEA+fSl3h9cUEnNfBwxnYd88gktBhFXbQc0kvsLwvFTdL1Ty\r\n6xSbYsXQv+o5+G5qSLcjkJclpl3oYL8IqXM=\r\n=Mq8B\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"808fb276433e9e103bc939f65fb747bc31376a20","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.326+808fb2764"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.326_1670599644842_0.2677672505785731","host":"s3://npm-registry-packages"}},"4.0.0-canary.327":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.327","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.327","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"98b8f75f318e2300f0387bb3f61cf6f17b4168dd","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.327.tgz","fileCount":47,"integrity":"sha512-SzUZcE5ZYYATerjPPgPUhNVur6rdYXeMp/m6mqhLvHKg8vDrCC5NkCVVRt/QH0ABDxmQ85zGV/nGshYVRmktWQ==","signatures":[{"sig":"MEYCIQDt+x5MwtEsLbbgt18tdAZJUhkn+Y7Tc19jApQPsObyjgIhAIl96blAfCPaEdwkHO4y0VppP9TWJO23FnlG1Tj1oxLr","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk2nAACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpg6g//cx4WExjAcrww8Cq8OVkcXoUfAVDyCTXQ7kwyq7FF+rN7evho\r\nzzfKrgbkVedKRi6r2d9f/m+U0AyVrGVHMc4OgCGj78fmytOB77j2tkgrcT37\r\nXQoaSQJxGid5AvBLremST3yoGKp5SyYlYMesig7q1JKx2HjmIZhXWHv6Olk0\r\n/waeIHRWXUYoyc1oSjBxpWMl+aMIDkKxr43i2X+8ASbQuN0S5VNoxYHWl4X7\r\nn3K98W13/Ky/IIBAvNT3tQ7lrIhGTm7BfY8THCLAG+3K4w5lCaRKlMProYFE\r\npYa2r0hgS3BEKQ4zDZBWKfij0ESF72fZtwS0n4CMXkcdIJqpqwtwzkTDH5ff\r\nJQCgx5KIWZKoqzgqJNoSTHYFo6J4xnSEWnxJ+xHUcV1i48d9ofmK0H+m88pr\r\nlcVUamWEh3DUumZ/jPXlkVQpy1HiSZrrocQqDSHDhMauFWKa4XyWG+IeC/gI\r\n3ryLi5NDxp7T36ejbTNjb0x+1XCrgr8Hf0GRGPDYrk5XMPFo/aoBYABQc/RF\r\nSLXSjQzsPY+913I7PGfMb3H1Al8zb4BW1fKMoaA7ZAKtrOcV7K2rYSy0/V8T\r\nABtrnBd0m/GYpW1+2qrmEZaD3CqmjC/x2Y0gvuiEtZnYgBd/vcNz2tCbw6wE\r\nKSuWjpnsSvI7RuicSUQCLZs1t/DN54IryDM=\r\n=8LVn\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ff58c53fa943f942d162f50bfeda5a69e02f2ea8","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.327+ff58c53fa"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.327_1670605247829_0.1295628584828752","host":"s3://npm-registry-packages"}},"4.0.0-canary.329":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.329","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.329","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"f041f12dcd93cb18b89fe3ae2efc09b3144c6cfc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.329.tgz","fileCount":47,"integrity":"sha512-/sok5+RCw14unntZYmdu7rH4HVW3uPHJaA5vKmRT+2k4v+4FzOiikz6O9x7z65gR4X18VymISYXWmK6ILjwUMQ==","signatures":[{"sig":"MEQCIBecDR1t2ltpKvEXYfEu8bk5zvuM/85UlsWy+m4mLuBhAiACPioRQDRagjlPtarp05qZ5ykLxpnkU/DN2JBjLf6+EA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk2rBACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqbqw/+J6o9nxCZsmgYsQwpq4oexziwSmVBXRCtm/gC8/bFEIpSiGIu\r\nX/Y6W+jETwDX6OpNBrIQ+AFIv2+tRsxkAzlx4czmqKE1Eudc7jN3kLSE/tGc\r\n36LJev6m4BV/Zwki4pEPIEWo0cv+dU2EIxPIJanSM4cudU0I7/QecmPAL5Vo\r\n4SlQVP2MzBiQROKZXfU2twAQzmzdVRV+VTstJQ8cxICqG5bPNbjt1wsQ2zK7\r\nELNkWWsfJ6Em05AThttMbaKFYRmE7y7gCE3orkCQo2ZAzIsgKZO7BSutFMvB\r\nxpAEWxOeWX1MiiB3UlL0dbBFR/tBHeIxlhaoy7VVY5UJyDW/6wOv2Ah2fzuQ\r\nLa21LJuFqYbOvIqfzdaGhikcQvZ2tHsthoG1gp6GiudCCQAEyuh/UOIT/bPj\r\n20fWbclq6sg9p+TVYlN6SqsmyEsRFDLQRvxS1wzT283ckva23lQpVgi0Tmbd\r\nxUcI6aSx0bumtOfJJFDI0m4lBnM4lt0MZp5zjA9HZKhxzdAsOLipr/Fsu05L\r\nojiNmI4KqelbB98HnsblE2P1lbSRwmLkCc6os6uIwcubHUE9EYlCMrH1vlz2\r\nJkGhX/8Q7krUPSkZCIpWpy2Zfp6sZEiZiTQW/j3S0CECIAzE1YN7r/JBdaUF\r\nt9Y8GjSOgsrRDfHvleID+FibEFkLvIXhD0o=\r\n=y/aU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b997c06f2228a8a73bc6e1a2ebe98e7a3904b004","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.329+b997c06f2"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.13"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.329_1670605504751_0.7247310608492619","host":"s3://npm-registry-packages"}},"4.0.0-canary.330":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.330","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.330","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d821c83b720e29d7f25965e34ce6428b3f83e4b8","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.330.tgz","fileCount":47,"integrity":"sha512-YPknwsNhfNak2IzzJ8oZJXGDuUWhf5np3Ese38JoahBxmSvG1N+gqpDzprRsIJjtfXVN3pQIOnJQjb+yfzYiYQ==","signatures":[{"sig":"MEUCIQDD40D1wcgJsfUEbOApdExpU1WLk/AweJmSDAZtugWmrQIgAukjQHAJRm+VA9GByTxbVJKcmG4QtUQ8/jD08XDuyA4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk4UJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmri+xAAgbM5aA4NqYzIT6NxOEu5B7MDNfgxipR09aLQkPKQQ2Sg/EH1\r\np8Vz04JNXY2ig22q7XPe7dbc/hL5cNtkfO6vxHRZF/vc4kV6uN2dEEIG1CMZ\r\nfuHteh2e5R4rPOJJ/QdjayChgKG/2wAft7wgFZTBu7UEVEVpjDxkyfaq4tKI\r\n/hZwumT6hKGqQmKBmy06czruE+so5B0bMCO0nSmLH2Jz1hY0mkgPLTx3pjFi\r\nu7SDCidqBnq93v/Vn/RVWfeaw1/YecJxMrNaNtXlyev655vh5uCRQ8Z8nmbe\r\nYXBriG6mKpM29/UUpHOwf63tjvKmIT2c6/2GD9F65uMh31ejsQvyKVdJQHme\r\n5EyTBvLTCTrgQDbwm2JXV0hWVO1iJorSBL8K9tQRPan4CwhV4fQF5SgfLdGS\r\nJrPZVAdNGP+up/Sa6wGsc5kFqqKprs9YlEBPvaRP5REAG+WsmJgogro+fWDX\r\nJRo0v5fVzSPSkBdpnfIZl7f9TDn+6M1p6t8Fhxqd2VI41Ajr9nD9HAWFaN4y\r\n3EgpFm1QYzFSavYlfmxh1orHCyZIomm727rGMx+F+VEzKIzNyXM5aJs7Mb0S\r\nM14bVQenPM2KLdPpqYrzIsaeWawqBHWBID+IGZLX18dBEjwQENsORTxBHRaX\r\nUB2ZSQWZyA8M2GSjWHuZhwk02rUJ3PVrxow=\r\n=Yxpk\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"05c8b66ea9637412ddb377684cb90872db55fd9c","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.330+05c8b66ea"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.330_1670612233093_0.7591356548732509","host":"s3://npm-registry-packages"}},"4.0.0-canary.332":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.332","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.332","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6cf8dfd3d274658c7dc53314670cc1c5ee94d27d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.332.tgz","fileCount":47,"integrity":"sha512-+49Nd8/oktEDQEb7u2/fSvCSI5OaZKvkMzcGtE21WZ8bYdDzutYG9DAJmeR679vTWz14GhA0h3cLraoSKouw2w==","signatures":[{"sig":"MEQCIEDlnMODwPaZpFIvTtD0xwBzPcro+IjxFBOPk3jcSzE6AiAQHBayol27cKpqzSdqYki/v+oYCYLHJDjh4Ixm8jp8kg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6L4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp5Eg//YpDBgJZ7jkUpNrPbu7LY0LFh+eZGb53wN0yAY4h8MV1d+i3h\r\nng1vWUP8ig7H5/Y+/Dlc/35VQc1vyX064r3HbbdVxb309THSqL2BcEFWInIs\r\nLxgpSqITtQ+VgYscTd7OOIbp4GbkQG89K8+92tHNtYhciAAgYBtINSiMwfV1\r\nwtphtFYdo5nhcbDfBSGeLoa2QAvR61DYjIQ7XibN/oovXyAQyPKSe7A8gOuf\r\nMobmm/poKjyEfMF/jK4ZFGdFyRH9CjfbZM5sJ93OdB8hr8Q0BbL9x9EBG4sW\r\nNKw+GlA0m1u6IWbSIpw2G9shhpWsDkHiKpVdGcsgSwBZHPvZa5vl6Ks/8y9r\r\nSUwlM8RcMEmk60B5Xb0N+TUzI4+CHmfPgNtvaodx/7birtCUBsqJBLJOl5wg\r\nxenzYd6UUzVcUOvw96inTmxiTGjIBez4nAbwjsZo5s62pSjsCUeorC8aExck\r\n5GBTqFnze7gWS02ZOWRjNFJePaKXznX295o+qtkXSHIbjCMFuM6x0dwmSu0M\r\nLFU5VE5jxGKn+lisZPC60XTi5Oi+K00btSJgBLKP/me3rL/AJjb7ULqegY0m\r\nGayWadZ8OlO03InK2GdB33cOOpIa4yope298e7IGoZINvxnrlspeMs8LB9VO\r\nvjSSW+d4Z8nSOh8c/mp4AuLLKSKR5lR36nQ=\r\n=6HL8\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"e903c90927a9dc062ef0aad5ae3004b556d4cd26","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.332+e903c9092"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.332_1670619896211_0.7207027243459314","host":"s3://npm-registry-packages"}},"4.0.0-canary.334":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.334","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.334","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8da37f7799806ca0bb7f726a7513363b200a6050","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.334.tgz","fileCount":47,"integrity":"sha512-wIzWD0CPjkRxd6f4I8/pzDtQEGE4MpCi4EPuV8CR8cJNeYeF5aqQtQi0b3KqgY6dX7Y80jRr8OewTEZ/qjxnBw==","signatures":[{"sig":"MEUCICtd1PTz/JADQu1Gl0HzYjuBBp1TIwEJTOtSIxtS2jFQAiEAjOMiphEIQTd/u1vgiUsMRa4kfIO4dbmst0slm6s7eRw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6MnACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrSRQ/6Aqm0RMk67PH+t4Z2DCZiqvPkCP0qlnz3gRoMREltkw12hiEy\r\nDafwSHlFgDynp0+tLWYCN+xuPG4uE7CO/3Jno9yYqSm/xWGmEBVrs+5U3n+q\r\nHJg5Z1Bvg96JCcl19zKLlO5V7oPUnKtx6WJMPGf28c8D5n4lcTdma8Z4SIMq\r\nUU3ybRa6zzt/hw53wQ+6FwkMawlGxM70SMm7rmGyPgqGLGcim918fLnU8D9f\r\nhzpVBTTcJqgF+W5TXSakwdXC+iwN8k+hzYYrtC283WEtvAC7mdNAB81R1ETM\r\nsncvPX2ZAG3I9WbCwxEmSi9U3Uc5z6i2s03FJr2y7XmXIxREBF9LcvLV9e4y\r\ncVfcZ1uxUybv7aph7GNkxnnx/N7LvyIwub1+1JDhbJJXFrCGfoitXeijFkSY\r\nR0lf2y/EdCjDktxuRdnmh24iaZRjF3V6xNVxvL8ak6QH/TPhnAzR1EiYDtAB\r\n4d2s4K+SQPGIDWiXeHXezvSjfKbCxIXq+Xal/A0LaavwwA2X0r14G3uMxkxE\r\nIBlKZUigZqhF0zYThVIyPiDKKZJa3jAtktykhNP2FfrLsllmEyda0ut1pBzu\r\n0ctN1kfihcTVjXARfJzOLEwdypT7WFOyCwAi4tfHdRdvm6tSB/RQuOkAP2/T\r\nvqLSEPMLbIooyfpP3c/vIXyDaiRxLcmkEUw=\r\n=8sYi\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d305bf35a9360e6227d98e69a273ba38905b6110","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.334+d305bf35a"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.334_1670619943628_0.6465300392703304","host":"s3://npm-registry-packages"}},"4.0.0-canary.331":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.331","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.331","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0df25a94a9a3a8a369a5c6376f392f630292cd4d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.331.tgz","fileCount":47,"integrity":"sha512-SYMVcyJqcTiBabhjekOTYR/HX91Vs9HsZi25kclvepaEMXJM1GcRnx1QmZ+e09lVfgYHHdYSdQISNlQiGF3U/g==","signatures":[{"sig":"MEYCIQDoY/KEone/vPeSJ0k/Tmxsk03Y/Wj1zIt3ioqZYmVrHQIhAI6EqW4OQl/gZLy9Dk5iK9chVGb0UQNrIKBmxYu422LL","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6O3ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqtJg//UTe4ZlrHxCJ5zfYK/0kOwZBvSG8G2ycBasIUG9UJ3mN5Gt7v\r\nYF4LgmafbVe2WpuM4L/uAD2ef9xpPmRiR5pj2cL/nNVZj6t75tEOeHEIDUWK\r\noeKQUEz9Gk6TvVhB5nhpN8EpOY8cvlt9iAWwaqvq07uE6xPlype/JcEEFwaY\r\n77uClO7QVilSNHDUwMKGekeR+5f2/67SV1O2a13N7ydC0baRTl8Pc9grUkhd\r\nBPaiEKS5Xok5ix7zne4nuFiPMYGGKXSPBCzr3FMkQv2BNKUYb8TuK6b7Z4zV\r\nGbPPLbMLyxWJb3WIOrgeTqRKk5czIrNKxsq5elbK8LXMZlGP/5ze+aXLAFUa\r\nVxmsxZXmviEdBr4pqOQzqeGjSk09/FGw8YFnjo2iPV92rR9mYQ+LcF4aPEf7\r\n+8gEvC4zghBfhZrUcXGgHxBVPBo6jpQ8n20cHXkFbAS5HolA6VpqaBgZr2Rh\r\nhXC8e5pJ4GASoM/kTHvrW7px6/5ZxX0+bsNMFaRGC3V7u8HjVcqYhSsK7TGb\r\n+1V1fJAwepdVDRg3DtNMIxTaIS4UjWkFg/dLOqTh5PnOGyuIOsSob4INUN4l\r\n8Igyk8h3xGfbJM+Ar9PBJeL4GhUppBLxBP+PSVKIqTmysxSXTTM3EgcPq/FN\r\n/ksjl4kzxQ9kbWpIXdPP7BHuSjKIOOxZMqw=\r\n=Jx3F\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"44e28b657df90ef88bdf63c2b89d1c723d739a57","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.331+44e28b657"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.331_1670620087219_0.46683864522568963","host":"s3://npm-registry-packages"}},"4.0.0-canary.333":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.333","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.333","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b5bfeae5384ec1eda2a6e1a081be0f6b1f0d955b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.333.tgz","fileCount":47,"integrity":"sha512-J2ybZcyWx6D729d77z/qr4JwELcqqVbBkyXJmamvA73rq2tbEL6WemTyxjzZmXb31yway93vU3JVGh+0vjHzOw==","signatures":[{"sig":"MEQCIBemKFA81l5Y2x+7Ns+rZC/HYkQV0u/OC6UnABpkmI9gAiACNb/7B7XJT+5hS7N3iY8RAlHtS2mMImyxdxgvu4k+Nw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk6QeACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoyCg/6A62suFw+DueENy2EGhwaiE9ZBM6FyVztQ4DsEvHIhIV4/wuv\r\nAi/jCu0G0RzlEV9iDVHRCn3A4Yw0bzyFaIpThAErgDv1J531YbgfrrThMkVb\r\nDUopKzXfxIsgaGeWL98/g8I7pQ4tEWt7yT6LIY/LFF39LPJyW9JESSfacER7\r\ntk1dw+HZ6zBkUE9oh1m722pHvsVouTiJKI8G+KAq38zU2fZOgWAik7tTyzzr\r\nm43pq+1GAi6nQHeoFEY13pukR3zK1f75aHzYIkWO05Mg5s6UeuPb3ZsBn/C3\r\njA3FhfSEyaiPdkg5m0I4vHZWVlOPLldQIZF8LdS7f2wD6KyLIL5+CQHUR8ev\r\nIvnvjWfP7r4lQJGkcr9q2Nl4hkm10uEt6qLOW+c/A6O9hNLShNiTakpHzBwx\r\nAb3pdU/kZxh+el8CaX0iDY2tXMOSZdLcugXFyZmEGz2xCndZY40bsfqEBozD\r\nL9Y8txritqX5f4tCq43lr7xcVShns/2IGrdxX7B+Oku5zASm+/gCIbMB2qGz\r\n9AIhguNBUrkjsUtPMLfj8kJS5cOTfPvkC+YcHRBPo+3C5KezryQDS6mj8McH\r\nt1StPYMydbTh4hPYObntyZqxqCKfDaluEO1fNUrE4B/7OrwiM+M+XJL1CW9X\r\n0Tj5J0fGEkMd3S+WiK1fdPArrMndU6cT9ow=\r\n=6IsD\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"61d5d587986092488e13d37ca3c65e052096c58e","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.333+61d5d5879"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.333_1670620190718_0.3042005467178397","host":"s3://npm-registry-packages"}},"4.0.0-canary.336":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.336","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.336","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0e7638e92b3f0e2a14483b68904b4e9470e79d9e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.336.tgz","fileCount":47,"integrity":"sha512-H9lQH+yitTxSSVpVfB49XQdRdOgYpkWhPXmUYLwnllX3ePkFc5Xzv/7a6iyj6Aa2sq/PikUygjL7THy/5StpTg==","signatures":[{"sig":"MEUCIH3bghyLrjiUJUJCTPXKFFekAivLw8XZM9b8jVVXwLorAiEAxF1bFiAzIKiCjvzLtAcuXBQphS6p1GMPht86arLnqfo=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8SQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoHEw//WEB42losRRNbJF1Vc8giurjYxlwMkrUz0/8kYmSnvD9ksx65\r\nBtdivRHmanMcQYVq7347O98A6jKbKLU0wmuzT8bieMioo7dway2ak5rIGZpe\r\nn0wYM0Nld0r6USvh3UnGaBXr9scVTiyAxle2YaUC1a4e3t4YhgYGZooILsbm\r\npUIU2W67IbbSczvIPELHUA+oHWe4SYpYx23xdli7KBLN8rKqH04m10tG1m9Q\r\nmKIqeeeOGP+Dzyq0mf/jcCflVdGzhHMJFv24jPUVa8XTWX1Uq5/3I9dlq9mJ\r\nuAUHNSAzG7thG2l02z5KPibG6aC42L9j2shxKSFA1id7F//flwT12JNlgs6V\r\nTfKuG7b1lqDNbIutDQiPtDVO0MFYylhZttdXV5H+bSBmHD8KiUOMEIW56bjb\r\n2HE0ONygn6L94s1kO1kaFsFu1AJ1jWlJcmSRp8LAQp2nMQE4ZZcFq2XqKWhK\r\n72bsKJcbtCzcVbFNvQ9ZpKNppmchJm9WqiCLtnRI4qVQrX1LbS1roRMQ6/wl\r\n34vry4ANROhhrQEqvtVc6q1/Ali/MJCdgg4rBXrsSOVz4EPGBd27Rkbvv0YF\r\n/MHuFc6SvcdYsG5in546EcutLGaoZtAIrxKxUeriZdepqldioGMKOsO00Thi\r\nkwBVx56CWTti0nWbC2FcbRpxa8J/trcI6nk=\r\n=/IhF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6895e7286184d2ae6f2b6d3246d99774bd193891","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.336+6895e7286"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.336_1670628495911_0.3245315203636381","host":"s3://npm-registry-packages"}},"4.0.0-canary.337":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.337","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.337","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8c65a8f1dceaf1a924e9ec4ee29b86550bce1f5c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.337.tgz","fileCount":47,"integrity":"sha512-yxXfq9VXvsx0wehkYAs2oqc8v+N8b5q8hz+1WmYg69GFQxExTWfc6qGZqa9dzQEYsjgTb1UAqYhbQCi6OSou3A==","signatures":[{"sig":"MEUCIFS92l2SGJnQwbEzym8y+BIdZCmWkqwDGDIfnp2D44XMAiEAsz/h3aXt/Gmh3sNII9sc5giWz/ZjWDB6Vt2eNL5OUNk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8UiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmorUhAAl08OjhCfTyWL94a0zj7JlnLkGYJrKJg5/S89vouFF3e/IaIJ\r\n5BI3rTfjTSsWglsdP31sShCX4xjdYl10efQo5pNzZsUHUcddMcwhh9G02Z2H\r\nzNYGD37jcaIPaRfLFKtsd6AH+wVs9UBw1pdItd38dE6lOG9XXgGSb4o9WtD0\r\n3v7M9Rk9Wu/juCQptQTFkTWNWsJm05wA8sMFK71mVtS8NPcplfVHVVWgQHq0\r\nIdwgG7xfMW6E26TigVpSACS8FYeVGGbwFq+LAg5Hfgilsscayjc8h/M9FRw4\r\nKVmp/Mnpkfe82CEh4LqbbJLbQ+DMHqZoPocJ/Wh9L3TukVL907jfg93fEw/z\r\nCGniEmJnzxXQkIkqIu52XJHr+uG1tZPNSIV4rzzOecaxNBZ0MLKXBrJxKJEi\r\n2DgvD3BlwaqA5NBFxRLCSoudSBKJ/s4z+1Od7Dk7dnsw4Hd8YjIme7UKKh5j\r\nwr/esFUhLVZh0MPnNJlH0JHGNByBKaoGN5MSE+cdKOBz5S8+rk0BAPzGc1bN\r\nA856zzcOTpntgaM3NuE5rJVqEK44RjiunMT55376oWubt4R+D8fwmK9cMBE6\r\nouCtn81fKPl8vwvBTEn9Q9t2OL7iX2xdbQH2v8FzBd46ESZ5jtVRY5+hljCJ\r\n/sdMV8AtumZGJaWHpm9A9jwZP/yKWW8/stY=\r\n=x3mN\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"44aa04f7607cbe08db8ece83bc1f24d39c512c26","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.337+44aa04f76"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.337_1670628642790_0.5332162377273777","host":"s3://npm-registry-packages"}},"4.0.0-canary.338":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.338","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.338","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b45bb7d7e45141190d070293e39a56852e728f75","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.338.tgz","fileCount":47,"integrity":"sha512-ECXS58vKDERMY6MgjSvN00HXAhxTb4IX2zQOM8RCD5v3NUBHgfI9qfGsk+IdtihaKMskQNuNK/PYuoUSsPoLfw==","signatures":[{"sig":"MEUCIQCPpZffZhtGH4ASzBkJyTZLqlroMA4/MIRXwIJhVaD6dQIgITVat26U8UfgG6S8kSPjIXF8R878WHAVI0LTXydL0hY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8V0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoK1xAAobWl8SnANBP3pmB0TR7corm9JGFIYCnnCweKGoP0FwGcLGN6\r\nEIV8+IaBa1xUv/9/MywXcFOzJd6p3EFRpsdZSLcDOUuU8pabJTsi/3XiyN1/\r\nOoaavxNv7ADRA8VjCaJuB9BHAWTUSsHTUsIO79tn1SeL+/dJu0wqJS1VoYv7\r\nikRXd32qFDfTZIktxH6h1j0tYwx0pnjbISgjldGYPKbGy2aSva8VfDcV6vGN\r\n+VEIC9Q1vM4uYiqTZrqH9nhEp624HT1w1MPDXrk0CgR7dIaoC0w4/9nMrngU\r\n2J7zBMt17qIaa9Ko5dAfPFuYB+8JFM7+hfQc7CwNjzGPTl6z/0sIHqKdyPOS\r\nPhGnw5eH0OSv3ntJPX6Qr3+/MB8fmEnMdLfIbszc5G0379VAJt+D1r1Xrky/\r\nlKe7CgTHRs58JupfSKRWv5bVSpRnjr4iLiYVthttNSd+q6boFEMphYP7gh39\r\nXkVK1ktRkmRCLSiMXPhnxxfDiueCCssJBh+T44al/tm85X8vu3ZLJ+/MqaNK\r\n8DSlR4W7asLDyThNofOyFUacR4IBPF+x28Y/VLlfEEF8897xtISkRQCGYWIN\r\np6K++poXwN8hIlryy5XASc9j2TFuDEKGFIqQHf9sooWLtNlQEhvjaoFgTIXl\r\n91YGEIigbrnL4eQZbPOCOzoPsMtb1tY0bXE=\r\n=UF9H\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"afeff253347718480b822f961d0cebdbe094b3a2","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.338+afeff2533"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.338_1670628724417_0.29955114694602947","host":"s3://npm-registry-packages"}},"4.0.0-canary.339":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.339","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.339","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"47c411b9e0d4cac2ad6584766ae1af08c5a110c3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.339.tgz","fileCount":47,"integrity":"sha512-3qZ4Lwo4gKJtVrLskPnsXV9txWp+nG1j4kSIHhndpPIlkSZqYUeisLyAzDo4OwvZpijErq3Y3RSU/z3Re0cpOg==","signatures":[{"sig":"MEUCIFs5n6rX0usF/ca6Hbc6pR1i1WbiK1L/sVNjhplKGTI5AiEA3yT655Q8g6RH/iboMYXKpIl3+swn4FhHP0yLl5fIlVw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk8afACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrG5g//TlnMwZuAMJoTut1REGg5pRt2PVwd8sQ/9YoD3MfZi4r6wQcq\r\nk6ogDGo+DtY2V6iD1IdzXS5jH5W9OhPc712UPa36/jq3o0R8LUgrHQE8pMcZ\r\n/ZIk8LCIRDdRBcpouBN14FwQv2JAHDR/K7RBzZFJ3yXV+ncXuwLd3/mwPpgQ\r\ndZOzh4qeTMD8wiASf1VKii5Nl0mLMbKsWsehGR9ipxcymxSH4J0sIzjmOFws\r\nVMEfpJQiJosKHpFI8fb94dSPMUVtJXW6s1nsYXnfBY8BDuuBLdfvlusPaZna\r\njGcIJBhv57SIC311KrW1nk2aCch924MQ46++cP+lbAfwsX8dEtg/jHPE9fEs\r\nV/fTCOvbMQ+3vGTiqYIeaxuCgTnwhWqksjh3WIAJJ01xFBYPG3zGc7ekrDXy\r\nwUvf5TLutg78nv5lR6a6b9281xnTc3d7gxTYd+Vdao4zEqy5YOYHk4W+sixi\r\nsDh1P725jflVdL7G3rchPt9II2u039FLXY11I//X6x4uQufAwK5LwFgUocvJ\r\nbX7GUXRE5If8AoxiVq+OdkzjVEldhIsqzo+qZzBcc3RxYSGiFXAHxyp0D8Vr\r\nwZHV+uAzJqRbdCQUNbTrdXU4/qQMLsBSsVUF0fQcEK5CIfDEvQBofXUuMR1P\r\nlivD7pV8yu7hoq9JefK7JHPRutRJ9xdAHmw=\r\n=wSJW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"43d21d1952978944cca731fcbe862454c5ea0b43","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.339+43d21d195"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.339_1670629022825_0.08839438646196385","host":"s3://npm-registry-packages"}},"4.0.0-canary.340":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.340","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.340","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"21757beb87ef575ae275ed1b416fb9bc353d3afb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.340.tgz","fileCount":47,"integrity":"sha512-sKoa+aNkbohxzUkeFmE0Kbt9H7LBIk5/PLJDbwO6CiCf4XFgqZnDh+48w8xdpt8Id6PDhMWERGjXNZn+WlpFlQ==","signatures":[{"sig":"MEUCIBT0AdBdK8fmQURLK41Lwxc6Zaq0F3t9r/5A+sAVODn1AiEA20Y4LrPF7FxuCRbmCmBTvxpWzuxH26NArpROJq2X/Sk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjk+4OACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpsTRAAkzdgvY1mhY9O12AjrzMlTAIzG3ac4jvB9TvixmoU1Mboc9LQ\r\np+AbDoQMuc1R1Jd2sg8emkOTSQ5gCj0nKKuPEA3LPXiApsNLttQM8tnasYrb\r\nmOzBZ3vEphezcEcIhY3c4VK/m469O2ugczLIBLEju71GTgJ9aoT5EKZH5cyp\r\n6uEIaCxz/9bctqYVEhlhndDvDGAOrB+LxtTL4oM1NvCVZdskgphnR25Dbiai\r\nMqnnOdV5TbHu8X4lKybspogu6xh8tYW+XSdZxCxuvAO+qWFgvnGUGy0E5Bd0\r\nMb5Z3iln5oxTaqsO/WU8NYdLDihNkZYuMIzVNBhg2MGOc9O7b2mMNDOY+tm0\r\nieQEZ4K4fT0TFNzmJfXupFfCmZAKOA0iETfqsAFyizUmiP3PtqIWpw5T85AL\r\nd+nm6jXiCk2Ch1DF524kJc+1Mcll5I/tR0vAUDZHVGenul7ktUqXLYvmIiOD\r\nI9UmxvXBTvrLrRVSpucQnkxKPiv0fPKzqYV/5wuga4kzVN/r+D6MnHJSh4Kx\r\nHJIdwtWN+7ymRedCubhMpL0HMyg4xXgIlBdJSUUtRlSbn6fJDY2c0qRq1UyK\r\nwTiwlnZs513OnyjW5fGhPKdyvcPVliti2sNX+6YXMyVP0Nl2ZdGrV2ODIu5m\r\nHIDsq02pwfonl6CMfszNEuy90Gs0nsRQZgw=\r\n=4Znl\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"9696505ffa17d93d2a333ddc257f8af3a50aed64","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.340+9696505ff"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.340_1670639118539_0.19009469856679173","host":"s3://npm-registry-packages"}},"4.0.0-canary.342":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.342","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.342","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"b9ba0402454bd74933757c33049e25660527e436","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.342.tgz","fileCount":47,"integrity":"sha512-pKKtb1ExCdFT1ddQUKgazlJnw67zDYeKcbcxpZQVxltUdmDIdZdiSkMcrgVilYyxKpNwxL0DdHuZgw1+2Vq5VQ==","signatures":[{"sig":"MEUCID9Bp5vTgIyySf5xshlFfOdLNQNpQILeK9U/ujVhsqnxAiEAx2MgKxaXqwWD1BBIaq9CB7EgNkotYlLibdN3z/51vs8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":146855,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlCViACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmre0g//UwBRBgNaQ0xhDS6Iu4nadKvua3jQJk3hokGKFnmQm9utuTia\r\nXEveaPUOUddLAYXeJNTNgj2kVXbkHo/qINQmZpJo+hy/7AzVKwerIQkvxEUU\r\nBpIFmLfDa8VOO5kifauJSM35vjAOz9BC7Fbu/eGVeW3rqEzoGj/GLl4QaSTE\r\n9faNAitWNLW6Z0tkjTP/8RoTojo+F6pxLltcyIkozwPGDsRf23tQPzynQJwz\r\nX3eASuCn9qnfg12qHj8p4pI7YQeLemCJ9/IV1X+4vX8h8WhSJXd3fge10R8h\r\nlpTiViKV/g7pDrNgpjqSHYJqbwG5axXmsxWwZ6VC0FciQ6n49Q/89It25vvJ\r\n5Tx1nkVyd9EvC02bIbXHYM76Y5ZwbtLF7onSO+BOrM9W+djNITI0fkbY2G8A\r\nEhjqPbMSDS48ANOIp+gWlrwKJsRsWSSSGjMvlvcAjp0aX3+MwmTN+gJzC9QQ\r\nJKE8g/xreZg7TWtOipkZO/de8WF7+ecoQ+JZZsEUVJPWecdAUCN7aH0WNoti\r\nzdTPz9xiv8vMJnGF4ZDT4Co5cAnfGAqZ+GVmlbfs0hLni395ISF1mEy79lpz\r\nQkuH78UTmvV0/x6aM/rdHkCapW6RYe+RkhA2m0sU4ufhuKLtWY2TGc60t3co\r\n9YNX0wFCwLxm+Q0LJDBa05/fyvMsMUD53w4=\r\n=2ptp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"eeb4fda1ed15e9e141957eb7ff654544abd31b3b","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.342+eeb4fda1e"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.342_1670653282534_0.4412715524341826","host":"s3://npm-registry-packages"}},"4.0.0-canary.343":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.343","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.343","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a00e4c808a6f276a547091581bb1113b20ca0dbf","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.343.tgz","fileCount":47,"integrity":"sha512-mj/zrHhWgdpqyuZ6xxSTy/QHAqxtjHUoSWK/ifuDPG3yXOKzKWCUQN3+JecgmHMLdR7HznrtNKx8cgR50UkOug==","signatures":[{"sig":"MEYCIQC6f4+idJgftc4HKleIlreoBqNweRYhZ4d+yybfK1u0SQIhAIpUF1lbmpHIxKGqE6jbQpRtf4pBCGZj+rT5DBAENJU4","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlE25ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp1Pg//UimYrqmOg+srCLPQ3vQ6MlKV/3TtASR+KFZPGxat1kH0vWnU\r\nDjH1XDOMhEc3iSIcXiF6hOopPKuoSL8mNb311Ji1Bc4fjtzHqM1enV0KCLu6\r\nSnGwOhlJ9eg6fdQW+OJKGD0QuvMzxSAeik/QLsbpyfjVvEIXcWh7SHvbOdtr\r\n9R3dgYlcjK8x4oLH7MK+TAzVnAeSWpkAQ6xznRuZmnNmiraWW+2yjLrvFc0m\r\njsVvMBKo/k4TnOMmL3N0rtGKzCjTdUGzRTx9ansKOX+9OvBHxO5LDiYg0dMo\r\n0t7UiK9qgXJAIsrq+j1Yj7Sm03OFIp/q88Cakw8XDvFju47Nv+IUKdUgBExE\r\nkQWgIFMolwlw9bvsVFF43BPPB1RFCK7hyKg4u2Wt8cf+SE28uRjDIDdrHUB3\r\n458mi1E4320AE2r/s1JzD1+30MXOJQMdlNFbFgT91pV20ibmYY7yOoJoDswi\r\nUKuRBgPkLZShu8YSIwAr7BY/aLTu6cKUQ9xCXTCf5HdVcLm7X3q+Y6WdYCT5\r\n4OjKmN5fl2zq+y9N9VFyAfB1DKPnt9BMDK38xW8k7a9QamRKgB0RT0oml+Cr\r\n5q5KZs42NL6sgbh2Lj87cnexUk41N8htnhVZDePaY4Sn2SGSwBHWq9LusdCj\r\njc4VU5wCz7wqiTHgewMdk/j14GirfCPX0KU=\r\n=MjgK\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"62da2df8e9734724304a8a013b0f3ca131df60dc","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.343+62da2df8e"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.343_1670663608856_0.23742539456720357","host":"s3://npm-registry-packages"}},"4.0.0-canary.344":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.344","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.344","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"83acb99d7fc870e7dee5c24dc7d31658c00cf6f7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.344.tgz","fileCount":47,"integrity":"sha512-s3cDFEQbaqJ3zpFh7XqI8t1AFSWxbO5K+vvEsG5VH03tQbV0maCVhK3NEjUfT0Bjxkv3oAoGCkA37m7LzmEbbg==","signatures":[{"sig":"MEQCIGDI+rLgZ/GVeKVidu2FBY0vy3b9//DFVJIOe0WqsVT7AiAXT7I1z119fMXGKRGfE0byEGoNlBh8lFTln3HRNRsDpg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlLJiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpBJQ//Xus6ZRHSTgfkiSpLd4EaIEUh9Gvx4Id+l4SJuG503xNSBNVH\r\notj5MGJoWDo8DKqmEA/inp6ErnOHk1WJviMkXKOsyTlB6FpOspCKjgPZaS7X\r\nsUZ5Ai2beDC+8XksugpTY8VSfnRhx6Mv5+mcPoL9zftFWZglKmbvb4GNEM2C\r\n4IGa4cujsAjWC8OyA+zCKUTf5WlInYQceNf7L4Exs8qIde4EZyFfVQqOoJ0G\r\nfteFTyidMsxKVW7V/vxhM7ivBbyHSjA3ebtYEu+9tKwWrTbxlimlvwczbBBW\r\nLQP7yFsaHlKHFPqWoB743vPtSF84XvHzKJXjBMKJP2tMow4LVxH4rHmxFtZV\r\nwqQsQfFHyRWQFMRwLdW4iGDrJc/MyMg8H/GlNRw+2l+wH5abVehgVgNTuVDh\r\nXo7EBBy9LSuJGEOpg+i0x3GNYT4dnbkqoUSVsC5wVZR3MA2laBmDkhhwqpSW\r\njAnJQgHXxqGFnGEl4qLQlk4K6BvzKVPxOjlRMzGFjLHm0qmogNMm3j2qWCUF\r\n1UxbTO99Gf9xmaC4EBg1v00UUJyrNQWVX8K3vQX/qJVbt5j1k7ZpYqv7NVt/\r\nhFrHsZ4lbVptd2sJm6Dh8mGEFMpDv4Gj9iufIQwGdEM4A0kp6F3B2oQZsMnb\r\n3h0B70MohzObzJUD24aRzUIHQdlAECHcjKQ=\r\n=mQfj\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8d6664cc5bf9f760161ae8cdcc3084612d078943","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.344+8d6664cc5"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.344_1670689378718_0.08548282467592072","host":"s3://npm-registry-packages"}},"4.0.0-canary.345":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.345","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.345","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"a53b752be666ea8117c5c21b87dfa3422a4c8da4","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.345.tgz","fileCount":47,"integrity":"sha512-wptCYFC5Kd7AsJdgcsMZNjETEMeXXNwHK99oaXMLbQAnzNAZcYIFRGlDklL6OJlz8LwNLurt+aYr4zea5i62oA==","signatures":[{"sig":"MEUCIHJaquze+1peCqs76w7OCqpifnC+pPl0BnWiwJV4k4ggAiEAow1cJVLNYmpIYtEwR7HywZ5U6alxKncAEQMlh2VKuHY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlRArACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpamg/9H+OvTAbWWbE7ChCxJbyRn/h7gu7oCEbJ65GwE3uvWCsPHi3C\r\nUzrfWflchyAQcvDAd0R5jUcw8IVQIpjUXc1yl03qpTJzJ7CeE91gFze3QhPi\r\nLLG9/WA4De9+BG6Zf8kXJ2kOih7K2wW+i7zoD1KmWwiJSz98jx+Zzq+6oO5q\r\n6MnihuCqgcJEYb0nU2mhEzI2NmdLcORamBpcRhPYNWmmEdkPjknYBZk559XN\r\nKezIf38KVp5SagtqL8JO9D1yd+jUgUR1ASM8bO3cGL9aN/LKpZsINLlIhHPI\r\ni2VE8HQW57QddM0kiRilEDu/GmdHx/BjRtKkPrSj8MKwf8XhIs89DmieAnsO\r\n08ce4J5b2In5BpxQtuBlJQo2WwsGBakxY8TVfNwkUIiS7Drp8D9Sk8O7uxDv\r\nuZApbGF5zvgbFfJn5a6/+mbTT2c5LWNU4EXAS/XDHEGRntvF9PGiZINAqk7Y\r\n92gyjICKhm9IOyE43v296K0VE1R+4JKHg5ZWnkAOnVwhVABRUr6sFM1qoXEc\r\nfmo9EI8ANqo8NM7+z5JZJpT6lGwaANlzj2ZUhBqUlk/pXxHenfHFZJxJoibi\r\n/fUKR8m9EKY3Bp8J+cLU12779NyJ1mJqLqV1zQ8buYWdJeawMtWXxh3hoeIu\r\ni3+iw1tzeOUYabRCN1kmaLJ5LNQ1Du2HbWU=\r\n=7teO\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ded69a3e9362bcfebbfd6b8be56e46441fb52d68","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.345+ded69a3e9"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.345_1670713387754_0.5691013768499897","host":"s3://npm-registry-packages"}},"4.0.0-canary.346":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.346","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.346","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"8ffbcc0af2bfe38023da3d72bdf2b5ccc1d7e0b0","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.346.tgz","fileCount":47,"integrity":"sha512-7osS9pekRnyuqxcmKEat6kb10X/nsr53KHC+Mt9G2zP4kzokWPApTU5FedzphalYvMyw7pekR8vpLU1x2BtfGA==","signatures":[{"sig":"MEQCIAWMHp1YyqvjZCsE8NABcnstKw2KIztSLyguWplesCP0AiBYfxUlKsyWMf/ju0d0CJgEgcU8B4mY1kfn8v4GiBFFLw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlSLIACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoFHQ/8DOXjHxnk6X9gan5M9m2fi/MpaPx/BB4wFRl+5AfEiWRU5iKO\r\nzmpurOLebYErpewKfY47dK4SUIp60Yf8xQfwalrDTrx07b9+dixHRDGNigCY\r\nfqi358Otu/7Um+Zc3H7BQeC1aFjOopNMmk2/Uo+/1A+rk5DtPAsMEAXqYO3V\r\ny5i5n/m0QB8ZAFgyuNIGCiF2hSe1HbmEw+pYj+EhCZQ+je5DCstWoqTFQaaz\r\nfrG9iEqH4jvp0PMRHVzip9yCGifQ2/+pyB5NSgn6K67m/ucnzWtNZK7p2des\r\nZVpBdBemD6DnS4pZpHAqH98cAFnC7lqD2gNZKogJl/FUzRD3ArrK30LboGFk\r\n/97cRsfoMqsrNPtq3acN40FpD6JocQI4rrBQu3qzQu4a5NU0WzwA1lUie3Za\r\nEa+E2bxxYhOhYRaT1pgS7lmvHYp1b5se660WnXcNb1+zq2y+LzHBoqVqKzIO\r\nKbNy0tblRm6vxEgoZfcwiFLdRZKXyiwsNmHwkh5jRhFJkUVJDr/SJ4G7kFXF\r\nPSrkc3mnlr37IXPqJXU3Es7hqpIOANnADmfMrGB2s/plelk4dqhTh/7KITFS\r\n4dZSWbTzP7BWQ41oJanOyzxYE2jBMtS3nJ/sDOi8QJxwy8PvILfs453cewnX\r\nCSqLWO+KfGj+AZzkv3n9s/bcwldwmM3bcyE=\r\n=A/o5\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"871addd33b370b11c21c734eb59e53a9ad7dba58","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.346+871addd33"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.346_1670718152225_0.01394565101827161","host":"s3://npm-registry-packages"}},"4.0.0-canary.347":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.347","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.347","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"721b9944ccca8839e08495121b60d2f41701c5d3","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.347.tgz","fileCount":47,"integrity":"sha512-ppSNQOYKE4nBWLfZFncZTh1Q8gEcMUGLw3AbL8nbNXtv87xCkO2ZY0+1zHCrvyhkJaEK2YipNTz5ZndZbHLHhQ==","signatures":[{"sig":"MEQCIC6omnPABzS1YYdZu9SDOY/dg1wVUzMFzTYOH0Xsl652AiAJ/PNxkrF1V9ii/4agEHUkMFTZPzNE8VR+Zr8zZStV0A==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlVDUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmppmQ//dWaA9WMJSg2APzHDziSX8PlyMjBpTa7HiayitzCUw5vRd675\r\nfO6rXE/4gMJ1Ko1++6dZNvpQ1/IJStyMVKJ2u1y7cCBl/MSCXg8g1t/Kmzwp\r\nYjgENZ4k87cqZCxTj1yV/y+WcK2rcfTmcAHqwyI6mcPJifwyfraKymSsDfD+\r\nPpFaGupjpDtTQCglrHMN6TnYQhVFJ99B48BMKB4RLgyrcOaxiMJYX4XMN8oK\r\nw5QHVo3D5iiCz/bzagss/LqY3DzaK6aqUdoAmPNJcMlCuAU1xqne34maXA+V\r\nJksI6dZZa0K5wOQ1xHw5Zo5wipm10KDvBb3LGn+W6BC7PUtwXq/ZB8egQ3Er\r\nzuAOVLchhPTjAiuVTo0ALkbm1FfV/rbJZqlFqqNZY5zpdm64ECX8L367+U7B\r\nGXVsTWY/r8RvWNkKdYEYaFjUfeiILuGl+8Vn6mHZzjf/4lZpysAR/Cu3sK91\r\npvOInru2fy4vrr/eD/4UtFn+tx8D1Z3sA1T63J14DUmHcqHQa8JGrDaQIUyj\r\nBKfb9wUYIltm2IWQ7e9q7aNEN5iSAamxLze1RwJRu3d41rKgXwyI3e6RhvID\r\nOOcEfjLJo6DipS5aigwRtdELqDHNmcFjL216brrcpAzifDUGVUKNGyejdUEB\r\nlZD4SbJ3vmyx8Me7dJ8H0ASTiGGIxVH1NLk=\r\n=UYzh\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"fd44ff3f552374eca00d6d881e7e75dd25e6a45e","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.347+fd44ff3f5"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.347_1670729939907_0.3744251161980834","host":"s3://npm-registry-packages"}},"4.0.0-canary.348":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.348","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.348","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"d53b432ec7eed41013b177bab750e519fef911cc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.348.tgz","fileCount":47,"integrity":"sha512-++Kcxa6O+GIFL4MOl0QvhO9764lgkA0D+zUoRb5cEwmo8hPisN2BojhE7rqVjjFjGDebgUcCyWUStgbaVDNoww==","signatures":[{"sig":"MEUCIQDRksD4ShEPb8KM86y9oEd9iMp7JDqq4eKmDlDtFuKbLQIgGU7aHxc1sP7zqGzGC1SaxHNWpi5rEbcBbF+oYYHFnqM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlzn1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpNQxAAn4BgejBP6G7rx9aQ1mf1HSJV1xX0oOlCSiYCij+rDaojYj1/\r\nAvc+F+brO9y9merk+SijA5KE+UQAs71g+A4WhAFui/4iDjiNCpcSTpmQ984y\r\nZqC+LIzHat1G2RUoPVLX4VpRWaiVfG4Z8k45ofJpHP4wz8haxZzWujQNgI/J\r\nw7zwcY6q+RyS9g2BMwriPvHUkFoR3plesc1/J40xDXnPqVISBBOTC2K/nalh\r\nlEJJ1FXkqz7sxsOE1Qpr9kPq6Q3OxNm5M7z8XyR1Y+goIzfgyjynFjIRCznD\r\nNmZcl9CF0FgkaAhPNp6TSPJr0E4hokOEMZ0fmSQtvpQxi2gkBNcmqS5yMvWj\r\nZaMJxYUaRgOtXGkeT9ljYTz1BIlox84xgr4XGmIJ/ZuPzAXYjG0AJior3mMI\r\nP1G2oRQCNqjmAEreiKFye4+mwkE0zc93k0zDeFLnoFkt4vvZ0AeBKkXkQXRY\r\nj/YdFcFs6IaI7ewzJT92WNrfzWRXyXhKZGf79wb3ek/3MGsiE18Z/AD8a8I8\r\ns2TMlGPlJELx99qsbs4NuHyn9zHmQj3pWHw6zEGgL85YgHU5Ttn37KsZ8k59\r\n9wWZWmGvjXWjOIzCm0I/iyfXGdsoEk8P8MElMz4j04YwR/l8t+zFSBI3Imhg\r\nttxdb9acukBOV7D2vFZgf5zFMHXHhWfnXuk=\r\n=Zgok\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0071302ec6b0241f47925d480c41f39ea82340b8","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.348+0071302ec"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.348_1670855157171_0.39888553940794624","host":"s3://npm-registry-packages"}},"4.0.0-canary.350":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.350","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.350","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"c6314d8e1ba1158275cde531f3b5c1a0f94f6cfc","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.350.tgz","fileCount":47,"integrity":"sha512-n6UH+st3LyCXKNIsMPGtkbE57Fyvpy/0Ms6cecv0oIBj5HvC5SEiSRQ6CBN7P9xSWi3sOC3b/wRDxjyfuXHZ2A==","signatures":[{"sig":"MEUCIQDRujXnAMa5GEyYXFnf90M6jQjxd+y3ecqt/4UvRXIGNAIgaULTLgkA3DxD7YmRsYTEivHaGaQJIWdI+NytwcU2p20=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl3g0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr4dg//e8tKt5lkwx87N3Kabo+4KW5QWy10oxc0haF5Ko9oRdNEQpbl\r\nbT4w8c38fRAzMs03SNME5HaHkoRbs0iN7sLd8edPB6CjIoS3UsqRhXQULjFm\r\nGlDOS2Pm+iIucUdSBFFebPWyqgODnMY9imHZJSpieJGnyddmBDmgP4UynQye\r\nvKRyGTU2OLwGn8LMCF9+64Facmg1HIV2rUCruZa34rAcrXx6k2u1YSzE6fso\r\nQunrU1BeSSwQMTr5/GJAztiChVbCYyJnj6eh13/a/vUkb/FAjINREoyRjJbd\r\n2mXFi80KMTt0g/exBDZjhKG5/OrNjDXiOfm8pNQ1RgIporfSNLUGjhBNWGYF\r\nSJJPghGqEHe22CO+uZ8ZF+b5jd35FQ1+Kn7k5g97gepQrTVdK8MmV4o2CHZ0\r\nsmg8iCF7Z9EaQEV7u31nJ6JAMTauXLo2yND2+sAqVwctpM3FJ5rKsO/j2yJ6\r\neNpH8TXGvm3bqh7LW5AzT5CdS/MeZZZsq6Gzo7YQGg8gSEX8DtfUVVGmrKSx\r\nrCiyGOCOYAS94PxTJRF8uqp+AwLuD7ddva4OH/CaQLu0qJO6S6sk6+2PU4Th\r\nadsGe3oiEOnnw5hUAfvD3BjyLdOubgPH8rsltNxdfyCqNr+J/o8/zrIfLPRu\r\nksJQuyrAcfFA2rerkm2r1SXJPsPD6mrNAR0=\r\n=7J4v\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"8de7b4460fe8b81680498a98b1c90c822fd1822f","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.350+8de7b4460"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.350_1670871092310_0.5812440897274538","host":"s3://npm-registry-packages"}},"4.0.0-canary.351":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.351","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.351","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"513cbbca60a5b9a9296dd1a5e51d8d8ff7dbf37b","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.351.tgz","fileCount":47,"integrity":"sha512-8+yqYO5SLVJ9jKw2aV4rg7cuWYXzTSvcqoee2J2dBJYGCEOzT+pseF6SLsoKQ/aviAJNMKcgEO3p3o7QUZ7Uyw==","signatures":[{"sig":"MEUCID3LpJXSHrKIv5/TUvrw56i+MnoZbEOHIFs+VhVDj0x3AiEA1UajBE2qvd5HdCCnuvVvxnvDUcsdD/2KsqWjMV+/yEQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl4sVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqkcA/+JTupShYAR/toxXW7xFyq+mX9oaS+dpugeKtcPu2U/KlYqIsC\r\n05Om+w7m0fFpBIJNGjMNnWlRVgDRgom3Lo3/ielujmBSF2nPLv2ifQGzIe11\r\nqp1AKHgAbAwHP2/vcbPowpxtPE0rgIrPriPN0lOA7vj8ZUyocEXMmFpAFNAx\r\n4KOlazKgGgCO98dupy7ElhVb0rhINIWKYndwxE9pEttmF3Dh+IGbr1W/pDNi\r\njiwwcPRwVTiwAwhRl5GTNpRtFVEkMkk436YEWIWcxc/khBbdeB0Rsj0s3uf1\r\nGLT8IS+C/RA4mrbY+DEczoWjehpM0tOpNDYsfOCVpCyPJWo4jyAQnMbydBB2\r\nrsrWIfufg2mAczxKGpF//5EZO9217ATKPtG8efS5pb99M8n5mzvCQd3dicAy\r\nu/eQRgUJXDYHJN/1XnGAtKeGLdqpHWaSEcr8plQgtHazZmHCOUXQg0qshGGH\r\nu6pNbWwdxiyZ08k9PlUNGTKy8kDXDg0/KsCrClXN2xN19m3VsbDjUAgVZX4Y\r\n14bn+adFwh9EFkTbeGl0ISz0e5cPlp4UziF0onnBbRsRut6Sed5zdIy1G0o4\r\nyKhbwakq62aWk8L7QiIJrhIAW1qOd71dvH0wSCyKCQ5M4q4sRKquO84AKwaY\r\noKNFLk+LUExSW6H8jMq03uff0bIXTGzq/Hs=\r\n=G5PB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"df1b410f264710cb7b4a1419d04882cc4f0a8441","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.351+df1b410f2"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.351_1670875925689_0.09486324205059615","host":"s3://npm-registry-packages"}},"4.0.0-canary.353":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.353","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.353","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"98bca9463247afde487e96c0f4b984c3cb21d4ce","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.353.tgz","fileCount":47,"integrity":"sha512-1pkGB1kjO7IQPo0uTXhJ5TPuSqHuirNgYDh6aTP5VC3btFszavMQdVaHqOb7cAU1YOQ1s//3+dtPv+bd9Y3Fzg==","signatures":[{"sig":"MEUCIQDi+zg+C9RN+EFD83EuaTnDo3vJelBBAbw7i5Tip/bW2AIgQqDqsFw9VLvMMN28Ag5Pen8zqw3196m2e4ATJ7MzXlk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5l/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpfow//evTbPg/ZG0akgwcLxEBNhEwImHoQaqqo/pUcmVDKWlSrCo6Z\r\nraB8hSaJnzYlQTnzO2mlmwDit0fKsO5pPBcXDulU70FKXJ+6qlKtOAdc4CIy\r\nq8cEn4PK76XirocAen8RQFBYHaBH0smzVFKYNdzgQ85Sd1GwKOGmRCHnvN7T\r\ni+2tW9+wjXa170FqJehIQWAv5B3eB13mFbwcAlu0vnTiMVuMRnMNgQGObKbY\r\nwYENGBP5ACIsITqEhQ4gFl/H0x83f3asFAbUWZAC7stJ56blPit0EsuC48bM\r\nS7AwQr2k+S33Lw6GT2/YB1OBUBWdYTD2ayefVUR7i9aaPkLZDxeSdNs4fYCz\r\nqaUmGunIgF4mzU4YQvb22T9iNJ8lPogJkNvYJ0DE8R2FwKreNHT8uNWi3EA/\r\n4HFszAIeb0KVxgWkiPrNl4+kUDOX17/+C7LyK8dfxrCNm7WRYqf20A3ZJbC8\r\nBCHaDG4M6jjpulxK/W5CgCV4am2VkklQPrHdlpmRN9gfEvQXtH5PVVVgEtmG\r\nxszFuJBv6KQoi7o5AhonnOm17gP+43j8t7vjioUeQb1Syv4gT8iK3NeA5NVY\r\nY3otf7N+8DngX+cCuWGIap7U5EAmgF9lQCuaNMB/Ctyu728C/oH+MGsDjobs\r\nvaxF+fMSOvgpMKtXA/Bko8Ael14vPKt1ZhE=\r\n=YHrG\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"b98b2a7aa70e091560d93a77e0d8777f4273a276","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.353+b98b2a7aa"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.353_1670879614997_0.4917089969959021","host":"s3://npm-registry-packages"}},"4.0.0-canary.352":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.352","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.352","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9d0e7baa531c9b7b1d4784c619b4ea390566c233","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.352.tgz","fileCount":47,"integrity":"sha512-xUK7O6BmwYwvme3DsJHRD+Z0Azhj75wLADL+4b7Q+/8KOmqcPrgnpeHjpy9/rCF/q1O245v6/ZYureuLgTsbTw==","signatures":[{"sig":"MEQCIGdp910oTv5GjXc3uOGpEiSAGr4sIf6hKglCKACUhP1lAiAM/AsdaIWP8YfZBea6JHCeRqjwd1rGmFa94v5faJEHEA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147001,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5qYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqCnhAAixAs+avW4qCqFfcbw4n9zwIf6ZUfAylUZMX8gQsnbl0lyKDc\r\nOF3xxtdLodqAPBAhmSPiaudpZWzyiD3vEK+myPy/FUMYDVuU92HMpwZAvVnO\r\naxypTvX0+5QakuSR8ThNPopLCAA435ryTmNZnXyTbCdSNI9e+OdhQqe4bjvx\r\na2o97ENgmBz2AqJOoWojay78ofYkm0zUwXXlx8u98E4Oajx3vL4hpqbjRnvu\r\nx0MZbsk07grAzFcZ1eSCb45kKm6VBXAHuzmftKu+6rltjoImgYXBUiTfX5i2\r\nOTXF0wkU4IQJ35c0ZuBLsnL76csbHB4Xc8qZbOXXp72kZcyW1fFNngeIYgSD\r\ntbRAqi8DxHenHRx2LmLadxFS9zBKbvpMCFXi8aVAhfME1YiH8PjIROqaVBvn\r\n2wYG+1cG6kXI0ckToUIZkZlIJ6ndIloV8LRKaiGZ7DHtvjhTc6lFvhdRI22k\r\nvPydA1DMwiShRJGSFxMij9G7DSG+b40WJiLiFNj3HueOTaD5+sQVIzK18C9o\r\neHmQmn7fqTM2ID++rlCCDNlEGU3epl+jg5JJf44J9tjhVGoxML6OjgF2PYP6\r\nunlZjBNMAu/2hjFg2fcsj6ihHkgXY2Gqi/msGO5LtNrzVZItmchYSGkBchJJ\r\ncTY/SGu2uG1LtKZuWfaeOjLQpaLDx2Fpy4U=\r\n=0/Fb\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"21b6b51dd0e38d5891da1fed8e7c8ffefcdc3d8d","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.352+21b6b51dd"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.352_1670879896512_0.13348142517524275","host":"s3://npm-registry-packages"}},"4.0.0-canary.354":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.354","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.354","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"bb14180581b8278a0569f9cf4e859922350d7e7e","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.354.tgz","fileCount":47,"integrity":"sha512-Ck0d8nuCz/Dw3uLE1kmqMrIxZfCuXyHTm56x4dCHz67mNrqkKwQV6hGLkklx4jxdBfGm9RWQiAOFSM/3IWImYw==","signatures":[{"sig":"MEUCIQDusDMEUO/3y9R5Jd+rgmQzwDYyAt5JGLgSwwDYXZUMJQIgSoPh0SEQ0mpspMbCK81KP2CCu6g+ZJ7x+RLM2ilygc0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl5xTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoYHRAAlddaWmP8EKbddWiRqjWs9dGuPmD8caQxJXtTI2GMzA3ibtoJ\r\nGrQP0yfJhQFwXSJf4rlsccKi/ZcnhlO+WvKh5uwVL02BXkmCPXJWocPnHo71\r\nYg95cRbKq7vqB8kfs+UQ0H9U+wr+nJxJb6w169BCz86ToOmM0jHJO0HiqlA+\r\neRLl6vrvRsfby8wOrOegAXUkIbwBVv8ZkUs09tApctcySXIM6Vs81lo0hRcf\r\nnGGDVtPZZBz0BWr56nihCTTqnrPoYtluxkxvamg7M3i1OsJk0UzRbiWgXzae\r\nceszFJAJUAUQeAYsBq7LMlJltew/tjzK93EL021SKtWKjIFIeJ+j956yr6bL\r\nRr7KK3TmqtYHXmto3BKEgFBV18YMxoa/N4KT7tVzSKTZKmL+bb+bM7R+B5ah\r\nf/VQKqMDxGsYxKYjLq5kpWV++gkgDcMPKNdJbG02CvLf4bqMzch42nH3YFZJ\r\nwp5uERF29Cmip/BL03X9jR0K9IMeJl2MgunH2UsIJkVUqVHzLGDrGcaWdGBL\r\n3R5A80A0m/KgU8hxf4J7oCZ6q6gYc+lKVk/y+oGjLl53g6UpWAF3QIBghV0Z\r\npYw7HG0keZ25JH5JCCBiNUmtQvUUUJF5TAemtV/7LSfq1SnVQ+t0ywlsFvtu\r\n1FubOnJI1t1CidknseVj9saGogVIJ3ZbDs8=\r\n=7QZJ\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"a9fc646485acb068cba2335d1f64bfb16842edf2","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.354+a9fc64648"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.354_1670880339666_0.7742344576827846","host":"s3://npm-registry-packages"}},"4.0.0-canary.355":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.355","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.355","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"13f3a71c5a6a9cfbd2e08f12c4d7ceefc889db5d","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.355.tgz","fileCount":47,"integrity":"sha512-E7ACwWJnqFfDYialokhmjOB+3Ro4+43CR8iYSZHL02N3wjTkdgbhKtzKp/8lrniufRIe4WbzA1m5+w5/2+54Ng==","signatures":[{"sig":"MEUCIQCVYLAv5MM7TeOIxlPZENnnHDpxZc9TeuiH0/zpAHa+DQIgPNWFEddT+yqLwUeN9amdnm3LEmeh0sgIBq1pbpCw8hg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl50tACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrfSRAAkGl8zJipz2ji3Zg0oV3Z7EDF7eTQXce5/GxN7zGEzu/SsyCG\r\nuG/GRh9n6W+go2lJt3ArSp7f0Fltk+F99XXuiFYW9D78oM3wVbEZE+S/1O12\r\nEjpceQ6pm6rcYmd2IbpBnKHOGUJrqyCy4aUASVpulU5uNKWv6WQ/1Srnw0ob\r\n0nE5crVP1BH9waJoEK2j/tsdYQTEPPpi0gLgsc2CHECqT+RLqR26PWOCJUqC\r\n82Zv0IEWbnh1TTD7+QHj+7YRJCkxETDmVVpSRiy7LTF32550uvLeiyHBJ8Go\r\nKb2OB7Eud0HkNYvIAXcNRjYEMG+GCp09sBkueSz5bHZ8M+GOu2+if4lmbike\r\nMS0fYpa9qqskluFvVFMMvQmWzWDVfG/zvCoxaa/1DgLQR1c5HUF93p9ZBAAk\r\nHuENvQyCZnTwt6wK1YeC8ZnZWEPGptWEM0t5iAMqKzB0jXSjvYLOa2VNZ29p\r\nwr6lelA0j9ZRGzwvT+/G860XSsHjKV3G0chnV9J3a4vLm5cFEcuBnunhQfnN\r\niVdKMQIuDqdEWArPetjjhXw+yTrARgFWDavIq3mac3oL16+QO0SiwRLil9wS\r\nmUxzfdAAYE1JgGJpxMUtvEHQIoEvARMQObXe+TH1h2+Bp0LATPgBmNK4k6ET\r\nx3T5QFBtlof6T01aFwPQ9fP9MPrNUKTQnZI=\r\n=g1b/\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"05ef6a40caa9bd765659f842d23ee0e267c292bf","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.355+05ef6a40c"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.355_1670880556893_0.48994539098022916","host":"s3://npm-registry-packages"}},"4.0.0-canary.356":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.356","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.356","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"6cc91fdb27855852d144a8c8e6aa876164243fdf","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.356.tgz","fileCount":47,"integrity":"sha512-ag1jik06jIIEWMcHxVMsXV0hfekNHOyIyJ9iKkKJLDiqSjBbB0FDqNhJxIPjvSSz6oZvUd7nQ62UdtOthL5g6Q==","signatures":[{"sig":"MEQCIEGa7OuPdEubGfhilIG7iXeNEbaPob5ylANBE07EaBFsAiA57GS15oUtn7M/gDfAUMh5+TbB2R3ZPZb+WC82Z4zIFg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl50/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrSbBAAj20U2Ky/ALPBKAbdr0XyM+iZGss7BJrg/K6LbuZELKgq/jyp\r\ntlHikzNwfRpdvTCF5AI4SKY8jcaohpcG9ClxAsownBodtseVP66TDBBUTGja\r\n3sLiCIewW3UdiKk3b+DXddY0Y9CxIujShwaUDOZRSr5MLD1w4mU4duaHAKbh\r\n9FB+X2ZEOcHHaKJOurkPVo1828uhJ6fsa3HuyzSa8mFbV8zBvhDedpJX9JWA\r\nsJ1ajlCXddvuS7Q1KkAerGg7CGPwr2SPcnzXabbIkMNw+c+I22HRaJqv3bAx\r\nnfR1MsWE5IE7GyxWS0eGnjhmT8eUHYYCqt1BTJpx0iPhcPsxuv9NS1Rnqbi6\r\n+ZtZpE3QDsvGDnLfAjO76iWuNFwLIN1aC0rNR4XnUX1cPXaw5GQQ9CZnBswu\r\nHTWQkTf//I6Jca0J0IG4XZUkhzxq0j8Qjbuva0lRrYJpxvIN8IVPKWxQ1iVp\r\n67Pw/F2FM6rxbHbASK8OAzFSO723Avj9IxiXE1pYhd+jgfqYeQbCJUgzXPym\r\nvb68l4bAg8wr1oKLpO3yHeWeOtVsqg6MBg4CJYHxa9P3V0hK4oyHtXl//Rlq\r\ncVZEYcq6mPYfcSHtExMg+1qTZaaKEAiZYtK44d37+Uy0mubvPRu7O850Gp4V\r\neHCNE6QOXK0pKFkcEQhinjKjXoVNgFmVQoQ=\r\n=bO1c\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"256cee55c7124571a9d243513df4939ca30cb57c","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.356+256cee55c"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.356_1670880575221_0.5201390812324158","host":"s3://npm-registry-packages"}},"4.0.0-canary.357":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.357","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.357","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2e9189350a2eb17b8a610f39599e27b9d47e4138","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.357.tgz","fileCount":47,"integrity":"sha512-oC1GQsKjL53akCWmmPfi9+b4JWkryJnd1cRkZkiXEFEudQ1ovp1DxBQYlGXUnBVo5bYFL/YOCLl6csWpVIWzjw==","signatures":[{"sig":"MEQCIH56tT9zjBrA0Ek2aJMUKYxAhZLaBYrLm9CdOUhlsXNrAiAxccmew1nJdSodndwHUl6juh+ffc+v7TU6pTXaXFUwIA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl6QtACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrsAA/+Kzv71E+k0CGWqoL4OAmNU7HfaLmoLAamft3onbl1g4cdHO08\r\nQJ0bHWaOnduFK/Q35qjaNiM3evMSdafQcitRYj4Rxmw7/HGjOLyTnFMHDFRj\r\nLeriyRkL0QA2TdSycH7khgVlRwzMSwMBR5k4zixaFOf3iyPHAHV1XrmDZiop\r\nPQx+yQkGVNiwDLtUPcGvXZ3rk6Cl4jtWojZisOE67FaHKLJsXx0x5khl6uqv\r\n3bEXBAnWFsdUn2IzPzyMOn5+JfUccUC8YlLqTWMinqIjhZSec0xbTa/6uyj4\r\nUB4Is2R7Hazgtf6dO6X9rlK0Jq0HCOyVQJ8Z81d2rDBpnbzeaJgJKcb7l8Dh\r\nyw26QQC38O1y0hw6HLF/k0PcE2ZjZQZQHTQVWPcldy9Rc+Nxp+EYxwULDmk7\r\nXazO3SoBrRhVCv09sfmRpwQiM6s2w+6APq8Sf4gZku/7VVxMB1oZ/mPWkz/c\r\nrhVBR1MSxqv3NOc96ISnwuPEDnM31bUPpez84LCDqvCE/SCI8Q5ByiLHqmgn\r\nnw/YrdBX1KXyhR1FtBMRijwETg7vDN06W7V9afzib4fOgcygEBfbGTQfqArC\r\n3G/tEPWLipzKp509yyrjuLnP00c9kYjg4jgxcHWQ8KXx+Cu0IxLb4DSHPAZP\r\nYcns9lZn57ac8tonZSbhUsvR3PKndFVeXxM=\r\n=DyrW\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"58a18fd08a30724d0eea8927d9408e75da623ea9","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.357+58a18fd08"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.357_1670882349418_0.2402321365471467","host":"s3://npm-registry-packages"}},"4.0.0-canary.358":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.358","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.358","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"cb1d3bf020402277b5e06f81b7583beb39b0bcec","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.358.tgz","fileCount":47,"integrity":"sha512-QEXy4jNmrJI46CdrM3AoTzU50TjUz7rQplzVVypvxIDzW55l9PkXoDIdHjBBmiX0nb8YR5dd5EwW0SbpEIOXiQ==","signatures":[{"sig":"MEYCIQC9k0xX56sctawFMf6KQAC+d9NhRp8+DyHsirTaOvW6MgIhAPoQsDdRgGyOb0K0n5iRqXS5GotjGbETr+lvFaScOk5/","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl7H1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqvxg/+L+oFQgIREY2X40+5lVDsfDzxQt9tMaT360vXyU8hv6Ts2qDN\r\nB/8Q43djSBng3DzYRrjS2YDQDvIB5+vDz6nuTb8/E3hK9THrIoNQm6GyNhlr\r\ntZUxaORyQ0X9c/BZtfR/dG3bSZ9gFiyjqS38a4pKsYywe0R1pSxqv8ojZWSi\r\ndZVG06LcrN622fmmkGih4rzcfYBqJSHp+OJ4efvIjNdTwp73GNq2S5TSlDKQ\r\nx+HGNYGhcxeXPhjjBCCwT1wHFMSny2wQn7aN7Q16duGI29H2f0gHuM1pb6st\r\nVQHlY/dj4eoODABN1d1yghtQGUefvisuBSYurPU0qHYSjSfr0NKGi7DuW/XY\r\nwdLbzvUVCCye7RjPUXjxt+92D0P8fvUqpmSstqmy3gSO0CvKV6s7szZOyJo2\r\nqnangjkhBRE4TkrEZgtJcPfuY3pUJHF+kFI9KZJ8lRadznQ8ISs4dNFg+N7W\r\nWxOziDm/W3eDcifbEl4wU8JW7EWOA9GD5JWEp3jm/+sBD7eoGEJU6KajsWjp\r\nIg72wiA74nGh5/m2d+QCsizaRwmsttagMaiRaiXtUQxHf3+fgPCemFCrrFfV\r\nd1MZv8NeOSl4iWIen4RkY7T7aamIwuoBPaaN1WS1hX3PszvyFa/zt/cGFkrA\r\nn8ydBhyDTcxJkSTwDz/3JjocEXVDkKd/MFQ=\r\n=ehvF\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"bdea4808f42115957d11cf86fb057118dc733a3e","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.358+bdea4808f"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.358_1670885877610_0.2470421978527617","host":"s3://npm-registry-packages"}},"4.0.0-canary.359":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.359","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.359","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"536972f61baaa618bf51a5f8f18db03a8c2e3b9c","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.359.tgz","fileCount":47,"integrity":"sha512-nkWEqAS4weLXtruilMxGsDpl0AqHeqKcg7+YrVhelxxBc0IBu/4JwSrNFp3CUVGuNPmjSgrrSlIS6jAMrfPESg==","signatures":[{"sig":"MEUCIQDs+OE5gm7IQcbGYeeqdnpxhmOkSztv2azT3rtrcti6mwIgZt5NEsf9KrWyNJGyIWp2KE9ohmsox5EYUW7fJvYwIik=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl9K8ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoHABAAhiCn3vpUOMnhmwZ98qRn2J96yt3SeegRe5FpRR3vVaiNRDwI\r\n6ubHP6Agy/+idnBJ5OxnBgITz2fcPcNB8tqfm57myWDnP5pr86ZZbZaHFkdU\r\nv8l3ftNNvC8YoEJoBFQyBveF1nYHuwTXMevMH6OcLiBwcosUtnXwzoZlZivC\r\nHCH5n77w7MUBOsthPVIeym/E3MGXF0plFyO5idujzqsU/r7eEz873gAG0nlW\r\nub8ZEmwH0I2feB6lHne56IWMC+MkNc+0mV3m+vvdTxFSHX72n8qOIBqr+9Sg\r\nUgnMqkPQqIV9tMfwFHiYtfX81RlPRNHdK9qjPY87dz6IRCs1diujqmhxahuG\r\nutnWNTFYkrezbv5JbaWCtHaE8Tts1pAXfr1Ibzov6G3X/QDBNbOev0P3kwj2\r\nU1j75gqpQ+9aeXBxZF7jlKnSassdtWPpnFH5z6+EnDjriiPJm/NyT6KzFRer\r\n8DdTwHEPtTXbsLUibTJn6BzFdFm60kN/rkAT2lbHwuT9l+/lz4Mh6aBxNINL\r\n0IfhYpP6vHNpi21ctwBGdxxiva0krdaH9WmCHkU8Qvl+7EAo6pnqD63WAimC\r\nRZg2Nt2zvQv0//qXg0YEYdD6TjEDzYldNX23ENQevEXrF2tGABPPd3hiL/ds\r\noNzxdbCHHDvgPwM5bcbFDEMovyb2uYAsgxM=\r\n=WIJ2\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"ef3600d14ada83c0265f52f623e19b43793562d0","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.359+ef3600d14"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.359_1670894268250_0.8725173580375303","host":"s3://npm-registry-packages"}},"4.0.0-canary.360":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.360","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.360","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"0636db766584e4f28ddbe16a10a973f71ede87fb","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.360.tgz","fileCount":47,"integrity":"sha512-iodUkrmiBt2JdosDbZYzcFv95wme5ZMJ89epnjVdPTLXJcYbkw4WTfPOd1exYOq6IrUUqAWb+S91Du5Gm2e1Kg==","signatures":[{"sig":"MEUCIQCPMVrAylvVZ2tNMAKJNizQ1igi573dq+cqpOXvOMSbyAIgPvaJFYgAvqojP26xvUA+2iScdQRHpiPmF94Sxz+oJv0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl949ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrv9A//c2ilqzsvILlThyfsUq2k7qiw6Axl88BkJqOer3Hqg9t6V6uc\r\niscghGhinSFZWd15LuuMAYS9zvGOFJu08/0/hOgbGq6UaDOWluiZxOZGwhs6\r\nT5vrWqEJnSlCdUrcNXoQhg22ecCD8T6VdSa3hEODLvPwiRWewyBoKoThKCEU\r\ntJYH1Az63UMitSJpvZy39gJbv3i6JiPfW/WORH8yXMW6pb/uzchvrsbSCErf\r\nOI+9K+swAkCytmhg68EL6Ozwex/dsAWpeKqOhDKgforzkRjp8Wx/3DB1JRKF\r\nPMyxzERkN51qM6WMkxZ/21rtNfj1WWHlJNPpT8w06R8dNk8k/EejPNr7QvpL\r\nSQHLzR10drcACInrgxBAJ9MndfIST+93fGyw3gZOBcT6nGp1TCQBhSySTnt6\r\nRWcjAfedTneCRJD8uy6+CQIqL6B4PNsVQJJKpDHdfD1Ce0GeKrQVZTShbWHh\r\n3herumSV7EfIuz1qJL5ZKPot084U+2dKAG9wQC9Jc+GsCdtskmO5y0eigqt2\r\nHSUjwcCKTZJ3krbTmgek8H8PInz+PFgppmHnrEalVCgGRtzEcfN1NGZh2LRB\r\nSNgksD0qiSUhDWe+nsvXyZLby2DURgF9O5Ujzwc0f0huPXUp8p2XSios9/EO\r\nZ7s0/UD2CESf1h41PHmhSCkHeiwEEAmpSxA=\r\n=IFVx\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"51d21a00cea4fc1bf8c5e0dcc20f4cadb0d809ae","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.360+51d21a00c"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.360_1670897213324_0.7787841715644552","host":"s3://npm-registry-packages"}},"4.0.0-canary.361":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.361","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.361","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"2bf6bca18e840251239361e5da9a007aeb581c50","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.361.tgz","fileCount":47,"integrity":"sha512-tJUwQ1MWizRk44fhVqKQ0wg/qC73UJMLVAApIhtQ7nPTZ9/Oz9Awe5ylt/MwZhl/S6SHB7Hy3vMe2y+OAlheGw==","signatures":[{"sig":"MEQCIHEbebh3oQ6DlgJY2zMKR5nVuxZN0+e+eW4EvOOq0QtPAiAECePNikOCNGUQW5rwnHKxNaHDqZkTaSG2yZXDchVoFw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjl/TqACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoMBQ/+L4xn6lEeDoD2d7llg/+ofrDdM9ZaCMPs1xTbNC2rD2g/Ciwo\r\nbAdk2glYdHzkhOq1pkeaRLpjTWzK8k94Z5QgiI2+Ru2wkc+QHO+gpwPJCWWf\r\n/gvHbUKEultfMz6xrcROFODq+3uk+kYppX9IMcLCpeuVqsV23BbDGR3PK5W7\r\nkmgX2XK6Lwb0lX6gLHwrJuzT9F18jNXxDMpUPDMAYGKfB7Iaoocb92dUNqGp\r\nnCWya2NR300ZTlRST5ONxmjrE9u784Cr+Dg607c1aSruyUd04qM6goVLVx74\r\nja++lP+qoipvm/NtByEJ9WDuspvTa0D+rHd7r2mw4I6P2sD0SNxZl8dr3e9s\r\n9xIYv6xx0oqsBPsZru2sjr/yOP5jrHnfnb9HcIxPQKLo1pm+Vy2q7o1Qcpon\r\nGuaodOIl6JmO9OZJriAxw9FGHoGBhhM1EFYhjzV6hVhmhI5qQmj7//Mbcop5\r\nuV6yrItkCUlp2sWzVu0JRo2iP3qvYfemnaEjKU+X/OrEKvk45NnVKMGBdG+n\r\nqvyM5n/fMqefIdLJgeoQrJSJUmX0mBx6YAeb8xEizjoNlFIVPcA980iPko1L\r\n5rpbLz46SY9nbuI0MWiN9iBAawmgE43qJAXr5XnxLJsKVyBhmCAYi+3AtNfu\r\n2KDZGTsYiO8mSmt3W4+dQUe1/cOpll567xw=\r\n=hBtU\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"680a2b5a9fab2318e6a4a5caaf47bcb4a4e6d136","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.361+680a2b5a9"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.361_1670903018640_0.6039576749754447","host":"s3://npm-registry-packages"}},"4.0.0-canary.364":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.364","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.364","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"5ff3c29b81490ac828ccac09a9d92af330234804","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.364.tgz","fileCount":47,"integrity":"sha512-hCQNKd7UWv4IjsjNslc5ZCRLxIKVn6XN71osNt32j6VBjGE+nUCWkJm/1nGHqUHmh5oNAqzWif9zYmtzjvgvHw==","signatures":[{"sig":"MEUCIQCXCFeqnsoM8IHYfNeqP/stg476HhlxH+AYCBXIhxsZfwIgNTmVhW7OJtDHhn8LKSoBMPAqrRZ0YvF2GGNLbqwcDH8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmEYVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoD4g/6AktMUCLRsqJaw97t20NTbOYD3ph08zMsKJIxmSd77oVX6BkD\r\nwGTZaX0+IHkBdwF66MVIIcnqSi2dxLMmnIeNxEMRsFlX/Us9Gt+kdLlgukTU\r\ntbcJToV0KncJJPenqcU3UY5ToFJbhJWN5tj5JybubHi6MXIMhcrfTR/aKrTY\r\nvCemtTetL13u7gcEEI3hvzRaGmg/FRvKZlIirB5gEr5/uFzi/uZ6MBUIChLp\r\n8oz57Dg5LC6msEchPH9Ef5BNIwM7oiY0JJCp5GRzl9UjF0+QHZIrBWRrJam3\r\n1iiBNEjejLxypv7Nb+9Fiso+OkmJ6sVqOQSnkPHaLlN6UyAft3/GwDf0ZJpJ\r\n2xfinHKDJ4vE2RETZQN/TGyVZCyezOSvhwnyvcLaRhAJEoq2CywQc8ie6F3p\r\nCGPybc1MgS/KpKDI89Flxr/4X+dYUhLWn3KtJ/VYhakWi/qkNfGta7cXpoD6\r\n+luucAv7B5SvHES8v86EwxEgunVrS5OxU+Cy5CQGNf5OO8SLYg+3q2nM5yYE\r\nvIMIi1k9rwlU2aK+kNMfR1ZhiXTZ8rEGqkBfUtVxSvUifKWHLrRf6Dzn7T+q\r\nGGfbbYtVP8S5/7GraWkxvRnyBR49alsHlRJQTXwN0/ASgm5MHUSRNDe6kg0R\r\ntVXTi5MVmc+YOOwhMBjWIe3yk7Wi1Vw9jhM=\r\n=X0BB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"d7e7af355c70bcb56f548e93702ed33b946a9418","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.364+d7e7af355"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.364_1670923797247_0.20386835517156876","host":"s3://npm-registry-packages"}},"4.0.0-canary.365":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.365","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.365","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"9dcee17c7727c397cff9b4ac672fe9c5c9e7667a","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.365.tgz","fileCount":47,"integrity":"sha512-zNQSIw4M6jcx0H4hhjTSDDcqLfsRHAxOO9vt4/Fyvzd+YzUvz9IRjtuJ2zhLKb/e8MuzHfxPPpNl6vuJU54CPQ==","signatures":[{"sig":"MEUCIQD/4aH11lD8OYIr7BgV3CDmmoJ4urLPOJed12DWX3cJ2AIgIXOYhWQKY8PhoEXTmCoy/HrPSjONZIiUutdHW49uP4Y=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmHcpACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpoKw/9FSq9SDkHGPLkEmNdKAgkO53EFjgC1zfpkrW3b3NrdlzIQPAB\r\nduT8Urq7utfZfIi37CaLcVXSkQIEErJvcbxxtKgMbxA+5RGa67H192bLL3hF\r\neShMTp6IXJegw0VuQgqE6cvyQItDck5n3lzL/p84zNIMIa2JHRfLV0BqzDJZ\r\nhUVXyxTRcZWK3wiBDAEOvCZJmsbnvP7KPi1m6dLK62cvPwEa6GqgKrPZ5mBw\r\ncJgE465bzj6B+xFD9RgsZR+qIlzMofEe1Diq4Ob/Qf+ejH/fyKEn/sohVprB\r\nMVfa5hIYdKnpjUArTYjYFwGsuW3iOkW8mZDzZtvN1isZLduP38kgoYiKuvLS\r\nE8MtF5NiG8p9NfYZqhT3ljyYf9u+SRL5dyC2vKjYNQ/uwGI95qXWs2BGvXW4\r\nPFtiIdvQRZ/FLaxDY+svJk5w5pVlnVXHl23j53O7d8eZIMoAQaKEImzn7Q02\r\n+cslT4Cc6/D3A8TKVAQMxhIbPXVkgugUZmtxRq1H1cYIjaQkGueU34JIOMkC\r\nXYCHBisRQy5UmaNhuhVgcTmbK4jlshoH0UGdp+FMCD08fcglmPl/EKkVunJp\r\nLOpsHLg9rK65UxlsOJ5znaBrwslxLb6cC4RTtSyJCBpTf4E1cOh+WthN0E8V\r\nFIN8SiyBaByJMruqQEbGge7Hqo6ArB9JQys=\r\n=vdRm\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0cf872dc32a525a4449dbabc23745a8c11215746","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.365+0cf872dc3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.365_1670936361631_0.44930865306854617","host":"s3://npm-registry-packages"}},"4.0.0-canary.366":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.366","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.366","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"fffca0f31896991f5127523f6014ea4a85975473","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.366.tgz","fileCount":47,"integrity":"sha512-wNSXZwzpIc1QoHelrktRTAhswBbFcFVIGiBuw6089LrzlV8asnuKzDU/F+NCMkyXcL0OQNf6YwUJu2wBb2tfrQ==","signatures":[{"sig":"MEYCIQDC9S9lRmN8BJUpYmEi2SFc5VXyHg4gmUJWrCNDKl2TVwIhAPL5fRdOb9wVILKEyxwDxZHSA2S0bck8B0s/Z6/WwII8","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmJ0HACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpTHA/7Bz+r+gMopYpL1ccVPf9+m4C3dyixmJXRUhxzEvfDD1RbnfVa\r\n9lKnMEutZmCgutN97vWB5mDuQpS/Um1Vm8WVMrhOSLDmeaMXKUsjmnwwiNWL\r\nGJojbsxbzK7G8TlHbJgVBnfUfuUAbQ7Q81zRUfptdgBL59srkaq0jGA7euxR\r\npTi3xYmHYmJsK29apam5r5rQAQ/wAozbRb/KBLe3W3C5Cu6TXfVSkUZ6vU4G\r\n9pMjoro9Cfij6EQz7jCVXdYz8KLD8qN4cpzqdV3eHCcgHIQPBBIkbGjRs4N1\r\nOlx9FENxo99O2dm7teuz1AEEO+0stDDNbTC87ualRJ85dDSyhX7tV2f22714\r\nevx1lTeCuvg9SCQtgNGhbBfFCttE6XPbak3ry4wbz7SN24W01UPDIDQfxiBW\r\nJsPI/OB6cwypPV8lYzMQ9p5eiki8g+k0KZkI9Zu4tkSz3pgwcwkIxKdNdlV8\r\njobi8RmavionjFDIq1xmp31a1C6MBGAZ9/yFJ7I6+NXt1C+8BKylSklooGVQ\r\nz/HKtryPNOXAPDh2H7aM4k5XSfAamNV2mHowJBcW8CUxjNrOnM2N04qMDXSS\r\n1VLcuF/tshzoauwzAJE7SbZ3OxJEZg+q6rBCuKC6hyi6Fu/2yPABwh4IIQxb\r\nNzpwwxw62Xj373rnv5RF09mJK12TkW7qm/k=\r\n=nNvL\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"6539f1c4bfb6dc4935a84ce32a7f762da4c9795a","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.366+6539f1c4b"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.366_1670946055038_0.2155628288659479","host":"s3://npm-registry-packages"}},"4.0.0-canary.367":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.367","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.367","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"41e89c66626cb13be0eb7f9c6e5718ee3f9322ab","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.367.tgz","fileCount":47,"integrity":"sha512-C8dPtyPaiVwFQem7mWShS6Dh79GVYpb7wlUi77/8dlD+LwkW4nhRs7vC0w78MDp17LQbiovjLvrokujIO3+9Pw==","signatures":[{"sig":"MEYCIQCm5KX+ve8Ov/fCartO2X2JMBCkY3Fd40JMKCVlqkvbTAIhAN/cTCr6OMQ6UVPbHnxCFRxPmG0ob4AErly6Us4wcmaY","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmLRSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr0Dw//fJ2T5gJiDl6iKSRxauvMeeWmoUzFIWbTZOzceMdRyFmjc5tx\r\nKNiJKGiK7b+xI8o6iMd6N+26nOlmpx209veIX93Fdw3h254r/uRSbT42PAFq\r\n8Y1QcEKgyIBaG13dNPeLfPXK8rD7alqLqYsNgSz/IrFaysyacd0Xmipu/o7E\r\nl7mOh1w9jeoI8VkMs5cq/eJNkZqY+M5a6L2Pj/qT3cm2qQqiwszsqJBbbWFT\r\nwssbYFgqbZOHSmat1FywCL0eD730i25BaVW7uBpDsTy0MKTCA25deUF31Kf1\r\n/ZsRZC7BCTkU7IsbiO87Bz44OxuYMy8uVv4q4kkLnpxlcBFS75pt4AAL8jEF\r\n82lCIChaDJ2wuwdxNxBetK4cvjbA5UnirzlBW6sqSjDHnVH0HhT8QlqJagav\r\nDeITqHwTWhyV+BuDRoxQoo6Olj6PyXRc+hJW1xY+MfVmBCg6+GZMDOKIBEPJ\r\nfw0LsT5Mr1OOVrB/U72AW7qhw53kgCxer/ThpKPad2jjcKfuzhiGZIBxXgsk\r\nWvV2U1zaPjLn71v++nC9+hIkhbsUsxKBiAsYJqsIFY+WyrZOol9uEzOVCbDi\r\nbXvYOHw4MHreX2qoHcTZMiqTv0zGOAEy0GudfOpH2xlJ/3tZPrMuqMZzBpnr\r\njJu6xm2E1NhttUCA2oYmkfhKknx4L8SiCmc=\r\n=l7L6\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"0b33c59d950c2d78625f4ae7adda0c69b7cb8e4e","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.367+0b33c59d9"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.367_1670952018458_0.031354106641283686","host":"s3://npm-registry-packages"}},"4.0.0-canary.368":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.368","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.368","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"4c7ebafe011718aa21a57150cf3fc90f3596a066","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.368.tgz","fileCount":47,"integrity":"sha512-yjID1iEAXH8++wmdcJfUX7xrllQ1NXwmCNz3xtf48WtuMjAK15sDCBlh17unGkPayb5ScHE2qOHDGV5ZonIghg==","signatures":[{"sig":"MEQCID7bz7t9fXyoIQc1atb66HsoOJJcAvmQXx+aPcg2V2XuAiBELl0PYW5LTkshBOc3pJ16PCQAQt+KoW5jEXyPu+Z7ow==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmPglACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpTcA/9H+niICGTMu2FvbxG+1W9DJoN8ERbVJrxD5/Bc4t6TWCZ8wgg\r\nfslbnY+Ts71prXQAiHkG9oj6HERNKabrCaLbOYk3DItt5HdZ34+BNDuPMifK\r\nd+gvqiN9+2e1PHXEapzNJ+Fi8UnUqjv4ArkqdMX91noZoH1QUZvyNZJVXnMl\r\nsQHUFtGLragaimVFFg9VfafoNEX3BdcGqZC9ejz8gpk9BZp33LyZSd2D+Y2u\r\nyn89cL+mPrsCepuOx84yA41peDp39udxMUGykYVpm7SqIpEg6Gz1TAwkMlhL\r\n0zt8cPUjsv77XRjoL4ygYEKK8lejHs4Y+iCBwQB1+faY1ruiVVWTylzQLsUy\r\nXeEAsR9vZ7SmVLOuW4oYcgSHACXivIXQGVDxVe4oeE01BBLaGsrjWbHjBhjz\r\nesw1JcuerCH26QGqJmHmiJzrYekxcYyV6+rCiUASlnemHjmeAx845jUavApf\r\n11Lcwk0Chvc+aSerV/JBiW7OK/oX1cagGoATwAiJsn+Ydy1nRP07v1dF6XyA\r\nmUeyUCma4y7dYUTCKpjAq5U+QlUfvZQJAbJGvkc3bBzL/hCAFU5iLnM8jX/c\r\nCgUBKu4BuXrx0Iuc01F+HJgxh3oX0Kqz8CnLrtJ2JOWwMf2vQfZzoypjX98B\r\n5JUctofrBD7/DrzfAfkDZG6DuHKW/oyH4LA=\r\n=KpOa\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"aa6fb1e09cd4a5876fcd775f3291190c8b9b2c6b","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.368+aa6fb1e09"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.368_1670969381332_0.6900703143104063","host":"s3://npm-registry-packages"}},"4.0.0-canary.369":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.369","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.369","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"da4812677166e5170a0b07320c1ee970d26d438f","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.369.tgz","fileCount":47,"integrity":"sha512-yBOvsAyjKKDiA4dMdKP12OmRiupi8zGP7jh999CHkfzHTfmgjjA9kaTu6AehzlLYq2t1GpCDDZWum64NjgtuHg==","signatures":[{"sig":"MEUCIQDEDx/AyiByPltEiw342Fuvs7X0kUKIUWlOU/REBcURNwIgRCIyqC+gW551bm8GM5jVoR5sA5NrPZ0Rr8KnUWkuUjw=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmP8jACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoMHA//XvOg1/SXle0MXVGnJNppZ5JTXzALfEKKuV0QqROsYD9speCH\r\nKOG1TynaE4Tnk6Mqc/fKKqGPB7URbG9vcWdnPU1wH1Ztc8qUXOwMZ1R9pUlR\r\nuxsTt1Tu7FchVkBLWqUeUBq2cHAwavbkZ7Yh8eYWl0K8lM14qp3uLrblr+ce\r\niu9hZdtetm1ybQvNX8p/4rPi23koMmFq/i9XSCUc+NS8TBiloSnkpjBhXiMk\r\nSvOVPsAsH+Ha5I/3Er0pVXJUbGPlu1qGAuxTjVjWn42gQf/J4OHoRgCi9ikf\r\nrt/B+8rw9hJGPATKWY9Rsaxy8CwmpCnGVJRojUsQC6VANQ+cysr/kFmX8NWy\r\nW6k1E1UspPSr8RCfHF1iqGauMZeygKWsQCpoLkZbiPtTsJBDJOW20ceTvSJZ\r\nlk4UjaHGOLE0mFICvddSp6AF8jqkAKUCibWBHRXpqnDmctJNellJeoM2D+O7\r\nP9NVv3lQG/ulCRhj7OjeVkaDdFfN4zdyvFOatZnWE7/remlcdlRBzXPwS6b1\r\nkfBFGuHWWIv4fEdTJPpIZ6scJy7jf2Tk4GUL2jHVB4r0/nJ8cw+L1XxO0XJq\r\n2AVhK4+DfVwvfB0Z6WfAUE3AGLJ8WKEfEVNgFtbUWYGZXyPsyFIGlDzfUUmG\r\nBhzDvVLiS9AcnLlVWyM9ioVHSzIqQOsu7nE=\r\n=HQ3n\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"2f65ef0a385c137d6a770c385e06da1ae7a63e0b","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.369+2f65ef0a3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.369_1670971171620_0.2700749494713002","host":"s3://npm-registry-packages"}},"4.0.0-canary.370":{"name":"@redwoodjs/auth-providers-setup","version":"4.0.0-canary.370","license":"MIT","_id":"@redwoodjs/auth-providers-setup@4.0.0-canary.370","maintainers":[{"name":"jtoar","email":"dominic.saadi@hey.com"},{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},{"name":"mojombo","email":"tom@mojombo.com"},{"name":"cannikin","email":"cannikin@fastmail.com"},{"name":"thedavidprice","email":"npm@thedavidprice.com"}],"homepage":"https://github.com/redwoodjs/redwood#readme","bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"dist":{"shasum":"ebd1e738fe6252dd4b95ead1927feb9e851d86d7","tarball":"https://registry.npmjs.org/@redwoodjs/auth-providers-setup/-/auth-providers-setup-4.0.0-canary.370.tgz","fileCount":47,"integrity":"sha512-NasM1SV2dKi+Sy1R+iA1tUKnPSSGzP8kbbvcWU0FfYYLSKPa6cL7V/oOQ2bFDKuoTfGH0yWALTYlm8gD4sBPuw==","signatures":[{"sig":"MEQCIC3r9biEPRwK8dcgBCXbaeZpHkwAFOjwZlc+ToQ9F0+iAiBw5BpPD92LCr/0PJG4t9xzW52gRBvoO4+OdrC5hZyCAg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":147147,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjmQRHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpOzg/+M5HgnH3jkQ5w7AYz/ct5ixVruuPurI7lmU4QcQHZ0Y/lfUAI\r\n4rb7P88vorJ1pxc4MZVz4kS2TzcLexRGWi8ZUoytwuPvLMzXzBuxPebeO9W7\r\npNSXU07qj/pPq179o+szjOTfioDN2RfcQkTgbfuHkn6KhErdfRtdTvNM2kd1\r\nXRyogakBzINQB7jk5WmZMvX/9yaIMQ7rPkHNAlnMha/oVAWsl/+06CSYN4XG\r\nm/yNKODHKxTO5cmhxkq92sgWBF8V8X0VkWVFooQ3s3o5/4aSNz8sHG+xPPXT\r\nY1KQrXHgcWyjywxa+DRo2gVjRgHEKkfGp38M0M1qRPiTFIKU00lV2Sdw1WL+\r\ndKOob/c97kDHPHDpcBl8pSkyyyNmG8mx5U0EZNYbYg/2OUZX6ZKGDRRsNygJ\r\nsX85EmPU91zslaMMC8ADDN36fVfaO7LxF/sW5YVKdNZP5cWPiZ1ZLupUIL2I\r\n/3UmYxLbva9/tFdtkfJcf4MxsEztFbD9DK5jt7EefogpDyV69kqumXXXzey4\r\nHBV4sUBfx0yAxC1RhNMo1F//KIuZiLtrvu2b3Rpa5HUIJM00HbDDprw8K3eh\r\n/OWBVr5qbdo7HJE4uZB3vOEQn2LEfKEt9JSQW3jXLrXWYcJG2uVVyl+iNYSw\r\nli2G2gjA6BUQ97FrPWgxfzfbD9GUf1it/8M=\r\n=jx29\r\n-----END PGP SIGNATURE-----\r\n"},"main":"./dist/index.js","types":"./dist/index.d.ts","readme":"# Authentication\n\n## Contributing\n\nIf you want to contribute a new auth provider integration we recommend you\nstart by implementing it as a custom auth provider in a Redwood App first. When\nthat works you can package it up as an npm package and publish it on your own.\nYou can then create a PR on this repo with support for your new auth provider\nin our `yarn rw setup auth` cli command. The easiest option is probably to just\nlook at one of the existing auth providers in\n`packages/cli/src/commands/setup/auth/providers` and the corresponding\ntemplates in `../templates`.\n\nIf you need help setting up a custom auth provider you can read the auth docs\non the web.\n\n### Contributing to the base auth implementation\n\nIf you want to contribute to our auth implementation, the interface towards\nboth auth service providers and RW apps we recommend you start looking in\n`authFactory.ts` and then continue to `AuthProvider.tsx`. `AuthProvider.tsx`\nhas most of our implementation together with all the custom hooks it uses.\nAnother file to be accustomed with is `AuthContext.ts`. The interface in there\nhas pretty god code comments, and is what will be exposed to RW apps.\n\n## getCurrentUser\n\n`getCurrentUser` returns the user information together with\nan optional collection of roles used by requireAuth() to check if the user is authenticated or has role-based access.\n\nUse in conjunction with `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param decoded - The decoded access token containing user info and JWT claims like `sub`\n@param { token, SupportedAuthTypes type } - The access token itself as well as the auth provider type\n@param { APIGatewayEvent event, Context context } - An object which contains information from the invoker\nsuch as headers and cookies, and the context information about the invocation such as IP Address\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\nThis example is the standard use of `getCurrentUser`.\n\n```js\nexport const getCurrentUser = async (decoded, { _token, _type }, { _event, _context }) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User details fetched via database query\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return await db.user.findUnique({ where: { decoded.email } })\n}\n```\n\n#### User info is decoded from the access token\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded }\n}\n```\n\n#### User info is contained in the decoded token and roles extracted\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  return { ...decoded, roles: parseJWT({ decoded }).roles }\n}\n```\n\n#### User record query by email with namespaced app_metadata roles as Auth0 requires custom JWT claims to be namespaced\n\n```js\nexport const getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { email: decoded.email } })\n\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded, namespace: NAMESPACE }).roles,\n  }\n}\n```\n\n#### User record query by an identity with app_metadata roles\n\n```js\nconst getCurrentUser = async (decoded) => {\n  const currentUser = await db.user.findUnique({ where: { userIdentity: decoded.sub } })\n  return {\n    ...currentUser,\n    roles: parseJWT({ decoded: decoded }).roles,\n  }\n}\n```\n\n#### Cookies and other request information are available in the req parameter, just in case\n\n```js\nconst getCurrentUser = async (_decoded, _raw, { event, _context }) => {\n  const cookies = cookie(event.headers.cookies)\n  const session = cookies['my.cookie.name']\n  const currentUser = await db.sessions.findUnique({ where: { id: session } })\n  return currentUser\n}\n```\n\n\n## requireAuth\n\n Use `requireAuth` in your services to check that a user is logged in, whether or not they are assigned a role, and optionally raise an error if they're not.\n\n```js\n@param {string=} roles - An optional role or list of roles\n@param {string[]=} roles - An optional list of roles\n\n@returns {boolean} - If the currentUser is authenticated (and assigned one of the given roles)\n\n@throws {AuthenticationError} - If the currentUser is not authenticated\n@throws {ForbiddenError} If the currentUser is not allowed due to role permissions\n```\n\n### Examples\n\n#### Checks if currentUser is authenticated\n\n```js\nrequireAuth()\n```\n\n#### Checks if currentUser is authenticated and assigned one of the given roles\n\n```js\n requireAuth({ role: 'admin' })\n requireAuth({ role: ['editor', 'author'] })\n requireAuth({ role: ['publisher'] })\n```\n","gitHead":"3d057db199487ea0b17240317d66ddde3f83f332","scripts":{"test":"jest src --passWithNoTests","build":"yarn build:js && yarn build:types","build:js":"babel src -d dist --extensions \".js,.ts,.tsx\" --copy-files --no-copy-ignored","test:watch":"yarn test --watch","build:types":"tsc --build --verbose","build:watch":"nodemon --watch src --ext \"js,ts,tsx,template\" --ignore dist --exec \"yarn build\"","prepublishOnly":"NODE_ENV=production yarn build","build:clean-dist":"rimraf 'dist/**/*/__tests__'"},"_npmUser":{"name":"peter.pistorius","email":"peter.pistorius@gmail.com"},"repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"_npmVersion":"lerna/6.1.0/node@v16.18.1+x64 (linux)","description":"## Contributing","directories":{},"_nodeVersion":"16.18.1","dependencies":{"core-js":"3.26.1","@babel/runtime-corejs3":"7.20.6","@redwoodjs/cli-helpers":"^4.0.0-canary.370+3d057db19"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"jest":"29.3.1","@babel/cli":"7.19.3","typescript":"4.7.4","@babel/core":"7.20.5","@types/yargs":"17.0.17"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers-setup_4.0.0-canary.370_1670972487716_0.7206051455313625","host":"s3://npm-registry-packages"}}},"time":{"created":"2022-10-13T21:35:16.248Z","modified":"2026-03-13T13:39:19.940Z","0.0.1":"2022-10-13T21:35:16.443Z","3.2.1-canary.123":"2022-10-13T22:21:12.091Z","3.2.1-canary.124":"2022-10-13T23:31:07.614Z","3.2.1-canary.125":"2022-10-14T00:20:17.290Z","3.2.1-canary.126":"2022-10-14T00:53:53.975Z","3.2.1-canary.127":"2022-10-14T01:26:41.024Z","3.2.1-canary.128":"2022-10-14T05:42:35.233Z","3.2.1-canary.129":"2022-10-14T08:08:56.208Z","3.2.1-canary.130":"2022-10-14T12:20:45.801Z","3.2.1-canary.131":"2022-10-14T12:58:41.288Z","3.2.1-canary.138":"2022-10-16T00:20:17.130Z","3.2.1-canary.139":"2022-10-25T22:08:25.721Z","3.2.1-canary.140":"2022-10-26T23:23:22.305Z","3.2.1-canary.141":"2022-10-26T23:49:11.252Z","3.2.1-canary.142":"2022-10-27T00:48:59.209Z","3.2.1-canary.143":"2022-10-27T00:58:49.259Z","3.2.1-canary.144":"2022-10-27T00:59:42.252Z","3.2.1-canary.147":"2022-10-27T01:07:00.780Z","3.2.1-canary.145":"2022-10-27T01:07:56.243Z","3.2.1-canary.146":"2022-10-27T01:08:51.007Z","3.2.1-canary.149":"2022-10-27T01:14:51.333Z","3.2.1-canary.148":"2022-10-27T01:17:18.570Z","3.2.1-canary.151":"2022-10-27T01:29:51.146Z","3.2.1-canary.156":"2022-10-27T19:42:49.031Z","3.2.1-canary.158":"2022-10-28T00:45:15.215Z","3.2.1-canary.159":"2022-10-30T00:16:38.045Z","3.2.1-canary.160":"2022-10-30T21:47:46.655Z","3.2.1-canary.161":"2022-10-31T12:29:12.144Z","3.2.1-canary.162":"2022-10-31T18:27:36.444Z","3.2.1-canary.163":"2022-10-31T22:15:36.962Z","3.2.1-canary.164":"2022-11-02T02:22:31.594Z","3.2.1-canary.165":"2022-11-02T18:42:29.902Z","3.2.1-canary.166":"2022-11-03T03:00:55.268Z","3.2.1-canary.167":"2022-11-03T07:58:29.318Z","3.2.1-canary.168":"2022-11-03T20:56:41.120Z","3.2.1-canary.169":"2022-11-03T21:45:33.485Z","3.2.1-canary.170":"2022-11-03T22:01:35.376Z","3.2.1-canary.171":"2022-11-03T22:03:57.916Z","4.0.0-canary.172":"2022-11-03T22:23:55.405Z","4.0.0-canary.173":"2022-11-04T17:28:08.167Z","4.0.0-canary.174":"2022-11-04T19:29:42.228Z","4.0.0-canary.177":"2022-11-05T07:46:12.774Z","4.0.0-canary.178":"2022-11-05T10:31:22.570Z","4.0.0-canary.179":"2022-11-05T18:50:53.429Z","4.0.0-canary.180":"2022-11-06T00:16:11.356Z","4.0.0-canary.182":"2022-11-07T17:37:11.524Z","4.0.0-canary.184":"2022-11-08T08:05:24.803Z","4.0.0-canary.185":"2022-11-08T13:42:46.400Z","4.0.0-canary.186":"2022-11-08T17:12:12.615Z","4.0.0-canary.187":"2022-11-08T20:38:44.600Z","4.0.0-canary.188":"2022-11-08T21:34:32.692Z","4.0.0-canary.189":"2022-11-09T00:44:43.408Z","4.0.0-canary.191":"2022-11-09T06:56:02.465Z","4.0.0-canary.192":"2022-11-09T09:24:55.573Z","4.0.0-canary.194":"2022-11-09T23:43:52.469Z","4.0.0-canary.195":"2022-11-09T23:56:34.161Z","4.0.0-canary.196":"2022-11-10T00:13:34.659Z","4.0.0-canary.197":"2022-11-10T00:39:10.027Z","4.0.0-canary.199":"2022-11-10T01:20:34.082Z","4.0.0-canary.200":"2022-11-10T03:02:24.415Z","4.0.0-canary.201":"2022-11-10T06:39:51.976Z","4.0.0-canary.204":"2022-11-10T23:03:20.435Z","4.0.0-canary.205":"2022-11-11T00:43:32.021Z","4.0.0-canary.206":"2022-11-11T01:45:08.927Z","4.0.0-canary.207":"2022-11-11T01:46:59.804Z","4.0.0-canary.208":"2022-11-11T02:37:59.362Z","4.0.0-canary.209":"2022-11-11T20:44:19.049Z","4.0.0-canary.210":"2022-11-11T22:26:17.004Z","4.0.0-canary.211":"2022-11-12T00:06:41.042Z","4.0.0-canary.213":"2022-11-12T00:10:00.034Z","4.0.0-canary.215":"2022-11-12T00:10:35.158Z","4.0.0-canary.214":"2022-11-12T00:11:40.316Z","4.0.0-canary.212":"2022-11-12T00:12:07.214Z","4.0.0-canary.217":"2022-11-12T02:23:16.954Z","4.0.0-canary.219":"2022-11-12T02:25:48.652Z","4.0.0-canary.220":"2022-11-12T02:54:42.622Z","4.0.0-canary.221":"2022-11-12T21:04:25.076Z","4.0.0-canary.222":"2022-11-12T21:06:11.084Z","4.0.0-canary.223":"2022-11-13T00:17:20.281Z","4.0.0-canary.224":"2022-11-13T02:40:05.665Z","4.0.0-canary.225":"2022-11-13T05:27:45.118Z","4.0.0-canary.226":"2022-11-13T07:52:40.137Z","4.0.0-canary.227":"2022-11-13T09:39:56.700Z","4.0.0-canary.229":"2022-11-13T14:39:25.627Z","4.0.0-canary.230":"2022-11-15T07:38:04.300Z","4.0.0-canary.231":"2022-11-16T18:41:36.493Z","4.0.0-canary.232":"2022-11-16T23:42:50.801Z","4.0.0-canary.233":"2022-11-17T19:16:56.674Z","4.0.0-canary.234":"2022-11-19T02:27:26.493Z","4.0.0-canary.235":"2022-11-20T00:19:23.485Z","4.0.0-canary.236":"2022-11-21T17:55:14.885Z","4.0.0-canary.237":"2022-11-21T18:45:58.476Z","4.0.0-canary.238":"2022-11-21T18:46:58.161Z","4.0.0-canary.239":"2022-11-21T19:23:30.247Z","4.0.0-canary.240":"2022-11-21T22:24:02.132Z","4.0.0-canary.241":"2022-11-21T23:25:08.417Z","4.0.0-canary.242":"2022-11-22T04:15:07.167Z","4.0.0-canary.243":"2022-11-22T07:55:43.212Z","4.0.0-canary.244":"2022-11-24T01:37:32.871Z","4.0.0-canary.245":"2022-11-24T01:39:22.965Z","4.0.0-canary.247":"2022-11-24T02:27:37.046Z","4.0.0-canary.248":"2022-11-24T05:51:57.091Z","4.0.0-canary.249":"2022-11-24T07:22:42.314Z","4.0.0-canary.250":"2022-11-24T10:48:05.380Z","4.0.0-canary.251":"2022-11-24T15:20:03.878Z","4.0.0-canary.252":"2022-11-24T15:55:48.658Z","4.0.0-canary.253":"2022-11-24T16:06:47.121Z","4.0.0-canary.256":"2022-11-24T17:58:31.533Z","4.0.0-canary.257":"2022-11-24T21:15:48.944Z","4.0.0-canary.258":"2022-11-25T23:57:48.535Z","4.0.0-canary.261":"2022-11-28T17:08:48.299Z","4.0.0-canary.262":"2022-11-28T18:55:33.966Z","4.0.0-canary.264":"2022-11-28T20:15:22.655Z","4.0.0-canary.265":"2022-11-28T21:30:55.121Z","4.0.0-canary.266":"2022-11-28T22:12:51.959Z","4.0.0-canary.267":"2022-11-28T22:14:12.187Z","4.0.0-canary.268":"2022-11-28T22:14:43.909Z","4.0.0-canary.269":"2022-11-28T22:15:02.203Z","4.0.0-canary.278":"2022-11-30T19:20:09.957Z","4.0.0-canary.279":"2022-11-30T21:58:48.751Z","4.0.0-canary.280":"2022-11-30T23:42:32.097Z","4.0.0-canary.304":"2022-12-06T18:29:35.395Z","4.0.0-canary.306":"2022-12-07T05:57:43.593Z","4.0.0-canary.307":"2022-12-07T06:55:35.695Z","4.0.0-canary.308":"2022-12-07T10:05:05.153Z","4.0.0-canary.309":"2022-12-07T14:13:23.263Z","4.0.0-canary.310":"2022-12-07T19:37:27.466Z","4.0.0-canary.311":"2022-12-07T19:55:22.849Z","4.0.0-canary.312":"2022-12-07T20:00:38.764Z","4.0.0-canary.313":"2022-12-08T06:35:36.218Z","4.0.0-canary.315":"2022-12-08T06:38:42.585Z","4.0.0-canary.314":"2022-12-08T06:39:27.294Z","4.0.0-canary.316":"2022-12-08T06:39:57.583Z","4.0.0-canary.318":"2022-12-08T17:39:25.707Z","4.0.0-canary.319":"2022-12-08T18:28:13.838Z","4.0.0-canary.320":"2022-12-08T22:34:17.693Z","4.0.0-canary.322":"2022-12-08T22:37:49.167Z","4.0.0-canary.321":"2022-12-08T22:41:13.110Z","4.0.0-canary.323":"2022-12-09T03:55:23.635Z","4.0.0-canary.324":"2022-12-09T04:05:10.998Z","4.0.0-canary.325":"2022-12-09T09:56:04.107Z","4.0.0-canary.326":"2022-12-09T15:27:25.039Z","4.0.0-canary.327":"2022-12-09T17:00:48.002Z","4.0.0-canary.329":"2022-12-09T17:05:04.979Z","4.0.0-canary.330":"2022-12-09T18:57:13.247Z","4.0.0-canary.332":"2022-12-09T21:04:56.435Z","4.0.0-canary.334":"2022-12-09T21:05:43.818Z","4.0.0-canary.331":"2022-12-09T21:08:07.380Z","4.0.0-canary.333":"2022-12-09T21:09:50.956Z","4.0.0-canary.336":"2022-12-09T23:28:16.067Z","4.0.0-canary.337":"2022-12-09T23:30:42.910Z","4.0.0-canary.338":"2022-12-09T23:32:04.629Z","4.0.0-canary.339":"2022-12-09T23:37:03.064Z","4.0.0-canary.340":"2022-12-10T02:25:18.726Z","4.0.0-canary.342":"2022-12-10T06:21:22.763Z","4.0.0-canary.343":"2022-12-10T09:13:29.149Z","4.0.0-canary.344":"2022-12-10T16:22:58.858Z","4.0.0-canary.345":"2022-12-10T23:03:07.925Z","4.0.0-canary.346":"2022-12-11T00:22:32.453Z","4.0.0-canary.347":"2022-12-11T03:39:00.131Z","4.0.0-canary.348":"2022-12-12T14:25:57.385Z","4.0.0-canary.350":"2022-12-12T18:51:32.445Z","4.0.0-canary.351":"2022-12-12T20:12:05.885Z","4.0.0-canary.353":"2022-12-12T21:13:35.193Z","4.0.0-canary.352":"2022-12-12T21:18:16.703Z","4.0.0-canary.354":"2022-12-12T21:25:39.828Z","4.0.0-canary.355":"2022-12-12T21:29:17.050Z","4.0.0-canary.356":"2022-12-12T21:29:35.382Z","4.0.0-canary.357":"2022-12-12T21:59:09.670Z","4.0.0-canary.358":"2022-12-12T22:57:57.805Z","4.0.0-canary.359":"2022-12-13T01:17:48.501Z","4.0.0-canary.360":"2022-12-13T02:06:53.541Z","4.0.0-canary.361":"2022-12-13T03:43:38.796Z","4.0.0-canary.364":"2022-12-13T09:29:57.453Z","4.0.0-canary.365":"2022-12-13T12:59:21.794Z","4.0.0-canary.366":"2022-12-13T15:40:55.256Z","4.0.0-canary.367":"2022-12-13T17:20:18.609Z","4.0.0-canary.368":"2022-12-13T22:09:41.546Z","4.0.0-canary.369":"2022-12-13T22:39:31.805Z","4.0.0-canary.370":"2022-12-13T23:01:27.928Z"},"bugs":{"url":"https://github.com/redwoodjs/redwood/issues"},"license":"MIT","homepage":"https://github.com/redwoodjs/redwood#readme","repository":{"url":"git+https://github.com/redwoodjs/redwood.git","type":"git","directory":"packages/auth-providers-setup"},"description":"## Contributing","maintainers":[{"email":"peter.pistorius@gmail.com","name":"peter.pistorius"},{"email":"justnvdm@gmail.com","name":"justinvdm"}],"readme":"","readmeFilename":""}